Courseiva

CCNA Securing Credentials and Data in Cloud Questions

15 questions · Securing Credentials and Data in Cloud · All types, answers revealed

1
Multi-Selecthard

A security analyst is investigating a suspected compromise of an AWS environment. The analyst discovers that an IAM user's access key was used from an unknown IP address to enumerate S3 buckets and download objects. The analyst needs to secure the environment and gather evidence. Which TWO actions should the analyst take to both contain the incident and preserve forensic data? (Choose two.)

Select 2 answers
A.Deactivate the compromised access key.
B.Rotate all IAM user access keys in the account.
C.Review AWS CloudTrail logs for the compromised access key.
D.Enable AWS CloudTrail logging for all regions.
E.Delete the IAM user associated with the access key.
AnswersA, C

Deactivating the access key immediately prevents further use of the stolen credentials, stopping the attacker from continuing to access AWS resources. It does not delete the key, so it can be re-enabled if needed for legitimate purposes, and it preserves the key's metadata for audit. This is a critical containment step that balances security with the need to maintain evidence.

Why this answer

Deactivating the compromised access key immediately stops the attacker from using it, while reviewing CloudTrail logs provides the necessary forensic evidence to understand the extent of the breach. Together, these actions contain the incident without destroying evidence. Deleting the user, enabling new logging, or rotating all keys either destroy evidence, fail to address the active threat, or cause unnecessary disruption.

Exam trap

The trap here is thinking that deleting the compromised IAM user is the best containment step; however, deletion destroys audit trails and can break legitimate access, whereas deactivation preserves evidence and is reversible.

2
MCQmedium

An incident responder discovers an EC2 instance in AWS has been compromised via a web application vulnerability. The instance profile attached to the instance has broad administrative permissions. What is the immediate priority to contain credential compromise in this scenario?

A.Terminate the compromised EC2 instance immediately to destroy any running malicious processes and volatile memory artifacts.
B.Attach a restrictive Network ACL to the subnet to block all inbound and outbound traffic originating from the compromised instance's private IP address.
C.Revoke active sessions using IAM boundary conditions and rotate or restrict the attached IAM instance profile role permissions.
D.Modify the VPC route table to remove the internet gateway route, isolating the entire virtual private cloud from external communication.
AnswerC

Invalidating active temporary credentials and modifying the role policies stops ongoing unauthorized API access. This directly mitigates the risk of lateral movement across the cloud environment by cutting off the compromised instance profile's valid session tokens.

Why this answer

Revoking existing session tokens and updating the IAM role trust and permission policies immediately restricts the attacker from leveraging active temporary security credentials. Incident handlers must remember that compromising an instance profile yields immediate access to STS tokens which persist even if the application vulnerability is patched or the instance is stopped without credential invalidation.

Exam trap

Candidates often assume that simply terminating the EC2 instance or applying a security group to block outbound traffic is sufficient, forgetting that temporary credentials generated prior to isolation may still be active externally.

3
MCQmedium

Which feature is most effective for preventing the accidental upload of secrets to a public cloud source code repository?

A.Implementing a post-push webhook to scan the repository.
B.Using pre-commit hooks to scan code for patterns.
C.Enabling public repository visibility scanning.
D.Enforcing HTTPS for all Git operations.
AnswerB

Pre-commit hooks catch secrets before they are committed to the local repository. This prevents sensitive data from ever reaching the remote server. It is a proactive, shift-left security control that empowers developers to fix mistakes locally, maintaining the integrity of the codebase and preventing accidental credential leakage effectively.

Why this answer

Pre-commit hooks are local scripts that run before a commit is finalized, scanning for patterns like API keys or passwords. They allow developers to catch mistakes immediately on their local machines before sensitive data is pushed to a remote repository. This prevents the secret from ever entering the version history, which is the most effective way to maintain the security of credentials in a distributed development workflow.

Exam trap

Candidates often choose server-side repository scanning or secret rotation services, which are reactive measures, failing to recognize that pre-commit hooks are the only proactive, preventative control that stops secrets before they are committed.

4
MCQhard

An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?

A.Amazon S3 server access logs.
B.AWS CloudTrail management events for the S3 service.
C.AWS CloudTrail data events for the S3 bucket.
D.VPC Flow Logs for the EC2 instance's network interface.
AnswerC

CloudTrail data events capture object-level API activity for S3, such as GetObject, PutObject, and DeleteObject. Since the attacker used the instance's IAM role to call s3:GetObject, these events will record the API call, including the identity (the role), the source IP, and the object accessed. This provides direct evidence of the exfiltration. Management events would not capture the object-level access, so data events are essential.

Why this answer

CloudTrail data events for S3 capture object-level API calls, including the identity of the caller (the IAM role) and the specific objects accessed. This directly evidences the exfiltration. Management events do not include data plane operations, S3 server access logs are less integrated, and VPC Flow Logs lack application-layer detail.

Thus, CloudTrail data events are the most direct source.

Exam trap

The trap here is confusing CloudTrail management events with data events, or assuming that VPC Flow Logs can show application-level S3 access, when only data events capture object-level operations.

5
MCQmedium

When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?

A.Setting a complex root password for the database.
B.Placing the database in a private subnet with restricted Security Group rules.
C.Enabling database logging for every query.
D.Using a public IP address for faster data synchronization.
AnswerB

Private subnets lack a route to an Internet Gateway, effectively isolating the database from the public internet. Restricting Security Group rules to only accept traffic from specific application server subnets ensures that even internal access is highly controlled, significantly reducing the surface area for unauthorized data exfiltration attempts.

Why this answer

Using a Virtual Private Cloud (VPC) and placing the database in private subnets ensures that the database is not routable from the public internet. By combining this with Security Groups that act as stateful firewalls, you create an isolated environment. Even if the database configuration is accidentally set to public, the network layer denies traffic, providing a critical safety net that prevents direct exploitation by external threat actors.

Exam trap

Candidates rely solely on application-level passwords or database encryption, forgetting that network architecture controls like private subnets provide essential isolation layers.

6
MCQeasy

A security team is configuring encryption for data at rest in an Amazon S3 bucket that stores regulated financial records. They need to ensure that the encryption keys are managed by the organization and can be rotated on demand, while also providing an audit trail of key usage. Which AWS service should they use to meet these requirements?

A.S3 server-side encryption with Amazon S3 managed keys (SSE-S3)
B.S3 server-side encryption with customer-provided keys (SSE-C)
C.AWS Key Management Service (KMS) with customer managed keys
D.Amazon S3 default encryption with AES-256
AnswerC

AWS KMS allows the creation of customer managed keys, which give the organization full control over key policies, rotation, and usage. KMS integrates with AWS CloudTrail to log every use of the key, providing an audit trail. It also supports automatic and manual key rotation. This meets the requirements for managing keys, on-demand rotation, and auditing key usage for S3 data at rest.

Why this answer

AWS KMS with customer managed keys provides the necessary control over encryption keys, including the ability to rotate them on demand and define key policies. It integrates with CloudTrail to log key usage, which is essential for auditing access to sensitive financial records. Other S3 encryption options either do not allow customer management of keys or lack the audit trail required for compliance.

Exam trap

The trap here is confusing S3 server-side encryption options with key management services; only KMS customer managed keys offer on-demand rotation and detailed audit trails.

7
MCQhard

An incident responder is analyzing a potential compromise of an AWS environment. The attacker gained access to an EC2 instance and then used the instance's IAM role to call the AWS Security Token Service (STS) AssumeRole API to obtain credentials for a role in another account. The attacker then used those credentials to access sensitive data. Which AWS service or feature would provide the most detailed log of the AssumeRole API call, including the identity of the caller and the target role?

A.AWS Config configuration history
B.Amazon VPC Flow Logs
C.AWS CloudTrail management events
D.Amazon GuardDuty findings
AnswerC

CloudTrail management events log all API calls that control AWS resources, including STS AssumeRole. The log entry includes the identity of the caller (the EC2 instance role), the target role, the requested session name, and the source IP address. This provides the most detailed record for tracing the cross-account role assumption. CloudTrail is the primary audit service for API activity in AWS.

Why this answer

CloudTrail management events capture all API calls, including STS AssumeRole, with details such as the caller's identity, the target role, the session name, and the source IP. This makes it the most detailed log for tracing cross-account role assumption. VPC Flow Logs, AWS Config, and GuardDuty findings either lack API-level detail or are not designed for forensic auditing of individual API calls.

Exam trap

The trap here is assuming that GuardDuty findings provide the granular API details needed for forensics, when they are actually high-level alerts that require CloudTrail for full context.

8
MCQmedium

A security analyst is reviewing access to a cloud-based file storage service. The organization uses SAML-based single sign-on (SSO) with an external identity provider (IdP) for authentication. The analyst notices that some users are still able to access the file storage service using their old username and password, even after SSO was enforced. Which of the following is the MOST likely cause?

A.The identity provider is not configured to send the correct user attributes.
B.The SAML assertion is not properly signed, allowing users to forge authentication.
C.The service's local authentication is still enabled, allowing users to bypass SSO.
D.The users have cached credentials in their browsers that bypass SSO.
AnswerC

If the cloud service still allows local username and password authentication, users can continue to log in directly, bypassing SSO. To enforce SSO, the service's local authentication must be disabled. This is a common misconfiguration when transitioning to SSO. The analyst should verify the service's authentication settings and disable any non-SSO login methods.

Why this answer

The most likely cause is that the service's local authentication remains enabled, permitting users to log in with their old credentials. Enforcing SSO requires disabling all other authentication methods. The other options either do not explain the use of old credentials or are less likely given the scenario.

The analyst should check and disable local authentication.

Exam trap

The trap here is focusing on SAML misconfigurations or cached credentials, when the simple explanation is that local authentication was never disabled, allowing users to bypass SSO entirely.

9
MCQmedium

A GCIH responder is investigating a compromised AWS account where an EC2 instance's IAM role credentials were stolen from the instance metadata service. The attacker used those temporary credentials from an external IP address to download sensitive objects from an S3 bucket. Which AWS service or mechanism would have provided the earliest detection of this specific anomalous behavior?

A.Amazon GuardDuty with findings for unauthorized access to IAM credentials
B.AWS CloudTrail data events for S3 object-level operations
C.Amazon Macie sensitive data discovery jobs on the S3 bucket
D.AWS Trusted Advisor security checks for S3 bucket permissions
AnswerA

GuardDuty continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior. It has specific finding types such as UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration that trigger when EC2 instance role credentials are used from an external IP address. This provides the earliest automated detection of this exact scenario because it correlates credential usage with network origin.

Why this answer

GuardDuty analyzes CloudTrail management events to identify when EC2 instance role credentials are used from an external IP address. This specific finding type, UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration, triggers because GuardDuty correlates the credential usage with the originating IP and flags it as anomalous. CloudTrail data events alone only log the API calls without assessing whether the source is expected, while Trusted Advisor and Macie focus on configuration and data classification respectively.

Exam trap

The trap here is assuming that CloudTrail data events alone will alert on stolen credentials, when in fact they only log API calls and require manual analysis to detect the anomaly.

10
MCQhard

An incident responder is analyzing a potential compromise in an AWS environment. The responder notices that an IAM role attached to an EC2 instance has been used to access an S3 bucket from an external IP address. The role's trust policy allows the EC2 service to assume it. Which technique is the attacker MOST likely using to abuse this role?

A.Use of long-term IAM user credentials embedded in the EC2 instance.
B.Cross-account role assumption via sts:AssumeRole.
C.Credential exfiltration from the EC2 instance metadata service (IMDS).
D.Exploitation of a confused deputy vulnerability in the S3 bucket policy.
AnswerC

The EC2 instance metadata service (IMDS) provides temporary credentials to the instance, which are associated with the IAM role. If an attacker gains access to the instance, they can query IMDS to retrieve these credentials and use them from an external IP address. This is a common attack vector, especially if IMDSv1 is enabled, which does not require a session token. The external IP usage indicates the credentials were stolen and used remotely.

Why this answer

The attacker most likely exfiltrated temporary credentials from the EC2 instance metadata service (IMDS) and used them from an external IP. Since the role's trust policy only allows EC2, the credentials must have been obtained from the instance itself. Cross-account assumption is blocked, confused deputy involves service manipulation, and long-term credentials are not used with roles.

Exam trap

The trap here is assuming that an external IP using role credentials implies cross-account access, when in fact it often indicates stolen temporary credentials from the instance metadata service.

11
MCQhard

During a cloud incident response engagement, an analyst reviews AWS CloudTrail logs and finds that an access key belonging to an IAM user was used from an unfamiliar IP address to call GetSecretValue against AWS Secrets Manager. The key is still active. Which immediate containment action best limits further credential misuse while preserving the ability to investigate who used the key?

A.Enable AWS GuardDuty and wait for its findings to confirm the anomaly before taking any action on the credential.
B.Delete the IAM user entirely with DeleteUser and recreate it later with the same permissions and a new access key.
C.Attach an inline IAM policy to the user that denies all actions with a Condition testing aws:SourceIp against the unfamiliar address.
D.Deactivate the access key with UpdateAccessKey, then rotate the key and review CloudTrail history associated with that key ID.
AnswerD

Deactivating the access key immediately stops any further API calls using that credential, which is the fastest containment step for a leaked long-term key. Because CloudTrail records the access key ID on every event, the history for that key remains queryable after deactivation, so the analyst can still reconstruct what the attacker did. Rotating afterward restores legitimate access safely.

Why this answer

The exposed long-term access key is the active threat, so the priority is to make it unusable right away. Deactivating the key with UpdateAccessKey halts all API calls tied to that credential while leaving the IAM user and its policies intact for analysis. CloudTrail retains the access key ID in every event record, so the investigation can continue after containment.

Rotating the credential afterward restores access without reintroducing the compromised secret.

Exam trap

The trap here is assuming that restricting the key by source IP or waiting for a detection service to flag the behavior constitutes containment, when the exposed credential itself must be deactivated to stop misuse.

12
MCQeasy

Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?

A.Separation of Duties.
B.Principle of Least Privilege.
C.Defense in Depth.
D.Security through Obscurity.
AnswerB

The Principle of Least Privilege requires that users be granted only the minimum permissions needed to complete a task. 'AdministratorAccess' provides broad, excessive permissions that are rarely required for daily operational tasks. Using such an account for routine work exposes the organization to unnecessary risk if the account is compromised.

Why this answer

The 'AdministratorAccess' policy provides full, unrestricted access to all services. Assigning this to daily tasks violates the Principle of Least Privilege, which dictates that users should only have the minimum permissions necessary to perform their jobs. Over-privileged accounts are a significant liability, as they allow an attacker who compromises the account to perform any action, including deleting logs or resources, which massively increases the potential impact of an incident.

Exam trap

Candidates sometimes confuse the principle of least privilege with separation of duties or defense-in-depth when evaluating over-assigned administrative access policies.

13
MCQmedium

An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?

A.Generate unique access keys for every developer stored in an encrypted S3 bucket.
B.Rotate IAM user access keys every 90 days via an automated script.
C.Implement IAM roles that grant temporary security credentials via STS.
D.Use an IAM group policy to enforce Multi-Factor Authentication on all API requests.
AnswerC

IAM roles provide temporary security credentials that expire automatically, effectively mitigating the risk of credential theft. By leveraging AWS Security Token Service (STS), developers can assume roles only when needed. This approach eliminates the need for managing static keys, significantly reducing the attack surface for programmatic cloud access.

Why this answer

Utilizing IAM roles with temporary security credentials is the best practice for cloud security. By assuming roles, you eliminate the risks associated with static access keys, which are frequently leaked or stolen. This approach aligns with the principle of least privilege, as temporary tokens expire automatically, reducing the window of opportunity for an attacker to exploit compromised credentials, thereby enhancing the overall security posture of the cloud environment.

Exam trap

Candidates frequently select long-term access keys configured with multi-factor authentication, forgetting that programmatic access requires automated temporary credentials.

14
MCQmedium

A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys managed by AWS Key Management Service (KMS) and that the encryption is enforced automatically for all new objects. Which configuration should they implement?

A.Use AWS Certificate Manager (ACM) to provision SSL/TLS certificates for the S3 bucket.
B.Create a bucket policy that denies unencrypted PutObject requests.
C.Enable default encryption on the S3 bucket using SSE-S3 (AES-256).
D.Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key.
AnswerD

SSE-KMS with a customer managed key uses AWS KMS to manage the encryption keys, providing centralized control, audit trails via CloudTrail, and the ability to rotate keys. Enabling default encryption ensures all new objects are encrypted automatically without relying on users to specify encryption headers. This directly satisfies the requirement for KMS-managed keys and enforced encryption.

Why this answer

Enabling default encryption with SSE-KMS and a customer managed key ensures that all new objects are encrypted using KMS-managed keys, meeting both the encryption at rest and key management requirements. It also provides auditability and control over the keys. Other options either use non-KMS keys, only enforce encryption without specifying key type, or address transit encryption instead of at rest.

Exam trap

The trap here is confusing encryption in transit with encryption at rest, or assuming that SSE-S3 satisfies a requirement for KMS-managed keys when it uses S3-managed keys instead.

15
MCQhard

Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?

A.A user is assigned two different roles with conflicting permissions.
B.A malicious user triggers a service to use its privileges against a resource.
C.Two cloud administrators inadvertently delete each other's work.
D.A service fails to refresh its temporary tokens, causing a lockout.
AnswerB

This occurs when an attacker convinces a service that has sufficient permissions to act on their behalf. Without checks like External IDs, the service might unknowingly perform actions, such as reading private data, because it trusts the requester. This is a major security concern in multi-tenant cloud environments.

Why this answer

The Confused Deputy problem occurs when a privileged service is coerced into performing an action on behalf of a user who lacks the permissions to perform that action directly. By utilizing 'External IDs' or 'Condition keys' like 'aws:SourceArn', developers can prevent this by ensuring that the service only assumes the role when the request originates from an authorized context, preventing unauthorized cross-account access and privilege escalation.

Exam trap

Candidates often confuse the Confused Deputy problem with simple privilege escalation or credential theft. They fail to recognize the specific nuance where a legitimate service is coerced into misusing its own authority.

Ready to test yourself?

Try a timed practice session using only Securing Credentials and Data in Cloud questions.