Tüm alıştırma soruları
1462 soru
A financial services firm is establishing a landing zone to host transaction-processing workloads that must comply with PCI-DSS. The company has structured its AWS Organizations hierarchy with distinct Organizational Units (OUs) for Core, Workloads, and Sandbox. The architecture team needs to restrict root user activity in the member accounts, enforce multi-factor authentication (MFA) for administrative tasks, and implement a single sign-on experience linked to their corporate identity provider (IdP). Which combination of actions should the Solutions Architect take to establish this governance framework? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is consolidating its billing and resource management under AWS Organizations. The security team wants to establish centralized access control so that employees can sign in using their existing corporate credentials and access their assigned AWS accounts without managing separate passwords. Which of the following is the most secure and operationally efficient method to achieve this goal?
A logistics company is designing a multi-account strategy using AWS Organizations. The IT department wants to implement centralized user access for administrative staff by integrating their existing external identity provider. Furthermore, the security team requires that no member account is allowed to disable AWS CloudTrail logging. Which solution should a solutions architect recommend to satisfy these requirements?
A software-as-a-service (SaaS) provider has multiple development and production environments, each hosted in a separate AWS account within an organization in AWS Organizations. The IT security team must establish a single location to manage user access and ensure that developers cannot configure long-term IAM user credentials. Which of the following actions should the Solutions Architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is configuring a new AWS Lambda function that must read data from an Amazon DynamoDB table. According to AWS security best practices, how should the solutions architect grant the Lambda function the necessary permissions to access the table?
A company has multiple AWS accounts managed under AWS Organizations. The security audit team in the central audit account needs read-only access to Amazon S3 buckets containing CloudTrail logs in all member accounts. A solutions architect must configure this access securely following the principle of least privilege. Which TWO actions should the solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial services company is deploying an application on-premises that needs to periodically read and write files to an Amazon S3 bucket. The application must also retrieve credentials to connect to an Amazon RDS database and decrypt sensitive configuration files using an AWS KMS customer managed key. The company's security policy strictly prohibits the use of long-term AWS credentials and requires that all access be based on temporary security credentials. The company already has an established internal public key infrastructure (PKI). Which combination of actions should a solutions architect recommend?
A Solutions Architect is designing a secure multi-account environment using AWS Organizations. The environment consists of a management account and multiple member accounts grouped into operational Organizational Units (OUs). The security team has established two key governance mandates: first, users from the corporate external Active Directory must have single sign-on access to member accounts based on their job roles without using persistent IAM credentials; second, all member accounts must be prevented from stopping AWS CloudTrail logging or deleting trails. Which combination of actions should the Solutions Architect take to satisfy these mandates? (Select TWO.)
Geçerli olan tümünü seçin
A company needs to grant a third-party auditing firm temporary access to run configuration compliance checks on resources across all accounts in its AWS Organization. The auditing firm will access the organization's accounts from their own AWS account () using a commercial automated tool. The company's security policy requires that:
- The auditing tool must only be allowed to read resource configuration metadata, with no access to read actual data stored in Amazon S3 buckets or databases.
- The configuration must mitigate the risk of the 'confused deputy' security vulnerability.
- The access granted to the auditing firm must automatically expire in days without requiring manual intervention.
Which solution meets these requirements securely and with the least administrative overhead?
A financial services company is using AWS Organizations to manage its multi-account environment. The security team wants to ensure that no member accounts in the 'Core-Workloads' Organizational Unit (OU) can disable Amazon GuardDuty or delete its detectors. Additionally, the company needs to establish centralized access control so that employees can sign in using their existing corporate identity provider credentials and be mapped to specific roles across various AWS accounts. Which combination of actions will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A Solutions Architect is designing a multi-account strategy using AWS Organizations. The organization consists of a management account, a Security organizational unit (OU), a Production OU, and a Development OU. The security team requires that no users or roles in the Production and Development OUs are allowed to disable AWS CloudTrail or delete trails. However, the Security OU must retain the ability to modify CloudTrail settings for automated maintenance. Additionally, the company wants to implement centralized single sign-on access using their existing external identity provider (IdP) without managing individual credentials in each member account.
Which combination of actions will meet these security and access requirements?
A Solutions Architect is designing a security governance framework for a healthcare technology provider. The provider has a multi-account environment managed through AWS Organizations, structured with separate OUs for Production, Testing, and Shared Services. The compliance team mandates that no IAM user or role within any member account—including administrative users—can create unencrypted Amazon EBS volumes or delete AWS KMS customer managed keys. Furthermore, the organization wants to manage human access centrally via an existing Microsoft Entra ID tenant without maintaining long-term security credentials in individual member accounts.
Which combination of actions should the Solutions Architect take to satisfy these governance and security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company needs to configure administrative access for a systems administrator to manage AWS resources daily. According to AWS security best practices, which approach should the company use to grant this access?
An organization is designing a serverless data processing application. AWS Lambda functions in the application must securely access a database password to connect to an Amazon RDS database. The database credentials must be rotated every 30 days without application downtime. Additionally, an external compliance auditor requires temporary, read-only access to the Amazon S3 bucket where the processed output files are stored.
Which combination of actions should the solutions architect take to meet these requirements securely? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise runs a microservices-based application on Amazon ECS in Account B. The application requires read access to sensitive customer data files stored in an Amazon S3 bucket within Account A. The S3 bucket is encrypted using an AWS KMS customer managed key (CMK) in Account A. A solutions architect must design a secure, cross-account access pattern following the principle of least privilege, ensuring that credentials are not hardcoded or stored insecurely. Which combination of configurations must the solutions architect implement to achieve this goal? (Select TWO.)
Geçerli olan tümünü seçin
A company is deploying a new web application on AWS using Amazon CloudFront and an Application Load Balancer. The company needs to design a security strategy that protects the application against two specific threats: common application-layer exploits such as SQL injection, and volumetric Layer 3 and Layer 4 DDoS attacks.
Which combination of AWS services should the solutions architect implement to address these threats? (Select TWO.)
Geçerli olan tümünü seçin
A municipal transit authority operates a real-time vehicle tracking API endpoint on AWS. The API is deployed behind an Application Load Balancer (ALB) and receives rapid HTTP requests from commuter mobile applications. The authority needs to protect the infrastructure from volumetric Layer 3/4 DDoS attacks and prevent clients from overwhelming the backend EC2 instances with high-rate Layer 7 HTTP GET requests. Which combination of AWS configurations should a solutions architect implement to meet these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is deploying an application on Amazon EC2 instances. The application needs to retrieve data from an Amazon DynamoDB table. Which TWO actions should a solutions architect take to configure access to the DynamoDB table in a secure manner? (Select TWO.)
Geçerli olan tümünü seçin
A Solutions Architect is designing a multi-account environment on AWS for a global retail analytics platform. The company wants to enforce a policy where database administrators can only manage database resources within specific production and development accounts. In addition, the security team requires that all user authentication be centralized against their existing external identity provider, and that security monitoring configurations in member accounts cannot be modified by any local administrators. Which combination of actions should the Solutions Architect recommend to meet these requirements with the least administrative effort?
A financial company uses a central identity AWS account to federate user logins from an external OIDC-compliant Identity Provider (IdP). Developers must perform administrative tasks on Amazon EC2 instances and Amazon RDS databases in multiple application-specific AWS accounts. The security team mandates that access must be granted dynamically based on the developer’s active project assignment, which is stored as a custom attribute in the IdP. The solution must enforce Attribute-Based Access Control (ABAC), support temporary credentials, and ensure no credentials or user profiles are manually maintained in the target application accounts. Which combination of actions will meet these requirements securely?