โ† All AWS Flashcard Decks

Security Automation Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Automation flashcards as text
  1. A team needs to automatically quarantine an EC2 instance when GuardDuty detects a cryptocurrency mining finding. Which architecture achieves this with the least custom code?

    Answer: EventBridge rule matching the GuardDuty finding type triggers an SSM Automation runbook that isolates the instance

    EventBridge natively receives GuardDuty findings as events, and SSM Automation runbooks can isolate instances without custom Lambda code.

  2. When implementing infrastructure-as-code security scanning in a pipeline, what is the primary difference between Checkov and AWS CloudFormation Guard?

    Answer: Checkov supports multiple IaC frameworks (Terraform, CloudFormation, Kubernetes) while cfn-guard is CloudFormation-specific with a custom policy language

    Checkov is a multi-framework open-source scanner while cfn-guard uses a domain-specific rule language designed specifically for CloudFormation and CDK templates.

  3. A company wants to ensure that all API calls made in their AWS accounts are logged and immutable audit trails are stored for 7 years. Which architecture satisfies this requirement?

    Answer: CloudTrail organization trail with log file validation enabled, logs shipped to S3 with Object Lock (Compliance mode) and Glacier lifecycle policy

    An organization trail with log file validation plus S3 Object Lock in Compliance mode creates tamper-proof, immutable audit logs that cannot be deleted even by root.

  4. In a multi-account AWS environment, which approach best prevents any account from disabling CloudTrail logging?

    Answer: An SCP that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail for all principals

    SCPs at the Organizations level are preventive controls that override all IAM permissions and prevent even account root from disabling CloudTrail.

  5. A security automation pipeline needs to dynamically retrieve a TLS certificate for a new service. Which AWS service automates certificate issuance and renewal with the least operational overhead?

    Answer: AWS Certificate Manager (ACM) with automatic renewal for certificates used with AWS services

    ACM automatically renews certificates before expiration when used with integrated AWS services like ALB, CloudFront, and API Gateway.

  6. Which AWS service enables you to define and audit that all EBS volumes attached to EC2 instances are encrypted, and automatically enforce encryption for new volumes?

    Answer: Enable EBS encryption by default at the account level plus an AWS Config rule to detect unencrypted existing volumes

    The account-level EBS encryption default ensures all new volumes are encrypted, while Config's encrypted-volumes rule detects existing non-compliant volumes.

  7. A CodePipeline deployment to production requires that a human security approver reviews the change before proceeding. Which stage type implements this control?

    Answer: A Manual Approval action in CodePipeline that sends an SNS notification to approvers

    CodePipeline's built-in Manual Approval action pauses the pipeline and sends SNS notifications to approvers who can approve or reject via console, CLI, or API.