ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company hosts several production workloads in AWS using long-lived access keys assigned to IAM users. A recently adopted security standard mandates that all privileged access employ short-lived credentials issued by a centralized identity provider and be fully auditable in CloudTrail. Which approach best meets the new requirement while minimizing code changes to existing workloads?
Create a separate AWS account for privileged operations and distribute the root user credentials to the security team for emergency use only.
Use AWS Secrets Manager to automatically rotate every IAM user access key every 90 days and store rotation events in CloudTrail.
Enable MFA Delete on all S3 buckets and require hardware MFA tokens for existing IAM users during console logins.
Replace the IAM users with IAM roles accessed through AWS IAM Identity Center federated to the corporate IdP; applications obtain temporary AWS STS credentials at runtime.
Using IAM roles that are assumed via AWS IAM Identity Center (formerly AWS SSO) satisfies the new security standard because the roles issue temporary AWS STS credentials each time they are assumed, eliminating long-lived access keys. Federation with the corporate IdP centralizes identity management, and all role assumptions are automatically logged in AWS CloudTrail, providing the required audit trail. Simply rotating access keys still leaves long-lived credentials in place, enabling MFA Delete on S3 addresses only object storage and does not replace access keys, and sharing root credentials violates AWS security best practices and offers no centralized auditing.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are IAM roles and how do they differ from IAM users?
Open an interactive chat with Bash
How does AWS IAM Identity Center enable centralized identity management?
Open an interactive chat with Bash
What is AWS CloudTrail and why is it important for auditing?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .