SOA-C02 exam dumps

SOA-C02 practice question 186 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 186

Select 3

As a SysOps Administrator, you are tasked with improving the security posture of your AWS environment. You decide to review AWS Trusted Advisor's security checks. During your review, you find that several checks are marked as 'Action Recommended.' Which of the following steps should you take to address these flagged items?

  1. A

    Ensure that all IAM users have multi-factor authentication (MFA) enabled.

  2. B

    Verify that Security Groups do not have overly permissive rules, such as 0.0.0.0/0 for SSH or RDP.

  3. C

    Disable unused AWS regions to prevent unauthorized access.

  4. D

    Rotate IAM access keys that are older than 90 days to meet security best practices.

  5. E

    Enable versioning on all S3 buckets to prevent accidental data loss.

Show answer and explanation

Correct answers: A, B, D

Explanation

AWS Trusted Advisor provides security checks to identify potential risks in your AWS environment. These checks include ensuring MFA is enabled for IAM users, limiting overly permissive Security Group rules, and rotating IAM access keys older than 90 days. Addressing these flagged issues helps improve the security posture of your AWS environment.

  • A. Correct.

    Trusted Advisor highlights IAM users without MFA as a risk because it weakens account security. Enabling MFA for all users is a recommended action.

  • B. Correct.

    Security Groups with overly permissive rules, such as allowing SSH or RDP from 0.0.0.0/0, can expose your environment to security threats. Trusted Advisor flags this as a high-risk issue.

  • C. Incorrect.

    Disabling unused AWS regions is not a feature or recommendation provided by Trusted Advisor. Trusted Advisor focuses on best practices within active resources and configurations.

  • D. Correct.

    IAM access keys older than 90 days are flagged by Trusted Advisor as a security best practice to be rotated. Rotating keys reduces the risk of unauthorized access.

  • E. Incorrect.

    While enabling versioning on S3 buckets is a good practice for data recovery, it is not flagged by Trusted Advisor under security checks.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam