ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 28 - SCS-C02 discussion

Report
Export

A company became aware that one of its access keys was exposed on a code sharing website 11 days ago. A Security Engineer must review all use of the exposed access keys to determine the extent of the exposure. The company enabled IAM CloudTrail m an regions when it opened the account

Which of the following will allow (he Security Engineer 10 complete the task?

A.
Filter the event history on the exposed access key in the CloudTrail console Examine the data from the past 11 days.
Answers
A.
Filter the event history on the exposed access key in the CloudTrail console Examine the data from the past 11 days.
B.
Use the IAM CLI lo generate an IAM credential report Extract all the data from the past 11 days.
Answers
B.
Use the IAM CLI lo generate an IAM credential report Extract all the data from the past 11 days.
C.
Use Amazon Athena to query the CloudTrail logs from Amazon S3 Retrieve the rows for the exposed access key tor the past 11 days.
Answers
C.
Use Amazon Athena to query the CloudTrail logs from Amazon S3 Retrieve the rows for the exposed access key tor the past 11 days.
D.
Use the Access Advisor tab in the IAM console to view all of the access key activity for the past 11 days.
Answers
D.
Use the Access Advisor tab in the IAM console to view all of the access key activity for the past 11 days.
Suggested answer: C

Explanation:

Amazon Athena is a service that enables you to analyze data in Amazon S3 using standard SQL1.You can use Athena to query the CloudTrail logs that are stored in S3 and filter them by the exposed access key and the date range2. The other options are not effective ways to review the use of the exposed access key.

asked 16/09/2024
paloma giraudo
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first