← All Architecting on AWS Certification Flashcard Decks

Quality Control & Inspection Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Quality Control & Inspection flashcards as text
  1. A company wants to enforce a maximum 90-day rotation policy for all IAM access keys organization-wide. Which combination BEST achieves continuous enforcement?

    Answer: AWS Config rule `access-keys-rotated` triggering an SNS alert to the security team

    The `access-keys-rotated` Config managed rule checks key age and can trigger SNS notifications to alert the security team when keys exceed 90 days.

  2. Which AWS service can automatically remediate a non-compliant resource by invoking an AWS Systems Manager Automation document?

    Answer: AWS Config automatic remediation

    AWS Config supports automatic remediation by associating a Config rule violation with an SSM Automation document that corrects the resource.

  3. A team uses AWS CodePipeline and wants to block deployments if the container image has critical CVEs. Which integration achieves this quality gate?

    Answer: Amazon Inspector scan results gating CodePipeline via Lambda

    A Lambda function can query Amazon Inspector findings for the image and return a failure status to CodePipeline if critical CVEs are present, acting as a deployment gate.

  4. Which AWS service uses machine learning to establish a baseline of normal API call behavior and alerts on anomalous patterns like unusual data access volume?

    Answer: Amazon GuardDuty

    Amazon GuardDuty uses ML on CloudTrail, VPC Flow Logs, and DNS logs to detect anomalous behavior such as unusual API calls or data exfiltration patterns.

  5. A customer needs to demonstrate SOC 2 compliance to an auditor. Which AWS service maps AWS controls to SOC 2 requirements and continuously collects evidence?

    Answer: AWS Audit Manager with the SOC 2 framework

    AWS Audit Manager provides a prebuilt SOC 2 framework that maps AWS controls to SOC 2 criteria and automatically collects evidence for auditors.

  6. What does the AWS Config rule `cloudtrail-enabled` check?

    Answer: That at least one multi-region CloudTrail trail is active in the account

    The `cloudtrail-enabled` managed rule verifies that at least one multi-region CloudTrail trail exists and is logging API activity.

  7. An architect is designing a quality inspection pipeline for infrastructure-as-code. Which tool scans CloudFormation templates for security misconfigurations BEFORE deployment?

    Answer: AWS CloudFormation Guard (cfn-guard)

    AWS CloudFormation Guard is an open-source policy-as-code tool that evaluates CloudFormation templates against custom rules before they are deployed.