exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 467 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 467
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security engineer for a company wants to maintain all IAM users and roles according to the principle of least privilege. The security engineer plans to audit the IAM permissions once every 365 days. The security engineer must view the permissions that each IAM identity used in the last 365 days and must remove any unused permissions.

Which solution will meet these requirements?

  • A. Use AWS CloudTrail logs to review IAM identity actions and to remove unused permissions.
  • B. Use AWS Config to review configuration changes by each IAM identity and to remove unused permissions.
  • C. Use AWS Identity and Access Management Access Analyzer to review last accessed information and to remove unused permissions.
  • D. Use AWS Trusted Advisor to check the IAM identities that have elevated permissions and to remove unused permissions.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cherry23
1 year, 9 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
jennyka76
2 years, 2 months ago
ANSWER - C https://aws.amazon.com/iam/features/analyze-access/
upvoted 2 times
...
cmctssg
2 years, 3 months ago
Selected Answer: C
C is the best solution. D is also incorrect because AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance. It does not provide information about last accessed permissions or unused permissions
upvoted 2 times
...
cmctssg
2 years, 3 months ago
D is also incorrect because AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance. It does not provide information about last accessed permissions or unused permissions
upvoted 1 times
...
PatrickLi
2 years, 3 months ago
Selected Answer: C
Answer is C
upvoted 2 times
...
sam15
2 years, 3 months ago
https://aws.amazon.com/blogs/security/iam-access-analyzer-makes-it-simpler-to-author-and-validate-role-trust-policies/
upvoted 2 times
...
silvian08
2 years, 3 months ago
Selected Answer: D
IAM provides last accessed information to help you identify unused permissions so that you can remove them. You can use last accessed information to refine your policies and allow access to only the services and actions that your entities use. https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html
upvoted 2 times
PatrickLi
2 years, 3 months ago
But you are referring to answer C? It has nothing to do with trusted advisor.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...