Security and Compliance
441 soru
A university IT department is setting up its AWS environment. The administrator needs to configure permissions for two scenarios: first, allowing an Amazon EC2 instance to securely write logs to an Amazon CloudWatch Logs stream; second, organizing access for ten lab students who all require identical read-only permissions to Amazon S3. Which of the following IAM solutions represent AWS best practices for these scenarios? (Select TWO.)
Geçerli olan tümünü seçin
An online travel agency is migrating its booking application to AWS. The agency must ensure that customer passport numbers are encrypted at rest using encryption keys managed by the customer, and that database backups are securely stored. Under the AWS shared responsibility model, which of the following are responsibilities of the customer for protecting this data? (Select TWO.)
Geçerli olan tümünü seçin
A company hosts a payroll processing portal on Amazon EC2 instances inside a virtual private cloud (VPC). The security administrator needs to permit inbound HTTPS traffic on port 443 from a specific corporate office IP address range. The administrator wants the return traffic from the EC2 instances back to the corporate office to be permitted automatically without needing to define any outbound rules. Which AWS resource or feature should the administrator configure to meet these requirements?
A logistics firm runs a vehicle tracking application on Amazon EC2 instances within a specific subnet in a Virtual Private Cloud (VPC). The security team must implement a solution that allows incoming HTTPS traffic to the EC2 instances from a trusted corporate partner's IP address range. Additionally, they must block all inbound traffic from a known malicious IP range at the subnet boundary. Which combination of AWS network security actions will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A digital publishing company is storing sensitive author manuscripts in an Amazon S3 bucket. The company mandates the use of server-side encryption with AWS Key Management Service (SSE-KMS) to protect the data at rest. Under the AWS Shared Responsibility Model, which of the following security-related tasks is the responsibility of the customer?
A fintech startup is deploying a transaction processing application on AWS. They need to configure access control for two distinct scenarios: first, an application running on an Amazon EC2 instance that needs to read and write transactions to an Amazon DynamoDB table; second, a cloud engineer who requires access to the AWS Management Console to monitor resources. Which of the following identity and access management practices should the startup implement? (Select TWO.)
Geçerli olan tümünü seçin
A research institution runs high-performance scientific simulations on Amazon EC2 instances within a private subnet. The security team must implement a network security strategy that meets two requirements:
1. Block traffic from a specific range of external IP addresses at the subnet boundary by explicitly evaluating both inbound and outbound traffic.
2. Allow incoming simulation control data to the EC2 instances, ensuring that return traffic is automatically permitted without requiring explicit outbound rules.
Which combination of AWS features best satisfies these requirements?
A real estate platform is migrating its property transaction registry to AWS. The platform must encrypt all sensitive transaction records at rest using AWS Key Management Service (AWS KMS). Under the AWS Shared Responsibility Model, which of the following actions are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
An eco-tourism agency hosts its public-facing room booking portal on Amazon EC2 instances within a public subnet, and its internal database on EC2 instances within a private subnet. The security team needs to configure network security controls to meet two requirements: block specific malicious public IP addresses at the subnet boundary, and allow the web servers to communicate with the database while ensuring return traffic is automatically allowed at the instance level. Which TWO configurations should the security team implement to meet these requirements?
Geçerli olan tümünü seçin
A logistics company is deploying a global package tracking system on AWS. The security team mandates that all telemetry data must be encrypted in transit from the tracking devices to the application's Application Load Balancer. Under the AWS Shared Responsibility Model, which of the following actions is the responsibility of the customer to meet this requirement?
A software development company wants to allow its developers to access the AWS Management Console using their existing corporate Active Directory credentials. The security team needs to configure this access without creating individual IAM users for each developer. Which of the following approaches represents the AWS-recommended best practice to achieve this?
A financial services firm is deploying a web application on Amazon EC2 instances in a new Virtual Private Cloud (VPC). The network security team wants to configure a firewall control that operates at the instance level. They require that any inbound traffic allowed into the instance is automatically permitted to flow outbound, without needing to create a corresponding outbound rule. Which AWS resource meets these requirements?
A healthcare provider plans to build a patient portal on AWS. The portal will run on Amazon EC2 instances and store sensitive medical imaging files in an Amazon S3 bucket. Compliance regulations require all data to be encrypted both at rest and in transit.
Which of the following actions are the responsibility of the customer to ensure data protection under the AWS Shared Responsibility Model? (Select TWO.)
Geçerli olan tümünü seçin
A growing digital marketing agency wants to streamline permissions management for its designers, copywriters, and analysts. The agency needs to ensure that when a new designer joins, they automatically receive the correct permissions, and when they change roles, their permissions are updated easily. Which of the following options represent AWS-recommended best practices to achieve this? (Select TWO.)
Geçerli olan tümünü seçin
A health-tech startup hosts its patient record database on Amazon EC2 instances inside a private subnet of a Virtual Private Cloud (VPC). The security team needs to restrict incoming database traffic to only the application server instances. Additionally, any outbound response traffic from the database back to the application servers must be allowed automatically, without configuring an explicit outbound rule. Which AWS firewall option should the security team configure to meet these requirements?
An organization is designing the network security architecture for a multi-tier application in an Amazon VPC. The database tier resides in a private subnet, while the web tier is in a public subnet. The security team needs to implement controls to restrict inbound and outbound traffic at both the subnet boundary and the individual Amazon EC2 instance level. Which of the following statements correctly describe the characteristics of Security Groups and Network Access Control Lists (Network ACLs) in this architecture? (Select TWO.)
Geçerli olan tümünü seçin
A media company is hosting a public-facing live video streaming ingest service on Amazon EC2 instances. The administrator needs to permit incoming traffic on port 1935 (RTMP) and ensure that outbound response traffic is automatically permitted back to the client without configuring any outbound rules. Which AWS security resource should be configured to meet this requirement?
A company is configuring network security for a web application hosted on Amazon EC2 instances in a VPC. The security team has two requirements:
1. Apply rules at the subnet boundary where both inbound and outbound traffic must be explicitly allowed, as rules are evaluated independently for return traffic.
2. Apply rules at the instance boundary where allowing inbound traffic automatically permits the corresponding outbound return traffic.
Which combination of AWS security features should the company use to meet these requirements?
A gaming company is deploying matchmaking servers on Amazon EC2 instances within a Virtual Private Cloud (VPC). The network security architecture must meet the following requirements:
1. Control traffic at the individual instance level, ensuring that return traffic for allowed inbound requests is automatically permitted.
2. Control traffic at the subnet boundary, acting as a secondary layer of defense that requires explicit rules for both inbound and outbound traffic.
Which two AWS network security features should the company implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An online education platform hosts its virtual classroom application on Amazon EC2 instances within a public subnet of a VPC. To enhance security, the network administrator must meet two requirements:
1. Block all inbound traffic from a known list of malicious IP addresses before it reaches the subnet.
2. Ensure the EC2 instances accept inbound HTTPS traffic on port 443, while automatically allowing the outbound response traffic back to the clients without configuring any outbound rules.
Which combination of AWS security features will satisfy these requirements?