SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to generate a report of all IAM users and their last activity. Which AWS service can provide this information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM Credential Report
IAM Credential Report provides a consolidated report of all IAM users and their last activity, including password last used and access key last rotated. Option A is incorrect because AWS Config tracks resource configuration changes, not user activity. Option C is incorrect because AWS Trusted Advisor provides cost optimization and security recommendations, not detailed user activity reports. Option D is incorrect because AWS CloudTrail logs API calls but does not generate a summarized report of user credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates recorded AWS resource configurations against desired policies, such as checking whether an S3 bucket is encrypted or an IAM role matches a compliant template. It does not capture sign-in activity, API calls, or the last-usage timestamps of user credentials, so it cannot produce the type of identity-focused report required. Therefore, Config is incorrect for this task.
- ✓
IAM Credential Report
Why this is correct
The IAM Credential Report is a downloadable CSV that lists every IAM user in the account with detailed fields including password last used, password last changed, access key IDs, key last used, and key rotation dates. This report is generated on demand or on a schedule using the AWS API, CLI, or console and directly satisfies the requirement to report on IAM users. It is the correct answer because it is purpose-built for summarizing user credential activity.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor provides real-time checks across categories like cost optimization, security, fault tolerance, and performance, offering recommendations such as whether IAM users have multi-factor authentication enabled. It does not maintain a historical record of when each IAM user's password or access keys were last used, and it does not generate a report of user activity. Thus, Trusted Advisor is not the appropriate service for this requirement.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity as event history, capturing who made calls, the actions taken, the resources involved, and the timestamps of those events. While this log can be queried for individual operations such as ConsoleLogin or GetUser, it does not produce a consolidated credential report showing last-usage and rotation status for all IAM users. CloudTrail is therefore an audit trail, not the IAM-focused summary report requested.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.