QuestionQ30

Incident Response

A company security engineer must create an incident response plan for compromised IAM user account credentials. The company uses an organization in AWS Organizations and AWS IAM Identity Center to manage user access. A delegated administrator account is used to implement AWS Security Hub. That delegated administrator account has an organizational AWS CloudTrail trail that logs every event to an Amazon S3 bucket. The company has also configured an organizational event data store that captures all events from the trail.

The incident response plan must include steps the security engineer can take to immediately disable any compromised IAM user upon receiving a security-incident notification.

The plan must prevent use of the IAM user in every AWS account. It also must collect all AWS actions the compromised IAM user performed across all accounts during the preceding 7 days.

Which solution meets these requirements?

Explanation

Disabling a user in IAM Identity Center centrally prevents that user from signing in to the AWS access portal and accessing assigned AWS accounts and applications. An organizational CloudTrail event data store captures organization-wide trail events and can be queried directly for activity within the preceding seven days. Disabling or changing an IAM user in only the management account would not affect identities in other accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!