SCS-C02 exam dumps

SCS-C02 practice question 71 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 71

Select 4

Your organization has experienced unauthorized access to an S3 bucket containing sensitive data. The security team suspects that an IAM misconfiguration allowed the access. As a security engineer, you are tasked with performing root cause analysis to identify the issue. Which of the following steps should you take to effectively determine the root cause?

  1. A

    Examine the S3 bucket policy and access control lists (ACLs) for overly permissive settings.

  2. B

    Check CloudTrail logs for any API calls and events related to the S3 bucket.

  3. C

    Disable all IAM roles and policies immediately to prevent further access.

  4. D

    Analyze IAM policies attached to users, groups, and roles that have permissions to the bucket.

  5. E

    Review AWS Config history to identify changes made to the S3 bucket configuration.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Performing root cause analysis for unauthorized access requires a systematic approach to investigate IAM configurations, S3 bucket policies, and access logs. Examining the S3 bucket policy, CloudTrail logs, IAM policies, and AWS Config history helps pinpoint the exact misconfiguration or event that led to the issue. Disabling all roles and policies is not a viable option, as it disrupts legitimate access and does not aid in identifying the root cause.

  • A. Correct.

    This is correct. Overly permissive S3 bucket policies or ACLs are a common cause of unauthorized access. Reviewing these settings is critical for identifying potential misconfigurations.

  • B. Correct.

    This is correct. CloudTrail logs provide detailed information about API calls and events, enabling you to trace the unauthorized access and understand how it occurred.

  • C. Incorrect.

    This is incorrect. Disabling all roles and policies immediately is overly disruptive and not a recommended approach for root cause analysis. Instead, targeted investigation and remediation should be performed.

  • D. Correct.

    This is correct. IAM policies attached to users, groups, and roles may contain permissions that allowed unauthorized access. Analyzing these policies is essential for identifying any misconfigurations.

  • E. Correct.

    This is correct. AWS Config tracks configuration changes to resources, including S3 buckets, and can help identify when and how the bucket’s settings were altered, potentially leading to unauthorized access.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam