Q233.During a security audit of a Service team's application a Solutions Architect discovers that a username and password for an Amazon RDS database and a set of AWS IAM user credentials can be viewed in the AWS Lambda function

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q233.During a security audit of a Service team's application a Solutions Architect discovers that a username and password for an Amazon RDS database and a set of AWS IAM user credentials can be viewed in the AWS Lambda function code. The Lambda function uses the username and password to run queries on the database and it uses the IAM credentials to call AWS services in a separate management account. The Solutions Architect is concerned that the credentials could grant inappropriate access to anyone who can view the Lambda code.The management account and the Service team's account are in separate AWS Organizations organizational units (OUs). Which combination of changes should the Solutions Architect make to improve the solution's security? (Select TWO.)

A.Configure Lambda to assume a role in the management account with appropriate access to AWS.
B.Configure Lambda to use the stored database credentials in AWS Secrets Manager and enable automatic rotation.
C.Create a Lambda function to rotate the credentials every hour by deploying a new Lambda version with the updated credentials :
D.Use an SCP on the management account's OU to prevent IAM users from accessing resources in the Service team's account.
E.Enable AWS Shield Advanced on the management account to shield sensitive resources from unauthorized IAM access.
正确答案AB
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top