Design Secure Architectures
438 soru
A Solutions Architect is designing a secure multi-account environment using AWS Organizations. The company needs to centrally manage single sign-on access for all employees across the accounts. Additionally, the security team must enforce compliance policies to prevent member accounts from disabling logging. Which combination of AWS services or features should the Solutions Architect implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company runs an application on an Amazon EC2 instance. The application needs to read and write items in an Amazon DynamoDB table. According to AWS security best practices, which approach should a solutions architect use to grant the application access to the DynamoDB table?
An enterprise architecture uses a centralized logging account (Account A) containing an Amazon S3 bucket for security audit logs. The bucket is encrypted using an AWS KMS customer managed key owned by Account A. A security auditing application runs on Amazon EC2 instances in a production account (Account B) and must write compliance reports directly to the S3 bucket in Account A.
Which combination of configuration steps will allow the application to securely write reports to the bucket while adhering to the principle of least privilege?
An enterprise application running on Amazon ECS tasks in AWS Account A () must retrieve sensitive daily reports from an Amazon S3 bucket located in AWS Account B (). The S3 bucket is encrypted using an AWS KMS customer managed key (CMK) in Account B. The solution must ensure that only the ECS tasks can access the data, adhere strictly to the principle of least privilege, and avoid the use of long-term credentials. Which combination of configurations will securely meet these requirements?
An organization needs to implement centralized user access management for its engineering department across a newly created multi-account AWS environment. The security policy mandates that engineers use their existing corporate directory credentials to log in, and no long-term credentials should be distributed.
Which solution should a Solutions Architect implement to meet these governance requirements?
A retail company has migrated its business units into separate AWS accounts controlled by AWS Organizations. The compliance department demands that all developer access be federated from the company's external Active Directory, granting role-based access without long-term credentials. Furthermore, the company must guarantee that no administrator in any member account can delete or stop AWS CloudTrail logging. Which combination of AWS configurations will satisfy these requirements?
An enterprise is planning to grant its network engineering team access to manage resources in the AWS Cloud. The network engineers are currently managed in the company's on-premises Active Directory. The company's security policy requires that engineers authenticate using their existing corporate credentials and that no long-term AWS credentials, such as access keys, are created or stored. Which solution meets these requirements while following AWS security best practices?
An organization needs to grant console access to its team of internal software developers. The developers already authenticate daily using the company's central Active Directory. Which approach represents the most secure method for granting AWS Management Console access to these developers?
A financial services firm is establishing a landing zone to host transaction-processing workloads that must comply with PCI-DSS. The company has structured its AWS Organizations hierarchy with distinct Organizational Units (OUs) for Core, Workloads, and Sandbox. The architecture team needs to restrict root user activity in the member accounts, enforce multi-factor authentication (MFA) for administrative tasks, and implement a single sign-on experience linked to their corporate identity provider (IdP). Which combination of actions should the Solutions Architect take to establish this governance framework? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is consolidating its billing and resource management under AWS Organizations. The security team wants to establish centralized access control so that employees can sign in using their existing corporate credentials and access their assigned AWS accounts without managing separate passwords. Which of the following is the most secure and operationally efficient method to achieve this goal?
A logistics company is designing a multi-account strategy using AWS Organizations. The IT department wants to implement centralized user access for administrative staff by integrating their existing external identity provider. Furthermore, the security team requires that no member account is allowed to disable AWS CloudTrail logging. Which solution should a solutions architect recommend to satisfy these requirements?
A software-as-a-service (SaaS) provider has multiple development and production environments, each hosted in a separate AWS account within an organization in AWS Organizations. The IT security team must establish a single location to manage user access and ensure that developers cannot configure long-term IAM user credentials. Which of the following actions should the Solutions Architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is configuring a new AWS Lambda function that must read data from an Amazon DynamoDB table. According to AWS security best practices, how should the solutions architect grant the Lambda function the necessary permissions to access the table?
A company has multiple AWS accounts managed under AWS Organizations. The security audit team in the central audit account needs read-only access to Amazon S3 buckets containing CloudTrail logs in all member accounts. A solutions architect must configure this access securely following the principle of least privilege. Which TWO actions should the solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial services company is deploying an application on-premises that needs to periodically read and write files to an Amazon S3 bucket. The application must also retrieve credentials to connect to an Amazon RDS database and decrypt sensitive configuration files using an AWS KMS customer managed key. The company's security policy strictly prohibits the use of long-term AWS credentials and requires that all access be based on temporary security credentials. The company already has an established internal public key infrastructure (PKI). Which combination of actions should a solutions architect recommend?
A Solutions Architect is designing a secure multi-account environment using AWS Organizations. The environment consists of a management account and multiple member accounts grouped into operational Organizational Units (OUs). The security team has established two key governance mandates: first, users from the corporate external Active Directory must have single sign-on access to member accounts based on their job roles without using persistent IAM credentials; second, all member accounts must be prevented from stopping AWS CloudTrail logging or deleting trails. Which combination of actions should the Solutions Architect take to satisfy these mandates? (Select TWO.)
Geçerli olan tümünü seçin
A company needs to grant a third-party auditing firm temporary access to run configuration compliance checks on resources across all accounts in its AWS Organization. The auditing firm will access the organization's accounts from their own AWS account () using a commercial automated tool. The company's security policy requires that:
- The auditing tool must only be allowed to read resource configuration metadata, with no access to read actual data stored in Amazon S3 buckets or databases.
- The configuration must mitigate the risk of the 'confused deputy' security vulnerability.
- The access granted to the auditing firm must automatically expire in days without requiring manual intervention.
Which solution meets these requirements securely and with the least administrative overhead?
A financial services company is using AWS Organizations to manage its multi-account environment. The security team wants to ensure that no member accounts in the 'Core-Workloads' Organizational Unit (OU) can disable Amazon GuardDuty or delete its detectors. Additionally, the company needs to establish centralized access control so that employees can sign in using their existing corporate identity provider credentials and be mapped to specific roles across various AWS accounts. Which combination of actions will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A Solutions Architect is designing a multi-account strategy using AWS Organizations. The organization consists of a management account, a Security organizational unit (OU), a Production OU, and a Development OU. The security team requires that no users or roles in the Production and Development OUs are allowed to disable AWS CloudTrail or delete trails. However, the Security OU must retain the ability to modify CloudTrail settings for automated maintenance. Additionally, the company wants to implement centralized single sign-on access using their existing external identity provider (IdP) without managing individual credentials in each member account.
Which combination of actions will meet these security and access requirements?
A Solutions Architect is designing a security governance framework for a healthcare technology provider. The provider has a multi-account environment managed through AWS Organizations, structured with separate OUs for Production, Testing, and Shared Services. The compliance team mandates that no IAM user or role within any member account—including administrative users—can create unencrypted Amazon EBS volumes or delete AWS KMS customer managed keys. Furthermore, the organization wants to manage human access centrally via an existing Microsoft Entra ID tenant without maintaining long-term security credentials in individual member accounts.
Which combination of actions should the Solutions Architect take to satisfy these governance and security requirements? (Select TWO.)
Geçerli olan tümünü seçin