Design Secure Architectures Practice Question

Question

For a data ingestion service, an architect is reviewing MFA and federation requirement set 11. Which design choice best fits the requirement while following AWS architectural best practices?

Answer choices

  1. A. Place all components on a single large instance to simplify troubleshooting.
  2. B. Reduce long-lived credentials and protect privileged access.
  3. C. Use long-lived access keys in application configuration so services can call AWS APIs directly.
  4. D. Disable monitoring until the workload reaches steady production traffic.

Correct Answer

B. Reduce long-lived credentials and protect privileged access.

Explanation

The best answer applies MFA and federation: reduce long-lived credentials and protect privileged access. The other options increase operational risk, weaken security, or remove observability that an AWS Solutions Architect should preserve.

Question details

  • Difficulty: medium
  • Domain: Design Secure Architectures
  • Objective: MFA and federation

Practice more

Start Design Secure Architectures practice

Back to Design Secure Architectures