Tüm alıştırma soruları
1473 soru
A health-tech company hosts its patient management portal on Amazon EC2 instances. The security team needs a service that can continuously monitor the AWS environment for potential security threats, such as command-and-control (C2) activity, unauthorized API calls, and brute-force attacks on the instances. Which AWS service is designed to perform this type of intelligent threat detection?
A media streaming company is preparing to share its compliance posture with new business partners. The company needs to retrieve official AWS security compliance documents, such as Service Organization Control (SOC) reports, to demonstrate the security of the AWS infrastructure. Which AWS service or portal provides on-demand access to these reports?
A retail company deploys its online storefront using AWS Elastic Beanstalk. Under the AWS Shared Responsibility Model, which two of the following security-related tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
A healthcare provider must ensure that all administrative actions performed in their AWS Cloud environment are recorded for regulatory compliance. They need to track when a user logs in, which resources were modified, and the source IP address of the request. Which AWS service is designed to record and log these API transactions?
A software-as-a-service (SaaS) company providing human resources platform services is undergoing an external SOC 2 Type II audit. The audit team requires documentation verifying the security and compliance of the AWS physical infrastructure, and confirmation of how the SaaS company manages encryption keys for its application data. Which of the following actions should the company take to meet these audit requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial services firm wants to audit user activity in its AWS account to ensure compliance. They need to keep a complete record of all API transactions, and they also want to receive real-time notifications if anyone attempts to modify security group rules. Which combination of AWS services should the company implement to achieve this? (Select TWO.)
Geçerli olan tümünü seçin
A company is designing a new web application in the AWS Cloud and wants to ensure that the architecture is modular and resilient to component outages. Which two of the following are design principles of the AWS Cloud that support this architecture? (Select TWO.)
Geçerli olan tümünü seçin
An online travel agency wants to improve its security posture on AWS. The company needs to implement a solution that continuously monitors its AWS accounts for malicious activity or unauthorized access, and it also needs to automate security assessments of its Amazon EC2 instances to identify software vulnerabilities. Which two AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A genomic research institute stores patient DNA sequencing data in Amazon S3 and runs analysis workloads on Amazon EC2. The institute's compliance guidelines state that:
1. The cryptographic keys used for encrypting the data at rest must be managed on dedicated, single-tenant hardware security modules (HSMs) where the customer has sole control over cryptographic web users and key policies.
2. All data in transit between the EC2 instances and the S3 buckets must be encrypted using Transport Layer Security (TLS).
Which of the following implementation details are correct? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst needs to determine which IAM user made a specific API call to delete an Amazon S3 bucket last week. Which AWS service should the analyst use to retrieve this API history?
A financial technology company must comply with a strict regulatory standard requiring that cryptographic keys used to encrypt transactional data at rest be stored in dedicated, single-tenant hardware security modules (HSMs) where the customer retains exclusive administrative control over the HSM partitions. Which of the following options represents the correct service selection and distribution of responsibility under the AWS Shared Responsibility Model?
A regional food delivery platform wants to focus its engineering resources on developing its proprietary dispatch algorithm rather than managing physical server racks, power supplies, and cooling systems. Additionally, the platform experiences massive, brief spikes in order volume during lunch and dinner hours, and wants to dynamically scale its infrastructure to avoid paying for idle resources during off-peak times. Which two of the following AWS Cloud benefits directly align with this company's goals?
Geçerli olan tümünü seçin
A renewable energy company operates a fleet of Amazon EC2 instances to monitor wind turbine telemetry and stores its deployment packages in Amazon Elastic Container Registry (Amazon ECR). The company needs to implement a solution that continuously scans its container images and virtual machines for software vulnerabilities, while also monitoring its AWS accounts for potential unauthorized behavior and DNS data exfiltration attempts.
Which of the following AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
An organization needs to grant a new database administrator the necessary permissions to manage Amazon RDS resources on a daily basis. Which of the following actions aligns with the AWS-recommended best practice for securing this access?
A telehealth startup is launching a patient consultation portal. Instead of purchasing physical servers and securing dedicated data center space upfront, the company decides to host the application on AWS and pay only for the virtual resources it uses each month. Which of the following benefits of the AWS Cloud is directly demonstrated by this business decision?
A financial services company uses Amazon Simple Storage Service (Amazon S3) to store sensitive customer transaction records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer responsible for performing?
An AWS cloud practitioner is configuring network security within a Virtual Private Cloud (VPC). To ensure proper network isolation, they need to identify the operational differences between Security Groups and Network Access Control Lists (Network ACLs). Which of the following statements correctly describe the behavior of these security controls? (Select TWO.)
Geçerli olan tümünü seçin
A global logistics firm currently hosts its fleet-management application in an on-premises data center. The application experiences massive, unpredictable traffic spikes during holiday shopping seasons, but remains largely idle during the rest of the year. The company plans to migrate this application to AWS. Which two of the following options describe how the economics of the AWS Cloud will help the company optimize its infrastructure costs?
Geçerli olan tümünü seçin
A healthcare provider is designing a patient registration portal on AWS. To prevent patient registrations from failing when the backend database is offline for scheduled maintenance, the architect decides to insert a message queue between the front-end registration portal and the database. Which AWS Cloud design principle is best illustrated by this architectural decision?
A developer deploys a web application on an Amazon EC2 instance and updates its security group to permit inbound traffic on port 80. Although no outbound rules are modified, the instance can successfully return response traffic to the clients. Which characteristic of security groups explains why this outbound traffic is allowed?