AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A developer has long-lived IAM access keys embedded in a script that has not been rotated in over two years. A security audit flags this as a risk. What is the recommended best practice to remediate this finding?
- AAttach an SCP that permanently blocks the sts:GetSessionToken action
- BIncrease the IAM password policy expiration period to cover access keys as well
- CReplace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used
- DEnable GuardDuty to automatically delete old access keys after 90 days
Show answer & explanationAnswer & explanation
Correct answer: C. Replace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used
AWS best practice is to avoid long-lived credentials altogether by using IAM roles that provide short-term temporary credentials via STS; when access keys are unavoidable, they should be rotated regularly and unused ones removed.
Why the other options are wrong
- A. Blocking GetSessionToken would break legitimate temporary credential usage, not fix the risk
- B. Password policies govern console passwords, not access key rotation
- D. GuardDuty detects threats but does not automatically delete or rotate access keys
Access Key Rotation Best Practice
AWS recommends using IAM roles for temporary credentials instead of long-lived access keys, and rotating any necessary access keys regularly.
- Long-lived access keys increase risk if leaked or forgotten
- IAM roles issue temporary credentials via AWS STS automatically
- When keys are required, rotate periodically and remove unused/old keys
Memory trick: Old keys rust — swap for a role's fresh temporary badge.