AnswerCorrect answer: C — an EventBridge rule on AWS Health Risk events (AWS_RISK_CREDENTIALS_EXPOSED) to SNS alerts on repo-exposed access keys.
A company wants to receive automated email notifications when AWS access keys from developer AWS accounts are detected on code repository sites. Which solution will provide the required email notifications?
Create an Amazon EventBridge rule to send Amazon Simple Notification Service (Amazon SNS) email notifications for Amazon GuardDuty UnauthorizedAccess:IAMUser/lnstanceCredentialExfiltration.OutsideAWS findings.
Change the AWS account contact information for the Operations type to a separate email address. Periodically poll this email address for notifications.
Create an Amazon EventBridge rule that reacts to AWS Health events that have a value of Risk for the service category. Configure email notifications by using Amazon Simple Notification Service (Amazon SNS). Correct Answer
Implement new anomaly detection software. Ingest AWS CloudTrail logs. Configure monitoring for ConsoleLogin events in the AWS Management Console. Configure email notifications from the anomaly detection software.
Community Votes
A
67%
C
33%
67% of anonymous learners picked answer A.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
When AWS discovers IAM access keys exposed on public code repositories, it emits an AWS Health event (AWS_RISK_CREDENTIALS_EXPOSED), not a GuardDuty instance-credential finding. Routing AWS Health events through EventBridge to SNS gives automated notification for exactly this exposure scenario. GuardDuty's InstanceCredentialExfiltration finding is specific to EC2 instance-role credentials used externally and does not cover developer access keys found in repos.
The company wants automated email alerts when IAM access keys from developer accounts are found on public code-repository sites. AWS detects credentials exposed in public repositories and publishes an AWS Health event of type AWS_RISK_CREDENTIALS_EXPOSED. An EventBridge rule that matches AWS Health events in the Risk service category (or that specific event type) and targets an SNS topic delivers the required automated email notifications.
Selecting the GuardDuty InstanceCredentialExfiltration option. That finding type applies to EC2 instance-profile temporary credentials used outside AWS, not to IAM user access keys discovered on public code repositories, so it does not match the detection requirement.
Community Discussion (7 comments)
phmeeeee👍 1Selected: A
C - AWS Health focuses on service status & planned changes. Correct answer is A - GuardDuty can detect exposed credentials and generates the finding UnauthorizedAccess and send the event to EventBridge to trigger the SNS.
AWSLoverLoverLoverLoverLover👍 1Selected: A
Correct Answer: A. Create an Amazon EventBridge rule to send Amazon Simple Notification Service (Amazon SNS) email notifications for AWS Health events with the eventTypeCode AWS_RISK_CREDENTIALS_EXPOSED. Not C. Create an Amazon EventBridge rule that reacts to AWS Health events that have a value of Risk for the service category. Configure email notifications by using Amazon Simple Notification Service (Amazon SNS). While this captures a broader range of events, it may lead to unnecessary notifications. Focusing specifically on the AWS_RISK_CREDENTIALS_EXPOSED event ensures that alerts are relevant to exposed credentials.
Wardove👍 1Selected: C
The Answer is C, here is a similar solution: https://github.com/aws/aws-health-tools/blob/master/automated-actions/AWS_RISK_CREDENTIALS_EXPOSED/README.md Answer cannot be A because referenced finding type is exclusive to EC2 instance profiles, and is triggered only if instance session credentials are actually being used to authenticate as the instance. https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationoutsideaws
youonebe👍 1Selected: A
answer A, no doubt
SCSC02Q👍 1Selected: C
Its C, since Q asks for DETECTION, whereas A is only after the event, GuardDuty finding indicates compromised access has already happened.
VPNalumni👍 1
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationoutsideaws A
mikelord👍 1Selected: A
Option A is the correct solution because it leverages Amazon GuardDuty to detect unauthorized use or exposure of AWS access keys and uses Amazon EventBridge along with Amazon SNS to provide automated email notifications, efficiently meeting the requirement with the least effort.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
AWS proactively scans public code repositories and, when it finds exposed IAM access keys, publishes an AWS Health event (AWS_RISK_CREDENTIALS_EXPOSED). An EventBridge rule reacting to AWS Health events in the Risk service category and targeting an SNS topic provides the automated email notification the company needs, directly matching the "access keys detected on code repository sites" scenario.
Why the Other Options Are Wrong
A is wrong because the GuardDuty finding it names, UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS, is specific to EC2 instance-role credentials used from outside AWS—not IAM access keys found on public repos—so it does not fire for this case. B (polling account contact email) is manual and not automated. D requires building external anomaly-detection software ingesting CloudTrail, far more operational overhead than the managed AWS Health/EventBridge path.
Community Comment Notes
Community voted A (67) but the precise detection for keys exposed on public repos is the AWS Health AWS_RISK_CREDENTIALS_EXPOSED event, which option C targets. A commenter correctly noted A's finding type is "exclusive to EC2 instance profiles" and that C is the detection path. The technically correct answer is C.