Security and Compliance
441 questions
An automotive manufacturer is auditing its connected-vehicle telemetry platform hosted on AWS to verify compliance with ISO/IEC 27001 standards. Under the AWS Shared Responsibility Model, which compliance-related activity is the sole responsibility of the customer?
A food delivery startup wants to continuously monitor its AWS accounts and workloads for malicious activity and unauthorized behavior, such as potential data exfiltration or unusual API calls. Which AWS service should the startup use to meet this requirement?
A logistics provider wants to identify potential security threats and malicious activity across their AWS accounts by analyzing VPC Flow Logs, DNS logs, and CloudTrail events. Which AWS service should they use for this continuous threat monitoring?
A utility company is deploying an IoT smart-grid application on AWS. The application ingests telemetry data from millions of smart meters over the public internet and stores the processed records in an Amazon S3 bucket. The company's compliance policy requires all data to be encrypted both in transit and at rest.
According to the AWS Shared Responsibility Model, which of the following actions are the responsibility of the customer to meet these security requirements? (Select TWO.)
Select all that apply
A logistics and package delivery company runs its route optimization software on a fleet of Amazon EC2 instances. The cybersecurity team wants to implement a security solution to achieve two goals: automatically scan the EC2 instances for known software vulnerabilities, and continuously monitor the AWS account for threat patterns such as credential theft or anomalous API activity. Which AWS services should the company use to meet these requirements? (Select two.)
Select all that apply
An e-commerce startup is designing a secure network environment within a Virtual Private Cloud (VPC). To protect their resources, they plan to use both Security Groups and Network Access Control Lists (Network ACLs). Which two of the following statements correctly describe the characteristics or behavior of these network security features?
Select all that apply
A government contractor is building a secure document storage platform on AWS for a federal agency. To satisfy the agency's security requirements, the contractor must verify that the underlying AWS infrastructure complies with the Federal Risk and Authorization Management Program (FedRAMP) standards. Which action should the contractor take to obtain the official AWS FedRAMP authorization documents?
A startup is deploying a new serverless application using AWS Lambda to process user uploads. In accordance with the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the startup?
A mobile gaming studio hosts its backend matchmaking services on a fleet of Amazon EC2 instances. Before releasing a major update, the development team wants to scan these virtual servers for known software vulnerabilities, unintended network accessibility, and packages that do not comply with security best practices. Which AWS service is designed to automatically perform these vulnerability assessments?
A global financial technology (FinTech) company is preparing to launch a payment processing application on AWS. To meet regulatory compliance, the company needs to verify the physical security standards of the AWS data centers and retrieve the latest AWS System and Organization Controls (SOC) 1 report. Which of the following actions should the company take? (Select TWO.)
Select all that apply
A company is setting up AWS access for a team of developers who need to manage cloud resources through the AWS Management Console and execute command-line scripts locally. The company wants to integrate access with their existing corporate identity provider and ensure that developers do not store long-term credentials on their local workstations. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A startup is deploying a web application on Amazon EC2 instances. The security team needs to continuously scan these EC2 instances for software vulnerabilities and unintended network exposure. Additionally, they need to monitor their AWS accounts for malicious activity and unauthorized behavior.
Which of the following AWS services should the startup use to meet these requirements? (Select two.)
Select all that apply
A company wants to establish baseline visibility for its new AWS account. The company has two requirements: first, it must record a history of all API calls and user activity for security compliance auditing; second, it must track infrastructure performance metrics (such as CPU utilization) and send alerts when resource limits are exceeded. Which of the following AWS services should the company use to meet these requirements? (Select TWO.)
Select all that apply
A financial services firm runs compliance monitoring agents on Amazon EC2 instances within a dedicated subnet. These agents must establish outbound connections to an external regulatory API on port to upload audit logs. The security team implements a strict Network Access Control List (Network ACL) for the subnet, adding an outbound rule that permits traffic to the API's IP range on TCP port . No inbound rules are added to the Network ACL. The associated Security Groups are left at their default settings (allowing all outbound traffic and no inbound traffic). During testing, the agents fail to establish a connection with the API.
Which modification is required to allow this communication while maintaining the principle of least privilege?
A company is setting up its security guidelines for access management in AWS. The IT manager wants to enforce Multi-Factor Authentication (MFA) to protect the account's resources. According to AWS security best practices, which of the following identities should have MFA enabled? (Select TWO.)
Select all that apply
A security team needs to monitor and audit IP traffic routing through network interfaces in a Virtual Private Cloud (VPC) to investigate network connectivity issues. Which AWS feature should the team enable to collect this network traffic information?
A retail company is migrating its customer database and product catalogs to Amazon S3. The company's security policy requires that all data stored in the cloud must be encrypted at rest. Under the AWS Shared Responsibility Model, which of the following is a customer responsibility regarding this encryption requirement?
An automotive telemetry platform processes vehicle sensor data using a fleet of Amazon EC2 instances. The security team needs to implement a solution to scan these EC2 instances for known software vulnerabilities and continuously monitor the AWS accounts for malicious activity or unauthorized behavior. Which two AWS services should the platform use to meet these requirements? (Select two.)
Select all that apply
A logistics company uses Amazon Simple Queue Service (SQS) to decouple its order processing systems. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer?
Select all that apply
An enterprise client is designing a security monitoring architecture for their AWS environment. The client must satisfy two requirements:
1. Detect and alert in real-time when administrative actions, such as the deletion of an Amazon S3 bucket, are initiated by any user or role.
2. Continuously monitor the network activity of Amazon EC2 instances to identify active threat behaviors, such as outbound port scanning or communication with known malicious command-and-control servers.
Which combination of AWS services should the client implement to meet these requirements?