Amazon SCS-C03 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/scs-c03.html
A security engineer needs to implement a solution to create and control the keys that a company uses for cryptographic operations. The security engineer must create symmetric keys in which the key material is generated and used within a custom key store that is backed by an AWS CloudHSM cluster. The security engineer will use symmetric and asymmetric data key pairs for local use within applications. The security engineer also must audit the use of the keys.
How can the security engineer meet these requirements?
To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use Amazon Athena.
To create the keys, use Amazon S3 and the custom key stores with the CloudHSM cluster. For auditing, use AWS CloudTrail.
To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use Amazon GuardDuty.
To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster. For auditing, use AWS CloudTrail.
implement control keys cryptographic operations makes To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster, For auditing, use AWS CloudTrail, the strongest match, because cryptographic operations symmetric keys key asks for a managed AWS capability and that reduces the need for extra supervisory automation. cryptographic operations symmetric keys key depends on To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster, For auditing, use AWS CloudTrail, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario which keeps the protection aligned with the stated AWS boundary. keys key material generated used is reinforced by A security engineer needs to implement a solution to create and control the keys, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance so administrators can review the configuration without tracing a custom chain.
generated used key store backed also supports To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster, For auditing, use AWS CloudTrail,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior and the design remains easier to govern across the environment. store backed CloudHSM cluster symmetric would be weaker with To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster, For auditing, use Amazon Athena,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere which is important when security controls must be repeatable. cluster symmetric asymmetric data key separates To create the keys, use Amazon S3 and the custom key stores with the CloudHSM cluster, For auditing, use AWS CloudTrail, and To create the keys, use AWS Key Management Service (AWS KMS) and the custom key stores with the CloudHSM cluster, For auditing, use Amazon GuardDuty, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly so the implementation follows the managed service contract instead of a workaround. data key pairs local applications points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads and it avoids mixing detection, storage, deployment, and identity responsibilities.
A company is using AWS Organizations with nested OUs to manage AWS accounts. The company has a custom compliance monitoring service for the accounts. The monitoring service runs as an AWS Lambda function and is invoked by Amazon EventBridge Scheduler.
The company needs to deploy the monitoring service in all existing and future accounts in the organization.
The company must avoid using the organization ' s management account when the management account is not required.
Which solution will meet these requirements?
Create a CloudFormation stack set in the organization ' s management account and manually add new accounts.
Configure a delegated administrator account for AWS CloudFormation. Create a CloudFormation StackSet in the delegated administrator account targeting the organization root with automatic deployment enabled.
Use Systems Manager delegated administration and Automation to deploy the Lambda function and schedule.
Create a Systems Manager Automation runbook in the management account and share it to accounts.
Organizations nested OUs manage compliance makes Configure a delegated administrator account for AWS CloudFormation, Create a CloudFormation StackSet in the delegated administrator account targeting the organization root with automatic deployment enabled, the strongest match, because manage compliance monitoring runs Lambda asks for a managed AWS capability which keeps the protection aligned with the stated AWS boundary. manage compliance monitoring runs Lambda depends on Configure a delegated administrator account for AWS CloudFormation, Create a CloudFormation StackSet in the delegated administrator account targeting the organization root with automatic deployment enabled, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario so administrators can review the configuration without tracing a custom chain. monitoring runs Lambda function invoked is reinforced by A company is using AWS Organizations with nested OUs to manage AWS accounts, The, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance and the design remains easier to govern across the environment.
function invoked EventBridge Scheduler deploy also supports Configure a delegated administrator account for AWS CloudFormation, Create a CloudFormation StackSet in the delegated administrator account targeting the organization root with automatic deployment enabled,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior which is important when security controls must be repeatable. Scheduler deploy monitoring organization avoid would be weaker with Create a CloudFormation stack set in the organization ' s management account and manually add new accounts,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere so the implementation follows the managed service contract instead of a workaround. organization avoid management required requirements separates Use Systems Manager delegated administration and Automation to deploy the Lambda function and schedule, and Create a Systems Manager Automation runbook in the management account and share it to accounts, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly and it avoids mixing detection, storage, deployment, and identity responsibilities. management required requirements delegated administrator points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads while keeping the service responsibility clear for operations teams.
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account.
All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for2 years.No changes or deletions of the logs are allowed.
Which combination of steps will meet these requirements with theLEAST operational overhead? (Select
TWO.)
In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock incompliance modewith a retention period of 2 years. Set the bucket policy to allow the organization' smanagement accountto write to the S3 bucket.
In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock incompliance modewith a retention period of 2 years. Set the bucket policy to allow the organization' smember accountsto write to the S3 bucket.
In the dedicated security account, create an Amazon S3 bucket with an S3 Lifecycle configuration that expires objects after 2 years. Allow member accounts to write to the bucket.
Create anAWS CloudTrail organization trail. Configure logs to be delivered to the Amazon S3 bucket in the dedicated security account.
Turn on AWS CloudTrail in each account and forward logs to the dedicated security account by using AWS Lambda and Amazon Data Firehose.
organization Organizations includes dedicated activity makes In the dedicated security account, create an Amazon S3 bucket, Configure S3 Object Lock incompliance modewith a retention period of 2 years, Set the bucket policy plus Create anAWS CloudTrail organization trail, Configure logs to be delivered to the Amazon S3 bucket in the dedicated security account, the strongest match, because includes dedicated activity member logged asks for a managed AWS capability so administrators can review the configuration without tracing a custom chain. includes dedicated activity member logged depends on In the dedicated security account, create an Amazon S3 bucket, Configure S3 Object Lock incompliance modewith a retention period of 2 years, Set the bucket policy to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario and the design remains easier to govern across the environment. member logged reported dedicated retain is reinforced by A company has AWS accounts in an organization in AWS Organizations, The organization includes, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance which is important when security controls must be repeatable.
dedicated retain activity logs secure also supports Create anAWS CloudTrail organization trail, Configure logs to be delivered to the Amazon S3 bucket in the dedicated security account,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior so the implementation follows the managed service contract instead of a workaround. logs secure storage location dedicated would be weaker with In the dedicated security account, create an Amazon S3 bucket, Configure S3 Object Lock incompliance modewith a retention period of 2 years, Set the bucket policy, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere and it avoids mixing detection, storage, deployment, and identity responsibilities. location dedicated for2 years changes separates In the dedicated security account, create an Amazon S3 bucket with an S3 Lifecycle configuration that expires objects after 2 years, Allow member accounts to write and Turn on AWS CloudTrail in each account and forward logs to the dedicated security account by using AWS Lambda and Amazon Data Firehose, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly while keeping the service responsibility clear for operations teams. years changes deletions logs allowed points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads and that reduces the need for extra supervisory automation.
A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company ' s primary website. The GuardDuty finding received read: UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company
does not operate. The security engineer needs to deny access to the malicious actor.
What is the first step the security engineer should take?
Open the EC2 console and remove any security groups that allow inbound traffic from 0.0.0.0/0.
Install the AWS Systems Manager Agent on the EC2 instance and run an inventory report.
Install the Amazon Inspector agent on the host and run an assessment with the CVE rules package.
Open the IAM console and revoke all IAM sessions that are associated with the instance profile.
received GuardDuty alert indicating finding makes Open the IAM console and revoke all IAM sessions that are associated with the instance profile, the strongest match, because indicating finding involving EC2 instance asks for a managed AWS capability and the design remains easier to govern across the environment. indicating finding involving EC2 instance depends on Open the IAM console and revoke all IAM sessions that are associated with the instance profile, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario which is important when security controls must be repeatable. EC2 instance hosts primary website is reinforced by A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance so the implementation follows the managed service contract instead of a workaround.
primary website GuardDuty finding received also supports Open the IAM console and revoke all IAM sessions that are associated with the instance profile,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior and it avoids mixing detection, storage, deployment, and identity responsibilities. finding received read UnauthorizedAccess IAMUser would be weaker with Open the EC2 console and remove any security groups that allow inbound traffic from 0, 0, 0, 0/0,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere while keeping the service responsibility clear for operations teams. UnauthorizedAccess IAMUser InstanceCredentialExfiltration confirmed malicious separates Install the AWS Systems Manager Agent on the EC2 instance and run an inventory report, and Install the Amazon Inspector agent on the host and run an assessment with the CVE rules package, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly and that reduces the need for extra supervisory automation. confirmed malicious actor used API points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads which keeps the protection aligned with the stated AWS boundary.
A company that builds document management systems recently performed a security review of its application on AWS. The review showed that uploads of documents through signed URLs into Amazon S3 could occur in the application without encryption in transit. A security engineer must implement a solution that prevents uploads that are not encrypted in transit.
Which solution will meet this requirement?
Ensure that all client implementations are using HTTPS to upload documents into the application.
Configure the s3-bucket-ssl-requests-only managed rule in AWS Config.
Add an S3 bucket policy that denies all S3 actions for condition "aws:SecureTransport": "false".
Add an S3 bucket ACL with a grantee of AllUsers, a permission of WRITE, and a condition of secureTransport.
builds document management systems recently makes Add an S3 bucket policy that denies all S3 actions for condition "aws, SecureTransport", "false", the strongest match, because systems recently performed review application asks for a managed AWS capability which is important when security controls must be repeatable. systems recently performed review application depends on Add an S3 bucket policy that denies all S3 actions for condition "aws, SecureTransport", "false", to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario so the implementation follows the managed service contract instead of a workaround. review application showed uploads documents is reinforced by A company that builds document management systems recently performed a security review of its, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance and it avoids mixing detection, storage, deployment, and identity responsibilities.
showed uploads documents through signed also supports Add an S3 bucket policy that denies all S3 actions for condition "aws, SecureTransport", "false",, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior while keeping the service responsibility clear for operations teams. through signed URLs could occur would be weaker with Ensure that all client implementations are using HTTPS to upload documents into the application,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere and that reduces the need for extra supervisory automation. could occur application without encryption separates Configure the s3-bucket-ssl-requests-only managed rule in AWS Config, and Add an S3 bucket ACL with a grantee of AllUsers, a permission of WRITE, and a condition of secureTransport, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly which keeps the protection aligned with the stated AWS boundary. without encryption transit implement prevents points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads so administrators can review the configuration without tracing a custom chain.
A company's security team needs to receive a notification whenever an AWS access key has not been rotated in 90 or more days. A security engineer must develop a solution that provides these notifications automatically.
Which solution will meet these requirements with the LEAST amount of effort?
Deploy an AWS Config managed rule to run on a periodic basis of 24 hours. Select the access-keys-rotated managed rule, and set the maxAccessKeyAge parameter to 90 days. Create an Amazon EventBridge rule with an event pattern that matches the compliance type of NON_COMPLIANT from AWS Config for the managed rule. Configure EventBridge to send an Amazon SNS notification to the security team.
Create a script to export a.csv file from the AWS Trusted Advisor check for IAM access key rotation.
Load the script into an AWS Lambda function that will upload the.csv file to an Amazon S3 bucket. Create an Amazon Athena table query that runs when the.csv file is uploaded to the S3 bucket. Publish the results for any keys older than 90 days by using an invocation of an Amazon SNS notification to the security team.
Create a script to download the IAM credentials report on a periodic basis. Load the script into an AWS Lambda function that will run on a schedule through Amazon EventBridge. Configure the Lambda script to load the report into memory and to filter the report for records in which the key was last rotated at least 90 days ago. If any records are detected, send an Amazon SNS notification to the security team.
Create an AWS Lambda function that queries the IAM API to list all the users. Iterate through the users by using the ListAccessKeys operation. Verify that the value in the CreateDate field is not at least 90 days old. Send an SNS notification to the security team if the value is at least 90 days old. Create an EventBridge rule to schedule the Lambda function to run each day.
team receive notification whenever access makes Deploy an AWS Config managed rule to run on a periodic basis of 24 hours, Select the access-keys-rotated managed rule, and set the maxAccessKeyAge parameter to the strongest match, because whenever access key been rotated asks for a managed AWS capability so the implementation follows the managed service contract instead of a workaround. whenever access key been rotated depends on Deploy an AWS Config managed rule to run on a periodic basis of 24 hours, Select the access-keys-rotated managed rule, and set the maxAccessKeyAge parameter to to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario and it avoids mixing detection, storage, deployment, and identity responsibilities. been rotated more days develop is reinforced by A company's security team needs to receive a notification whenever an AWS access key, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance while keeping the service responsibility clear for operations teams.
days develop provides notifications automatically also supports Deploy an AWS Config managed rule to run on a periodic basis of 24 hours, Select the access-keys-rotated managed rule, and set the maxAccessKeyAge parameter to, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior and that reduces the need for extra supervisory automation. notifications automatically requirements amount effort would be weaker with Create a script to export a, csv file from the AWS Trusted Advisor check for IAM access key rotation, Load the script into an AWS Lambda, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere which keeps the protection aligned with the stated AWS boundary. amount effort Deploy Config managed separates Create a script to download the IAM credentials report on a periodic basis, Load the script into an AWS Lambda function that will run on a and Create an AWS Lambda function that queries the IAM API to list all the users, Iterate through the users by using the ListAccessKeys operation, Verify that from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly so administrators can review the configuration without tracing a custom chain. Config managed rule run periodic points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads and the design remains easier to govern across the environment.
A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon EKS) clusters. The solution must require no additional configuration of the existing EKS deployment.
Which solution will meet these requirements with the LEAST operational effort?
Install a third-party security add-on.
Enable AWS Security Hub and monitor Kubernetes findings.
Monitor CloudWatch Container Insights metrics for EKS.
Enable Amazon GuardDuty and use EKS Audit Log Monitoring.
detect unauthenticated access Elastic Kubernetes makes Enable Amazon GuardDuty and use EKS Audit Log Monitoring, the strongest match, because Elastic Kubernetes EKS clusters require asks for a managed AWS capability and it avoids mixing detection, storage, deployment, and identity responsibilities. Elastic Kubernetes EKS clusters require depends on Enable Amazon GuardDuty and use EKS Audit Log Monitoring, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario while keeping the service responsibility clear for operations teams. clusters require additional configuration EKS is reinforced by A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance and that reduces the need for extra supervisory automation.
configuration EKS deployment requirements operational also supports Enable Amazon GuardDuty and use EKS Audit Log Monitoring,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior which keeps the protection aligned with the stated AWS boundary. requirements operational effort Enable GuardDuty would be weaker with Install a third-party security add-on,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere so administrators can review the configuration without tracing a custom chain. Enable GuardDuty EKS Audit Log separates Enable AWS Security Hub and monitor Kubernetes findings, and Monitor CloudWatch Container Insights metrics for EKS, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly and the design remains easier to govern across the environment. Audit Log Monitoring Install third points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads which is important when security controls must be repeatable.
AWS Config cannot deliver configuration snapshots to Amazon S3.
Which TWO actions will remediate this issue?
Verify the S3 bucket policy allows config.amazonaws.com.
Verify the IAM role has s3:GetBucketAcl and s3:PutObject permissions.
Verify the S3 bucket can assume the IAM role.
Verify IAM policy allows AWS Config to write logs.
Modify AWS Config API permissions.
Config cannot deliver configuration snapshots makes Verify the S3 bucket policy allows config, amazonaws, com, plus Verify the IAM role has s3, GetBucketAcl and s3, PutObject permissions, the strongest match, because configuration snapshots actions remediate issue asks for a managed AWS capability while keeping the service responsibility clear for operations teams. configuration snapshots actions remediate issue depends on Verify the S3 bucket policy allows config, amazonaws, com, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario and that reduces the need for extra supervisory automation. remediate issue Verify bucket policy is reinforced by AWS Config cannot deliver configuration snapshots to Amazon S3, Which TWO actions will remediate, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance which keeps the protection aligned with the stated AWS boundary.
bucket policy allows config amazonaws also supports Verify the IAM role has s3, GetBucketAcl and s3, PutObject permissions,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior so administrators can review the configuration without tracing a custom chain. config amazonaws com Verify IAM would be weaker with Verify the S3 bucket can assume the IAM role,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere and the design remains easier to govern across the environment. Verify IAM role GetBucketAcl PutObject separates Verify IAM policy allows AWS Config to write logs, and Modify AWS Config API permissions, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly which is important when security controls must be repeatable. GetBucketAcl PutObject permissions Verify bucket points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads so the implementation follows the managed service contract instead of a workaround.
A company runs its microservices architecture in Kubernetes containers on AWS by using Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Aurora. The company has an organization in AWS Organizations to manage hundreds of AWS accounts that host different microservices.
The company needs to implement a monitoring solution for logs from all AWS resources across all accounts. The solution must include automatic detection of security-related issues.
Which solution will meet these requirements with theLEAST operational effort?
Designate an Amazon GuardDuty administrator account in the organization's management account.
Enable GuardDuty for all accounts. Enable EKS Protection and RDS Protection in the GuardDuty administrator account.
Designate a monitoring account. Share Amazon CloudWatch Logs from all accounts. Use Amazon Inspector to evaluate the logs.
Centralize CloudTrail logs in Amazon S3 and analyze them with Amazon Athena.
Stream CloudWatch Logs to Amazon Kinesis and analyze them with custom AWS Lambda functions.
runs microservices architecture Kubernetes containers makes Designate an Amazon GuardDuty administrator account in the organization's management account, Enable GuardDuty for all accounts, Enable EKS Protection and RDS Protection in the GuardDuty administrator the strongest match, because Kubernetes containers Elastic EKS Aurora asks for a managed AWS capability and that reduces the need for extra supervisory automation. Kubernetes containers Elastic EKS Aurora depends on Designate an Amazon GuardDuty administrator account in the organization's management account, Enable GuardDuty for all accounts, Enable EKS Protection and RDS Protection in the GuardDuty administrator to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario which keeps the protection aligned with the stated AWS boundary. Kubernetes EKS Aurora organization Organizations is reinforced by A company runs its microservices architecture in Kubernetes containers on AWS by using Amazon, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance so administrators can review the configuration without tracing a custom chain.
organization Organizations manage hundreds host also supports Designate an Amazon GuardDuty administrator account in the organization's management account, Enable GuardDuty for all accounts, Enable EKS Protection and RDS Protection in the GuardDuty administrator, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior and the design remains easier to govern across the environment. hundreds host different microservices implement would be weaker with Designate a monitoring account, Share Amazon CloudWatch Logs from all accounts, Use Amazon Inspector to evaluate the logs,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere which is important when security controls must be repeatable. microservices implement monitoring logs resources separates Centralize CloudTrail logs in Amazon S3 and analyze them with Amazon Athena, and Stream CloudWatch Logs to Amazon Kinesis and analyze them with custom AWS Lambda functions, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly so the implementation follows the managed service contract instead of a workaround. logs resources include automatic detection points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads and it avoids mixing detection, storage, deployment, and identity responsibilities.
A company detects bot activity targeting Amazon Cognito user pool endpoints. The solution must block malicious requests while maintaining access for legitimate users.
Which solution meets these requirements?
Enable Amazon Cognito threat protection.
Restrict access to authenticated users only.
Associate AWS WAF with the Cognito user pool.
Monitor requests with CloudWatch.
detects bot activity targeting Cognito makes Enable Amazon Cognito threat protection, the strongest match, because targeting Cognito user pool endpoints asks for a managed AWS capability which keeps the protection aligned with the stated AWS boundary. targeting Cognito user pool endpoints depends on Enable Amazon Cognito threat protection, to place the control at the same account, resource, identity, key, log, network, or assessment boundary named by the scenario so administrators can review the configuration without tracing a custom chain. pool endpoints block malicious requests is reinforced by A company detects bot activity targeting Amazon Cognito user pool endpoints, The solution must, because that wording favors direct service configuration over scripts, forwarding jobs, manual reviews, or account-by-account maintenance and the design remains easier to govern across the environment.
malicious requests while maintaining access also supports Enable Amazon Cognito threat protection,, since the service keeps policy evaluation, collection, encryption, deployment, or access analysis inside the AWS plane that owns the behavior which is important when security controls must be repeatable. maintaining access legitimate users requirements would be weaker with Restrict access to authenticated users only,, because that alternative addresses a neighboring activity while the main security action still has to be solved elsewhere so the implementation follows the managed service contract instead of a workaround. users requirements Enable Cognito threat separates Associate AWS WAF with the Cognito user pool, and Monitor requests with CloudWatch, from the requested outcome, since those choices can help a wider architecture without satisfying the complete constraint directly and it avoids mixing detection, storage, deployment, and identity responsibilities. Cognito threat protection Restrict access points to a design with clearer responsibility, cleaner operations, and better reviewability for a security team managing AWS workloads while keeping the service responsibility clear for operations teams.
Showing 10 of 257 questions · Unlock the full set