โ† All AWS Flashcard Decks

Solutions Architect Security & Compliance Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Solutions Architect Security & Compliance flashcards as text
  1. A company wants to centralize security findings from GuardDuty, Inspector, and Macie across multiple AWS accounts. Which service aggregates these findings?

    Answer: AWS Security Hub

    AWS Security Hub aggregates, organizes, and prioritizes security findings from multiple AWS services and third-party tools across accounts.

  2. Which encryption option for RDS allows AWS to manage the encryption keys while the customer retains control of key policies via AWS KMS?

    Answer: RDS encryption at rest using AWS-managed KMS keys

    RDS encryption at rest using KMS allows AWS to manage the CMK operations while the customer controls key policies, rotation, and audit via KMS.

  3. A solutions architect needs to prevent any IAM entity in the organization from disabling AWS CloudTrail. Which is the most effective control?

    Answer: Apply an SCP denying cloudtrail:StopLogging and cloudtrail:DeleteTrail to all OUs

    An SCP denying cloudtrail:StopLogging and cloudtrail:DeleteTrail at the organization level prevents any account from disabling CloudTrail regardless of local IAM policies.

  4. What does enabling 'Block Public Access' at the S3 account level do to existing public bucket policies?

    Answer: It overrides existing policies and ACLs that grant public access

    Account-level S3 Block Public Access settings override and ignore existing bucket policies or ACLs that would otherwise grant public access.

  5. A company must ensure their AWS Lambda functions only access approved external endpoints. Which service can restrict outbound Lambda network traffic?

    Answer: VPC Security Groups and Network ACLs applied to Lambda in a VPC

    Placing Lambda in a VPC and applying security groups and NACLs restricts its outbound network traffic to only approved destinations.

  6. Which AWS Inspector scanning type identifies software vulnerabilities and unintended network exposure on EC2 instances?

    Answer: Network reachability and package vulnerability scanning

    AWS Inspector performs network reachability analysis and package vulnerability scanning on EC2 instances to identify exploitable vulnerabilities.

  7. A multi-tenant SaaS application stores customer data in separate S3 prefixes. Which mechanism ensures each tenant's IAM role can only access their own prefix?

    Answer: IAM policy conditions using aws:PrincipalTag and S3 prefix path variables

    Using IAM policy conditions with aws:PrincipalTag and S3 prefix variables (like ${aws:PrincipalTag/TenantID}) enables dynamic, attribute-based access control per tenant.