AWS Certified Security – Specialty practice questions

207 free questions with answers and explanations.

Practice test
  1. 201.A media company experiences a defacement of their public-facing website hosted on Amazon S3. The security team suspects an unauthorized modification of the S3 bucket's content. They need to quickly revert the website to a known good state. Assuming S3 Versioning was enabled on the bucket prior to the incident, which action should the security team take to recover the website with minimal downtime?Domain 1: Incident Response
  2. 202.A client is building a highly confidential application on AWS that processes Personally Identifiable Information (PII). Due to stringent compliance requirements, the client must ensure that the underlying physical servers hosting their Amazon EC2 instances are dedicated solely to their account and are not shared with any other AWS customers. This is crucial for avoiding the 'noisy neighbor' problem and meeting specific licensing requirements. Which EC2 purchasing option should the client choose to satisfy these requirements?Domain 3: Infrastructure Security
  3. 203.A security engineer is investigating a series of unauthorized root user API calls detected by AWS CloudTrail. To understand the full scope of the compromise, the engineer needs to reconstruct the sequence of events and identify all actions performed by the root user, including those that might have been immediately reverted or hidden. Which approach provides the most comprehensive forensic timeline of root user activity?Domain 1: Incident Response
  4. 204.A security engineer is investigating a potential compromise involving an AWS Lambda function. The function's code was recently updated, and a GuardDuty finding indicates 'Stealth:Lambda/CodeModified.Unauthorized'. The engineer needs to rapidly roll back the Lambda function to a previous, known good version and prevent further unauthorized modifications. Which AWS Lambda feature should be utilized for this recovery?Domain 1: Incident Response
  5. 205.An organization is using AWS Control Tower for multi-account governance. A security incident is detected in one of the member accounts, requiring immediate lockdown of all network access to a specific AWS Region within that account. The security team needs to prevent any traffic from entering or leaving this Region, even for newly provisioned resources, as part of the containment strategy. Which AWS service and control type should be used to enforce this broad network lockdown?Domain 1: Incident Response
  6. 206.A security engineer is investigating a potential compromise of a critical Amazon RDS database instance. They need to collect forensic data from the database, including logs and configuration, without impacting the production workload or altering the original evidence. Which is the MOST appropriate strategy to achieve this?Domain 1: Incident Response
  7. 207.A manufacturing company uses AWS IoT Core for managing a fleet of connected devices. A security engineer detects anomalous behavior from a device, indicating a potential compromise and unauthorized data exfiltration attempts. The engineer needs to immediately revoke the device's authorization to publish messages to AWS IoT Core and prevent it from connecting. Which action should be taken using AWS IoT Core features?Domain 1: Incident Response