โ† All AWS Flashcard Decks

Solutions Architect Security & Compliance Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Solutions Architect Security & Compliance flashcards as text
  1. A company needs to audit all API calls made to their AWS account over the past 90 days. Which service stores this data by default?

    Answer: AWS CloudTrail

    AWS CloudTrail records API activity and retains event history for 90 days by default in the console; longer retention requires an S3-backed trail.

  2. Which Amazon Macie capability helps protect sensitive data stored in Amazon S3?

    Answer: Using ML to discover and classify sensitive data like PII in S3

    Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data such as PII stored in S3 buckets.

  3. A solutions architect must ensure cross-account access to an S3 bucket is limited to a specific external AWS account. Which approach is correct?

    Answer: Add a bucket policy with the external account ARN as the Principal

    A bucket policy with the external account's ARN in the Principal element is the recommended way to grant cross-account access to an S3 bucket.

  4. Which AWS service provides managed DDoS protection and is automatically included at no cost for all AWS customers?

    Answer: AWS Shield Standard

    AWS Shield Standard is automatically applied to all AWS customers at no extra cost and provides protection against common Layer 3 and Layer 4 DDoS attacks.

  5. A developer accidentally pushed AWS access keys to a public GitHub repository. What should a solutions architect do FIRST?

    Answer: Immediately deactivate or delete the exposed access keys

    Immediately deactivating or deleting the exposed access keys stops any potential misuse before attackers can use them.

  6. Which AWS feature allows you to evaluate whether your AWS resource configurations comply with organizational policies on an ongoing basis?

    Answer: AWS Config Rules

    AWS Config Rules continuously evaluate resource configurations against desired settings and flag non-compliant resources automatically.

  7. An application uses an IAM role attached to an EC2 instance to access DynamoDB. What is retrieved from the instance metadata to authenticate API calls?

    Answer: Temporary security credentials issued by AWS STS

    EC2 instance roles use AWS STS to issue temporary credentials (access key, secret key, session token) available via the instance metadata service.