Security and Compliance
441 questions
A startup is preparing for a security audit and needs to generate a report showing who made specific API requests to modify their Amazon EC2 instances over the last thirty days. Which AWS service should the startup use to retrieve this API transaction history?
An online retail company is expanding its operations to new regions and must verify that the underlying AWS infrastructure meets both PCI DSS and ISO 27001 standards. Which of the following actions should the company take to verify AWS compliance and clarify security boundaries? (Select TWO.)
Select all that apply
A business analyst is configuring an Amazon Simple Storage Service (Amazon S3) bucket to store financial reports. The company requires that all objects in the bucket be encrypted at rest. Under the AWS shared responsibility model, which of the following tasks is the responsibility of the customer?
A financial technology firm wants to enhance its operational visibility and security auditing on AWS. The operations team needs to collect and search log files generated by their application running on Amazon EC2 instances, and trigger automated alerts when system errors are detected. Simultaneously, the security team needs to audit all administrative API requests made to AWS resources to identify which user made specific configuration changes. Which AWS services should the firm implement to fulfill these two requirements? (Select TWO.)
Select all that apply
A financial services company needs to investigate an incident where a critical Amazon RDS database instance was unexpectedly deleted. The security team must identify the specific IAM user who initiated the deletion, the exact time of the API call, and the source IP address of the request. Which AWS service should the security team use to retrieve this historical record of API activity?
A logistics company is migrating its application to Amazon EC2 instances. The security team needs to implement a logging and monitoring strategy that addresses two requirements: First, they must monitor application-specific log files generated on the EC2 instances for pattern matches and automatically notify administrators if error rates spike. Second, they must continuously analyze AWS API calls and network activity to detect potential security threats, such as compromised credentials or communication with known malicious IP addresses. Which TWO AWS services should the company implement to meet these requirements? (Select TWO.)
Select all that apply
A company wants to integrate a third-party security auditing application that runs on an external, non-AWS platform. The application requires read-only access to the company's AWS resource configurations. Which of the following is the AWS-recommended best practice to grant this access securely?
A logistics company is migrating its supply chain database to AWS. The compliance team needs to verify how regulatory compliance is managed under the AWS Shared Responsibility Model. Which of the following compliance-related activities is the sole responsibility of AWS?
A healthcare analytics company is migrating its data warehousing workloads to Amazon Redshift to perform complex queries on patient data. According to the AWS Shared Responsibility Model, which two of the following security and operational tasks are the responsibility of the customer?
Select all that apply
A company is configuring a Virtual Private Cloud (VPC) to host a new application. The security administrator wants to implement a defense-in-depth strategy by combining instance-level firewall protection with subnet-level firewall protection. Which of the following statements correctly describe the characteristics of Security Groups and Network Access Control Lists (Network ACLs)? (Select TWO.)
Select all that apply
A company's security team needs to define a custom set of permissions for their database administrators. The policy must be reusable across multiple IAM groups, support version history, and allow for easy rollbacks if a change causes issues. Which type of IAM policy should the security team implement to meet these requirements?
A digital marketing agency needs to implement security measures for its AWS infrastructure. The agency wants to continuously monitor its AWS accounts for unauthorized behavior and malicious activity. Additionally, they need to scan their Amazon Elastic Container Registry (Amazon ECR) container images for software vulnerabilities. Which two AWS services should the agency use to meet these requirements? (Select two.)
Select all that apply
An organization is setting up access controls for a new application developer who needs to manage Amazon S3 buckets and Amazon EC2 instances. Which of the following is the AWS-recommended method to configure this access?
A company is implementing a data protection policy for its applications running on AWS. The security team needs to understand the division of responsibility for data protection under the AWS Shared Responsibility Model.
Which of the following are responsibilities of the customer? (Select TWO.)
Select all that apply
An online education platform needs to implement a security and monitoring strategy for its AWS environment. The security team must meet two primary requirements: first, they must keep a complete history of all API calls made within their AWS account for auditing purposes; second, they need to continuously monitor their AWS accounts and workloads for malicious activity and unauthorized behavior, such as potential cryptocurrency mining. Which AWS services should the company implement to meet these requirements? (Select TWO.)
Select all that apply
Which of the following AWS Identity and Access Management (IAM) components is specifically designed to provide temporary security credentials for AWS services or federated users?
A financial institution is deploying a payment gateway on AWS. The institution's compliance policy dictates that all customer transactions must be encrypted at rest using single-tenant cryptographic hardware under the institution's exclusive control. Additionally, all transactional data must be encrypted in transit across all application tiers.
Under the AWS Shared Responsibility Model, which of the following are responsibilities of the customer to meet these security requirements? (Select TWO.)
Select all that apply
A startup is configuring access permissions for a newly deployed multi-tier application. An Amazon EC2 instance needs to retrieve configuration files from an Amazon S3 bucket, while an external systems administrator requires temporary access to troubleshoot EC2 configurations. Which two of the following options represent AWS-recommended practices for securing these access requirements?
Select all that apply
An education technology company is preparing for an independent audit to verify its compliance with international security standards. The compliance team needs to obtain official documentation regarding the security of the AWS physical infrastructure and understand which compliance tasks remain the responsibility of the company. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A company wants to grant a team of new developers access to manage AWS resources. All developers in the team require the same permissions. Which of the following actions align with AWS Identity and Access Management (IAM) security best practices to accomplish this? (Select TWO.)
Select all that apply