Security and Compliance
441 soru
A healthcare provider plans to store patient medical records in Amazon Simple Storage Service (Amazon S3) and must encrypt the data at rest to comply with regulatory standards. The provider wants to control their own encryption keys but wishes to avoid the operational overhead of provisioning, configuring, and maintaining dedicated, single-tenant hardware. Which solution and division of responsibility meets these requirements?
A startup is reviewing its AWS security configuration. Currently, all developers share a single IAM user with administrator privileges to manage resources, and an application running on Amazon EC2 instances uses hardcoded access keys to write data to an Amazon S3 bucket. Which of the following actions should the security team take to align with AWS security best practices? (Select TWO).
Geçerli olan tümünü seçin
An organization is deploying a new containerized application on Amazon EC2 instances that must periodically write application state data to an Amazon DynamoDB table. Additionally, an external compliance auditor requires temporary read-only access to the DynamoDB table to verify data integrity. Which two configurations represent the most secure AWS-recommended practices for managing these access requirements? (Select two.)
Geçerli olan tümünü seçin
A software-as-a-service (SaaS) provider needs to periodically analyze resource configurations stored in an Amazon S3 bucket within a customer's AWS account. The customer wants to grant this access to the provider's AWS account securely without creating or exchanging permanent IAM credentials. Which of the following is the AWS-recommended best practice to achieve this?
A media streaming company is preparing for an audit and needs to verify that the underlying AWS infrastructure complies with payment card industry and international security standards. Which AWS service provides the company with on-demand access to AWS security and compliance reports?
A municipality is deploying a smart parking system that collects sensor data using Amazon EC2 instances located in a private subnet. The network engineering team must design a security controls strategy to govern inbound and outbound traffic at both the subnet boundary and the instance level. Which two of the following statements correctly describe the behavior of the security components needed for this architecture?
Geçerli olan tümünü seçin
A company is configuring network security for an Amazon EC2 instance. The administrator wants to apply stateful firewall rules directly to the instance. Under the AWS Shared Responsibility Model, which of the following is the customer's responsibility to configure to meet this requirement?
A retail enterprise connects its on-premises data center to an AWS Virtual Private Cloud (VPC) using an AWS Site-to-Site VPN. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A software development team is building a serverless, event-driven web application. The architecture utilizes AWS Lambda to run the backend application code and Amazon DynamoDB as the database layer. According to the AWS Shared Responsibility Model, which of the following operational tasks are the sole responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A company is deploying a fleet of Amazon Elastic Compute Cloud (Amazon EC2) instances to host a new customer portal. According to the AWS Shared Responsibility Model, which of the following operational tasks is the sole responsibility of the customer?
A financial technology company deploys a transactional database using Amazon Relational Database Service (Amazon RDS). As part of a security audit, the company must document the division of operational tasks based on the AWS Shared Responsibility Model. Which of the following tasks is the customer's responsibility under the AWS Shared Responsibility Model for this database deployment?
A company is deploying a web application on an Amazon EC2 instance that needs to read and write files to an Amazon S3 bucket. Which of the following is the AWS-recommended best practice to grant the application access to the S3 bucket?
An administrator needs to configure an application running on an Amazon EC2 instance to read files from an Amazon S3 bucket. According to AWS security best practices, which approach should the administrator use to grant the EC2 instance the necessary permissions?
A company has a fleet of Amazon EC2 instances that need to dynamically retrieve customer reports from a private Amazon S3 bucket. The lead developer wants to ensure that the application on these instances has secure, programmatic access without hardcoding credentials or exposing the account to security risks. Which approach aligns with the AWS-recommended best practice for granting this access?
A multi-department enterprise needs to grant a third-party auditing firm temporary, read-only access to specific AWS Billing reports and Amazon CloudTrail logs in their production AWS account. The auditing firm has its own AWS account. Which of the following approaches is the most secure and aligns with AWS Identity and Access Management (IAM) best practices to accomplish this?
A multinational retail company is hosting its web applications on Amazon EC2 instances and is preparing for an upcoming external security audit. The company needs to document the exact division of security tasks between themselves and AWS. Which of the following tasks is the sole responsibility of AWS under the AWS Shared Responsibility Model?
A financial services company is migrating a multi-tier application to AWS. The web tier will be deployed on Amazon EC2 instances, while the data tier will utilize Amazon RDS for PostgreSQL. The company's security policy requires guest operating system patching and firewall port configurations to be strictly maintained. According to the AWS Shared Responsibility Model, which of the following statements correctly identifies the division of operational responsibilities between the customer and AWS for this deployment?
A financial services company uses an Amazon Simple Storage Service (Amazon S3) bucket to store sensitive customer account statements. Which of the following tasks are the responsibility of the customer under the AWS Shared Responsibility Model? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare organization stores medical imaging files and patient records in Amazon Simple Storage Service (Amazon S3) buckets. Under the AWS Shared Responsibility Model, which of the following security tasks are the sole responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A startup is setting up its first AWS account and wants to follow AWS Identity and Access Management (IAM) best practices to secure access for its developers and services. Which two recommendations should the startup implement to secure the account? (Select TWO.)
Geçerli olan tümünü seçin