All practice questions
1473 questions
A media company is looking for a way to continuously monitor its AWS accounts and workloads for malicious activities, such as cryptocurrency mining, unauthorized data access, or compromised credentials. The solution must automatically analyze data from AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to identify threats. Which AWS service should the company use to meet this requirement?
A retail company is migrating its inventory management system to AWS. The system runs on Amazon EC2 instances and requires permission to write to an Amazon DynamoDB table. Additionally, a team of developers requires access to perform administrative tasks. Which of the following actions represent AWS-recommended security practices for managing access in this scenario? (Select TWO.)
Select all that apply
A mobile game studio wants to launch a new multiplayer game. Instead of purchasing physical servers and hardware upfront in a traditional data center, the studio decides to host the game on AWS and pay for compute resources as they are consumed. Which of the following describes this financial shift?
A gaming studio is deploying a multiplayer matchmaking backend on AWS using Amazon DynamoDB to store player session states. Under the AWS Shared Responsibility Model, which two security-related tasks are the sole responsibility of the gaming studio?
Select all that apply
An enterprise wants to simplify permission management for its finance department. Currently, the IT team manually attaches permissions to each new financial analyst's AWS account, which has led to inconsistent access rights and administrative overhead. Which of the following is the AWS-recommended method to resolve this issue?
A company is setting up a new application on AWS and wants to establish baseline security logging and operational monitoring. They need to track user activity and API calls for auditing purposes, as well as collect and track performance metrics for their Amazon EC2 instances. Which of the following AWS services should the company use to meet these requirements? (Select TWO).
Select all that apply
A financial technology (FinTech) startup wants to accelerate its software development cycle by allowing developers to quickly provision test environments with various configurations. On-premises, obtaining these resources required a formal approval process and took several weeks. On AWS, developers can provision these environments within minutes using the AWS Management Console or AWS CLI. Which AWS Cloud benefit is directly illustrated by this scenario?
An organization is securing a proprietary database tier hosted on Amazon EC2 instances within a private subnet of a Virtual Private Cloud (VPC). The database must receive SQL traffic on TCP port from the application servers located in a public subnet, while ensuring strict network isolation at both the subnet and instance levels. Which two configuration steps are required to establish this network security architecture? (Select TWO.)
Select all that apply
A security team needs to monitor an AWS environment for active threats and unauthorized behavior. They require a solution that automatically analyzes AWS CloudTrail events, VPC Flow Logs, and DNS logs to identify activities like an Amazon EC2 instance communicating with a known malicious command-and-control server. The solution must be agentless and operate at the account level. Which AWS service should the security team use to meet these requirements?
A company wants to set up access for a new employee who needs to manage Amazon EC2 instances on a daily basis. The manager wants to follow AWS security best practices. Which of the following actions should the administrator take to grant the employee this access?
A digital marketing agency is launching a series of promotional campaigns that require temporary computing infrastructure. The agency wants to avoid making large upfront hardware payments and does not want to manage physical server infrastructure. Which of the following are official benefits of the AWS Cloud that directly align with these requirements? (Select TWO)
Select all that apply
A company is hosting a secure web application on Amazon EC2 instances within a VPC. The security team wants to allow incoming traffic on port (HTTPS) while blocking a specific range of known malicious IP addresses at the boundary before the traffic reaches any EC2 instance. They also need to ensure that the EC2 instances can send outbound response traffic back to clients. Which of the following network security configurations meets these requirements?
An enterprise is deploying an application on Amazon EC2 instances that needs to retrieve files from an Amazon S3 bucket. Which of the following configurations represent AWS Identity and Access Management (IAM) best practices for this scenario? (Select TWO.)
Select all that apply
A logistics company coordinates delivery routes using an application hosted on Amazon EC2 instances. The security team needs to implement a solution that continuously monitors the environment for active threats, such as instances communicating with known malicious command-and-control servers or performing unauthorized API actions. This monitoring must be performed without installing software agents or affecting application performance. Which AWS service should be used to meet these requirements?
Aegis Health is migrating its patient scheduling database to AWS. The database currently runs on an on-premises Microsoft SQL Server. The IT team wants to reduce database administration overhead, such as patching and backups, but does not want to change the database schema or write new application code. Which migration strategy should Aegis Health select to meet these requirements?
A local bakery chain plans to migrate its legacy inventory management application from on-premises servers to the AWS Cloud. By doing so, the company expects to eliminate the need to purchase physical hardware upfront.
Which two of the following represent the primary cloud economics benefits of this migration? (Select TWO.)
Select all that apply
A media streaming company uses Amazon CloudFront to distribute video content to users worldwide. Under the AWS Shared Responsibility Model, which two of the following security tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A startup is deploying a microservices application using AWS Lambda to process user registration data. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of AWS?
An online retailer wants to ensure that its billing application and its shipping notification application can operate independently. By inserting an Amazon Simple Queue Service (Amazon SQS) queue between the two applications, a delay in shipping notifications will not prevent billing transactions from completing. Which AWS Cloud design principle does this architecture demonstrate?
An automotive manufacturer is auditing its connected-vehicle telemetry platform hosted on AWS to verify compliance with ISO/IEC 27001 standards. Under the AWS Shared Responsibility Model, which compliance-related activity is the sole responsibility of the customer?