Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).
Start practicing
Securing Credentials and Data in Cloud — choose a session length
Free · No account required
Domain overview
This domain covers protecting credentials and data in cloud environments, focusing on AWS IAM, CloudTrail, Secrets Manager, and S3. Questions test detection of compromised access keys, IAM role trust misconfigurations like Confused Deputy, secret-scanning controls, and least-privilege enforcement during incident response.
Exam objectives
Analyzing AWS CloudTrail events for GetSecretValue calls from unfamiliar IP addresses using compromised IAM access keys
Identifying Confused Deputy risks in cross-account IAM role trust policies and external ID requirements
Using secret-scanning tools like git-secrets or pre-commit hooks to block credential commits to repositories
Recognizing least privilege violations when AdministratorAccess is granted for routine operational IAM tasks
Assuming CloudTrail alone blocks access-key abuse; it only logs API activity, so detection requires monitoring and alerting, not prevention.
Confusing Confused Deputy with privilege escalation: the issue is a trusted service being tricked, not the user gaining direct permissions.
Believing MFA on the IAM user prevents leaked access keys from working; long-term keys can still authenticate without MFA unless explicitly denied.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?
2When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?
3Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?
4Which feature is most effective for preventing the accidental upload of secrets to a public cloud source code repository?
5Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?
6An incident responder discovers an EC2 instance in AWS has been compromised via a web application vulnerability. The instance profile attached to the instance has broad administrative permissions. What is the immediate priority to contain credential compromise in this scenario?
7A GCIH responder is investigating a compromised AWS account where an EC2 instance's IAM role credentials were stolen from the instance metadata service. The attacker used those temporary credentials from an external IP address to download sensitive objects from an S3 bucket. Which AWS service or mechanism would have provided the earliest detection of this specific anomalous behavior?
8A security analyst is investigating a suspected compromise of an AWS environment. The analyst discovers that an IAM user's access key was used from an unknown IP address to enumerate S3 buckets and download objects. The analyst needs to secure the environment and gather evidence. Which TWO actions should the analyst take to both contain the incident and preserve forensic data? (Choose two.)
9A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys managed by AWS Key Management Service (KMS) and that the encryption is enforced automatically for all new objects. Which configuration should they implement?
10An incident responder is analyzing a potential compromise in an AWS environment. The responder notices that an IAM role attached to an EC2 instance has been used to access an S3 bucket from an external IP address. The role's trust policy allows the EC2 service to assume it. Which technique is the attacker MOST likely using to abuse this role?
11A security team is configuring encryption for data at rest in an Amazon S3 bucket that stores regulated financial records. They need to ensure that the encryption keys are managed by the organization and can be rotated on demand, while also providing an audit trail of key usage. Which AWS service should they use to meet these requirements?
12An incident responder is analyzing a potential compromise of an AWS environment. The attacker gained access to an EC2 instance and then used the instance's IAM role to call the AWS Security Token Service (STS) AssumeRole API to obtain credentials for a role in another account. The attacker then used those credentials to access sensitive data. Which AWS service or feature would provide the most detailed log of the AssumeRole API call, including the identity of the caller and the target role?
13An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?
14A security analyst is reviewing access to a cloud-based file storage service. The organization uses SAML-based single sign-on (SSO) with an external identity provider (IdP) for authentication. The analyst notices that some users are still able to access the file storage service using their old username and password, even after SSO was enforced. Which of the following is the MOST likely cause?
15During a cloud incident response engagement, an analyst reviews AWS CloudTrail logs and finds that an access key belonging to an IAM user was used from an unfamiliar IP address to call GetSecretValue against AWS Secrets Manager. The key is still active. Which immediate containment action best limits further credential misuse while preserving the ability to investigate who used the key?
Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).
The Courseiva GCIH question bank contains 15 questions in the Securing Credentials and Data in Cloud domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Credentials and Data in Cloud domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included