Safety Practices & PPE Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety Practices & PPE flashcards as text
Which AWS service provides automated security assessments to identify vulnerabilities and deviations from best practices in EC2 instances and applications?
Answer: Amazon Inspector
Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.
A company wants to ensure that no S3 bucket is ever made publicly accessible. Which AWS mechanism enforces this across an entire AWS account?
Answer: S3 Block Public Access account-level settings
S3 Block Public Access at the account level overrides any bucket-level or object-level ACL settings that would otherwise allow public access.
Which AWS feature allows you to define guardrails that prevent member accounts in an AWS Organization from performing unsafe or non-compliant actions?
Answer: AWS Service Control Policies (SCPs)
Service Control Policies (SCPs) act as guardrails that restrict what actions can be performed in member accounts, regardless of their IAM policies.
An architect needs to protect sensitive data in an RDS database so that even if the storage media is stolen, the data remains unreadable. Which approach should be used?
Answer: Enable RDS encryption at rest using AWS KMS
RDS encryption at rest using AWS KMS encrypts the underlying storage so data is unreadable without the decryption key.
Which AWS Well-Architected Framework pillar specifically addresses the ability to protect information, systems, and assets while delivering business value?
Answer: Security
The Security pillar of the AWS Well-Architected Framework covers protecting information, systems, and assets through risk assessments and mitigation strategies.
A developer accidentally committed AWS access keys to a public GitHub repository. What is the FIRST action an architect should take?
Answer: Rotate the access keys immediately
Immediately rotating (deactivating and replacing) the exposed access keys stops further unauthorized use before investigating the impact.
Which AWS service uses machine learning to continuously monitor AWS accounts for unusual activity and unauthorized behavior, acting as a threat detection service?
Answer: Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that uses ML to analyze CloudTrail, VPC Flow Logs, and DNS logs for malicious or unauthorized behavior.