Multiple Choice
A company's development team is designing an application using AWS Lambda and Amazon Elastic Container Service (Amazon ECS) . The development team needs to create IAM roles to support these systems. The company's security team wants to allow the developers to build IAM roles directly, but the security team wants to retain control over the permissions the developers can delegate to those roles. The development team needs access to more permissions than those required for application's AWS services. The solution must minimize management overhead. How should the security team prevent privilege escalation for both teams?
A) Enable AWS CloudTrail. Create a Lambda function that monitors the event history for privilege escalation events and notifies the security team.
B) Create a managed IAM policy for the permissions required. Reference the IAM policy as a permissions boundary within the development team's IAM role.
C) Enable AWS Organizations. Create an SCP that allows the iam:CreateUser action but that has a condition that prevents API calls other than those required by the development team.
D) Create an IAM policy with a deny on the iam:CreateUser action and assign the policy to the development team. Use a ticket system to allow the developers to request new IAM roles for their applications. The IAM roles will then be created by the security team.
Correct Answer:

Verified
Correct Answer:
Verified
Q189: A company uses multiple AWS accounts managed
Q190: A company recently performed an annual security
Q191: An organization has tens of applications deployed
Q192: A security engineer has noticed that VPC
Q193: A company's director of information security wants
Q195: After multiple compromises of its Amazon EC2
Q196: A company uses user data scripts that
Q197: A Security Engineer must enforce the use
Q198: A security alert has been raised for
Q199: A company needs a forensic-logging solution for