Security and Compliance
441 soru
A software development firm manages a multi-account AWS environment. A developer in the development account needs temporary administrative access to perform emergency troubleshooting on resources in the production account. Which of the following options represents the most secure, AWS-recommended method to achieve this?
A logistics company is preparing for an external audit to verify that its cloud infrastructure meets international compliance standards. The company needs to retrieve AWS security reports and determine which security tasks are managed directly by AWS. Which two of the following actions should the company take to meet these requirements?
Geçerli olan tümünü seçin
A systems administrator is troubleshooting a connectivity issue for a web application deployed on Amazon EC2 instances within a custom VPC subnet. The instances are associated with a stateful Security Group that allows inbound HTTP (port 80) traffic from any source, and allows all outbound traffic. At the subnet level, the custom Network Access Control List (Network ACL) is configured with an inbound rule allowing HTTP (port 80) traffic from any source, but its outbound rule set only contains the default deny rule. Users report that they receive connection timeouts when trying to access the web application. Which of the following explains why the connection attempts are timing out?
A regional energy utility company is hosting its customer portal on AWS. In preparation for an upcoming regulatory audit, the company's compliance officer needs to retrieve the AWS Service Organization Control (SOC) reports to verify the security controls of the AWS physical infrastructure. Which AWS resource provides on-demand access to these compliance documents?
A media streaming company wants to improve its security posture on AWS. The company needs to implement continuous monitoring of its AWS accounts for malicious activity or unauthorized behavior. Additionally, it needs to automatically scan its Amazon EC2 instances for software vulnerabilities.
Which of the following AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A smart-agriculture IoT company runs containerized data processing applications on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (Amazon ECR). The security team wants to implement continuous, automated scans to identify software vulnerabilities in both the EC2 operating system packages and the ECR container images. According to the AWS Shared Responsibility Model, which AWS service performs these scans, and who is responsible for configuring the tool and remediating the findings?
A startup is establishing its cloud presence and needs to set up administrative access for its system administrator. The administrator will be responsible for creating resources, managing network settings, and monitoring logs on a daily basis. What is the AWS-recommended best practice to configure this administrative access?
A startup wants to establish operational visibility and security auditing. They need to log all API calls made by users and services across their AWS account, and they also need to collect and monitor performance metrics, such as CPU utilization, from their Amazon EC2 instances.
Which of the following AWS services should the startup use to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A digital real estate platform runs its database and web servers on Amazon Elastic Compute Cloud (Amazon EC2) instances. The platform's security team needs to implement a solution that automatically scans these EC2 instances for software vulnerabilities, package issues, and unintended network path exposures. Which AWS service should the real estate platform use to meet these requirements?
A startup is setting up its initial AWS environment and wants to secure the account. Which of the following are AWS Identity and Access Management (IAM) best practices that the startup should implement? (Select TWO.)
Geçerli olan tümünü seçin
A non-profit organization stores its public files in Amazon S3 and runs a web application on Amazon EC2 instances. Which two of the following tasks are the responsibility of AWS under the AWS Shared Responsibility Model?
Geçerli olan tümünü seçin
A company wants to automate vulnerability assessments for its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which AWS service should the company use?
A health-tech company hosts its patient management portal on Amazon EC2 instances. The security team needs a service that can continuously monitor the AWS environment for potential security threats, such as command-and-control (C2) activity, unauthorized API calls, and brute-force attacks on the instances. Which AWS service is designed to perform this type of intelligent threat detection?
A media streaming company is preparing to share its compliance posture with new business partners. The company needs to retrieve official AWS security compliance documents, such as Service Organization Control (SOC) reports, to demonstrate the security of the AWS infrastructure. Which AWS service or portal provides on-demand access to these reports?
A retail company deploys its online storefront using AWS Elastic Beanstalk. Under the AWS Shared Responsibility Model, which two of the following security-related tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
A healthcare provider must ensure that all administrative actions performed in their AWS Cloud environment are recorded for regulatory compliance. They need to track when a user logs in, which resources were modified, and the source IP address of the request. Which AWS service is designed to record and log these API transactions?
A software-as-a-service (SaaS) company providing human resources platform services is undergoing an external SOC 2 Type II audit. The audit team requires documentation verifying the security and compliance of the AWS physical infrastructure, and confirmation of how the SaaS company manages encryption keys for its application data. Which of the following actions should the company take to meet these audit requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial services firm wants to audit user activity in its AWS account to ensure compliance. They need to keep a complete record of all API transactions, and they also want to receive real-time notifications if anyone attempts to modify security group rules. Which combination of AWS services should the company implement to achieve this? (Select TWO.)
Geçerli olan tümünü seçin
An online travel agency wants to improve its security posture on AWS. The company needs to implement a solution that continuously monitors its AWS accounts for malicious activity or unauthorized access, and it also needs to automate security assessments of its Amazon EC2 instances to identify software vulnerabilities. Which two AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A genomic research institute stores patient DNA sequencing data in Amazon S3 and runs analysis workloads on Amazon EC2. The institute's compliance guidelines state that:
1. The cryptographic keys used for encrypting the data at rest must be managed on dedicated, single-tenant hardware security modules (HSMs) where the customer has sole control over cryptographic web users and key policies.
2. All data in transit between the EC2 instances and the S3 buckets must be encrypted using Transport Layer Security (TLS).
Which of the following implementation details are correct? (Select TWO.)
Geçerli olan tümünü seçin