SOA-C02 Security and Compliance Practice Question
A SysOps administrator is configuring a new AWS account and wants to set up a secure password policy for IAM users. The policy must require at least 12 characters, one uppercase letter, one number, and must prevent password reuse. Where should this policy be configured?
⚠ Common exam trap
SOA-C02 often tests whether candidates confuse SCPs (permission guardrails) with the IAM account password policy, leading them to pick SCPs for password complexity requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the IAM console under Account settings, set the password policy.
The IAM account password policy is configured in the IAM console under Account settings, where you can enforce minimum length, character complexity, password reuse prevention, and expiration. This policy applies to all IAM users in the account and is the correct location for the stated requirements. It is a single account-level setting, not something attached to individual users or roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a service control policy (SCP) that enforces password complexity.
Why it's wrong here
A service control policy (SCP) is an AWS Organizations feature that restricts the maximum permissions for IAM users and roles in member accounts; it cannot directly enforce password complexity. SCPs can deny the ability to modify the password policy, but they do not contain configuration values for password length or character requirements. Password complexity is an IAM account-level setting, not a resource or action that an SCP can enforce.
- ✓
In the IAM console under Account settings, set the password policy.
Why this is correct
The IAM password policy is configured at the AWS account level under IAM > Account settings, and it applies uniformly to all IAM users in that account. This policy can enforce requirements like minimum length, uppercase/lowercase letters, numbers, symbols, password expiration, and reuse prevention. It is the standard mechanism for implementing password complexity rules across all IAM users, and it must be set independently for each AWS account.
- ✗
Set a password policy on the AWS account root user.
Why it's wrong here
The AWS account root user does not have an IAM password policy; its password is a single, separate credential established when the account is created. While you can change the root user password using the account profile settings, the IAM password policy (complexity, expiration, rotation) does not apply to the root user. Attempting to set a password policy specifically on the root user is not supported, because the root user is not an IAM entity.
- ✗
Create an IAM role with a password policy attached.
Why it's wrong here
An IAM role is not an identity that signs in with a password; roles are assumed by trusted identities and obtain temporary security credentials through AWS STS. Roles cannot have passwords attached, and therefore a password policy cannot be assigned to a role. Password policies apply only to IAM users, not to roles or other temporary-credential mechanisms.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.