QuestionQ49

Incident Response

A development team is building an open-source toolset to manage a company's software-as-a-service (SaaS) application. The company keeps the code in a public repository so that anyone can view and download the toolset code.

The company discovers that the code includes an IAM access key and secret key that allow access to internal resources in the company’s AWS environment.

A security engineer must implement a solution to determine whether the exposed credentials have been used without authorization. The solution must also prevent any further use of the exposed credentials.

Which combination of steps meets these requirements?

Choose two
Explanation

Deactivating the exposed IAM access key prevents it from being used for further API calls. An IAM credential report provides access-key last-used date, Region, and service data, along with IAM user credential status information, which can be used to investigate whether the credential activity aligns with the owning user. IAM Access Analyzer does not audit a particular key’s use or identify the actor behind it, and creating replacement credentials does not disable the compromised key.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!