Investigate the exposed key with IAM Access Analyzer and deactivate it to stop further use

Answer Correct answer: A, B — use IAM Access Analyzer to investigate the exposed key's usage and deactivate the key to stop further use.

A development team is creating an open source toolset to manage a company's software as a service (SaaS) application. The company stores the code in a public repository so that anyone can view and download the toolset's code. The company discovers that the code contains an IAM access key and secret key that provide access to internal resources in the company’s AWS environment A security engineer must implement a solution to identify whether unauthorized usage of the exposed credentials has occurred. The solution also must prevent any additional usage of the exposed credentials. Which combination of steps will meet these requirements? (Choose two.)

  1. Use AWS Identity and Access Management Access Analyzer to determine which resources the exposed credentials accessed and who used them. Correct Answer
  2. Deactivate the exposed IAM access key from the user’s IAM account. Correct Answer
  3. Create a rule in Amazon GuardDuty to block the access key in the source code from being used.
  4. Create a new IAM access key and secret key for the user whose credentials were exposed.
  5. Generate an IAM credential report. Check the report to determine when the user that owns the access key last logged in.

Community Votes

AB
100%

100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Deactivating the key (B) is the direct 'prevent additional usage' control. IAM Access Analyzer (A) can analyze access-key usage to show what the key touched and who used it, supporting the 'identify unauthorized usage' half. GuardDuty (C) cannot block a key, and simply creating a new key (D) or a credential report (E) does not stop or fully trace the leak. A and B are the pair.

An IAM access key was leaked in a public repo. To both find out whether it was misused and stop misuse, deactivate the exposed key immediately (prevents any further use) and use IAM Access Analyzer to analyze the key's access—identifying which resources it reached and which principal used it for forensic follow-up. A credential report (E) only shows last-login, not resource-level usage.

Relying on a credential report (E)—it shows password/key last-used, not which resources the key accessed, so it under-delivers on 'identify unauthorized usage.' Thinking GuardDuty (C) can block the key—GuardDuty detects, it does not revoke credentials. Creating a new key (D) does not contain the old one.

Community Discussion (7 comments)

f3f9bfe 👍 9 Selected: AB
Security Engineer must identified whether unauthorized usage of the exposed credential has occurred and prevent any additional usage of the exposed credential. The Answers are A and B
phmeeeee 👍 1 Selected: AB
To immediately stop the expored the credential. B - prevent any additional usage of the exposed credential. A - use for forensics the exposed credential.
7c84836 👍 1
why A over E?
sema2232 👍 3
B, E correct
aescudero51 👍 1 Selected: AB
My answer is A & B A. Use AWS Identity and Access Management Access Analyzer to determine which resources the exposed credentials accessed and who used them. This will help identify if any unauthorized activity occurred while the credentials were exposed. B. Deactivate the exposed IAM access key from the user's IAM account. This will immediately prevent any further use of the compromised credentials.
Zek 👍 2
A, B look Ok to me
danish1234 👍 3
A and E

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Deactivating the exposed access key (B) immediately prevents any additional use of the leaked credential. IAM Access Analyzer (A) can analyze the key's access activity to determine which resources the exposed credentials reached and which principal used them, fulfilling the investigation requirement. Together they cover both mandates.

Why the Other Options Are Wrong

C (GuardDuty rule) can alert on suspicious activity but cannot block a key from being used. D (create a new key) does nothing to neutralize the exposed one. E (credential report) reports last-used time, not the resource-level usage needed to confirm unauthorized access. A and B are the correct combination.

Community Comment Notes

Community voted A,B (100), with the top comment (likes=9) stating B prevents further use and A supports forensics on the exposed credential. A minority suggested B,E, but the majority confirmed A,B as the pair that both identifies misuse and stops it.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide