SOA-C02 Security and Compliance Practice Question
A company's security policy requires that IAM users rotate their access keys every 90 days. The SysOps administrator must automatically identify users whose access keys are older than 90 days and notify the security team. Which combination of AWS services should be used to meet this requirement with the least operational overhead?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing custom Lambda or CloudTrail-based approaches, missing that AWS Config provides a fully managed, built-in rule specifically designed for this exact compliance check with zero custom code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with the 'access-keys-rotated' managed rule and Amazon SNS
AWS Config's 'access-keys-rotated' managed rule checks whether IAM user access keys have been rotated within the specified number of days (default 90). When a non-compliant resource is detected, AWS Config can trigger an Amazon SNS notification directly, without any custom code or additional infrastructure. This combination provides a fully managed, serverless solution with the least operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config with the 'access-keys-rotated' managed rule and Amazon SNS
Why this is correct
AWS Config's managed rule 'access-keys-rotated' continuously evaluates each IAM user's active access keys against the configured maximum age (default 90 days). When the rule detects a key that exceeds the threshold, it marks the user as noncompliant and emits a compliance change notification through the Config delivery channel, which publishes to an Amazon SNS topic. Subscribing security personnel to that topic via email or SMS gives them a near-real-time alert, making this a purpose-built, scalable solution for enforcing rotation policy.
- ✗
AWS CloudTrail and Amazon CloudWatch Logs with metric filters and alarms
Why it's wrong here
AWS CloudTrail records 'CreateAccessKey' API calls, so you could in principle trigger a metric filter and alarm the moment a new key is created, but it provides no insight into how long existing keys have been active. CloudWatch Logs metric filters operate only on new log events; they cannot retroactively assess the age of keys created before the filter existed. To evaluate current key ages you would need to add custom logic (e.g., Lambda listing IAM users and keys), which goes beyond the stated CloudTrail/CloudWatch combination — making it an incomplete and non-architected approach.
- ✗
IAM Access Analyzer and AWS Lambda
Why it's wrong here
IAM Access Analyzer is designed to identify external access to resource-based policies by analyzing the policies attached to S3 buckets, KMS keys, Lambda functions, and IAM roles — it does not inspect IAM user credentials or track access key creation dates. Adding a Lambda function could theoretically be used to write a custom rotation-checking script, but that custom code would not leverage Access Analyzer for anything relevant to key age. Because the combination offers no built-in mechanism for detecting stale keys, it fails the security policy's rotation requirement.
- ✗
Amazon GuardDuty and Amazon EventBridge
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activities such as compromised credentials, unusual API calls, or crypto-mining behavior, not for compliance with internal key-rotation policies. Amazon EventBridge only routes events between AWS services; it could deliver GuardDuty findings to downstream targets but cannot evaluate whether an IAM access key is older than 90 days. This stack addresses security threats rather than administrative hygiene, so it would not trigger alerts for unrotated keys under normal conditions.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.