ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 260 - SCS-C01 discussion

Report
Export

You have just received an email from AWS Support stating that your AWS account might have been compromised. Which of the following steps would you look to carry out immediately. Choose 3 answers from the options below. Please select:

A.
Change the root account password.
Answers
A.
Change the root account password.
B.
Rotate all IAM access keys
Answers
B.
Rotate all IAM access keys
C.
Keep all resources running to avoid disruption
Answers
C.
Keep all resources running to avoid disruption
D.
Change the password for all IAM users.
Answers
D.
Change the password for all IAM users.
Suggested answer: A, B, D

Explanation:

One of the articles from AWS mentions what should be done in such a scenario If you suspect that your account has been compromised, or if you have received a notification from AWS that the account has been compromised, perform the following tasks:

Change your AWS root account password and the passwords of any IAM users.

Delete or rotate all root and AWS Identity and Access Management (IAM) access keys.

Delete any resources on your account you didn't create, especially running EC2 instances, EC2 spot bids, or IAM users. Respond to any notifications you received from AWS Support through the AWS Support Center.

Option C is invalid because there could be compromised instances or resources running on your environment. They should be shutdown or stopped immediately. For more information on the article, please visit the below URL:

https://aws.amazon.com/premiumsupport/knowledee-center/potential-account-compromise>The correct answers are: Change the root account password. Rotate all IAM access keys. Change thepassword for all IAM users. Submit your Feedback/Queries to our Experts

asked 16/09/2024
Isidre Piguillem
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first