AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A financial services company wants to enforce that all IAM users create passwords that are at least 14 characters long, contain a mix of character types, and expire after 90 days. Which AWS feature should be configured to meet this requirement?
- AA Service Control Policy attached to the organization root
- BAn IAM account password policy
- CAWS Config managed rule with automatic remediation
- DAn IAM permissions boundary applied to each user
Show answer & explanationAnswer & explanation
Correct answer: B. An IAM account password policy
IAM account password policies let administrators define complexity requirements, minimum length, expiration, and reuse prevention for IAM user console passwords across the AWS account.
Why the other options are wrong
- A. SCPs govern API actions and permissions, not password formatting rules
- C. Config can detect non-compliant settings but does not enforce password creation rules
- D. Permissions boundaries limit maximum permissions, not password complexity
IAM Password Policy
An account-wide setting that enforces password length, complexity, expiration, and reuse rules for IAM users.
- Configured per AWS account in IAM settings
- Can require minimum length, uppercase/lowercase/numbers/symbols
- Can set expiration period and prevent password reuse
Memory trick: One ruler measures every password in the account.