Security and Compliance
441 questions
A biotechnology startup is preparing to host sensitive clinical trial data on AWS. To satisfy regulatory requirements, the startup's compliance team must review AWS's third-party audit reports detailing the physical security and environmental controls of the AWS data centers. Which AWS service should the startup use to retrieve these documents?
A retail company is migrating a legacy web application to Amazon Elastic Compute Cloud (Amazon EC2) instances. Under the AWS Shared Responsibility Model, which TWO of the following security tasks are the responsibility of the customer?
Select all that apply
A financial data analysis firm uses a multi-node Amazon Redshift cluster to store and analyze large volumes of proprietary market data. Under the AWS Shared Responsibility Model, which TWO of the following security-related tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A software developer needs to access Amazon S3 buckets using the AWS Command Line Interface (CLI) from their local development workstation. According to AWS security best practices, which method should the developer use to authenticate and run these commands?
A pharmaceutical company is launching a new research database containing proprietary clinical trial data on AWS. To meet strict regulatory standards, the compliance team must download the AWS SOC 2 Type II report and verify that data protection standards are maintained. Which of the following actions must the company take to meet these compliance objectives? (Select TWO.)
Select all that apply
An organization is setting up AWS accounts for its new development team. To ensure a secure cloud environment, which of the following are AWS Identity and Access Management (IAM) best practices that the organization should implement? (Select TWO.)
Select all that apply
A financial trading firm hosts its transaction database on Amazon EC2 instances and stores historical backups in Amazon S3. To prepare for an upcoming audit, the compliance team must review the physical security controls of the AWS data centers and ensure the database infrastructure is patched in accordance with regulatory requirements. Which of the following actions should the team take to meet these compliance and governance requirements? (Select TWO.)
Select all that apply
A financial institution is deploying AWS Outposts inside its on-premises corporate data center to run low-latency applications. Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?
A company needs to perform automated security assessments on its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which AWS service should the company use to meet this requirement?
A startup is setting up its first AWS account to host a web application. The company's IT lead needs to perform daily operations, such as creating Amazon EC2 instances and configuring Amazon S3 buckets. Which AWS security best practice should the IT lead follow to manage these daily administrative tasks?
A digital media startup is developing a mobile photo-sharing application that requires millions of end-users to upload images directly to a private Amazon S3 bucket. Which of the following approaches aligns with AWS Identity and Access Management (IAM) best practices for granting access to these users?
An online retail company is auditing its cloud deployment to verify compliance with industry security standards. Under the AWS shared responsibility model, which of the following operational tasks is the sole responsibility of the customer?
A logistics company is deploying a tracking application on a fleet of Amazon EC2 instances that requires access to a private Amazon DynamoDB table. Additionally, an external audit team needs temporary access to view the company's billing dashboards for a period of one week. Which of the following configurations should the administrator implement to meet these requirements securely? (Select TWO.)
Select all that apply
A human resources software provider hosting its applications on AWS is undergoing an external compliance audit. The provider must officially accept a global Data Processing Addendum (DPA) with AWS and obtain the official ISO 27001 certification report for the underlying AWS data center infrastructure. Which AWS service should the provider use to satisfy both of these requirements?
A cloud administrator needs to grant the same read-only permissions to ten new security analysts. Which AWS Identity and Access Management (IAM) feature should the administrator use to manage and apply these permissions to all ten analysts at once?
A healthcare provider uses Amazon Simple Storage Service (Amazon S3) to store encrypted patient records. During a security audit, it is discovered that a bucket policy was improperly configured, allowing public read access to the records. Under the AWS Shared Responsibility Model, which of the following statements correctly identifies the party responsible for this configuration error and the reason?
A media streaming company is deploying a serverless image processing pipeline using AWS Lambda. Under the AWS Shared Responsibility Model, which of the following security tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A startup is designing a secure architecture on AWS. The security team wants to implement a solution that continuously monitors the AWS environment for unauthorized behavior, such as unusual API calls or potential database attacks. Additionally, they need to run automated scans on their container images to check for known software vulnerabilities before deployment. Which AWS services should the startup use to meet these requirements? (Select two.)
Select all that apply
A company needs to grant programmatic access to an external third-party Software-as-a-Service (SaaS) monitoring tool to read configuration metrics from their AWS account. The SaaS tool does not run on AWS infrastructure. According to AWS Identity and Access Management (IAM) best practices, which configuration should the administrator implement to grant this access?
A company hosts its customer database on an Amazon EC2 instance. Under the AWS Shared Responsibility Model, which of the following tasks is the sole responsibility of the customer?