Security and Compliance
441 soru
An enterprise is launching a new microservice on Amazon Elastic Container Service (Amazon ECS) that needs to write data to an Amazon DynamoDB table. Which configuration represents the most secure method for granting the microservice the necessary permissions?
An IoT company deploys telemetry collection servers on Amazon EC2 instances within a custom subnet. The cloud practitioner configures a Network Access Control List (Network ACL) at the subnet level to allow inbound TCP traffic on port 8883 from the internet. Although the EC2 instances' Security Groups are configured to allow all outbound traffic, the external sensors are unable to receive acknowledgment responses from the servers. Which of the following configuration changes is required to resolve this issue and allow the acknowledgment traffic back to the sensors?
A company is hosting a virtual classroom platform with video processing workloads on Amazon EC2 instances inside a private subnet. The security team wants to implement a multi-layered security approach: they need to block a specific range of malicious external IP addresses at the subnet boundary, and they must allow administrative SSH traffic to the instances from a designated bastion host while ensuring that the return traffic is automatically permitted. Which TWO of the following configurations should the team implement?
Geçerli olan tümünü seçin
A financial technology company is deploying a payment processing application on AWS. Their security policy mandates that all transaction logs must be encrypted at rest using cryptographic keys where the customer maintains direct control over key access policies. Furthermore, all data transmitted between their application servers and the database must be encrypted. Which of the following actions are responsibilities of the customer under the AWS Shared Responsibility Model to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is deploying an application on Amazon Elastic Compute Cloud (Amazon EC2) that must securely read data from an Amazon Simple Storage Service (Amazon S3) bucket and write results to an Amazon DynamoDB table. The security team mandates that no long-term credentials be stored on the instance and that the principle of least privilege be strictly followed. Which of the following actions should the company perform to meet these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A media streaming startup deploys its backend APIs using AWS Lambda. Under the AWS Shared Responsibility Model, which of the following operational tasks is the responsibility of the startup?
An online gaming platform is deploying a new database on Amazon EC2 instances to store player profile data. The security team must ensure that all data stored on the EC2 instances' Amazon Elastic Block Store (EBS) volumes is encrypted at rest. According to the AWS Shared Responsibility Model, which of the following is the customer’s responsibility in this scenario?
An enterprise manages its applications using separate AWS accounts for development and production. A developer in the development account needs to temporarily read logs from an Amazon S3 bucket located in the production account. Which of the following approaches represents the AWS-recommended security best practice to configure this cross-account access?
An inventory management system hosts its database on Amazon EC2 instances within a private subnet. The database instances must only receive inbound database traffic on port 5432 from the application tier EC2 instances. A cloud practitioner configures a Security Group for the database instances with an inbound rule allowing TCP traffic on port 5432 from the application tier's security group. Which of the following outbound configuration options is required on the database security group to allow the database instances to successfully return response traffic back to the application tier?
A logistics company is migrating its supply chain management system to AWS. The system will store shipment records in Amazon S3 and database backups on Amazon EBS volumes. The company's security policy requires all data to be encrypted at rest and in transit. According to the AWS Shared Responsibility Model, which of the following security actions are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A retail company is deploying a secure three-tier application within an Amazon VPC. The operations team needs to understand how to apply firewall-like controls at both the instance level and the subnet boundary. Which two of the following statements accurately describe the characteristics and behavior of Security Groups and Network Access Control Lists (Network ACLs) in this environment?
Geçerli olan tümünü seçin
An e-learning platform hosts its student database on Amazon RDS. The platform's security policy requires all data to be encrypted in transit between the application servers and the database instance. Under the AWS Shared Responsibility Model, which of the following is a customer responsibility for securing this data in transit?
An organization wants to grant their third-party auditing team temporary access to audit their AWS cloud resources for compliance. At the same time, the organization needs to allow their database administrators to manage Amazon RDS resources without sharing credentials or using individual user policies. Which of the following configurations align with AWS Identity and Access Management (IAM) best practices? (Select TWO.)
Geçerli olan tümünü seçin
A media streaming startup is configuring network security for its delivery servers within an Amazon VPC. The system administrator needs to block traffic from a list of known malicious IP addresses at the subnet boundary. The administrator must also manually define both inbound and outbound rules because the firewall does not automatically allow return traffic. Which AWS feature meets these requirements?
A financial technology company hosts a transaction processing application on Amazon EC2 instances within a private subnet. The security team must implement a network security strategy that blocks specific malicious IP addresses at the subnet boundary and restricts instance-level access to only authorized application servers. Which of the following configurations should the cloud practitioner implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare enterprise needs to store sensitive patient files on Amazon S3. To meet compliance regulations, they require encryption at rest using dedicated, single-tenant cryptographic hardware where they maintain full control over the administration of the hardware security modules (HSMs). Which AWS service or feature should the enterprise configure to manage their encryption keys?
A cloud architect at a media agency needs to manage AWS permissions for a team of 15 video editors and 5 system administrators. The video editors require read-only access to Amazon S3 buckets, while the administrators need full access to Amazon EC2 and Amazon RDS. Which of the following represents the most efficient way to manage and apply these permissions using AWS Identity and Access Management (IAM)?
A company is preparing for an internal security audit of its AWS environment. The security team discovers that several developers are sharing a single set of access keys to perform administrative tasks, and an automated application is using the AWS account root user credentials to generate daily billing reports. Which of the following remediation steps should the security team take to align with AWS Identity and Access Management (IAM) best practices? (Select TWO.)
Geçerli olan tümünü seçin
A gaming studio deploys a multiplayer matchmaking backend on Amazon EC2 instances inside a public subnet. The studio wants to ensure that only traffic from a specific list of trusted IP addresses can access these instances, and they want to minimize administrative overhead by relying on a stateful resource. Which AWS resource should be configured directly at the instance level to allow inbound traffic from these IP addresses while automatically permitting the corresponding outbound response traffic?
A smart home IoT startup is deploying an application on AWS to collect and store telemetry data. The startup's security policy requires encrypting all data at rest using AWS Key Management Service (AWS KMS). Under the AWS Shared Responsibility Model, which of the following represent the responsibilities of the customer and AWS regarding encryption and key management? (Select TWO)
Geçerli olan tümünü seçin