Editing AWS Certified Security - Specialty: 9 Sample questions
Jump to navigation
Jump to search
Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | ||
− | 1) A corporate cloud security policy states that | + | 1) A corporate cloud security policy states that communication between the company's [[VPC]] and [[KMS]] must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Select TWO.) |
:A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | :A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | ||
:B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | :B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | ||
:C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | :C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | ||
:D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | :D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | ||
− | :E) Add the following condition to the AWS KMS key policy: <code>" | + | :E) Add the following condition to the AWS KMS key policy: <code>"aws:SourceIp": "10.0.0.0/16"</code> |
− | |||
2) An application team is designing a solution with two applications. The security team wants the | 2) An application team is designing a solution with two applications. The security team wants the | ||
Line 13: | Line 12: | ||
with sensitive data. | with sensitive data. | ||
Which solution meets the requirement with the LEAST risk and effort? | Which solution meets the requirement with the LEAST risk and effort? | ||
− | :A) Use | + | :A) Use Amazon CloudWatch Logs to capture all logs, write an AWS Lambda function that parses the log file, and move sensitive data to a different log. |
− | :B) Use Amazon CloudWatch Logs with two | + | :B) Use Amazon CloudWatch Logs with two log groups, with one for each application, and use an AWS IAM policy to control access to the log groups, as required. |
:C) Aggregate logs into one file, then use Amazon CloudWatch Logs, and then design two CloudWatch metric filters to filter sensitive data from the logs. | :C) Aggregate logs into one file, then use Amazon CloudWatch Logs, and then design two CloudWatch metric filters to filter sensitive data from the logs. | ||
:D) Add logic to the application that saves sensitive data logs on the Amazon EC2 instances' local storage, and write a batch script that logs into the Amazon EC2 instances and moves sensitive logs to a secure location. | :D) Add logic to the application that saves sensitive data logs on the Amazon EC2 instances' local storage, and write a batch script that logs into the Amazon EC2 instances and moves sensitive logs to a secure location. | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
== See also == | == See also == |
Advertising: