Question 1
A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup
operation that uses AWS Backup.
The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.
Which combination of steps will meet this new requirement? (Select THREE.)
To make backups resilient to compromised credentials in production accounts:
- AWS Backup Vault Lock (Compliance Mode): Prevents anyone, even root users or administrators with compromised credentials, from deleting backups. Compliance mode cannot be overridden. This is the primary defense against ransomware attacks.
- MFA Delete on backup storage S3 buckets: Requires multi-factor authentication to delete backup data, adding an additional layer of protection even if credentials are compromised. Prevents simple credential-based deletion.
- Deny-based IAM policies: Create explicit deny statements in SCPs or IAM policies that deny backup deletion and modification actions to production account roles. This prevents privilege escalation attacks from modifying permissions to allow deletion.
- Why these three together: Backup Vault Lock prevents deletion; MFA Delete adds verification requirement; IAM deny policies prevent permission changes. Layered defense ensures ransomware cannot destroy backups even with compromised privileged credentials.
This multi-layered approach addresses the specific threat of privileged credential compromise in production accounts.