Safety Systems & Standards Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety Systems & Standards flashcards as text
Which AWS Systems Manager capability helps enforce patch compliance standards across a fleet of EC2 instances on a scheduled basis?
Answer: Systems Manager Patch Manager
Patch Manager automates patching of EC2 instances using patch baselines and maintenance windows to ensure compliance with OS and application patch standards.
A company must ensure no secrets are committed to their CodeCommit repository. Which approach integrates secret detection into the pipeline?
Answer: Use a CodeBuild pre-build phase with tools like git-secrets or truffleHog
Running secret-scanning tools such as git-secrets or truffleHog in a CodeBuild pre-build phase catches hardcoded credentials before they reach the repository.
What is the purpose of using AWS Secrets Manager rotation in a DevOps pipeline compared to storing credentials in environment variables?
Answer: It automatically rotates credentials and eliminates long-lived static secrets
Secrets Manager automatically rotates credentials on a schedule, reducing the risk of compromised long-lived static secrets stored in environment variables.
Which AWS service enables you to set up continuous compliance monitoring and automatically generate audit-ready reports for standards like PCI DSS and HIPAA?
Answer: AWS Audit Manager
AWS Audit Manager continuously collects evidence and maps it to compliance frameworks like PCI DSS, HIPAA, and SOC 2 to simplify audit preparation.
A DevOps engineer needs to ensure that only signed container images are deployed to Amazon ECS. Which AWS feature enforces this requirement?
Answer: AWS Signer with ECS task definition policy
AWS Signer can sign container images, and ECS can be configured to enforce signature verification policies that reject unsigned or improperly signed images.
Which CloudFormation feature detects when deployed stack resources have been manually changed outside of CloudFormation, which can indicate a compliance violation?
Answer: Drift detection
CloudFormation drift detection compares the actual configuration of stack resources against the expected template configuration, identifying unauthorized manual changes.
In AWS DevOps workflows, what is the primary security benefit of using IAM roles for CodeBuild projects instead of IAM users with access keys?
Answer: Roles issue temporary credentials that automatically expire, eliminating long-lived key exposure
IAM roles provide temporary, automatically-rotated credentials via STS, eliminating the risk of long-lived access keys being leaked or compromised.