SCS-C02 exam dumps

SCS-C02 practice question 20 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 20

Select 3

Your organization recently identified unauthorized access to sensitive data hosted in an Amazon S3 bucket. After conducting an initial investigation, you suspect that a compromised IAM user key may have been used to access the data. Which actions should you take to mitigate the incident and prevent further unauthorized access?

  1. A

    Disable the compromised IAM user and rotate their access keys immediately.

  2. B

    Enable Amazon S3 server access logging for the affected bucket to track future access requests.

  3. C

    Review AWS CloudTrail logs to identify the source and scope of the unauthorized access.

  4. D

    Delete the affected S3 bucket to ensure the data cannot be accessed anymore.

  5. E

    Apply a bucket policy to restrict access to specific IAM roles or IP ranges.

  6. F

    Create a new S3 bucket and migrate the sensitive data there without public access.

Show answer and explanation

Correct answers: A, C, E

Explanation

In response to a cloud security incident involving unauthorized access, it is critical to take actions that mitigate the immediate threat and address the root cause. Disabling the compromised IAM user and rotating their keys prevents further exploitation of the compromised credentials. Reviewing AWS CloudTrail logs helps identify the scope and source of the attack, which is vital for the investigation. Applying a bucket policy ensures tighter access controls to prevent unauthorized access in the future. While other options may have some value, they do not directly address the immediate or root causes of the incident, making them less relevant in this scenario.

  • A. Correct.

    Disabling the compromised IAM user and rotating their access keys is critical to immediately stop unauthorized access and prevent further exploitation.

  • B. Incorrect.

    Enabling S3 server access logging is useful for tracking future access, but it will not mitigate the current incident or stop unauthorized access immediately.

  • C. Correct.

    Reviewing AWS CloudTrail logs is essential for understanding the source, timing, and scope of the unauthorized access, which is critical for incident response.

  • D. Incorrect.

    Deleting the S3 bucket is not a recommended action during an incident, as it could result in data loss and hinder investigation efforts.

  • E. Correct.

    Applying a bucket policy to restrict access ensures only authorized users or IP ranges can access the S3 bucket, mitigating further unauthorized access.

  • F. Incorrect.

    Migrating data to a new S3 bucket does not directly address the root cause of the incident and could introduce additional complexity or downtime.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam