exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 247 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 247
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security engineer is defining the controls required to protect the AWS account root user credentials in an AWS Organizations hierarchy. The controls should also limit the impact in case these credentials have been compromised.
Which combination of controls should the security engineer propose? (Choose three.)

  • A. Apply the following SCP:
  • B. Apply the following SCP:
  • C. Enable multi-factor authentication (MFA) for the root user.
  • D. Set a strong randomized password and store it in a secure location.
  • E. Create an access key ID and secret access key, and store them in a secure location.
  • F. Apply the following permissions boundary to the root user:
Show Suggested Answer Hide Answer
Suggested Answer: ACD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ashmek
Highly Voted 2 years, 9 months ago
The following elements aren't supported in SCPs: Principal NotPrincipal NotResource https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_syntax.html
upvoted 6 times
...
Raphaello
Most Recent 1 year, 4 months ago
Selected Answer: ACD
ACD are the correct answers. Remember, "Principal", "NotPrincipal", and "NotResource" elements are not used in SCP.
upvoted 2 times
Raphaello
1 year, 4 months ago
Laughable wording here.. "The controls should also limit the impact in case these credentials have been compromised." One option (A) limits the impact in case of root credentials being compromised. C & D do not limit impact, but in fact they limit risks of root credentials being compromised on first place. Still ACD best answers, despite they don't have the same purpose.
upvoted 1 times
...
...
yorkicurke
1 year, 6 months ago
Selected Answer: ACD
these are exactly the same questions; so you can combine the comments and see for yourself; https://www.examtopics.com/discussions/amazon/view/51540-exam-aws-certified-security-specialty-topic-1-question-247/ https://www.examtopics.com/discussions/amazon/view/78660-exam-aws-certified-security-specialty-topic-1-question-247/
upvoted 1 times
...
Joe27
2 years, 8 months ago
Selected Answer: ACD
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_general.html#example-scp-root-user
upvoted 3 times
...
samecon
2 years, 10 months ago
Selected Answer: ACD
I will choose MFA
upvoted 1 times
MWinter
2 years, 9 months ago
what's the difference between A and B?
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...