โ† All Architecting on AWS Certification Flashcard Decks

Codes & Standards Compliance Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Codes & Standards Compliance flashcards as text
  1. An architect needs to automate evidence collection for PCI DSS, HIPAA, and NIST 800-53 frameworks continuously. Which AWS service is purpose-built for this?

    Answer: AWS Audit Manager

    AWS Audit Manager continuously collects evidence from AWS services, maps it to compliance frameworks like PCI DSS and HIPAA, and generates audit-ready reports.

  2. A company uses AWS Organizations and wants to prevent any member account from disabling CloudTrail. Which is the most scalable enforcement mechanism?

    Answer: An SCP denying cloudtrail:StopLogging and cloudtrail:DeleteTrail across the organization

    An SCP applied at the organization root or OU level preventively blocks cloudtrail:StopLogging and cloudtrail:DeleteTrail for all member accounts, regardless of IAM policies.

  3. Which encryption standard must AWS KMS CMKs use to comply with FIPS 140-2 Level 2, as required by many US government frameworks?

    Answer: AES-256 with validated HSMs

    AWS KMS uses AES-256 on FIPS 140-2 Level 2 validated hardware security modules (HSMs), meeting federal cryptographic standards.

  4. A retail company processing credit cards must segment its CDE from other systems per PCI DSS Requirement 1. Which AWS networking approach provides the strongest isolation?

    Answer: Placing CDE resources in a dedicated AWS account with its own VPC and no VPC peering to non-CDE

    A dedicated AWS account with its own VPC provides account-level blast-radius containment and prevents any inadvertent network paths from non-CDE environments.

  5. GDPR Article 17 grants users the 'right to erasure.' Which S3 capability most directly supports complying with this requirement?

    Answer: S3 batch operations to delete specific objects on demand

    S3 Batch Operations can target and permanently delete specific objects (e.g., a user's data) across large buckets, enabling compliance with GDPR right-to-erasure requests.

  6. An architect must ensure data in transit between on-premises systems and AWS meets NIST 800-52 TLS requirements. What is the recommended approach?

    Answer: Configure AWS services to use TLS 1.2 or higher and disable older protocol versions

    NIST SP 800-52 mandates TLS 1.2 minimum; AWS services support enforcing minimum TLS versions via security policies on load balancers, API Gateway, and CloudFront.

  7. Which AWS feature enables an organization to define a minimum baseline of security controls that cannot be overridden by member accounts, supporting CIS Benchmark compliance?

    Answer: AWS Control Tower Guardrails (mandatory controls)

    AWS Control Tower mandatory guardrails enforce non-negotiable security baselines (e.g., CloudTrail enabled, S3 public access blocked) across all enrolled accounts, supporting CIS Benchmark requirements.