AWS Certified Security – Specialty practice questions
207 free questions with answers and explanations.
- 51.A developer needs temporary credentials to access an Amazon S3 bucket from an EC2 instance. The EC2 instance is launched in a private subnet and does not have direct internet access. The credentials must be automatically rotated and follow the principle of least privilege. Which is the MOST secure and efficient way to provide these credentials?Domain 4: Identity and Access Management
- 52.A company uses AWS Organizations and has a multi-account strategy. They want to ensure that no AWS account within their organization can ever create an Amazon S3 bucket that is publicly accessible, regardless of any IAM policies or S3 bucket policies applied at the account level. This restriction must apply to all current and future accounts. Which AWS Organizations feature should be implemented to enforce this control?Domain 4: Identity and Access Management
- 53.A security administrator is reviewing an Amazon S3 bucket policy. The policy allows `s3:PutObject` action from a specific VPC endpoint (`vpce-1234567890abcdef0`) but implicitly denies all other principals. The administrator wants to ensure that all objects uploaded to this bucket are encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS), and that only a specific KMS key (`arn:aws:kms:us-east-1:123456789012:key/abc-123`) is used. How should the S3 bucket policy be modified to enforce this encryption requirement?Domain 4: Identity and Access Management
- 54.A company wants to centralize logging and auditing across all its AWS accounts, which are managed under AWS Organizations. They need to ensure that all AWS CloudTrail logs are delivered to a single, dedicated S3 bucket in a central logging account. No AWS account or user should be able to disable CloudTrail or modify its configuration to prevent logs from reaching the central bucket. Which solution provides the strongest, preventative control?Domain 4: Identity and Access Management
- 55.A security auditor needs to gain read-only access to all AWS accounts within an AWS Organization to review security configurations and compliance. The auditor's team uses a dedicated audit AWS account. The solution must ensure that the auditor's access is restricted to read-only operations and that the access can be easily revoked centrally if needed. Which approach should be implemented?Domain 4: Identity and Access Management
- 56.A security auditor discovers that an IAM role in an AWS account has a trust policy that allows `sts:AssumeRole` from any principal (`"AWS": "*"`). This role also has an attached IAM policy that grants administrative access (`AdministratorAccess`). The auditor is concerned about the security implications of this configuration. What is the MOST immediate and significant risk posed by this trust policy, even if the attached IAM policy has specific resource constraints?Domain 4: Identity and Access Management
- 57.A global technology company is developing a new serverless application that processes highly sensitive customer data. The data is stored in Amazon DynamoDB. Due to strict compliance requirements, all data in DynamoDB must be encrypted at rest with customer-managed keys (CMKs) that are automatically rotated annually. The security team also requires granular control over who can access and use these encryption keys. Which DynamoDB encryption configuration meets these requirements?Domain 5: Data Protection
- 58.A global enterprise collects and processes customer data from various regions worldwide. Due to stringent data sovereignty regulations in Europe, all personal data originating from EU citizens must be stored and processed exclusively within the EU. The enterprise uses Amazon S3 for data storage and AWS Lambda for processing. How can the enterprise enforce this data sovereignty requirement effectively?Domain 5: Data Protection
- 59.A financial institution is migrating its on-premises data to AWS. Due to strict regulatory compliance, all customer data, including personally identifiable information (PII) and financial transaction records, must remain within a specific geographic region (e.g., Frankfurt, Germany) and not leave that region, even for backup or disaster recovery purposes, unless explicitly approved through a separate, highly secure process. This includes data at rest and data in transit. Which AWS service or feature should the security architect primarily leverage to enforce this data residency requirement for S3 buckets storing this sensitive data?Domain 5: Data Protection
- 60.A company uses Amazon Cognito User Pools for authenticating its mobile application users. The application needs to allow authenticated users to upload images directly to a specific Amazon S3 bucket. Unauthenticated users should have restricted read-only access to a public S3 bucket. Additionally, the application requires fine-grained access control based on user attributes (e.g., premium users can access certain folders). Which AWS service and configuration should be used to achieve this?Domain 4: Identity and Access Management
- 61.A company is migrating its on-premises applications to AWS. These applications rely heavily on Microsoft Active Directory for user authentication and group-based access control. The company wants to minimize changes to its existing application code and administrative processes. They also require secure, high-availability integration with their AWS resources. Which AWS service is best suited for this requirement?Domain 4: Identity and Access Management
- 62.A global pharmaceutical company processes highly sensitive patient data in an AWS environment. Due to stringent regulatory requirements and internal security policies, all data must be encrypted at the application layer before being written to Amazon S3. The company also requires that the encryption keys are managed within an on-premises Hardware Security Module (HSM) and never leave the HSM for cryptographic operations. Which data encryption solution should the company implement?Domain 5: Data Protection
- 63.A global pharmaceutical company is building a new data lake on AWS using Amazon S3. The data lake will store highly sensitive genomic research data, patient records, and clinical trial results. The company requires that all data at rest be encrypted with customer-managed keys (CMKs) and that the encryption keys never leave the AWS Key Management Service (KMS) boundary, even during cryptographic operations. They also need to ensure that different research teams can manage their own encryption keys for their specific datasets while still adhering to the central security policy. Which data encryption solution best meets these requirements?Domain 5: Data Protection
- 64.A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. The data must be encrypted at rest and in transit. The security team requires full control over the encryption keys, including the ability to generate, rotate, and revoke them, with an audit trail of all key usage. The solution must also support integration with AWS CloudTrail for logging key operations. Which S3 encryption option best meets these requirements?Domain 5: Data Protection
- 65.A security engineer is configuring AWS Organizations for a new enterprise. The organization has several Organizational Units (OUs) for different departments, and each OU contains multiple AWS accounts. The engineer needs to ensure that no IAM user or role in any account can disable AWS CloudTrail logging. This restriction must apply even to administrators within the member accounts but should not affect the root user of the management account. Which AWS Organizations feature should be used?Domain 4: Identity and Access Management
- 66.A media company stores large volumes of video assets in Amazon S3. These assets are frequently accessed for a month after upload, then become rarely accessed but must be retained for 7 years for archival purposes. The security team also mandates that all data, regardless of its storage class, must be encrypted at rest. To optimize costs while meeting retention and encryption requirements, which S3 storage class and lifecycle policy combination should be recommended?Domain 5: Data Protection
- 67.A security engineer is designing an access strategy for a new application that will store highly sensitive customer data in an Amazon S3 bucket. Access to this bucket must be restricted to specific AWS IAM roles within the same AWS account and must also prevent data exfiltration by ensuring that objects can only be accessed from specific VPC endpoints. Additionally, the solution must prevent root user access to the bucket. Which combination of access control mechanisms should the security engineer implement to meet these requirements?Domain 4: Identity and Access Management
- 68.A global manufacturing company is migrating its enterprise resource planning (ERP) system to AWS. The ERP system stores highly sensitive intellectual property (IP) and financial data in an Amazon Aurora MySQL-compatible database. The company has a strict compliance requirement that mandates the use of hardware security modules (HSMs) for cryptographic operations and key storage. They also need to retain full control over the cryptographic keys. Which solution meets these requirements for encryption at rest for the Aurora database?Domain 5: Data Protection
- 69.A company uses AWS Organizations and has several member accounts. They want to ensure that specific sensitive S3 buckets, located in a 'DataLake' member account, can only be accessed by IAM roles within that same 'DataLake' account and by a dedicated 'AnalyticsRole' in a separate 'Analytics' member account. All other cross-account access to these buckets, including by the root user of any member account, must be explicitly denied. How can this be achieved most securely and efficiently?Domain 4: Identity and Access Management
- 70.A company is implementing a new compliance requirement that mandates all access to AWS resources must be explicitly allowed. If an action is not explicitly allowed by any policy, it must be denied. The security team wants to ensure that this principle is applied consistently across all IAM users, groups, and roles within a specific AWS account. How can they achieve this?Domain 4: Identity and Access Management
- 71.A security engineer is designing an access strategy for a new application that will process highly sensitive customer data. The application runs on EC2 instances and needs to securely store temporary credentials for accessing an Amazon S3 bucket, an Amazon DynamoDB table, and an Amazon SQS queue. The credentials must be rotated frequently and should not be hardcoded into the application. Which AWS service and feature should the engineer use to meet these requirements?Domain 4: Identity and Access Management
- 72.A security engineer needs to configure an S3 bucket policy for a new data lake. The policy must ensure that all objects uploaded to the bucket are encrypted using server-side encryption with AWS Key Management Service (SSE-KMS) and that the specific KMS key 'arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567' is used. Furthermore, any upload request that does not specify this encryption method and key must be explicitly denied. Which S3 bucket policy statement achieves this requirement?Domain 4: Identity and Access Management
- 73.A company is implementing a new compliance requirement that mandates all access to AWS resources must adhere to the principle of least privilege. They have an existing IAM user, 'AuditorUser', who has an attached policy allowing `s3:GetObject` on `arn:aws:s3:::my-sensitive-data-bucket/*`. However, a separate, broader policy attached to the 'AuditorGroup' (to which 'AuditorUser' belongs) explicitly denies `s3:*` actions on `arn:aws:s3:::my-sensitive-data-bucket/*`. When 'AuditorUser' attempts to retrieve an object from `my-sensitive-data-bucket`, what is the outcome, and why?Domain 4: Identity and Access Management
- 74.A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. Due to compliance requirements (e.g., HIPAA), all PHI must be encrypted at rest, and there must be a detailed audit trail of all key usage. The security team wants to manage the encryption keys and their policies directly. Which S3 encryption option best meets these requirements?Domain 5: Data Protection
- 75.A company is deploying a new web application that requires user authentication. The application needs to support both traditional username/password authentication and social identity providers like Google and Facebook. User profiles, including custom attributes, must be stored and managed securely. Which AWS service is best suited to handle these authentication and user management requirements?Domain 4: Identity and Access Management
- 76.A security auditor discovers that an IAM role named 'DevAdminRole' in an AWS account has a trust policy that allows an external AWS account (Account ID: 111122223333) to assume the role. The auditor also finds that the 'DevAdminRole' has an attached inline policy that grants 's3:*' permissions to all S3 buckets. The external account should no longer have any access. What is the MOST effective way to revoke access for the external account while ensuring the 'DevAdminRole' can still be used by trusted internal users?Domain 4: Identity and Access Management
- 77.A global software company is developing a new application that processes highly sensitive customer data. Due to regulatory requirements, all data at rest must be encrypted with keys that are stored and managed outside of AWS for complete customer control and to prevent AWS personnel from accessing the plaintext data. The solution needs to integrate with AWS services like Amazon S3 and Amazon RDS. Which encryption solution meets these stringent requirements?Domain 5: Data Protection
- 78.A global enterprise needs to store highly sensitive customer data in an Amazon S3 bucket. Access to this S3 bucket must be restricted to resources originating only from a specific Amazon Virtual Private Cloud (VPC) within the same AWS Region. Furthermore, all data transfers between the VPC and S3 must remain within the AWS network and not traverse the public internet. Which solution effectively enforces these access and network requirements?Domain 5: Data Protection
- 79.A security team has discovered an IAM role that is configured with a broad trust policy, allowing principals from another AWS account to assume it without any conditions. The role also has an attached policy that grants extensive permissions, including 'ec2:*' and 's3:*'. The team needs to immediately revoke access for the external account and implement a more secure configuration for future cross-account access, requiring MFA for any assumption of this role. Which two actions should the security team take?Domain 4: Identity and Access Management
- 80.A global pharmaceutical company is building a new data lake on AWS using Amazon S3. The data lake will store clinical trial data, which is highly regulated and requires encryption at rest using keys that are regularly rotated. The company's security policy states that the encryption keys must be unique for every object to minimize the blast radius if a single key is compromised. Which S3 encryption option, combined with a key management strategy, fulfills these requirements most effectively?Domain 5: Data Protection
- 81.A security engineer is troubleshooting an access issue for an IAM user named 'AppUser' in an AWS account. 'AppUser' is a member of the 'Developers' IAM group and has a directly attached IAM policy. The 'Developers' group also has an attached IAM policy. Additionally, a permissions boundary is attached to 'AppUser'. The user is trying to perform an action that they believe should be allowed, but they are receiving an 'Access Denied' error. In which order does IAM evaluate these policies to determine access?Domain 4: Identity and Access Management
- 82.A company stores application logs in Amazon CloudWatch Logs. Due to compliance requirements, these logs must be encrypted at rest. The company requires that the encryption keys be managed by AWS Key Management Service (KMS) with customer control over key access policies and auditability through CloudTrail. How can the security engineer ensure that CloudWatch Logs are encrypted with customer-managed KMS keys?Domain 5: Data Protection
- 83.A global enterprise needs to store highly sensitive customer data in an Amazon S3 bucket. Access to this data must be strictly controlled, allowing only specific IAM roles from a particular AWS account to read objects. Furthermore, the data must only be accessible from within the company's Virtual Private Cloud (VPC) through a private network connection, never over the public internet. Which combination of S3 bucket policies and network configurations will enforce these requirements?Domain 5: Data Protection
- 84.A pharmaceutical company is storing highly sensitive genomic research data in an Amazon S3 bucket. This data is subject to strict regulatory compliance that requires frequent audits to demonstrate that data has not been tampered with and retains its integrity. The company needs a mechanism to prove the immutability of the data and detect any unauthorized modifications over its entire lifecycle. Which AWS service and configuration should the company implement?Domain 5: Data Protection
- 85.A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be immutable for 7 years and then automatically deleted. Additionally, the institution needs to ensure that the immutability period cannot be shortened or bypassed by any user, including the root account. Which combination of S3 features should be used?Domain 5: Data Protection
- 86.A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted with a unique key derived from their individual tenant ID, to meet multi-tenancy isolation requirements and demonstrate strong data segregation. The solution must be scalable and minimize the performance impact on DynamoDB operations. Which encryption strategy should be implemented?Domain 5: Data Protection
- 87.A global enterprise collects and processes customer data from various regions worldwide. Due to strict data sovereignty laws (e.g., GDPR, CCPA), the enterprise must ensure that customer data originating from a specific country or economic bloc (e.g., European Union) is processed and stored exclusively within that geographic boundary. The solution needs to prevent data from being accidentally or maliciously moved outside its designated region. Which combination of AWS services and features provides the most robust and scalable solution for enforcing this data sovereignty?Domain 5: Data Protection
- 88.A global technology company is developing a new serverless application that processes highly sensitive customer personal data. The application uses AWS Lambda functions to process data and stores it in Amazon RDS for PostgreSQL. The company has a strict data residency requirement that mandates all data, including backups and snapshots, must remain within a specific AWS Region. Which solution ensures that the data at rest, including backups and snapshots, adheres to this data residency requirement?Domain 5: Data Protection
- 89.A global financial institution is expanding its operations into a new country with strict data residency laws. All customer data for this region must be stored and processed exclusively within the country's borders. The institution plans to use Amazon RDS for PostgreSQL to store customer transaction data and requires that all backups and snapshots also adhere to these residency requirements. Which solution ensures both the primary database and its backups remain within the specified AWS Region?Domain 5: Data Protection
- 90.A global e-commerce company uses Amazon S3 to store customer order data, which is classified into 'Public,' 'Internal,' and 'Confidential' categories. The security team wants to automatically identify and classify any newly uploaded objects that contain personally identifiable information (PII) or other sensitive data, regardless of their initial classification, and then trigger an alert. Which AWS service should be used to achieve this continuous and automated data classification and alerting?Domain 5: Data Protection
- 91.A healthcare organization stores sensitive patient data in an Amazon S3 bucket. They need to ensure that all data uploaded to this bucket is encrypted at rest and that only authorized users within their AWS account can access it. Additionally, they must prevent accidental public exposure of the bucket. Which combination of S3 features will best meet these security requirements?Domain 3: Infrastructure Security
- 92.A global enterprise is migrating its legacy applications to AWS. These applications frequently exchange sensitive data with on-premises systems and require a highly available, encrypted, and dedicated network connection. The security team mandates that all data in transit between AWS and on-premises must be encrypted end-to-end and use a private connection, not the public internet. Which combination of AWS services should be used to meet these requirements?Domain 3: Infrastructure Security
- 93.A company is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application requires outbound internet access to retrieve third-party APIs but should not be directly accessible from the internet. The security team also requires that all outbound traffic from the application instances passes through a centralized inspection point for deep packet inspection. How should this network architecture be designed to meet these requirements securely and efficiently?Domain 3: Infrastructure Security
- 94.A global software company maintains a single AWS account with multiple VPCs across different regions. They need to establish private, low-latency, and high-bandwidth connectivity between these VPCs for microservices communication, ensuring that traffic does not traverse the public internet. The solution must be scalable and simplify network management as more VPCs are added. Which AWS networking service should be used to achieve this?Domain 3: Infrastructure Security
- 95.A company requires that all data stored in Amazon EBS volumes attached to their EC2 instances must be encrypted. They also need to ensure that the encryption keys are managed by AWS Key Management Service (KMS) and that the encryption is enforced by default for all new volumes. What is the most effective way to implement this requirement?Domain 3: Infrastructure Security
- 96.A global enterprise is migrating its on-premises data centers to AWS. They have a requirement to establish secure, high-throughput, and redundant network connectivity between their on-premises network and their AWS VPCs across multiple regions. This connectivity must ensure all traffic is encrypted in transit and support dynamic routing. Which solution provides the most appropriate and resilient network architecture?Domain 3: Infrastructure Security
- 97.A security engineer needs to establish a secure and isolated environment for forensic analysis of a compromised EC2 instance. The forensic workstation needs to access the compromised instance's EBS volumes without any network connectivity to the internet or other production resources, and all actions must be logged. Which combination of AWS services and features should be used to create this forensic environment?Domain 1: Incident Response
- 98.A security engineer is investigating a potential compromise of an Amazon EC2 instance. The engineer needs to collect forensic data from the instance, including filesystem integrity checks, running process lists, and network connection states, but must do so without logging into the instance directly via SSH or RDP to avoid further altering the system or leaving traces. Which AWS service can facilitate this remote, agent-based data collection securely?Domain 1: Incident Response
- 99.A security architect needs to ensure that all newly created Amazon EBS volumes within a specific AWS account are encrypted by default. This is a mandatory compliance requirement for all data at rest. The architect wants to implement a solution that automatically enforces encryption without requiring manual intervention from developers. Which configuration should the architect implement?Domain 3: Infrastructure Security
- 100.A client is building a highly confidential application on AWS that processes Personally Identifiable Information (PII) and requires strict compliance with regulatory frameworks. The application will run on Amazon EC2 instances. Due to licensing constraints for specific software, the client needs to use existing server-bound licenses and requires assurance that their instances are physically isolated at the host hardware level. Which EC2 purchasing option should the client choose to meet these requirements?Domain 3: Infrastructure Security