SCS-C03 · Question #147
A security engineer for a company needs to design an incident response plan that addresses compromised IAM user account credentials. The company uses an organization in AWS Organizations and AWS IAM I
The correct answer is D. Disable the IAM user's access in IAM Identity Center. Use AWS CloudTrail to query the. When AWS IAM Identity Center is used to manage user access across an AWS Organization, Identity Center is the authoritative control plane for enabling and disabling user access. According to the AWS Certified Security - Specialty Official Study Guide, disabling a user in IAM Iden
Question
A security engineer for a company needs to design an incident response plan that addresses compromised IAM user account credentials. The company uses an organization in AWS Organizations and AWS IAM Identity Center to manage user access. The company uses a delegated administrator account to implement AWS Security Hub. The delegated administrator account contains an organizational trail in AWS CloudTrail that logs all events to an Amazon S3 bucket. The company has also configured an organizational event data store that captures all events from the trail. The incident response plan must provide steps that the security engineer can take to immediately disable any compromised IAM user when the security engineer receives a notification of a security incident. The plan must prevent the IAM user from being used in any AWS account. The plan must also collect all AWS actions that the compromised IAM user performed across all accounts in the previous 7 days. Which solution will meet these requirements?
Options
- ADisable the compromised IAM user in the organization management account. Use Amazon
- BRemove all IAM policies that are attached to the IAM user in the organization management
- CRemove any permission sets that are assigned to the IAM user in IAM Identity Center. Use
- DDisable the IAM user's access in IAM Identity Center. Use AWS CloudTrail to query the
How the community answered
(41 responses)- A2% (1)
- B10% (4)
- C15% (6)
- D73% (30)
Explanation
When AWS IAM Identity Center is used to manage user access across an AWS Organization, Identity Center is the authoritative control plane for enabling and disabling user access. According to the AWS Certified Security - Specialty Official Study Guide, disabling a user in IAM Identity Center immediately prevents that user from accessing any AWS account or role that is assigned through permission sets, satisfying the requirement to stop access organization-wide.
Topics
Community Discussion
No community discussion yet for this question.