SOA-C02 Security and Compliance Practice Question
A company's security policy requires that all IAM users must change their passwords every 90 days. The SysOps administrator needs to enforce this requirement. Which IAM setting should the administrator configure?
⚠ Common exam trap
Many exam-takers confuse IAM password policy with IAM user permissions or group policies, thinking that password rotation can be enforced through permission boundaries or role trust policies, which are unrelated to authentication settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM password policy
The IAM password policy is the correct setting because it allows the SysOps administrator to define password rotation requirements, such as a mandatory password change every 90 days. This policy is applied at the account level and enforces the security requirement for all IAM users, ensuring compliance without needing to modify individual user permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM password policy
Why this is correct
The IAM account password policy is the account-level security setting that governs the lifecycle of IAM user passwords. It can enforce a maximum password age, such as 90 days, which forces users to rotate their passwords at a set interval. This is the only mechanism in IAM that controls password expiration for all users in the account, directly satisfying the security policy's rotation requirement.
- ✗
IAM user permissions boundary
Why it's wrong here
An IAM user permissions boundary is a policy that defines the maximum permissions an IAM user can receive from other policies, such as managed or inline policies. It is an authorization control that limits what actions or resources the user can access, but it does not affect authentication credentials. Since password rotation is a credential lifecycle requirement, a permissions boundary cannot enforce a 90-day expiration and is therefore not the correct solution.
- ✗
IAM role trust policy
Why it's wrong here
An IAM role trust policy is a JSON policy attached to a role that specifies which principals—such as IAM users, service accounts, or entire AWS accounts—are allowed to assume that role. It is used in cross-account or service-level access delegation and does not apply to the password settings of IAM users. The trust policy controls the ability to assume a role, not the authentication credentials of the role's eventual users, so it cannot enforce password rotation for IAM users.
- ✗
IAM group policy
Why it's wrong here
An IAM group policy is an identity-based policy that is attached to an IAM group, and it grants permissions to all users who are members of that group. It determines what actions the users can perform on AWS resources, but it has no bearing on how those users authenticate or how often they must change their passwords. Password rotation is an account-wide security setting managed by the IAM password policy, not something that can be enforced per group or via group permissions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.