โ† All AWS Flashcard Decks

Networking and Security Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking and Security flashcards as text
  1. A company wants to restrict outbound internet traffic from EC2 instances in a private subnet while allowing instances to initiate connections to the internet. Which solution should be used?

    Answer: NAT Gateway placed in a public subnet

    A NAT Gateway in a public subnet allows private subnet instances to initiate outbound connections while preventing inbound connections from the internet.

  2. Which AWS service enables you to centrally manage firewall rules across multiple AWS accounts and VPCs in an organization?

    Answer: AWS Firewall Manager

    AWS Firewall Manager lets you centrally configure and manage firewall rules (WAF, Shield, Security Groups, Network Firewall) across accounts in AWS Organizations.

  3. A developer needs to allow an EC2 instance to access an S3 bucket without embedding AWS credentials in the application code. What is the best approach?

    Answer: Attach an IAM role to the EC2 instance

    Attaching an IAM role to an EC2 instance provides temporary credentials via the instance metadata service, eliminating the need to store long-term credentials.

  4. What is the purpose of VPC Flow Logs?

    Answer: To capture information about IP traffic going to and from network interfaces in a VPC

    VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol, action) flowing through ENIs, useful for security analysis and troubleshooting.

  5. A security team needs to detect and alert on unusual API activity in their AWS account. Which service should they enable?

    Answer: AWS CloudTrail with Amazon CloudWatch Alarms

    CloudTrail records all API calls; pairing it with CloudWatch Alarms enables automated detection and alerting on suspicious or unauthorized API activity.

  6. Which type of VPC endpoint should be used to privately connect to Amazon S3 without traversing the public internet?

    Answer: Gateway Endpoint

    A Gateway Endpoint for S3 (and DynamoDB) routes traffic through route table entries within the VPC, keeping traffic off the public internet at no additional cost.

  7. An organization wants to enforce MFA for all IAM users when they perform sensitive operations. Where should this requirement be configured?

    Answer: In an IAM policy using the aws:MultiFactorAuthPresent condition key

    The aws:MultiFactorAuthPresent condition key in IAM policies enforces MFA by denying access when MFA has not been used during authentication.

Networking and Security Flashcards โ€” AWS Study Cards with Answers