Question 19 of 19
Single answerA security engineer for a company needs to design an incident response plan that addresses compromised IAM user account credentials.The company uses an organization in AWS Organizations and AWS IAM Identify Center to manage user access. The company uses a delegated administrator account to implement AWS Security Hub. Amazon S3 bucket.The company has also configured an organizational event data store that captures all events from the trail, The incident response plan must provide steps that the security engineer can take to immediately dlisable any compromised IAM user when the security engineer receives a notification of a security incident. actions that the compromised IAM user performed across all accounts in the previous 7 days. Which solution will meet these requirements?
BRemove all IAM policies that are attached to the IAM user in the organization management account. Use Security Hub to query the CloudTrail logs for actions that the IAM user performed in the previous 7 days.
CRemove any permission sets that arc assigned to the IAM user in IAM Identity Center. Use Amazon CloudWatch Logs Insights to directly query the organizational CloudTrail logs in the S3 bucket for actions that the IAM user performed m the previous 7 days.
✓DDisable the IAM user's access in IAM Identity Center. Use CloudTrail to query the organizational event data store for actions that the IAM user performed in the previous 7 days.
✓
Correct Answer: D
Disable the IAM user's access in IAM Identity Center. Use CloudTrail to query the organizational event data store for actions that the IAM user performed in the previous 7 days.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of AWS certification topics.