AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A developer has long-lived IAM access keys embedded in a script that has not been rotated in over two years. A security audit flags this as a risk. What is the recommended best practice to remediate this finding?

  1. AAttach an SCP that permanently blocks the sts:GetSessionToken action
  2. BIncrease the IAM password policy expiration period to cover access keys as well
  3. CReplace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used
  4. DEnable GuardDuty to automatically delete old access keys after 90 days
Show answer & explanation

Correct answer: C. Replace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used

AWS best practice is to avoid long-lived credentials altogether by using IAM roles that provide short-term temporary credentials via STS; when access keys are unavoidable, they should be rotated regularly and unused ones removed.

Why the other options are wrong

  • A. Blocking GetSessionToken would break legitimate temporary credential usage, not fix the risk
  • B. Password policies govern console passwords, not access key rotation
  • D. GuardDuty detects threats but does not automatically delete or rotate access keys

Access Key Rotation Best Practice

AWS recommends using IAM roles for temporary credentials instead of long-lived access keys, and rotating any necessary access keys regularly.

  • Long-lived access keys increase risk if leaked or forgotten
  • IAM roles issue temporary credentials via AWS STS automatically
  • When keys are required, rotate periodically and remove unused/old keys

Memory trick: Old keys rust — swap for a role's fresh temporary badge.

More Security and Compliance questions