Security and Compliance
441 soru
A company is onboarding a new team of data analysts who require read-only access to Amazon S3 buckets. Which of the following actions should the company take to configure access in accordance with AWS Identity and Access Management (IAM) best practices? (Select TWO.)
Geçerli olan tümünü seçin
A technology startup runs its backend API on AWS Lambda. Under the AWS Shared Responsibility Model, which of the following security tasks is the responsibility of the startup?
A media company is migrating its backend processing workloads to serverless architectures using AWS Lambda. The company wants to ensure that all aspects of this environment conform to their security policies. Under the AWS Shared Responsibility Model, which responsibility falls solely on the customer when deploying these serverless functions?
A company has hired an external security auditing firm to inspect their AWS resource configurations. The auditors require read-only access to the AWS account for a limited period of two weeks. Which of the following options represents the AWS-recommended best practice to grant the external auditors access?
A startup is designing a secure multi-tier environment in an Amazon VPC. They require a network security control at the subnet boundary that does not track connection state, meaning inbound and outbound traffic must be allowed via explicit, separate rules. For individual Amazon EC2 instances, they require a firewall that automatically allows outbound return traffic if the inbound request is permitted. Which combination of AWS network security features should the startup implement to meet these requirements?
An automobile manufacturer is migrating its web applications to AWS and wants to establish automated security checks. The manufacturer needs to implement software vulnerability assessments on its application hosts and monitor AWS account activity for potential security threats. Which AWS services should be selected to fulfill these requirements? (Select two.)
Geçerli olan tümünü seçin
A retail corporation is migrating its point-of-sale systems to AWS and needs to ensure compliance with industry security regulations. Under the AWS Shared Responsibility Model, which of the following compliance-related tasks is the sole responsibility of the customer?
A multi-department enterprise has hired an external consulting firm to perform a security audit of their AWS environment. The auditors require read-only access to various AWS resources for a limited duration of two weeks. Which of the following is the AWS-recommended best practice to grant this external firm access to the enterprise's AWS account?
A healthcare technology company deploys microservices using AWS Lambda and container images stored in Amazon Elastic Container Registry (Amazon ECR). The security team needs to implement a solution that automatically scans these container images and Lambda functions for software vulnerabilities, and assesses the Lambda functions for unintended network exposure. Which AWS service should the company use to meet these requirements?
A retail company needs to track and audit all user activity and API calls within their AWS account for security compliance. They want to identify which specific user modified a security group rule or deleted an Amazon S3 bucket. Which AWS service should the company use to meet this requirement?
An e-commerce company is deploying containerized microservices using AWS Fargate. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A software company is configuring permissions for its new AWS environment. The IT administrator needs to manage access for ten developers who require the same set of permissions, and also grant an application running on Amazon Elastic Container Service (Amazon ECS) access to an Amazon DynamoDB table. Which of the following actions represent AWS security best practices to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A logistics company runs its tracking application using containerized microservices on Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. To maintain a robust security posture, the company needs to define the boundaries of the AWS Shared Responsibility Model for this serverless container environment.
Which of the following security tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A company is establishing its AWS environment and needs to define its identity and access management strategy. The security team must ensure that application servers running on Amazon EC2 can securely access files in Amazon S3, and that emergency administrative actions can be performed securely if primary identity systems fail. Which two AWS Identity and Access Management (IAM) best practices should the company implement? (Select TWO.)
Geçerli olan tümünü seçin
An online retail company is preparing for its annual security audit. The internal compliance team needs to access and download official AWS security and compliance documents, such as SOC reports and ISO certifications, to verify the security posture of the AWS infrastructure. Which AWS service or portal provides on-demand access to these compliance reports?
A logistics provider runs a custom inventory application on a fleet of Amazon EC2 instances. The provider wants to implement automated checks to identify known software package vulnerabilities and unintended network exposure on these instances. According to the AWS Shared Responsibility Model, which statement correctly identifies the party responsible for configuring these checks, and the AWS service that should be utilized?
A healthcare provider plans to migrate its legacy patient database to Amazon RDS for MySQL. Under the AWS Shared Responsibility Model, which of the following operational tasks is the responsibility of the customer?
A logistics enterprise is migrating its supply chain systems to AWS and must verify that the AWS infrastructure aligns with global security standards. The compliance team needs to access AWS's independent third-party audit reports and accept online agreements to meet regulatory requirements. Which of the following actions should the team perform? (Select TWO.)
Geçerli olan tümünü seçin
A fintech startup is deploying a digital wallet application. The environment consists of Amazon EC2 instances running payment processing software and containerized microservices hosted on Amazon Elastic Container Registry (Amazon ECR). The security team requires a solution to automatically scan these instances and container images for software vulnerabilities, and to continuously analyze log sources like VPC Flow Logs and CloudTrail events to detect malicious activity or unauthorized behavior. Which AWS services should the startup use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A financial technology startup has deployed application microservices across multiple AWS accounts. To protect their workloads, the startup's security team needs to implement a solution that continuously scans their container images and virtual machines for software vulnerabilities, while also analyzing log sources (such as VPC Flow Logs and DNS query logs) to detect active threats and potential data exfiltration. Which of the following AWS services should the startup configure to address both of these requirements? (Select two.)
Geçerli olan tümünü seçin