Soru

Zorluk: OrtaIdentity and Access Management (IAM)

A retail company is auditing its AWS account to align with AWS Identity and Access Management (IAM) security best practices. Currently, developers use shared credentials for daily administrative tasks, and multi-factor authentication (MFA) is not enabled on the account. Which of the following actions should the company perform to secure their environment? (Select TWO.)

  1. Enable multi-factor authentication (MFA) on the AWS account root user and restrict its use to only specific tasks that require root credentials.Cevap
  2. Configure AWS IAM Identity Center to delegate daily administrative access to developers using temporary security credentials.Cevap
  3. C
    Generate a single set of access keys for the AWS account root user and distribute them to developers for daily command line access.
  4. D
    Create permanent access keys for individual IAM roles and assign them to developers for access to the AWS Management Console.
  5. E
    Request that AWS Support manage and rotate the SSH keys used by developers to log into Amazon EC2 instances.

Cevap

To secure the AWS environment, the company should enable multi-factor authentication (MFA) on the AWS account root user and restrict its use, and configure AWS IAM Identity Center to delegate daily administrative access using temporary credentials.
The correct actions are to enable multi-factor authentication (MFA) on the root user to secure the account, and to set up AWS IAM Identity Center to manage developer access. This ensures that developers use temporary, unique credentials for daily operations instead of sharing permanent administrative access.

Adım Adım Çözüm

1
Identify root user credentials security requirements.
Determine that the root user should have MFA enabled and must not be used for daily operations.
Root user credentials have complete administrative access across the entire account and represent a high security risk if compromised.
2
Analyze credential management for daily developer operations.
Determine that developers should use temporary credentials managed via AWS IAM Identity Center rather than permanent or shared keys.
Using temporary credentials minimizes the risk of credential leakage and aligns with the principle of least privilege.

Anahtar Kavram

Implementing IAM best practices including securing the root account with MFA and utilizing temporary credentials via identity federation or IAM Identity Center.
Tahmini Süre:1m 0s
Bu soruyu puanla