ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 54 - SCS-C02 discussion

Report
Export

A company's Chief Security Officer has requested that a Security Analyst review and improve the security posture of each company IAM account The Security Analyst decides to do this by Improving IAM account root user security.

Which actions should the Security Analyst take to meet these requirements? (Select THREE.)

A.
Delete the access keys for the account root user in every account.
Answers
A.
Delete the access keys for the account root user in every account.
B.
Create an admin IAM user with administrative privileges and delete the account root user in every account.
Answers
B.
Create an admin IAM user with administrative privileges and delete the account root user in every account.
C.
Implement a strong password to help protect account-level access to the IAM Management Console by the account root user.
Answers
C.
Implement a strong password to help protect account-level access to the IAM Management Console by the account root user.
D.
Enable multi-factor authentication (MFA) on every account root user in all accounts.
Answers
D.
Enable multi-factor authentication (MFA) on every account root user in all accounts.
E.
Create a custom IAM policy to limit permissions to required actions for the account root user and attach the policy to the account root user.
Answers
E.
Create a custom IAM policy to limit permissions to required actions for the account root user and attach the policy to the account root user.
F.
Attach an IAM role to the account root user to make use of the automated credential rotation in IAM STS.
Answers
F.
Attach an IAM role to the account root user to make use of the automated credential rotation in IAM STS.
Suggested answer: A, D, E

Explanation:

because these are the actions that can improve IAM account root user security. IAM account root user is a user that has complete access to all AWS resources and services in an account. IAM account root user security is a set of best practices that help protect the account root user from unauthorized or accidental use. Deleting the access keys for the account root user in every account can help prevent programmatic access by the account root user, which reduces the risk of compromise or misuse. Enabling MFA on every account root user in all accounts can help add an extra layer of security for console access by requiring a verification code in addition to a password. Creating a custom IAM policy to limit permissions to required actions for the account root user and attaching the policy to the account root user can help enforce the principle of least privilege and restrict the account root user from performing unnecessary or dangerous actions. The other options are either invalid or ineffective for improving IAM account root user security.

asked 16/09/2024
Sukhpreet Sidhu
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first