A company needs automated email alerts when AWS access keys from developer accounts are detected on public code repositories. Which solution will deliver these email notifications?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon EventBridge rule that sends Amazon Simple Notification Service (Amazon SNS) emails for Amazon GuardDuty findings of type UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS..
Why this is the answer
The correct solution leverages Amazon GuardDuty's ability to detect compromised AWS credentials, specifically the UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS finding type, which directly addresses the scenario of access keys appearing on public repositories. An EventBridge rule can then filter for this specific GuardDuty finding and trigger an SNS topic to send email notifications. Incorrect options: Changing the Operations contact email is a passive, manual approach that doesn't provide automated detection or immediate alerts for this specific threat. AWS Health events with a Risk service category are related to AWS service health and potential security risks to the AWS infrastructure, not the exfiltration of customer access keys. Deploying new anomaly detection software is an overly complex and potentially expensive solution when GuardDuty already provides this specific detection natively. While it could theoretically work, it's not the most efficient or AWS-native approach.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed