A company's development team is designing an application using AWS Lambda and Amazon Elastic Container Service (Amazon ECS) . The development team needs to create IAM roles to support these systems. The company's security team wants to allow the developers to build IAM roles directly, but the security team wants to retain control over the permissions the developers can delegate to those roles. The development team needs access to more permissions than those required for application's AWS services. The solution must minimize management overhead. How should the security team prevent privilege escalation for both teams?
A) Enable AWS CloudTrail. Create a Lambda function that monitors the event history for privilege escalation events and notifies the security team.
B) Create a managed IAM policy for the permissions required. Reference the IAM policy as a permissions boundary within the development team's IAM role.
C) Enable AWS Organizations. Create an SCP that allows the iam:CreateUser action but that has a condition that prevents API calls other than those required by the development team.
D) Create an IAM policy with a deny on the iam:CreateUser action and assign the policy to the development team. Use a ticket system to allow the developers to request new IAM roles for their applications. The IAM roles will then be created by the security team.
Correct Answer:
Verified
Q252: A user is implementing a third-party web
Q253: A company has developed a new Amazon
Q254: An audit determined that a company's Amazon
Q255: A company has two AWS accounts: Account
Q256: A security engineer has been tasked with
Q258: A security engineer has enabled AWS Security
Q259: A company is storing data in Amazon
Q260: A company hosts an application on Amazon
Q261: A Security Engineer has launched multiple Amazon
Q262: A Security Engineer is troubleshooting a connectivity
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents