nerdexam
CompTIA

CS0-003 · Question #98

While conducting a cloud assessment, a security analyst performs a Prowler scan, which generates the following within the report: Based on the Prowler report, which of the following is the BEST…

The correct answer is B. Delete BusinessUsr access key 1. Prowler flags IAM access keys that violate security policies - in this report, BusinessUsr's access key 1 is the specific key identified as non-compliant (typically due to being unused for an extended period, exceeding the rotation age threshold, or never having been used at…

Submitted by javi_es· Mar 6, 2026Vulnerability management

Question

While conducting a cloud assessment, a security analyst performs a Prowler scan, which generates the following within the report:

Based on the Prowler report, which of the following is the BEST recommendation?

Exhibit

CS0-003 question #98 exhibit

Options

  • ADelete CloudDev access key 1.
  • BDelete BusinessUsr access key 1.
  • CDelete access key 1.
  • DDelete access key 2.

How the community answered

(49 responses)
  • A
    6% (3)
  • B
    73% (36)
  • C
    4% (2)
  • D
    16% (8)

Explanation

Prowler flags IAM access keys that violate security policies - in this report, BusinessUsr's access key 1 is the specific key identified as non-compliant (typically due to being unused for an extended period, exceeding the rotation age threshold, or never having been used at all), making option B the precise, targeted remediation.

Why the distractors are wrong:

  • A (CloudDev access key 1) - The report flags BusinessUsr, not CloudDev; deleting CloudDev's key would be acting on the wrong finding and could disrupt a legitimate user.
  • C (Delete "access key 1" generically) - Too vague; access key 1 exists for multiple users, and without specifying the user you could delete the wrong key or fail to address the actual flagged resource.
  • D (Delete access key 2) - Prowler's finding specifically targets key 1 for BusinessUsr; key 2 is not the one flagged in the report.

Memory tip: Think "Prowler = Precise" - Prowler findings always name the exact resource (user + key ID). On exam questions, match your recommendation to the exact flagged entity, not a similar one or a vague category. If the report names BusinessUsr/key1, the answer must name both.

Topics

#Cloud security assessment#Prowler scan#Access key management#Vulnerability remediation

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice