Security and Compliance
441 soru
A security analyst needs to determine which IAM user made a specific API call to delete an Amazon S3 bucket last week. Which AWS service should the analyst use to retrieve this API history?
A financial technology company must comply with a strict regulatory standard requiring that cryptographic keys used to encrypt transactional data at rest be stored in dedicated, single-tenant hardware security modules (HSMs) where the customer retains exclusive administrative control over the HSM partitions. Which of the following options represents the correct service selection and distribution of responsibility under the AWS Shared Responsibility Model?
A renewable energy company operates a fleet of Amazon EC2 instances to monitor wind turbine telemetry and stores its deployment packages in Amazon Elastic Container Registry (Amazon ECR). The company needs to implement a solution that continuously scans its container images and virtual machines for software vulnerabilities, while also monitoring its AWS accounts for potential unauthorized behavior and DNS data exfiltration attempts.
Which of the following AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
An organization needs to grant a new database administrator the necessary permissions to manage Amazon RDS resources on a daily basis. Which of the following actions aligns with the AWS-recommended best practice for securing this access?
A financial services company uses Amazon Simple Storage Service (Amazon S3) to store sensitive customer transaction records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer responsible for performing?
An AWS cloud practitioner is configuring network security within a Virtual Private Cloud (VPC). To ensure proper network isolation, they need to identify the operational differences between Security Groups and Network Access Control Lists (Network ACLs). Which of the following statements correctly describe the behavior of these security controls? (Select TWO.)
Geçerli olan tümünü seçin
A developer deploys a web application on an Amazon EC2 instance and updates its security group to permit inbound traffic on port 80. Although no outbound rules are modified, the instance can successfully return response traffic to the clients. Which characteristic of security groups explains why this outbound traffic is allowed?
A media company is looking for a way to continuously monitor its AWS accounts and workloads for malicious activities, such as cryptocurrency mining, unauthorized data access, or compromised credentials. The solution must automatically analyze data from AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to identify threats. Which AWS service should the company use to meet this requirement?
A retail company is migrating its inventory management system to AWS. The system runs on Amazon EC2 instances and requires permission to write to an Amazon DynamoDB table. Additionally, a team of developers requires access to perform administrative tasks. Which of the following actions represent AWS-recommended security practices for managing access in this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A gaming studio is deploying a multiplayer matchmaking backend on AWS using Amazon DynamoDB to store player session states. Under the AWS Shared Responsibility Model, which two security-related tasks are the sole responsibility of the gaming studio?
Geçerli olan tümünü seçin
An enterprise wants to simplify permission management for its finance department. Currently, the IT team manually attaches permissions to each new financial analyst's AWS account, which has led to inconsistent access rights and administrative overhead. Which of the following is the AWS-recommended method to resolve this issue?
A company is setting up a new application on AWS and wants to establish baseline security logging and operational monitoring. They need to track user activity and API calls for auditing purposes, as well as collect and track performance metrics for their Amazon EC2 instances. Which of the following AWS services should the company use to meet these requirements? (Select TWO).
Geçerli olan tümünü seçin
An organization is securing a proprietary database tier hosted on Amazon EC2 instances within a private subnet of a Virtual Private Cloud (VPC). The database must receive SQL traffic on TCP port from the application servers located in a public subnet, while ensuring strict network isolation at both the subnet and instance levels. Which two configuration steps are required to establish this network security architecture? (Select TWO.)
Geçerli olan tümünü seçin
A security team needs to monitor an AWS environment for active threats and unauthorized behavior. They require a solution that automatically analyzes AWS CloudTrail events, VPC Flow Logs, and DNS logs to identify activities like an Amazon EC2 instance communicating with a known malicious command-and-control server. The solution must be agentless and operate at the account level. Which AWS service should the security team use to meet these requirements?
A company wants to set up access for a new employee who needs to manage Amazon EC2 instances on a daily basis. The manager wants to follow AWS security best practices. Which of the following actions should the administrator take to grant the employee this access?
A company is hosting a secure web application on Amazon EC2 instances within a VPC. The security team wants to allow incoming traffic on port (HTTPS) while blocking a specific range of known malicious IP addresses at the boundary before the traffic reaches any EC2 instance. They also need to ensure that the EC2 instances can send outbound response traffic back to clients. Which of the following network security configurations meets these requirements?
An enterprise is deploying an application on Amazon EC2 instances that needs to retrieve files from an Amazon S3 bucket. Which of the following configurations represent AWS Identity and Access Management (IAM) best practices for this scenario? (Select TWO.)
Geçerli olan tümünü seçin
A logistics company coordinates delivery routes using an application hosted on Amazon EC2 instances. The security team needs to implement a solution that continuously monitors the environment for active threats, such as instances communicating with known malicious command-and-control servers or performing unauthorized API actions. This monitoring must be performed without installing software agents or affecting application performance. Which AWS service should be used to meet these requirements?
A media streaming company uses Amazon CloudFront to distribute video content to users worldwide. Under the AWS Shared Responsibility Model, which two of the following security tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A startup is deploying a microservices application using AWS Lambda to process user registration data. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of AWS?