Security and Compliance
441 soru
An online education platform stores student grades and profile details on AWS. To comply with privacy standards, the platform must ensure that data is encrypted both at rest and in transit. Under the AWS shared responsibility model, which of the following actions are responsibilities of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A cloud administrator is designing the network security architecture for a multi-tier application. The administrator needs to implement a firewall barrier at the boundary of a subnet that evaluates traffic flow in both directions independently (stateless). Which AWS resource must be used to achieve this?
A pharmaceutical research firm is deploying an application that uses Amazon DynamoDB to store proprietary drug discovery data. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
When configuring security controls within an Amazon Virtual Private Cloud (VPC), understanding the behavior of instance-level and subnet-level firewalls is critical. Which two of the following statements correctly describe the operational characteristics of these network security resources?
Geçerli olan tümünü seçin
An online educational platform hosts its application on Amazon EC2 instances. The DevOps team wants to automatically scan these virtual servers for software packages with known vulnerabilities and identify any unintended public network exposure. Which AWS service should the platform use to perform this automated vulnerability assessment?
A financial institution is migrating its payment transaction database to AWS. Due to strict regulatory compliance requirements, the institution must manage and control its cryptographic keys using dedicated, single-tenant hardware security modules (HSMs) directly within their Virtual Private Cloud (VPC). Which AWS service should the institution use to meet this requirement?
A multiplayer gaming startup needs to establish a security and operational monitoring strategy on AWS. The security team wants to audit all API actions and configuration changes made by developers across their AWS account. Concurrently, the operations team needs to track performance metrics of their Amazon EC2 instances and receive automated alerts if CPU utilization exceeds 80%. Which combination of AWS services should the startup implement to meet these requirements?
A media streaming company uses Amazon CloudFront to deliver video content to users globally. Under the AWS Shared Responsibility Model, which TWO of the following tasks are the responsibility of AWS?
Geçerli olan tümünü seçin
A logistics company manages its supply chain application on AWS. The security team needs to implement a solution that satisfies two requirements: first, automatically scanning container images stored in Amazon Elastic Container Registry (ECR) for software vulnerabilities; second, continuously monitoring the AWS environment for anomalous API activity and potential unauthorized access. Which of the following AWS services should the company use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
To secure a newly created AWS account, an administrator needs to establish basic identity and access controls. According to AWS security best practices, which of the following actions should the administrator perform? (Select TWO.)
Geçerli olan tümünü seçin
A travel booking platform is deploying a new application on AWS. To secure customer reservation records, the platform needs to encrypt data at rest within its storage services. The security team wants to use a fully managed service that creates and controls the cryptographic keys, rather than renting dedicated, single-tenant cryptographic hardware. Which AWS service is designed to meet this requirement?
An administrator needs to configure a network access control list (network ACL) to allow inbound traffic on a specific port to a subnet. Which of the following actions is also required to allow response traffic back to the client?
A biotechnology firm is preparing for an audit to verify compliance with international security standards. The compliance team needs to obtain AWS security reports and establish which security controls are the direct responsibility of the cloud provider. Which TWO actions should the company take to meet these requirements?
Geçerli olan tümünü seçin
A cloud practitioner is designing a database subnet within an Amazon VPC and needs to apply a firewall rule set at the subnet boundary. The configuration must be stateless, requiring both inbound and outbound traffic rules to be explicitly defined. Which AWS service or feature should be implemented to meet this requirement?
A company wants to allow its on-premises employees to access the AWS Management Console using their existing corporate directory credentials instead of creating individual IAM users. Which of the following are required to configure this federated access? (Select TWO.)
Geçerli olan tümünü seçin
A media company is migrating its video-on-demand platform to AWS. The security team needs to implement a logging and security monitoring solution that meets two requirements:
1. It must record, continuously monitor, and retain a history of all API calls and user actions within the AWS account for compliance auditing.
2. It must provide continuous, intelligent threat detection and anomaly monitoring to identify potential malicious activity, such as brute-force attacks or compromised credentials.
Which AWS services should the company implement to satisfy these security requirements? (Select two.)
Geçerli olan tümünü seçin
A financial company needs to implement a security and monitoring solution for its AWS environment. The security team must be able to audit all API actions taken by users and services across the account. Additionally, the operations team needs to collect and track performance metrics for their Amazon EC2 instances to configure automated alerts for high CPU utilization. Which of the following AWS services should be used to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A developer is troubleshooting connectivity to an Amazon EC2 instance and needs to analyze the firewall settings. The developer must evaluate the differences in behavior between security groups and network access control lists (network ACLs). Which two statements correctly describe how traffic is processed by these security features? (Select TWO.)
Geçerli olan tümünü seçin
A ridesharing service processes real-time driver and passenger location data on AWS. The security department wants to establish automated threat detection that monitors their AWS accounts for anomalous behavior, such as API activity from unrecognized IP addresses, compromised credentials, or EC2 instances communicating with malicious IP addresses. The service must analyze AWS CloudTrail event logs, VPC Flow Logs, and DNS logs. Which AWS service meets these needs?
A media streaming company is preparing for a security compliance review. The audit team needs to verify which IAM identity made the API calls to modify the configuration of an Amazon S3 bucket containing sensitive customer billing data. At the same time, the security team wants to set up automated threat detection to identify potential unauthorized activity or compromised credentials in their AWS environment. Which combination of AWS services should the company use to meet these requirements?