nerdexam
Amazon

SCS-C02 · Question #135

A security engineer recently rotated all IAM access keys in an AWS account. The security engineer then configured AWS Config and enabled the following AWS Config managed rules…

The correct answer is A. The IAM credential report was generated within the past 4 hours. https://repost.aws/knowledge-center/config-credential-report

Submitted by manish99· Mar 6, 2026Identity and Access Management

Question

A security engineer recently rotated all IAM access keys in an AWS account. The security engineer then configured AWS Config and enabled the following AWS Config managed rules:

mfa-enabled-for-iam-console-access, iam-user-mfa-enabled, access-keys-rotated, and iam-user- unused-credentials-check. The security engineer notices that all resources are displaying as noncompliant after the IAM GenerateCredentialReport API operation is invoked. What could be the reason for the noncompliant status?

Options

  • AThe IAM credential report was generated within the past 4 hours.
  • BThe security engineer does not have the GenerateCredentialReport permission.
  • CThe security engineer does not have the GetCredenlialReport permission.
  • DThe AWS Config rules have a MaximumExecutionFrequency value of 24 hours.

How the community answered

(15 responses)
  • A
    80% (12)
  • C
    13% (2)
  • D
    7% (1)

Explanation

https://repost.aws/knowledge-center/config-credential-report

Topics

#AWS Config managed rules#IAM credential report#access key rotation#compliance noncompliant

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice