Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 109

    A security engineer recently rotated all IAM access keys in an AWS account. The security engineer then configured AWS Config and enabled the following AWS Config managed rules: mfa-enabled-for-iam-console-access, iam-user-mfa-enabled, access-keys-rotated, and iam-user-unused-credentials-check.

    The security engineer notices that all resources are displaying as noncompliant after the IAM GenerateCredentialReport API operation is invoked.

    What could be the reason for the noncompliant status?

    • The IAM credential report was generated within the past 4 hours.

    • The security engineer does not have the GenerateCredentialReport permission.

    • The security engineer does not have the GetCredenlialReport permission.

    • The AWS Config rules have a MaximumExecutionFrequency value of 24 hours.


    シャッフルモード