An incident responder discovers that an AWS IAM role associated with an EC2 instance has been used to exfiltrate sensitive data from an S3 bucket. The administrator wants to revoke all active sessions for this compromised role immediately without deleting the role itself. Which action should the responder take?
Trap 1: Rotate the access keys associated with the IAM role immediately.
IAM roles do not use long-term access keys. Instead, they rely on temporary security credentials generated dynamically by the Security Token Service, rendering standard access key rotation ineffective for revoking active role sessions.
Trap 2: Attach an explicit Deny policy with a NotAction condition to the…
Attaching a policy with a NotAction condition can inadvertently lock out legitimate administrative access and fails to specifically target the issuance time of active temporary security tokens already distributed to the attacker.
Trap 3: Disable the trust relationship policy on the IAM role to stop…
Modifying the trust relationship prevents new assume-role requests from succeeding, but it does not invalidate temporary credentials that have already been successfully generated and issued to the attacker prior to the change.
- A
Rotate the access keys associated with the IAM role immediately.
Why it fails: IAM roles do not use long-term access keys. Instead, they rely on temporary security credentials generated dynamically by the Security Token Service, rendering standard access key rotation ineffective for revoking active role sessions.
- B
Attach an explicit Deny policy with a NotAction condition to the IAM role.
Why it fails: Attaching a policy with a NotAction condition can inadvertently lock out legitimate administrative access and fails to specifically target the issuance time of active temporary security tokens already distributed to the attacker.
- C
Attach an explicit Deny policy combined with the aws:TokenIssueTime condition to invalidate active STS sessions.
Evaluating the aws:TokenIssueTime condition against the exact moment of compromise within an explicit Deny policy forces AWS Security Token Service to reject all pre-existing temporary sessions derived from that specific role immediately.
- D
Disable the trust relationship policy on the IAM role to stop incoming assume-role requests.
Why it fails: Modifying the trust relationship prevents new assume-role requests from succeeding, but it does not invalidate temporary credentials that have already been successfully generated and issued to the attacker prior to the change.