โ† All Architecting on AWS Certification Flashcard Decks

Welding Procedures & Techniques Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Welding Procedures & Techniques flashcards as text
  1. An application must allow users to upload files directly to S3 without routing through the application server. Which mechanism enables this securely?

    Answer: Generate a presigned S3 URL on the server and return it to the client

    A presigned URL grants temporary, scoped upload access without exposing AWS credentials to the client.

  2. A company wants to prevent any IAM user in their AWS account from disabling AWS CloudTrail. Which is the most effective control?

    Answer: Apply an SCP in AWS Organizations that denies cloudtrail:StopLogging

    An SCP applied at the Organizations level enforces the deny across all accounts, overriding any IAM permission.

  3. Which AWS service helps identify security vulnerabilities in EC2 instances and container images automatically?

    Answer: Amazon Inspector

    Amazon Inspector performs automated vulnerability assessments on EC2 instances and ECR container images.

  4. A serverless application needs to call an internal microservice in a private VPC. How should the Lambda function be configured?

    Answer: Configure the Lambda function to run inside the VPC with appropriate security groups

    Placing the Lambda function in the VPC allows it to access private resources using standard VPC networking.

  5. What does Amazon CloudFront's Origin Access Control (OAC) accomplish?

    Answer: It restricts S3 bucket access so only CloudFront can read objects

    OAC ensures your S3 bucket is not publicly accessible and only CloudFront can fetch its content.

  6. An architect needs to enforce that all new S3 buckets created in an AWS account block public access. What is the most scalable solution?

    Answer: Enable S3 Block Public Access at the account level

    Enabling S3 Block Public Access at the account level automatically applies to all existing and future buckets.

  7. Which AWS service provides DDoS protection automatically for all AWS customers at no additional cost for layer 3 and 4 attacks?

    Answer: AWS Shield Standard

    AWS Shield Standard is automatically included for all AWS customers and protects against common layer 3/4 DDoS attacks.