Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified CloudOps Engineer - Associate SOA-C03 Question # 19 Topic 2 Discussion

Amazon Web Services AWS Certified CloudOps Engineer - Associate SOA-C03 Question # 19 Topic 2 Discussion

SOA-C03 Exam Topic 2 Question 19 Discussion:
Question #: 19
Topic #: 2

A CloudOps engineer must manage the security of an AWS account. Recently, an IAM user’s access key was mistakenly uploaded to a public code repository. The engineer must identify everything that was changed using this compromised key.

How should the CloudOps engineer meet these requirements?


A.

Create an Amazon EventBridge rule to send all IAM events to an AWS Lambda function for analysis.


B.

Query Amazon EC2 logs by using Amazon CloudWatch Logs Insights for all events initiated with the compromised access key within the suspected timeframe.


C.

Search AWS CloudTrail event history for all events initiated with the compromised access key within the suspected timeframe.


D.

Search VPC Flow Logs for all events initiated with the compromised access key within the suspected timeframe.


Get Premium SOA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.