exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 40 discussion

Exam question from Amazon's AWS-SysOps
Question #: 40
Topic #: 1
[All AWS-SysOps Questions]

Your organization's security policy requires that all privileged users either use frequently rotated passwords or one-time access credentials in addition to username/password.
Which two of the following options would allow an organization to enforce this policy for AWS users? (Choose two.)

  • A. Configure multi-factor authentication for privileged 1AM users
  • B. Create 1AM users for privileged accounts
  • C. Implement identity federation between your organization's Identity provider leveraging the 1AM Security Token Service
  • D. Enable the 1AM single-use password policy option for privileged users
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AWS_Noob
Highly Voted 2 years ago
A & B are correct MFA using a 3rd party authenticator like Google Authenticator. Creating an IAM user will assist with creating a user name and password. Read the question correctly
upvoted 9 times
...
albert_kuo
Most Recent 5 months, 1 week ago
Selected Answer: AC
options A (configure multi-factor authentication for privileged IAM users) and C (implement identity federation between your organization's Identity provider leveraging the IAM Security Token Service) are the two options that would allow an organization to enforce the policy of using frequently rotated passwords or one-time access credentials for AWS users.
upvoted 2 times
...
davidy2020
1 year, 12 months ago
IMO A - one time access C - STS token rotates each time and valid for limited time
upvoted 3 times
...
RicardoD
1 year, 12 months ago
A | B are the answers First, you need to create an IAM user (B), which will provide username and password, then you activate MFA (A), for those users and it will cover the one-time access credentials
upvoted 1 times
...
waterzhong
2 years ago
A & B Create the user then configure MFA. Should be what steps taken.
upvoted 1 times
...
mrbreeze
2 years ago
A & B Create the user then configure MFA. Should be what steps taken.
upvoted 1 times
...
MrDEVOPS
2 years ago
A and B I think Question wud have been , which two combinations of steps!!!
upvoted 1 times
...
onlinebaba
2 years ago
AB A = Frequently Rotated Passwords or One Time Passwords is satisfied by MFA B = In order to use username/password, privileged Users accounts need to be created using IAM
upvoted 1 times
onlinebaba
2 years ago
..and when creating User accounts in IAM, enforce MFA :)
upvoted 1 times
...
...
Albin
2 years ago
Ans: C and D
upvoted 2 times
...
gretch
2 years ago
AB frequently rotated password (enable password expiration, never heard of single-use password policy) and "one-time access credentials in addition to username/password" (MFA)
upvoted 1 times
...
awscertified
2 years ago
A. Configure multi-factor authentication for privileged 1AM users D. Enable the 1AM single-use password policy option for privileged users
upvoted 1 times
...
shahabjan
2 years ago
If anyone can help with this questions. A development team is designing an application that processes sensitive information within a hybrid deployment. the team needs to ensure the application data is protected both in transit and at rest. Which combination of actions should be taken to accomplish this? (select TWO). a. Use a VPN to set up a tunnel between the on-premises data center and the AWS resources. b. Use AWS Certification Manager to create a TLS/SSL certificates. c. Use AWS CloudHSM to encrypt the data. d. Use AWS KMS to create TLS/SSL certifications. e. Use AWS KMS to manage encryption keys used for data encryption.
upvoted 3 times
exequielrafaela
1 year, 12 months ago
For this Question please refer to https://www.examtopics.com/discussions/amazon/view/19994-exam-aws-sysops-topic-2-question-208-discussion/
upvoted 1 times
...
...
Suresh_bk201
2 years ago
frequently rotated passwords -- need IAM accounts to do that One time access creds -- refers to the mfa token which we can use only one time So B
upvoted 1 times
Suresh_bk201
2 years ago
* A and B
upvoted 1 times
...
...
kteng
2 years ago
I'm voting for A,D. MFA will not rotate your password, so it meets one of the requirement by the question. To rotate the password, you'll need to configure it from the password policy by setting password expire date, which is D. B is wrong, a IAM user for privileged accounts can still access with username/password.
upvoted 2 times
karmaah
2 years ago
One time password policy does not have the provision for pw rotation everytime . https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_passwords_account-policy.html
upvoted 1 times
...
...
karmaah
2 years, 1 month ago
When you use Multi Factor authentication, everytime, pw rotates ..So A has been selected instead of D. So answers are correct.
upvoted 1 times
karmaah
2 years ago
Not sure why not C for temp access..how B has been selected.
upvoted 1 times
karmaah
2 years ago
Ans should be A,C..Arguments welcome
upvoted 2 times
sospally
2 years ago
What if there is no Domain to Federate to? IAM users can have password policies applied. AB sounds like the best option.
upvoted 5 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago