Security and Compliance
441 questions
A startup is deploying a serverless backend application using AWS Lambda. Under the AWS Shared Responsibility Model, which TWO of the following tasks are the responsibility of the customer?
Select all that apply
A financial services company is setting up daily administrative access to their AWS infrastructure for a new operations team. To comply with security audits, they must ensure individual accountability and adhere to the principle of least privilege. Which of the following security practices should the company implement? (Select TWO.)
Select all that apply
A financial organization is deploying a microservices-based application using Amazon Elastic Container Service (Amazon ECS) on AWS Fargate. Under the AWS Shared Responsibility Model, which of the following are responsibilities of the customer? (Select TWO.)
Select all that apply
A retail enterprise is undergoing a Payment Card Industry Data Security Standard (PCI DSS) audit for its payment processing system hosted on AWS. The external auditors require evidence that the physical infrastructure of the AWS data centers hosting the services meets the required security standards. According to the AWS Shared Responsibility Model, which action should the retail enterprise take to meet this requirement?
A logistics company uses AWS Elastic Beanstalk to deploy and scale a web application. The platform automatically provisions Amazon EC2 instances, an Application Load Balancer, and an Auto Scaling group to support the workload. The company's security team is defining the operational boundaries for securing this deployment.
Which of the following tasks remains the sole responsibility of the customer under the AWS Shared Responsibility Model?
A company needs to grant a newly hired customer support team read-only access to specific Amazon S3 buckets. Which of the following identity and access management (IAM) practices should the administrator use to configure this access? (Select TWO.)
Select all that apply
A healthcare startup stores encrypted patient records in a private Amazon S3 bucket in its production AWS account. An internal compliance officer (an IAM user in the same account) requires read-only access to these records for auditing. Simultaneously, an automated diagnostic application running in an external partner's AWS account must upload new patient reports directly to the same bucket. The startup's security policy prohibits sharing credentials or setting up cross-account identity federation. Which of the following configurations represents the most secure, AWS-recommended approach to grant the required access?
A global logistics company needs to evaluate its cloud environment against the Federal Risk and Authorization Management Program (FedRAMP) requirements. The company must obtain official AWS compliance documents and verify which AWS services are compliant under the FedRAMP authorization boundary. Which of the following two actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A company uses Amazon Route 53 to host and manage its domain name system (DNS) records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?
A municipal agency is planning to host citizen records on AWS. The agency's compliance team needs to obtain AWS SOC 3 reports and sign a Business Associate Addendum (BAA) with AWS. Which of the following options represent the correct service and action to meet these requirements? (Select TWO.)
Select all that apply
A company is conducting a security audit of its AWS infrastructure. The audit reveals that the IT team uses the AWS account root user for daily configuration tasks, and several application servers use embedded long-term AWS access keys to write data to Amazon S3. Which of the following actions should the company take to align with AWS Identity and Access Management (IAM) security best practices? (Select TWO.)
Select all that apply
A startup is preparing for a security audit and needs to download official AWS compliance documentation. Which AWS service provides on-demand access to AWS security and compliance reports, such as Service Organization Control (SOC) reports and ISO certifications?
An energy technology provider is migrating its financial billing system to AWS. The company's compliance department needs to obtain a confidential AWS System and Organization Controls (SOC) 1 Type II report to prove to their external auditors that the AWS infrastructure controls are operating effectively. Which AWS resource should the company use to locate, accept the terms of, and download this report?
A mobile gaming startup is deploying a high-throughput, low-latency leaderboard and player session store using Amazon ElastiCache for Redis. The startup needs to secure this environment to protect user session tokens from unauthorized external access while maintaining compliance with regional data privacy standards. Under the AWS Shared Responsibility Model, which of the following tasks is the sole responsibility of the customer?
An online media streaming company is undergoing a security audit. The compliance team needs to access AWS security documents and accept standard agreements regarding content protection. Which TWO of the following tasks can the team perform using AWS Artifact to meet these requirements?
Select all that apply
A consulting firm is storing client project documents in an Amazon Simple Storage Service (Amazon S3) bucket. Under the AWS Shared Responsibility Model, which operational task is the sole responsibility of the customer?
A company is using Amazon DynamoDB to store user profile data for a mobile application. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A startup needs to grant a new database administrator access to manage Amazon RDS databases. Which of the following actions aligns with AWS security best practices for identity management?
A public sector organization is migrating a legacy database to AWS and must ensure the architecture meets strict government compliance guidelines. The organization needs to retrieve AWS's third-party compliance reports and must understand the compliance boundaries under the AWS Shared Responsibility Model. Which of the following describes the correct service for retrieving these reports and the compliance responsibility division if they deploy the database on Amazon EC2?
A retail company is migrating its core transactional inventory system to Amazon Aurora MySQL-Compatible Edition. The database will store sensitive inventory and pricing data and must be accessible only by specific application servers running in a private subnet. According to the AWS Shared Responsibility Model, which TWO of the following tasks are the responsibility of the customer to secure and maintain this database cluster?
Select all that apply