AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A financial services company wants to enforce that all IAM users create passwords that are at least 14 characters long, contain a mix of character types, and expire after 90 days. Which AWS feature should be configured to meet this requirement?

  1. AA Service Control Policy attached to the organization root
  2. BAn IAM account password policy
  3. CAWS Config managed rule with automatic remediation
  4. DAn IAM permissions boundary applied to each user
Show answer & explanation

Correct answer: B. An IAM account password policy

IAM account password policies let administrators define complexity requirements, minimum length, expiration, and reuse prevention for IAM user console passwords across the AWS account.

Why the other options are wrong

  • A. SCPs govern API actions and permissions, not password formatting rules
  • C. Config can detect non-compliant settings but does not enforce password creation rules
  • D. Permissions boundaries limit maximum permissions, not password complexity

IAM Password Policy

An account-wide setting that enforces password length, complexity, expiration, and reuse rules for IAM users.

  • Configured per AWS account in IAM settings
  • Can require minimum length, uppercase/lowercase/numbers/symbols
  • Can set expiration period and prevent password reuse

Memory trick: One ruler measures every password in the account.

More Security and Compliance questions