Security and Compliance
441 questions
A financial technology startup is developing a mobile payment application and decides to use Amazon Cognito User Pools for user identity management and authentication. Under the AWS Shared Responsibility Model, which of the following security tasks are the responsibility of the customer? (Select TWO).
Select all that apply
A global telecommunications provider is preparing for a regulatory audit of its customer portal. The compliance team must review the confidential AWS ISO 27001 Certification report to verify physical security, and ensure that the guest operating system patches are applied on their database running on Amazon EC2. Which combination of actions should the provider take to satisfy both requirements?
A global e-commerce corporation is preparing for an annual security audit to verify compliance with payment card industry and international security standards. The compliance team needs to obtain AWS's formal compliance reports and verify the division of security obligations for their hosted databases. Which of the following actions should the team perform to meet these compliance requirements? (Select TWO.)
Select all that apply
An enterprise is auditing its AWS environment. The audit team discovers that the development group shares a single set of IAM access keys to perform administrative actions. Additionally, the AWS account root user is frequently used to run daily database backup scripts. Which of the following actions should the security team take to remediate these security findings in accordance with AWS best practices? (Select TWO.)
Select all that apply
A retail company is designing its access management strategy on AWS. The company needs to configure access for its application developers and an application running on an Amazon EC2 instance. Which of the following actions follow AWS Identity and Access Management (IAM) best practices? (Select TWO.)
Select all that apply
A financial analytics firm is deploying a containerized API using Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. The security team must define the security controls for which they are solely responsible. Under the AWS Shared Responsibility Model, which of the following operational tasks is the responsibility of the customer for this deployment?
A software development team is deploying a serverless API using AWS Lambda to process incoming customer orders. Under the AWS Shared Responsibility Model, which operational task is the responsibility of the customer?
A municipal utility provider is migrating its operations to AWS and must review the security compliance reports of the AWS physical data centers to satisfy local government auditing requirements. How can the provider obtain these official AWS compliance documents?
A healthcare organization hires a new compliance officer who needs permanent, individual access to log into the AWS Management Console to review compliance reports. Which AWS Identity and Access Management (IAM) entity should be created to grant this access?
An organization is configuring a secure network architecture on AWS with public-facing web servers and a private database tier. To meet strict compliance guidelines, the security team must implement a layered defense-in-depth strategy. They need to understand how Security Groups and Network Access Control Lists (Network ACLs) behave when filtering traffic across these tiers.
Which of the following statements accurately describe the behavior and configuration of Security Groups and Network ACLs in this scenario? (Select TWO.)
Select all that apply
A healthcare startup needs to verify its compliance posture by reviewing official security documentation and accepting a Business Associate Addendum (BAA) with AWS. Which of the following actions can the startup perform using AWS Artifact to meet these requirements? (Select TWO.)
Select all that apply
An organization hosts a multi-tier web application where Amazon EC2 instances in a private subnet receive traffic from a public-facing Application Load Balancer (ALB). The security team configures the EC2 instances' Security Group to allow inbound HTTP traffic on port 80 only from the ALB's Security Group, and allowed all outbound traffic. At the subnet level, the Network ACL (NACL) is modified to allow inbound HTTP traffic on port 80 from the ALB's private IP range, and allow outbound HTTP traffic on port 80 to the ALB's private IP range, with all other traffic blocked by default rules. Users report receiving 502 Bad Gateway errors from the ALB. Which configuration change is required to resolve this issue and allow successful traffic flow?
A retail company runs its e-commerce website on several Amazon Elastic Compute Cloud (Amazon EC2) instances. Under the AWS Shared Responsibility Model, which of the following security tasks is the sole responsibility of AWS?
A smart-vehicle manufacturer is launching an autonomous fleet management platform on AWS. To meet regional regulatory requirements, the manufacturer's legal department must execute a Business Associate Addendum (BAA) with AWS, and the risk assessment team must download the ISO/IEC 27001 certification report for the AWS physical infrastructure. Which AWS resource should the manufacturer use to accept this online agreement and retrieve the required certification?
A financial services company is setting up its application environment on AWS. The environment will consist of developers who need to configure resources and applications running on Amazon EC2 instances that need to retrieve data from Amazon S3. Which two of the following actions align with AWS-recommended security best practices for managing identity and access in this scenario?
Select all that apply
A financial technology company wants to continuously monitor its AWS accounts for malicious activity and unauthorized behavior. The company needs a service that can analyze AWS CloudTrail event logs, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect issues like compromised EC2 instances or unauthorized API calls. Which AWS service should the company use to meet this requirement?
A company is migrating its relational database to Amazon RDS (Relational Database Service) to reduce operational overhead. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A logistics company is onboarding a new shipping partner that requires proof of AWS's ISO 9001 compliance. Which AWS service should the company use to download the required audit reports and certifications?
A smart-home IoT device manufacturer is preparing for a security audit of its database systems. The compliance team must review AWS physical infrastructure security controls via a SOC 2 report and verify who is responsible for patching the guest operating systems on their Amazon EC2 instances. Which of the following actions should the company take to meet these compliance and operational requirements? (Select TWO.)
Select all that apply
A logistics company wants to secure its cloud infrastructure. The development team needs a service to automatically scan their container images in Amazon Elastic Container Registry (ECR) for known software vulnerabilities. At the same time, the security team needs a service to continuously monitor their AWS accounts for malicious activity and unauthorized behavior. Which two AWS services should the company use to meet these requirements? (Select two.)
Select all that apply