AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard
A manufacturing company uses AWS IoT Core for managing a fleet of connected devices. A security engineer detects anomalous behavior from a device, indicating a potential compromise and unauthorized data exfiltration attempts. The engineer needs to immediately revoke the device's authorization to publish messages to AWS IoT Core and prevent it from connecting. Which action should be taken using AWS IoT Core features?
- ADelete the device's X.509 certificate from AWS Certificate Manager (ACM).
- BDisable the associated AWS IoT policy that grants publish and connect permissions.
- CDetach the X.509 certificate from the AWS IoT thing and then revoke the certificate.
- DModify the device's shadow document to set a 'disabled' status, which the device should heed.
Show answer & explanationAnswer & explanation
Correct answer: C. Detach the X.509 certificate from the AWS IoT thing and then revoke the certificate.
In AWS IoT Core, device authorization relies on X.509 certificates attached to IoT policies. Detaching the certificate from the IoT thing immediately revokes its permissions. Revoking the certificate itself further ensures it cannot be used again, even if reattached, providing comprehensive containment.
Why the other options are wrong
- A. Deleting a certificate from ACM doesn't directly revoke its use in IoT Core if it's already registered. IoT Core manages its own certificate store and policies.
- B. Disabling or modifying the IoT policy is a valid step, but detaching the certificate from the thing is a more direct and immediate way to revoke its authorization for that specific device.
- D. Device shadows are for state synchronization. While a device *should* heed a 'disabled' status, a compromised device might ignore it, making this an unreliable containment method for a security incident.
IoT Device Revocation
The process of immediately revoking an AWS IoT device's authorization to connect to AWS IoT Core and perform actions, typically by detaching and revoking its X.509 certificate.
- Uses X.509 certificates for authentication.
- Certificates are attached to IoT policies.
- Detaching and revoking the certificate is the most effective revocation method.
Memory trick: Certificates are the keys; detach and revoke to lock the device out.