SCS-C02 · Question #237
A security engineer discovers that a company's user passwords have no required minimum length. The company is using the following two identity providers (IdPs): - AWS Identity and Access Management (I
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #237. The question stem and answer options stay visible for context.
Question
A security engineer discovers that a company's user passwords have no required minimum length. The company is using the following two identity providers (IdPs):
- AWS Identity and Access Management (IAM) federated with on-premises
Active Directory
- Amazon Cognito user pools that contain the user database for an AWS
Cloud application that the company developed Which combination of actions should the security engineer take to implement a required minimum length for the passwords? (Choose two.)
Options
- AUpdate the password length policy in the IAM configuration
- BUpdate the password length policy in the Cognito configuration.
- CUpdate the password length policy in the on-premises Active Directory configuration.
- DCreate an SCP in AWS Organizations. Configure the SCP to enforce a minimum password length
- ECreate an IAM policy that includes a condition for minimum password length Enforce the policy
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.