Security and Compliance
441 questions
A logistics company is deploying a Redis cluster using Amazon ElastiCache to cache high-frequency tracking data. Under the AWS Shared Responsibility Model, which two of the following operational tasks are the responsibility of the customer?
Select all that apply
A university research laboratory is setting up an AWS account. The administrator needs to grant ten student researchers read-only access to a specific Amazon S3 bucket. Which of the following approaches represent AWS Identity and Access Management (IAM) best practices for this scenario? (Select two.)
Select all that apply
A digital advertising agency must provide its clients with independent audit reports verifying that the AWS infrastructure hosting their campaigns complies with global security standards. The agency also needs to review and accept a Non-Disclosure Agreement (NDA) with AWS. Which two tasks can the agency perform using AWS Artifact to satisfy these requirements?
Select all that apply
An educational technology company hosting student record databases on AWS must prepare for an audit by its university customers. The customers require verification of the physical security controls of the AWS data centers, and the company must accept the AWS non-disclosure agreements (NDAs) to access these documents. Which TWO actions should the company take to meet these compliance requirements? (Select TWO.)
Select all that apply
A financial organization is using AWS Storage Gateway (Volume Gateway) deployed as a virtual machine (VM) on their on-premises VMware ESXi hypervisor to replicate local file data to Amazon S3. Under the AWS Shared Responsibility Model, which of the following operational security tasks is the responsibility of AWS?
A startup is establishing its cloud environment and wants to secure access for its development team. The developers currently share a single set of credentials to manage AWS resources. Which TWO AWS Identity and Access Management (IAM) best practices should the startup implement to secure its environment? (Select TWO.)
Select all that apply
An online retail company wants to implement a service that continuously monitors their AWS accounts and workloads for malicious activity and unauthorized behavior. Which AWS service provides this threat detection capability?
An educational technology company is preparing for an audit of its online learning platform. The company needs to obtain official AWS compliance documents, such as SOC and PCI reports, and clarify the division of security responsibilities between the company and AWS for their Amazon EC2 instances. Which of the following actions should the company take to meet these compliance requirements? (Select TWO)
Select all that apply
A gaming company is launching a new multiplayer game on AWS and must provide its legal team with the official AWS SOC 2 compliance report. Which AWS service provides on-demand access to these security and compliance reports?
A logistics company is integrating its on-premises inventory server with AWS. The server must automatically upload daily reports to an Amazon S3 bucket. To comply with strict security standards, the company prohibits storing long-term AWS access keys on the physical on-premises server. Which configuration represents the most secure AWS-recommended best practice to grant this access?
A company stores its financial documents in an Amazon Simple Storage Service (Amazon S3) bucket. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A global pharmaceutical firm is validating its drug development systems on Amazon EC2 for GxP (Good Practice) regulatory compliance. The auditors require the firm to provide official documentation of AWS's physical security certifications and verify who is responsible for patching the virtualization hypervisor host operating system. Which combination of actions correctly addresses these requirements?
A pharmaceutical company deploys an AWS Outpost in its on-premises data center to comply with local data residency regulations. The IT team is establishing the operational security procedures for this hybrid deployment. Under the AWS Shared Responsibility Model, which two duties remain the responsibility of the customer? (Select TWO.)
Select all that apply
A developer needs to configure a script running on their local workstation to upload log files to an Amazon S3 bucket. Which of the following is the AWS-recommended method to securely authenticate this script?
A retail company wants to continuously monitor its AWS accounts, Amazon EC2 instances, and container workloads for potential security threats, such as instances communicating with known malicious IP addresses or performing unauthorized API calls. The solution must use threat intelligence and machine learning to identify these anomalies. Which AWS service should the company use to meet these requirements?
A financial company is preparing for an external audit of its application running on Amazon EC2 instances. The company needs to restrict network access to the servers and collect compliance reports showing that the underlying AWS physical infrastructure meets industry security standards. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
An online gaming company hosting its multiplayer game servers on Amazon EC2 wants to continuously monitor its AWS accounts for security threats like cryptocurrency mining, unauthorized API calls, and unusual data access patterns. The security team needs an intelligent service that automatically analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to detect these anomalies. Which AWS service should the company use to meet this objective?
An organization hosts a web application on Amazon EC2 instances in a public subnet. The security team wants to allow web clients to access the instances over HTTP (port 80) and HTTPS (port 443). However, to prevent data exfiltration, the EC2 instances must be restricted from initiating any outbound connections to the internet, while still allowing them to return responses to client requests. Which of the following configurations are required to achieve this goal? (Select TWO.)
Select all that apply
A financial company hosts a transaction processing application on Amazon EC2 instances and stores historical data archives in Amazon S3. The security team must implement a security strategy that achieves two goals: first, automatically identifying software package vulnerabilities and unintended network accessibility on the EC2 instances; second, continuously monitoring the AWS accounts and network traffic for active malicious activity, such as brute-force attacks or communication with known malicious command-and-control servers. Which of the following AWS services should be implemented to address these specific security requirements? (Select two.)
Select all that apply
A food delivery platform is preparing for an audit and needs to download official AWS compliance documents, such as SOC and PCI DSS reports, while also verifying its security responsibilities. Which of the following actions should the company take to meet these requirements? (Select TWO.)
Select all that apply