SCS-C02 exam dumps

SCS-C02 practice question 18 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 18

Select 2

Your company recently detected a security incident where an unauthorized IAM user accessed sensitive S3 bucket data. The security team has identified the compromised IAM user's credentials and disabled them. As part of the incident response, what additional actions should you take to prevent further unauthorized access and ensure proper remediation?

  1. A

    Review AWS CloudTrail logs to identify the scope of the unauthorized access.

  2. B

    Delete the compromised IAM user and all associated permissions.

  3. C

    Enable Amazon S3 server access logging on the affected bucket.

  4. D

    Rotate all access keys across all IAM users in the account.

  5. E

    Apply an S3 bucket policy to deny access from the compromised IAM user.

Show answer and explanation

Correct answers: A, C

Explanation

In the aftermath of a cloud security incident, it is essential to investigate the scope of the breach and improve monitoring to prevent future occurrences. Reviewing CloudTrail logs provides insight into the actions taken by the unauthorized user, while enabling S3 server access logging improves visibility of future access attempts. Deleting the IAM user prematurely or rotating all access keys unnecessarily could hinder the investigation or disrupt operations. Since the IAM user's credentials are already disabled, additional bucket policies are unnecessary to prevent access.

  • A. Correct.

    Reviewing AWS CloudTrail logs is a critical step to understand the extent of the security incident, including what actions were performed by the unauthorized user and which resources were accessed.

  • B. Incorrect.

    Deleting the compromised IAM user may seem like a solution, but it is not recommended during the investigation phase. You may need the user for forensic purposes or to understand permissions associated with it.

  • C. Correct.

    Enabling Amazon S3 server access logging will help you monitor future access attempts to the affected bucket and enhance visibility for ongoing security monitoring.

  • D. Incorrect.

    Rotating all access keys across all IAM users is not necessary unless there is evidence that multiple credentials have been compromised. Over-rotating keys could disrupt legitimate operations unnecessarily.

  • E. Incorrect.

    Applying an S3 bucket policy to deny access from the compromised IAM user is redundant since the credentials of that user have already been disabled.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam