Courseiva

CCNA Security Questions

75 of 314 questions · Page 1/5 · Security · Answers revealed

1
MCQmedium

A developer is building an application that uses Amazon Cognito for user authentication. The application needs to allow users to sign in with their existing Google accounts. Which action should the developer take to enable this?

A.Create a Cognito identity pool and enable the Google authentication provider, specifying the Google client ID.
B.Configure a Cognito user pool with a Google identity provider, providing the Google client ID and client secret.
C.Implement a custom OAuth 2.0 flow in the application that directly calls the Google API and then issues AWS credentials.
D.Use AWS IAM to create a role for Google users and attach a policy that allows access to the application.
AnswerB

Amazon Cognito user pools support federation with social identity providers like Google. By configuring Google as an identity provider in the user pool, users can sign in with their Google accounts. The developer must supply the Google app's client ID and client secret, which Cognito uses to validate tokens during the federation process.

Why this answer

Cognito user pools natively support federation with Google. Configuring Google as an identity provider in the user pool allows users to sign in with their Google credentials. Cognito handles the OAuth flow, token validation, and user profile creation, simplifying the integration.

Exam trap

The trap here is mixing up user pools and identity pools; identity pools are for AWS credentials, while user pools handle authentication and federation.

2
Multi-Selecthard

A developer is designing a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application must authenticate users using a third-party OIDC identity provider and authorize each request. Which THREE steps should the developer take? (Choose THREE.)

Select 3 answers
A.Create an Amazon Cognito user pool with the OIDC identity provider configured.
B.Generate an API key and distribute it to users for authentication.
C.Create an IAM authorizer in API Gateway to validate the JWT token.
D.In the Lambda function, parse the JWT claims from the event context to make authorization decisions.
E.Use a Cognito user pool authorizer in API Gateway to validate the token.
AnswersA, D, E

Amazon Cognito User Pools are designed to manage user identities and provide authentication for web and mobile applications. By configuring an OIDC identity provider within a Cognito User Pool, developers can enable users to authenticate through an external OIDC-compliant service. Cognito then issues its own JWTs (ID, Access, Refresh tokens) to the application, abstracting the external OIDC provider and simplifying integration for the serverless backend. This is a standard and secure pattern for federated authentication.

Why this answer

Amazon Cognito user pools can be configured to federate with third-party OIDC identity providers. This allows the user pool to act as an intermediary that handles the OIDC token exchange, issuing its own JWT tokens after successful authentication. This is the standard approach for integrating external OIDC providers with AWS serverless applications.

Exam trap

The trap here is confusing the role of API Gateway authorizers: candidates often pick IAM authorizer (Option C) thinking it can validate JWTs, but IAM authorizers require AWS SigV4 signing and are not designed for OIDC token validation, while the Cognito user pool authorizer is the correct choice for JWT-based federated authentication.

3
Multi-Selectmedium

An application in ECS Fargate needs to read a secret and decrypt it with KMS. Which two permissions/configurations are needed?

Select 2 answers
A.Store the secret in the container image
B.Task role permissions for Secrets Manager access
C.An EC2 instance profile attached to the Fargate host
D.KMS key policy/IAM permission allowing decrypt for the task role
AnswersB, D

Assigning an IAM Task Role to the ECS Fargate task and granting it `secretsmanager:GetSecretValue` permissions is the secure and recommended approach. This allows the application running within the container to programmatically retrieve the necessary secret from AWS Secrets Manager at runtime. This method ensures secrets are never hardcoded, facilitates centralized management and rotation, and adheres to the principle of least privilege by granting only the necessary access.

Why this answer

The ECS task role is an IAM role that the Fargate task assumes to make AWS API calls. To read a secret from AWS Secrets Manager, the task role must have an IAM policy granting `secretsmanager:GetSecretValue` permission. Option D is correct because the secret is encrypted with a KMS key, so the task role also needs a KMS key policy or IAM permission that allows `kms:Decrypt` on that specific key.

Exam trap

The trap here is that candidates often confuse EC2 instance profiles with ECS task roles, forgetting that Fargate is serverless and has no underlying EC2 host to attach an instance profile to.

4
MCQmedium

A developer needs to allow users from another AWS account (account ID: 123456789012) to read objects in an S3 bucket owned by the developer's account. The developer wants to use a bucket policy and does not want to create IAM users in the other account. Which bucket policy statement achieves this securely?

A.{"Principal": "*", "Action": "s3:GetObject", "Effect": "Allow", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringEquals": {"aws:SourceAccount": "123456789012"}}}
B.{"Principal": {"AWS": "arn:aws:iam::123456789012:root"}, "Action": "s3:GetObject", "Effect": "Allow", "Resource": "arn:aws:s3:::bucket/*"}
C.{"Principal": {"AWS": "arn:aws:iam::123456789012:user/cross-account-user"}, "Action": "s3:GetObject", "Effect": "Allow", "Resource": "arn:aws:s3:::bucket/*"}
D.{"Principal": {"AWS": "arn:aws:iam::123456789012:role/cross-account-role"}, "Action": "s3:GetObject", "Effect": "Allow", "Resource": "arn:aws:s3:::bucket/*"}
AnswerB

The root ARN of the trusted account (arn:aws:iam::123456789012:root) is used as the Principal. This delegates control to the other account's administrator, who can then grant read access to specific IAM users or roles in their account.

Why this answer

It uses the AWS account root principal ARN (arn:aws:iam::123456789012:root) to grant cross-account access to the S3 bucket. This allows any IAM user or role in the external account to read objects, provided the external account's administrator delegates permissions via IAM policies. The bucket policy does not require creating IAM users in the other account, aligning with the requirement.

Exam trap

The trap here is that candidates often confuse the root principal ARN with a specific IAM entity, leading them to choose options that require pre-existing users or roles in the external account, or they misuse conditions like aws:SourceAccount with a wildcard principal, which does not securely restrict access.

How to eliminate wrong answers

Option A is wrong because the aws:SourceAccount condition is used for ensuring the request originates from a specific AWS account in resource-based policies, but it is typically paired with aws:SourceArn to prevent confused deputy issues; here, it is used alone with a wildcard principal, which is insecure and does not restrict to the intended account. Option C is wrong because it specifies a specific IAM user ARN, which requires that user to exist in the external account, contradicting the requirement not to create IAM users. Option D is wrong because it specifies a specific IAM role ARN, which requires that role to exist in the external account, also contradicting the requirement not to create IAM users or roles.

5
MCQeasy

A company has a centralized logging solution where all EC2 instances send logs to a CloudWatch Logs group in a central account. The EC2 instances are in a different account (App Account). The developer configures the CloudWatch agent on the instances with the necessary IAM role. However, logs are not appearing in the central account's log group. The IAM role in the App Account has permissions to put logs to the central account's log group. What is the most likely missing configuration?

A.CloudWatch Logs must be encrypted with the same KMS key in both accounts.
B.The central account's log group must have a resource-based policy that grants the App Account's IAM role permissions to put logs.
C.The log group must be in the same region as the EC2 instances.
D.The EC2 instances must be in a VPC with a VPC endpoint for CloudWatch Logs.
AnswerB

For successful cross-account logging, the destination CloudWatch Logs log group in the central account absolutely requires a resource-based policy. This policy must explicitly grant the `logs:PutLogEvents` permission to the specific IAM role or user from the application account that will be sending the logs. Without this explicit permission defined directly on the log group resource, the application account's IAM principal, even with local `logs:PutLogEvents` permissions, will be denied access to write to a log group owned by a different AWS account, establishing the necessary trust boundary.

Why this answer

For cross-account CloudWatch Logs, the central account's log group must have a resource-based policy that grants the App Account's IAM role permission to put logs. Even if the IAM role in the App Account has permissions, the destination log group must also allow the source. This is a common missing configuration.

Exam trap

DVA-C02 often tests cross-account access where both identity-based and resource-based policies are needed. Candidates may focus only on the IAM role permissions and forget the resource-based policy on the destination log group.

How to eliminate wrong answers

Option A is wrong because KMS encryption keys do not need to be the same across accounts; the role needs permission to use the key, but that is not the primary missing configuration for log delivery. Option C is wrong because CloudWatch Logs are regional, but the EC2 instances and log group can be in different regions if configured, though typically they are in the same region; however, the error is about permissions, not region. Option D is wrong because a VPC endpoint is not required for CloudWatch Logs if the instances have internet access or NAT, and the issue is permissions, not network connectivity.

6
MCQeasy

A company wants to ensure that no Amazon S3 buckets in the AWS account can be made publicly accessible, even if a bucket policy or ACL is later configured to allow public access. Which AWS feature should the developer enable to enforce this at the account level?

A.S3 Block Public Access
B.S3 Object Lock
C.S3 Transfer Acceleration
D.S3 Bucket Policy with Deny clause
AnswerA

S3 Block Public Access, when configured at the account level, provides a comprehensive safeguard against unintended public exposure of S3 buckets and objects. It enforces four distinct settings (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets) that collectively override any bucket policies, ACLs, or object configurations that might otherwise grant public access. This powerful feature ensures that no S3 bucket within the AWS account can be made public, regardless of individual bucket settings.

Why this answer

S3 Block Public Access is the correct choice because it provides account-level settings that override any bucket-level policies or ACLs that would grant public access. When enabled at the account level, these settings apply to all current and future S3 buckets, effectively preventing any bucket from becoming publicly accessible regardless of subsequent configuration changes.

Exam trap

The trap here is that candidates often choose a bucket policy with a Deny clause (Option D) thinking it can enforce account-wide restrictions, but they overlook that such policies are bucket-specific and can be removed or modified by users with appropriate IAM permissions, whereas S3 Block Public Access provides a centralized, immutable account-level control.

How to eliminate wrong answers

Option B is wrong because S3 Object Lock is designed to prevent objects from being deleted or overwritten for a fixed period, not to control public access permissions. Option C is wrong because S3 Transfer Acceleration is a feature that speeds up uploads over long distances using AWS edge locations, and it has no effect on access control or public accessibility. Option D is wrong because a bucket policy with a Deny clause is applied at the individual bucket level, not at the account level, and it can be overridden or removed by anyone with sufficient permissions; it does not provide the centralized, enforceable control that Block Public Access offers.

7
MCQhard

A company's S3 bucket policy includes a condition that uses 'aws:SourceIp' to restrict access to a specific IP range. However, requests from that IP range are still denied. What is a possible reason?

A.The request is routed through CloudFront, which changes the source IP.
B.The bucket owner's IAM user policy overrides the bucket policy.
C.The request is coming through a VPC endpoint, so the source IP is not the client's IP.
D.The condition key 'aws:SourceIp' is misspelled.
AnswerC

When requests to S3 originate from within a VPC and are routed through a VPC endpoint for S3, the 'aws:SourceIp' condition key in the S3 bucket policy evaluates the private IP address of the VPC endpoint, not the original client's public IP address. Consequently, if the bucket policy's allowed IP range does not include the VPC endpoint's private IP, the request will be denied. To correctly permit access from a VPC endpoint, the 'aws:SourceVpce' condition key, specifying the VPC endpoint ID, should be used instead.

Why this answer

When a request is made through a VPC endpoint (specifically a Gateway Endpoint for S3), the source IP address seen by S3 is the private IP of the VPC endpoint, not the client's original public IP. The 'aws:SourceIp' condition key evaluates the IP address from which the request originates at the network layer, but VPC endpoints use private IPs from the VPC CIDR range, which will not match the public IP range specified in the policy. This causes the condition to fail and the request to be denied, even though the client is within the intended IP range.

Exam trap

The trap here is that candidates assume 'aws:SourceIp' always reflects the client's original public IP, but they forget that VPC endpoints and proxies (like CloudFront or a NAT gateway) can change the source IP seen by the service, leading to unexpected denials.

How to eliminate wrong answers

Option A is wrong because CloudFront does not change the source IP for S3 bucket policy evaluation; CloudFront uses its own IP addresses when forwarding requests to the origin, but the 'aws:SourceIp' condition in a bucket policy would see CloudFront's IP, not the client's IP, so this could also cause denial, but the question specifies the request is from the correct IP range and still denied, making VPC endpoint the more precise reason. Option B is wrong because IAM user policies do not override bucket policies; if both exist, the request must be allowed by at least one policy, but an explicit deny in the bucket policy would still block the request, and an IAM policy cannot override a bucket policy deny. Option D is wrong because if 'aws:SourceIp' were misspelled, the condition would be ignored (not evaluated), and the policy would likely allow the request (assuming other conditions are met), not deny it.

8
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. They have a Customer Master Key (CMK) with key rotation enabled. The S3 bucket has default encryption using SSE-KMS with this CMK. An application writes objects to the bucket. Which statement about the encryption is correct?

A.The CMK is used to generate a data key that encrypts the object, and the encrypted data key is stored with the object.
B.The CMK directly encrypts the object data.
C.When the CMK is rotated, all existing objects in the bucket are automatically re-encrypted with the new key.
D.Each object is encrypted with a unique data key that is stored alongside the object.
AnswerA

This statement accurately describes AWS KMS envelope encryption, which is the standard mechanism for encrypting data in Amazon S3 using KMS. The Customer Master Key (CMK) never directly encrypts the large object data; instead, it is used to generate and encrypt a unique data key. This data key then performs the actual encryption of the S3 object, and its encrypted form is securely stored alongside the object within its metadata, enabling decryption later.

Why this answer

AWS KMS uses envelope encryption: when an object is written to S3 with SSE-KMS, KMS generates a unique data key from the CMK, encrypts the object with that data key, and then stores the encrypted data key alongside the object in S3. The CMK itself never directly encrypts the object data; it only encrypts the data key. This ensures that the CMK can be rotated without affecting the encrypted objects, as the encrypted data key remains decryptable by the new key material if the key ID is the same.

Exam trap

The trap here is that candidates often confuse the role of the CMK and the data key, mistakenly thinking the CMK directly encrypts the object (Option B), or they assume key rotation triggers re-encryption of existing data (Option C), when in fact envelope encryption decouples the key rotation from the stored ciphertext.

How to eliminate wrong answers

Option B is wrong because the CMK never directly encrypts the object data; AWS KMS uses envelope encryption where the CMK encrypts a data key, and that data key encrypts the object. Option C is wrong because key rotation creates new backing key material for the CMK but does not re-encrypt existing objects; the old backing key remains available for decryption, and objects encrypted before rotation are not automatically re-encrypted. Option D is wrong because while each object is encrypted with a unique data key, that data key is not stored alongside the object in plaintext; it is stored encrypted under the CMK, and the statement omits the critical detail that the data key is encrypted.

9
MCQhard

Refer to the exhibit. An IAM policy allows s3:GetObject for a bucket only from a specific IP range. A developer accesses the bucket from a laptop with IP address 192.0.2.55, but access is denied. What is the most likely reason?

A.The policy includes an explicit deny statement elsewhere.
B.The condition key should be 'aws:SourceIp' without the 'IpAddress' wrapper.
C.The laptop's IP address is not within the allowed range.
D.The request is made from an AWS service, such as the AWS Management Console, which does not use the laptop's public IP.
AnswerD

This is the correct explanation. When a user interacts with AWS services through the AWS Management Console, the actual API requests to services like S3 are proxied through AWS's own infrastructure. Consequently, the `aws:SourceIp` condition in the IAM policy evaluates against the public IP address of the AWS service endpoint or proxy making the call, not the end-user's laptop IP address. If this AWS-owned IP falls outside the `192.0.2.0/24` range, the condition fails, and access is denied, even if the user's laptop IP is within the allowed range.

Why this answer

When a request is made via the AWS Management Console, the console itself acts as an intermediary. The console's requests originate from AWS service IPs, not the user's laptop public IP. Therefore, the `aws:SourceIp` condition in the IAM policy evaluates against the console's IP, which is not in the allowed range, causing the denial even though the laptop's IP is valid.

Exam trap

The trap here is that candidates assume the laptop's public IP is always used for the request, forgetting that the AWS Management Console acts as a proxy, so the `aws:SourceIp` condition evaluates the console's IP, not the user's.

How to eliminate wrong answers

Option A is wrong because the question states the policy allows s3:GetObject from a specific IP range, and there is no mention or evidence of an explicit deny statement elsewhere; the most likely reason is the IP mismatch due to the console proxy. Option B is wrong because the `IpAddress` wrapper is the correct syntax for the `aws:SourceIp` condition key in an IAM policy; omitting it would cause a syntax error, not a logical denial. Option C is wrong because the laptop's IP address (192.0.2.55) is within the allowed range as described in the scenario, so the denial must stem from the request not using that IP.

10
MCQmedium

A company uses AWS KMS to encrypt S3 objects. A developer needs to allow an IAM user to decrypt objects but not encrypt them. Which IAM policy action should be allowed?

A.kms:Decrypt
B.kms:GenerateDataKey
C.kms:Encrypt
D.kms:ReEncrypt
AnswerA

The `kms:Decrypt` permission is essential for retrieving and accessing S3 objects that have been encrypted using AWS KMS. When an application attempts to download an S3 object encrypted with a KMS key, S3 internally requests the KMS service to decrypt the data key associated with that object. This action allows the S3 service, on behalf of the requesting principal, to decrypt the object's content and return it in plaintext.

Why this answer

The correct action is `kms:Decrypt` because the developer's requirement is to allow an IAM user to decrypt S3 objects but not encrypt them. AWS KMS uses separate permissions for encryption and decryption operations; `kms:Decrypt` specifically grants the ability to decrypt ciphertext without granting any encryption capabilities. By allowing only this action, the user can decrypt objects encrypted with the KMS key but cannot encrypt new data or perform any key management operations.

Exam trap

The trap here is that candidates often confuse `kms:Decrypt` with `kms:GenerateDataKey` or `kms:ReEncrypt`, mistakenly thinking those actions are required for decryption, when in fact they also enable encryption capabilities that violate the requirement.

How to eliminate wrong answers

Option B is wrong because `kms:GenerateDataKey` is used to generate a data key for client-side encryption, which involves creating both a plaintext key and an encrypted key; allowing this would enable the user to encrypt new data, violating the requirement to prevent encryption. Option C is wrong because `kms:Encrypt` directly allows the user to encrypt plaintext into ciphertext using the KMS key, which is explicitly prohibited. Option D is wrong because `kms:ReEncrypt` allows decrypting ciphertext and re-encrypting it under a different KMS key, which includes decryption capability but also introduces encryption operations, violating the restriction against encryption.

11
MCQmedium

A company runs an application on Amazon EC2 instances that need to read files from an Amazon S3 bucket. The developer must grant access to the S3 bucket without storing long-term credentials on the instances. Which approach should the developer use?

A.Store the access key ID and secret access key in environment variables on the EC2 instance.
B.Create an IAM role with permissions to the S3 bucket and attach it to the EC2 instance profile.
C.Use an S3 bucket policy that grants access to the EC2 instance's public IP address.
D.Store the credentials in AWS Secrets Manager and have the application retrieve them at startup.
AnswerB

Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary credentials automatically from the instance metadata service, which rotate regularly. This satisfies the stem's constraint of granting S3 read access without storing long-term credentials on the instances, unlike embedding access keys.

Why this answer

Using an IAM role attached to an EC2 instance profile allows the application to obtain temporary security credentials from the AWS Security Token Service (STS) via the instance metadata service. This eliminates the need to store long-term credentials on the instance, adhering to the principle of least privilege and improving security posture.

Exam trap

The trap here is that candidates may think storing credentials in environment variables or Secrets Manager is acceptable, but the question explicitly requires no long-term credentials on the instance, making the IAM role the only correct answer that leverages temporary credentials via the instance metadata service.

How to eliminate wrong answers

Option A is wrong because storing access key ID and secret access key in environment variables on the EC2 instance exposes long-term credentials that could be compromised if the instance is accessed or the environment is leaked, violating the requirement to avoid storing long-term credentials. Option C is wrong because an S3 bucket policy that grants access based on the EC2 instance's public IP address is not a secure or reliable method; public IPs can change (unless using an Elastic IP) and do not authenticate the instance's identity, plus S3 bucket policies support principal-based access, not IP-based for EC2 instances in this context. Option D is wrong because while AWS Secrets Manager securely stores credentials, the application would still need to retrieve and use long-term credentials at startup, which contradicts the requirement to avoid storing long-term credentials on the instance; using an IAM role is the preferred approach for EC2 instances.

12
MCQmedium

A company wants to allow cross-account access to an S3 bucket in Account A from a role in Account B. The S3 bucket policy in Account A allows the role's ARN. However, access is denied. What is the most likely missing step?

A.Add a bucket policy that denies access to all principals.
B.The role in Account B must have an IAM policy that allows the S3 actions.
C.Disable block public access settings on the bucket.
D.Enable ACLs on the S3 bucket.
AnswerB

For successful cross-account access, both the resource-based policy (S3 bucket policy) and the identity-based policy (IAM policy attached to the role in Account B) must explicitly grant the necessary permissions. While the bucket policy grants the Account B role permission to *assume* access to the bucket, the role itself must possess an IAM policy allowing it to perform specific S3 actions like `s3:GetObject` or `s3:PutObject`. This dual authorization model ensures granular control and adherence to the principle of least privilege.

Why this answer

Cross-account S3 access requires both a resource-based policy (the bucket policy in Account A) that grants access to the role ARN, and an identity-based policy (an IAM policy attached to the role in Account B) that explicitly allows the S3 actions. Without the IAM policy in Account B, the role lacks permission to perform the S3 operations, even though the bucket policy permits the access. This is a fundamental principle of AWS cross-account authorization: both the resource side and the principal side must grant the necessary permissions.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, overlooking the requirement for an IAM policy on the requesting role to explicitly allow the S3 actions.

How to eliminate wrong answers

Option A is wrong because adding a bucket policy that denies access to all principals would explicitly block all access, including the intended cross-account access, making the problem worse. Option C is wrong because block public access settings are irrelevant to cross-account access via IAM roles; they only affect public access from the internet, not authenticated cross-account requests. Option D is wrong because enabling ACLs on the S3 bucket is not required for cross-account access; ACLs are a legacy access control mechanism and are not needed when using IAM policies and bucket policies, and they would not resolve the missing IAM policy issue.

13
MCQmedium

A company has an S3 bucket that stores sensitive data. They want to ensure that any object uploaded to the bucket is automatically encrypted with server-side encryption using AWS KMS (SSE-KMS). They also want to deny any uploads that do not specify the correct encryption. Which bucket policy condition should be used to enforce this requirement?

A.s3:x-amz-server-side-encryption equals aws:kms
B.s3:x-amz-server-side-encryption equals AES256
C.s3:x-amz-server-side-encryption-aws-kms-key-id equals a specific key ARN
D.aws:SecureTransport equals true
AnswerA

This condition key directly inspects the `x-amz-server-side-encryption` request header, which clients must include to specify the desired server-side encryption method. By setting `aws:kms` as the required value, a bucket policy with a Deny effect ensures that any object uploaded to the S3 bucket *must* explicitly request Server-Side Encryption with AWS Key Management Service (SSE-KMS). This effectively enforces the use of KMS-managed keys for sensitive data at rest, preventing uploads that do not comply with this encryption standard.

Why this answer

The condition `s3:x-amz-server-side-encryption equals aws:kms` enforces that any PUT request to the S3 bucket must include the `x-amz-server-side-encryption` header set to `aws:kms`, which triggers SSE-KMS encryption. This policy condition ensures that objects uploaded without specifying SSE-KMS are denied, meeting the requirement to automatically encrypt all uploaded objects with AWS KMS.

Exam trap

The trap here is that candidates confuse the condition for specifying a particular KMS key ARN (Option C) with the condition for simply requiring SSE-KMS encryption, leading them to pick an overly restrictive policy that would break uploads using the default KMS key.

How to eliminate wrong answers

Option B is wrong because `AES256` corresponds to SSE-S3 (S3-managed keys), not SSE-KMS, so it would enforce the wrong encryption type. Option C is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` enforces a specific KMS key ARN, but the question only requires SSE-KMS encryption, not a particular key; using this condition would be overly restrictive and could deny valid uploads using the default KMS key. Option D is wrong because `aws:SecureTransport` enforces HTTPS (TLS) for all requests, which is a transport-layer security requirement, not an encryption-at-rest requirement for object uploads.

14
MCQeasy

A company wants to encrypt data in transit between an EC2 instance and an S3 bucket. What should they do?

A.Use SSH to transfer files to S3.
B.Establish a VPN connection between the instance and S3.
C.Enable client-side encryption using the AWS SDK.
D.Use the S3 HTTPS endpoint for all API calls.
AnswerD

S3's HTTPS endpoints wrap every API call in TLS, encrypting the request and response payloads end-to-end between the EC2 instance and S3, which directly and completely satisfies the requirement to encrypt data in transit with no additional configuration needed.

Why this answer

Data in transit between EC2 and S3 is encrypted by using the S3 HTTPS endpoint for all API calls, which uses TLS/SSL to encrypt the connection. Option A is incorrect because S3 does not support SSH transfers; SSH is used for secure shell access, not for S3 API calls. Option B is incorrect because S3 does not support VPN connections; VPN is used for network-level encryption between on-premises networks and AWS, not directly between EC2 and S3.

Option C is incorrect because client-side encryption encrypts data before sending, but it does not address encryption in transit; HTTPS is the standard for in-transit encryption, and client-side encryption is for data at rest on the client side.

15
MCQhard

A developer needs to grant an IAM role in Account B read-only access to objects in an S3 bucket in Account A. The bucket is encrypted with server-side encryption using AWS KMS (SSE-KMS) with a customer managed key (CMK) in Account A. Which combination of policies is required for the cross-account access to succeed?

A.The bucket policy in Account A grants s3:GetObject to the role, the KMS key policy grants kms:Decrypt to the role, and the role in Account B has an IAM policy allowing s3:GetObject and kms:Decrypt
B.The bucket policy in Account A grants s3:GetObject to the role, and the role in Account B has an IAM policy allowing s3:GetObject. No KMS permissions are needed because SSE-KMS uses AWS managed keys by default.
C.The bucket policy in Account A grants s3:GetObject to the role, and the KMS key policy grants kms:Decrypt to the role. The role in Account B does not need additional IAM policies because the bucket and key policies provide sufficient permissions.
D.Only the bucket policy in Account A needs to grant s3:GetObject to the role. KMS is not involved because the bucket is encrypted with SSE-KMS but the role can decrypt using the default KMS key.
AnswerA

All three policies are required: bucket policy and key policy in Account A grant the necessary permissions, and the IAM role in Account B must have the corresponding IAM policy to authorize the use of those grants.

Why this answer

Cross-account access to an SSE-KMS encrypted S3 bucket requires three layers of permissions: the bucket policy in Account A must grant s3:GetObject to the IAM role in Account B, the KMS key policy must grant kms:Decrypt to the same role, and the role's IAM policy in Account B must allow both s3:GetObject and kms:Decrypt. Without any one of these, the request will fail due to either an S3 authorization error or a KMS decryption failure.

Exam trap

The trap here is that candidates assume bucket and key policies alone are sufficient for cross-account access, forgetting that the requesting principal (the IAM role) must also have an IAM policy that explicitly allows the required actions.

How to eliminate wrong answers

Option B is wrong because SSE-KMS with a customer managed key (CMK) requires explicit kms:Decrypt permissions; AWS managed keys are not used here, and omitting KMS permissions will cause a 'KMS.AccessDeniedException' when the role tries to read encrypted objects. Option C is wrong because the role in Account B must have an IAM policy that allows s3:GetObject and kms:Decrypt; bucket and key policies alone cannot grant permissions to a principal in another account—the role's trust policy and IAM permissions are necessary to authorize the action. Option D is wrong because KMS is always involved when SSE-KMS is used; the bucket is encrypted with a CMK, not the default KMS key, and the role must have kms:Decrypt permissions to decrypt the objects.

16
MCQmedium

A developer runs the AWS CLI command to decrypt a file using a KMS key. What is the most likely cause of the error?

A.The encrypted file is corrupted.
B.The CLI cannot read the file.
C.The IAM user lacks kms:Decrypt permission on the key.
D.The KMS key ID is incorrect.
AnswerC

An AccessDeniedException from KMS Decrypt specifically means the calling principal's IAM policy or the KMS key's resource policy (key policy) does not grant kms:Decrypt on that key — KMS enforces both the identity-based policy and the key policy, and either one missing the grant results in exactly this authorization failure.

Why this answer

The IAM user DevUser does not have kms:Decrypt permission on the specified KMS key.

17
Multi-Selecthard

A developer is troubleshooting an issue where an EC2 instance cannot access an S3 bucket. The instance has an IAM role with a policy that allows s3:GetObject on the bucket. Which TWO additional checks should the developer perform to resolve the issue?

Select 2 answers
A.Check the network ACLs for the subnet.
B.Check if the S3 bucket policy has an explicit deny statement that affects the EC2 instance.
C.Check if the EC2 instance is in a VPC with an S3 VPC endpoint configured.
D.Check the security group rules attached to the EC2 instance.
E.Check if the S3 bucket uses SSE-KMS encryption and the EC2 role has kms:Decrypt permissions.
AnswersB, E

An explicit deny statement within an S3 bucket policy takes precedence over any allow statements, including those granted by an IAM role attached to the EC2 instance. Even if the EC2 instance's IAM role has `s3:GetObject` permissions, a bucket policy explicitly denying access to that specific principal or IP range will override it, effectively blocking access to the S3 bucket. This is a critical aspect of AWS's authorization evaluation logic.

Why this answer

S3 bucket policies can explicitly deny access even if the IAM role attached to the EC2 instance grants s3:GetObject. An explicit deny in a bucket policy overrides any allow, so checking for such a deny statement is essential. Option E is correct because if the S3 bucket uses SSE-KMS encryption, the EC2 instance's IAM role must have kms:Decrypt permissions to decrypt the object; without it, GetObject requests will fail.

Exam trap

The trap here is that candidates often focus only on IAM policies or network controls (NACLs/security groups) and overlook the combination of bucket policies with explicit denies and KMS encryption permissions, which are common real-world blockers.

18
MCQmedium

A developer is configuring a load balancer in front of an EC2 instance running a web application. The application needs to authenticate users via an identity provider. Which AWS service should the developer use to handle authentication and authorization?

A.AWS Identity and Access Management (IAM)
B.Amazon Cognito
C.Amazon Route 53
D.Amazon CloudFront
AnswerB

Amazon Cognito provides user pools that handle sign-up, sign-in, and access control for web and mobile application users, including integration with third-party identity providers and social logins, and it issues JSON Web Tokens that a load balancer's built-in authentication action can validate before forwarding requests to the EC2 target, making it the purpose-built service for this use case.

Why this answer

Amazon Cognito is designed to handle user authentication and authorization for web and mobile applications. It provides user pools for sign-up/sign-in and identity pools for federated identities, allowing integration with external identity providers (IdPs) like Google, Facebook, and SAML. Since the application needs to authenticate users via an identity provider, Cognito is the correct choice.

Exam trap

DVA-C02 often tests the distinction between IAM (for AWS service access) and Cognito (for application user authentication), so candidates may incorrectly choose IAM when the question involves end-user authentication.

How to eliminate wrong answers

Option A is wrong because AWS IAM is used for managing access to AWS resources and services, not for authenticating end-users of an application. Option C is wrong because Amazon Route 53 is a DNS web service that routes end-users to internet applications, not an authentication service. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that speeds up distribution of static and dynamic web content, not an identity provider.

19
MCQeasy

A developer is building a serverless application using AWS Lambda functions that need to read and write to an Amazon DynamoDB table. What is the best practice for granting the Lambda function access to DynamoDB?

A.Create an IAM role with a trust policy that allows Lambda to assume it, and attach a permissions policy granting DynamoDB access.
B.Create an IAM user and store the access keys in the Lambda environment variables.
C.Attach a resource-based policy to the Lambda function that grants DynamoDB access.
D.Use the Lambda function's default VPC role to access DynamoDB via a VPC endpoint.
AnswerA

The standard and most secure method for a Lambda function to interact with other AWS services, such as DynamoDB, is by assuming an IAM execution role. This role requires a trust policy allowing `lambda.amazonaws.com` to assume it, and an attached permissions policy explicitly granting the necessary DynamoDB actions. This mechanism provides temporary, scoped credentials, adhering to the principle of least privilege and ensuring secure access.

Why this answer

AWS Lambda functions require an IAM role (execution role) with a trust policy that allows Lambda to assume it, and a permissions policy that grants the necessary DynamoDB actions (e.g., GetItem, PutItem). This is the standard and secure method for granting permissions to Lambda, as it avoids hardcoding credentials and follows the principle of least privilege.

Exam trap

The trap here is that candidates confuse resource-based policies (used for Lambda function invocation permissions) with execution roles (used for granting the Lambda function access to other AWS services), leading them to incorrectly choose Option C.

How to eliminate wrong answers

Option B is wrong because storing IAM user access keys in Lambda environment variables is insecure and violates best practices; keys can be exposed in logs or through the console, and they do not automatically rotate. Option C is wrong because Lambda functions do not support resource-based policies for granting access to other AWS services like DynamoDB; resource-based policies are used for cross-account access to the Lambda function itself, not for the function to access external resources. Option D is wrong because a VPC role or VPC endpoint does not grant IAM permissions; VPC endpoints enable private network connectivity but do not replace the need for an IAM role with DynamoDB access policies.

20
MCQeasy

A developer needs to securely store database credentials for a serverless application. Which service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3
D.AWS Key Management Service (KMS)
AnswerA

Secrets Manager is purpose-built for credentials like database usernames and passwords: it encrypts secrets at rest with KMS, supports automatic rotation via built-in Lambda rotation functions for RDS/Aurora/DocumentDB, and integrates natively with Lambda through the SDK or a caching layer extension for fast, secure retrieval.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials, with native integration to RDS rotation Lambdas and fine-grained IAM access. It encrypts secrets with KMS and supports automatic rotation, which is the key differentiator for credential storage.

Exam trap

DVA-C02 often tests the overlap between Parameter Store SecureString and Secrets Manager, baiting candidates who do not realize that automatic credential rotation is the decisive requirement that only Secrets Manager satisfies.

How to eliminate wrong answers

Option B is wrong because Systems Manager Parameter Store can store SecureString values but lacks built-in automatic rotation for database credentials and is better suited to configuration data than lifecycle-managed secrets. Option C is wrong because S3 is object storage with no native secret rotation, versioning of credentials, or fine-grained secret retrieval API, making it inappropriate and insecure for credentials. Option D is wrong because KMS is a key management service that encrypts data but does not store secrets itself; it is a building block used by Secrets Manager, not a credential store.

21
MCQmedium

A company has an Amazon S3 bucket that stores sensitive documents. The security team wants to ensure that all GET requests to the bucket are authenticated and that the requester does not have public access. Which combination of S3 features should the developer implement?

A.Block public access and enable S3 Access Points with a network origin policy
B.Enable S3 Object Lock and versioning
C.Use S3 Transfer Acceleration and server-side encryption
D.Configure a bucket policy that allows only specific IAM users and enable MFA Delete
AnswerA

This combination directly addresses the security of sensitive documents by preventing any public exposure. S3 Block Public Access is a critical account-level or bucket-level setting that overrides all other permissions, ensuring no object can be publicly accessed, regardless of bucket policies or ACLs. S3 Access Points, when configured with a network origin policy, allow granular control, restricting access to specific VPCs or IP ranges, further enhancing security by limiting the network attack surface while still enabling authenticated access for authorized users or applications within the defined network boundaries.

Why this answer

Blocking public access at the bucket level ensures that no anonymous or public requests can reach the bucket, while S3 Access Points with a network origin policy restrict access to requests originating from a specific VPC or on-premises network. This combination enforces that all GET requests must be authenticated (via the Access Point's IAM policies) and cannot come from public internet sources, meeting the security team's requirements.

Exam trap

The trap here is that candidates often confuse MFA Delete or encryption with authentication controls, not realizing that only explicit public access blocking combined with network-level restrictions (like Access Points) can prevent unauthenticated GET requests.

How to eliminate wrong answers

Option B is wrong because S3 Object Lock and versioning prevent object deletion or overwrite and maintain object history, but they do not control authentication or public access for GET requests. Option C is wrong because S3 Transfer Acceleration speeds up uploads over long distances and server-side encryption protects data at rest, neither of which authenticates requests or blocks public access. Option D is wrong because a bucket policy allowing only specific IAM users can restrict access, but MFA Delete only adds multi-factor authentication to delete operations, not to GET requests, and this combination does not inherently block public access from unauthenticated sources.

22
MCQeasy

A company is using AWS KMS to encrypt sensitive data stored in S3. The security team wants to ensure that only a specific IAM role can decrypt the data. What is the most secure way to achieve this?

A.Use S3 server-side encryption with S3-managed keys (SSE-S3).
B.Create a KMS key policy that grants the role the kms:Decrypt permission.
C.Enable automatic key rotation for the KMS key.
D.Use an S3 bucket policy to restrict access to the role.
AnswerB

A KMS key policy is the primary authorization mechanism for a Customer Managed Key (CMK), explicitly defining which IAM principals can perform cryptographic operations. Granting the `kms:Decrypt` permission to a specific role within the key policy directly enables that role to decrypt data encrypted by the CMK. This direct control over key usage is fundamental for fine-grained access management, ensuring only authorized entities can access sensitive data.

Why this answer

KMS key policies are the most direct and secure way to control who can perform cryptographic operations like kms:Decrypt on a specific CMK. By granting only the specific IAM role the kms:Decrypt permission in the key policy, you ensure that no other principal (including the root user or other roles) can decrypt the data, even if they have S3 access. This follows the principle of least privilege and decouples data access from infrastructure access.

Exam trap

The trap here is that candidates often confuse S3 bucket policies with KMS key policies, assuming that restricting S3 access is sufficient to prevent decryption, when in fact the KMS key policy is the only way to enforce decryption restrictions at the cryptographic level.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses S3-managed keys, which do not allow you to restrict decryption to a specific IAM role; any principal with S3 GetObject permission can decrypt the data. Option C is wrong because automatic key rotation only changes the backing key material over time for security hygiene, but does not restrict who can decrypt; it does not address access control. Option D is wrong because an S3 bucket policy can control access to the S3 object itself, but it cannot prevent decryption of the underlying KMS-encrypted data if the caller has both S3 GetObject and KMS Decrypt permissions; the KMS key policy is the authoritative control for decryption.

23
MCQeasy

A company requires that all objects uploaded to an Amazon S3 bucket are encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). The developer wants to enforce this with a bucket policy. Which condition key and value should be used in the policy to deny uploads that do not meet this requirement?

A.s3:x-amz-server-side-encryption equals AES256
B.s3:x-amz-server-side-encryption-aws-kms-key-id equals alias/aws/s3
C.aws:SecureTransport equals true
D.s3:object-lock-mode equals GOVERNANCE
AnswerA

This condition key, "s3:x-amz-server-side-encryption", directly evaluates the "x-amz-server-side-encryption" header included in an S3 PUT request. Specifying "AES256" mandates the use of Server-Side Encryption with Amazon S3-managed keys (SSE-S3), ensuring that S3 automatically encrypts objects using the AES-256 algorithm before storing them. This is the precise and correct method within a bucket policy to enforce encryption at rest for all uploaded objects without requiring AWS KMS.

Why this answer

The condition key `s3:x-amz-server-side-encryption` with value `AES256` directly checks that the request header `x-amz-server-side-encryption` is set to `AES256`, which is the required value for SSE-S3. By using this condition in a bucket policy with a Deny effect, any upload that does not include this header or includes a different value (e.g., `aws:kms`) will be rejected, enforcing server-side encryption with Amazon S3 managed keys.

Exam trap

The trap here is that candidates often confuse the condition key for SSE-S3 (`s3:x-amz-server-side-encryption` with value `AES256`) with the condition key for SSE-KMS (`s3:x-amz-server-side-encryption-aws-kms-key-id`), or mistakenly think `aws:SecureTransport` enforces encryption at rest instead of in transit.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` is used to enforce a specific KMS key ID for SSE-KMS, not for SSE-S3; using `alias/aws/s3` would require SSE-KMS, not SSE-S3. Option C is wrong because `aws:SecureTransport` checks whether the request uses HTTPS (TLS), which enforces encryption in transit, not encryption at rest. Option D is wrong because `s3:object-lock-mode` is used to enforce S3 Object Lock governance mode, which prevents object deletion or overwrite, and has nothing to do with encryption at rest.

24
MCQeasy

A developer needs to allow an Amazon EC2 instance to send messages to an Amazon SQS queue. What is the most secure way to grant this access?

A.Create a bucket policy on S3 to allow EC2 to access SQS
B.Use a resource-based policy on the SQS queue allowing the EC2 instance's security group
C.Assign an IAM role to the EC2 instance with permissions to send messages to SQS
D.Create an IAM user and store the credentials in the application configuration file
AnswerC

Assigning an IAM role to the EC2 instance with appropriate SQS permissions is the recommended and most secure approach. When an IAM role is associated with an EC2 instance, applications running on that instance can automatically obtain temporary, frequently rotated security credentials via the instance metadata service. This eliminates the need to hardcode or store long-term credentials, significantly enhancing security and simplifying credential management.

Why this answer

The most secure way to grant an EC2 instance access to SQS is to attach an IAM role to the instance with a policy allowing sqs:SendMessage on the specific queue. IAM roles provide temporary credentials via the instance metadata service (IMDS), eliminating the need to store long-lived access keys on the instance.

Exam trap

DVA-C02 often tests the misconception that security groups or S3 bucket policies can be used as IAM principals — candidates must remember that only IAM identities (users, roles, accounts) can be principals in resource policies.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies apply to S3 resources, not SQS, and cannot grant EC2 permissions to send messages to a queue. Option B is wrong because SQS resource-based policies can reference IAM principals (users, roles, accounts) but cannot reference a security group as a principal; security groups are network constructs, not IAM identities. Option D is wrong because creating an IAM user and embedding credentials in a configuration file exposes long-lived secrets that can be leaked, rotated poorly, and are not automatically rotated — this is an anti-pattern.

25
Drag & Dropmedium

Drag and drop the steps to implement a disaster recovery plan using cross-region replication for S3 in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create buckets, enable versioning, configure replication rule, and set permissions.

26
MCQeasy

A developer needs to grant an IAM user access to list objects in an S3 bucket named 'app-data'. Which IAM policy statement should be used?

A.{"Effect":"Allow","Action":"s3:*","Resource":"*"}
B.{"Effect":"Allow","Action":"s3:ListAllMyBuckets","Resource":"*"}
C.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::app-data"}
D.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::app-data/*"}
AnswerC

This policy correctly grants the `s3:ListBucket` action, which is specifically used to retrieve a list of objects and common prefixes within a designated S3 bucket. The resource ARN `arn:aws:s3:::app-data` precisely targets the `app-data` bucket, ensuring the user can list its contents without gaining broader, unnecessary permissions. This aligns perfectly with the principle of least privilege for the stated requirement.

Why this answer

The s3:ListBucket action is required to list the objects in an S3 bucket, and the resource ARN must specify the bucket itself (arn:aws:s3:::app-data) without a trailing /*. This grants permission to list the contents of the 'app-data' bucket, which is the exact requirement.

Exam trap

The trap here is that candidates often confuse s3:ListBucket (bucket-level action) with s3:GetObject (object-level action) or incorrectly apply the resource ARN with a trailing '/*' for bucket-level permissions.

How to eliminate wrong answers

Option A is wrong because it grants full administrative access to all S3 actions on all resources, which violates the principle of least privilege and is overly permissive for the specific task of listing objects. Option B is wrong because s3:ListAllMyBuckets lists all buckets in the account, not the objects within a specific bucket, and the resource '*' does not restrict to 'app-data'. Option D is wrong because s3:GetObject is used to retrieve an object's data, not to list objects; additionally, the resource ARN includes a trailing '/*' which refers to objects within the bucket, not the bucket itself.

27
MCQhard

A developer is storing an API secret for a third-party service in AWS Secrets Manager. The secret needs to be accessed by an AWS Lambda function that runs in a VPC. The Lambda function must have the minimum required permissions. Which IAM policy statement should the developer attach to the Lambda execution role?

A.A policy that grants secretsmanager:GetSecretValue for the specific secret ARN and includes a condition for aws:SourceVpce to restrict access to the VPC endpoint
B.A policy that grants secretsmanager:GetSecretValue for all secrets in the account
C.A policy that grants secretsmanager:GetSecretValue for the secret and includes a condition for aws:SourceIp
D.A policy that grants secretsmanager:GetSecretValue for the secret and includes a condition for ec2:Vpc
AnswerA

This policy correctly implements the principle of least privilege by granting access only to the specific secret identified by its Amazon Resource Name (ARN). Furthermore, the `aws:SourceVpce` condition key ensures that requests to retrieve the secret value must originate from the specified VPC endpoint, providing a critical layer of network-level security. This prevents unauthorized access attempts from outside the designated private network path, enhancing the overall security posture for confidential data.

Why this answer

It grants the minimum required permission (secretsmanager:GetSecretValue) scoped to the specific secret ARN, and uses the aws:SourceVpce condition key to restrict access to the VPC endpoint used by the Lambda function. This ensures that only requests originating from the specified VPC endpoint can retrieve the secret, aligning with the principle of least privilege and the requirement that the Lambda function runs in a VPC.

Exam trap

The trap here is that candidates often confuse aws:SourceIp with VPC-based access control, not realizing that Lambda functions in a VPC use private IPs and require VPC endpoint conditions (aws:SourceVpce or aws:SourceVpc) instead of IP-based conditions.

How to eliminate wrong answers

Option B is wrong because it grants secretsmanager:GetSecretValue for all secrets in the account, which violates the principle of least privilege by allowing access to secrets beyond the intended one. Option C is wrong because aws:SourceIp is not effective for Lambda functions in a VPC, as they use private IP addresses from the VPC subnet, and the condition would not match the source IP seen by Secrets Manager (which is the VPC endpoint's private IP). Option D is wrong because ec2:Vpc is not a valid condition key for Secrets Manager; the correct condition key for VPC endpoint restrictions is aws:SourceVpce, not ec2:Vpc.

28
Multi-Selectmedium

A developer is creating an IAM policy to allow access to an Amazon DynamoDB table. The policy must allow the user to read and write items, but not to delete the table or modify its schema. Which TWO DynamoDB actions should be included in the policy?

Select 2 answers
A.UpdateTable
B.Scan
C.GetItem
D.DeleteTable
E.PutItem
AnswersC, E

The GetItem action is a fundamental data plane operation in DynamoDB, specifically designed to retrieve a single item from a table. It requires the full primary key (partition key and sort key, if applicable) to uniquely identify and fetch the desired data record, making it the precise action for reading individual items.

Why this answer

GetItem and PutItem are the actions for reading and writing individual items. DeleteTable and UpdateTable are administrative actions that should not be allowed.

29
MCQeasy

A developer needs to grant least-privilege access to a Lambda function to write logs to CloudWatch Logs. Which IAM policy effect should be used?

A.Always allow
B.Allow
C.Deny
D.Revoke
AnswerB

Allow is the correct IAM policy effect for least-privilege access because it explicitly grants only the specific actions listed, such as logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, scoped to the exact CloudWatch Logs resource ARNs the Lambda function needs, without granting any broader access.

Why this answer

IAM policies use the Effect element with valid values of Allow or Deny; to grant least-privilege access, the policy statement must specify Effect: Allow with the specific action logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents scoped to the function's log group. Allow is the only effect that grants permissions in an identity-based policy. Deny would explicitly block the action, which is the opposite of the requirement.

Exam trap

DVA-C02 often tests IAM policy syntax basics, and the trap is that candidates overthink the question and look for a special effect, when the only valid granting effect is Allow.

How to eliminate wrong answers

Option A is wrong because 'Always allow' is not a valid IAM policy effect value; IAM only accepts Allow or Deny. Option C is wrong because Deny explicitly blocks the action and would prevent the Lambda function from writing logs, contradicting the least-privilege grant requirement. Option D is wrong because 'Revoke' is not a valid IAM policy effect and does not exist in IAM policy syntax.

30
MCQmedium

A company is using AWS CodeCommit for source control. Developers need to access the repository from their local machines. Which authentication method is recommended for secure access?

A.Use IAM user name and password for Git credentials.
B.Use IAM access key and secret key for authentication.
C.Use Amazon Cognito user pools for authentication.
D.Generate and use SSH keys paired with an IAM user.
AnswerD

Generating an SSH key pair and associating the public key with an IAM user is a secure and widely recommended method for authenticating Git operations with AWS CodeCommit. The private key resides on the developer's local machine, and CodeCommit uses the registered public key to verify the developer's identity during Git push/pull operations, ensuring secure access without exposing long-lived credentials. This method leverages standard Git SSH protocols.

Why this answer

SSH keys provide secure access without storing credentials on the machine and can be paired with an IAM user for CodeCommit. Option A is wrong because IAM user password is for console access, not Git. Option B is wrong because while access keys can be used for Git credentials, they are long-term credentials and less secure than SSH keys.

Option C is wrong because Cognito is for end-user authentication, not developer access to CodeCommit.

31
Multi-Selecthard

Which THREE are best practices for managing IAM users and roles? (Choose three.)

Select 3 answers
A.Rotate IAM user access keys periodically.
B.Grant least privilege permissions.
C.Use IAM roles for EC2 instances instead of storing access keys.
D.Use the root account for daily administrative tasks.
E.Assign full administrator access to all users.
AnswersA, B, C

IAM user access keys are long-term credentials that remain valid until explicitly deactivated or deleted. Periodic rotation—for example, via an automated script or the AWS Console—shrinks the exploit window should a key leak into source code or logs. AWS provides 'last used' information to help identify and prune stale keys, and rotating keys is a fundamental part of any credential management policy.

Why this answer

Option A is correct because periodically rotating IAM user access keys limits the window of exposure if a key is compromised, and AWS best practices recommend key rotation (for example, via the IAM console or aws iam create-access-key/update-access-key/delete-access-key). Option B is correct because granting least privilege means attaching only the minimal IAM policies and permissions required for a principal's task, reducing the blast radius of accidental or malicious actions. Option C is correct because EC2 instances should assume an IAM role through instance profiles and the Instance Metadata Service (IMDS) to obtain temporary credentials via AWS STS, eliminating long-lived access keys stored on the instance.

Option D is not correct because the root account should be used only for a few account-level tasks, protected with MFA, and never for daily administration. Option E is not correct because assigning full administrator access to all users violates least privilege and dramatically increases security risk.

Exam trap

DVA-C02 often tests the misconception that root account usage or broad admin access is acceptable for convenience, when AWS best practice strictly prohibits both.

32
MCQhard

A company uses AWS Organizations with multiple accounts. A developer needs to grant an IAM user in Account A (111111111111) read-only access to an S3 bucket in Account B (222222222222). The bucket is encrypted with SSE-S3. Which combination of policies is required for cross-account access?

A.Bucket policy in Account B granting s3:GetObject to the IAM user ARN, and an IAM policy in Account A allowing s3:GetObject.
B.Bucket policy in Account B granting s3:GetObject to Account A's root user ARN, and an IAM policy in Account A allowing s3:GetObject.
C.Bucket policy in Account B granting s3:GetObject to the IAM user ARN, and no IAM policy in Account A is needed.
D.IAM policy in Account A allowing s3:GetObject, and an S3 Access Point in Account B configured for cross-account access.
AnswerA

This combination correctly implements cross-account S3 access using the standard two-policy model. The bucket policy in Account B explicitly grants the `s3:GetObject` permission to the specific IAM user's ARN in Account A, acting as the resource-based policy. Concurrently, the IAM policy attached to the user in Account A allows that user to perform the `s3:GetObject` action, serving as the identity-based policy. Both policies must explicitly permit the action for access to be granted successfully.

Why this answer

Cross-account S3 access requires both a bucket policy in the resource account (Account B) that explicitly grants the IAM user ARN from Account A the s3:GetObject permission, and an IAM policy in the user's account (Account A) that allows the same action. The bucket policy acts as a resource-based policy that authorizes the cross-account principal, while the IAM policy is necessary to authorize the user to make the request. SSE-S3 encryption does not require additional configuration because S3 handles decryption automatically for authorized users.

Exam trap

The trap here is that candidates often think only a bucket policy is needed for cross-account access, forgetting that the IAM user must also have an explicit allow in their own account's IAM policy to actually invoke the S3 API call.

How to eliminate wrong answers

Option B is wrong because granting access to Account A's root user ARN would allow any principal in Account A to assume root-level permissions, which is overly broad and not a best practice; the correct approach is to grant access to the specific IAM user ARN. Option C is wrong because without an IAM policy in Account A allowing s3:GetObject, the IAM user lacks the necessary permissions to initiate the request, even if the bucket policy grants access; both policies are required for cross-account access. Option D is wrong because an S3 Access Point in Account B can simplify cross-account access but still requires a bucket policy that grants access to the Access Point, and the IAM user in Account A still needs an IAM policy allowing s3:GetObject; the Access Point alone does not eliminate the need for both policies.

33
MCQhard

A company has an S3 bucket configured with server-side encryption using AWS KMS (SSE-KMS). An application running on EC2 with an appropriate IAM role is unable to write objects to the bucket. The error message indicates an access denied error. Which additional permission is most likely required?

A.kms:GenerateDataKey
B.kms:Decrypt
C.kms:Encrypt
D.kms:ReEncrypt
AnswerA

When an object is written to a bucket using SSE-KMS, S3 internally calls KMS on the caller's behalf to generate a unique data encryption key for that object, so the IAM principal performing the PutObject must be granted kms:GenerateDataKey on the KMS key; without it, S3 cannot obtain the key material needed to encrypt the object and the write fails with access denied.

Why this answer

When writing an object to an S3 bucket encrypted with SSE-KMS, S3 must call KMS GenerateDataKey to obtain a data key for envelope encryption, so the writer needs kms:GenerateDataKey on the KMS key. Without it, the PutObject call fails with AccessDenied even if s3:PutObject is granted.

Exam trap

DVA-C02 often tests the envelope encryption workflow, baiting candidates into choosing kms:Encrypt when the actual KMS action S3 invokes for SSE-KMS writes is kms:GenerateDataKey.

How to eliminate wrong answers

Option B is wrong because kms:Decrypt is required for reading objects, not writing them; the error occurs on write, so Decrypt is not the missing permission. Option C is wrong because kms:Encrypt alone is not what S3 uses for SSE-KMS; S3 uses GenerateDataKey to create a data key and then encrypts the object with it, so Encrypt is not the correct action. Option D is wrong because kms:ReEncrypt is used when changing encryption keys or re-encrypting existing ciphertext, not for initial object uploads.

34
MCQeasy

Which AWS service provides a managed, rotating secret store for database credentials?

A.AWS Secrets Manager
B.AWS KMS
C.AWS IAM Roles
D.AWS Systems Manager Parameter Store
AnswerA

AWS Secrets Manager is a dedicated, managed service designed for securely storing, managing, and automatically rotating database credentials, API keys, and other secrets throughout their lifecycle. It provides built-in, configurable rotation for supported AWS services like RDS, Redshift, and DocumentDB, as well as custom rotation logic via AWS Lambda functions. This automatic rotation capability significantly enhances security by regularly changing credentials, minimizing the impact of compromised secrets.

Why this answer

AWS Secrets Manager is the correct service because it is specifically designed to manage the entire lifecycle of secrets, including automatic rotation of database credentials on a configurable schedule (e.g., every 30 days). It natively integrates with Amazon RDS, Aurora, Redshift, and DocumentDB to rotate credentials without application downtime, using a built-in Lambda rotation function. This makes it the only fully managed, rotating secret store among the options.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store (which can store secrets) with Secrets Manager, but Parameter Store lacks native automatic rotation, making Secrets Manager the only correct answer for a managed rotating secret store.

How to eliminate wrong answers

Option B (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys, not a secret store; it does not store or rotate database credentials. Option C (AWS IAM Roles) is wrong because IAM roles provide temporary credentials for AWS service access via the AWS STS, but they are not a secret store and cannot store or rotate static database passwords. Option D (AWS Systems Manager Parameter Store) is wrong because while it can store secrets as SecureString parameters, it does not provide native automatic rotation of database credentials; rotation must be implemented manually or via custom automation.

35
Multi-Selecthard

A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which THREE steps should be taken?

Select 3 answers
A.Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.
B.Grant all IAM users decrypt permission and rely on S3 bucket policies.
C.Create an IAM policy that grants kms:Decrypt only to the specific roles.
D.Create a customer-managed customer master key (CMK) in KMS.
E.Use separate CMKs for each IAM role to isolate access.
AnswersA, C, D

A KMS key policy is the primary access control mechanism for a CMK, defining who can use the key and under what conditions. By adding a "Condition" block to the key policy, you can specify that the "kms:Decrypt" action is only allowed when the "aws:PrincipalArn" matches the ARNs of the desired IAM roles. This ensures that even if an IAM user or role has "kms:Decrypt" permission via an IAM policy, the key policy will deny access unless the principal is one of the explicitly allowed roles. This provides a robust, centralized control over key usage.

Why this answer

Key policies in AWS KMS are resource-based policies that directly control access to the CMK. By adding a condition that restricts the `kms:Decrypt` action to only specific IAM roles (using the `aws:PrincipalArn` or `kms:CallerPrincipal` condition key), the security team can ensure that only those roles can decrypt data encrypted with that key. This approach is more secure than relying solely on IAM policies, as key policies are evaluated first and can explicitly deny access even if an IAM policy grants it.

Exam trap

The trap here is that candidates often think IAM policies alone are sufficient for KMS access control, but they forget that KMS key policies are the primary mechanism and must explicitly allow IAM policies to take effect; otherwise, even if an IAM policy grants `kms:Decrypt`, the key policy will deny the request.

36
MCQmedium

A company stores sensitive data in Amazon S3. The security team requires that all objects are encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). The developer needs to enforce that any PutObject request that does not specify the 'x-amz-server-side-encryption' header with value 'aws:kms' is denied. Which S3 bucket policy condition should be used?

A.s3:x-amz-server-side-encryption equals 'aws:kms'
B.s3:x-amz-server-side-encryption-aws-kms-key-id equals the KMS key ARN
C.s3:x-amz-acl equals 'bucket-owner-full-control'
D.s3:signatureversion equals 'AWS4-HMAC-SHA256'
AnswerA

This condition directly checks for the presence and specific value of the `x-amz-server-side-encryption` request header. When set to `aws:kms`, it mandates that Amazon S3 encrypts the object using Server-Side Encryption with AWS KMS (SSE-KMS) during the upload operation. This is the fundamental policy condition to enforce SSE-KMS for all new objects uploaded to the bucket, ensuring data is encrypted at rest using a customer-managed key or AWS-managed key within KMS.

Why this answer

The condition key `s3:x-amz-server-side-encryption` in an S3 bucket policy can be used to require that the `x-amz-server-side-encryption` header is set to `aws:kms` on every PutObject request. This enforces server-side encryption with AWS KMS (SSE-KMS) at the bucket policy level, denying any request that omits or uses a different encryption header value.

Exam trap

The trap here is that candidates often confuse the condition key for the encryption header (`s3:x-amz-server-side-encryption`) with the condition key for the KMS key ID (`s3:x-amz-server-side-encryption-aws-kms-key-id`), mistakenly choosing Option B to enforce SSE-KMS instead of the correct header-based condition.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` checks for a specific KMS key ARN, not the encryption header value; it would allow requests with any SSE-KMS key but does not enforce the header itself. Option C is wrong because `s3:x-amz-acl` controls access control lists (ACLs), not encryption requirements; it is unrelated to server-side encryption enforcement. Option D is wrong because `s3:signatureversion` checks the signature version used in the request (e.g., AWS Signature Version 4), which is about request authentication, not encryption headers.

37
MCQhard

A company wants to audit all API calls made to AWS. Which service should be used to collect and store these logs?

A.VPC Flow Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the primary service for auditing and monitoring all API calls made to your AWS account, whether through the AWS Management Console, AWS SDKs, command-line tools, or other AWS services. It records management events, such as creating or deleting resources, and can also capture data events for services like S3 and Lambda. CloudTrail logs provide crucial details including the identity of the caller, the time of the call, the source IP address, and the specific API operation performed, making it indispensable for security analysis, compliance, and operational troubleshooting.

Why this answer

AWS CloudTrail records all API calls and can store logs in S3. Option A (VPC Flow Logs) captures network traffic, not API calls. Option B (AWS Config) records resource configuration changes, not API calls.

Option D (Amazon CloudWatch Logs) can store logs but is not the primary service for API auditing.

38
Multi-Selecthard

Which TWO security best practices should be applied when using AWS Lambda? (Choose TWO.)

Select 2 answers
A.Attach an IAM execution role with least privilege permissions.
B.Enable CloudWatch Logs for the Lambda function.
C.Hardcode database credentials in the function code.
D.Store sensitive data in Lambda environment variables.
E.Use AWS Secrets Manager to retrieve secrets at runtime.
AnswersA, E

An IAM execution role defines the permissions that the Lambda function assumes when it executes. Applying the principle of least privilege means granting only the specific permissions required for the function to perform its intended tasks, such as reading from an S3 bucket or writing to a DynamoDB table, and nothing more. This significantly reduces the potential blast radius if the function is compromised, as an attacker would only gain access to the limited set of authorized actions.

Why this answer

Option A is correct because every Lambda function assumes an IAM execution role to call other AWS services, and granting only the specific actions and resources the function needs (least privilege) limits the blast radius if the function is compromised or misused. Option E is correct because AWS Secrets Manager stores credentials and other secrets encrypted and lets the function retrieve them at runtime via the AWS SDK, so secrets are not embedded in code or configuration and can be rotated automatically. Option B is not a security best practice in this context; CloudWatch Logs is primarily for observability and monitoring, and logging sensitive data can even increase exposure.

Option C is wrong because hardcoding database credentials in function code exposes secrets in source control, deployment packages, and logs. Option D is wrong because Lambda environment variables are not a secure secret store—they are visible in the function configuration and can be exposed through console access, APIs, or misconfigured permissions.

Exam trap

Candidates often confuse operational best practices (like enabling CloudWatch Logs) with security best practices, or they mistakenly believe that environment variables are a safe place to store secrets because they are not visible in the function code itself. However, environment variables are visible to anyone with access to view the Lambda configuration, making AWS Secrets Manager the secure choice.

39
Multi-Selecteasy

A developer wants to ensure that an S3 bucket is not publicly accessible. Which TWO measures should the developer implement?

Select 2 answers
A.Enable S3 server access logging.
B.Enable versioning on the bucket.
C.Enable default encryption on the bucket.
D.Review the bucket policy to ensure it does not allow public access.
E.Enable S3 Block Public Access settings on the bucket.
AnswersD, E

Reviewing the bucket policy is a direct and necessary step because a bucket policy with a Principal of '*' and actions such as s3:GetObject or s3:ListBucket grants public read access to everyone. Even if the bucket ACLs and other settings appear restrictive, such a policy statement can make all objects publicly accessible. By auditing and removing any statement that grants access to 'Principal: *' or does not restrict access to specific AWS accounts, the developer can confirm that the bucket no longer publicly exposes objects. This complements Block Public Access, which provides a defensive override, but the policy itself is the actual source of public access.

Why this answer

Option D is correct because the bucket policy is the resource-based policy that can explicitly grant public access (for example, a Principal of "*" with s3:GetObject), so reviewing it to confirm it does not allow public access is a direct way to prevent the bucket from being publicly accessible. Option E is correct because S3 Block Public Access settings, when enabled on the bucket, override any bucket policy or ACL that would otherwise make objects public, providing a strong account- or bucket-level safeguard against public exposure. Option A is incorrect because S3 server access logging only records requests made to the bucket for auditing purposes; it does not restrict or prevent public access.

Option B is incorrect because versioning preserves multiple versions of objects for recovery and rollback, but it has no effect on whether the bucket or its objects are publicly accessible. Option C is incorrect because default encryption protects data at rest but does not control who can access the objects, so it does not prevent public accessibility.

Exam trap

DVA-C02 often tests the misconception that encryption or versioning prevents public access, when only Block Public Access and policy review actually restrict it.

40
Multi-Selecteasy

Which THREE practices help protect data at rest in Amazon S3?

Select 3 answers
A.Enable versioning.
B.Enable MFA Delete.
C.Enable server-side encryption for the bucket.
D.Enable cross-region replication.
E.Use bucket policies to deny uploads without encryption headers.
AnswersB, C, E

MFA Delete provides a critical layer of security by requiring multi-factor authentication for two highly sensitive operations: permanently deleting an object version or changing the versioning state of a bucket. This mechanism significantly reduces the risk of accidental or malicious data loss, as an attacker would need both the AWS account credentials and physical access to the MFA device to perform these actions. By preventing unauthorized permanent deletion, MFA Delete protects the integrity and continued existence of data at rest.

Why this answer

MFA Delete (B) is correct because it requires multi-factor authentication to permanently delete object versions or change the versioning state of the bucket, protecting stored data from unauthorized deletion or tampering. Server-side encryption (C) is correct because SSE-S3, SSE-KMS, or SSE-C encrypts objects at rest within S3, rendering the stored data unreadable without the appropriate keys. Bucket policies that deny uploads without encryption headers (E) are correct because they enforce encryption at write time, ensuring objects cannot be stored unencrypted in the bucket.

Versioning (A) only preserves object versions and aids recovery; it does not itself encrypt or otherwise protect data at rest. Cross-region replication (D) copies objects to another region for durability and availability, but it does not protect the data at rest from unauthorized access.

Exam trap

The trap here is that candidates often confuse versioning (which provides data protection through object recovery) with data-at-rest security (which requires encryption or access controls like MFA Delete), leading them to select versioning as a valid practice for protecting data at rest.

41
MCQhard

A developer is using an S3 bucket to store sensitive files. The bucket policy includes a condition that requires TLS for all requests. A user reports that they can access the bucket via the AWS Management Console but not via an application using HTTP. What is the likely issue?

A.The application is using an expired IAM access key.
B.The bucket policy denies HTTP requests via aws:SecureTransport condition.
C.The S3 bucket is in a different region.
D.The application is not signing requests with Signature Version 4.
AnswerB

A bucket policy with an aws:SecureTransport condition set to false explicitly denies any request that is not sent over HTTPS. The AWS Management Console always uses the HTTPS protocol, so requests from the console satisfy the condition and succeed. However, the application is sending plain HTTP requests, which fail the condition and receive a 403 Access Denied, exactly matching the reported behavior.

Why this answer

The condition aws:SecureTransport requires HTTPS; the application uses HTTP, which violates the policy.

42
Multi-Selectmedium

A company is implementing a CI/CD pipeline using AWS CodePipeline and CodeBuild. The pipeline deploys a serverless application. Which TWO actions should be taken to securely manage the database credentials used by the application?

Select 2 answers
A.Embed the credentials in the Lambda function code.
B.Store the credentials in the buildspec.yml file in the CodeCommit repository.
C.Pass the credentials as CloudFormation parameters during deployment.
D.Use AWS Lambda environment variables with encryption using a KMS key.
E.Use AWS Secrets Manager to store the credentials and retrieve them in CodeBuild using an IAM role.
AnswersD, E

Storing sensitive information as AWS Lambda environment variables, encrypted with an AWS Key Management Service (KMS) key, is a secure and recommended practice. Lambda automatically encrypts these variables at rest using the specified KMS key and decrypts them at runtime when the function is invoked. This method prevents credentials from being exposed in plain text within the code or configuration, enhancing security and simplifying secret rotation.

Why this answer

AWS Lambda environment variables can be encrypted at rest using a KMS key, providing a secure way to store sensitive data like database credentials without hardcoding them in the function code. This approach ensures that the credentials are decrypted only when the Lambda function executes, and access to the KMS key can be controlled via IAM policies. Option E is also correct because AWS Secrets Manager is a dedicated service for managing secrets throughout their lifecycle, and CodeBuild can retrieve them securely using an IAM role with appropriate permissions, eliminating the need to store secrets in code or configuration files.

Exam trap

The trap here is that candidates may think CloudFormation parameters (Option C) are secure because they are not hardcoded, but they overlook that parameters can be exposed in plaintext in stack outputs, events, and parameter store, and they lack built-in encryption and rotation capabilities compared to Secrets Manager.

43
MCQmedium

Refer to the exhibit. An IAM policy is attached to a user. The user reports that they can access objects in the S3 bucket from their office IP address (192.0.2.15) but cannot access from home (203.0.113.5). What is the most likely reason?

A.The policy requires requests to originate from a VPC.
B.The bucket policy does not allow the user.
C.The policy restricts access based on source IP address.
D.The policy denies all s3:GetObject actions.
AnswerC

The policy includes an aws:SourceIp condition scoped to the office IP range (192.0.2.15), so any request originating from a different address, such as the home IP 203.0.113.5, fails the condition evaluation and the Allow statement does not apply, resulting in implicit denial of the request from home.

Why this answer

The correct option is C: the policy restricts access based on source IP address. Since the user can access the S3 bucket from the office IP 192.0.2.15 but not from the home IP 203.0.113.5, the IAM policy most likely includes a Condition element using aws:SourceIp (or NotIpAddress) that allows only the office IP range. Options A, B, and D do not fit: a VPC requirement would not explain why the office IP works, a bucket policy denying the user would block both locations, and a blanket Deny on s3:GetObject would also block access from the office.

44
MCQmedium

A developer is designing a serverless application using API Gateway, Lambda, and DynamoDB. The API must authenticate users using a JWT token. Which API Gateway feature should the developer use to validate the JWT before invoking the Lambda function?

A.Use an IAM authorizer with a resource policy.
B.Use an Amazon Cognito user pool authorizer.
C.Use a Lambda authorizer (custom authorizer).
D.Use an API Gateway resource policy to allow only authenticated IPs.
AnswerC

A Lambda authorizer, also known as a custom authorizer, offers the flexibility to implement bespoke authentication and authorization logic using an AWS Lambda function. This function receives the incoming request's authorization token, such as a custom JWT, and can perform any necessary validation, including signature verification, expiration checks, and claim validation against an issuer's public key or custom business rules. If the token is valid, the Lambda function returns an IAM policy allowing access to the API Gateway resources, making it ideal for validating custom JWTs from any identity provider.

Why this answer

A Lambda authorizer (custom authorizer) is required to validate JWTs issued by a third-party identity provider (IdP) in API Gateway REST APIs. While Amazon Cognito user pool authorizers can natively validate Cognito-issued JWTs, they cannot validate tokens from external providers. A Lambda authorizer allows you to run custom code to verify the signature, expiration, and claims of any third-party JWT before routing the request to the backend Lambda function.

Exam trap

The exam often tests your ability to choose between a Cognito authorizer and a Lambda authorizer. Remember: if the JWT is from Cognito, use the Cognito user pool authorizer (no custom code needed). If the JWT is from a third-party IdP (like Auth0, Okta, or a custom server), you must use a Lambda authorizer (for REST APIs) or a JWT authorizer (for HTTP APIs).

How to eliminate wrong answers

Option A is wrong because an IAM authorizer with a resource policy authenticates requests using AWS Signature Version 4, not JWT tokens, and is designed for AWS service-to-service or IAM user access, not for validating third-party JWTs. Option B is wrong because an Amazon Cognito user pool authorizer is a managed solution that validates JWTs issued only by a Cognito user pool; it cannot validate JWTs from other identity providers, which is the requirement in this scenario. Option D is wrong because an API Gateway resource policy controls access based on source IP addresses or AWS accounts, not on JWT token validation, and does not authenticate individual users.

45
Multi-Selectmedium

A company is using AWS Lambda functions that access an RDS database. Which THREE practices should be followed to secure the database credentials?

Select 3 answers
A.Use AWS Secrets Manager to store and automatically rotate the credentials.
B.Use a security group to decrypt the credentials.
C.Encrypt the credentials using AWS KMS and pass them as encrypted environment variables to Lambda.
D.Store the credentials in the Lambda function code.
E.Place the Lambda function inside a VPC and use a security group to allow access to RDS.
AnswersA, C, E

AWS Secrets Manager is a dedicated service designed for securely storing, managing, and automatically rotating credentials, API keys, and other secrets. By integrating with Secrets Manager, Lambda functions can retrieve the latest database credentials at runtime using an IAM role, eliminating the need to hardcode or embed them. This approach enhances security by centralizing secret management and enforcing regular credential rotation, significantly reducing the risk of compromise.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built to store database credentials securely and can automatically rotate RDS credentials on a schedule using a Lambda rotation function, eliminating hard-coded or long-lived secrets. Option C is correct because Lambda environment variables can be encrypted at rest with an AWS KMS customer managed key, so credentials are not stored in plaintext and the function decrypts them at runtime using its execution role permissions. Option E is correct because placing the Lambda function in the same VPC as the RDS instance and using a security group to permit traffic only to the database port (e.g., 3306 for MySQL or 5432 for PostgreSQL) restricts network access to the database.

Option B is incorrect because security groups are stateful virtual firewalls that filter network traffic; they do not decrypt credentials. Option D is incorrect because embedding credentials in Lambda function code exposes them in source control, deployment packages, and logs, which is an insecure anti-pattern.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with cryptographic operations, or assume that encrypting environment variables with KMS is sufficient, overlooking that Secrets Manager provides rotation and centralized audit capabilities that KMS alone does not.

46
MCQhard

A developer is using AWS KMS to encrypt data in an S3 bucket. The developer wants to ensure that the S3 bucket uses server-side encryption with AWS KMS managed keys (SSE-KMS) by default. Which configuration should be applied?

A.Add a bucket policy that denies PutObject without the 'x-amz-server-side-encryption' header set to 'aws:kms'.
B.Configure the bucket to use SSE-C with a customer-provided key.
C.Set the bucket's default encryption to SSE-S3.
D.Set the bucket's default encryption to SSE-KMS with a KMS key.
AnswerD

Configuring the S3 bucket's default encryption to SSE-KMS with a specified AWS KMS key ensures that all new objects uploaded to the bucket are automatically encrypted using that KMS key. This method directly leverages AWS KMS for key management, providing centralized control, auditability through CloudTrail, and integration with IAM policies, precisely meeting the requirement to use AWS KMS for data encryption.

Why this answer

Setting the bucket's default encryption to SSE-KMS with a KMS key ensures that all objects uploaded to the S3 bucket are automatically encrypted using server-side encryption with AWS KMS managed keys (SSE-KMS). This configuration enforces encryption at rest without requiring the client to specify encryption headers in the request, meeting the requirement for default SSE-KMS encryption.

Exam trap

The trap here is that candidates often confuse enforcing encryption via a bucket policy (Option A) with setting a default encryption configuration, but the policy only denies non-compliant requests without establishing a default, whereas the default encryption setting automatically applies encryption to all objects regardless of request headers.

How to eliminate wrong answers

Option A is wrong because a bucket policy that denies PutObject without the 'x-amz-server-side-encryption' header set to 'aws:kms' enforces encryption on a per-request basis but does not set a default encryption configuration for the bucket; it only rejects requests that lack the header, leaving the bucket without a default encryption setting. Option B is wrong because SSE-C uses a customer-provided key, not an AWS KMS managed key, and is not the SSE-KMS method specified in the requirement. Option C is wrong because SSE-S3 uses Amazon S3 managed keys, not AWS KMS managed keys, and thus does not fulfill the requirement for SSE-KMS.

47
MCQmedium

A developer is deploying a web application on Amazon ECS with a Fargate launch type. The application needs to securely access an Amazon DynamoDB table. How should the developer grant permissions?

A.Store AWS credentials in the container image
B.Define a task role for the ECS task with DynamoDB permissions
C.Assign an IAM role to the ECS service and use it from the container
D.Use an EC2 instance profile and mount it to the container
AnswerB

Defining an IAM task role for an Amazon ECS task is the recommended and most secure method for granting AWS permissions to applications running within containers. When a task starts, it assumes this specified IAM role, which then provides temporary, frequently rotated credentials to the container's processes. This mechanism ensures that the application can securely interact with AWS services like DynamoDB without needing to store any long-lived credentials directly, adhering to the principle of least privilege and significantly enhancing security posture.

Why this answer

The developer should define a task role for the ECS task with DynamoDB permissions. In ECS with Fargate, the task role is an IAM role that containers can assume to make AWS API calls. This provides secure, temporary credentials without embedding secrets in the container image.

Exam trap

DVA-C02 often tests the distinction between task execution roles and task roles, and candidates may confuse the two or assume that EC2 instance profiles work for Fargate.

How to eliminate wrong answers

Option A is wrong because storing AWS credentials in the container image is insecure and not recommended; credentials can be exposed if the image is compromised. Option C is wrong because assigning an IAM role to the ECS service is not how containers get permissions; the service role is used by ECS itself, not by the application code. Option D is wrong because EC2 instance profiles are for EC2 instances, not for Fargate tasks; Fargate tasks do not have access to instance metadata.

48
MCQmedium

A company has an S3 bucket containing confidential data. The security team wants to ensure that the bucket is never publicly accessible, even if a bucket policy or ACL is incorrectly set to allow public access. Which S3 feature should the developer enable?

A.Enable S3 Transfer Acceleration to ensure faster uploads.
B.Enable S3 Block Public Access (bucket-level).
C.Enable S3 Server Access Logging to monitor access.
D.Enable S3 Object Lock to prevent objects from being deleted.
AnswerB

S3 Block Public Access provides an additional layer of security that prevents any public access, even if a bucket policy or ACL inadvertently allows it. It is the recommended way to ensure a bucket is never public.

Why this answer

S3 Block Public Access (bucket-level) provides a definitive override that prevents any public access to the bucket, regardless of any bucket policies or ACLs that might otherwise grant public access. This feature acts as a safety net, ensuring that even if a policy or ACL is misconfigured to allow public access, the block public access settings will deny all public requests at the S3 service level before any policy evaluation occurs.

Exam trap

The trap here is that candidates often confuse monitoring features (like logging) or object protection features (like Object Lock) with access control mechanisms, failing to recognize that S3 Block Public Access is the only feature specifically designed to enforce a hard block on public access regardless of other configurations.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances using AWS edge locations, and it has no impact on access control or public accessibility. Option C is wrong because S3 Server Access Logging only records access requests for auditing purposes; it does not prevent public access or enforce any security restrictions. Option D is wrong because S3 Object Lock is designed to prevent objects from being deleted or overwritten for a specified retention period, but it does not control or block public read access to the bucket.

49
Multi-Selectmedium

A developer wants to encrypt data in an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). Which TWO steps are required?

Select 2 answers
A.Set the default encryption on the bucket to SSE-KMS.
B.Enable MFA Delete on the bucket.
C.Create a bucket policy that denies unencrypted requests.
D.Grant the IAM role kms:GenerateDataKey and kms:Decrypt permissions.
E.Enable versioning on the bucket.
AnswersA, D

Setting default encryption on the S3 bucket to SSE-KMS is the direct and required control because it instructs S3 to automatically apply KMS-based encryption to every new object written to the bucket, regardless of whether the upload request includes encryption headers. This setting meets the requirement without forcing changes to the application code, and it ensures that any object uploaded without explicit encryption is still encrypted at rest.

Why this answer

Option A is correct because configuring the bucket's default encryption to SSE-KMS ensures that objects uploaded without an explicit encryption header are automatically encrypted with AWS KMS keys (aws:kms), which is the core requirement for using SSE-KMS at the bucket level. Option D is correct because any principal writing or reading SSE-KMS-encrypted objects must have kms:GenerateDataKey (to obtain a data key for encryption) and kms:Decrypt (to decrypt the data key) permissions on the relevant KMS key; without these, S3 requests fail with AccessDenied. Option B is not required because MFA Delete only protects object version deletion and does not relate to enabling SSE-KMS.

Option C is not required because a deny-unencrypted-requests bucket policy is an optional hardening measure, not a prerequisite for SSE-KMS. Option E is not required because versioning is independent of server-side encryption configuration.

Exam trap

DVA-C02 often tests the misconception that enabling SSE-KMS is purely a bucket setting, when the IAM role also needs explicit KMS permissions (GenerateDataKey and Decrypt) or uploads/downloads will fail.

50
Multi-Selecthard

Which TWO actions should a developer take to securely manage database credentials in a serverless application?

Select 2 answers
A.Store credentials in AWS Secrets Manager and enable automatic rotation.
B.Use IAM database authentication for Amazon RDS.
C.Store credentials in a text file within the Lambda deployment package.
D.Hardcode credentials in environment variables.
E.Use security groups to allow only the Lambda function to access the database.
AnswersA, B

AWS Secrets Manager provides a dedicated, highly secure service for storing, retrieving, and managing sensitive information like database credentials. Enabling automatic rotation ensures that credentials are regularly updated without manual intervention, significantly reducing the risk window if a secret is compromised. This approach aligns with security best practices by centralizing secret management and automating lifecycle operations, enhancing overall application security posture.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built for storing and retrieving secrets such as database credentials, and enabling automatic rotation ensures credentials are periodically changed without manual intervention, reducing the risk of long-lived credential exposure. Option B is correct because IAM database authentication for Amazon RDS lets the Lambda function use its IAM role to generate a short-lived authentication token instead of a static password, eliminating the need to store database credentials at all. Option C is incorrect because embedding credentials in a text file inside the Lambda deployment package exposes them to anyone with access to the code artifact and provides no rotation or auditing.

Option D is incorrect because hardcoding credentials in environment variables leaves them in plaintext and visible in the Lambda configuration, and they cannot be rotated automatically. Option E is incorrect because security groups only control network-level access to the database and do not manage or protect the credentials themselves.

Exam trap

AWS often tests the distinction between network-level controls (security groups) and credential management, leading candidates to mistakenly select security groups as a method for securing credentials rather than managing them.

51
MCQmedium

Refer to the exhibit. A developer ran this CLI command and received the output shown. The application is retrieving the secret but getting an authentication error from the database. What is the MOST likely issue?

A.The secret is not marked as AWSCURRENT.
B.The application is not correctly parsing the JSON SecretString.
C.The CLI command should have used the --secret-string parameter.
D.The secret ID is incorrect.
AnswerB

AWS Secrets Manager typically stores credentials as a JSON string within the `SecretString` field, containing key-value pairs like `{"username":"user", "password":"p@ss"}`. Applications must correctly parse this JSON to extract individual components, such as the password. If the application fails to properly deserialize the JSON or handle special characters within the password value, it might attempt to use the entire unparsed string or an incorrect substring, leading to authentication failures.

Why this answer

The CLI command successfully retrieved the secret, as shown by the output containing the secret value. The application, however, is failing with an authentication error from the database. This indicates that the secret was retrieved but the application is likely misinterpreting the JSON structure of the SecretString.

If the secret is stored as a JSON object (e.g., containing username and password fields), the application must parse the JSON and extract the correct field (e.g., 'password'). If it treats the entire JSON string as the password, it will pass an invalid credential to the database, causing an authentication error.

Exam trap

The trap here is that candidates assume any retrieval error is due to an incorrect secret ID or missing label, but the question explicitly states the secret was retrieved successfully, shifting the issue to how the application processes the retrieved value.

How to eliminate wrong answers

Option A is wrong because the secret is successfully retrieved, and the AWSCURRENT label is automatically applied to the latest version of a secret; if it were missing, the retrieval would fail entirely, not cause a parsing issue. Option C is wrong because the CLI command used 'get-secret-value' which is the correct command to retrieve a secret; the '--secret-string' parameter is used when creating or updating a secret, not when retrieving it. Option D is wrong because the secret ID is correct—the command returned a valid secret value without an error, proving the ID was accurate.

52
MCQmedium

A company wants to enforce multi-factor authentication (MFA) for all users accessing the AWS Management Console. The company has an existing IAM setup with users and groups. Which approach should the developer recommend to enforce MFA?

A.Enable MFA at the account level using the AWS Account settings.
B.Attach an IAM policy to each user that denies all actions unless the user has MFA present.
C.Enable MFA on the root user and require all users to use the root user credentials with MFA.
D.Create a new IAM group for MFA users and add users to that group.
AnswerB

This is the correct and recommended method for enforcing MFA. An IAM policy can include a Condition element, such as "aws:MultiFactorAuthPresent": "true", within a Deny statement for all actions ("Action": "*", "Resource": "*") or within an Allow statement that only permits actions if MFA is present. This policy, when attached to users or groups, effectively prevents them from performing any AWS actions unless they authenticate with MFA, thereby enforcing its use across the account.

Why this answer

It uses an IAM policy with a condition key (`aws:MultiFactorAuthPresent`) to deny all actions when MFA is not present. This is the standard AWS-recommended approach to enforce MFA for IAM users accessing the Management Console, as it applies a deny-all-except-MFA effect at the user level without requiring account-level changes.

Exam trap

The trap here is that candidates assume MFA can be enforced at the account level (Option A) or by simply adding users to a group (Option D), but AWS requires an explicit IAM policy with a condition key to deny unauthenticated MFA actions.

How to eliminate wrong answers

Option A is wrong because AWS does not support enabling MFA at the account level for all users; MFA must be configured per IAM user or via a policy. Option C is wrong because sharing root user credentials violates security best practices and AWS prohibits using root user for everyday tasks; MFA on root does not enforce MFA for other IAM users. Option D is wrong because simply creating a group and adding users does not enforce MFA; a policy with a condition key must be attached to the group to deny actions without MFA.

53
MCQeasy

A developer needs to enforce encryption in transit for all traffic between an application and an RDS database. Which configuration should be used?

A.Configure the security group to only allow traffic on port 443.
B.Create a VPC peering connection between the application and database subnets.
C.Enable encryption at rest using AWS KMS.
D.Set the 'require_secure_transport' parameter to 'ON' in the DB parameter group.
AnswerD

Setting the 'require_secure_transport' parameter to 'ON' within the RDS DB parameter group is the correct method to enforce encryption in transit. This parameter, available for databases like MySQL and PostgreSQL, configures the database server to reject any client connection attempts that do not utilize SSL/TLS. By doing so, it ensures that all successful connections to the RDS instance are encrypted, protecting data as it travels over the network between the application and the database.

Why this answer

Setting the 'require_secure_transport' parameter to 'ON' in the DB parameter group enforces TLS/SSL encryption for all connections to the RDS database. This ensures that data in transit between the application and the database is encrypted, meeting the requirement for encryption in transit.

Exam trap

The trap here is that candidates often confuse encryption at rest (Option C) with encryption in transit, or assume that network-level controls like security groups (Option A) or VPC peering (Option B) inherently encrypt traffic, when they do not.

How to eliminate wrong answers

Option A is wrong because port 443 is used for HTTPS traffic, not for native database connections (e.g., MySQL uses port 3306, PostgreSQL uses 5432), and security groups do not enforce encryption—they only control network access. Option B is wrong because VPC peering connects networks but does not provide encryption for traffic; it only facilitates routing between VPCs without encrypting the data in transit. Option C is wrong because encryption at rest using AWS KMS protects data stored on disk, not data transmitted between the application and the database; it addresses a different security concern.

54
MCQeasy

A company wants to enforce that all uploads to an Amazon S3 bucket must be encrypted using server-side encryption with a specific AWS KMS customer managed key (CMK). The developer needs to write an IAM policy condition that denies any s3:PutObject request that does not use the specified KMS key. Which IAM condition key should be used?

A.s3:x-amz-server-side-encryption
B.kms:EncryptionContext
C.s3:x-amz-server-side-encryption-aws-kms-key-id
D.kms:KeyArn
AnswerC

This is the correct condition key to enforce the use of a specific AWS KMS customer master key (CMK) for server-side encryption on S3 uploads. It directly evaluates the value provided in the x-amz-server-side-encryption-aws-kms-key-id request header during a PutObject operation. By specifying a particular KMS key ARN with this condition, an S3 bucket policy can deny any upload requests that do not include or match the designated CMK.

Why this answer

The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key allows you to enforce that a specific AWS KMS customer managed key (CMK) ARN is used for server-side encryption on S3 PutObject requests. By using this condition key in a Deny statement, you can reject any upload that does not specify the required KMS key ID, ensuring encryption compliance.

Exam trap

The trap here is that candidates confuse the condition key for enforcing encryption type (Option A) with the condition key for enforcing a specific KMS key ID (Option C), or mistakenly think that a KMS-specific condition key like `kms:KeyArn` can be used in an S3 policy, when in fact it only applies to KMS API calls.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption` only checks whether the `x-amz-server-side-encryption` header is set to `AES256` or `aws:kms`, but it cannot enforce a specific KMS key ID. Option B is wrong because `kms:EncryptionContext` is used to control access based on encryption context in KMS operations, not to enforce which KMS key is used for S3 server-side encryption. Option D is wrong because `kms:KeyArn` is a condition key for KMS API actions (like `kms:Decrypt` or `kms:GenerateDataKey`), not for S3 PutObject requests, and it cannot be used directly in an S3 bucket policy to enforce encryption key selection.

55
Multi-Selecthard

Which THREE are valid methods to authenticate to AWS APIs? (Choose 3)

Select 3 answers
A.Temporary security credentials from AWS STS
B.Database password stored in Secrets Manager
C.Credentials from an EC2 instance profile
D.CloudFront key pair
E.IAM user access key ID and secret access key
AnswersA, C, E

Temporary security credentials from AWS STS are a valid authentication method because they provide short-lived access keys plus a session token that are used with Signature Version 4 to sign AWS API calls. These credentials are obtained by calling AssumeRole, GetFederationToken, or related STS APIs, and they are ideal for federated users, cross-account roles, and scenarios requiring limited-time access. The session token is mandatory when signing requests with these credentials.

Why this answer

Option A is correct because AWS STS issues temporary security credentials (access key ID, secret access key, and session token) via APIs like AssumeRole, GetSessionToken, or GetFederationToken, and these credentials are accepted by AWS APIs for signing requests with SigV4. Option C is correct because an EC2 instance profile delivers temporary IAM role credentials to the instance through the Instance Metadata Service (IMDS), which the AWS SDK and CLI automatically use to sign API calls. Option E is correct because a long-term IAM user access key ID and secret access key are the classic SigV4 signing credentials used to authenticate programmatic requests to AWS APIs.

Option B is not a valid AWS API authentication method because a database password in Secrets Manager is a secret for connecting to a database, not an AWS credential, even though Secrets Manager itself is accessed using AWS credentials. Option D is not valid because a CloudFront key pair is used to create signed URLs or signed cookies for private content distribution, not to authenticate requests to AWS service APIs.

Exam trap

DVA-C02 often tests the difference between AWS API authentication and other service-specific credentials; candidates may incorrectly select CloudFront key pairs or database passwords because they are AWS-related, but they do not authenticate to AWS APIs.

56
MCQmedium

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The role's trust policy allows the EC2 service, and the permissions policy grants s3:GetObject on the bucket. The application on the instance receives 'Access Denied' errors when trying to read objects. What is the most likely cause?

A.The IAM role's trust policy does not allow the EC2 service.
B.The S3 bucket has default encryption enabled.
C.The EC2 instance does not have an instance profile associated with the IAM role.
D.The S3 bucket policy explicitly denies s3:GetObject.
AnswerC

An EC2 instance requires an instance profile to assume an IAM role and obtain temporary security credentials. The instance profile acts as a container for the IAM role, allowing the EC2 instance to retrieve these credentials via its metadata service. Without an instance profile explicitly associated with the EC2 instance, the instance lacks the necessary mechanism to assume the designated IAM role, rendering it unable to acquire the permissions required to interact with other AWS services like S3.

Why this answer

The most likely cause is that the EC2 instance does not have an instance profile associated with the IAM role. An IAM role must be attached to an EC2 instance via an instance profile, which acts as a container for the role. Without this association, the instance cannot obtain temporary credentials from the AWS Security Token Service (STS) to sign API requests, resulting in 'Access Denied' errors even if the role's trust and permissions policies are correctly configured.

Exam trap

The trap here is that candidates often assume the IAM role's trust and permissions policies are sufficient, overlooking the mandatory instance profile association required for EC2 to use the role.

How to eliminate wrong answers

Option A is wrong because the trust policy allowing the EC2 service is correctly configured, as stated in the question; if it were not, the role could not be assumed at all, but the error occurs at the S3 access level, not at the role assumption level. Option B is wrong because default encryption on an S3 bucket does not affect IAM permissions for reading objects; it only encrypts objects at rest, and the application would still be able to read objects if it has the correct IAM permissions. Option D is wrong because the question states the permissions policy grants s3:GetObject, and there is no indication of a bucket policy; an explicit deny in a bucket policy would override the IAM role's allow, but the scenario does not mention any bucket policy, making this an unlikely primary cause.

57
MCQeasy

A developer needs to grant a Lambda function read-only access to an S3 bucket. Which IAM entity should be used to attach the permissions?

A.Create an IAM user and provide the credentials to the Lambda function.
B.Attach a resource-based policy to the S3 bucket.
C.Attach a policy to an IAM group and add the Lambda function to the group.
D.Create an IAM role with the necessary permissions and assign it to the Lambda function as the execution role.
AnswerD

This is the correct and AWS-recommended approach for granting permissions to a Lambda function. An IAM role, configured with a trust policy allowing `lambda.amazonaws.com` to assume it, serves as the function's execution role. An attached identity-based permissions policy then explicitly defines the specific actions the Lambda function is authorized to perform, such as `s3:GetObject` for read-only access, ensuring adherence to the principle of least privilege and providing temporary credentials.

Why this answer

Lambda functions require an IAM role (execution role) to obtain temporary AWS credentials via the AWS Security Token Service (STS). This role must have a trust policy allowing Lambda to assume it, and an attached permissions policy granting read-only access to the S3 bucket. This is the standard and secure method for granting permissions to an AWS service like Lambda.

Exam trap

The trap here is that candidates confuse resource-based policies (which grant access to the principal specified in the policy) with identity-based policies (which grant permissions to the principal the policy is attached to), and incorrectly think a bucket policy alone can grant permissions to a Lambda function without an execution role.

How to eliminate wrong answers

Option A is wrong because IAM users are intended for human or application access with long-term credentials, not for AWS services; embedding user credentials in a Lambda function is insecure and violates best practices. Option B is wrong because a resource-based policy on the S3 bucket can grant cross-account access or access to other AWS services, but it cannot directly grant permissions to a Lambda function's execution role; the Lambda function still needs an execution role with the appropriate permissions. Option C is wrong because IAM groups are used to manage permissions for IAM users, not for AWS services; Lambda functions cannot be added to an IAM group.

58
MCQmedium

A developer is designing an application that will process credit card payments and store them temporarily in an Amazon DynamoDB table. The developer must ensure that the payment data is encrypted at rest and that the encryption key is managed by the company's security team using AWS KMS. Which type of encryption should the developer enable on the DynamoDB table?

A.Server-side encryption with a customer-managed KMS key
B.Server-side encryption with an AWS managed KMS key
C.Client-side encryption
D.Static key encryption
AnswerA

Server-side encryption with a customer-managed KMS key (CMK) is the most appropriate choice for sensitive data like credit card payments. This option grants the company's security team full administrative control over the encryption key's policy, rotation schedule, and access permissions within AWS Key Management Service (KMS). Such granular control is often a strict requirement for compliance standards like PCI DSS, ensuring the organization maintains ownership and oversight of its cryptographic assets used for data at rest in DynamoDB.

Why this answer

The requirement specifies that the encryption key must be managed by the company's security team. Server-side encryption (SSE) with a customer-managed KMS key allows the company to create, rotate, and control access to the KMS key used to encrypt the DynamoDB table at rest. This gives the security team full control over the encryption key lifecycle, meeting the stated requirement.

Exam trap

The trap here is that candidates often confuse 'customer-managed KMS key' with 'AWS managed KMS key,' assuming any KMS encryption meets the requirement, but the exam specifically tests the distinction between who manages the key (customer vs. AWS) to enforce security control requirements.

How to eliminate wrong answers

Option B is wrong because server-side encryption with an AWS managed KMS key means AWS owns and manages the key, not the company's security team, so it does not satisfy the requirement for key management by the security team. Option C is wrong because client-side encryption encrypts data before it is sent to DynamoDB, which would require the developer to implement encryption logic in the application and manage keys separately, not using AWS KMS for server-side encryption at rest. Option D is wrong because 'static key encryption' is not a valid encryption type for DynamoDB; DynamoDB supports server-side encryption with AWS KMS keys (AWS managed or customer managed) and not a static key approach.

59
MCQeasy

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The application needs to authenticate users using a third-party identity provider that supports SAML 2.0. The company wants to use AWS Identity and Access Management (IAM) to manage user permissions. Which solution should the developer implement?

A.Use AWS Security Token Service (STS) to generate temporary credentials for the users.
B.Create an IAM identity provider for the SAML IdP and set up a role with a trust policy that allows federated users to assume it.
C.Store the SAML metadata document in AWS Certificate Manager.
D.Use Amazon Cognito user pools with a SAML identity provider.
AnswerB

This is the correct and standard approach for integrating a SAML-based Identity Provider with AWS. First, an IAM identity provider is created in AWS to register the SAML IdP's metadata document, establishing trust. Subsequently, an IAM role is configured with a trust policy that explicitly permits federated users from that specific SAML IdP to assume it, often based on SAML attributes. This role then defines the specific AWS permissions the federated users will inherit upon successful authentication and assumption.

Why this answer

It describes the standard AWS pattern for SAML 2.0 federation: creating an IAM identity provider for the external SAML IdP, then configuring an IAM role with a trust policy that allows users authenticated by that IdP to assume the role. This enables the application to use IAM to manage permissions for federated users without creating IAM users in the AWS account.

Exam trap

The trap here is that candidates may confuse Amazon Cognito (which also supports SAML) as the only way to federate with a third-party IdP, but the question explicitly requires IAM to manage permissions, making direct IAM SAML federation the correct choice.

How to eliminate wrong answers

Option A is wrong because AWS STS generates temporary credentials, but it does not directly handle SAML authentication; STS is used after federation is established to issue credentials for an assumed role. Option C is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates, not SAML metadata documents; SAML metadata is uploaded to IAM when creating the identity provider. Option D is wrong because Amazon Cognito user pools with a SAML IdP is a valid approach for user authentication, but the question specifically requires using IAM to manage user permissions, and Cognito does not integrate with IAM for permission management in the same way as direct IAM SAML federation.

60
MCQhard

A developer attached the following IAM policy to an IAM user: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*", "Condition": { "StringEquals": { "s3:x-amz-server-side-encryption": "AES256" } } } ] } ``` The user tries to download an object from example-bucket using the AWS CLI without specifying server-side encryption. What will happen?

A.The download succeeds because the policy allows s3:GetObject
B.The download fails with an AccessDenied error
C.The download succeeds because the object is encrypted with SSE-S3
D.The download fails with a 500 Internal Server Error
AnswerB

The IAM policy attached to the user explicitly includes a condition requiring the `s3:x-amz-server-side-encryption` header with a specific value in the request for `s3:GetObject` to be allowed. If the user attempts to download the object without including this mandatory header in their request, the policy's condition is not met. Consequently, access is denied, resulting in an `AccessDenied` error, typically an HTTP 403 Forbidden status.

Why this answer

The IAM policy allows s3:GetObject only if the request includes server-side encryption set to AES256. Since the user does not specify encryption, the condition is unmet, resulting in an AccessDenied error.

61
MCQhard

A developer is troubleshooting an issue where an S3 bucket policy is not granting cross-account access to a user in another AWS account. The bucket policy uses a Principal element with the AWS account ID. What is the most likely reason for the failure?

A.The bucket is encrypted with SSE-S3, which blocks cross-account access.
B.The bucket policy must use the user's ARN instead of the account ID.
C.The bucket policy cannot grant access to users in another account.
D.The IAM user in the other account does not have an IAM policy that allows the S3 action.
AnswerD

For successful cross-account access to an S3 bucket, a 'two-way street' of permissions is required. While the S3 bucket policy must explicitly grant access to the external account or user, the IAM user in that external account must also possess an identity-based IAM policy that permits the specific S3 actions, such as s3:GetObject or s3:PutObject. If the user's IAM policy is missing or too restrictive, even with a permissive bucket policy, access will be denied, as both policies must allow the action.

Why this answer

The most likely reason is that the IAM user in the other account does not have an IAM policy that allows the S3 action. For cross-account access, both the bucket policy (resource-based) and the IAM policy (identity-based) must grant the necessary permissions. Even if the bucket policy allows the account, the user's IAM policy must also allow the action.

Exam trap

DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the need for the user's IAM policy to also allow the action.

How to eliminate wrong answers

Option A is wrong because SSE-S3 encryption does not block cross-account access; encryption is orthogonal to permissions. Option B is wrong because the bucket policy can use the account ID as the principal; it does not require the user's ARN. Option C is wrong because bucket policies can grant access to users in another account; it is a common practice for cross-account access.

62
MCQhard

A company has a legacy application running on an EC2 instance that stores database credentials in a plain text configuration file. The security team requires that credentials be stored securely and rotated every 90 days. The developer must minimize changes to the application code. The application currently reads the configuration file from the file system. Which solution meets these requirements?

A.Encrypt the configuration file using AWS KMS and store the encrypted file on S3.
B.Use AWS Secrets Manager to store the credentials and configure automatic rotation with a Lambda function. Modify the application to retrieve the secret from Secrets Manager.
C.Store the credentials in environment variables on the EC2 instance.
D.Store the credentials in AWS Systems Manager Parameter Store as a SecureString and retrieve them at application startup.
AnswerB

AWS Secrets Manager is the most appropriate solution for managing application credentials, offering robust features like automatic rotation. By integrating with a custom Lambda function, Secrets Manager can programmatically rotate credentials for databases, API keys, or other services on a defined schedule, significantly enhancing the security posture. The application only needs to be modified to retrieve the current secret value from Secrets Manager at runtime, abstracting the actual credential management and minimizing code changes.

Why this answer

AWS Secrets Manager provides built-in support for automatic credential rotation using a Lambda function, meeting the 90-day rotation requirement without manual intervention. By modifying the application to retrieve the secret via the Secrets Manager API, the credentials are no longer stored in plain text, satisfying the security team's mandate. This approach minimizes code changes because the application only needs to replace the file read with an API call, preserving the existing logic structure.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Systems Manager Parameter Store, assuming both support automatic rotation, but Parameter Store does not provide built-in rotation capabilities, making Secrets Manager the only correct choice for automated rotation requirements.

How to eliminate wrong answers

Option A is wrong because encrypting the configuration file and storing it on S3 does not address rotation; the encrypted file would still need to be manually updated every 90 days, and the application would require code changes to decrypt the file. Option C is wrong because environment variables on the EC2 instance are not encrypted at rest by default and do not support automatic rotation; they also expose credentials in process listings or logs. Option D is wrong because AWS Systems Manager Parameter Store as a SecureString does not support automatic rotation natively; while it can store encrypted parameters, rotation would require custom automation, and the application would still need code changes to retrieve the parameter via the AWS SDK.

63
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with SSE-S3. What is the MOST effective way to enforce this?

A.Create an IAM policy that denies non-SSE-S3 encryption and attach it to all users.
B.Use AWS Config rules to detect buckets without SSE-S3 and send alerts.
C.Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.
D.Use S3 bucket policies to deny PutObject if encryption is not SSE-S3.
AnswerC

Service Control Policies (SCPs) in AWS Organizations provide a powerful *preventive* control mechanism that applies centrally across all member accounts within an Organizational Unit (OU) or the entire organization. By implementing an SCP to explicitly deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256, it effectively prevents any account from configuring S3 buckets without the required SSE-S3 encryption, ensuring compliance at the infrastructure level.

Why this answer

AWS Organizations allows you to create service control policies (SCPs) that can be applied to all accounts in the organization. An SCP can deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256 (SSE-S3). This centrally enforces encryption across all accounts.

Option A is incorrect because IAM policies must be attached to each user or group individually, and they cannot be enforced across all accounts centrally. Option B is reactive (detection only) and does not prevent non-compliant actions. Option D can enforce encryption on object uploads but does not prevent configuration of bucket-level encryption settings.

64
MCQmedium

A company has an S3 bucket that stores sensitive data. The data is encrypted at rest using an AWS KMS customer managed key (CMK). The security team wants to ensure that only a specific IAM role in the same account can decrypt the objects. Which configuration should the developer implement?

A.Add a bucket policy that denies s3:GetObject unless the request uses a specific IAM role.
B.Add a key policy that allows the IAM role to perform kms:Decrypt and denies all other principals.
C.Configure the S3 bucket with default encryption using the KMS key.
D.Create an IAM policy that grants kms:Decrypt only to the specific role.
AnswerB

A KMS key policy is the primary and mandatory control mechanism for defining who can use a Customer Master Key (CMK) for cryptographic operations, including kms:Decrypt. By explicitly allowing kms:Decrypt for the specified IAM role and implementing a default deny for all other principals, this policy directly enforces that only the designated role possesses the necessary permission to decrypt data encrypted with this specific KMS key. This ensures granular control over the sensitive data's accessibility in plaintext form.

Why this answer

KMS key policies directly control who can use the key for cryptographic operations like kms:Decrypt. By explicitly allowing only the specific IAM role and denying all other principals (including the root account), the key policy ensures that only that role can decrypt the S3 objects, regardless of any other IAM or bucket policies. This is the most secure and direct way to restrict decryption at the key level.

Exam trap

The trap here is that candidates often assume IAM policies alone can grant decryption access, but KMS key policies are the authoritative gatekeeper for key usage, and without an explicit Allow in the key policy, even an IAM policy with kms:Decrypt will fail.

How to eliminate wrong answers

Option A is wrong because a bucket policy denying s3:GetObject based on the IAM role does not control decryption; it controls read access to the object metadata and data, but if the object is encrypted with KMS, the request must also have kms:Decrypt permission, which the bucket policy cannot grant or deny. Option C is wrong because configuring default encryption with the KMS key only ensures new objects are encrypted at rest, but does not restrict which principals can decrypt them; any principal with kms:Decrypt on the key can still decrypt. Option D is wrong because an IAM policy granting kms:Decrypt to the role is insufficient if the key policy does not also allow the role; KMS key policies are the primary access control mechanism, and if the key policy denies all principals except the role, an IAM policy alone cannot override that denial.

65
Multi-Selecthard

A developer needs to securely expose an API running on an EC2 instance behind an Application Load Balancer. The API should only be accessible to authenticated users via a custom authorization header. Which steps should be taken? (Choose TWO.)

Select 2 answers
A.Create a Lambda authorizer that validates the custom header
B.Enable AWS WAF on the ALB to inspect the header
C.Use Amazon Cognito User Pools to validate the header
D.Use Amazon API Gateway instead of ALB
E.Configure the ALB to use the Lambda authorizer
AnswersA, D

A Lambda authorizer on the Application Load Balancer inspects the custom authorization header, validates the token, and returns an IAM policy allowing or denying the request. This enforces authentication at the load balancer before traffic reaches the EC2 instance.

Why this answer

Option A is correct because a Lambda authorizer (formerly custom authorizer) is the API Gateway mechanism designed to validate a custom authorization header by running a Lambda function that returns an IAM policy allowing or denying the request. Option D is correct because Amazon API Gateway natively supports Lambda authorizers and custom authorization headers, whereas an ALB does not provide this capability, so the API must be fronted by API Gateway to enforce header-based authentication. Option B is incorrect because AWS WAF inspects HTTP requests for threats like SQL injection or XSS and cannot perform custom token/header authorization logic.

Option C is incorrect because Cognito User Pools validate JWTs issued by Cognito, not arbitrary custom authorization headers. Option E is incorrect because ALBs have no native integration with Lambda authorizers; that feature exists only in API Gateway.

Exam trap

The trap is that candidates may assume ALB can use Lambda authorizers similar to API Gateway, but ALB lacks this feature. The correct solution is to use API Gateway with a Lambda authorizer instead of relying on ALB for custom authorization.

66
Multi-Selectmedium

A company wants to encrypt data at rest in Amazon RDS for MySQL. Which TWO actions should be taken?

Select 2 answers
A.Enable encryption at rest when creating the DB instance.
B.Encrypt individual tables using MySQL native encryption.
C.Enable encryption at rest after the DB instance is created.
D.Use AWS KMS to manage the encryption keys.
E.Use client-side encryption to encrypt data before sending to RDS.
AnswersA, D

Amazon RDS for MySQL supports encryption at rest, which must be configured during the initial creation of the DB instance. This ensures that the underlying storage volume, database snapshots, automated backups, and read replicas are all encrypted from the outset using an AWS Key Management Service (KMS) key. Attempting to enable encryption on an unencrypted instance after creation is not supported directly by RDS.

Why this answer

Amazon RDS for MySQL supports encryption at rest only at the time of DB instance creation. You must enable the encryption option in the console or specify the --storage-encrypted flag in the AWS CLI when launching the instance. Once enabled, RDS automatically encrypts the underlying storage, automated backups, read replicas, and snapshots using AES-256 encryption, with keys managed through AWS KMS.

Exam trap

The trap here is that candidates often assume encryption at rest can be enabled after instance creation (like modifying a DB parameter group) or that MySQL native encryption is available in RDS, but AWS restricts encryption to instance creation time and does not support MySQL's native table encryption within the managed service.

67
MCQhard

A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that all KMS keys are rotated every year. Which action should be taken?

A.Manually rotate the KMS key every year
B.Create a new KMS key and update all applications to use it
C.Enable automatic key rotation
D.Use AWS CloudWatch Events to trigger a Lambda function that rotates the key
AnswerC

Automatic key rotation re-wraps the KMS key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. Enabling it on each customer managed key meets the yearly rotation requirement with no manual intervention.

Why this answer

AWS KMS supports automatic key rotation for customer-managed KMS keys. When enabled, KMS rotates the key material annually without requiring any manual intervention or application changes. This satisfies the security team's requirement for yearly rotation while maintaining the same key ID and existing encrypted data accessibility.

Exam trap

The trap here is that candidates may think manual rotation or creating a new key is required because they confuse KMS key rotation with S3 bucket key rotation or assume that automatic rotation changes the key ID, which would break references to the key.

How to eliminate wrong answers

Option A is wrong because manual rotation requires creating a new key and updating applications, which is error-prone and does not automatically re-encrypt existing data. Option B is wrong because creating a new KMS key and updating applications introduces operational overhead and does not rotate the existing key; it replaces it, potentially breaking access to previously encrypted data. Option D is wrong because AWS CloudWatch Events triggering a Lambda function is unnecessary and overly complex; KMS already provides a built-in, fully managed automatic rotation feature that does not require custom scripting or event-driven orchestration.

68
MCQeasy

A developer needs to generate temporary credentials for a user to access an S3 bucket for 30 minutes. Which AWS service should be used?

A.IAM role
B.Amazon Cognito
C.AWS Key Management Service (KMS)
D.AWS Security Token Service (STS)
AnswerD

AWS Security Token Service (STS) is the dedicated AWS service for creating and providing temporary, limited-privilege credentials for AWS users, federated users, or applications. Developers utilize STS API operations like AssumeRole, GetFederationToken, or GetSessionToken to obtain these credentials, which consist of an access key ID, a secret access key, and a session token. These temporary credentials can be configured with a specific duration, such as 30 minutes, making them ideal for secure, short-lived access to AWS resources.

Why this answer

AWS Security Token Service (STS) is the correct service for generating temporary, limited-privilege credentials to access AWS resources. It can issue credentials with a configurable expiration period, such as 30 minutes, via the AssumeRole API call. This directly meets the requirement for time-bound access to an S3 bucket.

Exam trap

The trap here is that candidates confuse IAM roles (a permission container) with the service that actually issues temporary credentials (STS), leading them to select Option A instead of D.

How to eliminate wrong answers

Option A is wrong because an IAM role is a set of permissions, not a mechanism to generate temporary credentials; you must use STS (e.g., AssumeRole) to obtain temporary credentials for a role. Option B is wrong because Amazon Cognito is designed for user identity and authentication in web/mobile apps, not for directly generating temporary AWS credentials for a single S3 bucket access scenario; it uses identity pools which rely on STS under the hood but adds unnecessary complexity. Option C is wrong because AWS Key Management Service (KMS) manages encryption keys and cannot generate any type of credentials, temporary or otherwise.

69
MCQeasy

A developer needs to securely store database credentials for a Lambda function. The credentials should be automatically rotated every 30 days. Which AWS service should the developer use?

A.AWS Key Management Service (KMS) to encrypt the credentials.
B.Store the credentials in an IAM role's trust policy.
C.AWS Secrets Manager.
D.AWS Systems Manager Parameter Store with a SecureString parameter.
AnswerC

AWS Secrets Manager is the correct service for securely storing and managing database credentials because it is purpose-built for this task. It offers robust features like automatic rotation of credentials for supported databases, integration with other AWS services, and fine-grained access control. This automation significantly reduces the operational burden and enhances security by ensuring credentials are regularly updated without manual intervention.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets. It supports native rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in Lambda rotation functions, and can be configured to rotate on a schedule (e.g., every 30 days) without custom code. The service also integrates directly with Lambda via the AWS SDK to retrieve secrets at runtime, ensuring credentials are never hardcoded.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets with SecureString) with AWS Secrets Manager, but the key differentiator is that Secrets Manager provides built-in automatic rotation, which is explicitly required by the question.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encrypting data at rest, but it does not store credentials or provide automatic rotation; it only provides the encryption key, not the secret management lifecycle. Option B is wrong because IAM role trust policies define which principals can assume the role, not where to store credentials; storing credentials in a trust policy is not supported and would be a security risk. Option D is wrong because while Systems Manager Parameter Store with SecureString can store encrypted parameters, it does not natively support automatic rotation of credentials; you would need to build a custom rotation solution, whereas Secrets Manager provides built-in rotation capabilities.

70
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer. The application uses a PostgreSQL database on RDS. The security team requires that database credentials never be stored in application code or configuration files. Which solution meets this requirement?

A.Store the credentials in a Systems Manager Parameter Store parameter and retrieve them at application startup.
B.Store the credentials in an encrypted S3 bucket and have the application read the config file at startup.
C.Hardcode the credentials in a Lambda function that is called to get the credentials.
D.Use AWS Secrets Manager to store the credentials and retrieve them at runtime with automatic rotation.
AnswerD

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle. It integrates directly with various AWS services and databases to provide robust automatic rotation, ensuring credentials are regularly updated without manual intervention. Retrieving secrets at runtime, rather than just at startup, minimizes the exposure window and allows for dynamic credential updates without requiring application restarts, significantly enhancing the overall security posture.

Why this answer

AWS Secrets Manager is designed specifically for securely storing and automatically rotating database credentials. It integrates natively with RDS for PostgreSQL, enabling automatic rotation without code changes. The application retrieves credentials at runtime via the AWS SDK, ensuring they are never stored in code or configuration files.

Exam trap

The trap here is that candidates confuse Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with Secrets Manager, leading them to choose Option A despite the rotation requirement.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store does not natively support automatic rotation of RDS credentials; it is a parameter store, not a secrets manager with built-in rotation. Option B is wrong because storing credentials in an S3 bucket, even encrypted, still requires the application to read a configuration file at startup, which violates the requirement that credentials never be stored in configuration files. Option C is wrong because hardcoding credentials in a Lambda function still stores them in code, which is explicitly prohibited by the security requirement.

71
MCQhard

A developer is using IAM roles for Amazon EC2 to grant permissions to an application. The application makes API calls to DynamoDB and S3. After deploying, the application fails to access DynamoDB. The developer verifies the IAM role has the correct DynamoDB permissions. What is the most likely cause?

A.The IAM role does not have a trust policy for EC2.
B.The IAM role is not attached to the EC2 instance profile.
C.The DynamoDB table is in a different region than the EC2 instance.
D.The application is using the wrong AWS SDK.
AnswerB

An IAM role cannot be directly attached to an EC2 instance; it must be associated via an Instance Profile. The Instance Profile acts as a container for the IAM role, making its temporary credentials available to applications running on the EC2 instance through the instance metadata service. If the IAM role is not correctly embedded within an Instance Profile and that profile is not attached to the EC2 instance, the application will lack the necessary credentials to assume the role and perform actions like accessing DynamoDB.

Why this answer

For an EC2 instance to use an IAM role, the role must be attached to an EC2 instance profile, which is the container that passes the role's credentials to the instance via the instance metadata service. Even if the IAM role has the correct DynamoDB permissions, if it is not associated with the instance profile, the application will not receive temporary credentials and will fail to access DynamoDB.

Exam trap

The trap here is that candidates assume simply having the correct IAM role with proper permissions is sufficient, overlooking the mandatory step of attaching the role to an EC2 instance profile for credential delivery.

How to eliminate wrong answers

Option A is wrong because the IAM role does have a trust policy for EC2 (it must, otherwise the role could not be assumed by EC2 at all); the issue is the lack of attachment to the instance profile. Option C is wrong because DynamoDB is a global service that can be accessed across regions via its global endpoints, and region mismatch does not cause access failures when permissions are correct. Option D is wrong because the AWS SDK automatically handles credential retrieval from the instance metadata service; using a different SDK version or language does not prevent credential resolution if the role is properly attached.

72
MCQhard

A developer is configuring cross-account access for an S3 bucket. The source account (111111111111) wants to allow the target account (222222222222) to write objects to the bucket. The developer attaches the following bucket policy to the bucket in the source account: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::222222222222:root" }, "Action": "s3:PutObject", "Resource": "arn:aws:s3:::example-bucket/*" } ] } However, the write operation fails with AccessDenied. What is the most likely cause?

A.The target account has not attached an IAM policy granting the user or role s3:PutObject
B.The bucket has an S3 ACL that denies the target account
C.The bucket policy does not allow s3:PutObject for the target account
D.The bucket is encrypted with SSE-KMS and the target account lacks KMS permissions
AnswerA

For successful cross-account access to an S3 bucket, both the resource-based policy (the S3 bucket policy) on the target bucket AND an identity-based policy (IAM policy) attached to the user or role in the requesting (target) account must explicitly grant the necessary permissions. Even if the bucket policy allows the action, the requesting IAM principal must also have an IAM policy allowing it to perform s3:PutObject. This "two-policy" evaluation model ensures comprehensive security, making this the correct reason for denial if the IAM policy is missing.

Why this answer

Cross-account S3 access requires both a bucket policy that grants the target account principal (or a resource-based policy) AND an IAM policy in the target account that explicitly allows the user or role to perform the s3:PutObject action. Without the target account's IAM policy, the request is denied even if the bucket policy permits it, as the target account's principal lacks the necessary permissions to make the call.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, overlooking the requirement for an IAM policy in the target account to authorize the principal making the request.

How to eliminate wrong answers

Option B is wrong because S3 ACLs are legacy and, while they can grant cross-account permissions, the bucket policy is the primary mechanism here; an ACL denying the target account would cause a different error (e.g., AccessDenied with a different message) but is not the most likely cause given the bucket policy is already in place. Option C is wrong because the question states the developer attaches the bucket policy to allow the target account to write objects, so the bucket policy presumably includes s3:PutObject; if it didn't, the error would be expected, but the most likely cause is the missing IAM policy in the target account. Option D is wrong because SSE-KMS requires additional KMS key permissions (kms:GenerateDataKey, kms:Decrypt) for the target account, but the error would be a KMS-related AccessDenied, not a generic s3:PutObject failure; the question does not mention KMS, so this is less likely than the missing IAM policy.

73
Multi-Selectmedium

A company is using AWS KMS to encrypt data in S3. Which TWO actions are required to allow an IAM user to decrypt objects in a specific S3 bucket?

Select 2 answers
A.Attach a policy to the user allowing s3:GetObject on the bucket.
B.Attach a policy to the user allowing kms:Encrypt.
C.Attach a policy to the user allowing s3:PutObject.
D.Attach a policy to the user allowing kms:GenerateDataKey.
E.Attach a policy to the user allowing kms:Decrypt on the KMS key.
AnswersA, E

To retrieve any object from an S3 bucket, regardless of its encryption status, the principal (user or role) must have explicit permission to perform the s3:GetObject action. This action grants the ability to download the object's data, which is a fundamental prerequisite before any decryption process can even begin. Without this permission, S3 will deny the request to access the object entirely, making decryption impossible.

Why this answer

To decrypt an object stored in S3 using server-side encryption with AWS KMS (SSE-KMS), the IAM user must have the s3:GetObject permission to retrieve the encrypted object from the bucket. Without this permission, the user cannot even initiate the GetObject request, regardless of KMS permissions.

Exam trap

The trap here is that candidates often forget that decrypting an SSE-KMS encrypted object requires both S3 read permissions and KMS decrypt permissions, leading them to select only one of the two required actions.

74
Multi-Selectmedium

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets are encrypted with AES-256 (SSE-S3) and that no public access is allowed. Which TWO methods can be used to enforce these requirements across all accounts? (Choose TWO.)

Select 2 answers
A.Use AWS Config rules with automatic remediation to detect and fix non-compliant buckets.
B.Attach an IAM policy to all IAM users in each account that denies unencrypted operations.
C.Use an SCP in the root organizational unit to deny 's3:PutBucketPublicAccessBlock' and enforce encryption settings.
D.Enable AWS CloudTrail to log all S3 API calls and send alerts.
E.Use AWS Trusted Advisor to check for unencrypted buckets.
AnswersA, C

AWS Config rules continuously evaluate S3 buckets against predefined or custom compliance standards, such as requiring server-side encryption or blocking public access. When a non-compliant bucket is detected, Config can automatically trigger remediation actions, like applying a default encryption policy or enabling S3 Block Public Access, ensuring ongoing adherence to security policies across all accounts where the rule is deployed. This proactive approach ensures that any newly created or modified non-compliant buckets are swiftly brought into compliance without manual intervention.

Why this answer

AWS Config rules can evaluate S3 bucket configurations against desired settings (e.g., encryption enabled, public access blocked) and trigger automatic remediation via AWS Systems Manager Automation documents to fix non-compliant buckets. This provides continuous enforcement across all accounts in the organization without manual intervention.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs can grant permissions (they only deny), or they assume CloudTrail or Trusted Advisor can enforce security requirements when they are only detective or advisory tools.

75
Multi-Selectmedium

A developer is designing a system that must meet PCI DSS compliance. Which THREE AWS services can help with logging and monitoring security events?

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.AWS Key Management Service (KMS)
E.AWS Config
AnswersA, C, E

Amazon CloudWatch Logs provides a scalable and centralized service for ingesting, storing, and analyzing logs from various sources, including EC2 instances, Lambda functions, and custom applications. This service is crucial for meeting PCI DSS requirements for comprehensive audit trails, enabling the collection of system-level events, application logs, and security logs necessary for monitoring and incident response. Its ability to aggregate logs from disparate sources into a single, queryable repository significantly aids in demonstrating compliance with logging and monitoring mandates.

Why this answer

Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from various AWS resources and applications. For PCI DSS compliance, CloudWatch Logs can ingest security-related logs (e.g., from EC2, Lambda, or on-premises servers) and enable real-time monitoring, metric filters, and alarms to detect and respond to security events. It also supports log retention policies and encryption at rest using AWS KMS, which are required for audit trails under PCI DSS Requirement 10.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (network metadata) with security event logging, or mistakenly think KMS is a logging service because it is used for encryption, but neither generates or monitors security events as required by PCI DSS.

Page 1 of 5 · 314 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.