โ† All Architecting on AWS Certification Flashcard Decks

Quality Control & Inspection Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Quality Control & Inspection flashcards as text
  1. A security team wants to automatically assess EC2 instances for known software vulnerabilities and unintended network exposure. Which AWS service is purpose-built for this?

    Answer: Amazon Inspector

    Amazon Inspector automatically scans EC2 instances and container images for software vulnerabilities and unintended network exposure.

  2. Which AWS service aggregates security findings from multiple AWS security services and partner tools into a single dashboard?

    Answer: AWS Security Hub

    AWS Security Hub aggregates, organizes, and prioritizes security findings from services like GuardDuty, Inspector, and Macie.

  3. An architect must ensure S3 buckets never become publicly accessible across all accounts in an AWS Organization. Which control enforces this preventatively?

    Answer: S3 Block Public Access at the organization level

    Enabling S3 Block Public Access settings at the AWS Organizations level preventatively stops any account from making buckets public.

  4. AWS Audit Manager is BEST suited for which use case?

    Answer: Continuously collecting evidence to simplify compliance audits

    AWS Audit Manager continuously collects audit-ready evidence mapped to compliance frameworks like PCI DSS and HIPAA.

  5. A company needs to detect when an IAM policy is attached to a user directly (violating least-privilege policy). Which tool detects this configuration drift?

    Answer: AWS Config with a managed rule

    The AWS Config managed rule `iam-user-no-policies-check` flags any IAM user with policies attached directly rather than via groups.

  6. Which AWS Well-Architected Tool feature allows teams to compare their workload against AWS best practices across five pillars?

    Answer: Well-Architected Review milestones

    The Well-Architected Tool guides teams through a questionnaire and records milestone snapshots showing improvement over time across all five pillars.

  7. Amazon Macie is PRIMARILY used to inspect which type of resource for sensitive data?

    Answer: Amazon S3 buckets

    Amazon Macie uses machine learning to automatically discover and classify sensitive data stored in Amazon S3.