Quality Control & Inspection Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Quality Control & Inspection flashcards as text
A company wants to enforce a maximum 90-day rotation policy for all IAM access keys organization-wide. Which combination BEST achieves continuous enforcement?
Answer: AWS Config rule `access-keys-rotated` triggering an SNS alert to the security team
The `access-keys-rotated` Config managed rule checks key age and can trigger SNS notifications to alert the security team when keys exceed 90 days.
Which AWS service can automatically remediate a non-compliant resource by invoking an AWS Systems Manager Automation document?
Answer: AWS Config automatic remediation
AWS Config supports automatic remediation by associating a Config rule violation with an SSM Automation document that corrects the resource.
A team uses AWS CodePipeline and wants to block deployments if the container image has critical CVEs. Which integration achieves this quality gate?
Answer: Amazon Inspector scan results gating CodePipeline via Lambda
A Lambda function can query Amazon Inspector findings for the image and return a failure status to CodePipeline if critical CVEs are present, acting as a deployment gate.
Which AWS service uses machine learning to establish a baseline of normal API call behavior and alerts on anomalous patterns like unusual data access volume?
Answer: Amazon GuardDuty
Amazon GuardDuty uses ML on CloudTrail, VPC Flow Logs, and DNS logs to detect anomalous behavior such as unusual API calls or data exfiltration patterns.
A customer needs to demonstrate SOC 2 compliance to an auditor. Which AWS service maps AWS controls to SOC 2 requirements and continuously collects evidence?
Answer: AWS Audit Manager with the SOC 2 framework
AWS Audit Manager provides a prebuilt SOC 2 framework that maps AWS controls to SOC 2 criteria and automatically collects evidence for auditors.
What does the AWS Config rule `cloudtrail-enabled` check?
Answer: That at least one multi-region CloudTrail trail is active in the account
The `cloudtrail-enabled` managed rule verifies that at least one multi-region CloudTrail trail exists and is logging API activity.
An architect is designing a quality inspection pipeline for infrastructure-as-code. Which tool scans CloudFormation templates for security misconfigurations BEFORE deployment?
Answer: AWS CloudFormation Guard (cfn-guard)
AWS CloudFormation Guard is an open-source policy-as-code tool that evaluates CloudFormation templates against custom rules before they are deployed.