Security and Compliance
441 soru
A company is building a hybrid application where an on-premises server must upload log files directly to an Amazon S3 bucket. Additionally, a third-party auditing agency requires temporary, read-only access to inspect the S3 bucket's access configurations. To meet compliance standards, the company must avoid configuring or managing long-term AWS credentials for either the on-premises server or the external auditors. Which of the following solutions should the company implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is setting up a new multi-department environment on AWS. The security team is defining identity and access management policies for corporate employees, applications running on Amazon EC2 instances, and administrative workflows. Which of the following are recommended AWS IAM best practices for managing access for these entities? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare technology company is deploying a serverless application that processes patient health records. The architecture consists of an HTTPS endpoint hosted on Amazon API Gateway, custom backend logic running in AWS Lambda, and patient data stored in Amazon DynamoDB. Under the AWS Shared Responsibility Model, which two security and operational tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A company is using Amazon DynamoDB to store application data. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A software development company is migrating its monolithic API to a serverless architecture using AWS Lambda. As part of this transition, the security team is defining operational tasks under the AWS Shared Responsibility Model. Which of the following tasks remains the sole responsibility of the customer when deploying code to AWS Lambda?
A company needs to grant a newly hired security analyst access to the AWS Management Console to audit resource configurations. The analyst requires their own permanent credentials to log in. Which IAM entity should the administrator create to meet this requirement?
A developer using an IAM user in a development account (Account A) requires temporary access to perform administrative tasks on an Amazon DynamoDB table located in a production account (Account B). To adhere to AWS security best practices and the principle of least privilege, which of the following configuration steps must be implemented? (Select TWO.)
Geçerli olan tümünü seçin
A startup has five developers who all need the same administrative permissions to manage Amazon EC2 resources. According to AWS security best practices, which of the following is the most efficient way to manage these permissions?
A gaming company has a mobile application that needs to securely write game state files to an Amazon S3 bucket. Millions of players will use this application, and they must not have permanent AWS credentials embedded in the app code. Which approach should the company use to grant this access?
A media streaming company is deploying a containerized microservice using Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. The security team needs to define the operational boundaries between the company and AWS to ensure compliance. Which of the following operational tasks is the sole responsibility of the customer under the AWS Shared Responsibility Model for this architecture?
A company needs to restrict its database administrators from modifying Amazon RDS instances when they are working outside of the corporate network or outside of standard business hours. Which IAM mechanism should the security team implement to enforce these specific access conditions?
An administrator has created a new AWS account to host a student portal. To align with AWS security best practices, which action should the administrator perform first regarding the AWS account root user?
A startup is deploying a containerized microservices application using Amazon ECS on AWS Fargate. Under the AWS Shared Responsibility Model, which of the following tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A logistics company is containerizing its route-optimization API and deploying it using Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. The security team is establishing operational workflows to comply with the AWS Shared Responsibility Model. Which of the following tasks remains the sole responsibility of the customer in this deployment model?
A local healthcare provider is setting up access control for its staff in the AWS Cloud. The administrator needs to configure secure access for human users and application services while adhering to AWS Identity and Access Management (IAM) best practices. Which of the following actions represent AWS-recommended IAM security best practices for this setup? (Select TWO.)
Geçerli olan tümünü seçin
A retail company's security team is auditing its AWS environment. An application hosted on Amazon EC2 instances must access a private Amazon S3 bucket to process transaction logs, and an external security consultant requires temporary access to review the IAM configurations. Which TWO of the following options represent AWS-recommended security practices to implement these requirements?
Geçerli olan tümünü seçin
A shipping logistics company is deploying its microservices-based application using containers on AWS Fargate. Under the AWS Shared Responsibility Model, which two security tasks are the responsibility of the customer? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare organization is preparing for an external audit to verify HIPAA compliance for its cloud-based medical records application. The application's architecture consists of Amazon Elastic Compute Cloud (Amazon EC2) instances behind an Application Load Balancer, with data stored in an Amazon Aurora MySQL database cluster. To satisfy the audit, the organization must provide documentation of physical data center security, evidence of guest operating system patch compliance, and proof of data-in-transit encryption. Under the AWS Shared Responsibility Model, which combination of actions is the customer responsible for performing to meet these requirements?
An organization needs to grant a third-party security auditing application read-only access to review configuration metadata across all AWS resources in their production account. To comply with the AWS Shared Responsibility Model and Identity and Access Management (IAM) security best practices, which configuration should the cloud administrator implement?
A financial technology company is preparing for an annual security audit and needs to retrieve the latest AWS Service Organization Control (SOC) reports to verify AWS compliance. Which AWS service or portal provides on-demand access to these third-party audit reports?