Security and Compliance
441 questions
A game development studio is deploying dedicated multiplayer game servers on Amazon Elastic Compute Cloud (Amazon EC2). According to the AWS Shared Responsibility Model, which two operational security tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A municipal public transit authority is migrating its ticketing database and web applications to the AWS Cloud. During an audit, the compliance officer asks who is responsible for configuring firewall rules (such as security groups) to protect the applications, and how the authority can verify AWS's physical infrastructure compliance. Which of the following statements correctly identifies the responsibility mapping and the service needed to retrieve the necessary AWS compliance reports?
An organization runs automated database backup scripts on its on-premises servers. These scripts need to upload backups to an Amazon S3 bucket. To comply with security best practices, the organization wants to avoid storing long-term access keys on the physical servers. Which IAM solution should the organization implement to grant these scripts secure, temporary access?
A newly hired cloud administrator needs to perform daily operational tasks in the AWS Management Console, such as configuring network settings and managing Amazon S3 buckets. Which AWS security best practice should be followed to grant these permissions?
A SaaS provider hosts its web application on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (Amazon ECR). The security team needs to implement automated tools to accomplish two tasks:
1. Continually scan the EC2 instances and container images for software vulnerabilities and unintended network exposure.
2. Monitor AWS account activity and network traffic to detect anomalous behavior, potential unauthorized access, and malicious threats.
Which two AWS services should the company use to meet these requirements? (Select two.)
Select all that apply
A media broadcasting company is preparing for an annual governance review of its cloud-based video archiving system. The governance team needs to acquire official AWS ISO 27001 certification documents and clarify how the security of AWS's physical infrastructure is validated. Which two of the following options represent correct actions or concepts that meet these requirements? (Select TWO.)
Select all that apply
A logistics company is building a package tracking system on AWS. The company's security policy requires that all package destination logs must be encrypted at rest. Which of the following are customer responsibilities for protecting this data? (Select TWO.)
Select all that apply
An online education platform is deploying a new serverless application using AWS Lambda functions. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A company is setting up a new AWS account and needs to organize access permissions for several system administrators and developers. According to AWS Identity and Access Management (IAM) best practices, which TWO statements correctly describe the characteristics and usage of IAM groups? (Select TWO.)
Select all that apply
A digital publishing company requires a solution to track changes made to its AWS infrastructure resources, specifically recording who made a configuration change and when. At the same time, the company needs to monitor application log files for specific error patterns and trigger automated alerts. Which AWS services are designed to address these requirements?
A multi-department enterprise is setting up its AWS environment. The security team must define access controls for two distinct groups: a finance audit team that requires read-only access to AWS billing information, and an operations team that needs to start, stop, and reboot Amazon EC2 instances. Which TWO of the following configurations represent AWS-recommended IAM best practices to implement this access? (Select TWO.)
Select all that apply
An organization is deploying a web application on Amazon EC2 instances. The security team must ensure that inbound HTTP traffic to port 80 is permitted, and that the corresponding outbound response traffic is automatically allowed back to the client without needing a corresponding outbound rule. Which AWS security feature should be configured to meet this requirement?
A retail company wants to store its weekly sales reports in Amazon Simple Storage Service (Amazon S3). To protect this data, they want to enable encryption at rest using cryptographic keys that are fully managed by AWS. Which AWS service is designed to easily create and manage these encryption keys?
A logistics company is using Amazon Simple Queue Service (SQS) to decouple its order processing systems. Under the AWS Shared Responsibility Model, which TWO of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A travel booking startup wants to establish a logging and monitoring workflow on AWS. The security team needs to audit and track all API calls and user changes made within the AWS account for compliance. The operations team needs to monitor the CPU usage of their Amazon EC2 instances and receive alerts if utilization goes above a threshold. Which AWS services should the startup implement to meet these requirements? (Select TWO.)
Select all that apply
A company wants to share a dataset stored in an Amazon S3 bucket with a partner organization's AWS account. The company wants to grant this access by attaching a policy directly to the S3 bucket itself, specifying who can access it. Which type of policy should the company use to meet these requirements?
A company is configuring a multi-tier web application within an Amazon VPC and needs to implement granular network security controls. The network architect plans to use a combination of Security Groups and Network Access Control Lists (Network ACLs) to secure the application instances and subnets. Which of the following statements correctly describe how Security Groups and Network ACLs handle inbound and outbound traffic? (Select TWO.)
Select all that apply
A software development firm is deploying its microservices-based application using Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A logistics company suspects that credentials for one of its administrative accounts have been compromised, leading to unauthorized resource creation in multiple AWS Regions. The security team wants to implement a service that continuously monitors their AWS accounts for malicious activity and anomalies, such as unauthorized API calls or unusual network traffic, without needing to write custom detection rules. Which AWS service should the company use to meet this requirement?
A startup is setting up an application on AWS and must encrypt its customer data at rest. According to the AWS Shared Responsibility Model, which of the following is the customer's responsibility regarding data protection?