Soru

Zorluk: KolayIdentity and Access Management (IAM)

A solutions architect is configuring baseline security controls for a new AWS account. The company wants to secure administrative access and protect resources in accordance with AWS Identity and Access Management (IAM) best practices. Which of the following security practices should the solutions architect implement? (Select TWO.)

  1. Enable Multi-Factor Authentication (MFA) for the AWS account root user and all administrative identities.Cevap
  2. Apply the principle of least privilege by granting only the minimum permissions necessary to perform a task.Cevap
  3. C
    Use the AWS account root user access keys for daily administrative tasks to avoid authorization issues.
  4. D
    Create individual IAM users with long-term passwords for corporate directory users who need AWS Console access.
  5. E
    Store sensitive database credentials as plaintext parameters in Systems Manager Parameter Store to simplify configuration.

Cevap

Enable Multi-Factor Authentication (MFA) for the AWS account root user and all administrative identities, and apply the principle of least privilege by granting only the minimum permissions necessary to perform a task.
The correct practices are to enable Multi-Factor Authentication (MFA) on the root user and administrative accounts to prevent unauthorized access, and to apply the principle of least privilege so that users only have the permissions necessary to do their job.

Adım Adım Çözüm

1
Analyze administrative account security.
Identify that the root user and other administrative accounts represent high-privilege entry points requiring MFA.
MFA adds an extra layer of protection beyond a standard password, which is essential for administrative credentials.
2
Analyze standard credential management guidelines.
Confirm that permission policies should follow the least privilege model, while avoiding root credentials and individual IAM users for federated employees.
Applying least privilege limits security exposure, while using identity federation avoids creating unnecessary long-term IAM credentials.

Anahtar Kavram

AWS Identity and Access Management (IAM) Best Practices
Bu soruyu puanla