Amazon
SOA-C03 · Question #23
A CloudOps engineer must manage the security of an AWS account. Recently, an IAM user's access key was mistakenly uploaded to a public code repository. The engineer must identify everything that was c
Sign in or unlock SOA-C03 to reveal the answer and full explanation for question #23. The question stem and answer options stay visible for context.
Submitted by jordan8· Mar 5, 2026Security and compliance
Question
A CloudOps engineer must manage the security of an AWS account. Recently, an IAM user's access key was mistakenly uploaded to a public code repository. The engineer must identify everything that was changed using this compromised key. How should the CloudOps engineer meet these requirements?
Options
- ACreate an Amazon EventBridge rule to send all IAM events to an AWS Lambda function for
- BQuery Amazon EC2 logs by using Amazon CloudWatch Logs Insights for all events initiated with
- CSearch AWS CloudTrail event history for all events initiated with the compromised access key
- DSearch VPC Flow Logs for all events initiated with the compromised access key within the
Unlock SOA-C03 to see the answer
You've previewed enough free SOA-C03 questions. Unlock SOA-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#CloudTrail#compromised access key#incident response#IAM forensics