Security and Compliance
441 questions
A gaming company is deploying multiplayer session backends on Amazon Elastic Compute Cloud (Amazon EC2) instances. The system requires temporary outbound ports to be opened dynamically to send traffic back to clients. The security team wants to ensure that any outbound response traffic for established inbound connections is allowed automatically without needing to define explicit outbound rules. Additionally, these rules must apply directly at the instance level. Which AWS network security feature should the company use to meet these requirements?
A digital art platform stores high-resolution images in an Amazon S3 bucket. The platform's compliance team requires all stored images to be encrypted at rest. The platform wants a fully managed solution where AWS handles the maintenance, clustering, and scaling of the underlying hardware security modules (HSMs), while the customer manages access policies for the encryption keys. Which AWS service should the platform use to meet this requirement?
A company wants to allow its corporate employees to log in to the AWS Management Console using their existing Active Directory credentials. The security team wants to avoid the administrative overhead of creating and managing individual IAM users for each employee. Which of the following is the AWS-recommended approach to grant this access?
A financial services firm hosts a reporting database on Amazon EC2 instances in a private subnet. A cloud practitioner needs to configure network security controls to protect the database. They must implement both a security group and a network access control list (network ACL). Which of the following statements correctly describe the behavior of these security controls? (Select TWO.)
Select all that apply
A media production company has migrated its collaborative design assets from on-premises storage to Amazon FSx for Windows File Server. Under the AWS Shared Responsibility Model, which of the following operational tasks are the sole responsibility of the customer? (Select TWO.)
Select all that apply
An organization has just created a new AWS account and is planning its initial security and access control setup. The IT manager needs to secure the account access and configure day-to-day administrative privileges. Which of the following actions align with AWS security best practices for managing access in this scenario? (Select TWO.)
Select all that apply
A research laboratory is building a web application on AWS that handles sensitive clinical trials data. The regulatory authority requires the laboratory to encrypt all trial results at rest using dedicated, single-tenant hardware security modules (HSMs) that they control directly. They must also ensure that database credentials are encrypted and automatically rotated. Which of the following AWS services should the laboratory use to meet these requirements? (Select TWO.)
Select all that apply
A financial technology company is using Amazon Cognito user pools to manage customer authentication and authorization for its mobile banking application. Under the AWS Shared Responsibility Model, which of the following is a responsibility of the customer?
A SaaS company is hosting a collaborative document editing application on Amazon EC2 instances. The system administrator wants to allow incoming HTTP/HTTPS traffic to the EC2 instances, ensuring that any corresponding outbound response traffic is automatically permitted regardless of outbound rules. Which AWS network security feature should be configured to meet this requirement?
A media streaming company is storing user account information in Amazon S3 and database backups in Amazon RDS. The company's compliance policy requires all of this data to be encrypted at rest. According to the AWS Shared Responsibility Model, which of the following is a customer responsibility in this scenario?
A biotechnology startup uses Amazon DynamoDB to store and query gene sequencing metadata. To comply with industry security regulations, the startup must implement strict access control and verify compliance of the cloud environment. Under the AWS Shared Responsibility Model, which of the following is a responsibility of the customer?
A company is designing the network security architecture for a new web application deployed across multiple subnets in a Virtual Private Cloud (VPC). The cloud practitioner needs to configure instance-level firewalls that automatically allow return traffic for established connections, as well as subnet-level firewalls where rules must be explicitly configured for both inbound and outbound traffic.
Which of the following AWS network security features should be configured to meet these requirements? (Select TWO.)
Select all that apply
A financial services company is deploying an application on AWS. The application will store credit card transactions in an Amazon S3 bucket and use Amazon RDS for MySQL to manage active customer accounts. The company's compliance policy requires all data to be encrypted at rest and encrypted in transit.
According to the AWS Shared Responsibility Model, which two of the following actions are the responsibility of the customer? (Select TWO.)
Select all that apply
An AWS IAM user has two identity-based policies attached to their identity. The first policy explicitly allows the 's3:GetObject' action on all Amazon S3 resources, while the second policy explicitly denies the 's3:GetObject' action on a specific S3 bucket named 'financial-records'. Which of the following describes the final access decision when the user attempts to retrieve an object from the 'financial-records' bucket?
A startup is establishing its initial AWS environment and wants to secure access controls for its development team and applications running on Amazon EC2. Which of the following actions represent AWS-recommended security best practices? (Select TWO)
Select all that apply
A company is using Amazon ElastiCache (Redis OSS) to cache session data for a high-traffic web application. Under the AWS Shared Responsibility Model, which of the following are responsibilities of the customer? (Select TWO.)
Select all that apply
A digital publishing company hosts its content management system on Amazon Elastic Compute Cloud (Amazon EC2) instances within a public subnet. Following a security audit, the team needs to implement a rule that blocks a specific list of malicious IP addresses from reaching any resources within that subnet. Additionally, the security team notes that the control must evaluate both inbound and outbound traffic separately since it does not automatically track connection states. Which AWS resource should the company configure to meet these requirements?
A ride-sharing company is deploying an application on AWS that processes passenger location coordinates. To ensure data privacy, the developer wants to encrypt this coordinate data while it is transmitted from the passenger's mobile app to the application backend on AWS. Under the AWS Shared Responsibility Model, which of the following is the customer's responsibility in this scenario?
A healthcare provider deploys AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to manage employee access to clinical applications. Under the AWS Shared Responsibility Model, which two tasks are the sole responsibility of the customer? (Select TWO.)
Select all that apply
A logistics company is hosting a dispatch coordinate management system on Amazon EC2 instances within a Virtual Private Cloud (VPC). A security administrator needs to implement a network security design that meets two criteria:
1. Block a list of specific malicious IP addresses at the subnet boundary before the traffic reaches any resources.
2. Automatically allow return traffic for any authorized inbound connections to the EC2 instances without needing to configure outbound rules.
Which of the following configurations should the administrator implement to meet these requirements? (Select TWO.)
Select all that apply