exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 284 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 284
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company's security team suspects that an insider threat is present. The security team is basing its suspicion on activity that occurred in one of the company's
AWS accounts. The activity was performed with the AWS account root user credentials. The root user has no access keys. The company uses AWS
Organizations, and the account where the activity occurred is in an OU.
A security engineer needs to take away the root user's ability to make any updates to the account. The root user password cannot be changed to accomplish this goal.
Which solution will meet these requirements?

  • A. Attach the following SCP to the account:
  • B. Attach the following SCP to the account:
  • C. Attach the following SCP to the account:
  • D. Attach the following inline IAM policy to the root user:
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Toptip
1 year, 11 months ago
Selected Answer: B
B is correct C is wrong because "Principal" is not supported in SCP syntax
upvoted 1 times
...
ITGURU51
2 years ago
The company is using AWS organizations and the threat activity happened in a specific OU. Therefore we know that D can safely be eliminated for the equation. We need a service control policy applied to the OU. Answer B provides a working solution when all the other options are taken into consideration. The SCP does not support Principal statements. In addition, the syntax to specific the root user is incorrect in answer A. (B)
upvoted 1 times
ITGURU51
2 years ago
The syntax to specify the root user is incorrect.
upvoted 1 times
...
...
Smartphone
2 years, 3 months ago
B is the correct answer.
upvoted 3 times
...
sakibmas
2 years, 4 months ago
Selected Answer: B
SCP does not support Principal
upvoted 4 times
...
jishrajesh
2 years, 4 months ago
Selected B
upvoted 1 times
...
madcloud
2 years, 7 months ago
B works, but i am not sure why D does not ? inline policy for the root user would be very specific to deny root user access. what is missing ?
upvoted 1 times
...
bobby_kl
2 years, 8 months ago
Selected Answer: B
B - correct no Principal in SCP
upvoted 2 times
...
sapien45
2 years, 8 months ago
no Principal in SCP PrincipalArn would do the trick
upvoted 1 times
...
MungKey
2 years, 8 months ago
A - Not correct - "arn:aws:root"? B - Correct - Denies all activites by all root accounts C - Not correct - Principal is not supported by SCPs D - Not correct - Denies everyone
upvoted 2 times
...
vbal
2 years, 8 months ago
B is correct way.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago