exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 567 discussion

Exam question from Amazon's AWS-SysOps
Question #: 567
Topic #: 1
[All AWS-SysOps Questions]

An organization has hired an external firm to audit unauthorized changes on the company's AWS environment, the external auditor needs appropriate access.
How can this be accomplished?

  • A. Create an IAM user and assign them a new policy with GetResources access on AWS Artifact
  • B. Create an IAM user and add them to the existing ג€Administratorג€ IAM group
  • C. Create an IAM user and assign them a new IAM policy with read access to the AWS CloudTrail logs in Amazon S3
  • D. Create an IAM user and assign them a new policy with ListFindings access on Amazon Inspector
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 5 months ago
C is correct
upvoted 8 times
...
albert_kuo
Most Recent 9 months, 4 weeks ago
Selected Answer: C
AWS CloudTrail provides detailed logs of API activity within an AWS account, including changes made to resources. These logs can be invaluable for auditing and tracking unauthorized changes. By granting the auditor read access to the CloudTrail logs in Amazon S3, they will be able to review the logs and identify any unauthorized or suspicious activity. Creating an IAM user specifically for the auditor allows you to control their access separately from other users or groups. By assigning a new IAM policy with read access only to the CloudTrail logs in Amazon S3, you can limit the auditor's permissions to the necessary resources without granting unnecessary privileges.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago