AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A CloudOps engineer must enforce the following requirements for IAM user passwords in a single AWS account: at least 16 characters, one uppercase, one lowercase, one number, one symbol, no reuse of the previous 15 passwords, and disable console access after 90 days until the password is changed. Which action meets these requirements with minimal operational effort?
Create an IAM account password policy that sets minimum length to 16, requires uppercase, lowercase, numbers and symbols, prevents reuse of 15 previous passwords, and enables 90-day hard expiry.
Enable the AWS Config managed rule for account password policy compliance and configure an EventBridge rule to disable each IAM user after 90 days.
Attach an IAM managed policy to all console users that includes condition keys enforcing minimum length and complexity requirements.
Use AWS IAM Identity Center with an external identity provider and configure the provider to apply the required password rules.
The IAM account password policy natively supports all the listed controls. By setting the minimum length to 16, selecting the four character-type check boxes, configuring password reuse prevention to 15 previous passwords, and enabling password expiration after 90 days with the hard-expiry option, every requirement is enforced automatically for all IAM users. The other options either rely on custom IAM policies (which cannot control password complexity), require additional automation to disable accounts, or introduce an external identity provider, adding unnecessary operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IAM account password policy in AWS?
Open an interactive chat with Bash
What does the 'hard-expiry' option in an IAM password policy do?
Open an interactive chat with Bash
Why can't custom IAM policies enforce password complexity in AWS?
Open an interactive chat with Bash
What is an IAM account password policy and how does it work?
Open an interactive chat with Bash
What is the purpose of enabling hard-expiry in a password policy?
Open an interactive chat with Bash
Why can't IAM managed policies enforce password complexity requirements?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .