Security and Compliance
441 soru
A logistics company is migrating its supply chain database to AWS. The compliance team requires that all data stored at rest in Amazon S3 be encrypted. The compliance policy specifically mandates that the encryption keys must be generated and stored in a dedicated, single-tenant cryptographic hardware appliance that the company fully controls, while AWS remains responsible for the physical security and maintenance of the appliance hardware. Which service and management model should the company implement?
A company's security team is designing a multi-layered auditing and threat detection strategy for their application servers running on Amazon EC2. The team must satisfy three distinct operational security requirements:
1. Audit and record a history of all API calls, including the specific IAM identities, source IP addresses, and timestamps, to determine who modified resources.
2. Monitor active network traffic patterns to detect potential security threats, such as instances communicating with known command-and-control servers.
3. Track performance metrics of the EC2 instances, such as CPU utilization, and trigger automated alerts if resource usage exceeds defined limits.
Which combination of AWS services will successfully address these three requirements?
A university is hosting its student registration portal on AWS. The university's compliance department requires a complete history of all API calls and administrative actions taken within the AWS account to audit user activity. Which AWS service should the university use to meet this audit requirement?
A digital marketing agency needs to retrieve the AWS Service Organization Control (SOC) reports to satisfy a client's security questionnaire about the underlying cloud infrastructure. Which AWS tool or service should the agency use to obtain these official documents?
A global organization wants to implement a robust security logging and auditing architecture. They need to meet three distinct security and operational monitoring objectives:
1. They must track and log all management events and API calls across their entire AWS Organization for compliance auditing.
2. They need to monitor CPU utilization and disk read/write metrics of their Amazon EC2 instances to dynamically scale resources and trigger operational alerts.
3. They require intelligent threat detection that uses machine learning to continuously analyze metadata logs (such as VPC Flow Logs and DNS logs) to identify potential malicious activity.
Which combination of AWS services should the organization implement to satisfy these requirements?
A media streaming platform is implementing a security policy to protect user payment information and video assets on AWS. The security team needs to configure encryption for data at rest in Amazon S3 and data in transit between users and the streaming application. Which of the following statements represent the customer's responsibility under the AWS Shared Responsibility Model for this data protection scenario? (Select TWO.)
Geçerli olan tümünü seçin
A cloud administrator is configuring security settings for an Amazon S3 bucket that will store proprietary company documents. To protect data at rest, which security action is the cloud administrator responsible for executing?
A gaming company is migrating its leaderboard database to AWS. The company needs to encrypt the database backups stored in Amazon S3 at rest and ensure that all data sent to the database is encrypted in transit. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
A tourism agency is deploying a customer-facing mobile booking application and decides to use Amazon Cognito for user authentication and directory management. Under the AWS Shared Responsibility Model, which of the following is a responsibility of the customer?
An application developer is configuring security rules for an Amazon EC2 instance. They notice that when they allow inbound traffic on a specific port, the return outbound traffic is automatically allowed without requiring an explicit outbound rule. Which AWS network security component exhibits this stateful behavior?
A newly formed cloud engineering team needs to perform daily administrative duties, such as configuring network settings and launching Amazon EC2 instances. Which approach represents the AWS-recommended best practice for securing the AWS account root user while enabling these tasks?
A cloud engineer has successfully created a new AWS account for a startup. To secure the account immediately, what is the AWS-recommended best practice for performing daily administrative operations?
A financial technology firm wants to enhance its security posture on AWS. The firm needs to meet two specific requirements: first, they want to continuously monitor their AWS accounts, workloads, and data for malicious activity, such as unauthorized API calls or potential data exfiltration. Second, they need an automated way to scan container images stored in Amazon Elastic Container Registry (Amazon ECR) for software vulnerabilities before they are deployed to production.
Which two AWS services should the firm use to satisfy these security requirements? (Select two.)
Geçerli olan tümünü seçin
A small retail business is deploying a new online storefront using Amazon Lightsail virtual private servers. Under the AWS Shared Responsibility Model, which two security-related tasks are the responsibility of the customer? (Select TWO)
Geçerli olan tümünü seçin
A business is deploying its first application in a Virtual Private Cloud (VPC) and needs to configure basic network security controls. The administrator wants to use both Security Groups and Network Access Control Lists (Network ACLs) to secure their resources.
Which TWO statements correctly describe the characteristics of these security resources?
Geçerli olan tümünü seçin
A digital healthcare company hosts a patient portal on AWS and must meet strict regulatory compliance requirements for security monitoring and auditing. The compliance and operations teams define three specific requirements:
1. Every API call made by IAM users or AWS services must be recorded, stored securely, and cryptographically validated to ensure the integrity of the audit logs.
2. System administrators must receive real-time alerts if application-level logs on Amazon EC2 instances show a sudden spike in specific error codes.
3. The environment must be continuously analyzed for malicious activity, such as instances scanning for open ports or communicating with known malicious IP addresses.
Which of the following configurations should the company implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A logistics company wants to track activity across its AWS infrastructure. The operations team needs to:
1. Audit all user actions and API calls to identify who deleted an Amazon S3 bucket.
2. Monitor system performance metrics, such as CPU utilization of Amazon EC2 instances, and trigger alarms if they exceed normal thresholds.
Which AWS services should the company use to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A retail company wants to secure its AWS infrastructure by auditing all API activities and setting up real-time monitoring for unauthorized access attempts. The security team needs to track who made API calls to modify security group rules and also detect if any Amazon EC2 instances are communicating with known malicious IP addresses.
Which AWS services should the company implement to meet these security requirements? (Select TWO)
Geçerli olan tümünü seçin
A smart home device manufacturer hosts its telemetry processing application on a fleet of Amazon EC2 instances. The security team wants to continuously monitor the AWS environment for potential security threats, such as EC2 instances communicating with known malicious IP addresses or unexpected API calls from unauthorized locations. Which AWS service should the manufacturer use to detect these active threats?
A company is configuring access for two new entities: a monitoring application running on an on-premises server that requires read-only access to Amazon CloudWatch, and a new human administrator who needs full access to manage Amazon EC2 resources. Which IAM identities should the company create to provide secure access for these entities? (Select TWO)
Geçerli olan tümünü seçin