exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 213 discussion

A security engineer discovers that a company’s user passwords have no required minimum length. The company is using the following two identity providers (IdPs):
• AWS Identity and Access Management (IAM) federated with on-premises Active Directory
• Amazon Cognito user pools that contain the user database for an AWS Cloud application that the company developed

Which combination of actions should the security engineer take to implement a required minimum length for the passwords? (Choose two.)

  • A. Update the password length policy in the IAM configuration.
  • B. Update the password length policy in the Cognito configuration.
  • C. Update the password length policy in the on-premises Active Directory configuration
  • D. Create an SCP in AWS Organizations. Configure the SCP to enforce a minimum password length for IAM and Cognito.
  • E. Create an IAM policy that includes a condition for minimum password length. Enforce the policy for IAM and Cognito.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
youonebe
3 months, 1 week ago
Selected Answer: BC
For Amazon Cognito: You can configure password length requirements directly in Cognito user pools5 The minimum password length can be set between 6 and 99 characters, though users can set passwords up to 256 characters long5 This is configured through the Password Policy settings in the Cognito user pool5 For Active Directory (federated with IAM): Since IAM is federated with on-premises Active Directory, the password policies are managed at the Active Directory level13 Password length requirements can be configured in Active Directory through Group Policy settings13 Changes must be made in Active Directory, not IAM, since AD is the authoritative source for authentication
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago