Security and Compliance
441 questions
A multi-department enterprise wants to secure its AWS environment by implementing the principle of least privilege and reducing security risks associated with credential management. The administrator must configure access for both developers (human users) and applications running on Amazon EC2 instances (machine identities). Which two methods represent AWS security best practices for managing these identities? (Select TWO.)
Select all that apply
A retail corporation is designing a hybrid cloud architecture and needs to secure its data at rest on AWS. The security compliance policy states that the keys used for encrypting financial transactions must be stored on dedicated, single-tenant cryptographic hardware controlled entirely by the customer. However, for standard application logs stored in Amazon S3, the company wants to use a fully managed service where AWS handles the physical hardware management, but the customer retains control over key policies and rotation.
Which two of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A government contractor is deploying an application on AWS that handles classified public safety records. Compliance regulations mandate that all data at rest must be encrypted using cryptographic keys stored inside dedicated, single-tenant hardware security modules (HSMs) that are physically and logically isolated. Which option correctly identifies the AWS service that meets this requirement and the customer's responsibility for that service under the AWS Shared Responsibility Model?
A retail company is migrating its customer database to Amazon RDS for PostgreSQL to reduce administrative overhead. Which two of the following tasks are the responsibility of the customer under the AWS Shared Responsibility Model?
Select all that apply
A company's backend application instances in Subnet A must query a PostgreSQL database running on an Amazon EC2 instance in Subnet B. To secure this traffic, a network administrator is configuring network access control lists (Network ACLs) for Subnet B and a security group for the database instance. Which two configuration steps are required to allow this database traffic while maintaining the principle of least privilege? (Select TWO.)
Select all that apply
A global online learning platform hosts virtual classrooms on Amazon EC2 instances and stores course materials in Amazon S3 buckets. The security team needs to implement a solution that continuously scans their EC2 instances for software vulnerabilities and unintended network exposure. Additionally, they must identify potential security threats across their AWS accounts, such as cryptocurrency mining or brute-force attacks, using machine learning and threat intelligence. Which combination of AWS services will address these requirements? (Select two.)
Select all that apply
A retail company is auditing its AWS account to align with AWS Identity and Access Management (IAM) security best practices. Currently, developers use shared credentials for daily administrative tasks, and multi-factor authentication (MFA) is not enabled on the account. Which of the following actions should the company perform to secure their environment? (Select TWO.)
Select all that apply
A logistics company containerizes its shipment tracking application and deploys it on AWS Fargate. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
An enterprise is establishing access policies for a newly deployed reporting service hosted on an Amazon EC2 instance and a database administrator who requires CLI access for database maintenance. Which of the following identity configurations represent AWS-recommended practices? (Select TWO.)
Select all that apply
A medical device manufacturer is deploying an IoT monitoring system on AWS. The quality assurance team must retrieve official AWS compliance reports, such as ISO certificates, to complete their regulatory filing. Which AWS service provides on-demand access to these security and compliance reports?
A fintech startup is deploying a public-facing REST API using Amazon API Gateway to expose financial transaction data. The API must be secured against unauthorized access, and all data transit must be encrypted. Under the AWS Shared Responsibility Model, which of the following tasks is the sole responsibility of the customer?
A research institute manages high-performance simulation applications running on a fleet of Amazon EC2 instances. The institute's security audit team requires a tool that can continuously scan the operating systems of these instances for known software vulnerabilities and analyze network paths to identify unintended exposure to the internet. Which AWS service is designed to perform these automated vulnerability assessments?
A financial services company uses Amazon S3 Glacier Flexible Retrieval to archive historical transaction records for compliance auditing. Under the AWS Shared Responsibility Model, which of the following security and operational tasks are the sole responsibility of the customer? (Select TWO.)
Select all that apply
A company hires a new systems administrator who needs daily access to manage Amazon EC2 instances and Amazon RDS databases. Which of the following is the AWS-recommended best practice for granting this administrator access?
A cloud architect is designing the network security for a SaaS application's web servers running on Amazon EC2 instances in a VPC. To establish a defense-in-depth strategy, the architect plans to use both Security Groups and Network Access Control Lists (Network ACLs). Which of the following statements correctly describe the characteristics and differences between these two firewall layers? (Select TWO.)
Select all that apply
A software-as-a-service (SaaS) provider is preparing for an ISO 27001 certification audit of its order management application. To satisfy the auditors, the company must verify that the underlying AWS physical infrastructure is certified and identify which specific AWS services in their deployment are covered under this compliance standard. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A global retail company is preparing for an annual PCI-DSS audit of its payment processing workload hosted on AWS. The compliance team needs to gather official documentation proving the physical security compliance of AWS data centers and establish a workflow to continuously audit and evaluate AWS resource configurations against regulatory standards. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A logistics company is migrating its tracking application to AWS and needs to set up a comprehensive monitoring and auditing solution. The company wants to track all administrative actions and API modifications made to their AWS resources for compliance auditing. Additionally, they need to collect system-level metrics, such as CPU utilization from their Amazon EC2 instances, and automatically send alerts if thresholds are exceeded.
Which of the following AWS services should the company configure to meet these requirements? (Select TWO.)
Select all that apply
A financial technology company is preparing for a security audit and must establish robust auditing and monitoring controls. The company needs to maintain a complete history of all API calls made within their AWS environment for compliance verification. Additionally, the security team needs to receive immediate notifications if any unauthorized modifications are made to network security configurations, such as security group rules.
Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A financial technology startup is setting up its AWS environment. An application running on Amazon ECS tasks needs to retrieve records from an Amazon DynamoDB table, while an external compliance auditor requires weekly console access to inspect security configurations without modifying any resources. Which TWO of the following identity and access management actions should the startup implement to meet these requirements securely? (Select TWO.)
Select all that apply