AWS Certified Security – Specialty practice questions

207 free questions with answers and explanations.

Practice test
  1. 1.A financial institution is storing sensitive customer transaction data in Amazon S3. Due to regulatory compliance, this data must be retained for 7 years in an immutable state, meaning it cannot be deleted or modified by anyone, including root users, for the duration of the retention period. After 7 years, the data can be automatically deleted. Which combination of S3 features will meet these requirements most effectively?Domain 5: Data Protection
  2. 2.A research institution stores highly sensitive genomic data in an Amazon S3 bucket. This data must remain immutable for a minimum of 10 years to comply with regulatory mandates, meaning it cannot be overwritten or deleted by any user, including the root account. After 10 years, the data can be automatically deleted. Which S3 feature should be used to enforce this immutability and automatic deletion?Domain 5: Data Protection
  3. 3.A security team needs to ensure that all IAM users in a specific AWS account are forced to enable multi-factor authentication (MFA) for console access. If a user attempts to access the console without MFA, the access should be denied. Which IAM policy condition should be used to enforce this requirement?Domain 4: Identity and Access Management
  4. 4.A company uses AWS SSO (IAM Identity Center) to manage access to multiple AWS accounts. They have several AWS accounts organized into Organizational Units (OUs). A new security policy requires that all users in the 'Developers' group, who are part of the 'Development' OU, must have read-only access to all S3 buckets in their respective development accounts. How should this be configured using IAM Identity Center?Domain 4: Identity and Access Management
  5. 5.A global e-commerce company uses Amazon S3 to store customer order data. Due to varying international data privacy regulations, the company must classify its data based on sensitivity (e.g., Public, Internal, Confidential, Restricted) and apply appropriate retention policies and access controls. Public data can be stored indefinitely, Internal data for 5 years, Confidential for 7 years, and Restricted for 10 years. What is the most effective and scalable way to implement this data classification and lifecycle management within AWS, ensuring compliance and minimizing operational overhead?Domain 5: Data Protection
  6. 6.A large enterprise with a complex AWS environment is migrating applications that require robust, centralized logging and auditing of all AWS API calls and related events across all accounts in their AWS Organization. They need to ensure that the audit logs are immutable, encrypted, and stored in a central, secure S3 bucket that cannot be tampered with, even by root users of individual member accounts. Which solution should the security architect recommend?Domain 4: Identity and Access Management
  7. 7.A global software company is developing a new application that processes highly sensitive customer financial data. The company has a strict policy that all encryption keys must be generated, stored, and managed in an external key management system (KMS) located outside of AWS. The application needs to encrypt data before it is uploaded to Amazon S3. Which method should the company use to meet this requirement?Domain 5: Data Protection
  8. 8.A company policy dictates that all AWS IAM users must use strong, unique passwords and enable Multi-Factor Authentication (MFA). An AWS Config rule is in place to detect non-compliant MFA settings for IAM users. However, the security team needs a proactive measure to prevent users from disabling their MFA devices or changing their password policy settings after they have been configured correctly. Which IAM condition key should be used in an IAM policy to prevent these changes?Domain 4: Identity and Access Management
  9. 9.A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be retained for 7 years and remain immutable, meaning they cannot be deleted or modified by any user, including the root account. After the 7-year retention period, the logs can be automatically deleted to manage storage costs. Which S3 configuration should be implemented?Domain 5: Data Protection
  10. 10.A research institution is storing petabytes of genomic data in Amazon S3. This data is rarely accessed after its initial upload and processing, but must be retained for at least 10 years for compliance reasons. The institution needs to minimize storage costs while ensuring data integrity and durability. Which S3 storage class is the most cost-effective solution for this scenario?Domain 5: Data Protection
  11. 11.A research institution is storing petabytes of genomic data in Amazon S3. This data is rarely accessed (less than once a year) but must be retained for regulatory purposes for at least 10 years. When access is required, it can tolerate retrieval times of several hours. The institution needs the most cost-effective storage solution while meeting these requirements. Which S3 storage class should be used?Domain 5: Data Protection
  12. 12.A company is using AWS Cognito User Pools for customer authentication in their mobile application. They want to integrate with another backend service that requires temporary, fine-grained access to AWS resources (e.g., uploading files to a specific S3 bucket). The integration needs to be secure and minimize the exposure of long-term credentials. Which service should be used to provide these temporary AWS credentials to the authenticated Cognito users?Domain 4: Identity and Access Management
  13. 13.A company is implementing a new compliance requirement that mandates all access to AWS resources must originate from corporate IP addresses, with the exception of specific mobile users who need to access resources from anywhere using multi-factor authentication (MFA). How can this be achieved using IAM policies?Domain 4: Identity and Access Management
  14. 14.A global enterprise collects and processes customer data from various regions worldwide. Due to strict data residency regulations in the EU, all data originating from EU customers must be stored and processed exclusively within the EU. The enterprise uses Amazon S3 for data storage and AWS Lambda for processing. How can the company ensure data residency for EU customer data?Domain 5: Data Protection
  15. 15.A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. They are required to encrypt all new objects uploaded to this bucket by default. Additionally, they need to ensure that the encryption keys are centrally managed and that access to these keys is auditable. Which S3 encryption configuration meets these requirements while providing central key management and auditability?Domain 5: Data Protection
  16. 16.A company is implementing a data loss prevention (DLP) strategy for sensitive documents stored in Amazon S3. The company needs to automatically identify documents containing PII (e.g., social security numbers, credit card numbers) and prevent them from being shared publicly or with unauthorized external parties. Which AWS service is best suited for automatically discovering, classifying, and reporting on such sensitive data in S3?Domain 5: Data Protection
  17. 17.A financial institution is migrating its on-premises applications to AWS. These applications rely heavily on Kerberos authentication and LDAP for user and group management. The institution requires a fully managed directory service that can seamlessly integrate with their existing on-premises Active Directory while providing high availability and disaster recovery within AWS. They also need to ensure that AWS services can directly authenticate against this directory. Which AWS directory service best meets these requirements?Domain 4: Identity and Access Management
  18. 18.A company is implementing a new policy that requires all S3 buckets to be encrypted at rest. They want to ensure that if a user attempts to upload an unencrypted object to any S3 bucket, the upload fails. Additionally, all existing unencrypted objects must be encrypted. Which combination of S3 features will provide the most comprehensive solution without requiring changes to existing application code?Domain 4: Identity and Access Management
  19. 19.A global technology company is developing a new serverless application that processes highly sensitive personal data. The data will be stored in an Amazon RDS PostgreSQL database. Due to data residency regulations, all data must remain within the EU. The company also requires that the encryption keys for the database are customer-managed and automatically rotated annually. Which solution meets these requirements?Domain 5: Data Protection
  20. 20.A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to performance requirements, the table is configured for on-demand capacity. The company's compliance regulations mandate that all data at rest must be encrypted with customer-managed keys (CMKs) from AWS KMS. What is the most straightforward way to ensure that the DynamoDB table's data is encrypted with the specified CMK?Domain 5: Data Protection
  21. 21.A security auditor discovers that an IAM role in an AWS account has a trust policy that allows an external AWS account (Account B) to assume it. However, the external account is no longer managed by the company. The auditor needs to revoke access for Account B immediately and ensure no other external accounts can assume this role in the future, while still allowing existing internal trusted entities to assume the role. Which action should the auditor take?Domain 4: Identity and Access Management
  22. 22.A global company uses AWS Organizations and has a multi-account strategy. They want to ensure that all IAM users across all member accounts are required to use Multi-Factor Authentication (MFA) when accessing the AWS Management Console. Furthermore, they want to prevent any member account from disabling this MFA requirement. Which AWS service or feature should the security team use to enforce this policy centrally?Domain 4: Identity and Access Management
  23. 23.A development team uses AWS CodeBuild to run CI/CD pipelines. The CodeBuild projects need to access resources in other AWS accounts, such as pulling code from a CodeCommit repository in a 'Source' account and deploying artifacts to an S3 bucket in a 'Deployment' account. The security team wants to ensure that these cross-account interactions adhere to the principle of least privilege and are auditable. What is the most secure and scalable approach?Domain 4: Identity and Access Management
  24. 24.A media company uses Amazon S3 to store large video files that are frequently accessed by content delivery networks (CDNs). They need to ensure that all data is encrypted at rest and in transit. The company also wants to minimize operational overhead for key management. Which encryption solution meets these requirements with the least operational burden?Domain 5: Data Protection
  25. 25.A security team needs to enforce that all IAM users in a specific AWS account are forced to re-authenticate using Multi-Factor Authentication (MFA) if their last MFA authentication occurred more than 4 hours ago. This requirement applies to all actions on sensitive resources. Which IAM condition key should be used in an IAM policy to achieve this?Domain 4: Identity and Access Management
  26. 26.A global media company stores vast amounts of video content (terabytes) in Amazon S3. This content is frequently accessed by customers for streaming, requiring low-latency access. However, after 30 days, the content's access frequency significantly drops, becoming rarely accessed but still needing to be available within minutes if requested. The company wants to optimize storage costs while maintaining accessibility. Which S3 storage class transition strategy should be implemented?Domain 5: Data Protection
  27. 27.A software-as-a-service (SaaS) company is developing a new application that stores highly sensitive customer data. The company's compliance requirements mandate that all customer data must be encrypted using customer-controlled keys. Additionally, the application needs to perform cryptographic operations (encrypt, decrypt) on the data within a FIPS 140-2 Level 3 validated hardware security module (HSM) that is fully managed by AWS. Which AWS service should the security architect recommend to meet these stringent encryption and key management requirements?Domain 5: Data Protection
  28. 28.A financial institution is developing a new data analytics platform that processes highly sensitive customer financial data. They need to ensure that all data in Amazon S3 is encrypted at rest and that the encryption keys are automatically rotated annually for enhanced security. The solution should minimize manual intervention for key rotation. Which S3 encryption configuration, combined with key management, best meets these requirements?Domain 5: Data Protection
  29. 29.A global banking institution uses Amazon S3 to store transaction logs. Due to compliance requirements, these logs must be retained for 5 years in an immutable state, meaning they cannot be deleted or modified. After the 5-year period, the logs must be automatically moved to a lower-cost archival storage class and then deleted after an additional 2 years. Which solution effectively combines S3 features to meet these requirements?Domain 5: Data Protection
  30. 30.A security engineer is designing an access strategy for a new application that will process highly sensitive customer data. The application consists of multiple microservices running on Amazon EKS, and each microservice requires specific, fine-grained permissions to interact with various AWS services (e.g., S3, DynamoDB, SQS). The engineer wants to ensure that each microservice has only the permissions it needs, without sharing credentials or relying on EC2 instance profiles. How can the engineer securely manage these permissions for the EKS microservices?Domain 4: Identity and Access Management
  31. 31.A company is developing a new serverless application that uses AWS Lambda functions to process data stored in Amazon S3. The Lambda functions need to read from a source S3 bucket and write to a destination S3 bucket. The security team insists on implementing the principle of least privilege. Which is the MOST secure way to grant the Lambda functions access to the S3 buckets?Domain 4: Identity and Access Management
  32. 32.A financial institution requires strict access control for its data stored in Amazon S3. They have a policy that states data owners must explicitly approve every new access grant to their S3 buckets. Additionally, all S3 buckets must be private by default. Which access control mechanism, combined with appropriate IAM policies, best supports this requirement without creating overly permissive access or management overhead?Domain 4: Identity and Access Management
  33. 33.A company policy dictates that all AWS IAM users must use strong, unique passwords and enable multi-factor authentication (MFA). The security team wants to automate the enforcement of these policies and detect non-compliant users. Which combination of AWS services should be used?Domain 4: Identity and Access Management
  34. 34.A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to compliance requirements, all data at rest in DynamoDB must be encrypted with customer-managed keys (CMKs) from AWS Key Management Service (KMS). The security team needs to ensure that these CMKs are automatically rotated annually for enhanced security. Which option fulfills this requirement?Domain 5: Data Protection
  35. 35.A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically isolated and encrypted using a unique encryption key, managed by the SaaS provider, to meet multi-tenancy security requirements. The solution should also allow for individual customer key revocation without impacting other tenants. Which encryption approach should the SaaS provider implement?Domain 5: Data Protection
  36. 36.A global media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to a new compliance mandate, all data stored in DynamoDB must be encrypted at rest. Furthermore, the encryption keys must be rotated automatically on an annual basis to enhance security posture. Which DynamoDB encryption configuration meets these requirements with minimal operational overhead for key management?Domain 5: Data Protection
  37. 37.A financial institution is migrating its on-premises applications to AWS. These applications rely heavily on a centralized Microsoft Active Directory for user authentication and authorization. The institution requires a highly available, scalable, and secure directory service that can seamlessly integrate with existing on-premises Active Directory and also provide single sign-on (SSO) capabilities for AWS services and third-party applications. Which AWS service should the institution choose to meet these requirements?Domain 4: Identity and Access Management
  38. 38.A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. The company needs to implement a solution to ensure that all objects uploaded to this S3 bucket are encrypted at rest using encryption keys that they manage, and that all access to these encryption keys is centrally audited. Which S3 encryption option should be chosen?Domain 5: Data Protection
  39. 39.A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted using a unique encryption key derived from their individual customer ID. This ensures that a compromise of one key does not affect other customers' data. The solution needs to be scalable and efficient for a large number of tenants. Which data protection approach should be used?Domain 5: Data Protection
  40. 40.A company is migrating its on-premises directory services to AWS and needs a managed solution for user authentication and authorization. The solution must support multi-factor authentication (MFA) and integrate with existing enterprise applications that use LDAP. The security team also requires the ability to apply fine-grained access control to AWS resources based on group memberships. Which AWS service should the company use to meet these requirements?Domain 4: Identity and Access Management
  41. 41.A company is implementing a new policy that requires all S3 buckets to be encrypted at rest. They want to enforce this at the account level to prevent any unencrypted objects from being uploaded to any S3 bucket. If an object is uploaded without encryption headers, it should be denied. Which S3 bucket policy should be implemented to meet this requirement?Domain 4: Identity and Access Management
  42. 42.A global company uses AWS IAM Identity Center (formerly AWS Single Sign-On) to manage access to multiple AWS accounts for its employees. The company has a requirement that all administrative access to production AWS accounts must enforce multi-factor authentication (MFA). Normal user access to development accounts does not require MFA. How can the security administrator enforce this MFA requirement efficiently using IAM Identity Center?Domain 4: Identity and Access Management
  43. 43.A global e-commerce company uses Amazon S3 to store customer order data, which is classified into various sensitivity levels (e.g., PII, financial, public). They need to automate the classification of new objects as they are uploaded to S3 and trigger different workflows based on the sensitivity level. For instance, highly sensitive data might require immediate alerting and a stricter access policy. Which solution effectively automates this data classification and subsequent action?Domain 5: Data Protection
  44. 44.A research institution is storing highly sensitive genomic data in Amazon S3. This data must adhere to strict data classification standards, requiring that access be granted only to specific researchers for specific projects, and only from within authorized VPCs. Furthermore, the data must never be exposed to the public internet. How can the institution enforce these granular access controls and network isolation for the S3 bucket?Domain 5: Data Protection
  45. 45.A financial services company is developing a new application that processes highly sensitive customer financial data. The company's compliance requirements dictate that data must be encrypted at rest and in transit, and that the encryption keys must be managed by the customer. Furthermore, the solution must prevent any AWS service from automatically decrypting the data on behalf of the customer without explicit customer action or permission. Which encryption solution provides the highest level of customer control and prevents automatic AWS service decryption?Domain 5: Data Protection
  46. 46.A development team uses AWS CodeBuild to run CI/CD pipelines. The CodeBuild projects need to retrieve source code from a private Amazon S3 bucket, publish build artifacts to another S3 bucket, and update an Amazon DynamoDB table with build status. The security team wants to apply the principle of least privilege. Which approach ensures CodeBuild projects have only the necessary permissions?Domain 4: Identity and Access Management
  47. 47.A global pharmaceutical company is developing a new data analytics platform that processes highly sensitive patient genomic data. This data is stored in Amazon S3. The company has a strict regulatory requirement that all encryption keys for sensitive data must be generated and managed within their on-premises Hardware Security Modules (HSMs) and never leave the HSM boundary. The solution must integrate seamlessly with AWS services for data processing and storage, without compromising the on-premises key management policy. Which AWS data protection solution should the company implement?Domain 5: Data Protection
  48. 48.A financial institution is migrating its on-premises data to AWS. Due to strict regulatory requirements, they need to prevent any AWS account within their organization from creating S3 buckets in regions outside of the EU (e.g., US regions) to ensure data residency. They also need to enforce that all S3 buckets are created with default encryption enabled. Which AWS service can enforce these organization-wide policies?Domain 5: Data Protection
  49. 49.A financial services company is storing customer transaction data in Amazon S3. Due to regulatory requirements (e.g., GDPR, CCPA), they must be able to identify and redact or delete specific customer data upon request, even within archived datasets. The data is currently stored in S3 Glacier Deep Archive for cost efficiency. Which data classification and management strategy allows for efficient identification and targeted deletion of specific customer records while maintaining cost-effectiveness for long-term storage?Domain 5: Data Protection
  50. 50.A global e-commerce company uses Amazon S3 to store customer order data, which is classified into 'Public', 'Internal', and 'Confidential' based on its sensitivity. The security team needs to automatically discover and classify new objects uploaded to S3 into these categories and identify any 'Confidential' data that might be inadvertently exposed. Which AWS service is best suited for this task?Domain 5: Data Protection