Security and Compliance
441 questions
A company is migrating its database to Amazon RDS. Under the AWS Shared Responsibility Model, which task is the responsibility of the customer?
A company wants to secure its Virtual Private Cloud (VPC) by controlling traffic entering and leaving its subnets. The security team needs a solution that evaluates traffic using stateless rules at the subnet boundary. Which AWS resource or feature should the company configure to achieve this?
A healthcare technology company runs its patient portal on a fleet of Amazon EC2 instances. The security compliance officer needs to ensure that the operating systems of these instances are regularly checked for software vulnerabilities and unintended network exposure. According to the AWS Shared Responsibility Model, which customer-managed action should the company take to meet this requirement?
A pharmaceutical research firm must encrypt clinical trial data stored in Amazon S3. The firm's compliance policy mandates that encryption keys must be generated and stored on dedicated, single-tenant hardware security modules (HSMs) directly controlled by the firm's security team. However, the firm still wants to leverage the automated, seamless server-side encryption features of Amazon S3 without custom application-side coding. Which of the following approaches meets these requirements?
An online retail company is designing a security and operational monitoring strategy. The company needs to audit administrative API activities (such as who created a resource or modified access policies) and track EC2 instance CPU utilization to trigger alerts if performance degrades. Which AWS services should the company use to meet these two requirements?
An enterprise is migrating its legacy web application to AWS and decides to run it inside Docker containers using AWS Fargate. Under the AWS Shared Responsibility Model, which two of the following operational tasks are the responsibility of the customer?
Select all that apply
A company needs to grant an external auditor temporary access to view the configuration of their AWS resources. The auditor does not have an AWS account but has a corporate identity provider (IdP). Which of the following is the most secure AWS-recommended method to grant this access?
A retail company wants to track and record all API activity and user actions across its AWS account for compliance auditing. The company needs to know which user initiated an action, the time of the event, and the IP address from which the request was made. Which AWS service should the company use to meet this requirement?
A company is hosting a secure web application on Amazon EC2 instances located in a public subnet. To implement a defense-in-depth strategy, the network team uses both Security Groups and Network Access Control Lists (Network ACLs). External clients must be allowed to access the application over HTTPS (port 443), while all other inbound traffic must be blocked. Which two configurations are required to allow this traffic to flow successfully to and from the instances?
Select all that apply
A cloud administrator wants to configure network security for a new application deployment in a Virtual Private Cloud (VPC). Which TWO of the following statements correctly describe the behavior and boundaries of Security Groups and Network Access Control Lists (Network ACLs)? (Select TWO.)
Select all that apply
A business analyst needs temporary access to run a weekly report on billing data in the AWS Management Console. To follow the principle of least privilege and avoid managing long-term credentials, which approach should the administrator use?
A media streaming company wants to implement network-level monitoring and real-time security alerts for its virtual private cloud (VPC) environment. The company has two requirements:
1. Capture detailed information about the IP traffic going to and from network interfaces in the VPC to audit security group rule effectiveness.
2. Create automated alarms that notify the security operations team if there is a sudden spike in unauthorized connection attempts (such as HTTP 403 errors or failed SSH attempts).
Which combination of AWS features or services should the company configure to meet these requirements? (Select TWO.)
Select all that apply
A gaming studio needs to implement a security logging and monitoring strategy for its multiplayer game backend. The studio has two primary requirements: first, it must track and audit all administrative API operations and configuration changes across its AWS account for compliance purposes; second, it must monitor compute instance performance metrics (such as CPU usage) and trigger real-time alerts when threshold limits are exceeded. Which of the following AWS services should the gaming studio use to meet these requirements? (Select TWO.)
Select all that apply
A financial services company is deploying a database workload using Amazon Relational Database Service (Amazon RDS). Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?
A smart agriculture startup is deploying IoT soil sensors that upload environmental telemetry data to AWS. The startup's compliance team requires a detailed ledger of who accessed or modified the AWS resources hosting this telemetry, while their operations team needs real-time alerts if telemetry ingestion metrics drop below a certain threshold. Which AWS services should the startup implement to meet both the auditing and operational alerting requirements?
A healthcare startup is preparing for an external audit to verify compliance with HIPAA and SOC standards for its platform hosted on AWS. Which of the following actions should the startup take to meet these compliance requirements? (Select TWO.)
Select all that apply
An organization wants to configure secure access to its AWS resources. They need to grant an application running on an Amazon EC2 instance access to an Amazon S3 bucket, and they need to configure access for a new team of system administrators. Which of the following AWS Identity and Access Management (IAM) practices should the organization implement? (Select TWO.)
Select all that apply
A gaming startup is launching a new multiplayer game on AWS. To ensure security compliance and operational stability, the startup needs to accomplish two tasks: first, they must log and audit all administrative API operations and user activity within their AWS account; second, they must monitor system performance metrics (such as CPU utilization of their virtual servers) and receive alerts if performance drops. Which TWO AWS services should the startup implement to meet these requirements? (Select TWO)
Select all that apply
Under the AWS shared responsibility model, a company wants to ensure that its data is encrypted at rest. Which two tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
An administrator needs to assign similar security permissions to ten new developers in an organization. Which of the following are AWS-recommended practices for managing these permissions? (Select TWO.)
Select all that apply