Investigate the exposed key with IAM Access Analyzer and deactivate it to stop further use
A development team is creating an open source toolset to manage a company's software as a service (SaaS) application. The company stores the code in a public repository so that anyone can view and download the toolset's code. The company discovers that the code contains an IAM access key and secret key that provide access to internal resources in the company’s AWS environment A security engineer must implement a solution to identify whether unauthorized usage of the exposed credentials has occurred. The solution also must prevent any additional usage of the exposed credentials. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Deactivating the key (B) is the direct 'prevent additional usage' control. IAM Access Analyzer (A) can analyze access-key usage to show what the key touched and who used it, supporting the 'identify unauthorized usage' half. GuardDuty (C) cannot block a key, and simply creating a new key (D) or a credential report (E) does not stop or fully trace the leak. A and B are the pair.
An IAM access key was leaked in a public repo. To both find out whether it was misused and stop misuse, deactivate the exposed key immediately (prevents any further use) and use IAM Access Analyzer to analyze the key's access—identifying which resources it reached and which principal used it for forensic follow-up. A credential report (E) only shows last-login, not resource-level usage.
Relying on a credential report (E)—it shows password/key last-used, not which resources the key accessed, so it under-delivers on 'identify unauthorized usage.' Thinking GuardDuty (C) can block the key—GuardDuty detects, it does not revoke credentials. Creating a new key (D) does not contain the old one.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.