SCS-C02 exam dumps

SCS-C02 practice question 503 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 503

Select 3

Your organization is designing an application architecture using the AWS Well-Architected Framework. As part of improving the Security Pillar, you want to ensure that the application adheres to the principle of 'least privilege' while managing permissions. Which of the following approaches aligns with the security best practices in the Well-Architected Framework?

  1. A

    Use AWS Identity and Access Management (IAM) groups to assign permissions instead of directly assigning permissions to individual IAM users.

  2. B

    Grant full administrative privileges to all application resources to simplify management and avoid permission issues.

  3. C

    Implement IAM roles for applications and services that need access to AWS resources, instead of using IAM user access keys.

  4. D

    Enable multi-factor authentication (MFA) for root and privileged IAM users.

  5. E

    Attach policies directly to individual IAM users to ensure fine-grained control over their permissions.

Show answer and explanation

Correct answers: A, C, D

Explanation

The AWS Well-Architected Framework emphasizes the principle of 'least privilege' in the Security Pillar. This includes using IAM groups and roles for permission management, enabling MFA for enhanced security, and avoiding practices like granting full administrative privileges or attaching policies directly to users. These approaches help minimize the attack surface, reduce potential risks, and ensure effective access management across AWS environments.

  • A. Correct.

    Using IAM groups to assign permissions is a best practice as it simplifies permission management and ensures that individual users are not directly assigned permissions, which reduces the risk of errors or misuse.

  • B. Incorrect.

    Granting full administrative privileges violates the principle of least privilege and introduces unnecessary security risks by over-provisioning access.

  • C. Correct.

    IAM roles are designed for secure and temporary access to AWS resources, and they eliminate the need for long-term credentials like access keys, which enhances security.

  • D. Correct.

    Enabling multi-factor authentication (MFA) for root and privileged IAM users is a critical security measure to protect against unauthorized access, especially for high-privilege accounts.

  • E. Incorrect.

    Attaching policies directly to individual IAM users is discouraged as it makes permission management complex and error-prone. Instead, policies should be attached to groups or roles for better scalability and maintainability.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam