All practice questions
1473 questions
A food delivery platform is preparing for an audit and needs to download official AWS compliance documents, such as SOC and PCI DSS reports, while also verifying its security responsibilities. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A media streaming company wants to enhance its security posture. The security team needs a solution to achieve two goals: first, they want to continuously monitor their AWS accounts for malicious activity and unauthorized behavior; second, they want to perform automated security assessments on their Amazon EC2 instances to identify software vulnerabilities. Which of the following AWS services should the company use to meet these requirements? (Select two.)
Select all that apply
A financial institution deploying a payment processing application on AWS wants to ensure compliance with the Payment Card Industry Data Security Standard (PCI-DSS). Under the AWS Shared Responsibility Model, which compliance-related task is the sole responsibility of the customer?
A quality assurance team at a financial software company currently maintains a permanent, always-on staging environment for testing weekly application updates. Because this environment is idle for most of the week, the team decides to use AWS CloudFormation to automatically spin up a brand new, identical staging environment at the start of a test run and completely destroy it once testing is complete. Which design principle of the AWS Cloud is directly demonstrated by this approach?
A health-tech organization needs to secure its AWS environment to meet compliance standards. The compliance team requires the organization to implement a mechanism that records all historical API activities to identify who made specific configuration changes to security groups, and also run automated scans on their Amazon EC2 instances to check for known software vulnerabilities and package exposures. Which combination of AWS services or responsibility frameworks will meet these requirements?
A startup has just created its first AWS account and wants to secure the account root user. Which of the following actions represent AWS security best practices for protecting the account root user? (Select TWO.)
Select all that apply
A logistics company, SwiftRoute Logistics, plans to migrate its on-premises package tracking application to the AWS Cloud. The migration team will move the application's web servers directly to Amazon EC2 instances without modification, but will transition its self-managed relational database to Amazon Relational Database Service (Amazon RDS) to eliminate database administration tasks. Which migration strategy is SwiftRoute Logistics using?
A software-as-a-service (SaaS) provider wants to implement Amazon Inspector to enhance the security posture of its application hosting environment. Which of the following tasks can Amazon Inspector perform to assist the provider with vulnerability management? (Select two.)
Select all that apply
A company is developing a new mobile application and decides to store customer profile data in Amazon DynamoDB. Under the AWS Shared Responsibility Model, which of the following tasks is the customer responsible for?
An enterprise wants to allow its employees to log in to the AWS Management Console using their existing corporate credentials managed by an on-premises identity provider. The security team mandates that employees must not have permanent AWS IAM user credentials. Which of the following IAM features or mechanisms should the enterprise use to implement this configuration?
A government transit agency runs a fleet of on-premises database servers and also hosts application servers on Amazon EC2. The agency needs to configure a nightly backup process that uploads database logs to a secured Amazon S3 bucket, while strictly adhering to the principle of least privilege and avoiding the use of long-term credentials on any server. Which TWO of the following configurations represent AWS-recommended security practices for this architecture?
Select all that apply
A retail company has a web application hosted on an Amazon EC2 instance that needs to read and write images to an Amazon S3 bucket. According to AWS security best practices, which of the following is the most secure method to grant the EC2 instance access to the S3 bucket?
A financial services company is setting up AWS access for its newly hired database administrators. The company wants to enforce the principle of least privilege, simplify permissions management as the team grows, and secure individual console access. Which two of the following actions represent recommended AWS Identity and Access Management (IAM) best practices to achieve this?
Select all that apply
A media company is migrating its video transcoding pipeline to AWS. The solution architect designs the system to use Amazon S3 to store raw uploads, which triggers an AWS Lambda function to process the video. The processed videos are then stored in a different S3 bucket. Additionally, the Lambda functions automatically scale out to handle thousands of concurrent uploads during peak hours and scale down to zero when there is no activity.
Which two design principles of the AWS Cloud does this architecture represent? (Select TWO).
Select all that apply
An independent software vendor (ISV) is transitioning its application from a traditional on-premises hosting model to AWS. Under the old model, the ISV had to invest heavily in purchasing physical servers and storage arrays before launch to ensure the application could support its projected user base. On AWS, the ISV plans to deploy resources on-demand and scale them dynamically. Which option correctly identifies the primary AWS Cloud benefit demonstrated by this shift, along with the correct financial or operational rationale?
A real estate platform is preparing for an external security audit and needs to download official compliance reports, such as ISO certifications and Service Organization Control (SOC) reports, to prove the security of the AWS infrastructure. Which AWS service should the platform use to access these documents?
A startup is developing a mobile application backend. The company wants to focus on writing application code and delivering features without spending time on provisioning, patching, or managing operating systems. To achieve this, they select AWS Lambda for compute and Amazon DynamoDB for database storage. Which AWS Cloud design principle is best demonstrated by this architectural decision?
A digital healthcare startup plans to host a patient telemetry application on AWS. To meet regulatory requirements, the startup needs to obtain the AWS ISO 27001 certification, accept the HIPAA Business Associate Addendum (BAA), and ensure that database records are encrypted. Which of the following actions should the startup take to meet these compliance and governance requirements? (Select TWO.)
Select all that apply
A media streaming company uses Amazon CloudFront to distribute video files to global users. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of AWS?
Select all that apply
A gaming studio wants to automatically identify software vulnerabilities and unintended network exposure on its Amazon EC2 instances. Which AWS service should the studio use to perform these security assessments?