A. Configure Lambda to assume a role in the management account with appropriate access to AWS. Most Voted
B. Configure Lambda to use the stored database credentials in AWS Secrets Manager and enable automatic rotation. Most Voted
C. Create a Lambda function to rotate the credentials every hour by deploying a new Lambda version with the updated credentials.
D. Use an SCP on the management account’s OU to prevent IAM users from accessing resources in the Service team’s account.
E. Enable AWS Shield Advanced on the management account to shield sensitive resources from unauthorized IAM access.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.