CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 14: AWS Certified Security - Specialty SCS-C03(New)

A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company’s primary website. The GuardDuty finding received read:UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. The security engineer confirmed that a malicious actor used API access k…

Nội dung câu hỏi

A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company’s primary website. The GuardDuty finding received read:UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company does not operate. The security engineer needs to deny access to the malicious actor. What is the first step the security engineer should take?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Open the EC2 console and remove any security groups that allow inbound traffic from 0.0.0.0/0.
  2. B. Install the AWS Systems Manager Agent on the EC2 instance and run an inventory report.
  3. C. Install the Amazon Inspector agent on the host and run an assessment with the CVE rules package.
  4. D. Open the IAM console and revoke all IAM sessions that are associated with the instance profile. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề