ExamGecko
Question list
Search
Search

List of questions

Search

Question 100 - PCCSE discussion

Report
Export

A manager informs the SOC that one or more RDS instances have been compromised and the SOC needs to make sure production RDS instances are NOT publicly accessible.

Which action should the SOC take to follow security best practices?

A.
Enable ''AWS S3 bucket is publicly accessible'' policy and manually remediate each alert.
Answers
A.
Enable ''AWS S3 bucket is publicly accessible'' policy and manually remediate each alert.
B.
Enable ''AWS RDS database instance is publicly accessible'' policy and for each alert, check that it is a production instance, and then manually remediate.
Answers
B.
Enable ''AWS RDS database instance is publicly accessible'' policy and for each alert, check that it is a production instance, and then manually remediate.
C.
Enable ''AWS S3 bucket is publicly accessible'' policy and add policy to an auto-remediation alert rule.
Answers
C.
Enable ''AWS S3 bucket is publicly accessible'' policy and add policy to an auto-remediation alert rule.
D.
Enable ''AWS RDS database instance is publicly accessible'' policy and add policy to an auto-remediation alert rule.
Answers
D.
Enable ''AWS RDS database instance is publicly accessible'' policy and add policy to an auto-remediation alert rule.
Suggested answer: B

Explanation:

Following best practices, the Security Operations Center (SOC) should enable a policy that checks for publicly accessible AWS RDS database instances and then manually remediate each instance confirmed to be part of the production environment. This approach ensures that only those resources that should not be publicly accessible are modified, avoiding unintended access restrictions on non-production instances.

asked 23/09/2024
Peter Keijer
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first