Topic 1 Question 157
A company uses an organization in AWS Organizations to manage hundreds of AWS accounts. Some of the accounts provide access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies.
The company needs to identify which external principals have access to which accounts.
Which solution will provide this information?
Enable AWS Identity and Access Management Access Analyzer for the organization. Configure the organization as a zone of trust. Filter findings by AWS account ID.
Create a custom AWS Config rule to monitor IAM roles in each account. Deploy an AWS Config aggregator to a central account. Filter findings by AWS account ID.
Activate Amazon Inspector. Integrate Amazon Inspector with AWS Security Hub. Filter findings by AWS account ID for the IAM role resource type and the S3 bucket policy resource type.
Configure the organization to use Amazon GuardDuty. Filter findings by AWS account ID for the Discovery:IAMUser/AnomalousBehavior finding type.
ユーザの投票
コメント(4)
- 正解だと思う選択肢: A
AWS IAM Access Analyzer is a least privilege service that allows central review and removal of unused and external access across your AWS accounts with continuous monitoring. Reference: https://aws.amazon.com/iam/access-analyzer/
👍 3jade2902024/06/02 Option A is the most appropriate solution for identifying external principals' access to AWS accounts within an organization.
👍 2mehmetsungur2024/05/16- 正解だと思う選択肢: A
A is correct
👍 2fibonacciname2024/05/23
シャッフルモード