SCS-C02 exam dumps

SCS-C02 practice question 406 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 406

Select 3

Your organization is using AWS Systems Manager Parameter Store to store sensitive database credentials as SecureString parameters. A developer accidentally shared the ARN of one of these parameters in a public repository. As a security engineer, what steps should you take to mitigate the risk of exposure and ensure no unauthorized access occurs?

  1. A

    Rotate the database credentials and update the SecureString parameter with the new credentials.

  2. B

    Use AWS Key Management Service (KMS) to re-encrypt the exposed SecureString parameter with a new encryption key.

  3. C

    Restrict access to the exposed parameter by updating the IAM policies associated with it.

  4. D

    Delete the exposed SecureString parameter and create a new one with updated credentials.

  5. E

    Enable AWS CloudTrail integration with Parameter Store to monitor access to the exposed parameter.

Show answer and explanation

Correct answers: A, C, E

Explanation

When sensitive information stored in AWS Systems Manager Parameter Store is exposed, it is critical to rotate the credentials to render the exposed values useless. Additionally, updating IAM policies to restrict access and enabling CloudTrail for monitoring are essential actions to ensure that any unauthorized access attempts are blocked and logged. Re-encrypting the parameter or simply deleting it does not fully address the root problem of credential exposure.

  • A. Correct.

    Rotating the database credentials ensures that any compromised credentials are no longer valid. This is a critical step to mitigate the risk of exposure.

  • B. Incorrect.

    Re-encrypting the SecureString parameter with a new KMS key does not address the exposure since the original credentials are still compromised.

  • C. Correct.

    Restricting access to the parameter by updating IAM policies reduces the chance of unauthorized access to the exposed parameter.

  • D. Incorrect.

    Deleting the parameter without rotating the credentials first could lead to service disruptions if applications rely on the parameter. Simply deleting the parameter is not the best mitigation strategy.

  • E. Correct.

    Enabling AWS CloudTrail integration allows you to monitor access to the exposed parameter, providing visibility into unauthorized access attempts or usage.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam