Amazon
SOA-C02 · Question #102
A company requires that all IAM user accounts that have not been used for 90 days or more must have their access keys and passwords immediately disabled. A SysOps administrator must automate the proce
Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #102. The question stem and answer options stay visible for context.
Submitted by tom_us· Mar 30, 2026Security and Compliance
Question
A company requires that all IAM user accounts that have not been used for 90 days or more must have their access keys and passwords immediately disabled. A SysOps administrator must automate the process of disabling unused keys using the MOST operationally efficient method. How should the SysOps administrator implement this solution?
Options
- ACreate an AWS Step Functions workflow to identify IAM users that have not been active for 90
- BConfigure an AWS Config rule to identify IAM users that have not been active for 90 days.
- CDevelop and run a Python script on an Amazon EC2 instance to programmatically identify IAM
- DSet up an AWS Config managed rule to identify IAM users that have not been active for 90 days.
Unlock SOA-C02 to see the answer
You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#AWS Config managed rules#IAM credential lifecycle#access key management#automated remediation