New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

SCS-C01 Exam Results

Page: 33 / 44
Total 589 questions

AWS Certified Security - Specialty Questions and Answers

Question 129

An organization has setup multiple IAM users. The organization wants that each IAM user accesses the IAM console only within the organization and not from outside. How can it achieve this?

Please select:

Options:

A.

Create an IAM policy with the security group and use that security group for IAM console login

B.

Create an IAM policy with a condition which denies access when the IP address range is not from the organization

C.

Configure the EC2 instance security group which allows traffic only from the organization's IP range

D.

Create an IAM policy with VPC and allow a secure gateway between the organization and IAM Console

Question 130

You have a set of Customer keys created using the IAM KMS service. These keys have been used for around 6 months. You are now trying to use the new KMS features for the existing set of key's but are not able to do so. What could be the reason for this.

Please select:

Options:

A.

You have not explicitly given access via the key policy

B.

You have not explicitly given access via the IAM policy

C.

You have not given access via the IAM roles

D.

You have not explicitly given access via IAM users

Question 131

An auditor needs access to logs that record all API events on IAM. The auditor only needs read-only access to the log files and does not need access to each IAM account. The company has multiple IAM accounts, and the auditor needs access to all the logs for all the accounts. What is the best way to configure access for the auditor to view event logs from all accounts? Choose the correct answer from the options below

Please select:

Options:

A.

Configure the CloudTrail service in each IAM account, and have the logs delivered to an IAM bucket on each account, while granting the auditor permissions to the bucket via roles in the secondary accounts and a single primary IAM account that can assume a read-only role in the secondary IAM accounts.

B.

Configure the CloudTrail service in the primary IAM account and configure consolidated billing for all the secondary accounts. Then grant the auditor access to the S3 bucket that receives the CloudTrail log files.

C.

Configure the CloudTrail service in each IAM account and enable consolidated logging inside of CloudTrail.

D.

Configure the CloudTrail service in each IAM account and have the logs delivered to a single IAM bucket in the primary account and erant the auditor access to that single bucket in the orimarv account.

Question 132

While analyzing a company's security solution, a Security Engineer wants to secure the IAM account root user.

What should the Security Engineer do to provide the highest level of security for the account?

Options:

A.

Create a new IAM user that has administrator permissions in the IAM account. Delete the password for the IAM account root user.

B.

Create a new IAM user that has administrator permissions in the IAM account. Modify the permissions for the existing IAM users.

C.

Replace the access key for the IAM account root user. Delete the password for the IAM account root user.

D.

Create a new IAM user that has administrator permissions in the IAM account. Enable multi-factor authentication for the IAM account root user.

Page: 33 / 44
Total 589 questions