Safety Systems & Standards Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety Systems & Standards flashcards as text
Which AWS service should a DevOps team use to implement a Web Application Firewall that protects applications deployed behind an Application Load Balancer?
Answer: AWS WAF
AWS WAF integrates with Application Load Balancers and CloudFront to filter HTTP traffic using customizable rules that block common web exploits.
A pipeline deploys a Lambda function that will process sensitive PII data. Which AWS tool should be used to assess the function's permissions for least-privilege compliance?
Answer: IAM Access Analyzer
IAM Access Analyzer analyzes resource-based policies and IAM policies to identify overly permissive access and generate least-privilege policy recommendations.
Which deployment strategy minimizes risk by keeping the old environment live while the new version serves a small percentage of production traffic for validation?
Answer: Canary deployment
Canary deployments route a small fraction of production traffic to the new version, allowing real-world validation with limited blast radius before full rollout.
AWS CodePipeline integrates with AWS CloudTrail. What specific safety benefit does this integration provide in a DevOps context?
Answer: It provides a tamper-evident audit trail of all pipeline actions and approvals
CloudTrail records every CodePipeline API call with actor identity and timestamp, creating an immutable audit log for compliance and incident investigation.
A security team requires that all data in transit between microservices in an ECS cluster is encrypted. Which approach enforces this at the infrastructure level?
Answer: Configuring AWS App Mesh with TLS between service proxies
AWS App Mesh manages service-to-service communication and can enforce mutual TLS (mTLS) encryption between all Envoy proxies in an ECS cluster.
Which CloudFormation Stack Policy feature helps prevent accidental deletion or replacement of critical production resources during stack updates?
Answer: Stack policies that deny Update:Replace and Update:Delete on specified resources
Stack policies define what update actions are allowed on specific resources, preventing destructive actions like replacement or deletion on critical production resources.
When implementing immutable infrastructure in AWS, what is the key safety advantage over mutable (in-place update) deployments?
Answer: Immutable deployments eliminate configuration drift and enable instant rollback by switching traffic back to old instances
Because immutable deployments never modify running instances, every deployment starts from a known-good base, eliminating configuration drift and enabling fast rollback by routing traffic back.