Security and Compliance
441 questions
A financial services organization is deploying AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to enable single sign-on (SSO) for its cloud-based workloads. According to the AWS Shared Responsibility Model, which of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A retail company hosts its e-commerce website on Amazon Elastic Compute Cloud (Amazon EC2) instances. Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?
An online gaming studio is deploying a multiplayer game database using Amazon RDS for PostgreSQL. To meet security compliance standards, the studio must define the security boundaries between their team and AWS. Which of the following operational tasks remains the responsibility of the customer under the AWS Shared Responsibility Model?
A financial services institution deploys an AWS Outposts rack in its on-premises data center to run latency-sensitive algorithmic trading applications. Under the AWS Shared Responsibility Model, which TWO tasks are the responsibility of the customer?
Select all that apply
A financial technology startup is preparing for a compliance audit. An external auditing firm requires temporary, read-only access to the startup's AWS resources. The external auditors do not possess AWS accounts, and the startup's security policy strictly prohibits creating permanent IAM users for third-party entities. Which of the following is the most secure, AWS-recommended method to grant the auditors access?
A healthcare company is preparing for an external audit and must retrieve AWS security and compliance documents, such as the AWS Service Organization Control (SOC) reports. Which AWS portal provides on-demand, self-service access to these agreements and reports?
A healthcare technology company is hosting its customer portal on AWS. The static frontend files are stored in an Amazon S3 bucket, and the backend application is exposed via Amazon API Gateway. Under the AWS Shared Responsibility Model, which of the following security tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A software startup wants to allow a third-party vendor to run automated test suites against resources in its AWS development account. The vendor requires programmatic access for a limited time, and the startup must ensure that no long-term credentials are shared or stored. Which of the following is the most secure AWS-recommended method to grant this access?
An educational institution uses Amazon Simple Storage Service (Amazon S3) to store student records. Under the AWS Shared Responsibility Model, which of the following are responsibilities of the customer? (Select TWO.)
Select all that apply
A company has recently created a new AWS account. To ensure the account is secure, which two actions should the administrator perform on the AWS account root user? (Select TWO.)
Select all that apply
A university database administrator needs to grant an administrative application running on a local, on-premises server the ability to read metadata from an Amazon DynamoDB table. Additionally, a new junior administrator has joined the team to assist with day-to-day configuration. Which of the following actions align with the AWS recommended best practices for IAM and access control? (Select TWO.)
Select all that apply
A real estate platform uses Amazon DynamoDB to store property listing details. Under the AWS Shared Responsibility Model, which of the following security tasks is the sole responsibility of the customer?
A media streaming company uses Amazon DynamoDB to store user watch histories and profiles. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
An enterprise client in the financial sector is undergoing an annual Payment Card Industry Data Security Standard (PCI DSS) compliance audit. The external auditors require official proof of compliance for the physical and environmental security controls of the AWS data centers where the client's applications are hosted. Which AWS service should the security team use to obtain the necessary reports, and how is the responsibility for physical security partitioned in this context?
A healthcare startup must verify that AWS infrastructure meets compliance regulations for HIPAA and obtain SOC 2 reports for its investors. Which two tasks can the startup perform directly within AWS Artifact?
Select all that apply
A media company is migrating its user authentication store to Amazon DynamoDB. The company must comply with strict industry data security standards. Under the AWS Shared Responsibility Model, which two security tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
An application running on an Amazon EC2 instance needs to securely access files in an Amazon S3 bucket. According to AWS security best practices, which IAM entity should be attached to the EC2 instance to grant these permissions without storing long-term credentials?
An organization wants to configure an application running on an Amazon EC2 instance to read files from an Amazon S3 bucket. The application must not store long-term AWS credentials on the instance. Which of the following solutions represents the AWS-recommended best practice to grant the necessary permissions?
An online education platform is expanding its services to support medical residency programs and needs to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA). To do this, the platform's administrator needs to review AWS security documentation and formally accept the AWS Business Associate Addendum (BAA). Which of the following tasks can the administrator perform using AWS Artifact to meet these requirements? (Select TWO.)
Select all that apply
A retail company plans to expand its online operations to Europe and must verify that the underlying AWS infrastructure complies with the General Data Protection Regulation (GDPR). Which AWS service should the company use to download official AWS compliance reports and accept agreements?