An engineer accidentally committed an AWS access key and secret access key to a public GitHub repository for the company’s open-source project. The manager promptly disabled the key. The company must assess the impact of the exposure with the least management overhead. What should a security engineer do?
Choose an answer
Tap an option to check your answer.
Correct answer: Review the AWS Identity and Access Management (IAM) credential report to see when the access key was last used..
Why this is the answer
The IAM credential report provides a comprehensive list of all users and their credential status, including the last time an access key was used. This report is directly accessible and offers a clear, consolidated view of credential activity, making it the most efficient way to assess when the exposed key was last active. Reviewing AWS Trusted Advisor's IAM use report is less direct for this specific task; while it offers recommendations, it doesn't provide the granular "last used" timestamp for individual access keys as clearly as the credential report. Searching CloudWatch Logs would be overly complex and time-consuming, requiring specific log group knowledge and filtering, and might not even contain all relevant API calls. VPC flow logs record network traffic, not API calls or access key usage, making them irrelevant for this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed