AWS Certified Security – Specialty practice questions

207 free questions with answers and explanations.

Practice test
  1. 101.A company is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application requires outbound internet access to retrieve updates and interact with third-party APIs. However, the security team mandates that the EC2 instances themselves must reside in private subnets and should not have direct public IP addresses. All outbound internet traffic must be routed through a centralized point for inspection and auditing. How should this be configured to meet the security requirements?Domain 3: Infrastructure Security
  2. 102.A financial institution is deploying a new critical application on AWS that requires strict network isolation and the ability to control all inbound and outbound traffic at a granular level for specific IP addresses and ports. The application will run on Amazon EC2 instances within a Virtual Private Cloud (VPC). Which AWS networking construct should be used to provide the most granular, instance-level control over network traffic for these EC2 instances?Domain 3: Infrastructure Security
  3. 103.A financial institution uses AWS Organizations to manage multiple accounts. A security incident has been detected in a member account where an S3 bucket containing sensitive customer data was accidentally made public. The security team needs to quickly identify all other S3 buckets across all member accounts that might also be publicly accessible to prevent similar incidents and assess the full scope of the exposure. Which AWS service should they leverage for this task efficiently?Domain 1: Incident Response
  4. 104.A software development company is building a new serverless application using AWS Lambda functions. The Lambda functions need to access sensitive data stored in an Amazon RDS PostgreSQL database, which is located in a private subnet. The company requires that all connections from the Lambda functions to the database are private and do not traverse the public internet. How should the Lambda functions be configured to meet this requirement securely?Domain 3: Infrastructure Security
  5. 105.An organization is investigating a potential insider threat where an IAM user is suspected of unauthorized access to sensitive S3 buckets. The security team needs to analyze the user's historical access patterns to S3, including successful and failed attempts, to determine the extent of the unauthorized activity. They also need to identify any unusual access locations or times. Which AWS service combination is most effective for this detailed behavioral analysis?Domain 1: Incident Response
  6. 106.A media company is hosting a popular streaming service on AWS, utilizing a fleet of EC2 instances behind an Application Load Balancer (ALB). The company is concerned about Distributed Denial of Service (DDoS) attacks and common web exploits targeting their application. They need a solution that provides immediate, automated protection against these threats without manual intervention and can scale with their traffic. Which AWS service combination should be implemented for this scenario?Domain 3: Infrastructure Security
  7. 107.A company is using AWS Lambda functions to process sensitive customer data. They need to ensure that these Lambda functions can securely access an Amazon S3 bucket in a different AWS account without exposing the S3 bucket to the public internet. The security team also mandates that access should be granted with the principle of least privilege. How should this cross-account access be configured?Domain 3: Infrastructure Security
  8. 108.A client is deploying a new internal API using Amazon API Gateway. This API will be consumed by applications running on EC2 instances within a private subnet of their VPC. For security and compliance, the API must not be accessible from the public internet, and all traffic between the EC2 instances and the API Gateway must remain within the AWS network. How should the API Gateway be configured to meet these requirements?Domain 3: Infrastructure Security
  9. 109.A company is deploying a new serverless application using AWS Lambda functions. The Lambda functions need to access resources within a private VPC, including an Amazon RDS database and an Amazon ElastiCache cluster. The security team insists that the Lambda functions must not have any public internet access. Which configuration is necessary to meet these requirements?Domain 3: Infrastructure Security
  10. 110.A global e-commerce company uses AWS Lambda functions to process sensitive customer order information. They need to ensure that these Lambda functions can access specific resources in a different AWS account (e.g., an S3 bucket or a DynamoDB table) securely, without sharing IAM user credentials or making the resources publicly accessible. The access must adhere to the principle of least privilege, allowing only the necessary actions. Which mechanism should be implemented to achieve this cross-account access securely?Domain 3: Infrastructure Security
  11. 111.A client is deploying a new internal API using Amazon API Gateway. This API will be consumed exclusively by other services running within their AWS VPC and must not be accessible from the public internet. The security team requires that all traffic to this API remains entirely within the AWS network and is not exposed to the internet at any point. Which type of API Gateway endpoint should be configured to meet these security requirements?Domain 3: Infrastructure Security
  12. 112.A media company is hosting a popular streaming service on AWS, utilizing a fleet of EC2 instances behind an Application Load Balancer (ALB). They are experiencing frequent DDoS attacks targeting their public-facing ALB. The security team needs to implement a solution that provides managed DDoS protection and filters malicious web traffic based on common web exploits. Which AWS service combination should be deployed to address these concerns effectively?Domain 3: Infrastructure Security
  13. 113.A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances running critical applications that require remote administration. The current practice involves using SSH with key pairs, but the organization wants to implement a solution that eliminates the need to open inbound SSH ports on security groups, centrally manages access, and records all administrative sessions for auditing purposes. Which AWS service can accomplish these requirements effectively?Domain 3: Infrastructure Security
  14. 114.A security engineer is setting up automated remediation for Amazon GuardDuty findings. Specifically, for a 'CredentialAccess:IAMUser/AnomalousBehavior' finding, the engineer wants to automatically revoke all active IAM access keys for the affected IAM user. This remediation must be idempotent and ensure that the keys are revoked even if the remediation is triggered multiple times for the same finding. Which AWS service should be used to achieve this automated and idempotent key revocation?Domain 1: Incident Response
  15. 115.A financial institution is deploying a new backend service on AWS that processes highly sensitive customer data. This service runs on EC2 instances and requires dedicated, non-shared tenancy for compliance reasons. The institution also needs to ensure that the underlying hardware is dedicated to their use and isolated from other AWS customers. What EC2 deployment option should they choose to meet these strict compliance and isolation requirements?Domain 3: Infrastructure Security
  16. 116.A security engineer is tasked with automating the containment of compromised EC2 instances. Upon detection of a severe threat by Amazon GuardDuty, the automated response system should immediately detach all IAM roles from the affected EC2 instance to revoke its permissions, preventing further unauthorized actions or privilege escalation. Which AWS service should be used to orchestrate this automated response?Domain 1: Incident Response
  17. 117.A security engineer is investigating a potential compromise of an Amazon S3 bucket where sensitive data might have been exfiltrated. The engineer needs to identify the exact objects that were accessed, the IAM principal that accessed them, and the time of access to reconstruct the attack timeline. The S3 bucket has S3 server access logging enabled, delivering logs to another S3 bucket. Which AWS service should the engineer use to efficiently query these S3 access logs to build a timeline of accessed objects?Domain 1: Incident Response
  18. 118.A client is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application instances reside in private subnets and require outbound internet access to download software updates and access third-party APIs. However, the client's security policy strictly forbids any inbound internet access to these instances. Which AWS networking component should the security architect deploy to enable secure outbound internet access while preventing inbound connections?Domain 3: Infrastructure Security
  19. 119.A security engineer is investigating a potential compromise of an Amazon EC2 instance. Initial alerts indicate unusual outbound network traffic to a known malicious IP address. The engineer needs to quickly isolate the compromised instance without disrupting other services while preserving its state for forensic analysis. Which AWS service and action should the engineer take first?Domain 1: Incident Response
  20. 120.A client is deploying a new serverless application using AWS Lambda functions. The Lambda functions need to access a private Amazon RDS PostgreSQL database instance, which is located in a private subnet within a VPC. The Lambda functions also need to make outbound calls to external third-party APIs over the internet. The security team mandates that the Lambda functions should not have direct internet access within the VPC, and all outbound internet traffic must be routed through a NAT Gateway. How should the security architect configure the Lambda functions and VPC to meet these requirements?Domain 3: Infrastructure Security
  21. 121.A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances that are directly exposed to the public internet via public IP addresses and have SSH (port 22) open to 0.0.0.0/0. The auditor recommends immediate action to secure these instances. Which is the MOST secure and operationally efficient way to allow administrators to securely connect to these EC2 instances?Domain 3: Infrastructure Security
  22. 122.A software company operates a critical microservices application on AWS Fargate. They need to ensure that container images used in production are free from known vulnerabilities and meet security standards before deployment. The process must be automated as part of their CI/CD pipeline. Which solution provides a secure and automated way to achieve this?Domain 3: Infrastructure Security
  23. 123.A global e-commerce company uses AWS Lambda functions to process sensitive customer order data. The Lambda functions need to retrieve order details from an Amazon DynamoDB table located in a different AWS account (Account B) than where the Lambda functions are deployed (Account A). The security team requires that access to DynamoDB must be tightly controlled using the principle of least privilege and should not expose the Lambda functions to the public internet. Which is the MOST secure and efficient way to grant the Lambda function access to the DynamoDB table?Domain 3: Infrastructure Security
  24. 124.A software company operates a critical microservices application on AWS Fargate. They need to ensure that container images deployed to Fargate are scanned for vulnerabilities before deployment and that only approved images are allowed to run. Which AWS services should be integrated to establish a secure container image supply chain?Domain 3: Infrastructure Security
  25. 125.A client is building a highly confidential application on AWS that processes personally identifiable information (PII). They want to ensure that all compute instances processing this data have the strongest possible isolation from other AWS customers, even at the hardware level. The application needs to run on Amazon EC2. Which EC2 deployment option provides this level of dedicated physical isolation?Domain 3: Infrastructure Security
  26. 126.A healthcare organization stores sensitive patient data in an Amazon RDS for PostgreSQL database. Due to strict compliance regulations, they must ensure that all connections to the database are encrypted and that the database is not publicly accessible. They also need to implement a strong authentication mechanism. Which set of configurations should be applied to meet these requirements?Domain 3: Infrastructure Security
  27. 127.A media company is hosting a popular streaming service on AWS, utilizing a fleet of EC2 instances behind an Application Load Balancer (ALB). They observe frequent HTTP flood attacks and malicious bot traffic targeting their web application. The company needs a solution to protect their application from these common web exploits and unwanted traffic, filter requests based on IP addresses and HTTP headers, and integrate seamlessly with their existing ALB. Which AWS service should they implement?Domain 3: Infrastructure Security
  28. 128.A security engineer is investigating a potential compromise of an Amazon EC2 instance within a production VPC. The instance is suspected of communicating with a known command-and-control (C2) server. The engineer needs to immediately block all inbound and outbound traffic to and from this specific EC2 instance without affecting other instances in the same security group or subnet, to contain the threat and prevent further data exfiltration or lateral movement. Which AWS service or feature should the engineer use to achieve this containment effectively and with the highest granularity?Domain 1: Incident Response
  29. 129.A security engineer is investigating a potential compromise of an Amazon EKS cluster where a malicious container image might have been deployed. The engineer needs to perform live memory forensics on a specific worker node to identify running processes, open network connections, and loaded kernel modules that could indicate compromise. The worker nodes are EC2 instances. Which approach should the engineer take to capture the memory image for forensic analysis?Domain 1: Incident Response
  30. 130.A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances in public subnets that are running critical backend services. These instances have Security Groups that allow inbound SSH (port 22) from 0.0.0.0/0. The auditor recommends immediate action to mitigate this high-risk vulnerability. Which is the MOST secure and efficient way to restrict SSH access while maintaining operational functionality?Domain 3: Infrastructure Security
  31. 131.A developer is configuring an AWS CodeDeploy deployment for an application running on EC2 instances. The deployment must ensure that the application's sensitive configuration files, stored in an Amazon S3 bucket, are securely downloaded to the instances during deployment. The S3 bucket is encrypted with SSE-KMS. What is the most secure way for the CodeDeploy agent on the EC2 instances to access these files?Domain 3: Infrastructure Security
  32. 132.A financial services company is deploying a new application on AWS that handles highly sensitive customer data. The application will run on Amazon EC2 instances within a private subnet and requires outbound internet access for patching and updates, but no inbound internet access. The security team mandates that all outbound internet traffic must be inspected by a third-party firewall appliance for deep packet inspection and intrusion prevention. How should the security architect design the network to meet these requirements securely?Domain 3: Infrastructure Security
  33. 133.A company's security team has detected a sophisticated, persistent threat actor attempting to establish persistence within their AWS environment. The threat actor is using compromised IAM credentials to make unusual API calls, including attempts to create new IAM users and attach policies. The security team needs to quickly identify all API calls made by the compromised credentials, across all regions, to understand the full scope of the compromise and the actions taken by the attacker. Which AWS service is best suited for this comprehensive investigation?Domain 1: Incident Response
  34. 134.A global enterprise is migrating its legacy applications to AWS. These applications frequently communicate with on-premises systems and other AWS VPCs. The security team requires that all network traffic between these environments must be encrypted and centrally managed. Which AWS networking service should be used to establish secure, encrypted, and centrally managed connectivity?Domain 3: Infrastructure Security
  35. 135.A financial services company is migrating its on-premises applications to AWS. They have a strict compliance requirement that all data stored in Amazon EBS volumes attached to their EC2 instances must be encrypted by default, without requiring manual intervention from developers. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS) for enhanced control and auditing. How can this be enforced across their AWS account?Domain 3: Infrastructure Security
  36. 136.A financial institution is deploying a new critical application on AWS that requires strict inbound and outbound network traffic control. The application will run on Amazon EC2 instances within a Virtual Private Cloud (VPC). The security team has mandated that only traffic from a specific set of IP addresses should be allowed to reach the application, and the application itself should only be able to communicate with approved internal services. Which AWS service is the MOST appropriate to enforce these granular network access controls at the instance level?Domain 3: Infrastructure Security
  37. 137.A global software company maintains a single AWS account with multiple VPCs across different AWS Regions. They need to establish secure, high-bandwidth network connectivity between these VPCs and also connect to their on-premises data centers via AWS Direct Connect. The security team requires a centralized network routing approach that minimizes management overhead and allows for granular routing control between all connected networks. Which AWS networking service should be used to achieve this?Domain 3: Infrastructure Security
  38. 138.A security operations team is investigating a suspected data exfiltration attempt from an Amazon RDS database instance. They need to determine if any outbound connections were made from the RDS instance to suspicious external IP addresses. The RDS instance is configured with VPC Flow Logs enabled for its subnet. Which service should the team use to efficiently query and analyze these flow logs to identify potential exfiltration attempts?Domain 1: Incident Response
  39. 139.A financial institution is deploying a new critical application on AWS that requires strict network isolation. The application's Amazon EC2 instances must only communicate with specific internal services (e.g., a database, a caching layer) and absolutely no other services or the internet, except for necessary OS updates from trusted sources. The security team wants to apply the principle of least privilege at the network level. Which AWS networking component should be used to achieve this granular control over traffic to and from the EC2 instances?Domain 3: Infrastructure Security
  40. 140.A company is developing a new application that uses Amazon API Gateway to expose RESTful APIs. These APIs need to be accessible only from specific internal VPCs and not from the public internet. Furthermore, the company requires that all API calls are authenticated using IAM credentials. How should this API Gateway be configured?Domain 3: Infrastructure Security
  41. 141.A global healthcare provider stores vast amounts of patient health information (PHI) in an Amazon S3 bucket. Due to strict regulatory requirements, all PHI data must be encrypted at rest. The security team requires that encryption keys be automatically rotated at least annually and that all key usage be auditable. The solution must also be cost-effective and easy to manage with minimal operational overhead. Which encryption method best meets these requirements?Domain 5: Data Protection
  42. 142.A global e-commerce company uses Amazon S3 to store customer order data, which is classified as 'Confidential' and 'Public'. The security team needs to automatically identify and classify new objects uploaded to S3 that contain personally identifiable information (PII) such as credit card numbers or social security numbers, especially those incorrectly marked as 'Public'. This process should also trigger alerts for misclassified sensitive data. Which AWS service can accomplish this most efficiently?Domain 5: Data Protection
  43. 143.A security operations center (SOC) team is investigating a potential data exfiltration attempt from an Amazon EC2 instance within a VPC. They suspect that an attacker gained access and is communicating with an external malicious IP address. To confirm this, they need to analyze network traffic flow data, including source/destination IP addresses, ports, protocols, and traffic volume. Which AWS logging solution provides this specific type of information?Domain 2: Logging and Monitoring
  44. 144.A global e-commerce company operates several highly critical web applications behind Application Load Balancers (ALBs). The security team needs to monitor for web-based attacks, such as SQL injection and cross-site scripting (XSS), and block malicious traffic in real-time. They also require detailed logs of blocked requests for forensic analysis. Which AWS security service, combined with its logging capabilities, should be implemented?Domain 2: Logging and Monitoring
  45. 145.A company is required to regularly analyze their AWS environment for potential security vulnerabilities and deviations from security best practices, such as insecure configurations, exposed secrets, or misconfigured permissions. The analysis needs to be automated and provide actionable findings that can be integrated into a security workflow. Which AWS service is designed to perform these automated security assessments?Domain 2: Logging and Monitoring
  46. 146.A research institution stores petabytes of genomic data in Amazon S3. This data is rarely accessed (less than once a year) but must be retained for decades due to scientific and regulatory requirements. When access is needed, retrieval times of several hours are acceptable, but cost minimization is a critical factor. Which S3 storage class is the most appropriate for this use case?Domain 5: Data Protection
  47. 147.A security engineer is tasked with establishing a centralized logging solution for an organization's AWS environment. The solution must collect logs from various AWS services, including CloudTrail, VPC Flow Logs, and S3 access logs, and then send them to a security information and event management (SIEM) system for analysis. The engineer needs to ensure that the log data is securely transported and that the solution is scalable and cost-effective. Which AWS service is most appropriate for aggregating and delivering these diverse log sources to the SIEM?Domain 2: Logging and Monitoring
  48. 148.A compliance officer requires a solution to periodically audit the security group rules across all AWS accounts in an organization to ensure that no overly permissive inbound rules (e.g., SSH or RDP from 0.0.0.0/0) are configured. The solution needs to generate a compliance report and trigger an alert if any non-compliant rules are found. Which AWS services should be used to achieve this?Domain 2: Logging and Monitoring
  49. 149.A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data have server access logging enabled and that these access logs are stored in a separate, secure S3 bucket in a different AWS account. The auditor also needs to continuously monitor for any S3 buckets that do not meet this logging standard. Which set of AWS services can address these requirements efficiently?Domain 2: Logging and Monitoring
  50. 150.A security analyst needs to create a custom CloudWatch alarm that triggers when an AWS Identity and Access Management (IAM) root user performs any API activity. This alarm should notify the security team immediately via email. Which of the following combinations of AWS services and configurations will achieve this goal?Domain 2: Logging and Monitoring