Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C03 Exam - Topic 1 Question 14 Discussion

A company receives an alert from AWS Support. The alert shows a compromised access key on a single standalone AWS account. A security engineer must determine the scope of the issue. Then, the security engineer must triage and remediate the issue.Which solution will meet these requirements?
B) Review AWS CloudTrail logs. Remove any unauthorized resources. Rotate all IAM access keys for the user that has the AWSCompromisedKeyQuarantineV3 policy attached. Remove the policy from the user.
A) Delete the IAM user that has the AWSCompromisedKeyQuarantineV3 policy attached. Review Amazon CloudWatch for suspicious activity.
C) Remove the AWSCompromisedKeyQuarantineV3 policy from the impacted IAM user. Review AWS CloudTrail logs. Remove any unauthorized resources.
D) Review Amazon CloudWatch logs for suspicious activity. Remove all unauthorized resources. Rotate the impacted IAM access keys.

Amazon SCS-C03 Exam - Topic 1 Question 14 Discussion

Actual exam question for Amazon's SCS-C03 exam
Question #: 14
Topic #: 1
[All SCS-C03 Questions]

A company receives an alert from AWS Support. The alert shows a compromised access key on a single standalone AWS account. A security engineer must determine the scope of the issue. Then, the security engineer must triage and remediate the issue.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed 100to 150 words of Explanation From AWS Certified Security -- Specialty topics: AWSCompromisedKeyQuarantineV3 is applied by AWS when IAM user credentials are compromised or exposed, and AWS explicitly warns not to remove the policy until the support-case instructions are followed. The correct response is to first determine scope by reviewing CloudTrail activity for the compromised key, identify API calls and unauthorized resources, remove unauthorized resources, rotate or replace the compromised access keys, and only then remove the quarantine policy after remediation is complete. Deleting the user immediately can destroy useful attribution and may break legitimate dependencies. Removing the quarantine policy first is unsafe because it may restore attacker capability. CloudWatch logs alone do not provide the full account-wide API activity trail needed for scope determination.

================


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel