ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 133 - SCS-C01 discussion

Report
Export

A Security Engineer must design a solution that enables the Incident Response team to audit for changes to a user’s IAM permissions in the case of a security incident. How can this be accomplished?

A.
Use AWS Config to review the IAM policy assigned to users before and after the incident.
Answers
A.
Use AWS Config to review the IAM policy assigned to users before and after the incident.
B.
Run the GenerateCredentialReport via the AWS CLI, and copy the output to Amazon S3 daily for auditing purposes.
Answers
B.
Run the GenerateCredentialReport via the AWS CLI, and copy the output to Amazon S3 daily for auditing purposes.
C.
Copy AWS CloudFormation templates to S3, and audit for changes from the template.
Answers
C.
Copy AWS CloudFormation templates to S3, and audit for changes from the template.
D.
Use Amazon EC2 Systems Manager to deploy images, and review AWS CloudTrail logs for changes.
Answers
D.
Use Amazon EC2 Systems Manager to deploy images, and review AWS CloudTrail logs for changes.
Suggested answer: A

Explanation:

https://aws.amazon.com/blogs/security/how-to-record-and-govern-your-iam-resourceconfigurations-using-aws-config/

asked 16/09/2024
Karim Barakat
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first