ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 268 - SCS-C01 discussion

Report
Export

Which of the following is not a best practice for carrying out a security audit?

Please select:

A.
Conduct an audit on a yearly basis
Answers
A.
Conduct an audit on a yearly basis
B.
Conduct an audit if application instances have been added to your account
Answers
B.
Conduct an audit if application instances have been added to your account
C.
Conduct an audit if you ever suspect that an unauthorized person might have accessed your account
Answers
C.
Conduct an audit if you ever suspect that an unauthorized person might have accessed your account
D.
Whenever there are changes in your organization
Answers
D.
Whenever there are changes in your organization
Suggested answer: A

Explanation:

A year's time is generally too long a gap for conducting security audits The AWS Documentation mentions the following You should audit your security configuration in the following situations:

On a periodic basis.

If there are changes in your organization, such as people leaving.

If you have stopped using one or more individual AWS services. This is important for removing permissions that users in your account no longer need. If you've added or removed software in your accounts, such as applications on Amazon EC2 instances, AWS OpsWor stacks, AWS CloudFormation templates, etc. If you ever suspect that an unauthorized person might have accessed your account.

Option B, C and D are all the right ways and recommended best practices when it comes to conducting audits For more information on Security Audit guideline, please visit the below URL:

https://docs.aws.amazon.com/eeneral/latest/gr/aws-security-audit-euide.htmlThe correct answer is: Conduct an audit on a yearly basis Submit your Feedback/Queries to ourExperts

asked 16/09/2024
Ankit Parimi
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first