問題文
A long-lived service identity that has only ever listed objects in one bucket suddenly enumerates permissions across several accounts. Why is this the kind of activity Wiz Defend surfaces?
選択肢
- Because the identity has broad permissions, and any use of an identity with broad permissions is reported regardless of what it did, which is why narrowing permissions is the only way to reduce the volume of this category of detection.
- Because permission enumeration is always denied by the provider, and denied operations are the only ones that produce detections.
- Because service identities are not permitted to make any calls other than the ones written in their documentation, so any undocumented call is treated as a failure of change control and reported as such.
- Because the operations depart from what that identity has been observed doing, and a sudden interest in what it is allowed to do is a common early step after credentials are taken.