A software company is conducting a security audit of its three-node Amazon Aurora MySQL DB cluster. Which finding is a security concern that needs to be addressed?
A.
The AWS account root user does not have the minimum privileges required for client applications.
B.
Encryption in transit is not configured for all Aurora native backup processes.
C.
Each Aurora DB cluster node is not in a separate private VPC with restricted access.
D.
The IAM credentials used by the application are not rotated regularly.
I chose D however I believe A is somewhat confusing because root shouldn't be used by the application and it is privilege shouldn't be minimized for application use. Very confusing
Go with D, not A. A is saying root does NOT have the required minimum permissions for the application. Which is fine....if you're not using root for the application, then who cares. Nowhere does it say, "root is being used for application access".
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Pranava_GCP
1 year, 8 months agoclarksu
2 years agombadioum
2 years, 1 month agolollyj
2 years, 5 months agoJeanGat
2 years, 8 months agocloudsunriser
2 years, 8 months agoyxyj
2 years, 8 months agoSonamDhingra
2 years, 8 months agoAdi_M
2 years, 8 months agombar94
2 years, 8 months agoKapello10
1 year, 8 months ago