AWS Certified Security – Specialty practice questions
207 free questions with answers and explanations.
- 151.A financial institution requires continuous monitoring of administrative activities within their AWS accounts to detect any unauthorized changes to security configurations or resource policies. They need to ensure that all API calls and console actions are recorded, immutable, and retained for seven years for audit purposes. Which AWS service should be configured to meet these requirements, and what feature ensures immutability?Domain 2: Logging and Monitoring
- 152.A security engineer is investigating a potential compromise of an AWS access key associated with an IAM user. They need to determine the last time the access key was used, from which IP address, and what AWS services it accessed. This information is crucial for incident response. Which AWS service and its features would provide this specific audit information?Domain 2: Logging and Monitoring
- 153.A company is implementing a new microservices architecture on AWS, using Amazon EKS for container orchestration. They need to monitor container logs and performance metrics to detect anomalies and potential security threats. The solution must be able to collect logs from multiple containers, forward them to a centralized logging system, and allow for real-time analysis. Which approach effectively addresses these requirements?Domain 2: Logging and Monitoring
- 154.A multinational corporation is expanding its operations into a new region with stringent data residency regulations. All customer data originating from this region must be stored and processed exclusively within the region's geographical boundaries. The company uses Amazon S3 for data storage and AWS Lambda for data processing. How can the company ensure strict data residency for its S3 buckets and associated Lambda functions?Domain 5: Data Protection
- 155.A financial institution stores critical transaction logs in an Amazon S3 bucket. Due to regulatory compliance (e.g., FINRA, SEC), these logs must be immutable and retained for a minimum of seven years, with no possibility of deletion or modification by any user, including the root account. After seven years, the logs can be automatically deleted. Which S3 feature should the security architect recommend to meet these requirements?Domain 5: Data Protection
- 156.A security architect is designing a multi-account logging strategy for an organization with strict regulatory requirements. All CloudTrail logs from member accounts must be aggregated into a central logging account. Furthermore, these aggregated logs must be encrypted at rest, protected against accidental deletion, and retained for ten years. Which configuration ensures these requirements are met with minimal operational overhead?Domain 2: Logging and Monitoring
- 157.A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data is stored in the same DynamoDB table, but strict isolation and encryption at the application layer are required for multi-tenancy. The solution must ensure that each tenant's data is encrypted with a unique key, and that the application handles the encryption and decryption process before data is sent to or retrieved from DynamoDB. Which approach should the security architect recommend?Domain 5: Data Protection
- 158.A security engineer needs to monitor for any attempts to modify or delete a critical AWS CloudFormation stack that defines the network infrastructure. This monitoring solution must provide immediate alerts to the security team. Which approach should the engineer implement?Domain 2: Logging and Monitoring
- 159.A global enterprise uses multiple AWS accounts and regions for its operations. The security team needs to monitor security findings from various AWS services (e.g., GuardDuty, Inspector, Config, IAM Access Analyzer) from a single pane of glass. They also require automated remediation actions for certain high-severity findings. Which AWS service is best suited for aggregating these findings and orchestrating automated responses?Domain 2: Logging and Monitoring
- 160.A security team is implementing a custom intrusion detection system (IDS) on an EC2 instance. This IDS needs to analyze network traffic in real-time for suspicious patterns. The EC2 instance must have access to all network traffic flowing through its associated network interface, not just traffic destined for the instance itself. Which feature should be enabled on the EC2 instance's network interface to achieve this?Domain 2: Logging and Monitoring
- 161.A security engineer has configured an AWS WAF Web ACL to protect a public-facing web application. The engineer needs to monitor WAF logs for specific attack patterns (e.g., SQL injection attempts, cross-site scripting) and receive real-time alerts when these patterns are detected. The logs should be stored centrally for auditing and forensics. Which solution provides the most effective way to meet these requirements?Domain 2: Logging and Monitoring
- 162.A company is migrating a legacy application to AWS and needs to ensure that all network traffic, including internal VPC communications and external internet-bound traffic, is captured and sent to a centralized security information and event management (SIEM) system for deep packet inspection and anomaly detection. The SIEM is hosted on EC2 instances in a separate security VPC. What is the most efficient and scalable way to achieve this comprehensive network traffic capture?Domain 2: Logging and Monitoring
- 163.A security engineer needs to establish real-time threat detection and continuous monitoring for an AWS environment, including identifying unusual API calls, potential unauthorized access, and known malicious IP addresses. The solution must be fully managed and integrate seamlessly with existing security workflows. Which AWS service is best suited for this requirement?Domain 2: Logging and Monitoring
- 164.A global enterprise operates multiple AWS accounts across various regions and requires a centralized, immutable, and long-term archive for all security logs, including CloudTrail, VPC Flow Logs, and custom application logs. The solution must ensure that logs cannot be altered or deleted for seven years to meet regulatory compliance, and a dedicated security account should be used for storage. How should the security engineer design this logging architecture?Domain 2: Logging and Monitoring
- 165.A security operations center (SOC) team needs to monitor an AWS environment for potential indicators of compromise (IOCs) such as unusual API call patterns, unauthorized access attempts, and known malicious IP addresses. They require a service that can automatically analyze various AWS data sources, generate findings with severity levels, and integrate with existing incident response workflows. Which AWS service is best suited for this requirement?Domain 2: Logging and Monitoring
- 166.A security auditor needs to verify that a company's AWS environment is continuously monitored for compliance with security best practices, such as ensuring S3 buckets are not publicly accessible, IAM policies adhere to least privilege, and security groups restrict unnecessary ports. The auditor requires a consolidated view of compliance status across all accounts and regions, with automated checks and remediation capabilities. Which AWS service provides this comprehensive compliance monitoring and reporting?Domain 2: Logging and Monitoring
- 167.A large enterprise uses AWS Organizations with multiple accounts. They require a centralized and immutable log of all API calls and configuration changes across all accounts for compliance and auditing purposes. The logs must be encrypted at rest and in transit, and retained for seven years. Which logging solution should the security architect design to meet these requirements?Domain 2: Logging and Monitoring
- 168.A company is migrating its on-premises applications to AWS. They use custom applications that generate security-relevant logs in various formats (JSON, plain text, syslog) on EC2 instances. The security team needs to centralize these logs into a single, queryable repository for threat hunting and compliance auditing. The solution must support real-time ingestion, flexible querying capabilities, and long-term archival. Which combination of AWS services would best meet these requirements?Domain 2: Logging and Monitoring
- 169.A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data are continuously monitored for unauthorized access and data exfiltration attempts. The solution must integrate with an existing security information and event management (SIEM) system for alerting and reporting. Which combination of AWS services should be implemented to meet this requirement effectively?Domain 2: Logging and Monitoring
- 170.A security engineer is tasked with monitoring for unauthorized modifications to critical AWS CloudFormation stacks that define the core infrastructure of a production environment. Any attempt to modify or delete these stacks must trigger an immediate alert to the security team. The solution needs to be robust, real-time, and target specific CloudFormation stack operations. Which AWS service combination provides the most effective and granular monitoring solution?Domain 2: Logging and Monitoring
- 171.A security engineer is troubleshooting an issue where a Lambda function, intended to process S3 object creation events, is not being invoked. The engineer suspects a misconfiguration in the event source mapping or permissions. To diagnose this, the engineer needs to view the execution logs of the Lambda function, including any errors or output, and also verify if the S3 event is correctly triggering the Lambda function. Which AWS services should the engineer check?Domain 2: Logging and Monitoring
- 172.A security engineer needs to monitor and audit the security configuration of all EC2 instances across multiple AWS accounts in an organization. Specifically, they need to ensure that all EC2 instances are launched with specific IAM roles, are tagged correctly, and do not have public IP addresses unless explicitly approved. The solution should provide continuous compliance assessment and generate alerts for non-compliant resources. Which AWS service should be used to achieve this?Domain 2: Logging and Monitoring
- 173.A security engineer needs to establish a robust monitoring solution for cross-account administrative activities within an AWS Organization. The solution must ensure that all API calls made by IAM users and roles in every account are captured, immutable, and retained for 10 years for forensic analysis. Furthermore, any attempts to disable CloudTrail logging or delete logs must generate immediate alerts. Which combination of services should the engineer implement?Domain 2: Logging and Monitoring
- 174.A security engineer is investigating a series of failed login attempts targeting an EC2 instance running a critical application. The attempts are originating from various suspicious IP addresses. The engineer needs to quickly identify the source IP addresses, the time of the attempts, and the specific user accounts targeted, to block further access. Which logging and monitoring solution provides the most direct and actionable information for this investigation?Domain 2: Logging and Monitoring
- 175.A security operations center (SOC) needs to create a custom dashboard in Amazon CloudWatch to monitor suspicious activities detected by Amazon GuardDuty across multiple AWS accounts. The dashboard should display key GuardDuty findings, such as the total number of findings, findings by severity, and findings by type. Which steps are required to achieve this, assuming GuardDuty is already enabled in all accounts?Domain 2: Logging and Monitoring
- 176.A security engineer needs to establish a robust monitoring solution to detect unusual API call patterns, unauthorized access attempts, and potential insider threats across multiple AWS accounts within an AWS Organization. The solution must be cost-effective and provide near real-time threat detection capabilities without requiring extensive manual configuration. Which AWS service is best suited for this requirement?Domain 2: Logging and Monitoring
- 177.A security engineer is investigating a series of suspicious activities originating from an EC2 instance, including unusual outbound network connections and attempts to access internal resources. The engineer needs to quickly determine which AWS Identity and Access Management (IAM) role or user was used to launch the affected EC2 instance and what other actions that IAM entity has performed recently. Which AWS service provides the most direct and efficient way to retrieve this information?Domain 2: Logging and Monitoring
- 178.A security engineer has deployed a new web application on Amazon EKS. The application consists of multiple microservices running in pods across several nodes. The engineer needs to collect detailed logs from these pods, including application-specific logs and container runtime logs, and centralize them for monitoring and troubleshooting. The solution must be scalable, resilient, and allow for easy searching and analysis. Which logging approach should the engineer implement?Domain 2: Logging and Monitoring
- 179.A company is using AWS Organizations to manage multiple accounts. They need to ensure that all AWS accounts are continuously monitored for security vulnerabilities and deviations from best practices. The solution should provide a consolidated view of security posture across all accounts, integrate with existing ticketing systems, and generate security findings based on industry standards. Which AWS service is designed to address these requirements holistically?Domain 2: Logging and Monitoring
- 180.A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data are protected against accidental deletion or modification for a minimum of one year. The auditor needs to verify that this protection is active and cannot be easily bypassed. Which S3 feature should be enabled and how can its enforcement be demonstrated?Domain 2: Logging and Monitoring
- 181.A security architect is designing a logging solution for a highly regulated financial application hosted on AWS. The application generates sensitive audit logs that must be immutable and retained for seven years to meet compliance requirements. The solution must prevent any deletion or modification of these logs, even by root users, for the entire retention period. Which AWS service and configuration combination should the architect choose?Domain 2: Logging and Monitoring
- 182.A security team needs to monitor the configuration of security groups across multiple AWS accounts in an AWS Organization. They require automatic remediation of non-compliant security group rules (e.g., overly permissive inbound rules like 0.0.0.0/0 on port 22 or 3389) and real-time alerts when such rules are detected. The solution should be scalable and minimize operational overhead. Which approach best meets these requirements?Domain 2: Logging and Monitoring
- 183.A security engineer needs to establish a centralized logging solution for a new application deployed on Amazon EKS. The application consists of multiple microservices, each running in its own pod. All application logs, standard output, and standard error from containers must be collected, processed, and sent to a centralized Amazon OpenSearch Service domain for analysis and visualization. The solution should be robust, scalable, and handle high volumes of log data. Which logging agent and delivery mechanism should the engineer choose?Domain 2: Logging and Monitoring
- 184.A security engineer is investigating a potential compromise of an AWS EC2 instance. The instance was observed making outbound connections to an unknown IP address on a non-standard port. The engineer needs to quickly identify all network traffic to and from this specific EC2 instance, including source/destination IP addresses, ports, protocols, and action (ALLOW/REJECT). Which AWS service should the engineer leverage to obtain this detailed network flow information?Domain 2: Logging and Monitoring
- 185.A security engineer has configured an AWS WAF Web ACL to protect a public-facing web application. To monitor the effectiveness of WAF rules and identify potential attack patterns, the engineer needs to enable detailed logging of all web requests that WAF inspects. The logs should be easily accessible for real-time analysis and long-term storage. Which destination should the engineer configure for WAF logs?Domain 2: Logging and Monitoring
- 186.A security engineer is investigating a potential compromise involving an AWS access key. The key was used to make several unauthorized API calls from an unknown IP address. The engineer needs to quickly determine the exact API calls made, the resources affected, the source IP address, and the user identity associated with the access key. Which AWS service is the primary source for this forensic investigation?Domain 2: Logging and Monitoring
- 187.A security engineer is investigating a series of unauthorized API calls originating from an unusual geographic location, targeting an AWS account. The engineer needs to identify the specific API calls made, the IAM principal that made them, and the source IP address. Which AWS service should the engineer consult to gather this information?Domain 2: Logging and Monitoring
- 188.A security engineer is investigating a potential data exfiltration attempt from an EC2 instance that is part of a critical application. The attacker is suspected of trying to send data to an external malicious IP address. The engineer needs to analyze the network traffic originating from this specific EC2 instance to identify the destination IP addresses and ports. Which logging solution should the engineer primarily review?Domain 2: Logging and Monitoring
- 189.A global enterprise uses AWS Organizations with multiple accounts and requires a centralized, immutable audit trail of all management events across all accounts and regions. The audit trail must be encrypted at rest and in transit, and accessible only by a dedicated security team in a separate logging account. What is the most secure and compliant way to achieve this?Domain 2: Logging and Monitoring
- 190.A company is implementing a new containerized application on Amazon Elastic Kubernetes Service (EKS). The security team requires a solution to centralize and analyze logs from all pods across multiple EKS clusters for security auditing and incident response. The solution must support filtering, searching, and long-term retention of logs. Which combination of AWS services would best meet these requirements?Domain 2: Logging and Monitoring
- 191.A security engineer has deployed a new web application on Amazon EKS. The application consists of several microservices, and the engineer needs to ensure that all application logs, regardless of the pod they originate from, are collected, centralized, and available for real-time monitoring and troubleshooting. The solution should be resilient to pod restarts and scaling events. Which approach should the engineer take?Domain 2: Logging and Monitoring
- 192.A security engineer needs to implement a solution to monitor for unauthorized modifications to critical AWS CloudFormation stacks. Specifically, they want to be alerted immediately if a CloudFormation stack's resources are updated, deleted, or if a stack operation fails. The solution should be near real-time and allow for automated response actions. Which AWS service combination is most appropriate for this task?Domain 2: Logging and Monitoring
- 193.A security engineer needs to establish real-time monitoring for suspicious network activities within a Virtual Private Cloud (VPC) to detect potential Distributed Denial of Service (DDoS) attacks or port scans. The solution must be cost-effective and provide actionable insights without requiring extensive custom development. Which AWS service is best suited for this requirement?Domain 2: Logging and Monitoring
- 194.A financial services company uses AWS for its critical applications. A recent security alert from Amazon GuardDuty indicates a 'Backdoor:EC2/C&CActivity.B' finding on an EC2 instance, suggesting communication with a known command and control server. The security team needs to immediately isolate the compromised instance from the network while preserving its state for forensic analysis. Which AWS security service and action should be taken first to achieve this?Domain 1: Incident Response
- 195.A financial institution is deploying a new critical application on AWS that requires strict network isolation and granular control over inbound and outbound traffic for its Amazon EC2 instances. The security team mandates that all instances must only communicate with explicitly allowed resources and that any unauthorized access attempts must be blocked at the instance level. Which AWS service or feature should be primarily used to meet these requirements for network traffic filtering?Domain 3: Infrastructure Security
- 196.A security team needs to establish a dedicated, isolated environment within AWS for conducting forensic analysis of compromised resources. This environment must ensure that forensic tools and collected evidence cannot communicate with production networks or the internet, except for strictly controlled outbound access for updates. Which combination of AWS networking components should be used to build this highly isolated forensic environment?Domain 1: Incident Response
- 197.A security engineer needs to analyze the full network traffic (packet capture) of a suspected compromised EC2 instance without directly logging into it or installing agents, to avoid altering the evidence. The analysis requires deep inspection of network protocols and payloads. Which AWS service combination provides the capability to capture and analyze this traffic?Domain 1: Incident Response
- 198.A global software company maintains sensitive intellectual property in an Amazon S3 bucket. A security team suspects an insider threat attempting to access or exfiltrate data from this S3 bucket using an assumed role. The team needs to quickly identify which IAM roles have been assumed to access the S3 bucket and from which source accounts or external identities. Which AWS service and data source should be used to trace these assumed role activities?Domain 1: Incident Response
- 199.A global e-commerce company uses AWS CloudTrail to log API activity across multiple accounts. A security engineer is investigating a series of unauthorized 'DeleteObject' API calls to an Amazon S3 bucket containing sensitive customer data. The engineer needs to quickly determine the source IP address, IAM principal, and user agent responsible for these specific actions. Which CloudTrail feature should the engineer use to efficiently filter and retrieve this information?Domain 1: Incident Response
- 200.A company uses AWS WAF to protect its public-facing web applications. A security analyst observes a sudden surge in HTTP 5xx errors and high CPU utilization on backend EC2 instances, coinciding with an increase in requests originating from a single IP address. The analyst suspects a Layer 7 DDoS attack. Which AWS WAF action should be implemented first to mitigate this specific threat?Domain 1: Incident Response