exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 785 discussion

Exam question from Amazon's AWS-SysOps
Question #: 785
Topic #: 1
[All AWS-SysOps Questions]

A company uses federation to authenticate users and grant AWS permissions. The SysOps Administrator has been asked to determine who made a request to
AWS Organizations for a new AWS account.
What should the Administrator review to determine who made the request?

  • A. AWS CloudTrail for the federated identity user name
  • B. AWS IAM Access Advisor for the federated user name
  • C. AWS Organizations access log for the federated identity user name
  • D. Federated identity provider logs for the user name
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_federated-users.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
neel376
Highly Voted 2 years, 7 months ago
I believe its A. Cloudtrail https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html Check the "Logging IAM and AWS STS API Requests" section
upvoted 12 times
...
AWS_Noob
Highly Voted 2 years, 7 months ago
A All AWS Organizations actions are logged by CloudTrail and are documented in the AWS Organizations API Reference. For example, calls to CreateAccount (including the CreateAccountResult event), ListHandshakesForAccount, CreatePolicy, and InviteAccountToOrganization generate entries in the CloudTrail log files.
upvoted 6 times
...
albert_kuo
Most Recent 9 months, 2 weeks ago
Selected Answer: A
AWS CloudTrail provides a detailed history of AWS API calls made by or on behalf of an AWS account. This includes API calls made through AWS Management Console, SDKs, command-line tools, and other AWS services. When a user makes a request to AWS Organizations for creating a new AWS account, this action is logged by CloudTrail.
upvoted 1 times
...
antthomas
2 years, 1 month ago
Selected Answer: A
All AWS Organizations actions are logged by CloudTrail and are documented in the AWS Organizations API Reference. For example, calls to CreateAccount (including the CreateAccountResult event), ListHandshakesForAccount, CreatePolicy, and InviteAccountToOrganization generate entries in the CloudTrail log files.
upvoted 1 times
...
RicardoD
2 years, 6 months ago
A is the answer
upvoted 1 times
...
jackdryan
2 years, 6 months ago
I'll go with A
upvoted 1 times
...
MFDOOM
2 years, 6 months ago
A. AWS CloudTrail for the federated identity user name
upvoted 1 times
...
nicat
2 years, 6 months ago
A. AWS CloudTrail for the federated identity user name https://aws.amazon.com/blogs/security/how-to-easily-identify-your-federated-users-by-using-aws-cloudtrail/
upvoted 4 times
...
gretch
2 years, 6 months ago
it's A https://aws.amazon.com/blogs/security/how-to-easily-identify-your-federated-users-by-using-aws-cloudtrail/
upvoted 2 times
...
Golddust
2 years, 6 months ago
I would also go with A. CloudTrail https://aws.amazon.com/blogs/security/how-to-easily-identify-your-federated-users-by-using-aws-cloudtrail/
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago