Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company's security policy requires that IAM users rotate their access keys every 90 days. The SysOps administrator must automatically identify users whose access keys are older than 90 days and notify the security team. Which combination of AWS services should be used to meet this requirement with the least operational overhead?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing custom Lambda or CloudTrail-based approaches, missing that AWS Config provides a fully managed, built-in rule specifically designed for this exact compliance check with zero custom code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with the 'access-keys-rotated' managed rule and Amazon SNS

AWS Config's 'access-keys-rotated' managed rule checks whether IAM user access keys have been rotated within the specified number of days (default 90). When a non-compliant resource is detected, AWS Config can trigger an Amazon SNS notification directly, without any custom code or additional infrastructure. This combination provides a fully managed, serverless solution with the least operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config with the 'access-keys-rotated' managed rule and Amazon SNS

    Why this is correct

    AWS Config's managed rule 'access-keys-rotated' continuously evaluates each IAM user's active access keys against the configured maximum age (default 90 days). When the rule detects a key that exceeds the threshold, it marks the user as noncompliant and emits a compliance change notification through the Config delivery channel, which publishes to an Amazon SNS topic. Subscribing security personnel to that topic via email or SMS gives them a near-real-time alert, making this a purpose-built, scalable solution for enforcing rotation policy.

  • ✗

    AWS CloudTrail and Amazon CloudWatch Logs with metric filters and alarms

    Why it's wrong here

    AWS CloudTrail records 'CreateAccessKey' API calls, so you could in principle trigger a metric filter and alarm the moment a new key is created, but it provides no insight into how long existing keys have been active. CloudWatch Logs metric filters operate only on new log events; they cannot retroactively assess the age of keys created before the filter existed. To evaluate current key ages you would need to add custom logic (e.g., Lambda listing IAM users and keys), which goes beyond the stated CloudTrail/CloudWatch combination — making it an incomplete and non-architected approach.

  • ✗

    IAM Access Analyzer and AWS Lambda

    Why it's wrong here

    IAM Access Analyzer is designed to identify external access to resource-based policies by analyzing the policies attached to S3 buckets, KMS keys, Lambda functions, and IAM roles — it does not inspect IAM user credentials or track access key creation dates. Adding a Lambda function could theoretically be used to write a custom rotation-checking script, but that custom code would not leverage Access Analyzer for anything relevant to key age. Because the combination offers no built-in mechanism for detecting stale keys, it fails the security policy's rotation requirement.

  • ✗

    Amazon GuardDuty and Amazon EventBridge

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that continuously monitors for malicious activities such as compromised credentials, unusual API calls, or crypto-mining behavior, not for compliance with internal key-rotation policies. Amazon EventBridge only routes events between AWS services; it could deliver GuardDuty findings to downstream targets but cannot evaluate whether an IAM access key is older than 90 days. This stack addresses security threats rather than administrative hygiene, so it would not trigger alerts for unrotated keys under normal conditions.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.