A security engineer rotated all IAM access keys in an AWS account and enabled the following AWS Config managed rules: mfa-enabled-for-iam-console-access, iam-user-mfa-enabled, access-keys-rotated, and iam-user-unused-credentials-check. After invoking the IAM GenerateCredentialReport API, all resources appear as noncompliant. What is the most likely reason?
Choose an answer
Tap an option to check your answer.
Correct answer: The IAM credential report was generated within the last 4 hours..
Why this is the answer
The most likely reason for the noncompliant status is that the IAM credential report was generated within the last 4 hours. AWS Config rules that rely on the credential report, such as access-keys-rotated and iam-user-unused-credentials-check, use a cached version of the report. This cache is refreshed approximately every four hours. If the credential report was generated recently, the Config rules might still be evaluating against an older, cached version that doesn't reflect the recent key rotations, leading to false noncompliance. The other options are less likely. The security engineer must have the necessary permissions to invoke GenerateCredentialReport for the report to be generated at all. GetCredentialReport is for retrieving the report, not generating it. While MaximumExecutionFrequency can affect when rules run, the issue here is specifically about the data source (the credential report) being outdated, not the rule execution frequency itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed