ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 265 - SCS-C01 discussion

Report
Export

A security team is creating a response plan in the event an employee executes unauthorized actions on AWS infrastructure. They want to include steps to determine if the employee's IAM permissions changed as part of the incident. What steps should the team document in the plan?

Please select:

A.
Use AWS Config to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
Answers
A.
Use AWS Config to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
B.
Use Made to examine the employee's IAM permissions prior to the incident and compare them to the employee's A current IAM permissions.
Answers
B.
Use Made to examine the employee's IAM permissions prior to the incident and compare them to the employee's A current IAM permissions.
C.
Use CloudTrail to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
Answers
C.
Use CloudTrail to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
D.
Use Trusted Advisor to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
Answers
D.
Use Trusted Advisor to examine the employee's IAM permissions prior to the incident and compare them to the employee's current IAM permissions.
Suggested answer: A

Explanation:

You can use the AWSConfig history to see the history of a particular item.

The below snapshot shows an example configuration for a user in AWS Config

Option B,C and D are all invalid because these services cannot be used to see the history of a particular configuration item. This can only be accomplished by AWS Config. For more information on tracking changes in AWS Config, please visit the below URL:

https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/TrackineChanees.htmllThe correct answer is: Use AWS Config to examine the employee's IAM permissions prior to theincident and compare them the employee's current IAM permissions.

Submit your Feedback/Queries to our Experts

asked 16/09/2024
Gerhard Seher
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first