A company uses SAML federation for access to AWS accounts. An isolated workload account runs immutable Amazon EC2 infrastructure with no routine human access. The company requires a "break-glass" capability to access the workload account and EC2 instances if SAML fails. An audit found that the workload account does not have this capability. The company must implement break-glass access, log all activity, and notify the security team. Which combination of solutions will meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a local IAM break-glass user in the workload account for the security team. Create an AWS CloudTrail trail with delivery to Amazon CloudWatch Logs. Use Amazon EventBridge to monitor activity by local users., Enable AWS Systems Manager Session Manager for Amazon EC2. Configure an AWS CloudTrail filter for Session Manager activity and send results to an Amazon Simple Notification Service (Amazon SNS) topic..
Why this is the answer
Creating a local IAM break-glass user provides a direct, independent access path to the AWS account, bypassing SAML. CloudTrail with CloudWatch Logs ensures all activity is logged, and EventBridge can then monitor for actions by this local user, notifying the security team. This meets the requirements for break-glass, logging, and notification. Enabling AWS Systems Manager Session Manager allows secure, auditable access to EC2 instances without opening inbound ports or managing SSH keys, which is crucial for immutable infrastructure. Configuring a CloudTrail filter for Session Manager activity and sending results to an SNS topic ensures that all break-glass access to instances is logged and the security team is immediately notified. The other options are incorrect because: Creating a break-glass EC2 key pair doesn't provide account-level access and managing keys can be problematic. Creating a break-glass IAM role with AssumeRoleWithSAML still relies on SAML, defeating the purpose of a break-glass if SAML fails. Creating local OS-level users and unrestricted security groups introduces significant security risks and doesn't provide account-level access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed