A threat assessment has identified a risk whereby an internal employee could exfiltrate sensitive data from production host running inside AWS (Account 1). The threat was documented as follows:
Threat description: A malicious actor could upload sensitive data from Server X by configuring credentials for an AWS account (Account 2) they control and uploading data to an Amazon S3 bucket within their control.
Server X has outbound internet access configured via a proxy server. Legitimate access to S3 is required so that the application can upload encrypted files to an
S3 bucket. Server X is currently using an IAM instance role. The proxy server is not able to inspect any of the server communication due to TLS encryption.
Which of the following options will mitigate the threat? (Choose two.)
Nebolos
Highly Voted 3 years, 7 months agoHungdv
Highly Voted 3 years, 6 months agoBosch123
2 years, 7 months agoRobert0
1 year, 10 months agoGustava6272
3 years, 6 months ago0x00infosec
Most Recent 7 months agoDeyemzy
10 months, 3 weeks agojlggross
9 months, 2 weeks agoRaphaello
1 year, 2 months agoBenah
1 year, 7 months agoGreen53
1 year, 10 months agoRobert0
1 year, 10 months agounravikumar
1 year, 11 months agomatrpro
1 year, 12 months agoroguecloud
2 years, 3 months agorazguru
2 years, 3 months agoboooliyooo
2 years, 3 months agosakibmas
2 years, 4 months agoexam67
2 years, 4 months agogg12345
2 years, 5 months agosakibmas
2 years, 7 months ago