Security Automation Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Automation flashcards as text
A development team uses AWS CDK to define infrastructure. How can they integrate automated security policy checks into their development workflow before code is committed?
Answer: Use cdk-nag as a pre-commit hook or CDK aspect to validate stacks against security best practice rules
cdk-nag is an open-source CDK aspect that applies security and compliance rule packs (AWS Solutions, NIST, PCI) at synthesis time, giving developers immediate feedback.
Amazon Macie is enabled in an AWS account. Which type of data does Macie primarily help protect?
Answer: Sensitive data such as PII and financial information stored in Amazon S3
Macie uses ML to discover and protect sensitive data (PII, financial records, credentials) stored in S3 buckets.
A pipeline must verify that third-party Docker base images have not been tampered with before use. Which mechanism provides cryptographic verification of image integrity?
Answer: Docker Content Trust (DCT) with image signing verified via Notary, enforced through the DOCKER_CONTENT_TRUST=1 environment variable
Docker Content Trust uses Notary to cryptographically sign and verify images, ensuring that only signed images from trusted publishers are pulled.
AWS IAM Access Analyzer is configured in an AWS account. What is its primary function in a security automation context?
Answer: Identify resources that are shared with external principals outside the zone of trust using policy analysis
IAM Access Analyzer uses formal verification to identify resource policies (S3, KMS, IAM roles, etc.) that grant access to external principals.
A security team needs to automatically block IP addresses identified by GuardDuty as malicious across all accounts in an AWS Organization. Which service enables centralized enforcement of this control?
Answer: AWS Network Firewall managed rule groups updated by Lambda from GuardDuty findings, deployed via Firewall Manager
AWS Firewall Manager centrally deploys and manages Network Firewall policies across accounts, and Lambda can dynamically update threat intelligence rule groups from GuardDuty findings.
In a CI/CD pipeline, dependency scanning (software composition analysis) is used to detect what type of security risk?
Answer: Known vulnerabilities in third-party open-source libraries and packages used by the application
Software composition analysis (SCA) identifies open-source dependencies with known CVEs, license violations, or other supply-chain risks.
A company wants to ensure that Lambda functions deployed through their pipeline do not have overly permissive execution roles. Which approach enforces this at pipeline time?
Answer: IAM Access Analyzer policy validation integrated as a CodeBuild step that fails the build if policies exceed a defined permission scope
IAM Access Analyzer's policy validation API can be called in CodeBuild to programmatically check for overly permissive policies and fail the pipeline before deployment.