Who is responsible for rotating IAM user access credentials and secret keys under the AWS shared responsibility model?
Choose an answer
Tap an option to check your answer.
Correct answer: The customer is responsible for rotating keys..
Why this is the answer
Under the AWS shared responsibility model, security in the cloud is the customer's responsibility, while security of the cloud is AWS's responsibility. Managing IAM user access credentials and secret keys, including their rotation, falls under customer responsibility. This is a crucial security best practice to minimize the risk of compromised credentials. Leaving keys unrotated indefinitely (first option) is a significant security vulnerability. While AWS provides the services and infrastructure for key management, they do not manage the customer's specific IAM user credentials or perform rotations for them (third option). Similarly, AWS Support will not rotate keys on behalf of the customer (fourth option); they can provide guidance, but the action remains with the customer.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed