exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 470 discussion

A company is using AWS to deploy a critical application on a fleet of Amazon EC2 instances. The company is rewriting the application because the application failed a security review. The application will take 12 months to rewrite. While this rewrite happens, the company needs to rotate IAM access keys that the application uses.

A SysOps administrator must implement an automated solution that finds and rotates IAM access keys that are at least 30 days old. The solution must then continue to rotate the IAM access keys every 30 days.

Which solution will meet this requirement with the MOST operational efficiency?

  • A. Use an AWS Config rule to identify IAM access keys that are at least 30 days old. Configure AWS Config to invoke an AWS Systems Manager Automation runbook to rotate the identified IAM access keys.
  • B. Use AWS Trusted Advisor to identify IAM access keys that are at least 30 days old. Configure Trusted Advisor to invoke an AWS Systems Manager Automation runbook to rotate the identified IAM access keys.
  • C. Create a script that checks the age of IAM access keys and rotates them if they are at least 30 days old. Launch an EC2 instance. Schedule the script to run as a cron expression on the EC2 instance every day.
  • D. Create an AWS Lambda function that checks the age of IAM access keys and rotates them if they are at least 30 days old. Use an Amazon EventBridge rule to invoke the Lambda function every time a new IAM access key is created.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
numark
4 months, 2 weeks ago
Selected Answer: A
This is the most operationally efficient solution as it automates the process of identifying and rotating IAM access keys that are at least 30 days old. AWS Config can continuously monitor and record AWS resource configurations, and in this case, it can detect IAM access keys that reach a certain age. With an AWS Systems Manager Automation runbook, the process can be automated to rotate these keys without manual intervention.
upvoted 1 times
...
Aamee
5 months, 3 weeks ago
Selected Answer: A
Correction: Voting for A.
upvoted 1 times
...
siheom
5 months, 4 weeks ago
Selected Answer: A
vote A
upvoted 2 times
...
Aamee
6 months ago
Selected Answer: B
Although the suggested ans. shows option A is correct but I've a doubt if option B can be the possible correct answer here...
upvoted 1 times
Aamee
6 months ago
After reading it again, I believe option A is a more better choice here...
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago