exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 172 discussion

In IAM, which of the following is true of temporary security credentials?

  • A. Once you issue temporary security credentials, they cannot be revoked.
  • B. None of these are correct.
  • C. Once you issue temporary security credentials, they can be revoked only when the virtual MFA device is used.
  • D. Once you issue temporary security credentials, they can be revoked.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Temporary credentials in IAM are valid throughout their defined duration of time and hence can't be revoked. However, because permissions are evaluated each time an AWS request is made using the credentials, you can achieve the effect of revoking the credentials by changing the permissions for the credentials even after they have been issued.
Reference:
http://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_disable-perms.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ExtHo
Highly Voted 3 years, 7 months ago
Answer is A Here https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_disable-perms.html clearly mentioned Temporary security credentials are valid until they expire, and they cannot be revoked but you can achieve the effect of revoking the credentials by changing the permissions for the credentials even after they have been issued its alternative way only.
upvoted 10 times
01037
3 years, 6 months ago
Thank you
upvoted 1 times
...
bamjive06
3 years, 6 months ago
Thanks
upvoted 1 times
...
...
amministrazione
Most Recent 8 months, 1 week ago
A. Once you issue temporary security credentials, they cannot be revoked.
upvoted 1 times
...
hilft
2 years, 9 months ago
A. You cannot revoke the temporary security credentials. There is a section in Adrian Cantrill's course on how to deal with when a malicious user receives temporary credentials.
upvoted 1 times
...
TechIsi
2 years, 12 months ago
D is correct, all users of the role are impacted https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html
upvoted 1 times
...
pcops
3 years, 4 months ago
Temporary security credentials are valid until they expire, and they cannot be revoked.
upvoted 1 times
...
robertomartinez
3 years, 6 months ago
the problem is that the question is not precise enough, like many other question. theoratically it's yes you can revoke, but you're gonna reset ALL sessions associated with the role. These old questions are really terrible (multiple interpretations, knowing limits and instance capabilities by heart...), I hope the recent questions are better as I don't see how answering these kinfd of question make you a good architect
upvoted 1 times
robertomartinez
3 years, 6 months ago
even the chosen quote text in the answer says "A, ...but also D".
upvoted 1 times
...
...
rain_wu
3 years, 6 months ago
Answer is D
upvoted 1 times
...
pt8
3 years, 6 months ago
It's D. See how 'To immediately deny all permissions to any current user of role credentials' https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html
upvoted 1 times
...
cpal012
3 years, 7 months ago
D is correct. You can revoke them for a role but it affects all users and they will need to reauthenticate
upvoted 1 times
...
ramikhreim
3 years, 7 months ago
Temporary security credentials are valid until they expire, and they cannot be revoked. However, because permissions are evaluated each time an AWS request is made using the credentials, you can achieve the effect of revoking the credentials by changing the permissions for the credentials even after they have been issued. If you remove all permissions from the temporary security credentials, subsequent AWS requests that use those credentials will fail. The mechanisms for changing or removing the permissions assigned to temporary security credentials are explained in the following sections.
upvoted 2 times
...
manoj101
3 years, 7 months ago
D is correct
upvoted 2 times
...
NKnab
3 years, 7 months ago
I think D is correct
upvoted 4 times
...
krtek77
3 years, 7 months ago
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html
upvoted 1 times
tan9
3 years, 7 months ago
By preforming the process depicted the CREDENTIAL itself is still not revocable, you revoke ALL active sessions associated to the role instead.
upvoted 2 times
...
kaush
3 years, 7 months ago
When you enable users to access the AWS Management Console with a long session duration time (such as 12 hours), their temporary credentials do not expire as quickly. If users inadvertently expose their credentials to an unauthorized third party, that party has access for the duration of the session. However, you can immediately revoke all permissions to the role's credentials issued before a certain point in time if you need to. All temporary credentials for that role issued before the specified time become invalid. This forces all users to reauthenticate and request new credentials.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago