nerdexam
Amazon

SCS-C02 · Question #103

A company maintains an open-source application that is hosted on a public GitHub repository. While creating a new commit to the repository, an engineer uploaded their AWS access key and secret access

The correct answer is D. Analyze a credential report in AWS Identity and Access Management (IAM) to see when the. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_getting-report.html

Submitted by lucia.co· Mar 6, 2026Incident Response

Question

A company maintains an open-source application that is hosted on a public GitHub repository. While creating a new commit to the repository, an engineer uploaded their AWS access key and secret access key. The engineer reported the mistake to a manager, and the manager immediately disabled the access key. The company needs to assess the impact of the exposed access key. A security engineer must recommend a solution that requires the least possible managerial overhead. Which solution meets these requirements?

Options

  • AAnalyze an AWS Identity and Access Management (IAM) use report from AWS Trusted Advisor
  • BAnalyze Amazon CloudWatch Logs for activity by searching for the access key.
  • CAnalyze VPC flow logs for activity by searching for the access key.
  • DAnalyze a credential report in AWS Identity and Access Management (IAM) to see when the

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    15% (8)
  • C
    10% (5)
  • D
    71% (37)

Explanation

https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_getting-report.html

Topics

#credential exposure#IAM credential report#access key assessment#incident investigation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice