A development team released an open source toolset for a SaaS application, hosted in a public source code repository. The company discovered that the repository contains an IAM access key and secret key that grant access to internal AWS resources. A security engineer must determine whether the exposed credentials have been misused and prevent any further use. Which combination of actions will meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Identity and Access Management (IAM) Access Analyzer to identify which resources the exposed credentials accessed and who used them., Deactivate the exposed IAM access key for the affected IAM user..
Why this is the answer
Deactivating the exposed IAM access key immediately prevents any further unauthorized use, fulfilling the requirement to stop further use. Using IAM Access Analyzer helps identify the resources the exposed credentials could access and, combined with CloudTrail logs, can determine if and how they were misused. This addresses the requirement to determine misuse. Creating a custom GuardDuty rule is not directly applicable to blocking specific access keys; GuardDuty focuses on threat detection. Creating a new access key doesn't address the immediate threat of the exposed key. Generating an IAM credential report shows sign-in activity, but not necessarily API calls made by an access key, nor does it stop ongoing misuse.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed