nerdexam
Amazon

SCS-C02 · Question #68

A security engineer for a company wants to maintain all IAM users and roles according to the principle of least privilege. The security engineer plans to audit the IAM permissions once every 365 days.

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #68. The question stem and answer options stay visible for context.

Submitted by stefanr· Mar 6, 2026Identity and Access Management

Question

A security engineer for a company wants to maintain all IAM users and roles according to the principle of least privilege. The security engineer plans to audit the IAM permissions once every 365 days. The security engineer must view the permissions that each IAM identity used in the last 365 days and must remove any unused permissions. Which solution will meet these requirements?

Options

  • AUse AWS CloudTrail logs to review IAM identity actions and to remove unused permissions.
  • BUse AWS Config to review configuration changes by each IAM identity and to remove unused
  • CUse AWS Identity and Access Management Access Analyzer to review last accessed information
  • DUse AWS Trusted Advisor to check the IAM identities that have elevated permissions and to

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM Access Analyzer#least privilege#last accessed information#IAM audit
Full SCS-C02 Practice