Courseiva

CCNA Security Questions

75 of 314 questions · Page 2/5 · Security · Answers revealed

76
MCQmedium

A company wants to encrypt data in transit between an on-premises application and an Amazon RDS instance. Which of the following should be implemented?

A.Use an AWS Site-to-Site VPN connection
B.Use SSL/TLS for the database connection
C.Place the RDS instance in a private subnet and use a bastion host
D.Enable encryption at rest on the RDS instance
AnswerB

SSL/TLS (Secure Sockets Layer/Transport Layer Security) is the industry standard protocol for encrypting data in transit directly between a client application and a database server. It establishes a secure, encrypted channel, ensuring confidentiality, integrity, and authentication of the data exchanged. For an RDS instance, configuring the database client to use SSL/TLS guarantees that all data transmitted between the on-premises application and the RDS database is encrypted throughout its journey, fulfilling the requirement for data encryption in transit.

Why this answer

Encrypting data in transit between an on-premises application and Amazon RDS requires enabling SSL/TLS on the database connection. RDS supports SSL/TLS for all supported engines, and the client must be configured to use the RDS certificate authority to establish an encrypted channel. This directly protects data as it travels over the network from the application to the database endpoint.

Exam trap

DVA-C02 often tests the distinction between encryption in transit and encryption at rest, so the trap is selecting a network-level control like VPN or a storage-level control like encryption at rest instead of the application-level SSL/TLS connection.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN encrypts traffic at the network layer between the on-premises network and the VPC, but it does not encrypt the database connection itself; if the VPN terminates before the RDS instance, the final leg could still be unencrypted. Option C is wrong because a private subnet and bastion host improve network access control but do not encrypt data in transit. Option D is wrong because encryption at rest protects stored data on disk, not data moving over the network.

77
Multi-Selecteasy

A developer is storing secrets such as database passwords. Which TWO AWS services can be used to securely store and retrieve secrets?

Select 2 answers
A.AWS CloudHSM
B.AWS Systems Manager Parameter Store
C.AWS Identity and Access Management (IAM)
D.AWS Secrets Manager
E.Amazon S3
AnswersB, D

AWS Systems Manager Parameter Store is a secure, hierarchical service for storing configuration data and secrets, including database passwords, as String, StringList, or SecureString parameters. SecureString parameters are encrypted with AWS KMS and can be retrieved via the AWS SDK, CLI, or directly from EC2 and Lambda, with IAM policies controlling access. It is a low-cost, no-extra-fee option (beyond KMS) and supports versioning, making it a lightweight and practical choice when you don't need built-in automatic rotation.

Why this answer

AWS Systems Manager Parameter Store (B) is correct because it can store secrets as SecureString parameters, which are encrypted with AWS KMS and can be retrieved programmatically by applications via the SSM API, making it a valid service for storing and retrieving database passwords. AWS Secrets Manager (D) is correct because it is purpose-built for storing, retrieving, and rotating secrets such as database credentials, using KMS encryption and APIs like GetSecretValue. AWS CloudHSM (A) is not correct here because it provides dedicated hardware security modules for cryptographic key operations, not a managed secret storage and retrieval service.

AWS Identity and Access Management (C) manages identities, permissions, and policies rather than storing secret values. Amazon S3 (E) is object storage and, while it can be encrypted, it is not designed as a secrets management service for securely storing and retrieving credentials.

Exam trap

DVA-C02 often tests the distinction between services that store secrets versus those that manage access or keys, causing candidates to confuse IAM or CloudHSM with secret storage solutions.

78
MCQmedium

A developer is managing an application that uses Amazon S3 to store user-uploaded images. The application generates thumbnails using AWS Lambda and stores them in a separate S3 bucket. The security team requires that all objects in both buckets be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The developer has configured the Lambda function to use an IAM role with permissions to call KMS Encrypt and Decrypt. However, when a user uploads an image, the Lambda function fails to write the thumbnail with an 'Access Denied' error. The upload bucket has default encryption set to SSE-KMS. What is the MOST likely cause of the failure?

A.The Lambda function is not in a VPC that has access to the KMS key.
B.The output bucket does not have a bucket policy allowing the Lambda function to write.
C.The upload bucket's default encryption is not applied to objects uploaded by Lambda.
D.The Lambda execution role lacks kms:GenerateDataKey permission for the KMS key.
AnswerD

When an S3 object is encrypted using Server-Side Encryption with AWS KMS (SSE-KMS), S3 requires permission to interact with the specified KMS key to generate a unique data key for object encryption. The `kms:GenerateDataKey` permission is essential for the Lambda's execution role to allow S3, acting on the Lambda's behalf, to request and use this data key from AWS KMS. Without this specific permission, the encryption process fails, resulting in an error during the object upload.

Why this answer

SSE-KMS encryption requires the caller to have both kms:Encrypt and kms:GenerateDataKey permissions on the KMS key. The Lambda execution role was granted Encrypt and Decrypt but not GenerateDataKey, so when S3 attempts to encrypt the thumbnail using SSE-KMS, the KMS call fails and S3 returns Access Denied. Adding kms:GenerateDataKey (and typically kms:Decrypt for reads) resolves the issue.

Exam trap

DVA-C02 often tests the misconception that kms:Encrypt is sufficient for SSE-KMS; candidates overlook that S3 uses GenerateDataKey for envelope encryption, so the missing permission is GenerateDataKey, not Encrypt.

How to eliminate wrong answers

Option A is wrong because Lambda does not need to be in a VPC to call KMS; KMS is a public AWS service reachable via the AWS network. Option B is wrong because the error is an Access Denied on the KMS operation, not an S3 bucket policy denial; the output bucket policy is not the root cause here. Option C is wrong because default encryption on the upload bucket applies to objects uploaded to that bucket, not to objects written to the output bucket; the failure is on the thumbnail write, which uses the output bucket's encryption settings.

79
MCQmedium

A developer needs to encrypt secrets (database passwords) that are used by an application running on EC2. The application retrieves the secrets at startup. Which combination of services provides the MOST secure and manageable solution?

A.Store the secrets in AWS Secrets Manager and use an IAM role to access them.
B.Encrypt the secrets with AWS KMS and store them in an S3 bucket with a bucket policy.
C.Store the secrets in AWS Systems Manager Parameter Store with a SecureString parameter.
D.Hardcode the secrets in the application code and encrypt the code.
AnswerA

Secrets Manager stores the database passwords centrally and supports native rotation, while the EC2 instance profile's IAM role grants retrieval permissions without embedding long-lived credentials. This removes hard-coded secrets and satisfies the secure, manageable requirement.

Why this answer

Storing secrets in AWS Secrets Manager and using an IAM role to access them provides the most secure and manageable solution. Secrets Manager is designed for secret management, supports automatic rotation, and integrates with IAM for fine-grained access control. Using an IAM role for EC2 eliminates the need to embed credentials in the application, enhancing security.

Exam trap

DVA-C02 often tests secret management best practices; candidates may choose Parameter Store SecureString as it is also secure, but Secrets Manager is preferred for its automatic rotation and dedicated secret management features.

How to eliminate wrong answers

Option B is wrong because while KMS encryption and S3 storage can be secure, it requires manual management of secrets, lacks automatic rotation, and is more complex to manage access compared to Secrets Manager. Option C is wrong because Systems Manager Parameter Store with SecureString is a valid option, but it lacks some advanced features of Secrets Manager like automatic rotation and cross-account access, and it may require more manual management. Option D is wrong because hardcoding secrets, even if encrypted, is a poor practice; the encryption key must be managed, and the code could be decompiled, exposing secrets.

80
MCQeasy

A developer is creating a new IAM policy to allow users to list objects in a specific S3 bucket. The policy must follow the principle of least privilege. Which policy statement should the developer use?

A.{"Effect":"Allow","Action":"s3:ListAllMyBuckets","Resource":"*"}
B.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::example-bucket"}
C.{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::example-bucket/*"}
D.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::example-bucket/*"}
AnswerB

Granting only `s3:ListBucket` on the bucket ARN itself satisfies least privilege, because listing objects is a bucket-level operation evaluated against the bucket resource, not the objects within it. Omitting `s3:GetObject` and any wildcard resource prevents unintended read access to object contents.

Why this answer

The s3:ListBucket action controls the ability to list the objects within a specific bucket, and it must be granted on the bucket resource itself (arn:aws:s3:::example-bucket), not on the objects inside it. Option B correctly pairs the least-privilege action with the correct resource ARN, allowing the user to list objects in only that one bucket. This satisfies the principle of least privilege because it grants no access to other buckets and no object-level read/write permissions.

Exam trap

DVA-C02 often tests the confusion between bucket-level actions (s3:ListBucket on the bucket ARN) and object-level actions (s3:GetObject/s3:PutObject on the object ARN), causing candidates to pick an object-level permission when a bucket-level listing permission is required.

How to eliminate wrong answers

Option A is wrong because s3:ListAllMyBuckets grants permission to list every bucket in the AWS account and must be paired with Resource "*", which violates least privilege and does not scope access to the specific bucket. Option C is wrong because s3:PutObject is a write action that uploads objects, not a list action, and it is applied to the object ARN (example-bucket/*) rather than the bucket ARN. Option D is wrong because s3:GetObject retrieves object contents, not bucket listings, and it is also applied to the object ARN instead of the bucket ARN.

81
MCQeasy

A developer wants to grant a user in a different AWS account access to an S3 bucket. The developer has written a bucket policy that allows the user's IAM user ARN. However, the access is still denied. What is the most likely reason?

A.The user's IAM user policy does not explicitly allow the required S3 action
B.The bucket policy does not have a principal of '*' to allow external accounts
C.The bucket is in a different region than the user's account
D.The user is using the wrong S3 endpoint (e.g., path-style vs virtual-hosted)
AnswerA

For cross-account S3 access, both the resource-based bucket policy and the identity-based IAM user policy must explicitly grant the necessary permissions. If the user's IAM policy lacks an `Allow` statement for actions like `s3:GetObject` or `s3:PutObject`, even if the bucket policy permits the external account, the request will be denied. This dual authorization model ensures granular control from both the resource owner and the identity owner.

Why this answer

When granting cross-account access to an S3 bucket, both the bucket policy (resource-based policy) and the user's IAM policy (identity-based policy) must explicitly allow the action. The bucket policy alone is insufficient if the user's IAM policy does not include an explicit Allow for the S3 action, because IAM denies by default. Even though the bucket policy grants access, the user's own IAM policy must also permit the operation for the request to succeed.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the external user's IAM policy must also explicitly allow the action, as IAM denies all actions by default.

How to eliminate wrong answers

Option B is wrong because a bucket policy does not require a principal of '*' to allow external accounts; you can specify the exact IAM user ARN as the principal, which is more secure and correct. Option C is wrong because S3 is a global service and bucket policies work across regions; the region of the bucket and the user's account does not affect access control. Option D is wrong because the S3 endpoint type (path-style vs virtual-hosted) affects URL format but does not impact authorization; access is denied due to IAM permissions, not endpoint choice.

82
MCQhard

A developer is building a serverless application using API Gateway and Lambda. The API must be accessed only by authenticated users from a specific AWS Cognito User Pool. Which method should be used?

A.Create a Lambda authorizer that checks the token against Cognito.
B.Use an IAM authorizer with a policy that allows only Cognito roles.
C.Use a resource policy on API Gateway to restrict by source IP.
D.Configure a Cognito Authorizer on the API Gateway method.
AnswerD

Configuring a Cognito user pool authorizer directly on the API Gateway method tells API Gateway to automatically validate the Authorization header's JWT against the specified user pool's public keys and required scopes before invoking the Lambda backend, requiring zero custom authorization code and rejecting any request lacking a valid token issued by that pool.

Why this answer

API Gateway can use a Cognito Authorizer to validate tokens from a specific user pool.

83
Multi-Selectmedium

A company wants to securely store database credentials for a Lambda function. The credentials must be automatically rotated. Which TWO services should be used together?

Select 2 answers
A.AWS KMS
B.AWS Secrets Manager
C.AWS CloudHSM
D.AWS Lambda
E.AWS Systems Manager Parameter Store
AnswersB, D

AWS Secrets Manager is a dedicated service for securely storing and managing secrets, including database credentials. It provides robust features for automatic rotation of secrets, which is crucial for enhancing security by regularly changing credentials without manual intervention. Furthermore, it integrates seamlessly with various AWS databases and services, simplifying the process of retrieving and using secrets in applications, making it the ideal solution.

Why this answer

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It integrates natively with AWS Lambda and supports automatic rotation via a built-in rotation function or a custom Lambda function, meeting the requirement for automated credential rotation without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks automatic rotation, which is explicitly required in the question.

84
MCQeasy

A developer needs to grant a Lambda function permission to write logs to CloudWatch Logs. Which IAM entity should be used?

A.Attach an inline policy to the Lambda function.
B.Create an IAM execution role with the necessary permissions and associate it with the function.
C.Use a service control policy (SCP) to allow logging.
D.Add a resource-based policy to the Lambda function.
AnswerB

Creating an IAM execution role with the necessary permissions and associating it with the Lambda function is the correct and standard approach. This execution role defines the specific actions the Lambda function is authorized to perform when it executes, such as reading from S3, writing to DynamoDB, or publishing logs to CloudWatch. The Lambda service assumes this role on behalf of your function, ensuring adherence to the principle of least privilege.

Why this answer

Lambda functions require an IAM execution role to obtain temporary credentials for accessing other AWS services. This role must include a trust policy allowing Lambda to assume it and a permissions policy granting the specific actions (e.g., logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents) on CloudWatch Logs. Associating this role with the function is the standard and secure way to grant permissions.

Exam trap

The trap here is confusing the entity that receives permissions (the Lambda function) with the mechanism that grants them (an execution role), leading candidates to incorrectly select attaching a policy directly to the function or using a resource-based policy.

How to eliminate wrong answers

Option A is wrong because an inline policy is attached to an IAM user, group, or role, not directly to a Lambda function; Lambda functions do not have IAM policies attached to them. Option C is wrong because Service Control Policies (SCPs) are used to set permission boundaries across an entire AWS organization or organizational unit, not to grant permissions to individual Lambda functions. Option D is wrong because resource-based policies are used to grant other AWS services or accounts access to the Lambda function itself (e.g., allowing an S3 bucket to invoke the function), not to grant the function permissions to other services like CloudWatch Logs.

85
Multi-Selectmedium

A developer is building a web application that uses Amazon Cognito for user authentication. Which TWO actions should be taken to secure the application?

Select 2 answers
A.Enable multi-factor authentication (MFA) for users.
B.Disable token expiration to avoid frequent re-authentication.
C.Use HTTPS for all communication between the client and the application.
D.Use IAM users for authentication instead of Cognito.
E.Store user tokens in local storage for persistence.
AnswersA, C

Enabling multi-factor authentication (MFA) for users significantly enhances the security posture of a web application. MFA adds a crucial second layer of verification beyond just a password, requiring users to provide something they know (their password) and something they have (like a code from an authenticator app or a hardware token). This makes it substantially more difficult for unauthorized individuals to gain access, even if they manage to compromise a user's primary credentials, aligning with robust identity and access management best practices.

Why this answer

Enabling multi-factor authentication (MFA) adds an extra layer of security beyond just a password, requiring users to provide a second factor (e.g., a one-time code from an authenticator app or SMS). This significantly reduces the risk of unauthorized access due to compromised credentials. Amazon Cognito supports MFA natively, allowing developers to enforce it for user pools.

Exam trap

The trap here is that candidates often think disabling token expiration improves user experience, but they overlook the critical security risk of token theft and the need for short-lived tokens (e.g., 1 hour for access tokens) combined with refresh tokens to balance security and usability.

86
MCQmedium

A developer is using AWS Secrets Manager to store database credentials. The application runs on EC2 and needs to retrieve the secret. Which approach is the most secure?

A.Store the secret in an environment variable in the user data script.
B.Use an IAM role attached to the EC2 instance with permissions to access the secret, and call the AWS SDK to retrieve it at runtime.
C.Retrieve the secret at application startup and store it in a configuration file.
D.Download the secret from an S3 bucket using pre-signed URLs.
AnswerB

Attaching an IAM role to an EC2 instance provides a secure and scalable way to grant temporary, automatically rotated credentials to applications running on the instance. The application can then use the AWS SDK to programmatically retrieve the secret from AWS Secrets Manager at runtime, ensuring secrets are never hardcoded or stored persistently on the instance. This approach adheres to the principle of least privilege and eliminates the need for manual credential management.

Why this answer

It follows the principle of least privilege and avoids hardcoding or storing secrets in insecure locations. By attaching an IAM role to the EC2 instance, the application can securely retrieve the secret from AWS Secrets Manager at runtime using the AWS SDK, without ever exposing the secret in code, configuration files, or environment variables. This approach leverages IAM's temporary credentials from the instance metadata service (IMDS) to authenticate the SDK call, ensuring the secret is never persisted locally.

Exam trap

The trap here is that candidates often think storing secrets in environment variables or configuration files is acceptable because it's 'runtime only,' but the exam emphasizes that any persistent or accessible storage of secrets violates security best practices, and only IAM roles with SDK retrieval provide the necessary isolation and rotation support.

How to eliminate wrong answers

Option A is wrong because storing the secret in an environment variable via user data script exposes it in the EC2 instance's metadata and process list, making it accessible to any user or process on the instance and violating security best practices. Option C is wrong because storing the secret in a configuration file after retrieval persists it on disk, increasing the risk of exposure through file system access, backups, or logs, and defeats the purpose of using Secrets Manager for dynamic rotation. Option D is wrong because downloading the secret from an S3 bucket using pre-signed URLs requires storing the secret in S3 first, which introduces additional management overhead and potential exposure, and pre-signed URLs can be intercepted or leaked, whereas Secrets Manager provides native encryption and access control.

87
MCQhard

An application running on an EC2 instance needs to access a DynamoDB table. The instance is in a private subnet. What is the most secure way to grant access without using long-lived credentials?

A.Create a VPC endpoint for DynamoDB and attach a security group to allow access.
B.Store IAM user access keys in the application configuration file.
C.Create an IAM role with DynamoDB access and attach it to the EC2 instance profile.
D.Use a security group to allow the EC2 instance to communicate with DynamoDB.
AnswerC

Attaching an IAM role with DynamoDB access to an EC2 instance profile is the AWS best practice for granting permissions to applications running on EC2 instances. This mechanism allows the EC2 instance to obtain temporary, frequently rotated credentials from the instance metadata service (IMDS). The application can then use these temporary credentials to make authorized API calls to AWS services like DynamoDB, eliminating the need to store static, long-lived credentials on the instance and enhancing security.

Why this answer

It uses an IAM role attached to the EC2 instance profile, which allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS). This eliminates the need for long-lived credentials and follows the principle of least privilege. The instance can securely access DynamoDB without storing any secrets on the instance.

Exam trap

The trap here is that candidates often confuse network-level controls (VPC endpoints or security groups) with identity-based access control, mistakenly thinking that enabling private connectivity alone grants API access to DynamoDB.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for DynamoDB enables private network connectivity but does not grant IAM permissions; without an IAM role or credentials, the EC2 instance cannot authenticate to DynamoDB. Option B is wrong because storing IAM user access keys in the application configuration file introduces long-lived credentials that can be compromised, violating the security best practice of using temporary credentials. Option D is wrong because security groups control network traffic at the instance level and cannot authenticate or authorize API calls to DynamoDB; DynamoDB access requires IAM permissions, not network rules.

88
MCQmedium

A developer needs to grant an IAM user in the same AWS account access to a specific object in an S3 bucket. The bucket policy currently grants access only to the bucket owner (the root account). Which identity-based policy statement should the developer add to the IAM user's permissions?

A.A bucket policy that allows s3:GetObject for the user.
B.An IAM policy that allows s3:GetObject for the specific object ARN.
C.An S3 access point policy.
D.An IAM policy that allows s3:ListBucket for the bucket.
AnswerB

This is the correct and most direct method for granting an IAM user access to a specific S3 object. An IAM policy is an identity-based policy attached directly to the IAM user (or their group/role), explicitly defining their permissions. By allowing s3:GetObject for the specific object's Amazon Resource Name (ARN), the user is directly granted the necessary permission to retrieve that object's content, provided no explicit deny exists elsewhere.

Why this answer

An IAM policy attached directly to the user can grant s3:GetObject permission for a specific object ARN (e.g., arn:aws:s3:::bucket-name/object-key). This identity-based policy overrides the bucket policy's default deny for the root-only access, as long as there is no explicit deny in the bucket policy. The bucket policy restricts access to the root account, but an explicit allow in an IAM policy can still grant access to the user since IAM policies and bucket policies are evaluated together, and an explicit allow in either can permit the action unless an explicit deny exists.

Exam trap

The trap here is that candidates confuse resource-based policies (bucket policies) with identity-based policies (IAM policies) and assume that a bucket policy is the only way to grant S3 access, overlooking that IAM policies can grant access to specific objects even when the bucket policy restricts access to the root account.

How to eliminate wrong answers

Option A is wrong because a bucket policy is a resource-based policy, not an identity-based policy; the question specifically asks for an identity-based policy statement to add to the IAM user's permissions. Option C is wrong because an S3 access point policy is a separate resource-based policy attached to an access point, not an identity-based policy attached to the IAM user; it does not directly grant permissions to the user's identity. Option D is wrong because s3:ListBucket is a bucket-level action that lists objects in the bucket, not a specific object-level action; it does not grant access to a specific object and is irrelevant for granting GetObject on a particular object ARN.

89
MCQhard

A developer applied the above bucket policy to an S3 bucket. What is the outcome?

A.Anonymous users are allowed to read objects.
B.Only write requests are denied if not using HTTPS.
C.All requests to the bucket must use HTTPS; otherwise, they are denied.
D.The policy has no effect because it uses Deny.
AnswerC

This statement is correct. The bucket policy uses an `Effect: Deny` combined with a `Condition` that `aws:SecureTransport` is `false`. This configuration explicitly blocks any request made to the S3 bucket that does not utilize HTTPS encryption. Consequently, all successful interactions with the bucket must occur over a secure transport layer, enforcing HTTPS for data in transit.

Why this answer

The bucket policy includes a `Deny` effect with a `StringNotEquals` condition on `aws:SecureTransport`, which denies any request that does not use HTTPS. Since the `Principal` is set to `*`, this applies to all users, including anonymous users. Therefore, any request made over HTTP is denied, effectively requiring HTTPS for all access.

Exam trap

The trap here is that candidates often think a `Deny` statement with a condition is ineffective or only applies to specific actions, but in reality, the `Deny` with `StringNotEquals` on `aws:SecureTransport` explicitly blocks all non-HTTPS requests, making it a powerful enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because the policy denies all requests that are not HTTPS, and anonymous users are subject to this condition; they are not allowed to read objects unless they use HTTPS. Option B is wrong because the policy denies all requests (both read and write) that do not use HTTPS, not just write requests. Option D is wrong because the policy does have an effect: it uses `Deny` with a condition, which is a valid and enforceable S3 bucket policy statement that blocks non-HTTPS requests.

90
MCQmedium

Refer to the exhibit. A developer ran the above commands to inspect a KMS key. What can be determined about this key?

A.The key is disabled.
B.The key can be used in multiple AWS regions.
C.The key is an AWS managed key.
D.The key is a customer managed key.
AnswerD

The KeyManager field explicitly reads CUSTOMER, which is the definitive indicator that this key was created directly by the account owner and is a customer managed key, giving the account full control over its policy, rotation, and lifecycle.

Why this answer

The KeyManager field shows 'CUSTOMER', indicating it is a customer managed key. Option A is incorrect because KeyState is 'Enabled', so the key is not disabled. Option B is incorrect because MultiRegion is false, so the key is not multi-region.

Option C is incorrect because the key is customer managed, not AWS managed.

91
MCQmedium

A company is using AWS Secrets Manager to rotate database credentials automatically. The rotation Lambda function fails with a timeout. Which action should be taken to resolve this issue?

A.Reduce the rotation schedule interval.
B.Increase the Lambda function timeout.
C.Place the Lambda function in a VPC with a NAT gateway.
D.Store the rotation schedule in EC2 user data.
AnswerB

AWS Secrets Manager leverages a Lambda function to execute the actual database credential rotation logic. When this Lambda function's execution duration exceeds its configured timeout setting, the function is forcibly terminated, preventing the successful completion of the rotation process. Increasing the Lambda function's timeout directly provides more execution time, allowing the rotation logic to connect to the database, modify credentials, and update Secrets Manager without premature termination.

Why this answer

The Lambda function is timing out during the rotation process, which indicates that the default 3-second timeout is insufficient for the rotation logic. Increasing the Lambda function timeout (Option B) directly addresses this by allowing the function more time to complete the rotation, such as calling the Secrets Manager API, updating the database, and verifying the new credentials.

Exam trap

The trap here is that candidates may confuse a timeout with a network issue and incorrectly choose to place the Lambda in a VPC with a NAT gateway, when the real problem is simply that the default execution duration is too short for the rotation logic.

How to eliminate wrong answers

Option A is wrong because reducing the rotation schedule interval does not fix a timeout during execution; it only makes the rotation happen more frequently, potentially exacerbating the issue. Option C is wrong because placing the Lambda function in a VPC with a NAT gateway is unrelated to a timeout; it is used to enable internet access for Lambda functions in a VPC, but rotation timeouts are typically due to insufficient execution time, not network connectivity. Option D is wrong because storing the rotation schedule in EC2 user data is irrelevant; Secrets Manager rotation is managed by Lambda, not EC2, and user data is used for instance bootstrapping, not for scheduling rotation.

92
MCQeasy

A developer is creating an IAM policy for an Amazon S3 bucket that must allow read access to a specific object only. Which policy element should be used to restrict access to the object?

A.Action
B.Condition
C.Principal
D.Resource
AnswerD

The Resource element is precisely where the specific AWS entity or entities that a policy statement applies to are defined. To restrict access to a particular S3 object, its unique Amazon Resource Name (ARN) must be explicitly listed in this field. This directly scopes the policy's permissions to 'that object only,' ensuring fine-grained control over access to individual S3 objects rather than an entire bucket.

Why this answer

The Resource element in an IAM policy specifies the object or bucket to which the policy applies. To allow read access to a specific object only, you must specify the object's ARN (e.g., arn:aws:s3:::bucket-name/object-key) in the Resource element. This restricts the policy's effect to that object.

Exam trap

DVA-C02 often tests the confusion between Action and Resource, where candidates mistakenly believe Action restricts the object, when Resource is the element that specifies the target object.

How to eliminate wrong answers

Option A is wrong because the Action element specifies the API operations (e.g., s3:GetObject) but does not restrict which object the action applies to. Option B is wrong because the Condition element adds constraints (e.g., IP address, MFA) but does not identify the target object; it is used in conjunction with Resource. Option C is wrong because the Principal element specifies who is allowed or denied access (e.g., an IAM user or role), not which object is accessed.

93
MCQeasy

A developer is creating an IAM policy to allow an EC2 instance to read objects from a specific S3 bucket named 'my-app-data'. The policy should be attached to an IAM role that will be assumed by the EC2 instance. Which policy statement meets this requirement?

A.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::my-app-data/*" } ] }
B.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "*" } ] }
C.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject" ], "Resource": "arn:aws:s3:::my-app-data/*" } ] }
D.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-app-data/*" } ] }
AnswerD

This policy correctly grants only the necessary read access to the specified S3 resources. The "Action": "s3:GetObject" precisely allows the retrieval of objects, which is a read-only operation. Furthermore, the "Resource": "arn:aws:s3:::my-app-data/*" correctly limits this permission to objects within the 'my-app-data' bucket, adhering to the principle of least privilege by preventing access to other buckets or broader S3 actions.

Why this answer

It grants only the s3:GetObject permission on the specific S3 bucket 'my-app-data' and its objects, which is the minimum required to allow an EC2 instance to read objects from that bucket. The policy is designed to be attached to an IAM role that the EC2 instance assumes, following the principle of least privilege.

Exam trap

The trap here is that candidates often choose overly permissive policies (like s3:* or including s3:PutObject) or forget to scope the resource to the specific bucket, leading to security misconfigurations that fail the principle of least privilege.

How to eliminate wrong answers

Option A is wrong because it allows all S3 actions (s3:*) on the bucket objects, which is overly permissive and violates the requirement to only allow read access. Option B is wrong because it allows s3:GetObject on all S3 resources (*), which grants read access to any S3 bucket, not just 'my-app-data', and is a security risk. Option C is wrong because it includes s3:PutObject in addition to s3:GetObject, which allows write access to the bucket, exceeding the requirement of read-only access.

94
Multi-Selecteasy

A company wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which THREE actions are required?

Select 3 answers
A.Instruct users to use their MFA device when logging in
B.Configure a password policy that requires MFA
C.Create a service control policy (SCP) to enforce MFA
D.Enable MFA for each IAM user
E.Create an IAM policy that denies access unless MFA is present
AnswersA, D, E

This option describes the user's required action once MFA is properly configured and enforced. After an MFA device is associated with an IAM user and an IAM policy requires its use, users must actively provide the time-based one-time password (TOTP) from their virtual or hardware MFA device during the authentication process to successfully log into the AWS Management Console or make API calls. This is the final step in the MFA workflow from the user's perspective.

Why this answer

Option D is correct because MFA must first be enabled/assigned for each IAM user (via the IAM console, CLI, or API, associating a virtual or hardware MFA device) before it can be enforced. Option A is correct because users must actually supply the MFA code at sign-in; the AWS Management Console login flow prompts for the MFA token after the password, and without that second factor the session cannot be established. Option E is correct because an IAM policy using the aws:MultiFactorAuthPresent condition key (typically with a Deny statement, e.g., denying all actions when aws:MultiFactorAuthPresent is false) enforces MFA programmatically for console access.

Option B is not correct because a password policy controls password complexity, length, reuse, and expiration—it has no MFA enforcement capability. Option C is not correct because SCPs apply only to AWS Organizations accounts (setting permission guardrails) and do not enforce MFA for individual IAM users in a single account.

Exam trap

Candidates often think that password policies can enforce MFA, but AWS IAM password policies only control password complexity, expiration, and reuse. They cannot enforce MFA. Similarly, while SCPs can deny actions without MFA at the Organization level, they do not configure or enable MFA for individual IAM users.

95
MCQeasy

A company wants to encrypt data at rest in Amazon S3. Which AWS service can be used to manage the encryption keys?

A.AWS Certificate Manager (ACM)
B.AWS CloudHSM
C.AWS Identity and Access Management (IAM)
D.AWS Key Management Service (KMS)
AnswerD

AWS Key Management Service (KMS) is a fully managed service designed to simplify the creation, storage, and control of encryption keys used across various AWS services. It integrates seamlessly with Amazon S3 to provide server-side encryption with KMS-managed keys (SSE-KMS), where S3 utilizes your customer master keys (CMKs) to encrypt and decrypt objects. KMS ensures the secure lifecycle management and auditability of these cryptographic keys, which are fundamental for robust data-at-rest encryption in S3.

Why this answer

AWS Key Management Service (KMS) is the service that manages encryption keys for Amazon S3's server-side encryption with KMS (SSE-KMS). Option A is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not encryption keys for S3. Option B is wrong because AWS CloudHSM provides hardware-based key management but is not directly integrated with S3 for SSE; KMS is the managed service for this use case.

Option C is wrong because AWS Identity and Access Management (IAM) controls access permissions, not encryption key management.

96
MCQeasy

A developer needs to allow an EC2 instance to read items from a DynamoDB table. Which is the best practice for granting permissions?

A.Store IAM user access keys on the instance
B.Use root user credentials
C.Attach an IAM role with the required permissions to the EC2 instance
D.Apply a service control policy (SCP) to the instance
AnswerC

Attaching an IAM role with the required permissions to an EC2 instance is the secure and recommended method for granting AWS services access to other AWS resources. When an IAM role is associated with an EC2 instance via an instance profile, the instance can automatically obtain temporary, frequently rotated credentials from the AWS Security Token Service (STS). This eliminates the need to embed or store static access keys on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.

Why this answer

Attaching an IAM role to the EC2 instance is the AWS best practice because it provides temporary, automatically rotated credentials via the instance metadata service (IMDS), eliminating the need to embed long-lived access keys. The role's policy grants only the required DynamoDB read permissions, following least privilege. This is the standard, secure, and auditable approach for EC2-to-AWS-service authentication.

Exam trap

DVA-C02 often tests the misconception that SCPs or bucket policies can grant permissions to an EC2 instance — candidates confuse organization-level guardrails (SCPs) with identity-based permissions (IAM roles), or think access keys are acceptable for convenience.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys on an instance is a security anti-pattern: keys are long-lived, can be leaked via logs or snapshots, and require manual rotation. Option B is wrong because using root user credentials violates least privilege and AWS best practice; root should never be used for application access and should have MFA enabled. Option D is wrong because SCPs are applied to AWS Organizations accounts/OU roots to set permission guardrails, not to individual EC2 instances; an SCP cannot grant permissions and does not attach to instances.

97
Multi-Selectmedium

A company wants to audit access to their S3 buckets. Which TWO services can be used to log and monitor S3 API calls?

Select 2 answers
A.AWS Config
B.S3 server access logs
C.AWS CloudTrail
D.AWS KMS
E.Amazon CloudWatch Logs
AnswersB, C

S3 server access logging records every request made to a bucket, including the requester's IP address (or IAM role/account if available), the request operation (e.g., REST.GET.OBJECT), the object key, response status, and timestamps, then delivers these logs to a destination bucket you designate. These logs provide a comprehensive object-level audit trail of both authenticated and unauthenticated access, making them a direct answer to the audit requirement. Keep in mind the logs are delivered on a best-effort basis with no guarantee of completeness, but they are still the standard method for forensic analysis of S3 access.

Why this answer

S3 server access logs (Option B) provide detailed records about requests made to an S3 bucket, including object-level API calls. AWS CloudTrail (Option C) logs management events for S3, such as bucket creation or configuration changes, and can also be configured to log data events for object-level operations. Option A (AWS Config) is used for resource configuration tracking, not API call logging.

Option D (AWS KMS) manages encryption keys. Option E (Amazon CloudWatch Logs) can store logs but does not directly capture S3 API calls; it works with CloudTrail or other sources.

98
Multi-Selecteasy

Which TWO AWS services can be used to protect an application running on EC2 from common web exploits like SQL injection and cross-site scripting?

Select 1 answer
A.Amazon CloudWatch
B.Security Groups
C.AWS WAF
D.AWS Shield Advanced
E.AWS Identity and Access Management (IAM)
AnswersC

AWS WAF is correct because it filters HTTP(S) requests to block SQL injection and cross-site scripting attacks.

Why this answer

AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting by inspecting HTTP(S) requests and blocking malicious patterns. AWS Shield Advanced is a DDoS protection service; it does not directly filter for SQL injection or XSS. Therefore, only AWS WAF is the appropriate service for this specific protection.

Exam trap

The trap here is that candidates often confuse AWS Shield Advanced (a DDoS protection service) with application-layer protection, mistakenly believing it can block web exploits like SQL injection and XSS, when in fact it focuses on volumetric DDoS attacks and does not inspect HTTP payload content.

99
MCQeasy

A developer needs to grant an IAM user the ability to create and manage CloudFormation stacks. Which IAM policy action should be allowed?

A.cloudformation:CreateStack
B.lambda:CreateFunction
C.ec2:RunInstances
D.s3:CreateBucket
AnswerA

cloudformation:CreateStack is the specific IAM action that authorizes a principal to launch a new CloudFormation stack from a template; combined with related actions like UpdateStack and DeleteStack it forms the core permission set needed to create and manage stacks, making it the directly applicable action for this requirement.

Why this answer

Option A (cloudformation:CreateStack). This action allows the IAM user to create and manage CloudFormation stacks. Option B (lambda:CreateFunction) is for creating Lambda functions, option C (ec2:RunInstances) is for launching EC2 instances, and option D (s3:CreateBucket) is for creating S3 buckets.

None of these other actions are related to CloudFormation stack management.

100
MCQeasy

A developer needs to grant cross-account access to an S3 bucket for an IAM user from another AWS account. The developer has added a bucket policy that allows the user's ARN. However, the user still cannot access the bucket. What additional step is required?

A.The user must have an IAM policy allowing the required S3 actions on that bucket
B.The bucket must be made public
C.The user must use a different AWS CLI profile
D.The resource-based policy must explicitly allow the user's ARN
AnswerA

For an IAM user in one AWS account to access an S3 bucket in another account, both the resource-based policy (bucket policy) and the identity-based policy (IAM user policy) must explicitly grant the necessary permissions. Even if the bucket policy permits the cross-account access, the IAM user's own policy must also authorize the specific S3 actions. This adherence to the principle of least privilege ensures that the user is explicitly allowed to perform the action from their identity's perspective.

Why this answer

A is correct because cross-account access to an S3 bucket requires both a resource-based policy (the bucket policy) that grants access to the user's ARN and an identity-based policy (an IAM policy attached to the user) that explicitly allows the required S3 actions on that bucket. Without the IAM policy, the user's account denies the request by default, even if the bucket policy permits it. This is the principle of 'permission delegation' in AWS: the resource owner can grant access, but the user's own account must also authorize the action.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the requesting account must also explicitly authorize the action via an IAM policy, which is a common oversight in AWS cross-account scenarios.

How to eliminate wrong answers

Option B is wrong because making the bucket public would grant access to all anonymous users, which is overly permissive and not a secure or necessary step for cross-account access; the bucket policy already specifies the user's ARN. Option C is wrong because using a different AWS CLI profile does not resolve the underlying permission issue; the user's IAM policy must allow the S3 actions regardless of the profile used. Option D is wrong because the developer has already added a bucket policy that explicitly allows the user's ARN, so this step is already done; the missing piece is the user's own IAM policy.

101
MCQeasy

A developer is deploying a web application on EC2 instances behind an Application Load Balancer (ALB). The application needs to encrypt data in transit between the client and the ALB. Which AWS service should be used to manage the SSL/TLS certificate?

A.AWS Certificate Manager (ACM)
B.AWS Key Management Service (KMS)
C.AWS Secrets Manager
D.AWS Identity and Access Management (IAM)
AnswerA

AWS Certificate Manager (ACM) is the dedicated AWS service for provisioning, managing, and deploying SSL/TLS certificates, including those required for HTTPS on web applications. It integrates seamlessly with services like Application Load Balancer (ALB), allowing you to easily attach certificates to secure traffic. ACM handles the entire certificate lifecycle, including automatic renewal, which significantly reduces the operational overhead of manual certificate management and ensures continuous secure communication between clients and the load balancer.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it provisions, manages, and deploys public and private SSL/TLS certificates that can be associated with an Application Load Balancer (ALB) to encrypt data in transit between clients and the ALB. ACM handles certificate renewal automatically and integrates natively with ALB, removing the need for manual certificate management. This ensures HTTPS termination at the load balancer, securing the client-to-ALB communication.

Exam trap

The trap here is that candidates may confuse AWS KMS (used for encryption at rest) with ACM (used for encryption in transit), or incorrectly assume IAM can manage SSL/TLS certificates for ALBs when it only supports legacy certificate uploads for CloudFront and Elastic Load Balancers in specific cases.

How to eliminate wrong answers

Option B (AWS KMS) is wrong because KMS is a key management service for creating and controlling encryption keys used for data at rest, not for managing SSL/TLS certificates for data in transit. Option C (AWS Secrets Manager) is wrong because Secrets Manager is designed to rotate and manage secrets such as database credentials and API keys, not SSL/TLS certificates for load balancers. Option D (AWS IAM) is wrong because IAM is an identity and access management service for controlling user and resource permissions, and while IAM can support SSL certificates for legacy CloudFront distributions, it does not manage or automate SSL/TLS certificates for ALBs and is not the recommended service for this purpose.

102
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The developer wants to restrict access to the API so that only authenticated users can invoke it. Which API Gateway feature should be used?

A.API Gateway Lambda authorizer
B.AWS WAF
C.API Gateway usage plan
D.API Gateway resource policy
AnswerA

An API Gateway Lambda authorizer (formerly custom authorizer) is a serverless function that you provide to control access to your API methods. It intercepts incoming requests, validates bearer tokens (like JWTs or OAuth tokens) or other custom authorization headers, and then returns an IAM policy. This policy explicitly allows or denies the request to proceed to the backend integration, making it ideal for implementing custom authentication and authorization schemes.

Why this answer

A Lambda authorizer (formerly custom authorizer) is correct because it allows API Gateway to invoke a Lambda function that validates a token or request parameters and returns an IAM policy granting or denying access. This is the standard way to implement custom authentication logic (e.g., JWT validation, OAuth) for API Gateway REST or HTTP APIs. It directly restricts invocation to authenticated users based on the authorizer's decision.

Exam trap

DVA-C02 often tests the distinction between authentication and authorization mechanisms, and candidates confuse usage plans (throttling) with authorizers (authentication), or mistakenly select AWS WAF for user authentication.

How to eliminate wrong answers

Option B is wrong because AWS WAF is a web application firewall that filters malicious traffic based on IP, headers, or patterns, but it does not authenticate users or validate identity tokens. Option C is wrong because usage plans are for throttling and quota management per API key, not for authentication. Option D is wrong because resource policies control access at the resource level (e.g., based on IP or VPC endpoint) but do not authenticate individual users.

103
MCQeasy

A developer wants to encrypt data in transit between an API Gateway REST API and its clients. Which configuration should be used?

A.Use a custom domain name with a certificate from ACM.
B.Implement client-side encryption using a JavaScript library.
C.Use the default HTTPS endpoint provided by API Gateway.
D.Attach an AWS WAF web ACL to the API Gateway.
AnswerC

The default HTTPS endpoint provided by API Gateway automatically ensures that all data transmitted between the client and the API Gateway is encrypted in transit. AWS manages the SSL/TLS certificates and the underlying infrastructure, providing robust transport layer security (TLS) out-of-the-box. This inherent feature means developers do not need to perform additional steps to secure the communication channel.

Why this answer

API Gateway REST APIs automatically provide an HTTPS endpoint using TLS for data in transit encryption. This default endpoint uses an Amazon-issued certificate, ensuring encryption between clients and API Gateway without any additional configuration. The developer only needs to use the default HTTPS URL provided by API Gateway to satisfy the requirement.

Exam trap

The trap here is that candidates often overcomplicate the solution by assuming a custom domain or additional services like WAF are needed for encryption, when the default HTTPS endpoint already provides TLS encryption for data in transit.

How to eliminate wrong answers

Option A is wrong because using a custom domain name with a certificate from ACM is an optional feature for branding or custom DNS, not a requirement for encrypting data in transit; the default HTTPS endpoint already provides encryption. Option B is wrong because client-side encryption using a JavaScript library encrypts data before sending it over the network, but it does not address the requirement of encrypting data in transit between the client and API Gateway; the transport layer (TLS) is already encrypted by the default HTTPS endpoint, and client-side encryption adds unnecessary complexity and is not a standard approach for transport encryption. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits, not a mechanism for encrypting data in transit; it operates at the application layer and does not provide TLS/SSL encryption.

104
MCQhard

A developer is using AWS Lambda to process sensitive data. The Lambda function needs to access a DynamoDB table that is encrypted with a customer-managed CMK. The developer is using the default Lambda execution role. What must be done to allow Lambda to decrypt the DynamoDB table?

A.Add a policy to the Lambda execution role allowing dynamodb:GetItem.
B.Add a policy to the KMS key that allows the Lambda execution role to perform kms:Decrypt.
C.Configure a VPC endpoint for DynamoDB.
D.Modify the Lambda function to call KMS Decrypt API.
AnswerB

The KMS key policy must allow the Lambda execution role to perform kms:Decrypt. This is required because DynamoDB uses server-side encryption with KMS, and the service needs to decrypt data on behalf of the Lambda function.

Why this answer

The DynamoDB table is encrypted with a customer-managed CMK. The Lambda execution role must be granted permission to use that key. This is done by adding a statement to the KMS key's key policy that allows the Lambda execution role to perform kms:Decrypt.

DynamoDB will then perform the decryption on behalf of Lambda. Option A is incorrect because dynamodb:GetItem alone does not grant KMS decrypt permissions. Option C is incorrect because a VPC endpoint is not related to KMS permissions.

Option D is incorrect because Lambda does not need to directly call the KMS Decrypt API; the key policy handles the authorization.

105
MCQeasy

A developer needs to grant an IAM role in the same AWS account read-only access to objects in a specific S3 bucket. The bucket is configured with a bucket policy that has an explicit Deny statement denying all principals except the root user. Which approach should the developer use to grant the required access?

A.Modify the bucket policy to allow the IAM role explicitly, or remove the Deny statement
B.Attach an IAM policy to the role that allows s3:GetObject on the bucket
C.Use an S3 access point instead of the bucket directly
D.Make the bucket public to allow all access
AnswerA

To grant an IAM role read-only access when an explicit Deny exists in the bucket policy, the Deny statement must be modified or removed. AWS IAM policy evaluation logic dictates that an explicit Deny always takes precedence over any Allow statement, whether from an identity-based policy (on the role) or a resource-based policy (on the bucket). Adjusting the bucket policy to explicitly allow the specific IAM role for `s3:GetObject` actions, or ensuring the existing Deny no longer applies to that role, is the only way to permit access.

Why this answer

The bucket policy contains an explicit Deny that overrides any allow permissions, including those granted by an IAM policy attached to the role. To grant the IAM role read-only access, the developer must either remove the Deny statement or add an explicit Allow for the role in the bucket policy, because an explicit Deny in a resource-based policy cannot be overridden by an identity-based policy.

Exam trap

The trap here is that candidates assume an IAM policy attached to the role is sufficient to override a bucket policy's explicit Deny, but they forget that explicit Deny always wins regardless of the source of the allow.

How to eliminate wrong answers

Option B is wrong because attaching an IAM policy that allows s3:GetObject to the role is insufficient; the explicit Deny in the bucket policy will still block access, as explicit Deny statements take precedence over any allow. Option C is wrong because an S3 access point uses the same underlying bucket policy; the explicit Deny in the bucket policy would still apply to requests made through the access point unless the bucket policy is modified. Option D is wrong because making the bucket public would grant access to everyone, which violates the principle of least privilege and does not specifically grant read-only access to the IAM role.

106
MCQhard

A company uses an Amazon S3 bucket to store sensitive documents. The security team requires that all objects uploaded to the bucket must be encrypted at rest using server-side encryption with a customer-managed KMS key (SSE-KMS). A developer needs to enforce this by denying any PutObject request that does not specify the required encryption. Which bucket policy condition should be used?

A."Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
B."Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}
C."Condition": {"Null": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "true"}}
D."Condition": {"ArnNotEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
AnswerA

This policy condition correctly enforces the use of a *specific* AWS KMS key for Server-Side Encryption (SSE-KMS) when objects are uploaded to the S3 bucket. The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key checks the value of the `x-amz-server-side-encryption-aws-kms-key-id` request header. By using `StringNotEquals` with the desired KMS key ARN, any PUT object request that does *not* specify this exact ARN in the header will be denied, effectively mandating its use. This ensures sensitive documents are encrypted with the designated corporate key.

Why this answer

The condition `s3:x-amz-server-side-encryption-aws-kms-key-id` with `StringNotEquals` explicitly denies any PutObject request that does not specify the exact customer-managed KMS key ARN. This enforces SSE-KMS with a specific key, meeting the security team's requirement that all objects must be encrypted at rest using that key.

Exam trap

The trap here is that candidates often confuse the condition key for the encryption type (`s3:x-amz-server-side-encryption`) with the condition key for the specific KMS key ID (`s3:x-amz-server-side-encryption-aws-kms-key-id`), leading them to pick Option B which only enforces SSE-KMS but not a specific customer-managed key.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption` with `aws:kms` only checks that SSE-KMS is used, but does not enforce a specific customer-managed KMS key; it would allow any KMS key, including the default AWS-managed key. Option C is wrong because the `Null` condition on `s3:x-amz-server-side-encryption-aws-kms-key-id` would deny requests where the key ID is not present, but it would not enforce that the key is the specific customer-managed key; it could be any KMS key ID. Option D is wrong because `ArnNotEquals` is not a valid condition operator for S3 bucket policies; the correct operator for string comparison is `StringNotEquals`.

107
MCQeasy

A developer needs to encrypt data in an S3 bucket. The company requires that the encryption key be managed by AWS but with the ability to audit key usage. Which S3 encryption option should the developer use?

A.Server-Side Encryption with AWS KMS (SSE-KMS).
B.Client-side encryption.
C.Server-Side Encryption with S3-Managed Keys (SSE-S3).
D.Server-Side Encryption with Customer-Provided Keys (SSE-C).
AnswerA

This option is ideal when the company requires robust control and auditability over encryption keys. With SSE-KMS, S3 encrypts objects using a customer master key (CMK) stored in AWS Key Management Service. This enables detailed logging of key usage requests through AWS CloudTrail, providing an essential audit trail for compliance, while AWS KMS handles the secure storage and management of the CMK.

Why this answer

SSE-KMS uses AWS Key Management Service (KMS) to manage the encryption keys, and it provides audit trails of key usage via AWS CloudTrail. This meets the requirement of AWS-managed keys with auditability. SSE-S3 uses S3-managed keys but does not provide detailed audit logs of key usage.

Client-side encryption and SSE-C involve customer-managed keys, which do not meet the 'managed by AWS' requirement.

Exam trap

DVA-C02 often tests the difference between SSE-S3 and SSE-KMS regarding auditability; candidates may incorrectly assume SSE-S3 provides key usage logs, but only SSE-KMS integrates with CloudTrail for auditing.

How to eliminate wrong answers

Option B is wrong because client-side encryption means the customer manages the keys and encryption process, which does not meet the requirement that the key be managed by AWS. Option C is wrong because SSE-S3 uses S3-managed keys, but it does not provide the ability to audit key usage; CloudTrail does not log individual S3 object encryption key usage for SSE-S3. Option D is wrong because SSE-C requires the customer to provide and manage the encryption keys, so AWS does not manage them, and auditability is limited to the customer's own key management.

108
MCQeasy

A developer needs to share an S3 bucket with a third-party AWS account. The third-party will upload files to the bucket using their own IAM users. The developer creates a bucket policy that grants s3:PutObject to the third-party account's root user. However, the third-party reports that their IAM users cannot upload files. What is the MOST likely reason?

A.The third-party's IAM users do not have an IAM policy allowing s3:PutObject.
B.The bucket policy must include a condition requiring encryption.
C.The bucket policy should grant access to the IAM user ARN instead of the root user.
D.The developer must create IAM users in their own account for the third-party.
AnswerA

Even if the S3 bucket policy grants permission to the third-party's account, the specific IAM user or role within that third-party account must also possess an identity-based policy that explicitly allows the s3:PutObject action. Without this corresponding identity-based permission, the request will be denied, as AWS IAM operates on an explicit allow principle where both sides must concur for cross-account access.

Why this answer

For cross-account access to S3, both the resource-based policy (bucket policy) and the identity-based policy (IAM policy attached to the third-party's IAM users) must grant the required permission. The bucket policy correctly grants s3:PutObject to the third-party account, but the third-party's IAM users also need an IAM policy allowing s3:PutObject. Without that identity-based permission, the request is denied even though the bucket policy allows it.

Exam trap

DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, when in fact the third-party's IAM users also need an identity-based policy allowing the action.

How to eliminate wrong answers

Option B is wrong because encryption conditions are optional and not required for uploads; while a bucket policy can enforce encryption, its absence does not block uploads. Option C is wrong because granting access to the account root ARN in a bucket policy is a valid way to delegate permissions to the entire account, and the third-party's IAM users would still need identity-based permissions. Option D is wrong because the developer should not create IAM users in their own account for the third-party; the third-party uses their own IAM users, and cross-account access is granted via bucket policy and identity-based policies in the third-party account.

109
MCQmedium

A developer is using AWS CodePipeline to deploy a web application. The pipeline includes a source stage from CodeCommit, a build stage using CodeBuild, and a deploy stage using CodeDeploy to EC2 instances. The application stores sensitive data in an S3 bucket. The developer needs to ensure that the S3 bucket is only accessible from the EC2 instances and not from any other AWS service or account. The EC2 instances have an IAM role that allows s3:GetObject. What additional configuration is required?

A.Use SSE-KMS encryption on the bucket.
B.Enable S3 Block Public Access on the bucket.
C.Add a bucket policy that allows access only from the VPC endpoint or specific IP addresses of the EC2 instances.
D.Move the sensitive data to a different S3 bucket and update the application.
AnswerC

A well-crafted S3 bucket policy can precisely define which principals, from which network locations, can perform specific actions on the bucket and its objects. By incorporating conditions that check for a VPC endpoint ID (using `aws:sourceVpce`) or specific source IP addresses (using `aws:SourceIp` for public IPs or `aws:VpcSourceIp` for private IPs within a VPC), access can be strictly limited to the intended EC2 instances or services operating within a controlled network environment. This granular control directly addresses the requirement to restrict access to authorized resources.

Why this answer

A bucket policy that restricts access to the S3 bucket from a specific VPC endpoint or the EC2 instances' IP addresses ensures that only requests originating from those sources are allowed. This complements the IAM role's s3:GetObject permission by adding a network-level condition, preventing other AWS services or accounts from accessing the bucket even if they have valid IAM credentials. The condition key `aws:SourceVpce` or `aws:SourceIp` in the bucket policy enforces this restriction.

Exam trap

The trap here is that candidates often confuse encryption (SSE-KMS) or public access controls (Block Public Access) with network-level access restrictions, failing to realize that IAM permissions alone are insufficient to prevent access from other AWS services or accounts that have their own valid credentials.

How to eliminate wrong answers

Option A is wrong because SSE-KMS encryption protects data at rest but does not control access to the bucket; it only ensures data is encrypted, not who can read it. Option B is wrong because S3 Block Public Access prevents public access from the internet but does not restrict access from other AWS services or accounts that have valid IAM credentials. Option D is wrong because moving the data to a different bucket does not solve the access control issue; the same problem would persist unless additional restrictions are applied.

110
Multi-Selecthard

A company has an IAM policy that allows s3:GetObject for all users in the account. However, a specific user is receiving access denied errors. Which THREE possible causes should the developer investigate?

Select 3 answers
A.An SCP at the organization level denies s3:GetObject.
B.The user is using an incorrect region endpoint.
C.The user's IAM role has an attached policy that denies s3:GetObject.
D.The S3 bucket is in a different AWS account.
E.A bucket policy explicitly denies the user.
AnswersA, C, E

Service control policies in AWS Organizations override account-level IAM grants, so an SCP denying s3:GetObject blocks access even though the identity policy allows it. This satisfies the stem's constraint: a user with an explicit allow still receives Access Denied, because SCPs cap effective permissions for all principals in the member account.

Why this answer

Option A is correct because AWS Organizations service control policies (SCPs) act as permissions guardrails that limit the maximum permissions for accounts in the organization; an SCP that denies s3:GetObject overrides the account-level IAM allow, producing Access Denied. Option C is correct because an explicit Deny in any attached IAM policy (identity-based) always wins over an Allow in the same or another policy, so a deny statement for s3:GetObject on the user's role blocks the action. Option E is correct because S3 bucket policies are resource-based policies evaluated alongside IAM policies, and an explicit Deny in the bucket policy for that user (or principal) overrides the account's Allow, resulting in Access Denied.

Option B is not correct because using an incorrect regional endpoint typically causes connection or redirect errors (e.g., 301/PermanentRedirect), not an authorization Access Denied for a valid request. Option D is not correct because cross-account access is possible when the bucket policy grants permission to the external principal; being in a different account alone does not cause Access Denied.

Exam trap

DVA-C02 often tests the misconception that an Allow in an IAM policy is sufficient for access, when in fact any explicit Deny at the SCP, identity, or bucket-policy layer overrides it.

111
Multi-Selecthard

A developer is designing a system to store sensitive user data in Amazon S3. The data must be encrypted at rest and the encryption keys must be rotated annually. Which services can be used to meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon S3 SSE-KMS
B.AWS Secrets Manager
C.AWS Certificate Manager (ACM)
D.AWS KMS
E.AWS CloudHSM
AnswersA, D

SSE-KMS encrypts S3 objects at rest using AWS KMS customer managed keys, and KMS supports automatic annual key rotation, satisfying both the encryption and rotation requirements. It is the server-side option that keeps key management within KMS.

Why this answer

Option A (Amazon S3 SSE-KMS) is correct because server-side encryption with AWS KMS keys (SSE-KMS) encrypts objects at rest in S3 and supports automatic annual key rotation when the underlying KMS customer managed key has rotation enabled. Option D (AWS KMS) is correct because it is the service that creates and manages the customer managed keys used for encryption and provides built-in annual automatic key rotation (every 365 days) for symmetric KMS keys. Option B (AWS Secrets Manager) is not for encrypting S3 object data at rest; it stores and rotates secrets such as database credentials.

Option C (AWS Certificate Manager) manages TLS/SSL certificates for encryption in transit, not S3 data-at-rest encryption keys. Option E (AWS CloudHSM) provides dedicated hardware security modules and does not by itself deliver S3 at-rest encryption with annual key rotation as required.

Exam trap

The trap here is that candidates often confuse AWS KMS with AWS CloudHSM, thinking both support automatic key rotation, but CloudHSM requires manual rotation and lacks native S3 integration for SSE.

112
MCQmedium

A company manages multiple AWS accounts using AWS Organizations. A developer needs to allow an IAM role in the production account to read objects from an S3 bucket in the development account. The bucket is encrypted with an AWS KMS customer managed key (CMK) in the development account. Which of the following is required to enable this cross-account access?

A.Grant the production account's root user access to the KMS key and the S3 bucket.
B.Add a bucket policy allowing the production account's IAM role and a KMS key policy granting the same role.
C.Create an IAM role in the production account with permissions to access the S3 bucket and KMS key.
D.Enable S3 bucket logging to allow cross-account access.
AnswerB

To enable secure cross-account access, a bucket policy must explicitly grant the production account's IAM role permissions for S3 actions like `s3:GetObject` on the bucket. Concurrently, a KMS key policy is essential to grant the *same* IAM role `kms:Decrypt` permissions, allowing it to decrypt objects encrypted with that KMS key. This combination of resource-based policies on the S3 bucket and KMS key establishes the necessary trust relationship, ensuring the production account's role can both access the bucket and decrypt its contents.

Why this answer

Cross-account access to an S3 bucket encrypted with a KMS customer managed key requires both a bucket policy that grants the production account's IAM role s3:GetObject permission and a KMS key policy that grants the same role kms:Decrypt permission. The bucket policy authorizes the S3 operation, while the key policy authorizes decryption of the object; both policies must explicitly allow the cross-account principal.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, forgetting that KMS-encrypted objects require a separate key policy grant for the decrypt permission.

How to eliminate wrong answers

Option A is wrong because granting the production account's root user access is overly broad and unnecessary; the principle of least privilege requires granting only the specific IAM role, not the entire root account. Option C is wrong because creating an IAM role in the production account with permissions to access the S3 bucket and KMS key does not solve the cross-account authorization; the development account's bucket policy and KMS key policy must explicitly allow the production account's role, not just the role having permissions in its own account. Option D is wrong because enabling S3 bucket logging only records access events and does not grant any cross-account permissions; it is irrelevant to authorization.

113
MCQeasy

A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the files and write results to a DynamoDB table. What is the MOST secure way to grant the necessary permissions?

A.Attach a resource-based policy to the S3 bucket and DynamoDB table allowing access from the Lambda function.
B.Create an IAM execution role for Lambda with permissions to read from S3 and write to DynamoDB.
C.Configure the S3 bucket policy to allow the Lambda function's ARN.
D.Store AWS access keys in the Lambda environment variables.
AnswerB

An IAM execution role is the recommended and most secure method for granting a Lambda function permissions to interact with other AWS services. When a Lambda function assumes this role, it receives temporary credentials, allowing it to perform actions like reading from an S3 bucket and writing to a DynamoDB table, as defined by the role's attached IAM policies. This approach adheres to the principle of least privilege and eliminates the need for hardcoding or managing static credentials within the function's configuration.

Why this answer

The most secure and AWS-recommended pattern is to create an IAM execution role for the Lambda function that grants least-privilege access to the specific S3 bucket and DynamoDB table. Lambda assumes this role at invocation, so no long-lived credentials exist and permissions are centrally managed.

Exam trap

DVA-C02 often tests whether candidates confuse resource-based policies (which grant others access to a resource) with execution roles (which grant a compute service access to other resources), leading them to pick a bucket policy instead of an IAM role.

How to eliminate wrong answers

Option A is wrong because resource-based policies on S3 and DynamoDB are used for cross-account or service-principal access, not for granting a Lambda function in the same account its execution permissions; Lambda still needs an execution role. Option C is wrong because an S3 bucket policy granting the Lambda ARN does not give Lambda permission to call DynamoDB and is not the mechanism Lambda uses to obtain credentials. Option D is wrong because storing AWS access keys in environment variables is an anti-pattern that exposes long-lived credentials in plaintext and violates least-privilege and rotation best practices.

114
Matchingmedium

Match each AWS tool or feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Infrastructure as Code

PaaS for web apps

Automated code deployment

Distributed tracing

Key management encryption

Why these pairings

AWS CodeDeploy automates code deployments, while Amazon CloudWatch provides monitoring. The distractors swap these definitions to test understanding of each service's purpose.

115
Multi-Selecteasy

A developer is creating an IAM policy for an EC2 instance to allow it to read from an S3 bucket. Which of the following are required? (Choose TWO.)

Select 2 answers
A.Create an IAM role with s3:GetObject permissions
B.Use KMS to encrypt the S3 objects
C.Configure an S3 bucket policy allowing the role
D.Attach the IAM role to the EC2 instance
E.Create an instance profile and assign a key pair
AnswersA, D

An IAM role is the fundamental identity construct used to grant permissions to AWS services, including EC2 instances. Creating an IAM role with the specific `s3:GetObject` permission ensures that the EC2 instance is authorized to retrieve objects from an S3 bucket, adhering to the principle of least privilege by granting only the necessary read access for the intended operation.

Why this answer

An IAM role is the recommended way to grant temporary, secure credentials to an EC2 instance for accessing AWS services. The s3:GetObject permission allows the instance to read objects from an S3 bucket, which is the specific action required for read access.

Exam trap

The trap here is that candidates often think an S3 bucket policy is always required when using an IAM role, but it is only necessary for cross-account access or when the bucket policy explicitly restricts access; for same-account access, the role's permissions alone are sufficient.

116
Multi-Selecteasy

A developer is creating an IAM policy for a Lambda function that needs to read from an SQS queue and write to a DynamoDB table. Which THREE permissions are required? (Select THREE.)

Select 3 answers
A.sqs:DeleteMessage
B.dynamodb:PutItem
C.sqs:ReceiveMessage
D.sqs:SendMessage
E.dynamodb:GetItem
AnswersA, B, C

This permission is essential for a Lambda function processing messages from an SQS queue. After a message is successfully processed, the function must explicitly call `DeleteMessage` to remove it from the queue. Without this action, the message will eventually become visible again after its visibility timeout expires, leading to duplicate processing and potential data inconsistencies, which is critical to avoid for reliable message handling.

Why this answer

A is correct because the Lambda function must delete messages from the SQS queue after processing them to prevent them from being reprocessed. The sqs:DeleteMessage permission is required to call the DeleteMessage API, which removes the message from the queue using its receipt handle. Without this permission, the function would successfully receive and process the message but fail to delete it, causing the message to become visible again after the visibility timeout expires.

Exam trap

The trap here is that candidates often confuse the permissions needed for a Lambda function acting as a consumer (ReceiveMessage and DeleteMessage) with those needed for a producer (SendMessage), or they mistakenly think GetItem is required for writing to DynamoDB when PutItem is the correct write operation.

117
MCQmedium

A developer runs the above command and gets the output shown. What is the developer verifying?

A.Whether the object is encrypted
B.The size and ETag of an object in S3
C.The version ID of the object
D.Whether the user has permissions to access the object
AnswerB

The `aws s3api get-object-attributes` command is specifically engineered to efficiently retrieve various attributes of an S3 object without requiring the download of the object's content. Among the key pieces of metadata it returns are the `ObjectSize`, which provides the total size of the object in bytes, and the `ETag`, an entity tag that serves as a hash of the object's content. These attributes are crucial for integrity checks, conditional requests, and managing storage consumption within S3.

Why this answer

The command retrieves attributes of an object, including its size and ETag. Option A is incorrect because encryption is not checked by this command. Option C is incorrect because version ID is not part of the output shown.

Option D is incorrect because the command does not test permissions; it just returns the object metadata if the user has read access.

118
MCQmedium

A developer is building a mobile application that uses Amazon Cognito for user authentication. After a user signs in, the application needs to access an Amazon DynamoDB table. The developer has set up an identity pool with an authenticated role. The IAM role attached to the authenticated identity has a policy allowing the required DynamoDB actions. However, users report that they cannot perform DynamoDB operations. What is the MOST likely cause of this issue?

A.The identity pool is not configured to use the authenticated role.
B.The app is not passing the correct identity ID.
C.The IAM role's trust policy does not allow Cognito to assume it.
D.The DynamoDB table is encrypted with a different KMS key.
AnswerC

The trust policy of an IAM role explicitly defines which entities are permitted to assume that role. For Amazon Cognito Identity Pools to issue temporary AWS credentials to an authenticated user, the IAM role associated with the authenticated identity must have a trust policy that grants the Cognito Identity service principal (cognito-identity.amazonaws.com) the sts:AssumeRole permission. Without this crucial trust relationship, Cognito cannot generate the necessary temporary credentials, leading to 'Access Denied' errors when the application attempts to interact with other AWS services, regardless of the permissions policy attached to the role.

Why this answer

The most likely cause is that the IAM role's trust policy does not include a statement allowing Amazon Cognito (specifically the `cognito-identity.amazonaws.com` service principal) to assume the role. Even if the identity pool is configured to use the authenticated role and the role's permissions policy grants DynamoDB actions, Cognito must be able to assume the role via AWS Security Token Service (STS) `AssumeRoleWithWebIdentity`. Without the correct trust relationship, Cognito cannot obtain temporary credentials for the user, so all DynamoDB operations fail.

Exam trap

The trap here is that candidates often focus on the permissions policy (allowing DynamoDB actions) and overlook the trust policy, which is a separate and critical requirement for Cognito to assume the role and generate credentials.

How to eliminate wrong answers

Option A is wrong because if the identity pool were not configured to use the authenticated role, the developer would not have been able to set it up in the first place; the configuration is a prerequisite that is explicitly stated as done. Option B is wrong because the identity ID is used to identify the user within the identity pool, but passing an incorrect identity ID would cause authentication failures or mismatched credentials, not a permissions issue on DynamoDB after sign-in; the core problem is the lack of a trust policy allowing role assumption. Option D is wrong because KMS key encryption on the DynamoDB table would only cause access failures if the IAM role lacked `kms:Decrypt` permissions or the key policy denied access, but the question states the role's policy allows the required DynamoDB actions, and KMS key mismatch would produce a different error (AccessDeniedException for KMS), not a generic inability to perform DynamoDB operations.

119
MCQeasy

A developer needs to allow an IAM user to manage only their own access keys (create, list, update, delete). Which IAM policy statement achieves this?

A.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/${aws:username}"}
B.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/JohnDoe"}
C.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"*"}
D.{"Effect":"Allow","Action":["iam:ListAccessKeys","iam:GetAccessKeyLastUsed"],"Resource":"*"}
AnswerA

This policy correctly grants comprehensive permissions for managing access keys through the `iam:*AccessKey*` action wildcard, which includes actions like Create, Delete, and Update. Crucially, the `Resource` element utilizes the `arn:aws:iam::*:user/${aws:username}` policy variable. This dynamic variable ensures that the policy's scope is strictly limited to the IAM user's own user resource, allowing them to create, delete, update, and list *only their own* access keys, thereby adhering to the principle of least privilege and the specific requirement.

Why this answer

It uses the `iam:*AccessKey*` wildcard action to cover all access key management operations (create, list, update, delete) and restricts the resource to `arn:aws:iam::*:user/${aws:username}`. The `${aws:username}` policy variable dynamically resolves to the IAM user's own username, ensuring that each user can only manage their own access keys. This follows the principle of least privilege by scoping permissions to the user's own resource.

Exam trap

The trap here is that candidates often choose Option C (resource `*`) thinking it grants access to all users' keys, but they overlook that the wildcard resource would allow a user to manage other users' keys, violating the 'only their own' requirement.

How to eliminate wrong answers

Option B is wrong because it hardcodes the username 'JohnDoe', which would only allow that specific user to manage their own access keys, not any IAM user as required by the question. Option C is wrong because the resource `*` grants access to all IAM users' access keys, violating the requirement that each user manages only their own keys. Option D is wrong because it only includes read-only actions (`iam:ListAccessKeys` and `iam:GetAccessKeyLastUsed`) and omits the create, update, and delete actions needed to fully manage access keys.

120
MCQmedium

A company wants to store database credentials securely and rotate them automatically on a schedule. The credentials are used by an AWS Lambda function to access an Amazon RDS instance. Which AWS service should the developer use to meet these requirements?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.AWS Key Management Service (KMS)
D.AWS Certificate Manager (ACM)
AnswerA

AWS Secrets Manager is specifically designed for securely storing and managing secrets such as database credentials, API keys, and other sensitive data. It offers robust capabilities for automatic rotation of credentials, particularly for services like Amazon RDS, Amazon Redshift, and Amazon DocumentDB, significantly enhancing security posture by reducing the lifespan of individual credentials. This built-in automation directly addresses the requirement for secure storage and regular rotation, minimizing the risk of compromise.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, retrieve, and automatically rotate database credentials on a schedule. It natively supports automatic rotation for Amazon RDS databases (including MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) by integrating with Lambda to update the credentials in both Secrets Manager and the RDS instance. This meets the requirement for both secure storage and scheduled rotation without custom infrastructure.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with Secrets Manager, leading them to choose Parameter Store for its lower cost, but the requirement for automatic rotation disqualifies it.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it requires custom solutions or integration with Secrets Manager for rotation. Option C is wrong because AWS KMS is a key management service for encryption keys, not for storing or rotating secrets like database credentials. Option D is wrong because AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for database credentials or rotation.

121
MCQeasy

A developer in Account A has an Amazon S3 bucket that contains sensitive data. The developer wants to grant an IAM user in Account B read-only access to objects in the bucket. The developer has added a bucket policy in Account A that grants s3:GetObject access to the IAM user's ARN. However, the IAM user in Account B still receives Access Denied errors. What additional configuration is required?

A.Add an IAM policy in Account B that allows the user to perform s3:GetObject on the bucket's ARN.
B.Create an S3 access point and grant the user access through it.
C.Change the bucket policy to grant access to the entire AWS account B instead of the specific user.
D.Enable S3 object ownership and set the bucket ACL to grant read access to the user in Account B.
AnswerA

The core principle for cross-account S3 access dictates that both the resource owner (Account A) and the identity owner (Account B) must explicitly grant permission. While the bucket policy in Account A grants permission *to* Account B, the IAM user in Account B still requires an identity-based policy attached to them that explicitly allows the `s3:GetObject` action on the specified bucket ARN. This two-policy evaluation ensures that both accounts agree on the access, making this the correct and necessary step.

Why this answer

Cross-account access to S3 requires both a bucket policy in the source account (Account A) granting the necessary permissions to the target IAM user, and an IAM identity-based policy in the target account (Account B) that explicitly allows the same action (s3:GetObject) on the bucket's ARN. Without the IAM policy in Account B, the user lacks the authorization to initiate the request, even though the bucket policy permits it. This dual-permission model is a fundamental security requirement for cross-account S3 access.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, overlooking the mandatory IAM policy in the target account that must explicitly allow the action.

How to eliminate wrong answers

Option B is wrong because creating an S3 access point does not bypass the need for an IAM policy in Account B; access points still require both the bucket policy and the user's IAM policy to grant cross-account permissions. Option C is wrong because granting access to the entire AWS account B instead of the specific user would allow all principals in Account B (including unintended users) to access the bucket, which violates the principle of least privilege and does not resolve the missing IAM policy issue. Option D is wrong because S3 object ownership and bucket ACLs are legacy mechanisms that do not apply to cross-account access when a bucket policy is already in use; ACLs are disabled by default for new buckets and are not a substitute for the required IAM policy in Account B.

122
MCQeasy

A developer needs to securely store database credentials for a Lambda function. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS CloudHSM
C.AWS KMS
D.Amazon DynamoDB
AnswerA

AWS Secrets Manager enables automatic rotation of database credentials on a configurable schedule, satisfying the developer's need to avoid hard-coded secrets in Lambda environment variables. Its built-in integration with Amazon RDS, Redshift, and DocumentDB allows the Lambda function to retrieve current credentials at runtime via the GetSecretValue API, eliminating manual secret management.

Why this answer

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS Secrets Manager API, allowing the function to retrieve credentials at runtime without hardcoding them, and supports automatic rotation using built-in or custom Lambda rotation functions. This makes it the ideal choice for securely handling database credentials in a serverless application.

Exam trap

The trap here is that candidates often confuse AWS KMS (which only manages encryption keys) with AWS Secrets Manager (which manages the full lifecycle of secrets), leading them to choose KMS because they think 'encryption' is the primary requirement, when in fact the question asks for secure storage and management of credentials, not just encryption.

How to eliminate wrong answers

Option B (AWS CloudHSM) is wrong because it provides dedicated hardware security modules (HSMs) for cryptographic key generation and storage, not for managing application secrets like database credentials; it lacks built-in secret rotation and retrieval APIs. Option C (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys used to encrypt data, not for storing or rotating secrets; while it can encrypt secrets stored elsewhere, it does not natively manage the secret lifecycle. Option D (Amazon DynamoDB) is wrong because it is a NoSQL database designed for high-performance, scalable data storage, not a secrets management service; storing credentials in DynamoDB would require manual encryption, rotation, and access control, increasing security risk and operational overhead.

123
MCQmedium

A company uses an S3 bucket to store sensitive customer data. The bucket policy currently allows access to a specific IAM role used by an EC2 instance. A security audit reveals that the bucket is also accessible from an external AWS account. Which action should the security team take to restrict access to only the intended role?

A.Use S3 Object Ownership to disable ACLs.
B.Enable S3 Block Public Access on the bucket.
C.Modify the IAM role trust policy to only allow the EC2 instance.
D.Add a condition in the bucket policy to allow access only when the request includes the specific IAM role ARN.
AnswerD

Adding a condition in the S3 bucket policy is the precise method for restricting access to a specific IAM role. By utilizing a condition key like `aws:PrincipalArn` or `aws:SourceArn` within the bucket policy's `Condition` block, you can ensure that S3 operations are permitted only when the requesting principal's ARN matches the specified IAM role. This directly enforces the principle of least privilege by granting access exclusively to the intended role, even across accounts.

Why this answer

Adding a condition in the bucket policy using the `aws:PrincipalArn` condition key allows you to restrict access exclusively to the specific IAM role ARN. This ensures that even if the bucket policy grants access to an external AWS account, only requests made by the designated IAM role (e.g., `arn:aws:iam::123456789012:role/EC2AppRole`) will be allowed, effectively blocking any other principals, including those from external accounts.

Exam trap

The trap here is that candidates often confuse IAM role trust policies with resource-based policies (like S3 bucket policies), thinking that modifying the trust policy will control access to the bucket, when in fact the bucket policy itself must explicitly restrict the principal.

How to eliminate wrong answers

Option A is wrong because disabling ACLs via S3 Object Ownership does not restrict access based on IAM roles or external accounts; it only controls whether ACLs are used to manage permissions, not the bucket policy or IAM policies. Option B is wrong because S3 Block Public Access only prevents public (anonymous or authenticated AWS users) access, but the external AWS account is a trusted AWS principal, not a public user, so Block Public Access would not block that access. Option C is wrong because the IAM role trust policy controls which entities can assume the role, not which principals can access the S3 bucket; the bucket policy must be modified to restrict access to the role.

124
MCQhard

Refer to the exhibit. A developer runs an AWS CLI command on an EC2 instance and receives the error shown. The instance has an IAM role attached with the necessary permissions. What is the most likely cause of this error?

A.The CLI command is not supported on EC2 instances.
B.The CLI is not configured to use the instance profile credentials; environment variables or config file might be overriding.
C.The IAM role does not have the required permissions for the CLI command.
D.The instance does not have an IAM role attached.
AnswerB

This option correctly identifies a common troubleshooting scenario. The AWS CLI follows a specific credential resolution order, where environment variables (e.g., AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY) and entries in the ~/.aws/credentials file take precedence over instance profile credentials. If explicit, but invalid or incomplete, credentials are set in these higher-priority locations, the CLI will attempt to use them first and fail with a "missing credentials" error, even if a valid instance profile is attached to the EC2 instance.

Why this answer

The error indicates that the AWS CLI cannot find credentials. Even though the EC2 instance has an IAM role attached, the CLI will not automatically use instance profile credentials if environment variables (e.g., AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY) or a config file (e.g., ~/.aws/credentials) are present with different or invalid values. The CLI's credential provider chain checks environment variables first, then the config file, and only falls back to the instance metadata service (IMDS) if no other credentials are found.

Therefore, overriding settings are the most likely cause.

Exam trap

The trap here is that candidates assume the IAM role is automatically used by the CLI, but they overlook that environment variables or a local AWS credentials file can override the instance profile credentials, causing a 'Unable to locate credentials' error even when the role is correctly attached.

How to eliminate wrong answers

Option A is wrong because the AWS CLI is fully supported on EC2 instances and can run any command the instance's IAM role permits. Option C is wrong because the error message explicitly states 'Unable to locate credentials,' not a permissions error; if the role lacked permissions, the error would be 'AccessDenied' or similar. Option D is wrong because the question states the instance has an IAM role attached, so the role exists; the issue is that the CLI is not using it.

125
MCQhard

An application running on EC2 needs to access an S3 bucket. The developer has assigned an IAM role to the EC2 instance with a policy that allows s3:GetObject on the bucket. However, the application is still getting access denied errors. What should the developer check?

A.Check that the application is using HTTPS instead of HTTP.
B.Check the S3 bucket policy for an explicit deny statement that applies to the IAM role.
C.Check that the EC2 instance has permissions to decrypt the KMS key used by S3.
D.Check that the EC2 instance is in the same VPC as the S3 bucket.
AnswerB

AWS IAM policy evaluation logic dictates that an explicit deny statement always overrides any allow statements, regardless of where they are defined. If the S3 bucket policy contains an explicit deny that matches the EC2 instance's IAM role or the request's attributes, access will be blocked. This powerful mechanism ensures that specific access restrictions are enforced even if broader permissions are granted elsewhere, making it a critical check.

Why this answer

Even if the IAM role attached to the EC2 instance allows s3:GetObject, an S3 bucket policy with an explicit deny statement that applies to that role will override the allow. IAM policy evaluation logic dictates that an explicit deny in any policy (resource-based or identity-based) takes precedence over any allow, resulting in access denied errors.

Exam trap

The trap here is that candidates assume an IAM role with an allow policy is sufficient, overlooking that S3 bucket policies can contain explicit deny statements that override the role's permissions.

How to eliminate wrong answers

Option A is wrong because S3 supports both HTTP and HTTPS, and using HTTP does not cause access denied errors; HTTPS is recommended for encryption in transit but not a requirement for authorization. Option C is wrong because the question does not mention S3 server-side encryption with KMS, and without a KMS key being used, KMS permissions are irrelevant to the access denied error. Option D is wrong because S3 buckets are global resources and do not reside in a VPC; EC2 instances can access S3 over the internet or via a VPC endpoint, but being in the same VPC is not a requirement for access.

126
MCQhard

A developer receives the above error when trying to launch an EC2 instance. What is the most likely cause?

A.The account has reached its EC2 instance limit
B.The developer is trying to launch the instance in a restricted VPC
C.An SCP at the organizational level denies ec2:RunInstances
D.The developer's IAM policy does not allow ec2:RunInstances
AnswerC

Service Control Policies (SCPs) in AWS Organizations are designed to set maximum available permissions for all IAM entities within affected accounts. An explicit deny statement within an SCP overrides any allow statements in IAM policies, effectively preventing the "ec2:RunInstances" action from being performed, even if the user's IAM policy explicitly allows it. The error message directly indicating an explicit deny by an SCP precisely matches this behavior.

Why this answer

The error message explicitly mentions a service control policy (SCP) that denies the action, indicating that an SCP at the organizational level is blocking the ec2:RunInstances action. Option C is therefore correct. Option A is incorrect because instance limit errors show a message about reaching the maximum number of instances, not an SCP denial.

Option B is incorrect because VPC restrictions typically produce errors related to network constraints, not an explicit SCP reference. Option D is incorrect because an IAM policy denial would result in an 'UnauthorizedOperation' error, not one mentioning SCP.

127
Multi-Selecteasy

A developer is tasked with securing a legacy application that stores secrets in environment variables. Which THREE AWS services can be used to improve the security posture?

Select 3 answers
A.AWS Key Management Service (KMS)
B.AWS Certificate Manager
C.AWS CloudHSM
D.AWS Systems Manager Parameter Store
E.AWS Secrets Manager
AnswersA, D, E

AWS KMS is the correct answer because it provides the encryption key management that secures secrets at rest. KMS creates and protects Customer Master Keys (CMKs) that can encrypt data keys via envelope encryption, and both Systems Manager Parameter Store and Secrets Manager rely on KMS to encrypt their stored secret values. While KMS itself is not a secrets repository, it is the foundational service that makes secure secret storage possible. For this legacy application, using KMS to encrypt secrets either directly or through integration with other AWS services satisfies the security requirement.

Why this answer

AWS Key Management Service (KMS) (A) is correct because it provides managed encryption keys that can be used to encrypt secrets at rest, and it integrates with services like Secrets Manager and Parameter Store to protect the underlying data with customer master keys (CMKs). AWS Systems Manager Parameter Store (D) is correct because it offers a centralized, secure store for configuration data and secrets, supports SecureString parameters encrypted via KMS, and can be referenced by applications instead of hardcoding values in environment variables. AWS Secrets Manager (E) is correct because it is purpose-built for storing, rotating, and retrieving secrets such as database credentials and API keys, with native KMS encryption and fine-grained IAM access control.

AWS Certificate Manager (B) is not correct because it manages and provisions TLS/SSL certificates for services like ELB and CloudFront, not application secrets. AWS CloudHSM (C) is not correct because it provides dedicated hardware security modules for cryptographic operations and key storage, but it is not a secrets management service for replacing environment-variable-stored secrets.

Exam trap

DVA-C02 often tests the distinction between secret storage services and certificate/HSM services — candidates pick ACM or CloudHSM thinking 'security,' but those do not store application secrets.

128
MCQeasy

A company requires that all data in Amazon S3 be encrypted at rest using server-side encryption with a customer-managed KMS key. The developer needs to ensure that any object uploaded without the x-amz-server-side-encryption header set to aws:kms is denied. How can this be enforced?

A.Use a bucket policy that denies s3:PutObject if the encryption condition is not met.
B.Configure default encryption on the bucket with SSE-KMS.
C.Enable S3 Object Lock.
D.Use a CloudTrail trail to monitor uploads.
AnswerA

A bucket policy with a Deny effect on the s3:PutObject action can explicitly check for the presence of server-side encryption headers. By using a condition like StringNotEquals on s3:x-amz-server-side-encryption or Null for its absence, the policy will reject any upload that does not specify the required encryption. This mechanism directly enforces the company's encryption mandate at the point of ingestion, preventing non-compliant data from being stored.

Why this answer

An S3 bucket policy with a condition that denies s3:PutObject unless the `s3:x-amz-server-side-encryption` header equals `aws:kms` enforces server-side encryption with a customer-managed KMS key at the API level. This policy explicitly rejects any upload that does not include the required encryption header, ensuring compliance even if default encryption is bypassed or misconfigured.

Exam trap

The trap here is that candidates often confuse default encryption (which silently applies encryption but does not deny non-compliant uploads) with a bucket policy that actively denies requests, leading them to choose Option B as a simpler but ineffective solution.

How to eliminate wrong answers

Option B is wrong because configuring default encryption on the bucket with SSE-KMS only applies encryption to objects uploaded without an explicit encryption header; it does not deny uploads that omit the header, so objects can still be uploaded without the required `x-amz-server-side-encryption` header. Option C is wrong because S3 Object Lock is designed to prevent object deletion or overwrites for compliance or retention purposes, not to enforce encryption requirements during upload. Option D is wrong because CloudTrail trails only log API calls for auditing and monitoring; they cannot enforce or deny S3 PutObject operations based on encryption headers.

129
MCQmedium

A developer needs to allow an EC2 instance to read from a DynamoDB table. Which is the best practice to grant permissions?

A.Create an IAM role with the required permissions and attach it to the EC2 instance.
B.Generate an IAM user access key and store it in the application configuration.
C.Hardcode the AWS credentials in the application code.
D.Add the DynamoDB table ARN to the EC2 instance's security group.
AnswerA

Attaching an IAM role to an EC2 instance is the recommended and most secure method for granting AWS service permissions. This approach leverages temporary credentials automatically provided to the instance via the EC2 instance metadata service, eliminating the need to store static, long-term credentials on the instance itself. The role defines specific permissions, such as dynamodb:GetItem or dynamodb:Query, allowing the EC2 instance to interact with DynamoDB securely and with the principle of least privilege.

Why this answer

The best practice for granting an EC2 instance permissions to access DynamoDB is to create an IAM role with the required permissions and attach it to the instance. This eliminates the need to manage long-term credentials, as the instance automatically retrieves temporary security credentials from the instance metadata service (IMDS) via the AWS Security Token Service (STS). This approach follows the principle of least privilege and ensures credentials are rotated automatically.

Exam trap

The trap here is that candidates may confuse security groups (network-level access control) with IAM policies (identity-based access control) and incorrectly think adding a DynamoDB table ARN to a security group can grant data access, when in fact security groups only control network traffic and cannot authorize API calls to DynamoDB.

How to eliminate wrong answers

Option B is wrong because storing an IAM user access key in the application configuration introduces long-term static credentials that must be manually rotated, increasing the risk of exposure and violating AWS best practices for EC2. Option C is wrong because hardcoding AWS credentials in application code is a severe security risk, as the credentials can be exposed through version control, logs, or decompilation, and it also prevents automatic rotation. Option D is wrong because security groups are stateful firewalls that control network traffic at the instance level, not IAM permissions; they cannot grant access to DynamoDB, which operates over HTTPS and requires identity-based authentication.

130
MCQmedium

A developer needs to grant temporary access to an Amazon S3 bucket for a user from a different AWS account. The developer wants to use the most secure method that does not require sharing long-term credentials. Which approach should the developer take?

A.Create an IAM user in the developer's account and share the access keys
B.Use S3 bucket policy with a condition for the external account's IAM user
C.Use cross-account IAM roles with STS AssumeRole
D.Use S3 access control lists (ACLs) with the external user's canonical user ID
AnswerC

Using cross-account IAM roles with AWS Security Token Service (STS) AssumeRole is the most secure and recommended method for granting temporary access. The external user's identity assumes a pre-defined role in the developer's account, which then issues temporary, time-limited credentials (access key ID, secret access key, and session token). This approach eliminates the need to share long-term keys, provides fine-grained control over permissions, and automatically revokes access after the session duration expires.

Why this answer

Using cross-account IAM roles with AWS Security Token Service (STS) AssumeRole allows the external user to obtain temporary, limited-privilege credentials without sharing any long-term access keys. This approach follows the principle of least privilege and eliminates the risk of exposed static credentials, as the temporary credentials automatically expire after a configurable duration (default 1 hour, max 12 hours).

Exam trap

The trap here is that candidates often confuse S3 bucket policies with cross-account access, thinking a bucket policy alone can grant temporary credentials, when in fact bucket policies only authorize access based on the requester's existing (long-term) credentials and do not issue temporary tokens.

How to eliminate wrong answers

Option A is wrong because sharing IAM user access keys exposes long-term credentials that never expire, violating the requirement for temporary access and increasing the risk of credential leakage. Option B is wrong because an S3 bucket policy with a condition for an external account's IAM user still requires that external user to use their own long-term IAM credentials to sign requests, which does not grant temporary access and does not eliminate long-term credential sharing. Option D is wrong because S3 ACLs use canonical user IDs (the account's AWS-assigned identifier) and require the external user to authenticate with their own long-term credentials; ACLs also do not provide temporary credentials and are considered a legacy access control mechanism that is less secure and less flexible than IAM roles.

131
Multi-Selecthard

A developer is designing a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party identity provider (IdP). Which TWO services can be used to manage user authentication?

Select 2 answers
A.Amazon Cognito User Pools
B.AWS IAM
C.AWS Lambda custom authorizer
D.AWS Security Token Service (STS)
E.AWS Secrets Manager
AnswersA, C

Amazon Cognito User Pools act as a robust, managed user directory service that handles user sign-up, sign-in, and access control for web and mobile applications. It natively supports federation with various third-party Identity Providers (IdPs) such as Google, Facebook, Apple, and enterprise SAML/OIDC providers, allowing users to authenticate using their existing social or corporate credentials. After successful authentication, Cognito issues standard JWTs (ID and Access tokens) that can be used to authorize access to API Gateway and other AWS services.

Why this answer

Amazon Cognito User Pools is a fully managed identity service that provides user sign-up, sign-in, and access control for web and mobile applications. It integrates directly with third-party identity providers (IdPs) such as Facebook, Google, or SAML-based providers, making it the correct choice for managing user authentication in a serverless application with API Gateway and Lambda.

Exam trap

The trap here is that candidates often confuse AWS IAM (which manages AWS resource permissions) with user authentication, or they assume STS alone can authenticate users, when in fact STS only issues tokens after authentication has already occurred via another service like Cognito or an IdP.

132
MCQmedium

A company is using Amazon S3 to store sensitive documents. The security team requires that all access to the bucket be logged for audit purposes, but the company wants to avoid AWS CloudTrail data event charges and needs detailed HTTP request/response records. Which feature should be enabled?

A.S3 server access logging
B.Amazon CloudWatch Logs
C.S3 Inventory
D.AWS CloudTrail
AnswerA

S3 server access logging is the correct mechanism for recording detailed information about every request made to an S3 bucket, including successful and failed requests. These logs capture crucial details such as the requester's IP address, the operation performed (e.g., GET, PUT), the object key, the time of the request, and HTTP status codes. This comprehensive logging is essential for auditing access to sensitive documents and understanding usage patterns directly at the object level.

Why this answer

S3 server access logging provides detailed records for requests made to an S3 bucket, including the requester, bucket name, request time, action, and response status. Unlike AWS CloudTrail data events, which incur additional charges per 100,000 events, S3 server access logging is free to enable (you only pay for the storage of the log files). This makes it the ideal choice for detailed HTTP-level logging without extra service costs.

Exam trap

Candidates often confuse S3 server access logging with AWS CloudTrail. While CloudTrail is the standard for API auditing, CloudTrail data events (required for object-level logging like GetObject/PutObject) incur significant costs at scale. S3 server access logging is the cost-effective choice when you need to log S3 HTTP requests and want to avoid CloudTrail data event charges.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Logs is a service for monitoring, storing, and accessing log files from AWS resources like EC2 or Lambda, but it does not natively capture S3 access logs without additional configuration (e.g., using S3 event notifications to push logs to CloudWatch). Option C is wrong because S3 Inventory provides a list of objects and their metadata (e.g., size, encryption status) for compliance and lifecycle management, but it does not log access requests or actions performed on the bucket. Option D is wrong because AWS CloudTrail records management events (e.g., bucket creation, policy changes) and data events (e.g., GetObject, PutObject) for S3, but it is not the primary feature for detailed, request-level logging; S3 server access logging is the dedicated feature for granular access logs, while CloudTrail is often used for governance and compliance at a higher level.

133
Multi-Selecthard

A developer needs to securely distribute temporary AWS credentials to authenticated mobile users. Which two components are commonly involved?

Select 2 answers
A.Amazon Cognito identity pools
B.AWS root access keys
C.IAM roles with scoped permissions
D.An unrestricted S3 bucket policy
AnswersA, C

Amazon Cognito identity pools are specifically designed to provide temporary, limited-privilege AWS credentials to users authenticated through various identity providers, including Cognito User Pools, social logins, or SAML. Upon successful authentication, an identity pool exchanges the user's token for a set of temporary AWS credentials, allowing mobile or web applications to directly access specified AWS services with fine-grained permissions defined by an associated IAM role. This mechanism ensures secure, temporary access without embedding long-lived credentials in client applications.

Why this answer

Amazon Cognito identity pools allow you to exchange identity tokens (from a user pool or external IdP) for temporary AWS credentials via the AWS Security Token Service (STS). These credentials are scoped to an IAM role with fine-grained permissions, enabling secure, least-privilege access to AWS resources from mobile apps without embedding long-term keys.

Exam trap

The trap here is that candidates confuse Cognito user pools (which handle authentication and issue JWTs) with identity pools (which provide temporary AWS credentials), or mistakenly think root keys or open bucket policies are acceptable for mobile distribution.

134
MCQhard

A Lambda function needs to read from a DynamoDB table and send messages to an SQS queue. The function's IAM role should follow the principle of least privilege. Which policy statement should be attached to the role?

A.{"Effect":"Allow","Action":["dynamodb:*"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}
B.{"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}
C.{"Effect":"Allow","Action":["dynamodb:GetItem","sqs:SendMessage","sqs:ReceiveMessage"],"Resource":"*"}
D.{"Effect":"Allow","Action":["dynamodb:GetItem","dynamodb:PutItem"],"Resource":"*"}
AnswerB

This policy correctly applies the principle of least privilege by granting only the "dynamodb:GetItem" action, which is necessary for reading data from the specified DynamoDB table. Additionally, it provides the "sqs:SendMessage" action, which is precisely what the Lambda function requires to interact with the designated SQS queue. Each permission is scoped to its specific resource, ensuring minimal access.

Why this answer

Option B is correct because it grants only the specific DynamoDB read action (GetItem) needed to read from the table and the specific SQS write action (SendMessage) needed to send messages to the queue, scoped to the exact resource ARNs. This adheres to the principle of least privilege by not allowing any unnecessary operations or resources. Wrapping the statements in an array makes the policy snippet syntactically valid.

Exam trap

The trap here is that candidates often choose a wildcard resource or overly broad actions (like dynamodb:* or sqs:*) because they think it's simpler, failing to recognize that the principle of least privilege requires scoping both actions and resources to the minimum necessary.

How to eliminate wrong answers

Option A is wrong because it grants all DynamoDB actions (dynamodb:*) on the table, which includes write, delete, and administrative operations far beyond the required read-only access. Option C is wrong because it uses a wildcard resource (*) for both DynamoDB and SQS, which would allow access to any table or queue in the account, violating least privilege. Option D is wrong because it includes dynamodb:PutItem (a write action) that is not needed, and also uses a wildcard resource (*) instead of restricting to the specific table ARN.

135
MCQeasy

A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which IAM policy statement should be attached?

A.{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}
B.{"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::my-bucket","arn:aws:s3:::my-bucket/*"]}
C.{"Effect":"Deny","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}
D.{"Effect":"Allow","Action":["s3:PutObject","s3:DeleteObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerB

Pairing s3:ListBucket with the bucket-level ARN and s3:GetObject with the object-level wildcard ARN correctly grants exactly the two actions needed for read-only access: enumerating the bucket's contents and downloading individual objects, while granting no write or delete permissions on either the bucket or its objects.

Why this answer

It grants read-only access by allowing the `s3:GetObject` action (to read objects) and the `s3:ListBucket` action (to list objects in the bucket). The resources are correctly specified: `arn:aws:s3:::my-bucket` for the bucket-level `ListBucket` action and `arn:aws:s3:::my-bucket/*` for the object-level `GetObject` action. This combination provides the minimal permissions needed for read-only access without allowing write or delete operations.

Exam trap

The trap here is that candidates often forget to include both the bucket ARN and the object ARN, or they mistakenly use a single ARN like `arn:aws:s3:::my-bucket/*` for both actions, which would fail for `s3:ListBucket` because it requires the bucket-level ARN.

How to eliminate wrong answers

Option A is wrong because it allows all S3 actions (`s3:*`) on the bucket, which grants full administrative access, not read-only. Option C is wrong because it uses a `Deny` effect on `s3:GetObject`, which explicitly blocks read access, the opposite of what is needed. Option D is wrong because it allows `s3:PutObject` and `s3:DeleteObject`, which are write and delete operations, not read-only.

136
MCQhard

An application receives webhooks from a partner. The developer must verify that each request was signed by the partner and not modified in transit. What should the application validate?

A.The source port number
B.The CloudWatch log stream name
C.The HMAC or digital signature over the payload using the shared/public key material
D.The API Gateway request ID only
AnswerC

An HMAC (Hash-based Message Authentication Code) or a digital signature provides cryptographic proof of both the sender's identity (authentication) and the message's integrity (non-tampering). The sender computes this value over the webhook payload using either a shared secret key (for HMAC) or their private key (for a digital signature). The receiver then independently computes the expected value using the same shared secret or the sender's public key, verifying that the request originated from the legitimate partner and that the data has not been altered in transit.

Why this answer

Webhook verification relies on validating a cryptographic signature (HMAC or digital signature) computed over the request payload using a pre-shared secret or public key. This ensures the payload was signed by the partner and has not been tampered with during transit, as any modification would invalidate the signature. The application must recompute the HMAC or verify the digital signature using the partner's public key and compare it to the signature provided in the request header.

Exam trap

The trap here is that candidates confuse request metadata (like source port or request ID) with cryptographic verification mechanisms, assuming any unique identifier can prove authenticity, when only HMAC or digital signatures provide integrity and sender verification.

How to eliminate wrong answers

Option A is wrong because the source port number is a transient network-layer attribute that can be spoofed or changed by NAT/firewalls, and it provides no cryptographic proof of authenticity or integrity. Option B is wrong because a CloudWatch log stream name is an AWS-specific logging resource identifier unrelated to request signing or payload integrity verification. Option D is wrong because an API Gateway request ID is a unique identifier for debugging and tracing, not a cryptographic mechanism to verify the sender's identity or detect payload tampering.

137
MCQhard

A developer wants to enforce that all requests to an Amazon S3 bucket must use HTTPS (TLS). The bucket is used for static website hosting. Which bucket policy condition should be used to deny requests that do not use HTTPS?

A."aws:SecureTransport": "false"
B."aws:SecureTransport": "true"
C."aws:SourceVpc": "true"
D."aws:Referer": "https"
AnswerA

This option correctly enforces HTTPS. When used in a Deny statement within an S3 bucket policy, the condition `"aws:SecureTransport": "false"` explicitly blocks any request that is *not* using HTTPS. By denying all unencrypted requests, the policy effectively mandates that all successful interactions with the S3 bucket must utilize HTTPS (TLS) for data in transit, ensuring secure communication.

Why this answer

The `aws:SecureTransport` condition key evaluates to `false` when the request is not sent over HTTPS (TLS). By using a Deny effect with this condition set to `false`, the policy blocks any HTTP requests to the S3 bucket, ensuring all traffic uses encrypted connections. This is a standard approach for enforcing TLS on S3 buckets, including those used for static website hosting.

Exam trap

The trap here is that candidates often confuse `aws:SecureTransport` with `aws:SourceVpc` or `aws:Referer`, or mistakenly think setting the condition to `true` in a Deny statement will block non-HTTPS traffic, when in fact it would block HTTPS traffic instead.

How to eliminate wrong answers

Option B is wrong because setting `aws:SecureTransport` to `true` would allow only HTTPS requests, but the question requires denying non-HTTPS requests; a Deny policy with `true` would block HTTPS traffic, which is the opposite of the desired outcome. Option C is wrong because `aws:SourceVpc` is used to restrict requests to those originating from a specific VPC, not to enforce HTTPS; setting it to `true` is invalid as this condition key expects a VPC ID, not a boolean. Option D is wrong because `aws:Referer` is used to restrict requests based on the HTTP Referer header (e.g., to prevent hotlinking), not to enforce HTTPS; the value `https` is a protocol scheme, not a valid referer pattern, and this condition does not check transport security.

138
MCQmedium

A developer needs to call AWS APIs from application code running on EC2. Which credential source should the AWS SDK use by default?

A.Static credentials committed to Git
B.A credentials file copied into the AMI
C.The root account access key
D.Temporary credentials from the instance profile role
AnswerD

Attaching an IAM role to an EC2 instance via an instance profile is the recommended and most secure method for granting AWS API access to applications running on that instance. This mechanism automatically provides temporary, frequently rotated credentials to the instance metadata service, which applications can retrieve without needing to store any long-term static keys. This significantly enhances security, simplifies credential management, and adheres to the principle of least privilege by allowing granular permissions.

Why this answer

The AWS SDK on EC2 automatically retrieves temporary credentials from the instance metadata service (IMDS) at http://169.254.169.254/latest/meta-data/iam/security-credentials/. These credentials are provided by the IAM role attached to the EC2 instance (the instance profile role) and are rotated automatically, eliminating the need to store long-term credentials on the instance.

Exam trap

The trap here is that candidates may think manually embedding credentials (via a file or environment variable) is acceptable, but the AWS SDK on EC2 is designed to use the instance profile role by default, and any static credential source is both insecure and not the default behavior.

How to eliminate wrong answers

Option A is wrong because committing static credentials to Git is a severe security risk and violates AWS best practices; the SDK does not default to Git-stored credentials. Option B is wrong because copying a credentials file into the AMI embeds long-term credentials in the image, which can be exposed if the AMI is shared or reused, and the SDK does not default to an AMI-embedded file. Option C is wrong because root account access keys are highly privileged, static, and should never be used in application code; the SDK does not default to root keys.

139
MCQhard

A developer is deploying an application on Amazon ECS with Fargate. The application needs to access an S3 bucket that contains sensitive data. The developer wants to avoid storing AWS credentials in the container image. What is the MOST secure way to grant the application access to the S3 bucket?

A.Create an IAM task role with a policy that allows S3 access and specify it in the task definition.
B.Set the AWS credentials as environment variables in the task definition.
C.Store the credentials in an EFS volume and mount it to the container.
D.Use an IAM instance profile attached to the underlying EC2 instance.
AnswerA

An ECS task IAM role, specified in the task definition, causes the ECS agent to inject temporary, automatically-rotated credentials into the container via the task metadata endpoint, so the application's SDK picks up scoped S3 permissions without any long-lived secret ever being stored or configured.

Why this answer

An IAM task role for ECS tasks allows the container to assume the role without storing credentials. Option B is wrong because environment variables are not secure. Option C is wrong because mounting credentials in a volume is insecure.

Option D is wrong because IAM instance profiles are for EC2 instances, not Fargate tasks.

140
MCQeasy

A developer needs to grant an IAM user in Account A access to an S3 bucket in Account B. What is the correct combination of policies?

A.An S3 bucket policy in Account B that allows the IAM user's ARN.
B.An IAM policy in Account A allowing access to the S3 bucket, and a bucket policy in Account B allowing the IAM user.
C.An IAM policy in Account A allowing access, and a bucket ACL in Account B granting access to the IAM user.
D.Create an IAM role in Account B that the user can assume, and attach a bucket policy allowing the role.
AnswerB

This is the correct and most direct combination for granting cross-account S3 access to an IAM user. The IAM policy attached to the user in Account A provides the necessary identity-based permissions for the user to initiate S3 actions. Concurrently, the S3 bucket policy in Account B, a resource-based policy, explicitly grants permission to the specific IAM user's ARN from Account A, overriding the default deny for cross-account access. Both policies must grant permission for the request to be authorized successfully.

Why this answer

Cross-account S3 access requires two policies: an IAM policy in the source account (Account A) granting the user permission to perform S3 actions on the bucket, and a bucket policy in the target account (Account B) that explicitly allows the IAM user's ARN. The bucket policy acts as a resource-based policy that delegates access to the external principal, while the IAM policy authorizes the user to make the request. Without both, the request will be denied by either the source account's implicit deny or the target account's default deny.

Exam trap

The trap here is that candidates often think a bucket policy alone is sufficient for cross-account access (Option A), forgetting that the IAM user's own account must also explicitly authorize the action through an IAM policy.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy alone in Account B that allows the IAM user's ARN is insufficient — the IAM user in Account A still needs an IAM policy that explicitly grants permission to perform the S3 action, otherwise the request is denied by the source account's implicit deny. Option C is wrong because bucket ACLs do not support granting access to IAM users from another AWS account; ACLs only support AWS accounts or predefined groups, not individual IAM user ARNs. Option D is wrong because while creating an IAM role in Account B and allowing the user to assume it is a valid cross-account access pattern, the question specifically asks for granting access to an IAM user directly, not via role assumption; additionally, the bucket policy would need to allow the role's ARN, not the user's ARN, making this a different mechanism than what the question describes.

141
MCQhard

A company uses a customer managed AWS KMS key to encrypt sensitive data stored in DynamoDB. A Lambda function reads from the DynamoDB table and needs to decrypt the data. The Lambda function's execution role has an IAM policy that allows kms:Decrypt on the key. However, access is denied. What must the developer add to the KMS key policy to resolve the issue?

A.Add a statement granting kms:Decrypt to the Lambda function's execution role.
B.Add a statement granting kms:Decrypt to the Lambda function's resource-based policy.
C.Add a statement granting kms:Decrypt to the Lambda service principal.
D.Add a statement granting kms:Decrypt to the account root user with a condition for the Lambda function.
AnswerA

When a Lambda function needs to interact with a customer-managed AWS KMS key, the key policy associated with that KMS key must explicitly grant permissions to the entity making the request. The Lambda function assumes an IAM execution role, and it is this role that makes API calls to KMS. Therefore, the KMS key policy must include a statement allowing the kms:Decrypt action for the specific ARN of the Lambda function's execution role, ensuring direct access control and adherence to the principle of least privilege.

Why this answer

KMS key policies are resource-based policies that control access to the key itself. Even if the Lambda execution role has an IAM policy granting kms:Decrypt, the KMS key policy must explicitly allow the role (or the user/account) to perform that action. Without this statement in the key policy, the IAM permission is ineffective, resulting in an access denied error.

Exam trap

The trap here is that candidates often assume IAM permissions alone are sufficient for KMS operations, forgetting that KMS key policies act as an additional layer of access control that must explicitly allow the principal.

How to eliminate wrong answers

Option B is wrong because Lambda functions do not have resource-based policies that can grant KMS permissions; KMS actions must be authorized via the key policy or IAM, not a Lambda resource policy. Option C is wrong because granting kms:Decrypt to the Lambda service principal would allow any Lambda function in the account to decrypt using the key, which is overly permissive and not the correct way to grant access to a specific function. Option D is wrong because granting kms:Decrypt to the account root user with a condition for the Lambda function is unnecessarily complex and not a standard pattern; the root user already has full control over the key, and conditions cannot directly reference a Lambda function's identity in a reliable way.

142
MCQhard

A company uses an AWS Lambda function to process files uploaded to an S3 bucket. The Lambda function needs to read the files and write results to a DynamoDB table. The Lambda function is configured with an IAM role that has policies allowing s3:GetObject on the bucket and dynamodb:PutItem on the table. Despite correct permissions, the function fails with an AccessDenied error when trying to put items. What is the most likely cause?

A.The Lambda function is in a VPC without a VPC endpoint for DynamoDB.
B.The DynamoDB table has a resource-based policy that explicitly denies access to the Lambda function's IAM role.
C.The S3 bucket is in a different region, causing cross-region access issues.
D.The DynamoDB table is encrypted with a customer managed KMS key, and the Lambda role does not have kms:Decrypt permission.
AnswerB

AWS evaluates both identity-based policies (attached to the Lambda function's IAM role) and resource-based policies (attached directly to the DynamoDB table) to determine access. An explicit "Deny" statement in *any* applicable policy, including a resource-based policy, always takes precedence over any "Allow" statements. Therefore, even if the Lambda role has an "Allow" policy, an explicit "Deny" on the DynamoDB table itself will result in an "AccessDenied" error.

Why this answer

DynamoDB tables can have resource-based policies that explicitly deny access even if the IAM role has the necessary permissions. Since explicit denies in resource-based policies override any allow in identity-based policies, the Lambda function's IAM role with dynamodb:PutItem permission is still blocked, causing the AccessDenied error.

Exam trap

The trap here is that candidates often assume IAM role permissions alone guarantee access, forgetting that resource-based policies on DynamoDB tables can explicitly deny access, which overrides any allow in identity-based policies.

How to eliminate wrong answers

Option A is wrong because a Lambda function in a VPC without a VPC endpoint for DynamoDB would cause a network timeout or connectivity error, not an AccessDenied error, as DynamoDB calls go over HTTPS and the error would be a timeout or connection failure, not an IAM permission denial. Option C is wrong because S3 and DynamoDB are both global services; cross-region access is fully supported and does not cause AccessDenied errors—the error would be a different type like a timeout or throttling if there were latency issues. Option D is wrong because while KMS permissions are needed for encrypted tables, the error message would be a KMS AccessDenied or a 400 error, not a generic AccessDenied on PutItem, and the question states the function fails specifically when trying to put items, not during encryption/decryption.

143
Multi-Selectmedium

A developer is using AWS Lambda and needs to ensure that the function can access an RDS database securely. Which THREE steps should be taken?

Select 3 answers
A.Place the Lambda function inside a VPC.
B.Store the database credentials in AWS Secrets Manager and retrieve them in the Lambda code.
C.Attach an IAM role to the Lambda function that grants rds:* permissions.
D.Configure the RDS instance to require client certificates.
E.Configure the security group of the RDS instance to allow inbound traffic from the Lambda function's security group.
AnswersA, B, E

By default, Lambda functions run in an AWS-owned VPC and cannot connect to resources in your private subnets. Attaching the function to the same VPC provisions elastic network interfaces in your subnets, giving it private IP connectivity to the RDS instance. This is the foundational step required before any TCP connection to RDS can be established.

Why this answer

Option A is correct because a Lambda function can only reach an RDS instance that resides in a VPC if the function itself is configured with VPC connectivity (subnets and a security group), which is required for private network access to the database. Option B is correct because hardcoding credentials is insecure; storing them in AWS Secrets Manager and retrieving them at runtime (optionally with Lambda's Secrets Manager extension/caching) keeps the database password encrypted and rotatable. Option E is correct because RDS access is controlled by security group rules, so the RDS instance's security group must allow inbound traffic on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL) referencing the Lambda function's security group as the source.

Option C is not appropriate because rds:* IAM permissions govern the RDS control plane API, not the ability to open a database connection, and Lambda's execution role does not grant network access to RDS. Option D is not required for this scenario; client certificate authentication is an optional RDS TLS feature and is not one of the standard steps to let Lambda connect securely.

Exam trap

DVA-C02 often tests the misconception that IAM permissions alone are sufficient for Lambda-to-RDS access, ignoring the need for VPC networking and security group rules.

144
MCQmedium

A developer is using Amazon API Gateway with a Lambda authorizer to secure a REST API. The developer wants to pass user context from the authorizer to the backend Lambda function. How should the developer accomplish this?

A.Include the user context in the principal identifier returned by the authorizer.
B.Encode the user context in the authorization token.
C.Use a custom header that maps to a resource path parameter.
D.Return a context object from the Lambda authorizer that maps to integration request parameters.
AnswerD

The Lambda authorizer's output includes an optional `context` object, which is a key-value map designed specifically for passing arbitrary, trusted information to the backend integration. API Gateway automatically makes the properties within this `context` object available for mapping to various integration request parameters, such as HTTP headers, query string parameters, or even parts of the request body. This mechanism ensures that validated user context, like user ID or roles, is securely and explicitly delivered to the downstream service.

Why this answer

The Lambda authorizer can return a context object alongside the IAM policy. This context object can be mapped to integration request parameters (such as headers or path parameters) using API Gateway's mapping templates or passthrough behavior. The backend function then receives the user context via those parameters.

Option D is correct because returning a context object from the authorizer and mapping it to integration request parameters is the standard method. Option A is incorrect because the principal identifier is a single field, not suitable for passing multiple context values. Option B is incorrect because the authorization token is the input to the authorizer, not the output.

Option C is incorrect because custom headers are not automatically mapped to resource path parameters; such a mapping would not pass user context from the authorizer.

145
MCQhard

A developer needs to grant a user in another AWS account (Account B) read-only access to objects in an Amazon S3 bucket owned by Account A. The developer has already added a bucket policy that grants s3:GetObject access to the IAM user in Account B. However, the user in Account B still gets Access Denied when trying to read objects. What additional configuration is required?

A.The user in Account B must have an IAM policy that allows s3:GetObject on the bucket ARN
B.The bucket must be made public by unchecking 'Block all public access'
C.The developer must create a new IAM role in Account A and have the user in Account B assume that role
D.The user in Account B must use the S3 console instead of the AWS CLI
AnswerA

Cross-account access requires both a bucket policy that grants the user permissions and an IAM policy in the user's account that allows the action. The IAM policy is necessary because the default is to deny all actions.

Why this answer

The bucket policy in Account A grants s3:GetObject access to the IAM user in Account B, but this alone is insufficient. For cross-account access, the IAM user in Account B must also have an IAM policy attached that explicitly allows s3:GetObject on the bucket ARN. Without this, the user’s own account denies the request before it reaches Account A’s bucket policy, resulting in Access Denied.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, overlooking the requirement for an explicit IAM policy in the requesting account to allow the action.

How to eliminate wrong answers

Option B is wrong because making the bucket public by unchecking 'Block all public access' would grant anonymous access to everyone, which violates the principle of least privilege and is not required for a specific cross-account user. Option C is wrong because while creating an IAM role in Account A and having the user in Account B assume it is a valid alternative approach, it is not the additional configuration required here—the developer has already chosen a bucket policy approach, and the missing piece is the IAM policy in Account B. Option D is wrong because the S3 console and AWS CLI both enforce the same IAM permissions; the issue is a lack of permissions, not the tool used.

146
Multi-Selectmedium

A company is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. Which permissions are required for the CodeBuild service role? (Choose THREE.)

Select 3 answers
A.ecr:PutImage
B.ecr:DescribeRepositories
C.ecr:CreateImage
D.ecr:BatchGetImage
E.ecr:GetAuthorizationToken
AnswersA, B, E

The `ecr:PutImage` permission is absolutely essential for CodeBuild to successfully publish a Docker image to an Amazon ECR repository. This API call is responsible for uploading the Docker image manifest and all its associated image layers, effectively registering the new image version within the specified repository and making it available for subsequent deployments or pulls.

Why this answer

`ecr:PutImage` is the permission required to push a Docker image to an Amazon ECR repository. When CodeBuild completes a build and runs `docker push`, it calls the ECR API `PutImage` to upload the image manifest. Without this permission, the push operation will fail with an access denied error.

Exam trap

The trap here is that candidates may confuse `ecr:PutImage` with the non-existent `ecr:CreateImage` or mistakenly think `ecr:BatchGetImage` is needed for pushing, when in fact it is only used for pulling images.

147
MCQeasy

A developer stores database credentials for an application running on Amazon EC2. The security team requires that the credentials be automatically rotated every 30 days to reduce the risk of compromise. Which AWS service should the developer use to store and automatically rotate the credentials?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.IAM Roles for EC2
AnswerB

AWS Secrets Manager is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It provides native, automatic rotation capabilities for various services, including Amazon RDS, Amazon Redshift, and Amazon DocumentDB, with configurable schedules (e.g., every 30 days). This eliminates the need for manual rotation or complex custom solutions, significantly enhancing security posture by regularly changing credentials.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store database credentials and other secrets, and it provides built-in, configurable automatic rotation (e.g., every 30 days) using AWS Lambda. This meets the security team's requirement without custom scripting or infrastructure management.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store for its lower cost or familiarity, despite the explicit rotation requirement.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store can store credentials but does not natively support automatic rotation; rotation would require custom automation with Lambda or other services, making it less suitable for this requirement. Option C is wrong because AWS Key Management Service (KMS) is a key management service for encryption keys, not for storing or rotating database credentials; it can encrypt secrets but does not manage rotation of the credentials themselves. Option D is wrong because IAM Roles for EC2 provide temporary credentials for AWS API access, not for storing or rotating database credentials; they cannot be used to store or rotate application-level database passwords.

148
Multi-Selectmedium

Which TWO are best practices for securing an AWS account? (Choose 2)

Select 2 answers
A.Disable AWS CloudTrail to reduce costs
B.Disable password rotation to avoid user inconvenience
C.Use the root user for daily administrative tasks
D.Enable multi-factor authentication (MFA) for privileged users
E.Use IAM roles for applications that run on EC2 instances
AnswersD, E

MFA adds a second authentication factor, such as a time-based one-time password (TOTP) from a hardware or virtual device, significantly reducing the risk of unauthorized access even if a password is compromised. For privileged users with access to sensitive resources, MFA is a critical control defined in the AWS Well-Architected Framework. It protects against credential theft and phishing attacks.

Why this answer

The best practices for securing an AWS account include enabling multi-factor authentication (MFA) for privileged users (Option D) and using IAM roles for applications that run on EC2 instances (Option E). Option A is incorrect because disabling CloudTrail reduces visibility into API activity, which is a security risk. Option B is incorrect because disabling password rotation weakens security posture.

Option C is incorrect because the root user should be reserved for a limited set of tasks and not used daily.

Exam trap

This question tests knowledge of AWS security best practices. A common trap is to assume that disabling CloudTrail saves costs without considering security implications, or that password rotation should be disabled for convenience.

149
MCQeasy

A developer is building a serverless application using AWS Lambda. The Lambda function needs to write logs to CloudWatch Logs. What is the recommended way to grant the necessary permissions?

A.Use AWS KMS to encrypt the log data and grant permissions.
B.Attach an IAM execution role with CloudWatch Logs permissions.
C.Create a resource-based policy on the Lambda function.
D.Store AWS access keys in environment variables.
AnswerB

Attaching an IAM execution role to the Lambda function is the standard and most secure method for granting it permissions to interact with other AWS services. When the Lambda function executes, it assumes this role, which dictates its authorized actions. To enable the function to write logs to CloudWatch, the attached IAM role must include policies explicitly granting permissions such as `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents`.

Why this answer

AWS Lambda uses an IAM execution role to obtain temporary credentials for accessing other AWS services. To allow a Lambda function to write logs to CloudWatch Logs, you must attach an IAM role with a policy that includes permissions for the `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` actions. This is the standard and recommended security practice for granting permissions to Lambda functions.

Exam trap

The trap here is that candidates often confuse resource-based policies (which control who can invoke the function) with execution roles (which control what the function can do), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because AWS KMS is used for encryption key management, not for granting permissions; it does not provide IAM-level access control for writing logs. Option C is wrong because resource-based policies on a Lambda function control who can invoke the function, not what the function itself can do (like writing to CloudWatch Logs); permissions for the function's actions are defined in its execution role. Option D is wrong because storing AWS access keys in environment variables is a security anti-pattern; Lambda should never use long-term credentials, and instead relies on the IAM execution role to provide temporary, automatically rotated credentials.

150
MCQmedium

An application running on an EC2 instance needs to access a DynamoDB table. The instance is in a private subnet without internet access. Which method should be used to grant the instance access to DynamoDB securely?

A.Store AWS credentials in a file on the instance and use them in the application
B.Configure security group rules to allow outbound traffic to DynamoDB
C.Attach a NAT gateway to the private subnet and use IAM user credentials
D.Create a VPC endpoint for DynamoDB and attach an IAM role to the instance
AnswerD

Creating a VPC endpoint for DynamoDB establishes a private, secure connection directly from the VPC to the DynamoDB service, bypassing the public internet and enhancing data security and network performance. Concurrently, attaching an IAM role to the EC2 instance provides temporary, automatically rotated credentials that the application can assume, adhering to the principle of least privilege and eliminating the need to store static credentials on the instance. This combination offers both secure network access and robust authentication.

Why this answer

A VPC Gateway Endpoint for DynamoDB allows EC2 instances in a private subnet to access DynamoDB without traversing the internet or requiring a NAT gateway. By attaching an IAM role to the EC2 instance, the application can securely obtain temporary credentials via the instance metadata service, eliminating the need to store long-term credentials on the instance.

Exam trap

The trap here is that candidates often confuse security groups with network routing, assuming that allowing outbound traffic to DynamoDB's IP range is sufficient, but without a VPC endpoint or internet gateway, the traffic has no route to reach the DynamoDB service.

How to eliminate wrong answers

Option A is wrong because storing AWS credentials in a file on the instance is a security risk and violates the principle of least privilege; it also requires managing long-term keys, which can be rotated or compromised. Option B is wrong because security groups control network traffic at the instance level, but DynamoDB is a managed service outside the VPC; without a VPC endpoint or internet access, security group rules alone cannot route traffic to DynamoDB. Option C is wrong because a NAT gateway would provide internet access, but it introduces additional cost and complexity, and using IAM user credentials on the instance still requires managing long-term keys; the recommended approach is to use an IAM role with a VPC endpoint.

← PreviousPage 2 of 5 · 314 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.