โ† All Architecting on AWS Certification Flashcard Decks

Safety Practices & PPE Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Safety Practices & PPE flashcards as text
  1. An architect is designing a VPC and wants to add an extra layer of stateless traffic filtering at the subnet boundary. Which AWS component provides this?

    Answer: Network Access Control Lists (NACLs)

    NACLs are stateless firewalls that operate at the subnet level, filtering both inbound and outbound traffic based on rules.

  2. Which AWS service enables centralized management of firewall rules across multiple accounts and VPCs in an AWS Organization?

    Answer: AWS Firewall Manager

    AWS Firewall Manager provides centralized administration and enforcement of firewall rules across an AWS Organization from a single account.

  3. A company processes payment data and must meet PCI DSS compliance. Which AWS tool provides compliance reports and attestations to verify AWS infrastructure meets this standard?

    Answer: AWS Artifact

    AWS Artifact provides on-demand access to AWS compliance reports, including PCI DSS Attestations of Compliance, for audit and compliance verification.

  4. Which encryption option for S3 allows the customer to provide and manage their own encryption keys outside of AWS, while AWS performs the encryption?

    Answer: SSE-C (Server-Side Encryption with Customer-Provided Keys)

    SSE-C lets customers provide their own encryption keys with each request; AWS uses the key to encrypt/decrypt but never stores it.

  5. An application team wants to receive automated alerts when a root account login is detected in their AWS account. Which combination of services achieves this?

    Answer: Use AWS CloudTrail with CloudWatch alarms filtering for root login events

    CloudTrail logs the root login event and a CloudWatch metric filter plus alarm can trigger an SNS notification when a root account sign-in is detected.

  6. Which AWS feature restricts the maximum permissions that an IAM entity (user or role) can have, even if their policy grants more?

    Answer: IAM permission boundaries

    Permission boundaries set the maximum permissions an IAM entity can have; the effective permissions are the intersection of the boundary and identity-based policies.

  7. A solutions architect wants to prevent accidental deletion of critical S3 objects by requiring a separate authorization step before permanent deletion. Which S3 feature achieves this?

    Answer: S3 Versioning with MFA Delete enabled

    S3 MFA Delete requires a valid MFA token before permanently deleting object versions, adding a mandatory second factor for destructive operations.