exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 18 discussion

Exam question from Amazon's AWS-SysOps
Question #: 18
Topic #: 1
[All AWS-SysOps Questions]

When assessing an organization s use of AWS API access credentials which of the following three credentials should be evaluated? (Choose three.)

  • A. Key pairs
  • B. Console passwords
  • C. Access keys
  • D. Signing certificates
  • E. Security Group memberships
Show Suggested Answer Hide Answer
Suggested Answer: BCD 🗳️
AWS provides a number of authentication mechanisms including a console, account IDs and secret keys, X.509 certificates, and MFA devices to control access to
AWS APIs. Console authentication is the most appropriate for administrative or manual activities, account IDs and secret keys for accessing REST-based interfaces or tools, and X.509 certificates for SOAP-based interfaces and tools.
Your organization should consider the circumstances under which it will leverage access keys, x.509certificates, console passwords, or MFA devices

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Techhod
Highly Voted 2 years, 7 months ago
Answer is ACD: You use different types of security credentials depending on how you interact with AWS. For example, you use a user name and password to sign in to the AWS Management Console. You use access keys to make programmatic calls to AWS API actions. Key pairs consist of a public key and a private key. You use the private key to create a digital signature, and then AWS uses the corresponding public key to validate the signature. You can create Amazon EC2 key pairs from the Amazon EC2 console, CLI, or API. Access keys consist of an access key ID and a secret access key. You use access keys to sign programmatic requests that you make to AWS if you use the AWS SDKs, REST, or Query APIs. One can use the IAM API to upload a certificate, via the UploadServerCertificate request. Option B and E are wrong because this is done via the Console and not via API’s. For more information on Security, please visit the below URL: http://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html
upvoted 8 times
newbie2019
2 years, 7 months ago
Wrong, key pairs are not used in API access. They are used by EC2 instances and CloudFront *only*. Answer is BCD. https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html#key-pairs
upvoted 8 times
pleasespammelater
2 years, 7 months ago
I agree with Techhod. Using a key during CloudFront API access counts - see https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-creating-signed-url-canned-policy.html Also, C doesn't make sense since by console passwords can only be used for accessing the console, not for using the API. See https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html
upvoted 1 times
...
...
...
th3wolf
Most Recent 9 months ago
CDE are correct. While options A (Key pairs) and B (Console passwords) are also related to AWS access, they are not as directly relevant to API access credentials. Key pairs are more commonly used for SSH access to EC2 instances, and Console passwords are used to access the AWS Management Console. While they are essential for overall security, they are not the primary credentials used for making programmatic API requests, which are the focus of the question. Hence, options C, D, and E are the more relevant credentials to evaluate in the context of AWS API access.
upvoted 1 times
...
xxxdolorxxx
2 years, 5 months ago
At first I thought ABC. Although I'm not sure if console passwords qualifies as API, so I could see why others didn't pick B. But D seems to be more along the lines of SSL. However the exaptation seems to have been taken from somewhere. Usually when the answers are incorrect there is no no explanation or a link that has the actual correct answers. So now I vote ACD.
upvoted 1 times
...
naiduveerendra
2 years, 6 months ago
ACD is the answer
upvoted 1 times
...
RicardoD
2 years, 6 months ago
B|C|D are the answers You wont need key pair or Security group membership
upvoted 1 times
...
waterzhong
2 years, 6 months ago
key pairs are not used in API access. They are used by EC2 instances and CloudFront *only*. Answer is BCD.
upvoted 1 times
...
vudophi
2 years, 6 months ago
Answer is ACD
upvoted 1 times
...
NorthStar2010
2 years, 6 months ago
BCD,, All console call are through API
upvoted 1 times
...
Kilonso
2 years, 6 months ago
Well. I think it should be ABC also
upvoted 2 times
...
nzieno
2 years, 6 months ago
ABC Console password gives you access to AWS API's
upvoted 3 times
...
AWS_Noob
2 years, 6 months ago
BCD They asking to evaluate credentials. So how do you evaluate a key pair credential? AWS provides a number of authentication mechanisms including a console, account IDs and secret keys, X.509 certificates and MFA devices to control access to AWS APIs" Console authentication is the most appropriate for administrative or manual activities, Account IDs and secret keys for accessing REST based interfaces or tools, and X.509 certificates for SOAP based interfaces and tools. Your organization should consider the circumstances under which it will leverage access keys, x.509 certificates, console passwords, or MFA devices. access keys = access key IDs + secret access keys Amazon EC2 uses public–key cryptography to encrypt and decrypt login information. This does not guarantee authentication.
upvoted 4 times
...
awscertified
2 years, 6 months ago
A. Key pairs C. Access keys D. Signing certificates
upvoted 1 times
...
nicat
2 years, 6 months ago
Answer is ACD
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago