Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO of the following are valid AWS IAM security best practices?

⚠ Common exam trap

SCS-C02 often tests the root-user and credential-sharing misconceptions; candidates who think deleting users is cleaner than disabling, or that root is fine for admin work, pick the wrong options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a strong password policy for IAM users.

Option A is correct because implementing a strong IAM account password policy enforces complexity requirements such as minimum length, uppercase/lowercase, numbers, symbols, and rotation, which reduces the risk of brute-force and credential-guessing attacks against IAM user sign-ins. Option D is correct because enabling MFA for privileged users adds a second authentication factor, so a compromised password alone is insufficient to perform sensitive actions, which is a core AWS IAM best practice. Option B is not a best practice because IAM access keys are long-term credentials tied to a specific identity and must never be shared; sharing them breaks accountability and complicates rotation and revocation. Option C is not correct as stated because AWS recommends disabling (deactivating) credentials and removing permissions before deleting users, and deletion should be done only when the identity is truly no longer needed. Option E is not a best practice because the root user has unrestricted access and should be used only for the few tasks that require it, with MFA enabled and access keys removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a strong password policy for IAM users.

    Why this is correct

    A strong password policy enforces length, complexity and rotation, reducing credential-guessing and brute-force success against IAM users. It satisfies the stem's best-practise criterion by hardening the primary authentication secret before other controls are layered on.

  • ✗

    Share IAM user access keys among team members for convenience.

    Why it's wrong here

    Sharing access keys destroys the audit trail, since CloudTrail logs attribute every action to one identity, and it prevents revoking one person's access without disrupting others. It is tempting to reduce credential sprawl, but AWS instead recommends per-user credentials, roles, and temporary STS tokens for shared workloads.

  • ✗

    Delete IAM users instead of disabling them when not needed.

    Why it's wrong here

    Deleting IAM users removes the audit history and any resource policies referencing them, and recreated users receive different unique IDs, breaking trust relationships. It is tempting as tidy housekeeping, but AWS advises disabling credentials and removing permissions first, then deleting only after confirming nothing depends on the identity.

  • ✓

    Enable multi-factor authentication (MFA) for privileged users.

    Why this is correct

    MFA adds a second authentication factor beyond the password, so a compromised credential alone cannot authenticate. Enforcing it on privileged users directly satisfies the stem's best-practise requirement by protecting the accounts with the greatest blast radius.

  • ✗

    Use the AWS account root user for everyday administrative tasks.

    Why it's wrong here

    The root user holds unrestricted access, including billing and account closure, so using it daily removes the permission boundaries and least-privilege controls that IAM users and roles provide. It is tempting for convenience, but AWS advises locking away root credentials and using it only for the few tasks that genuinely require it.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.