Courseiva

CCNA Security Questions

75 of 314 questions · Page 4/5 · Security · Answers revealed

226
MCQmedium

A developer needs to encrypt secrets such as database passwords used by an application running on EC2. Which AWS service should be used to securely store and rotate these secrets?

A.AWS CloudHSM
B.AWS Secrets Manager
C.AWS KMS
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving various types of secrets, including database credentials, API keys, and other sensitive data. Its key feature is native integration with services like Amazon RDS, enabling automatic rotation of database passwords on a schedule or on demand. This capability is crucial for enhancing security posture and meeting compliance requirements by regularly changing sensitive credentials.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate secrets such as database passwords, API keys, and other credentials. It integrates natively with AWS services like RDS, Redshift, and DocumentDB to enable automatic rotation of secrets without custom code, and it enforces encryption at rest using AWS KMS. This makes it the ideal service for the use case described, where secrets must be both stored securely and rotated automatically.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation, which is the key requirement in this question.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules for cryptographic key storage and operations, but it does not offer a managed service for storing or rotating secrets like database passwords; it is a lower-level key management solution. Option C is wrong because AWS KMS is a key management service that creates and controls encryption keys used to encrypt data, but it does not store secrets or provide automatic rotation of secrets; it only supports automatic rotation of the KMS key itself, not the secret value. Option D is wrong because AWS Systems Manager Parameter Store can store secrets as SecureString parameters with KMS encryption, but it lacks built-in automatic rotation capabilities; any rotation would require custom implementation using AWS Lambda or other automation.

227
MCQmedium

A developer is deploying a containerized application on Amazon ECS with the Fargate launch type. The application needs to read data from an Amazon S3 bucket. The developer wants to follow the principle of least privilege. How should the developer grant the necessary permissions to the ECS tasks?

A.Store AWS access keys as environment variables in the task definition.
B.Create an IAM task role and reference it in the task definition using the 'taskRoleArn' parameter.
C.Create an IAM user and embed its credentials in the container image.
D.Use an S3 bucket policy that grants access based on the security group of the ECS tasks.
AnswerB

Creating an IAM task role and referencing it via the 'taskRoleArn' parameter in the task definition is the recommended and most secure method for granting AWS permissions to containers. ECS automatically injects temporary, frequently rotated credentials into the container's metadata service. This allows applications using the AWS SDK to seamlessly assume the role and access AWS resources without hardcoding any credentials, adhering to the principle of least privilege and secure credential management.

Why this answer

Amazon ECS with the Fargate launch type supports IAM task roles, which allow you to assign an IAM role to the ECS task itself. By referencing the IAM task role in the task definition using the 'taskRoleArn' parameter, the containerized application can securely obtain temporary credentials from the ECS container agent via the AWS STS service, adhering to the principle of least privilege without embedding long-lived credentials.

Exam trap

The trap here is that candidates may confuse IAM roles with IAM users or think that network-level controls like security groups can be used for S3 access, but AWS S3 does not evaluate security groups for authorization; only IAM policies and bucket policies are evaluated.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys as environment variables in the task definition exposes long-term credentials in plaintext, violating the principle of least privilege and increasing the risk of credential leakage. Option C is wrong because embedding IAM user credentials in the container image is a security anti-pattern that hardcodes long-lived secrets, making rotation difficult and violating best practices for container security. Option D is wrong because S3 bucket policies cannot grant permissions based on security groups; security groups are network-level constructs for EC2 instances and are not evaluated by AWS S3 for access control decisions.

228
MCQmedium

A developer needs to allow an EC2 instance to read objects from a specific S3 bucket. Which is the MOST secure way to grant permissions?

A.Store AWS access keys in the EC2 instance's user data
B.Use an S3 bucket policy that allows access from the EC2 instance's public IP
C.Create an IAM role with S3 read permission and attach it to the EC2 instance as an instance profile
D.Attach a security group to the EC2 instance that allows S3 access
AnswerC

This is the secure and recommended method. An IAM role, configured with a trust policy allowing the EC2 service to assume it, grants temporary, frequently rotated credentials to the EC2 instance. By attaching this role via an instance profile, the EC2 instance can make API calls to S3 using these temporary credentials, inheriting the S3 read permissions defined in the role's policy without ever storing static access keys on the instance. This approach adheres to the principle of least privilege and enhances security significantly.

Why this answer

Creating an IAM role with S3 read permission and attaching it to the EC2 instance as an instance profile is the most secure way because it provides temporary, automatically rotated credentials to the instance without storing any long-term secrets. The instance profile delivers credentials via the EC2 instance metadata service (IMDS), and the role's policy can be scoped to only the specific S3 bucket and read actions needed. This eliminates the risk of leaked access keys.

Exam trap

DVA-C02 often tests the misconception that security groups or bucket policies based on IP can grant S3 access — candidates pick those because they sound like network-level controls, but IAM roles with instance profiles are the only secure, credential-free method.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys in user data embeds long-lived credentials in the instance, which are visible in the console and metadata, and cannot be rotated automatically — a major security risk. Option B is wrong because allowing access based on the EC2 instance's public IP is unreliable (IPs change) and insecure (any resource with that IP could access the bucket), and it does not authenticate the instance identity. Option D is wrong because security groups control network traffic (ports/protocols), not IAM permissions — a security group cannot grant S3 read access, and S3 access is authorized by IAM, not network rules.

229
MCQeasy

A developer is creating an IAM policy to allow an EC2 instance to access an S3 bucket. Which AWS service should the developer use to securely provide credentials to the EC2 instance?

A.Use Amazon Cognito identity pools to generate temporary credentials for the instance.
B.Create an IAM user with access keys and store them on the instance.
C.Create an IAM role and attach it to the EC2 instance profile.
D.Store the AWS access key in AWS Secrets Manager and retrieve it at runtime.
AnswerC

Creating an IAM role and attaching it to an EC2 instance profile is the secure and recommended best practice for granting AWS permissions to an EC2 instance. The instance profile acts as a container for the IAM role, allowing the instance to assume the role and obtain temporary, automatically rotated credentials. These credentials are securely provided through the EC2 instance metadata service, eliminating the need to store static access keys on the instance itself.

Why this answer

IAM roles are designed to be assumed by AWS services like EC2. Instance profiles deliver temporary credentials to the EC2 instance automatically, avoiding hard-coded keys. Option A is incorrect because Cognito identity pools are intended for user identity in mobile/web apps, not for EC2 instances.

Option B is incorrect because storing IAM user access keys on the instance is insecure and not recommended. Option D is incorrect because AWS Secrets Manager is for managing secrets such as database credentials, not for providing credentials to EC2 instances. Option C is the correct approach: create an IAM role with the necessary S3 permissions and attach it to the EC2 instance profile.

230
MCQmedium

Refer to the exhibit. A developer created an IAM role for a Lambda function. When the Lambda function invokes, it fails with an access denied error when trying to write logs to CloudWatch Logs. What is the most likely cause?

A.The trust policy does not allow the Lambda service to assume the role.
B.The CloudWatch Logs log group has a resource-based policy that denies the Lambda function.
C.The role lacks a permissions policy that allows CloudWatch Logs actions.
D.The Lambda function is not associated with this role.
AnswerC

The permissions policy attached to an IAM role dictates the specific AWS API actions that the role, once assumed, is authorized to perform. For a Lambda function to successfully send logs to CloudWatch, its execution role must have a permissions policy explicitly allowing actions such as 'logs:CreateLogGroup', 'logs:CreateLogStream', and 'logs:PutLogEvents'. Without these explicit permissions, the function's attempts to interact with CloudWatch Logs will result in an "Access Denied" error, even if the role itself was successfully assumed.

Why this answer

The Lambda function's IAM role must include a permissions policy that grants the `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` actions. Without these permissions, the Lambda runtime cannot write logs to CloudWatch Logs, resulting in an access denied error. The error occurs at invocation time when the Lambda service attempts to create or write to the log stream on behalf of the function.

Exam trap

Candidates often confuse trust policies with permissions policies, assuming that if the role is assumed successfully, all subsequent API calls will work. However, the trust policy only governs role assumption, not the actions the role can perform.

How to eliminate wrong answers

Option A is wrong because the trust policy is what allows the Lambda service to assume the role; if it were missing or incorrect, the error would be 'Lambda cannot assume the role' rather than an access denied on CloudWatch Logs writes. Option B is wrong because CloudWatch Logs log groups do not have resource-based policies by default; such policies are optional and typically used for cross-account access, not for denying a function that already has the correct role. Option D is wrong because the question states the developer created the role for the Lambda function, implying the function is associated with it; if it were not associated, the error would be about missing execution role or permissions, not specifically CloudWatch Logs access denied.

231
MCQmedium

A developer launches an Amazon EC2 instance that needs to read and write data to an Amazon DynamoDB table. The developer must follow the principle of least privilege and ensure that no long-term credentials are stored on the instance. Which approach should the developer use?

A.Create an IAM user with programmatic access, store the access key and secret key in a configuration file on the EC2 instance.
B.Store the DynamoDB credentials in AWS Systems Manager Parameter Store as a SecureString, and retrieve them from the EC2 instance at runtime.
C.Create an IAM role with the necessary DynamoDB permissions, and attach the role to the EC2 instance profile. The SDK will automatically retrieve temporary credentials from the instance metadata.
D.Use a Lambda function to generate temporary credentials for the EC2 instance and pass them via user data at launch.
AnswerC

This is the recommended and most secure method. By attaching an IAM role to the EC2 instance profile, the instance is granted temporary, frequently rotated credentials via the Instance Metadata Service (IMDS). AWS SDKs and CLIs automatically query IMDS for these credentials, eliminating the need to store any long-term access keys directly on the instance. This significantly reduces the attack surface and simplifies credential management.

Why this answer

It uses an IAM role attached to the EC2 instance profile, which allows the AWS SDK to automatically retrieve temporary credentials from the instance metadata service (IMDS). This follows the principle of least privilege by granting only the necessary DynamoDB permissions and eliminates the need to store any long-term credentials on the instance, as the credentials are rotated automatically by AWS STS.

Exam trap

The trap here is that candidates may choose Option B (Parameter Store) thinking it securely stores credentials, but they overlook that the instance still needs an IAM role to access Parameter Store, and the retrieved credentials are static rather than automatically rotated temporary credentials, which fails the 'no long-term credentials' requirement.

How to eliminate wrong answers

Option A is wrong because storing an IAM user's access key and secret key in a configuration file on the EC2 instance violates the requirement of no long-term credentials on the instance and increases the risk of credential exposure. Option B is wrong because while Parameter Store can securely store credentials, the EC2 instance would still need an IAM role or long-term credentials to retrieve them, and the retrieved credentials (if stored as a SecureString) are static, not temporary, thus not fully meeting the 'no long-term credentials' requirement. Option D is wrong because using a Lambda function to generate temporary credentials and passing them via user data at launch would require the instance to store those credentials locally, and the credentials would not be automatically rotated or refreshed, leading to potential security issues and operational complexity.

232
MCQhard

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The bucket policy also grants access to the role. An application running on the instance is unable to read objects. The instance has the correct instance profile. What is the MOST likely cause?

A.The bucket policy has a condition that does not match the request context.
B.The EC2 instance's security group blocks outbound traffic to S3.
C.The S3 bucket is in a different AWS account.
D.The instance profile is not attached to the EC2 instance.
AnswerA

An S3 bucket policy's conditions evaluate specific attributes of an incoming request, such as source IP, VPC endpoint ID, or specific tags. If any condition in an allow statement is not met, or if a condition in a deny statement *is* met, the request will be implicitly or explicitly denied, respectively. Therefore, even if the IAM role attached to the EC2 instance has the necessary S3 permissions, a mismatch with a restrictive bucket policy condition will prevent access.

Why this answer

The most likely cause is that the bucket policy includes a condition (e.g., aws:SourceIp, aws:SourceVpce, or aws:SecureTransport) that does not match the request context from the EC2 instance. Even though the IAM role grants access, the bucket policy's explicit condition denies the request if the condition key evaluates to false, resulting in an implicit deny. This is a common misconfiguration where the role has permissions but the bucket policy's conditions are too restrictive.

Exam trap

The trap here is that candidates often overlook bucket policy conditions and assume that if the IAM role has S3 permissions and the instance profile is attached, access should work, ignoring that bucket policies can impose additional restrictions that override role permissions.

How to eliminate wrong answers

Option B is wrong because security groups operate at the network layer (stateful filtering) and do not block outbound traffic to S3 by default; S3 uses HTTPS (TCP/443) which is typically allowed, and security groups do not inspect application-layer conditions. Option C is wrong because cross-account access is fully supported with proper IAM roles and bucket policies; the bucket being in a different account would not inherently cause failure if permissions are correctly configured. Option D is wrong because the question explicitly states the instance has the correct instance profile, so the instance profile attachment is not the issue.

233
MCQeasy

What is required for the Lambda function to access the code in the S3 bucket?

A.The S3 bucket policy must grant access to the Lambda service.
B.The Lambda function must be in a VPC with an S3 VPC endpoint.
C.The S3 bucket must be configured as a static website with CloudFront.
D.The Lambda execution role must have s3:GetObject permission on the S3 bucket.
AnswerD

For an AWS Lambda function to successfully retrieve its deployment package, which is stored as an object in an S3 bucket, the function's associated IAM execution role must possess the necessary permissions. Specifically, the s3:GetObject action is required to allow the Lambda service, acting on behalf of the function, to read the code object from the specified S3 bucket. Without this explicit permission, the Lambda service cannot access the code to initialize and execute the function.

Why this answer

To allow a Lambda function to access AWS resources like an S3 bucket during its execution, it must assume an IAM execution role with the appropriate permissions. To read an object from S3, the execution role must have the `s3:GetObject` permission for the target bucket and object path.

Exam trap

Candidates often confuse the permissions needed by the IAM identity creating/updating the Lambda function (which needs access to the deployment package in S3) with the permissions needed by the Lambda execution role itself (which needs access to resources the function interacts with at runtime).

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy granting access to the Lambda service is not sufficient; the Lambda execution role must also have the necessary IAM permissions, and the bucket policy alone does not authorize the Lambda function's principal. Option B is wrong because placing the Lambda function in a VPC with an S3 VPC endpoint is only required when the Lambda function needs to access S3 without traversing the public internet, but it is not a requirement for the Lambda function to access its own code in S3; the default public S3 endpoint works without a VPC. Option C is wrong because configuring the S3 bucket as a static website with CloudFront is unrelated to Lambda's code retrieval; Lambda downloads the deployment package directly from S3 via the S3 API, not through a website or CloudFront.

234
Multi-Selectmedium

A company stores sensitive data in an S3 bucket. The security team requires that all data be encrypted at rest and in transit. Which THREE measures should be implemented?

Select 3 answers
A.Use HTTPS for all requests to S3
B.Enable server-side encryption (SSE) on the S3 bucket
C.Add a bucket policy that denies requests without encryption in transit
D.Use client-side encryption
E.Enable MFA Delete on the bucket
AnswersA, B, C

When accessing S3, using HTTPS (TLS/SSL) encrypts the data as it travels between the client and the S3 service endpoints. This prevents eavesdropping and man-in-the-middle attacks, ensuring the confidentiality and integrity of sensitive data during transmission over public networks. AWS S3 supports HTTPS by default, and it is a fundamental security best practice for protecting data in transit.

Why this answer

HTTPS encrypts data in transit between the client and S3 using TLS, ensuring confidentiality and integrity during transmission. This satisfies the requirement for encryption in transit, as HTTP requests would send data in plaintext.

Exam trap

The trap here is that candidates may confuse client-side encryption as a bucket-level security measure, but it is an application-side implementation that does not enforce encryption at the S3 bucket level, and MFA Delete is a red herring unrelated to encryption requirements.

235
MCQmedium

A developer has an AWS Lambda function that needs to read objects from an S3 bucket in another account. The Lambda function's execution role includes an IAM policy that allows s3:GetObject on the bucket. The bucket owner has added a bucket policy that grants s3:GetObject to the Lambda execution role. However, the Lambda function receives Access Denied errors. The S3 bucket uses SSE-KMS for encryption. What is the most likely cause?

A.The S3 bucket does not have versioning enabled.
B.The Lambda function's execution role does not have an explicit allow for s3:GetObject.
C.The Lambda function is not in the same AWS region as the S3 bucket.
D.The Lambda function does not have kms:Decrypt permission on the KMS key used by the bucket.
AnswerD

When an S3 bucket utilizes Server-Side Encryption with AWS KMS (SSE-KMS) for object encryption, any entity attempting to read those encrypted objects requires two distinct sets of permissions. First, it needs `s3:GetObject` permission on the S3 bucket and object. Second, and critically, the Lambda function's execution role must also have `kms:Decrypt` permission on the specific AWS KMS key used to encrypt the objects. This `kms:Decrypt` permission is granted via the KMS key policy, not the S3 bucket policy, and without it, the Lambda cannot decrypt the object data even if it successfully retrieves the encrypted bytes from S3.

Why this answer

When an S3 bucket uses SSE-KMS, the Lambda function must have explicit kms:Decrypt permission on the KMS key to decrypt the object after s3:GetObject retrieves the encrypted data. Even though the bucket policy and execution role allow s3:GetObject, the missing KMS permission causes an Access Denied error because S3 returns the encrypted object and the Lambda runtime cannot decrypt it without the key.

Exam trap

The trap here is that candidates focus on the S3 bucket policy and IAM role for s3:GetObject, overlooking that SSE-KMS introduces a separate KMS authorization layer that must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because S3 versioning is unrelated to access permissions or KMS decryption; it controls object version retention, not read access. Option B is wrong because the scenario explicitly states the execution role includes an IAM policy that allows s3:GetObject, so an explicit allow exists. Option C is wrong because cross-region access between Lambda and S3 is fully supported; region mismatch does not cause Access Denied errors unless the bucket policy explicitly restricts by source IP or VPC, which is not mentioned.

236
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command to decrypt a file using a KMS key. The command fails with an AccessDeniedException. What is the most likely cause?

A.The IAM user 'DevUser' does not have the kms:Decrypt permission on the KMS key.
B.The ciphertext blob is not base64-encoded.
C.The KMS key is disabled.
D.The KMS key ID is incorrect.
AnswerA

The error message "User: arn:aws:iam::123456789012:user/DevUser is not authorized to perform: kms:Decrypt" explicitly indicates that the IAM principal attempting the operation lacks the necessary kms:Decrypt permission. This typically means either the IAM policy attached to 'DevUser' does not grant kms:Decrypt on the specific KMS key, or the KMS key policy itself does not permit 'DevUser' to perform this action. For a KMS operation to succeed, both the IAM identity's policy and the KMS key's resource policy must explicitly allow the requested action.

Why this answer

An AccessDeniedException indicates that the IAM identity (user or role) making the request lacks the required kms:Decrypt permission on the specified KMS key. KMS key policies and IAM policies must both allow the action for the call to succeed.

Exam trap

Candidates often confuse AccessDeniedException with other KMS errors. For example, a disabled key throws DisabledException, and an invalid or improperly encoded ciphertext throws InvalidCiphertextException. AccessDeniedException specifically points to an authorization/permission issue.

How to eliminate wrong answers

Option B is wrong because the AWS CLI decrypt command automatically handles base64 decoding of the ciphertext blob if the --ciphertext-blob parameter is provided as a file or base64-encoded string; an incorrect encoding would produce a ValidationError, not AccessDeniedException. Option C is wrong because a disabled KMS key would return a DisabledException, not AccessDeniedException. Option D is wrong because an incorrect key ID would result in a NotFoundException or InvalidKeyIdException, not AccessDeniedException.

237
MCQhard

A developer notices that an IAM user has permissions to terminate EC2 instances, but the user should only be allowed to stop instances. The developer needs to update the policy to prevent termination while allowing stop. Which IAM policy statement should be added?

A.{"Effect":"Deny","Action":"ec2:TerminateInstances","Resource":"*"}
B.{"Effect":"Allow","Action":"ec2:TerminateInstances","Resource":"*"}
C.{"Effect":"Allow","Action":["ec2:StopInstances","ec2:TerminateInstances"],"Resource":"*"}
D.{"Effect":"Allow","Action":"ec2:RebootInstances","Resource":"*"}
AnswerA

An explicit Deny statement takes precedence over any Allow, so even if the user's other policies grant ec2:TerminateInstances, this line will effectively block the action. The wildcard resource scopes the denial to all EC2 instances in the account, meaning no running instance can be terminated by that user. This directly implements the developer's requirement to prevent termination.

Why this answer

An explicit Deny statement always overrides any Allow in IAM policy evaluation, so adding {"Effect":"Deny","Action":"ec2:TerminateInstances","Resource":"*"} guarantees the user cannot terminate instances even if an existing policy grants it. This is the only option that removes the unwanted permission while leaving ec2:StopInstances untouched.

Exam trap

DVA-C02 often tests the misconception that adding an Allow for a different action (like StopInstances) implicitly removes the TerminateInstances permission, when in fact IAM is additive and only an explicit Deny can revoke an existing Allow.

How to eliminate wrong answers

Option B is wrong because an Allow for ec2:TerminateInstances would grant the very permission the developer is trying to remove, not restrict it. Option C is wrong because it explicitly allows both StopInstances and TerminateInstances, which is the opposite of the requirement. Option D is wrong because ec2:RebootInstances is a different API action that neither stops nor terminates instances and does nothing to block termination.

238
MCQhard

A developer is troubleshooting access to an S3 bucket from an EC2 instance. The instance has an IAM role with a policy that allows s3:GetObject on the bucket. However, the application receives an AccessDenied error. The bucket policy is as follows: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:role/AppRole" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-bucket/*" } ] } The EC2 instance is using the correct IAM role. What is the most likely cause of the error?

A.The bucket uses default encryption with SSE-S3, and the application does not support it.
B.The IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy.
C.The IAM role policy allows s3:GetObject, but the bucket policy also must allow it, which it does.
D.The bucket policy requires MFA, but the application does not provide it.
AnswerB

For an EC2 instance to access an S3 bucket, both the IAM role attached to the instance and the S3 bucket policy must explicitly grant the necessary permissions. If the S3 bucket policy includes a Principal element or a Condition that references a specific IAM role ARN, a mismatch between that ARN and the actual ARN of the role assumed by the EC2 instance will result in an AccessDenied error. This strict ARN matching ensures that only authorized identities can perform actions, even if the IAM role policy itself grants permissions.

Why this answer

The correct answer is B: the IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy. In S3, when a bucket policy explicitly names a Principal, the request must come from exactly that principal; if the instance's role ARN differs (for example, a different role name, path, or account), the bucket policy does not grant access and the request is denied even though the identity-based policy allows s3:GetObject. Option A is wrong because SSE-S3 encryption is transparent to clients and does not cause AccessDenied.

Option C is wrong because it merely restates that both policies allow the action, which would not produce a denial. Option D is wrong because the shown bucket policy contains no MFA condition.

239
Multi-Selecteasy

A developer needs to securely store database credentials and retrieve them programmatically from a Lambda function. Which AWS services can be used for this purpose? (Choose TWO.)

Select 2 answers
A.AWS Systems Manager Parameter Store (SecureString)
B.AWS Secrets Manager
C.AWS CloudFormation
D.AWS Identity and Access Management (IAM)
E.Amazon S3
AnswersA, B

AWS Systems Manager Parameter Store SecureString parameters store database credentials as encrypted values using AWS KMS, and they can be retrieved through the AWS API, CLI, or SDK by services like EC2, ECS, and Lambda. However, while Parameter Store can integrate with KMS and supports versioning, it does not natively automate credential rotation, so it is best when you need encrypted secrets without the additional lifecycle features of Secrets Manager.

Why this answer

AWS Systems Manager Parameter Store (SecureString) [CORRECT] is right because it stores sensitive values like database credentials as encrypted parameters using KMS, and a Lambda function can retrieve them programmatically via the GetParameter API with the WithDecryption flag set to true. AWS Secrets Manager [CORRECT] is also right because it is purpose-built for storing and rotating secrets such as database credentials, and Lambda can retrieve them programmatically using the GetSecretValue API. AWS CloudFormation does not belong because it is an infrastructure-as-code service for provisioning resources, not a secrets store for runtime retrieval.

AWS Identity and Access Management (IAM) does not belong because it manages permissions and identities, not the storage of credential values themselves. Amazon S3 does not belong because it is object storage and, while it can hold files, it is not designed as a secure credential store with native secret-retrieval APIs for this use case.

Exam trap

DVA-C02 often tests the confusion between services that store secrets (Secrets Manager, Parameter Store SecureString) and services that merely authorize or provision (IAM, CloudFormation) — candidates must pick the storage services.

240
MCQmedium

A company uses AWS KMS to encrypt data at rest in S3. The security team requires that all objects uploaded to a specific S3 bucket must be encrypted with a specific KMS key (key ID: xyz). The developer needs to enforce this by denying any PutObject request that does not use the correct key. Which bucket policy condition should be used?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.kms:EncryptionContext
C.s3:EncryptionAlgorithm
D.kms:GrantOperations
AnswerA

This condition key, `s3:x-amz-server-side-encryption-aws-kms-key-id`, is precisely designed for S3 bucket policies to enforce the use of a *specific* AWS KMS customer master key (CMK) when objects are uploaded with server-side encryption using KMS (SSE-KMS). By including this condition, an S3 bucket policy can mandate that all incoming objects encrypted with SSE-KMS must utilize a predefined KMS key ARN, preventing uploads encrypted with unauthorized or default KMS keys. This ensures strict compliance with data residency or security requirements by linking data to a specific cryptographic key.

Why this answer

The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key allows you to enforce that a specific KMS key ID (e.g., `xyz`) is used for server-side encryption with AWS KMS (SSE-KMS). By including this condition in a bucket policy with a `Deny` effect, any `PutObject` request that does not specify the required key ID will be denied, meeting the security team's requirement.

Exam trap

The trap here is confusing S3-specific condition keys (like `s3:x-amz-server-side-encryption-aws-kms-key-id`) with KMS condition keys (like `kms:EncryptionContext`), leading candidates to pick a KMS condition key that does not apply to S3 bucket policies.

How to eliminate wrong answers

Option B is wrong because `kms:EncryptionContext` is a condition key used to control access based on the encryption context in KMS API calls (e.g., `Encrypt`, `Decrypt`), not to enforce the KMS key ID used for S3 object encryption. Option C is wrong because `s3:EncryptionAlgorithm` is not a valid S3 condition key; S3 uses `s3:x-amz-server-side-encryption` to specify the encryption type (e.g., AES256 or aws:kms), not the algorithm. Option D is wrong because `kms:GrantOperations` is a condition key used to restrict the operations allowed in a KMS grant, not to enforce the KMS key ID in S3 PutObject requests.

241
MCQmedium

A developer is writing an AWS Lambda function that needs to access an Amazon S3 bucket. The Lambda function's execution role has been granted s3:GetObject permission on the bucket. However, when the function runs, it receives an Access Denied error. The S3 bucket policy allows access only from a specific VPC endpoint. What is the most likely cause of the error?

A.The Lambda execution role lacks the s3:ListBucket permission, which is required to access objects in the bucket.
B.The Lambda function's execution role needs an explicit deny override for the bucket policy condition.
C.The S3 bucket policy must be updated to include the Lambda function's IAM role ARN as a principal.
D.The Lambda function is not configured to use the VPC endpoint; it must be associated with the VPC and route traffic through the endpoint.
AnswerD

If the S3 bucket policy restricts access to a specific VPC endpoint, the Lambda function must send requests through that endpoint. This requires the Lambda function to be configured with VPC access, and the VPC must have an S3 gateway endpoint. Without this, the request originates from the public internet and is denied by the bucket policy.

Why this answer

The S3 bucket policy likely has a condition that restricts access to requests originating from a specific VPC endpoint. For the Lambda function to access the bucket, it must be configured to run within the VPC and use the VPC endpoint for S3. Without this, the request comes from the public internet and is denied.

Exam trap

The trap here is assuming that IAM permissions alone are sufficient; bucket policies with VPC endpoint conditions require the request to originate from that endpoint.

242
MCQeasy

A developer wants to encrypt data in transit between an application and an S3 bucket. Which option achieves this?

A.Enable server-side encryption with S3 managed keys (SSE-S3).
B.Configure an IAM policy to require encryption.
C.Use HTTPS when making requests to S3.
D.Use AWS KMS to encrypt the data before upload.
AnswerC

Making requests to the S3 API endpoint over HTTPS wraps every request and response in TLS, encrypting the data as it moves across the network between the application and S3's servers, which is precisely what in-transit encryption means and is enabled by default on all S3 endpoints.

Why this answer

HTTPS encrypts data in transit between the application and S3, ensuring confidentiality during transmission. Option A is incorrect because SSE-S3 encrypts data at rest, not in transit. Option B is incorrect because IAM policies control access permissions, not encryption.

Option D is incorrect because encrypting data with AWS KMS before upload addresses at-rest encryption, but without HTTPS, data is still transmitted in plaintext.

243
MCQeasy

A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3 with server-side encryption
D.Amazon DynamoDB
AnswerA

AWS Secrets Manager is the optimal choice as it is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It offers native integration with services like Amazon RDS and Amazon Redshift for automatic credential rotation, enhancing security by regularly changing credentials without application downtime. Furthermore, it provides fine-grained access control through AWS IAM and comprehensive auditing via AWS CloudTrail, ensuring secure and compliant secret management.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials such as database passwords. It integrates natively with Lambda via the AWS SDK, supports automatic rotation using Lambda rotation functions, and encrypts secrets with KMS. For database credentials specifically, Secrets Manager's built-in RDS/Redshift/DocumentDB rotation templates make it the recommended service.

Exam trap

DVA-C02 often tests the distinction between Secrets Manager and Parameter Store — candidates pick Parameter Store because it can store SecureStrings, but the question's emphasis on 'database credentials' signals Secrets Manager's native rotation capability.

How to eliminate wrong answers

Option B is wrong because Systems Manager Parameter Store can store SecureString values but lacks native automatic rotation for database credentials and is better suited to configuration data. Option C is wrong because S3 with SSE is object storage, not a secrets management service — it lacks rotation, fine-grained secret retrieval APIs, and audit integration designed for credentials. Option D is wrong because DynamoDB is a NoSQL database, not a secrets store; using it would require custom encryption, rotation, and access-control logic.

244
MCQmedium

A developer is deploying an application on Amazon EC2 instances that need to securely retrieve secrets from AWS Secrets Manager. What is the MOST secure way to provide the necessary permissions without hardcoding credentials?

A.Store the secret in an environment variable.
B.Attach an IAM role to the EC2 instance with permission to access Secrets Manager.
C.Embed the secret in the application code.
D.Use a configuration file stored in S3 with bucket policy.
AnswerB

An IAM role attached to the EC2 instance delivers temporary, automatically rotated credentials through the instance metadata service, so no long-term secrets are stored on the instance. This satisfies the no-hardcoded-credentials constraint while granting least-privilege access to Secrets Manager.

Why this answer

Attaching an IAM role to the EC2 instance is the most secure method because it leverages temporary security credentials obtained via the EC2 instance metadata service (IMDS). This eliminates the need to hardcode, embed, or store any long-term credentials on the instance, adhering to the AWS Well-Architected Framework's security pillar. The IAM role's policy grants the instance precise permissions to call Secrets Manager APIs like GetSecretValue, ensuring least privilege.

Exam trap

The trap here is that candidates may think environment variables or S3 configuration files are secure enough, but the exam emphasizes that any form of static credential storage (including environment variables) is insecure compared to IAM roles, which provide automatic, temporary, and rotated credentials.

How to eliminate wrong answers

Option A is wrong because storing the secret in an environment variable still exposes the secret in plaintext within the instance's process space and can be read by any user or process with access to the environment, violating security best practices. Option C is wrong because embedding the secret in application code hardcodes the credential, making it visible in source control, logs, or binary analysis, and prevents rotation without redeployment. Option D is wrong because using a configuration file stored in S3 with a bucket policy does not inherently provide secure access; the EC2 instance would still need credentials to retrieve the file, and the bucket policy alone cannot grant permissions to the instance without an IAM role or user, while also exposing the secret in transit and at rest if not encrypted.

245
MCQhard

An organization wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team needs to deny any console access if MFA is not enabled. Which IAM policy statement should be used?

A.Deny action '*' unless 'aws:MultiFactorAuthPresent' is true.
B.Deny action '*' if 'aws:MultiFactorAuthPresent' is false.
C.Deny action '*' if 'aws:MultiFactorAuthPresent' is false using BoolIfExists.
D.Allow action '*' if 'aws:MultiFactorAuthPresent' is true.
AnswerB

Because the aws:MultiFactorAuthPresent key is always populated with a true or false value during Management Console sign-in, a Deny statement using Bool with the condition set to false correctly and directly blocks every console action for any session that did not authenticate with MFA, which is exactly the explicit-deny enforcement the security team requires.

Why this answer

It uses a Deny statement with the condition 'aws:MultiFactorAuthPresent' set to 'false', which explicitly blocks any action when MFA is not present. This is the standard approach to enforce MFA for console access, as it overrides any Allow policies by default. The Deny effect ensures that even if other policies grant access, the lack of MFA results in denial.

Exam trap

The trap here is that candidates confuse 'Deny' with 'Allow' logic or misuse 'BoolIfExists' thinking it handles missing keys, but for console access the key is always present, so 'Bool' is required to correctly enforce the denial.

How to eliminate wrong answers

Option A is wrong because it uses 'unless' syntax, which is not valid in IAM policy language; IAM uses condition operators like 'Bool', 'StringEquals', etc., not 'unless'. Option C is wrong because 'BoolIfExists' is used when the condition key might not exist (e.g., for API calls that don't support MFA), but for console access the key is always present, so 'Bool' is appropriate and 'BoolIfExists' could inadvertently allow access if the key is missing. Option D is wrong because an Allow statement alone cannot enforce denial; it would only grant access when MFA is present but would not block access when MFA is absent if other policies allow it, and it fails to explicitly deny non-MFA access.

246
MCQhard

A company wants to encrypt data at rest in an Amazon RDS for PostgreSQL database. The database is already running, and the company wants to enable encryption without significant downtime. Which approach should be taken?

A.Take a snapshot of the database and enable encryption on the snapshot.
B.Take a snapshot, copy the snapshot with encryption, and restore a new encrypted instance from the encrypted snapshot.
C.Modify the RDS instance and enable encryption in the configuration.
D.Create a read replica with encryption and promote it.
AnswerB

This is the correct and standard procedure for adding encryption to an existing unencrypted Amazon RDS instance. First, a snapshot captures the current data of the unencrypted instance. Then, this unencrypted snapshot is copied, and crucially, during the copy process, encryption with an AWS Key Management Service (KMS) key is enabled. Finally, a new encrypted RDS instance is launched from this newly encrypted snapshot, effectively migrating the data to an encrypted environment.

Why this answer

RDS encryption at rest can only be enabled at instance creation time, so an existing unencrypted instance must be migrated. The supported path is to snapshot the instance, copy the snapshot with encryption enabled, then restore a new encrypted DB instance from that encrypted snapshot — this yields an encrypted database with only the downtime of the cutover.

Exam trap

DVA-C02 often tests that RDS encryption cannot be enabled in place — candidates pick 'Modify the instance' or 'encrypt the snapshot' because those seem simpler, but the only valid path is snapshot → encrypted copy → restore.

How to eliminate wrong answers

Option A is wrong because you cannot enable encryption directly on an existing snapshot; snapshots inherit the encryption state of their source, and there is no 'encrypt this snapshot' toggle. Option C is wrong because RDS does not allow enabling encryption via a Modify operation on a running instance — the encryption setting is immutable after creation. Option D is wrong because read replicas inherit the encryption state of the primary; you cannot create an encrypted read replica from an unencrypted primary, so this approach is not possible.

247
MCQmedium

A company uses AWS KMS to encrypt data at rest. A developer wants to allow a Lambda function to decrypt data using a KMS key. What is the minimum permissions required?

A.kms:Decrypt on all keys.
B.kms:Encrypt and kms:Decrypt on the key.
C.kms:Decrypt on the key in the Lambda execution role.
D.Full access to KMS.
AnswerC

Attaching a policy statement granting only kms:Decrypt, scoped to the specific key's ARN, on the Lambda execution role is exactly the least-privilege permission needed — it grants decrypt capability for that one key and nothing more.

Why this answer

The minimum permission required is kms:Decrypt on the specific key, attached to the Lambda execution role. The Lambda function only needs to decrypt data, not encrypt it, so kms:Decrypt is sufficient. Granting it on the specific key follows the principle of least privilege.

Exam trap

DVA-C02 often tests least privilege, and candidates may choose kms:Encrypt and kms:Decrypt thinking both are needed, but the question specifies only decryption.

How to eliminate wrong answers

Option A is wrong because granting kms:Decrypt on all keys is overly broad and violates least privilege. Option B is wrong because kms:Encrypt is not needed if the function only decrypts. Option D is wrong because full access to KMS is excessive and insecure.

248
MCQeasy

A developer is troubleshooting an S3 bucket policy that is denying all access. The policy has an explicit Deny for s3:PutObject. What is the most likely reason for the denial even though an Allow exists?

A.The bucket policy has an explicit Deny for all actions.
B.The user is not authorized because the bucket is in a different account.
C.IAM evaluates explicit Deny before Allow.
D.The AWS account root user has denied access.
AnswerC

This statement accurately describes a fundamental principle of AWS Identity and Access Management (IAM) policy evaluation. When multiple policies apply to a request, IAM first checks for any explicit Deny statements. If an explicit Deny exists for the requested action or resource, the request is immediately denied, regardless of any explicit Allow statements that might also be present. An explicit Deny always overrides an explicit Allow, making it the most powerful permission modifier in the evaluation logic.

Why this answer

IAM policy evaluation logic explicitly states that an explicit Deny always overrides any Allow. In S3 bucket policies, if any statement includes an explicit Deny for s3:PutObject that matches the principal and resource, the request is denied regardless of other Allow statements. This is the core reason the denial occurs even when an Allow exists.

Exam trap

DVA-C02 often tests the 'explicit Deny always wins' rule, but candidates sometimes think an Allow in a different policy can override a Deny, or that the most specific policy wins — the exam expects you to know Deny is absolute.

How to eliminate wrong answers

Option A is wrong because the question states the policy has an explicit Deny for s3:PutObject, not for all actions; a blanket Deny for all actions would be a different (and broader) misconfiguration. Option B is wrong because cross-account access can be a factor, but the question already establishes an explicit Deny for s3:PutObject as the cause; cross-account alone does not cause denial if the bucket policy allows it. Option D is wrong because the root user does not 'deny access' via a separate mechanism; root has full permissions unless an SCP or explicit Deny applies, and the question's Deny is in the bucket policy.

249
MCQmedium

A company wants to encrypt data in transit between an Application Load Balancer and its EC2 instances. The instances run a custom web server. Which configuration should the developer implement?

A.Configure the ALB listener with a TLS certificate and set the target group protocol to HTTPS. Install the server certificate on the EC2 instances.
B.Use AWS Certificate Manager to issue a certificate for the EC2 instances and configure the web server to use it.
C.Configure the ALB listener with a TLS certificate and set the target group protocol to HTTP.
D.Enable client certificate authentication on the ALB.
AnswerA

Configuring the ALB listener with a TLS certificate ensures traffic from the client to the ALB is encrypted. By setting the target group protocol to HTTPS, the ALB then re-encrypts this traffic before forwarding it to the backend EC2 instances. The EC2 instances must have their own server certificates installed and configured on their web servers to successfully complete the TLS handshake, thereby providing comprehensive end-to-end encryption for data in transit.

Why this answer

To encrypt data in transit between an Application Load Balancer (ALB) and EC2 instances, the ALB listener must be configured with a TLS certificate for client-to-ALB encryption, and the target group protocol must be set to HTTPS to enable encryption between the ALB and the instances. The EC2 instances must have a server certificate installed (e.g., from ACM or self-signed) to terminate the TLS connection, ensuring end-to-end encryption. This setup allows the ALB to re-encrypt traffic after decrypting it from the client, using HTTPS for the backend connection.

Exam trap

The trap here is that candidates often assume setting the ALB listener to HTTPS alone encrypts the entire path, forgetting that the target group protocol must also be HTTPS to encrypt the ALB-to-instance traffic, or they mistakenly think ACM certificates can be directly installed on EC2 instances.

How to eliminate wrong answers

Option B is wrong because AWS Certificate Manager (ACM) cannot issue certificates directly to EC2 instances; ACM certificates are designed for use with AWS services like ALB, CloudFront, or API Gateway, and cannot be exported for installation on custom web servers. Option C is wrong because setting the target group protocol to HTTP sends unencrypted traffic between the ALB and EC2 instances, failing to encrypt data in transit as required. Option D is wrong because client certificate authentication on the ALB is used for mutual TLS (mTLS) to verify client identity, not for encrypting data in transit between the ALB and backend instances.

250
Multi-Selectmedium

Which TWO actions can help protect an S3 bucket from data leaks? (Choose two.)

Select 2 answers
A.Enable versioning.
B.Enable default encryption.
C.Enable MFA Delete.
D.Block public access at the bucket level.
E.Configure cross-region replication.
AnswersB, D

Enabling default encryption for an S3 bucket ensures that all newly written objects are encrypted at rest, either with SSE-S3 (AES-256) or SSE-KMS, so the raw data is stored as ciphertext. This protects against data leaks where an attacker gains access to the underlying storage media or backups, because they cannot interpret the encrypted bytes without the decryption keys. Note that default encryption is not a replacement for access control; it is a confidentiality layer that complements IAM policies and Block Public Access, and it can be enforced at the bucket policy level to reject unencrypted writes.

Why this answer

Option B (Enable default encryption) is correct because it ensures that all objects written to the bucket are encrypted at rest using SSE-S3, SSE-KMS, or SSE-C, so even if objects are inadvertently exposed or accessed without authorization, the data remains unreadable without the appropriate keys. Option D (Block public access at the bucket level) is correct because S3 Block Public Access settings override bucket policies and ACLs to prevent any public exposure, which is the primary vector for S3 data leaks. Option A (Enable versioning) only preserves object versions and aids recovery from overwrites or deletions; it does not prevent unauthorized access or public exposure.

Option C (Enable MFA Delete) adds protection against accidental or malicious deletion of object versions but does not stop data from being read or leaked. Option E (Configure cross-region replication) copies objects to another region for durability and latency, but it does not restrict access and can even widen the exposure surface if the destination bucket is misconfigured.

Exam trap

DVA-C02 often tests the misconception that versioning or MFA Delete prevent data leaks, when they actually address data integrity and deletion protection, not access control.

251
Multi-Selecteasy

Which TWO services can be used to encrypt data at rest in Amazon S3? (Choose two.)

Select 2 answers
A.SSE-KMS
B.AWS IAM
C.AWS Certificate Manager (ACM)
D.AWS CloudHSM
E.SSE-S3
AnswersA, E

SSE-KMS encrypts each object using a data key generated and protected by an AWS KMS customer managed or AWS managed key, giving administrators fine-grained IAM control over who can use the key, a full CloudTrail audit trail of key usage, and support for key rotation.

Why this answer

Options A and E are correct. Option A: SSE-KMS uses AWS Key Management Service (KMS) for managing encryption keys, providing additional control and audit capabilities. Option E: SSE-S3 uses S3-managed keys for encryption at rest.

Option B is incorrect because AWS IAM is an access management service, not an encryption service. Option C is incorrect because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not data encryption. Option D is incorrect because AWS CloudHSM provides hardware security modules but is not directly integrated with S3 for encryption.

Exam trap

Candidates often confuse the two server-side encryption options (SSE-S3 and SSE-KMS) and may forget that both can encrypt data at rest in S3. Also, IAM and ACM are not encryption services.

252
MCQmedium

A developer runs the commands above. The key is disabled. An application that uses this key to encrypt S3 objects starts failing. What should the developer do to fix the issue?

A.Delete the key and recreate it
B.Create a new KMS key and update the application to use it
C.Enable the KMS key
D.Enable automatic key rotation
AnswerC

When an AWS KMS key is disabled, it transitions into a `Disabled` state, preventing any cryptographic operations such as encryption or decryption. Enabling the KMS key directly changes its state back to `Enabled`, immediately restoring its full functionality. This allows the application to resume using the key for all authorized cryptographic operations without requiring any changes to application code or data migration, making it the most direct and efficient solution.

Why this answer

Enable the KMS key. The key is disabled, so enabling it will restore functionality. Option A (delete the key and recreate it) would create a new key, but the application would need to be updated to use the new key, which is unnecessary since the original key exists and can simply be re-enabled.

Option B (create a new KMS key and update the application to use it) is also a valid but more complex fix; however, the simplest and most direct solution is to re-enable the key. Option D (enable automatic key rotation) does not affect the disabled state; it only sets a rotation policy for future key updates.

253
MCQmedium

A developer is creating a new IAM policy to allow an application to read objects from a specific S3 bucket and write logs to a CloudWatch log group. Which policy statement is correct?

A.{"Effect":"Allow","Action":["ec2:DescribeInstances"],"Resource":"*"}
B.{"Effect":"Allow","Action":["s3:ListBucket"],"Resource":"arn:aws:s3:::my-bucket/*"}
C.{"Effect":"Allow","Action":["s3:GetObject","logs:CreateLogStream","logs:PutLogEvents"],"Resource":["arn:aws:s3:::my-bucket/*","arn:aws:logs:us-east-1:123456789012:log-group:MyLogGroup:*"]}
D.{"Effect":"Allow","Action":["s3:PutObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerC

This statement correctly pairs s3:GetObject, which retrieves object content, with logs:CreateLogStream and logs:PutLogEvents, the two actions required to create a log stream and write log events, and scopes each action to its precise resource ARN, satisfying both requirements with least privilege.

Why this answer

It grants the necessary permissions: s3:GetObject to read objects from the bucket, and logs:CreateLogStream and logs:PutLogEvents to write logs to the CloudWatch log group. The resources are correctly specified: the bucket ARN with a wildcard for objects, and the log group ARN with a wildcard for log streams. Option A is incorrect because it uses ec2:DescribeInstances, which is unrelated to S3 or CloudWatch.

Option B is incorrect because it only allows s3:ListBucket on the bucket (listing objects) but not reading them (s3:GetObject), and it does not include CloudWatch actions. Option D is incorrect because it only allows s3:PutObject (writing objects) rather than reading, and lacks CloudWatch permissions.

254
MCQmedium

A company's security policy requires that all data in transit between an Application Load Balancer (ALB) and its backend EC2 instances be encrypted. The ALB currently uses HTTPS listeners. What configuration ensures encryption between the ALB and targets?

A.Add a security group rule allowing port 443 from the ALB to the instances.
B.Configure the target group to use HTTPS protocol.
C.Use a Network Load Balancer with a TLS listener.
D.Set the listener protocol to HTTPS with a certificate.
AnswerB

Configuring the target group to use HTTPS protocol explicitly instructs the Application Load Balancer (ALB) to establish a TLS-encrypted connection when forwarding requests to its registered backend instances. This setting ensures that all data transmitted from the ALB to the instances is encrypted in transit, directly fulfilling the security policy requirement. It offloads the initial client-side TLS termination to the ALB while maintaining a secure communication channel to the backend.

Why this answer

To encrypt traffic between the ALB and backend EC2 instances, the target group protocol must be set to HTTPS, which uses TLS encryption. Option A is incorrect: security group rules control access but do not encrypt traffic. Option C is incorrect: while a Network Load Balancer with a TLS listener encrypts client-to-ALB traffic, it does not affect ALB-to-target encryption, and the question specifically asks about an Application Load Balancer.

Option D is incorrect: setting the listener protocol to HTTPS with a certificate encrypts client-to-ALB traffic, not the traffic between ALB and targets.

255
MCQhard

A company uses AWS KMS customer master keys (CMKs) to encrypt sensitive data in Amazon S3. A compliance requirement mandates that the backing keys for the CMKs be automatically rotated every year. The developer must implement this with minimal operational overhead. Which solution meets the requirement?

A.Enable automatic key rotation for the CMK in AWS KMS.
B.Create a new CMK every year and update the S3 bucket policy to use the new key.
C.Use an AWS managed key (aws/s3) which automatically rotates annually.
D.Use SSE-S3 encryption with automatically rotated keys instead of KMS.
AnswerA

Enabling automatic key rotation for a CMK in AWS KMS ensures that the underlying cryptographic material (backing key) used for encryption is replaced annually. This process is transparent to applications, as the CMK's Amazon Resource Name (ARN) and Key ID remain unchanged, allowing existing encrypted data to still be decrypted by the original backing key. This fully automates the compliance requirement for annual key rotation without operational disruption.

Why this answer

AWS KMS supports automatic key rotation for customer managed CMKs. When enabled, KMS automatically rotates the backing key annually (approximately every 365 days) with no additional operational overhead. This satisfies the compliance requirement for yearly rotation without manual intervention.

Exam trap

The trap here is that candidates may confuse AWS managed keys (which rotate automatically but not on a customer-defined schedule) with customer managed CMKs, or assume that manual key rotation is required when automatic rotation is available.

How to eliminate wrong answers

Option B is wrong because manually creating a new CMK each year and updating the S3 bucket policy introduces significant operational overhead and violates the 'minimal operational overhead' requirement. Option C is wrong because AWS managed keys (aws/s3) are automatically rotated, but the rotation schedule is managed by AWS and is not guaranteed to be exactly every year; additionally, the question specifies using customer master keys (CMKs), not AWS managed keys. Option D is wrong because SSE-S3 uses server-side encryption with Amazon S3-managed keys, not AWS KMS CMKs, and the rotation schedule is managed by S3, not the customer, so it does not meet the requirement of using KMS CMKs with annual rotation.

256
MCQmedium

A company is using an S3 bucket to store sensitive data. They want to ensure that all objects uploaded to the bucket are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). What is the most secure way to enforce this?

A.Enable default encryption on the bucket with SSE-KMS.
B.Create a bucket policy that denies PutObject without encryption.
C.Create a bucket policy that denies PutObject unless the x-amz-server-side-encryption header is set to aws:kms.
D.Enable S3 Block Public Access on the bucket.
AnswerC

This bucket policy precisely enforces server-side encryption using AWS KMS for all new objects uploaded to the bucket. By including a Condition that checks StringEquals on the s3:x-amz-server-side-encryption key with a value of aws:kms, any PutObject request not specifying SSE-KMS will be explicitly denied. This ensures that all sensitive data at rest is encrypted with customer-managed or AWS-managed KMS keys, providing robust protection.

Why this answer

Option C is correct because a bucket policy that denies PutObject unless the x-amz-server-side-encryption header equals aws:kms actively rejects any upload that does not explicitly request SSE-KMS, making it the strongest enforcement mechanism for this scenario. This policy-level Deny cannot be bypassed by users or roles, and it ensures every object is encrypted with AWS KMS keys rather than weaker or default encryption. Option A only sets a default that can be overridden by an uploader specifying a different encryption method, so it does not truly enforce SSE-KMS.

Option B is too vague because it does not specify the required encryption type, allowing SSE-S3 or other algorithms, and Option D addresses public access, not encryption at rest.

257
Multi-Selecthard

A security audit reveals that an S3 bucket is publicly accessible. The bucket policy is as follows: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":"*","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}]}. Which TWO actions should be taken to remediate this issue? (Select TWO.)

Select 2 answers
A.Remove the public access grant from the bucket ACL.
B.Create an IAM user policy that denies s3:GetObject for anonymous users.
C.Enable versioning on the bucket.
D.Modify the bucket policy to remove the Allow effect for Principal "*".
E.Enable default encryption on the bucket.
AnswersA, D

Removing a public access grant from the bucket Access Control List (ACL) is a direct and effective method to revoke public access. ACLs are a legacy access control mechanism that can explicitly grant read or write permissions to predefined groups like "Everyone" (public access) or "Authenticated Users". By deleting the specific ACL entry that allows public read access, the bucket immediately ceases to be publicly accessible via that mechanism.

Why this answer

The bucket ACL may still grant public access even if the bucket policy is the primary issue. Removing the public access grant from the ACL ensures that no anonymous principals have s3:GetObject permissions via ACLs, which is a separate access control mechanism from bucket policies. This is a direct remediation step to eliminate public read access.

Exam trap

The trap here is that candidates may think only the bucket policy needs fixing, overlooking that ACLs can independently grant public access, so both the policy and ACL must be remediated.

258
MCQmedium

A company is using AWS Lambda to process sensitive data. The Lambda function needs to access an S3 bucket in the same account. What is the BEST practice for granting permissions?

A.Use an S3 bucket policy that allows access from the Lambda function's ARN.
B.Create an IAM role with a policy granting S3 access and attach it to the Lambda function.
C.Generate a key pair and use it to authenticate the Lambda function to S3.
D.Store the AWS access key ID and secret access key in the Lambda environment variables.
AnswerB

This is the AWS best practice for granting permissions to Lambda functions. By assigning an IAM execution role, the Lambda function automatically assumes this role and receives temporary, frequently rotated credentials from the AWS Security Token Service (STS) to interact with S3. This approach adheres to the principle of least privilege, centralizes access control, and eliminates the need to manage long-term static credentials within the function code or configuration, significantly enhancing security.

Why this answer

The AWS best practice for granting a Lambda function access to other AWS services is to create an IAM role with the required permissions and assign it as the function's execution role. Lambda assumes this role at runtime and the function receives temporary credentials via the environment, so no long-lived secrets are needed. This follows least-privilege and avoids credential management overhead.

Exam trap

DVA-C02 often tests the misconception that embedding access keys in environment variables is acceptable for Lambda, when the correct answer is always an IAM execution role with temporary credentials.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy alone does not give the Lambda function an identity to authenticate with — the function still needs an IAM role to obtain credentials, and resource-based policies are typically used in addition to, not instead of, identity-based permissions. Option C is wrong because key pairs are used for EC2 SSH access, not for authenticating Lambda to S3; S3 uses IAM, not SSH keys. Option D is wrong because storing long-lived access keys in environment variables is an anti-pattern that exposes credentials, requires manual rotation, and violates AWS security best practices.

259
MCQmedium

A developer is building a serverless application using AWS Lambda and needs to securely store database credentials. Which AWS service should be used to store and retrieve the credentials?

A.AWS CloudFormation
B.AWS Secrets Manager
C.AWS Systems Manager Parameter Store
D.AWS Key Management Service (KMS)
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive information such as database credentials, API keys, and other application secrets throughout their lifecycle. It offers robust features like automatic rotation of secrets, fine-grained access control through IAM, and integration with other AWS services for easy secret injection into applications. Its ability to automatically rotate secrets without requiring application code changes is a key advantage for enhancing security posture and reducing operational overhead, making it the ideal choice for dynamic secret management.

Why this answer

AWS Secrets Manager (option B) is the correct choice because it is purpose-built to store, rotate, and retrieve secrets such as database credentials via API calls, and Lambda functions can fetch them at runtime using the AWS SDK with fine-grained IAM permissions. It also natively supports automatic rotation of credentials for supported databases like Amazon RDS, MySQL, and PostgreSQL, which reduces the risk of long-lived static credentials. AWS CloudFormation (A) is an infrastructure-as-code service for provisioning resources, not for storing secrets.

AWS Systems Manager Parameter Store (C) can hold parameters including SecureString values, but it lacks built-in secret rotation and is less tailored to credential lifecycle management. AWS KMS (D) is an encryption key management service that encrypts data but does not itself store or serve database credentials.

260
MCQhard

A company is designing a multi-account strategy using AWS Organizations. They want to enable cross-account access for developers using IAM roles. Each developer has an IAM user in the 'developers' account. The 'production' account has an IAM role 'AdminRole' that can be assumed by the 'developers' account. Which trust policy should be attached to 'AdminRole'?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::123456789012:root"},"Action":"sts:AssumeRole"}]} where 123456789012 is the developers account ID.
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"Service":"ec2.amazonaws.com"},"Action":"sts:AssumeRole"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::123456789012:user/*"},"Action":"sts:AssumeRole"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::123456789012:role/AdminRole"},"Action":"sts:AssumeRole"}]}
AnswerA

The trust policy's Principal must name the trusting account's root ARN, 123456789012, which delegates assumption to that account's IAM users. Developers then attach a policy permitting sts:AssumeRole on AdminRole, satisfying cross-account role assumption from the developers account.

Why this answer

The trust policy on the 'AdminRole' in the production account must allow the entire 'developers' account (using its root ARN) to assume the role. When an IAM user in the developers account calls sts:AssumeRole, AWS evaluates the trust policy; specifying the root ARN of the developers account (arn:aws:iam::123456789012:root) delegates trust to the entire account, and the individual user's permissions are then controlled by an IAM policy attached to the user or a group that grants sts:AssumeRole for this role.

Exam trap

The trap here is that candidates often confuse the trust policy's Principal with the resource being accessed, mistakenly specifying the role's own ARN (Option D) or limiting to specific users (Option C), instead of using the root ARN of the trusted account to allow any authorized entity in that account to assume the role.

How to eliminate wrong answers

Option B is wrong because it specifies a Service principal (ec2.amazonaws.com), which is used for AWS services like EC2 to assume a role, not for cross-account IAM users. Option C is wrong because it restricts the principal to IAM users with a wildcard (arn:aws:iam::123456789012:user/*), which would not allow IAM roles or the root account to assume the role, and also does not cover cases where the developer might be using an IAM role in the developers account. Option D is wrong because it specifies the ARN of the AdminRole itself as the principal, which would create a self-referential trust policy that does not grant access to any external account; the principal must be the trusted account's root or specific IAM entities.

261
MCQhard

A company uses AWS Lambda to process sensitive data. The Lambda function needs to access an RDS database with a password stored in AWS Secrets Manager. The function currently retrieves the secret using the AWS SDK. What is the best practice to secure this setup?

A.Configure the Lambda function to use IAM database authentication for RDS.
B.Store the password as a Lambda environment variable encrypted with KMS.
C.Use the AWS CLI within the Lambda function to fetch the secret each time.
D.Rotate the secret daily using Secrets Manager and cache it in Lambda.
AnswerA

Configuring the Lambda function to use IAM database authentication for RDS is the most secure and recommended approach. This method allows the Lambda function to connect using its execution role, generating short-lived, temporary authentication tokens instead of relying on static usernames and passwords. It eliminates the need to store or manage long-term database credentials, significantly enhancing security by leveraging AWS IAM's robust permission model and automatic credential rotation.

Why this answer

IAM database authentication eliminates the need to store or retrieve a password entirely. The Lambda function assumes an IAM role that generates a temporary authentication token (valid for 15 minutes) using the AWS SDK, which is then used to connect to RDS via TLS. This approach follows the principle of least privilege and removes the risk of static credentials being exposed or misused.

Exam trap

The trap here is that candidates assume Secrets Manager is always the best practice for secrets, but the question specifically asks for the best practice to secure the setup, and IAM authentication removes the secret entirely, which is more secure than any secret management approach.

How to eliminate wrong answers

Option B is wrong because storing the password as a Lambda environment variable, even if encrypted with KMS, still introduces a static secret that could be exposed through logs, error messages, or function configuration views. Option C is wrong because using the AWS CLI within a Lambda function is inefficient (adds cold-start latency and dependency on the CLI binary) and still requires the function to handle the secret in memory, whereas the SDK is the recommended method. Option D is wrong because daily rotation and caching in Lambda does not address the fundamental risk of a static password; the secret still exists and could be compromised, whereas IAM authentication removes the password entirely.

262
MCQmedium

A company has a requirement to automatically rotate database credentials every 30 days. Which AWS service can meet this requirement with minimal development effort?

A.AWS KMS
B.AWS IAM
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is specifically designed to help you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle. It offers built-in, automated rotation for various database types, including Amazon RDS, Amazon DocumentDB, and other services, ensuring credentials are regularly updated without requiring application code changes.

Why this answer

AWS Secrets Manager is the correct choice because it provides built-in, automated rotation of database credentials without custom code. You can define a rotation schedule (e.g., every 30 days) and Secrets Manager will automatically update the secret and the database password using a Lambda function, meeting the requirement with minimal development effort.

Exam trap

The trap here is that candidates often confuse Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with Secrets Manager, overlooking the critical requirement for automated rotation with minimal effort.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encryption keys, not for storing or rotating database credentials. Option B is wrong because AWS IAM manages users, roles, and permissions, but it does not natively rotate database credentials or store secrets. Option C is wrong because AWS Systems Manager Parameter Store can store secrets but lacks built-in automatic rotation; you would need to build custom automation to rotate credentials every 30 days, which contradicts the 'minimal development effort' requirement.

263
MCQmedium

A company stores sensitive documents in an Amazon S3 bucket. The security team requires that all objects uploaded must be encrypted at rest using a specific customer-managed AWS KMS key (key-id: 1234-5678). The developer must enforce this by denying any PutObject request that does not use the correct key. Which S3 bucket policy condition should be used?

A.s3:x-amz-server-side-encryption with value 'aws:kms'
B.s3:x-amz-server-side-encryption-aws-kms-key-id with value 'arn:aws:kms:us-east-1:123456789012:key/1234-5678'
C.s3:x-amz-acl with value 'bucket-owner-full-control'
D.aws:SourceArn with value the bucket ARN
AnswerB

The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition directly enforces the use of a specific AWS KMS key by comparing its ARN against the value provided in the S3 PUT object request header. This precise condition ensures that only objects encrypted with the designated customer-managed key (CMK) are successfully uploaded to the bucket. It provides the granular control necessary to meet strict compliance requirements for sensitive data, ensuring data at rest is secured with an auditable, pre-approved key.

Why this answer

The condition key `s3:x-amz-server-side-encryption-aws-kms-key-id` allows you to enforce that a specific customer-managed AWS KMS key (identified by its full ARN) is used for server-side encryption. By denying PutObject requests that do not match this key ID, the security team ensures all uploaded objects are encrypted at rest with the required KMS key.

Exam trap

The trap here is that candidates often confuse `s3:x-amz-server-side-encryption` (which only checks if SSE-KMS is enabled) with `s3:x-amz-server-side-encryption-aws-kms-key-id` (which checks the specific key ID), leading them to pick Option A, which does not enforce the required customer-managed key.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption` with value `aws:kms` only enforces that SSE-KMS is used, but does not restrict which KMS key is used; any KMS key (including default AWS-managed keys) would satisfy the condition. Option C is wrong because `s3:x-amz-acl` with value `bucket-owner-full-control` controls access permissions via ACLs, not encryption requirements, and is irrelevant to enforcing encryption key usage. Option D is wrong because `aws:SourceArn` is used to restrict requests based on the source ARN (e.g., to prevent cross-service confused deputy attacks), not to enforce encryption key selection.

264
Multi-Selecteasy

Which TWO of the following are best practices for securing AWS account root user?

Select 2 answers
A.Delete the root user access keys.
B.Use the root user for daily administrative tasks.
C.Set a password policy that locks the root user after 10 failed attempts.
D.Share the root user password with senior developers for emergencies.
E.Enable multi-factor authentication (MFA) for the root user.
AnswersA, E

Root user access keys are permanent long-term credentials with unrestricted privileges across the account, including billing and even account closure. They cannot be constrained by IAM policies or permission boundaries, so if they are compromised, the attacker gains full control without any possibility of mitigating the scope. AWS best practice is to never create root access keys, and if they already exist, delete them immediately and rely on password plus MFA for the rare root sign-in.

Why this answer

Option A is correct because AWS best practice is to remove (delete) any access keys associated with the root user, since long-term programmatic credentials on the root account pose a severe risk if leaked and root should not be used for API/CLI access. Option E is correct because enabling MFA on the root user adds a critical second authentication factor, protecting the account from password compromise and required for sensitive root-only operations. Options B, C, and D are not best practices: the root user should not be used for daily administrative tasks (use IAM users/roles instead), AWS does not provide an account-level password policy that locks the root user after failed attempts, and sharing the root password with developers violates least privilege and accountability.

Exam trap

DVA-C02 often tests the misconception that the root user should be used for convenience or that IAM password policies apply to it — candidates must remember the root user is special-cased and should be locked down, not used.

265
MCQhard

A company has a multi-account architecture using AWS Organizations. The security team wants to centrally manage IAM policies that apply to all accounts. Which AWS feature should the developer use?

A.Service control policies (SCPs) in AWS Organizations.
B.IAM cross-account roles.
C.AWS Config conformance packs.
D.IAM policies attached to the root user.
AnswerA

Service Control Policies (SCPs) in AWS Organizations are powerful guardrails that define the maximum available permissions for accounts, Organizational Units (OUs), or the entire organization. They do not grant permissions themselves but filter the permissions that IAM policies can grant, effectively restricting actions across all affected accounts centrally. This centralized enforcement mechanism is ideal for establishing and maintaining security and compliance standards across a multi-account architecture, ensuring no account can exceed the defined boundaries.

Why this answer

Service control policies (SCPs) in AWS Organizations are the only feature that lets you centrally define and enforce permission guardrails across every account in the organization. SCPs are attached at the OU or account level and define the maximum permissions available to IAM principals in member accounts, so a single policy change propagates to all accounts. This directly satisfies the requirement to 'centrally manage IAM policies that apply to all accounts.'

Exam trap

DVA-C02 often tests the misconception that IAM policies or cross-account roles can centrally govern all accounts, when in fact only SCPs in AWS Organizations provide organization-wide permission guardrails.

How to eliminate wrong answers

Option B is wrong because IAM cross-account roles only grant access between specific accounts and do not centrally enforce or manage policies across the entire organization. Option C is wrong because AWS Config conformance packs are used for compliance assessment and reporting against configuration rules, not for centrally managing or enforcing IAM permissions. Option D is wrong because IAM policies attached to a root user apply only to that single account's root user and cannot be used to govern all accounts in an organization.

266
MCQhard

A developer is troubleshooting an IAM policy that is supposed to allow a Lambda function to read objects from an S3 bucket. The Lambda function role has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::example-bucket/*","arn:aws:s3:::example-bucket"]}]}. Despite this, the Lambda function receives an AccessDenied error when trying to read objects. What is the most likely cause?

A.The S3 bucket has a bucket policy that explicitly denies the Lambda function's access.
B.The IAM policy does not include the s3:GetObjectVersion action.
C.The Lambda function is in a different AWS account than the S3 bucket.
D.The IAM policy uses an incorrect resource ARN format.
AnswerA

AWS IAM policy evaluation logic dictates that an explicit deny in any applicable policy always overrides an explicit allow. Even if the Lambda function's execution role has an IAM policy granting s3:GetObject access, a bucket policy on the target S3 bucket that explicitly denies access to that specific Lambda role will prevent the action. This creates an effective deny, regardless of the identity-based policy, making it the most probable cause for troubleshooting.

Why this answer

The IAM policy attached to the Lambda function role correctly grants s3:GetObject and s3:ListBucket permissions on the bucket and its objects. However, if the S3 bucket itself has a bucket policy that explicitly denies access to the Lambda function's role, that explicit deny overrides any allow from IAM policies, resulting in an AccessDenied error. This is because AWS evaluates all policies (identity-based and resource-based) and an explicit deny always takes precedence.

Exam trap

The trap here is that candidates often assume the IAM policy alone is sufficient and overlook the possibility of a bucket policy that explicitly denies access, which overrides any IAM allow.

How to eliminate wrong answers

Option B is wrong because the s3:GetObjectVersion action is only needed when accessing a specific version of an object using version ID; the error occurs on a standard read, which only requires s3:GetObject. Option C is wrong because cross-account access would still work if the bucket policy grants access to the Lambda function's role; the error is not inherently caused by being in a different account. Option D is wrong because the resource ARN format is correct: 'arn:aws:s3:::example-bucket/*' for objects and 'arn:aws:s3:::example-bucket' for the bucket itself, which is the standard format for S3 ARNs.

267
Multi-Selecteasy

Which TWO actions are required to enable server-side encryption for an Amazon RDS instance? (Choose 2)

Select 2 answers
A.Enable encryption on the database after creation
B.Use client-side encryption in the application
C.Configure the DB instance to use a VPC
D.Use AWS KMS to manage the encryption key
E.Specify encryption at rest when creating the DB instance
AnswersD, E

Amazon RDS server-side encryption is built on AWS KMS; you must select a customer master key (CMK) when enabling encryption at rest. The KMS key encrypts the database storage, automated snapshots, and read replicas through envelope encryption, and RDS uses the key to encrypt the data key that protects the volume. Without specifying a KMS key, the encryption option cannot be applied, making KMS key management an essential part of the required configuration.

Why this answer

Option D is correct because Amazon RDS encryption at rest is implemented using AWS Key Management Service (KMS) customer master keys (CMKs), so you must use AWS KMS to manage the encryption key that protects the DB instance's storage and snapshots. Option E is correct because RDS encryption at rest can only be enabled at the moment of DB instance creation (via the console, CLI --storage-encrypted, or API StorageEncrypted=true); you cannot turn it on afterward. Option A is wrong because an existing unencrypted RDS instance cannot simply have encryption enabled after creation—you must create a new encrypted instance from a snapshot.

Option B is wrong because client-side encryption is an application-level concern and does not enable RDS server-side encryption at rest. Option C is wrong because placing the DB instance in a VPC is a networking configuration and has no bearing on enabling storage encryption.

Exam trap

DVA-C02 often tests the immutability of RDS encryption — candidates pick 'enable encryption after creation' because they assume it is a toggleable setting like in some other services, but RDS requires encryption at creation time.

268
MCQmedium

A developer needs to prevent accidental public access to all S3 buckets in an account. Which account-level control should be enabled?

A.S3 Transfer Acceleration
B.S3 Block Public Access
C.S3 Inventory
D.S3 Object Lambda
AnswerB

S3 Block Public Access is the correct and most effective service for preventing accidental public access to S3 buckets and objects across an entire AWS account or specific buckets. It offers four distinct settings that can be applied at the account or bucket level: blocking new public ACLs, ignoring existing public ACLs, blocking new public bucket policies, and blocking public and cross-account access to buckets with public policies. These controls override other access configurations, ensuring strong protection against unintended public exposure.

Why this answer

S3 Block Public Access is an account-level control that provides a centralized way to enforce that no S3 buckets or objects in the account can be made publicly accessible, regardless of individual bucket policies or ACLs. This setting overrides any bucket-level public access settings, effectively preventing accidental exposure of data to the internet.

Exam trap

The trap here is that candidates may confuse bucket-level controls (like bucket policies or ACLs) with account-level controls, or mistakenly think features like Transfer Acceleration or Inventory provide security, when only S3 Block Public Access offers a centralized, account-wide safeguard against public exposure.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature that speeds up uploads over long distances using AWS edge locations, not a security control for preventing public access. Option C is wrong because S3 Inventory is used to generate reports on object metadata and replication status for auditing and compliance, not to block public access. Option D is wrong because S3 Object Lambda allows you to add custom code to process data during S3 GET, HEAD, and LIST requests, but it does not provide any access control or public access blocking functionality.

269
MCQhard

A company uses AWS Secrets Manager to rotate database credentials for an RDS MySQL instance. The rotation Lambda function fails with the error: 'Secret is scheduled for deletion.' What is the MOST likely cause?

A.The secret has been marked for deletion and is in the waiting period.
B.The secret's rotation schedule has been disabled.
C.The Lambda function does not have permission to access the secret.
D.The RDS instance is not in the same VPC as the Lambda function.
AnswerA

When a secret in AWS Secrets Manager is marked for deletion, it enters a configurable waiting period (3 to 30 days) before permanent removal. During this period, the secret is effectively read-only and cannot be modified, including initiating a rotation. Any attempt to rotate a secret in this state will fail, as Secrets Manager prevents operations that would alter a secret designated for deletion, ensuring data integrity before its final removal. This specific state directly causes rotation failures.

Why this answer

The error 'Secret is scheduled for deletion' indicates that the secret has been marked for deletion and is currently in the mandatory waiting period (default 7 to 30 days). During this period, AWS Secrets Manager prevents any operations on the secret, including rotation, to ensure the deletion is intentional. The rotation Lambda function fails because it cannot access or modify a secret that is pending deletion.

Exam trap

The trap here is that candidates may confuse the 'scheduled for deletion' error with a permissions or network issue, but the error message directly points to the secret's lifecycle state, which is a distinct concept in AWS Secrets Manager.

How to eliminate wrong answers

Option B is wrong because disabling the rotation schedule would prevent the Lambda function from being triggered, but it would not cause a 'Secret is scheduled for deletion' error; the secret would still be accessible. Option C is wrong because a permissions issue would result in an 'AccessDeniedException' or similar authorization error, not a deletion-specific error message. Option D is wrong because VPC mismatch would cause a network timeout or connectivity error, not a deletion-related error; the Lambda function would still be able to call the Secrets Manager API if network access is configured.

270
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to enforce that all S3 buckets across all accounts are encrypted using SSE-KMS with a specific KMS key from the central security account. They also want to prevent any unencrypted bucket creation. A developer in the development account creates a new S3 bucket and enables default encryption using SSE-S3. The bucket creation succeeds, but the security team wants to prevent this. The developer argues that the bucket still encrypts data at rest. Compliance requires SSE-KMS only. What should the security team do to enforce this policy across all accounts?

A.Create an IAM policy in the central security account that denies s3:PutBucketEncryption if the encryption is not SSE-KMS.
B.Use AWS Config to detect non-compliant buckets and automatically apply default encryption with SSE-KMS.
C.Enable CloudTrail to log all S3 API calls and manually review for non-compliant buckets.
D.Create a service control policy (SCP) that denies s3:PutObject and s3:PutBucketEncryption unless the encryption is SSE-KMS with the specific KMS key.
AnswerD

Service Control Policies (SCPs) are a feature of AWS Organizations that allow central management of permissions across all accounts in the organization. An SCP can explicitly deny actions like `s3:PutObject` and `s3:PutBucketEncryption` unless specific conditions, such as the use of SSE-KMS with a designated KMS key, are met. This provides proactive, preventative enforcement at the organizational level, ensuring compliance before resources are created or modified.

Why this answer

A service control policy (SCP) applied at the AWS Organizations root or OU level can centrally deny S3 bucket creation and encryption configuration unless SSE-KMS with the specific KMS key is used. SCPs affect all accounts in the organization, preventing developers from bypassing the policy by creating buckets with SSE-S3, as the SCP condition key `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id` enforce the required encryption at the API level before the bucket is created.

Exam trap

The trap here is that candidates often confuse IAM policies (which are account-scoped) with SCPs (which are organization-wide), and assume that AWS Config remediation or CloudTrail can proactively enforce encryption, when in fact only SCPs can deny the API call at the point of creation across all accounts.

How to eliminate wrong answers

Option A is wrong because an IAM policy in the central security account only applies to principals in that account, not to developers in other accounts, and cannot prevent bucket creation across the organization. Option B is wrong because AWS Config can detect non-compliant buckets and trigger remediation (e.g., via Lambda), but it is reactive—it does not prevent the initial creation of an unencrypted bucket, which the security team explicitly wants to block. Option C is wrong because CloudTrail logging only provides auditing after the fact, not proactive enforcement; manual review is impractical and does not prevent non-compliant bucket creation.

271
MCQmedium

A developer is building a serverless application that processes personally identifiable information (PII). The application uses API Gateway, Lambda, and DynamoDB. The developer needs to ensure that the PII is encrypted at rest in DynamoDB. The company already uses AWS KMS with a customer-managed key for other services. The developer wants to reuse the same KMS key for DynamoDB. After enabling encryption with the KMS key, the Lambda function fails to write to the table with an AccessDenied error. The Lambda execution role has dynamodb:PutItem permission. What is the most likely cause?

A.The Lambda execution role lacks kms:Encrypt and kms:Decrypt permissions on the customer-managed KMS key.
B.The Lambda execution role does not have DynamoDB write permissions.
C.The DynamoDB table has a resource-based policy that denies access.
D.The Lambda function is not in a VPC, so it cannot access the KMS key.
AnswerA

The Lambda execution role requires kms:Encrypt and kms:Decrypt permissions on the customer-managed KMS key (CMK) when interacting with a DynamoDB table encrypted with that CMK. Although DynamoDB handles the actual encryption and decryption at rest, it performs these KMS operations on behalf of the calling principal, which is the Lambda function in this scenario. Without these specific KMS permissions granted to its execution role, the Lambda function cannot authorize DynamoDB to use the CMK for data operations, leading to access denied errors when attempting to write or read items.

Why this answer

When a DynamoDB table is encrypted with a customer-managed KMS key, any operation that reads or writes data to the table requires the caller to have permissions to use that KMS key. Even though the Lambda execution role has dynamodb:PutItem permission, the PutItem operation internally triggers KMS Encrypt and Decrypt calls to manage the encryption of the item. Without kms:Encrypt and kms:Decrypt permissions on the specific KMS key, the request fails with an AccessDenied error.

Exam trap

The trap here is that candidates assume DynamoDB's built-in encryption with a KMS key is transparent and does not require additional IAM permissions beyond the DynamoDB actions, but in reality, the caller must have explicit KMS permissions on the key for any read or write operation.

How to eliminate wrong answers

Option B is wrong because the question explicitly states that the Lambda execution role has dynamodb:PutItem permission, so the failure is not due to missing DynamoDB write permissions. Option C is wrong because there is no mention of a resource-based policy on the DynamoDB table, and the error is specifically related to KMS permissions, not a table policy denying access. Option D is wrong because Lambda functions do not need to be in a VPC to access KMS; KMS is a regional service accessible over the public AWS network, and VPC configuration is irrelevant to KMS key access permissions.

272
MCQeasy

A developer is designing a web application that will run on EC2 instances behind an Application Load Balancer. The application needs to authenticate users. Which service should the developer use to manage user identities and provide single sign-on?

A.AWS IAM
B.Amazon Cognito
C.AWS Directory Service
D.AWS Security Token Service (STS)
AnswerB

Amazon Cognito is the ideal service for managing user identities and authentication for web and mobile applications, offering highly scalable user directories through its User Pools feature. It handles user registration, sign-in, and account recovery, and can integrate with social identity providers or enterprise directories. Cognito provides robust authentication flows and token management, specifically designed for application end-users.

Why this answer

Amazon Cognito is the correct choice because it is a fully managed identity service designed for web and mobile applications. It provides user sign-up, sign-in, and access control, and supports single sign-on (SSO) through federation with social identity providers (e.g., Google, Facebook) and enterprise identity providers via SAML 2.0 or OIDC. This makes it ideal for authenticating users in an application running behind an Application Load Balancer.

Exam trap

The trap here is confusing AWS IAM (for AWS resource access) with a customer-facing identity service, leading candidates to choose IAM for user authentication instead of Cognito.

How to eliminate wrong answers

Option A is wrong because AWS IAM is designed for managing permissions for AWS services and resources, not for authenticating end users of a web application; it lacks built-in user registration, sign-in UI, and SSO federation for external identities. Option C is wrong because AWS Directory Service is primarily for integrating with Microsoft Active Directory or creating managed directories for enterprise workloads, not for providing a simple, scalable user identity store with social login or SSO for web applications. Option D is wrong because AWS Security Token Service (STS) is used to issue temporary security credentials for AWS API requests, not for managing user identities or providing authentication and SSO for application users.

273
MCQmedium

A developer is creating a web application that uses Amazon Cognito for user authentication. The application needs to verify the identity of users before allowing access to the API. Which Cognito feature should the developer use?

A.User Pools
B.Identity Pools
C.Cognito Sync
D.Cognito Events
AnswerA

Amazon Cognito User Pools serve as a secure, scalable user directory that handles user registration, authentication, and account recovery for web and mobile applications. They manage user identities, issue JSON Web Tokens (JWTs) upon successful authentication, including ID, access, and refresh tokens, which are then used to authorize access to application APIs. This service is the primary component for directly authenticating users into your application, making it the correct choice for managing user sign-in.

Why this answer

Amazon Cognito User Pools provide a fully managed identity and access management service specifically designed for user authentication and authorization in web and mobile applications. They handle user sign-up, sign-in, and identity verification through features like multi-factor authentication (MFA) and JSON Web Token (JWT) issuance, making them the correct choice for verifying user identity before granting API access.

Exam trap

The trap here is confusing Identity Pools (which grant AWS credentials) with User Pools (which authenticate users), leading candidates to select Identity Pools when the question explicitly asks about verifying user identity, not granting AWS resource access.

How to eliminate wrong answers

Option B (Identity Pools) is wrong because Identity Pools are used to exchange user tokens (from a User Pool or other identity provider) for temporary AWS credentials to access AWS services like DynamoDB or S3, not for authenticating users directly. Option C (Cognito Sync) is wrong because Cognito Sync is a deprecated service for synchronizing user profile data across devices, not for identity verification. Option D (Cognito Events) is wrong because Cognito Events are AWS Lambda triggers that run during User Pool operations (e.g., pre-sign-up), but they do not perform user authentication themselves.

274
MCQeasy

A developer wants to securely store database credentials used by a Lambda function. The credentials should be automatically rotated every 90 days. Which service should be used?

A.AWS Secrets Manager
B.AWS Key Management Service (KMS)
C.AWS Identity and Access Management (IAM)
D.AWS Systems Manager Parameter Store
AnswerA

AWS Secrets Manager stores credentials securely and natively supports automatic rotation through Lambda rotation functions, satisfying the 90-day rotation constraint. Unlike Parameter Store, which offers no built-in rotation, Secrets Manager schedules rotation and updates the secret, so the Lambda function retrieves current database credentials without manual intervention.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It supports native rotation with built-in integration for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, MariaDB) and Amazon DocumentDB, allowing you to configure automatic rotation every 90 days without custom code. The service encrypts secrets at rest using AWS KMS and enforces fine-grained access control via IAM policies.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation, which is explicitly required by the 90-day rotation requirement in the question.

How to eliminate wrong answers

Option B (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys, not a secret storage service; it cannot store or rotate database credentials. Option C (IAM) is wrong because it manages users, groups, roles, and permissions for AWS API access, not database credentials; it has no mechanism to store or rotate secrets. Option D (AWS Systems Manager Parameter Store) is wrong because while it can store secrets as SecureString parameters, it does not natively support automatic rotation of credentials; you would need to build a custom rotation solution using Lambda, whereas Secrets Manager provides built-in rotation.

275
MCQhard

A developer needs to ensure that every cryptographic operation performed on an AWS KMS customer master key (CMK) used for server-side encryption in Amazon S3 is recorded in AWS CloudTrail for auditing. The developer has already enabled CloudTrail and is logging management events. However, the security team wants to see all calls to the KMS Decrypt and Encrypt APIs for this specific key. What must the developer do?

A.Enable CloudTrail data events for the S3 bucket containing the encrypted objects.
B.Create an additional CloudTrail trail that logs all management events for the KMS key.
C.Enable CloudTrail data events for the specific KMS key ARN.
D.Enable CloudTrail Insights events on the existing trail.
AnswerC

CloudTrail data events for KMS record every call to Decrypt, Encrypt, GenerateDataKey, etc. By specifying the key ARN in the data event selector, only operations on that key are logged, meeting the audit requirement without excessive logging.

Why this answer

CloudTrail data events can be configured to log individual API operations (such as Decrypt and Encrypt) on specific KMS keys. By default, CloudTrail management events do not include these data-plane operations; enabling data events for the specific KMS key ARN ensures every cryptographic call is recorded for auditing.

Exam trap

The trap here is that candidates confuse S3 server-side encryption with KMS data events, assuming that logging S3 bucket data events will capture KMS calls, when in fact KMS data-plane operations require explicit data event logging on the KMS key itself.

How to eliminate wrong answers

Option A is wrong because enabling CloudTrail data events for the S3 bucket captures S3 object-level operations (e.g., GetObject, PutObject), not the KMS Decrypt and Encrypt API calls themselves. Option B is wrong because management events already include KMS key management actions (e.g., CreateKey, DisableKey) but not data-plane cryptographic operations; creating another trail with management events does not capture Decrypt/Encrypt. Option D is wrong because CloudTrail Insights events detect unusual API activity patterns but do not log individual Decrypt/Encrypt calls; they are an analysis feature, not a logging configuration for specific API operations.

276
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer. The security team discovers that the application is vulnerable to SQL injection attacks. The team wants to implement a web application firewall (WAF) to block these attacks. The architecture includes an ALB, EC2 instances in an Auto Scaling group, and an RDS database. The ALB currently has a listener on port 443 with an SSL certificate. The developer must integrate AWS WAF with minimal changes to the existing infrastructure. Which action should the developer take?

A.Subscribe to AWS Shield Advanced and enable automatic mitigation.
B.Install a WAF agent on each EC2 instance in the Auto Scaling group.
C.Place a CloudFront distribution in front of the ALB and associate WAF with CloudFront.
D.Associate AWS WAF directly with the Application Load Balancer.
AnswerD

AWS WAF supports direct association with an Application Load Balancer through a web ACL, letting the developer attach managed rule groups such as the SQL injection rule set (AWSManagedRulesSQLiRuleSet) to the existing ALB with no new services, no DNS changes, and no modification to the SSL listener, satisfying the requirement for minimal-change integration.

Why this answer

AWS WAF can be directly associated with an Application Load Balancer (ALB) to filter HTTP/HTTPS requests and block SQL injection attacks. This requires minimal changes to the existing infrastructure because no additional components like CloudFront or agents are needed. Option A is incorrect because AWS Shield Advanced is a DDoS protection service, not a WAF, and does not include SQL injection rules.

Option B is incorrect because WAF is a managed service that operates at the edge or load balancer level, not as an agent on EC2 instances. Option C is incorrect because while you could place CloudFront in front of the ALB and attach WAF to CloudFront, it adds unnecessary complexity and cost when the ALB already supports direct WAF association.

277
MCQhard

A company wants to encrypt data at rest in Amazon S3 using server-side encryption with KMS (SSE-KMS). They want to ensure that only certain IAM roles can decrypt objects. What must be configured?

A.IAM role policy to allow kms:Decrypt
B.S3 bucket policy to allow decrypt
C.KMS key policy to allow the IAM roles to decrypt
D.KMS key policy to allow s3.amazonaws.com to decrypt
AnswerC

For an IAM role to successfully decrypt data encrypted with an AWS KMS Customer Managed Key (CMK), the KMS key policy associated with that specific CMK must explicitly allow the IAM role to perform the `kms:Decrypt` action. This is a critical requirement because the key policy is the definitive access control mechanism for the KMS key, dictating which principals are authorized to use it. Without this explicit permission in the key policy, decryption attempts by the IAM role will fail, even if the role's IAM policy permits `kms:Decrypt`.

Why this answer

SSE-KMS uses a customer master key (CMK) to encrypt and decrypt S3 objects. The KMS key policy is the primary access control mechanism for a CMK; it must explicitly grant the IAM roles the kms:Decrypt permission. Without this policy statement, even if the IAM roles have a policy allowing kms:Decrypt, they will be denied access because KMS key policies can override IAM permissions when the key policy does not grant access to the account's IAM principals.

Exam trap

The trap here is that candidates assume an IAM role policy granting kms:Decrypt is sufficient, forgetting that KMS key policies act as an independent access control layer that can explicitly deny or allow access, and without the key policy granting the role, the IAM policy is ineffective.

How to eliminate wrong answers

Option A is wrong because an IAM role policy allowing kms:Decrypt is necessary but not sufficient; the KMS key policy must also grant the role permission to use the key, and if the key policy does not include the role, the IAM policy alone will not allow decryption. Option B is wrong because S3 bucket policies control access to S3 actions (like s3:GetObject) but cannot grant KMS decryption permissions; KMS actions are governed solely by KMS key policies and IAM policies. Option D is wrong because allowing the service principal s3.amazonaws.com to decrypt would grant decryption to any S3 request that uses the key, bypassing the IAM role restriction and violating the requirement that only certain IAM roles can decrypt.

278
Multi-Selecthard

A company is designing a secure CI/CD pipeline using AWS CodePipeline and AWS CodeBuild. The pipeline must securely store and access sensitive parameters (e.g., API keys) used during the build. Which TWO services can be used to securely store and retrieve these parameters?

Select 2 answers
A.AWS Systems Manager Parameter Store (SecureString)
B.AWS Secrets Manager
C.Amazon S3 with server-side encryption
D.AWS Key Management Service (KMS) alone
E.AWS CloudFormation parameter store
AnswersA, B

Systems Manager Parameter Store lets you store values as SecureString parameters encrypted under a KMS key, and CodeBuild buildspec files natively support pulling these into environment variables at build time via the parameter-store mapping, making it a valid secure retrieval mechanism.

Why this answer

AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are both designed to securely store secrets and can be accessed by CodeBuild via IAM roles.

279
Multi-Selecthard

A developer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a Lambda function. Which THREE practices should be followed to ensure security?

Select 3 answers
A.Use IAM roles for pipeline actions instead of access keys.
B.Scan code dependencies for known vulnerabilities.
C.Use CloudFront to distribute pipeline artifacts.
D.Store database credentials in AWS Secrets Manager and retrieve them during deployment.
E.Encrypt artifacts in transit using TLS.
AnswersA, B, D

IAM roles provide temporary, short-lived credentials that are automatically rotated by AWS, significantly reducing the risk associated with long-lived access keys. When an AWS service like CodeBuild or CodeDeploy assumes an IAM role, it receives a temporary security token, eliminating the need to embed static credentials directly into pipeline configurations or source code. This aligns with the principle of least privilege and enhances security posture by preventing credential leakage and simplifying credential management.

Why this answer

IAM roles provide temporary credentials for AWS services, eliminating the need to manage long-term access keys. CodePipeline can assume an IAM role to perform actions like deploying a Lambda function, which reduces the risk of credential leakage. This follows the principle of least privilege and is a security best practice for automated pipelines.

Exam trap

The trap here is that candidates may confuse CloudFront's artifact distribution capability with S3's role in CodePipeline, or assume TLS encryption is an optional security practice rather than a default AWS behavior.

280
MCQeasy

A company runs an application on Amazon EC2 instances that need to read data from an Amazon DynamoDB table. The developer must grant access to DynamoDB without storing any long-term credentials on the instance. Which approach should the developer use?

A.Store the AWS access key and secret key in a configuration file.
B.Use an IAM role and attach it to the EC2 instance profile.
C.Use an IAM user and store credentials in AWS Secrets Manager.
D.Use the DynamoDB table's resource-based policy to allow the EC2 instance.
AnswerB

Attaching an IAM role to an EC2 instance profile is the recommended and most secure method for granting AWS service access to applications running on EC2 instances. This mechanism provides temporary, automatically rotated credentials to the instance via the EC2 instance metadata service, eliminating the need to store any long-term static credentials on the instance itself. This approach adheres to the principle of least privilege, significantly reducing the attack surface and improving overall security posture by ensuring credentials are short-lived and not directly exposed.

Why this answer

Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS) via the instance metadata service. This eliminates the need to store long-term credentials on the instance, adhering to the principle of least privilege and improving security posture.

Exam trap

The trap here is that candidates may think resource-based policies (Option D) can grant access to EC2 instances, but DynamoDB resource-based policies only support principals like AWS accounts, IAM users, or IAM roles—not EC2 instances directly—and the correct mechanism for EC2 is always an IAM role attached to the instance profile.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in a configuration file on the EC2 instance introduces long-term static credentials, which violates the requirement to avoid storing long-term credentials and increases the risk of credential leakage. Option C is wrong because using an IAM user and storing credentials in AWS Secrets Manager still requires the EC2 instance to retrieve and use long-term credentials (the IAM user's access keys) at some point, and the instance would need to authenticate to Secrets Manager, typically with another set of credentials, creating a circular dependency; the recommended approach for EC2 is always an IAM role. Option D is wrong because DynamoDB does not support resource-based policies that grant access to EC2 instances directly; resource-based policies in DynamoDB are used for cross-account access or service-to-service authorization, not for granting permissions to compute resources like EC2 instances.

281
MCQmedium

A developer is troubleshooting access to an S3 bucket from an EC2 instance. The bucket policy allows s3:GetObject for the instance's IAM role, but the application is still getting access denied errors. What is the MOST likely cause?

A.The EC2 instance's security group does not allow outbound traffic to S3.
B.The S3 bucket is encrypted with SSE-KMS and the instance does not have kms:Decrypt permissions.
C.The S3 bucket has a block public access setting enabled.
D.The EC2 instance does not have an instance profile associated with the IAM role.
AnswerB

While missing `kms:Decrypt` permissions would indeed prevent an EC2 instance from accessing SSE-KMS encrypted S3 objects, this presumes the instance already has an IAM identity and general S3 access permissions. The scenario describes troubleshooting general access, implying a more fundamental issue. Without an instance profile, the EC2 instance cannot assume any IAM role, meaning it would lack *all* permissions, including any necessary KMS permissions, making the instance profile the more foundational problem.

Why this answer

When an S3 bucket is encrypted using SSE-KMS, any entity attempting to retrieve an object (s3:GetObject) must also have permission to decrypt the object using the KMS key (kms:Decrypt). If the IAM role has the correct S3 permissions but lacks the kms:Decrypt permission on the KMS key, AWS S3 will return an 'Access Denied' error.

Why other options are incorrect:

A: Security group restrictions on outbound traffic would cause the connection to time out, not return an 'Access Denied' error.

C: Block Public Access settings prevent anonymous/public access, but access via an authorized IAM role is not public access.

D: If the EC2 instance did not have an instance profile associated, the AWS SDK would fail locally with a credentials lookup error (e.g., 'Unable to locate credentials') rather than receiving an 'Access Denied' response from the S3 service.

Exam trap

AWS frequently tests the interaction between S3 permissions and KMS permissions. Remember that if an S3 bucket is encrypted with a customer managed KMS key (SSE-KMS), the caller needs both S3 permissions (s3:GetObject) and KMS permissions (kms:Decrypt) to successfully download the file. Lacking KMS permissions results in an 'Access Denied' error.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer and do not affect outbound traffic to S3 by default; outbound traffic is allowed unless explicitly denied, and S3 access uses HTTPS over port 443 which is typically open. Option B is wrong because while SSE-KMS requires kms:Decrypt permissions, the question states the bucket policy allows s3:GetObject for the role, and the error could be due to missing KMS permissions, but the most likely cause given the scenario is the missing instance profile, not KMS. Option C is wrong because block public access settings only restrict public (unauthenticated) access, not access from an IAM role that has been explicitly granted permissions via a bucket policy.

282
MCQmedium

A developer is creating an IAM policy to allow a Lambda function to write logs to CloudWatch. Which policy should be attached to the Lambda execution role?

A.AWSLambdaBasicExecutionRole
B.AdministratorAccess
C.AmazonDynamoDBFullAccess
D.AmazonS3FullAccess
AnswerA

The AWSLambdaBasicExecutionRole is an AWS managed policy specifically designed to grant a Lambda function the essential permissions required for its operation. This includes the ability to create log groups and log streams in Amazon CloudWatch Logs, and to put log events into those streams. These permissions are fundamental for monitoring function execution, debugging, and ensuring operational visibility, making it the correct and least-privileged choice for basic Lambda functionality.

Why this answer

The AWSLambdaBasicExecutionRole managed policy grants permissions for Lambda to write logs to CloudWatch Logs, specifically allowing the logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents actions. This is the minimal set of permissions required for a Lambda function to send execution logs to CloudWatch, making it the correct choice for this use case.

Exam trap

The trap here is that candidates may mistakenly choose a broad policy like AdministratorAccess or a service-specific policy like AmazonDynamoDBFullAccess, thinking they need to grant 'full' permissions or that the Lambda function might need access to other services, when the question specifically asks only for CloudWatch logging permissions.

How to eliminate wrong answers

Option B (AdministratorAccess) is wrong because it grants full administrative permissions to all AWS services, which violates the principle of least privilege and is overly permissive for a Lambda function that only needs to write logs. Option C (AmazonDynamoDBFullAccess) is wrong because it provides full access to DynamoDB operations but does not include any CloudWatch Logs permissions, so the Lambda function would fail to write logs. Option D (AmazonS3FullAccess) is wrong because it grants full access to S3 buckets and objects but lacks the necessary CloudWatch Logs actions, making it irrelevant for logging purposes.

283
MCQeasy

A company wants to give a third-party auditor read-only access to their AWS account for compliance purposes. What is the most appropriate way to grant this access?

A.Attach the AdministratorAccess managed policy to an IAM user.
B.Create an IAM role with the SecurityAudit managed policy and allow the auditor to assume it.
C.Create an IAM user with a custom policy that allows all actions.
D.Share the root account credentials with the auditor.
AnswerB

Creating an IAM role with the SecurityAudit managed policy and allowing the auditor to assume it is the correct approach because SecurityAudit grants only read-only access to security-related services and many other AWS services, aligning with the auditor's need to review configurations and logs without making changes. The role uses temporary credentials through AWS STS, so no long-term keys are issued or shared, and access can be scoped with a trust policy that specifies the auditor's AWS account or external identity provider. This follows least privilege and provides a secure, auditable mechanism for third-party access.

Why this answer

An IAM role with the AWS-managed SecurityAudit policy grants read-only access to configuration and audit metadata across services without allowing data access or mutations. The auditor assumes the role using STS, receiving temporary credentials, which is the AWS-recommended pattern for cross-account or third-party access. This satisfies least privilege and avoids long-lived credentials.

Exam trap

DVA-C02 often tests the reflex to grant access via IAM users or managed admin policies when the correct answer is a scoped IAM role with temporary credentials — candidates overlook roles and least-privilege managed policies like SecurityAudit.

How to eliminate wrong answers

Option A is wrong because AdministratorAccess grants full control over the account, violating least privilege and giving the auditor far more than read-only compliance access. Option C is wrong because a custom policy allowing all actions is effectively admin access and is both over-permissive and unnecessary when SecurityAudit already exists. Option D is wrong because sharing root credentials is a severe security anti-pattern — root has unrestricted access, cannot be scoped, and its compromise is catastrophic; AWS explicitly advises against root usage for anything but a few account-level tasks.

284
MCQhard

A developer is deploying a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party OIDC provider. The developer wants to minimize latency and avoid managing sessions. What is the BEST approach to achieve this?

A.Use Amazon Cognito User Pools with the OIDC identity provider and integrate with API Gateway.
B.Use Lambda@Edge to validate tokens at CloudFront edge locations.
C.Use Amazon Cognito Identity Pools with the OIDC provider.
D.Implement a custom Lambda authorizer in API Gateway to validate tokens.
AnswerA

Amazon Cognito User Pools provide a managed user directory service that handles user registration, authentication, and account recovery. When integrated with API Gateway, User Pools can directly validate JSON Web Tokens (JWTs) issued after successful user authentication, simplifying the authorization process. This native integration offloads token validation and user management, making it an efficient and scalable solution for serverless applications without requiring custom code.

Why this answer

Amazon Cognito User Pools natively support OIDC identity providers as federated IdPs, and API Gateway can use a Cognito User Pool authorizer to validate the resulting JWT tokens at the edge with minimal latency and no session management. This offloads authentication to a managed service, satisfying the requirements for third-party OIDC auth, low latency, and statelessness.

Exam trap

The trap is confusing Cognito User Pools (authentication, OIDC federation, JWT issuance) with Cognito Identity Pools (AWS credential vending) — candidates who pick Identity Pools misunderstand that API Gateway authorization needs authentication tokens, not temporary AWS credentials.

How to eliminate wrong answers

Option B is wrong because Lambda@Edge runs at CloudFront edge locations but is not an authentication service — it would require custom token validation code and adds complexity without the managed OIDC integration Cognito provides. Option C is wrong because Cognito Identity Pools provide AWS credentials for authenticated users (federation for AWS access), not user authentication/session tokens for API Gateway authorization. Option D is wrong because a custom Lambda authorizer requires writing and maintaining token validation logic, increasing latency and operational overhead compared to the native Cognito User Pool authorizer.

285
MCQeasy

A company has a DynamoDB table that stores personally identifiable information (PII). A developer needs to allow a Lambda function to read and write to this table. What is the MOST secure way to grant the Lambda function access?

A.Create an IAM role with a policy that allows DynamoDB read/write access and attach it to the Lambda function.
B.Use a resource-based policy on the DynamoDB table to allow the Lambda function's IAM role.
C.Create an IAM user with programmatic access and embed the credentials in the Lambda environment variables.
D.Have the Lambda function assume a role using AWS STS each time it runs.
AnswerA

An IAM role attached to the Lambda function supplies temporary credentials via the execution environment, so no long-term keys are stored. Scoping the policy to the specific DynamoDB table actions follows least privilege, satisfying the PII security requirement.

Why this answer

Attaching an IAM role with a least-privilege policy to the Lambda function is the AWS-recommended, most secure approach. Lambda assumes the execution role automatically at invocation, and no long-lived credentials are stored anywhere. This eliminates credential leakage risk and follows the principle of least privilege.

Exam trap

DVA-C02 often tests whether candidates know that Lambda automatically assumes an execution role — the trap is picking STS AssumeRole inside the function or embedding credentials, which are either redundant or insecure.

How to eliminate wrong answers

Option B is wrong because DynamoDB does not support resource-based policies that grant access to IAM roles for data-plane operations; DynamoDB resource policies are limited and not a substitute for identity-based policies on the Lambda execution role. Option C is wrong because embedding IAM user credentials in environment variables is a serious security anti-pattern — credentials can be exposed via logs, console, or code, and they are long-lived. Option D is wrong because Lambda already assumes an execution role automatically; manually calling STS AssumeRole inside the function adds unnecessary complexity and latency, and still requires an execution role with sts:AssumeRole permissions.

286
MCQmedium

A company has an S3 bucket that stores sensitive customer data. The security team requires that all data be encrypted at rest using server-side encryption with AWS KMS. Additionally, they want to enforce that objects are not uploaded without encryption. Which bucket policy should be used?

A.Deny s3:PutObject if the request includes x-amz-server-side-encryption
B.Deny s3:PutObject unless the request includes x-amz-server-side-encryption with value aws:kms
C.Allow s3:PutObject only if the request uses a specific KMS key
D.Deny s3:PutObject unless the request includes x-amz-server-side-encryption with value AES256
AnswerB

This bucket policy statement correctly enforces Server-Side Encryption with AWS KMS (SSE-KMS) for all objects uploaded to the S3 bucket. By using a `Deny` effect with a `StringNotEquals` condition on the `s3:x-amz-server-side-encryption` header, it ensures that any `PutObject` request that does not explicitly specify `aws:kms` for server-side encryption will be rejected. This guarantees that all sensitive customer data at rest is protected by customer-managed or AWS-managed KMS keys.

Why this answer

It uses a Deny effect with a condition that checks for the presence and value of the `x-amz-server-side-encryption` header. This policy explicitly denies any `s3:PutObject` request that does NOT include `x-amz-server-side-encryption` with the value `aws:kms`, thereby enforcing server-side encryption with AWS KMS (SSE-KMS) on all uploads.

Exam trap

The trap here is that candidates often confuse the encryption header values (`aws:kms` vs `AES256`) or mistakenly think that an Allow statement alone can enforce encryption, when in fact a Deny statement with a condition is required to block non-compliant requests.

How to eliminate wrong answers

Option A is wrong because it denies `s3:PutObject` if the request includes the `x-amz-server-side-encryption` header, which would block all encrypted uploads, not enforce them. Option C is wrong because it only allows `s3:PutObject` if a specific KMS key is used, but it does not enforce that encryption is present at all; a request without encryption could still be allowed if no explicit Deny is present. Option D is wrong because it enforces SSE-S3 (AES256) rather than SSE-KMS (aws:kms), which does not meet the requirement for server-side encryption with AWS KMS.

287
MCQhard

A company uses AWS CloudFormation to deploy resources. The templates are stored in an S3 bucket. A developer wants to ensure that only authorized users can create stacks from these templates. What should be implemented?

A.Use IAM policies to control who can call CreateStack and add S3 bucket policies to restrict template access.
B.Use a stack policy to restrict updates.
C.Enable CloudTrail to log template access.
D.Set the S3 bucket to private and rely on bucket policies.
AnswerA

IAM policies are crucial for controlling which users or roles can invoke the `CreateStack` API action within CloudFormation, directly preventing unauthorized stack deployments. Concurrently, S3 bucket policies restrict access to the CloudFormation template file itself, ensuring only authorized entities can read or download it. This dual-layer approach provides robust preventative security by controlling both the action and the asset, embodying a defense-in-depth strategy.

Why this answer

It combines two layers of access control: IAM policies restrict the ability to call the CreateStack API action, and S3 bucket policies restrict access to the template objects stored in S3. This ensures that even if a user has IAM permissions to create stacks, they cannot retrieve or use the template unless the S3 bucket policy also grants them access. Without both controls, an unauthorized user could bypass IAM by directly accessing the template URL or using a different AWS account.

Exam trap

The trap here is that candidates often assume S3 bucket policies alone are sufficient for access control, forgetting that IAM policies are required to authorize the CreateStack API call itself.

How to eliminate wrong answers

Option B is wrong because stack policies control updates to stack resources after creation, not who can create stacks from templates. Option C is wrong because CloudTrail logs API calls for auditing but does not enforce any access control or authorization. Option D is wrong because setting the S3 bucket to private and relying solely on bucket policies does not prevent an authorized S3 user from creating a stack with the template; it also fails to control the CreateStack API call itself, which is governed by IAM.

288
MCQhard

A company uses AWS Secrets Manager to store database credentials. The credentials must be automatically rotated every 30 days. The developer needs to configure rotation without exposing the secret to any IAM user directly. Which configuration steps should the developer take?

A.Enable automatic rotation and choose a rotation interval of 30 days. Secrets Manager will automatically rotate the secret using a built-in Lambda function.
B.Create a Lambda function with rotation logic, attach an IAM role with permissions to read and update the secret, and configure Secrets Manager to invoke the function every 30 days.
C.Use AWS Certificate Manager (ACM) to rotate the secret automatically every 30 days.
D.Store the secret in AWS Systems Manager Parameter Store and set a schedule to rotate it using a CloudWatch Events rule.
AnswerB

This is the correct approach for implementing secret rotation with AWS Secrets Manager. To enable automatic rotation, a dedicated AWS Lambda function must be created, containing the specific logic to generate a new secret, update it in the target service (e.g., a database), and then update Secrets Manager. This Lambda function requires an IAM role with precise permissions, including `secretsmanager:GetSecretValue` to retrieve the current secret and `secretsmanager:PutSecretValue` to store the new one, along with permissions to interact with the target resource. Secrets Manager is then configured to invoke this Lambda function on the specified schedule, such as every 30 days.

Why this answer

AWS Secrets Manager does not provide a built-in Lambda function for rotating database credentials; you must create your own Lambda function that contains the rotation logic (e.g., querying the database, creating a new credential, and updating the secret). The Lambda function must be attached to an IAM role with permissions to read and update the secret, and Secrets Manager invokes this function based on the rotation schedule (every 30 days). This ensures the secret is never exposed directly to any IAM user, as only the Lambda function interacts with the secret programmatically.

Exam trap

The trap here is that candidates assume Secrets Manager provides a built-in Lambda function for all secret types, but in reality, you must create your own Lambda function for database credentials, while only AWS-managed secrets (like RDS) have pre-built rotation templates.

How to eliminate wrong answers

Option A is wrong because Secrets Manager does not include a built-in Lambda function for rotating secrets; you must provide your own custom Lambda function with the rotation logic. Option C is wrong because AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for rotating database credentials stored in Secrets Manager. Option D is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it is a simple key-value store without built-in rotation capabilities, and using a CloudWatch Events rule would require custom scripting and does not integrate with Secrets Manager's native rotation features.

289
MCQmedium

A developer attached the IAM policy above to an IAM user. What is the effect when the user tries to download an object from the 'confidential' folder in 'example-bucket'?

A.The policy is invalid because Deny cannot be used with s3:*
B.The user can download only if the object is encrypted
C.The user is denied access because of the explicit Deny statement
D.The user can download the object because of the Allow statement
AnswerC

The user is denied access precisely because of the explicit Deny statement within the IAM policy. According to IAM policy evaluation logic, an explicit Deny always takes precedence over any Allow statements. If a Deny statement matches the requested action (s3:GetObject) and resource (an object within the confidential folder), access is immediately blocked, regardless of other Allow permissions.

Why this answer

In AWS IAM, an explicit Deny statement always overrides any Allow statement, regardless of order or specificity. The policy includes a Deny for s3:* on the confidential folder, so the user is denied access to download objects there even if a separate Allow exists.

Exam trap

DVA-C02 often tests the IAM evaluation logic where candidates forget that explicit Deny always wins, leading them to pick the Allow-based answer.

How to eliminate wrong answers

Option A is wrong because Deny can absolutely be used with wildcard actions like s3:*; IAM policies support wildcards in both Action and Resource elements. Option B is wrong because encryption status of the object is irrelevant to the policy evaluation; the explicit Deny blocks access regardless of encryption. Option D is wrong because the Allow statement cannot override an explicit Deny; IAM evaluates explicit Deny first and it wins.

290
MCQmedium

A developer is creating a Lambda function that requires access to a DynamoDB table. The function will be invoked by an Amazon API Gateway REST API. What is the BEST way to secure this architecture?

A.Create an IAM role for the Lambda function with a policy granting access to the DynamoDB table.
B.Attach a resource-based policy to the DynamoDB table allowing Lambda access.
C.Use API Gateway to pass a shared secret to Lambda for DynamoDB access.
D.Store the DynamoDB access keys in the Lambda environment variables.
AnswerA

Creating an IAM role for the Lambda function is the standard and most secure method for granting AWS service permissions. This role provides temporary, automatically rotated credentials to the Lambda execution environment, allowing it to assume the specified permissions. By attaching an identity-based policy that grants specific `dynamodb:` actions on the target table, the Lambda function adheres to the principle of least privilege, accessing only what it needs.

Why this answer

The Lambda function needs an execution role—an IAM role that Lambda assumes at runtime—with a policy that grants the specific DynamoDB actions (e.g., GetItem, PutItem) on the target table. This follows the principle of least privilege and is the standard AWS pattern for granting Lambda access to AWS resources. API Gateway invokes the Lambda function via a resource-based policy on the function itself, but that does not affect DynamoDB access; the Lambda execution role handles all downstream permissions.

Exam trap

The trap here is that candidates confuse resource-based policies (used for granting invocation permissions to other AWS accounts or services) with execution roles (used for granting the Lambda function permissions to access other AWS resources), leading them to incorrectly choose Option B or think Option C is a valid authentication method.

How to eliminate wrong answers

Option B is wrong because resource-based policies on DynamoDB tables are not supported; DynamoDB uses IAM policies attached to users, roles, or the table's own resource policy (only for cross-account access via VPC endpoints or AWS Organizations), not for granting access to a Lambda function in the same account. Option C is wrong because passing a shared secret via API Gateway to Lambda for DynamoDB access is insecure and unnecessary; secrets should never be passed through API Gateway payloads, and AWS recommends using IAM roles for service-to-service authentication. Option D is wrong because storing DynamoDB access keys (long-term credentials) in Lambda environment variables violates security best practices—they can be exposed in logs, console, or version history—and AWS strongly recommends using IAM roles with temporary credentials instead.

291
MCQmedium

A developer is configuring an S3 bucket to host a static website. The bucket policy allows public read access. However, users receive a 403 Forbidden error when accessing the website. What is the most likely cause?

A.The bucket is located in a different AWS region than the website endpoint.
B.The bucket name does not match the domain name.
C.The bucket has 'Block all public access' settings enabled.
D.The bucket is not configured with CloudFront as a content delivery network.
AnswerC

The S3 Block Public Access settings are a powerful security control that overrides any bucket policies or access control lists (ACLs) that might otherwise grant public read access. When 'Block all public access' is enabled, it explicitly prevents anonymous users from accessing objects within the bucket, including static website content. For a static website to be publicly accessible, these settings must be disabled, specifically the 'Block public and cross-account access to buckets and objects' option, allowing the bucket policy to grant public read permissions.

Why this answer

The 'Block all public access' settings in the S3 bucket's Permissions tab override any bucket policy that grants public read access. Even if the bucket policy explicitly allows s3:GetObject for Principal "*", enabling any of the four block public access settings (especially 'Block public access to buckets and objects granted through new public bucket policies' or 'Block public and cross-account access to buckets and objects through any public bucket policies') will cause S3 to reject all anonymous requests, resulting in a 403 Forbidden error when accessing the static website endpoint.

Exam trap

The trap here is that candidates assume a bucket policy granting public read access is sufficient for static website hosting, overlooking that S3's Block Public Access settings act as a separate, overriding permission layer that can silently deny all public access even when the bucket policy is correctly configured.

How to eliminate wrong answers

Option A is wrong because S3 static website hosting endpoints are region-specific (e.g., http://bucket-name.s3-website-us-east-1.amazonaws.com), but the bucket's region does not affect access permissions; a 403 Forbidden error is an authorization issue, not a routing issue. Option B is wrong because while a bucket name must match the domain name for custom domain mapping (e.g., via Route 53), the 403 Forbidden error occurs regardless of domain name mismatch; a mismatch would cause a DNS resolution failure or a different error (e.g., 404 NoSuchBucket), not a 403. Option D is wrong because CloudFront is not required for S3 static website hosting; S3 can serve content directly via its website endpoint, and the absence of CloudFront does not cause a 403 Forbidden error—it would only affect performance, caching, or HTTPS support if not configured.

292
Multi-Selectmedium

Which TWO actions are recommended to secure an S3 bucket? (Choose 2)

Select 2 answers
A.Block public access at the bucket level
B.Disable versioning to reduce complexity
C.Use HTTP instead of HTTPS for faster access
D.Enable default encryption
E.Grant public read access via ACLs
AnswersA, D

Blocking public access at the bucket level is a key security control that prevents all public access, even if a bucket policy or ACL explicitly grants it. This setting overrides any permissive configuration and acts as a safety net against accidental data leaks, making it a mandatory part of AWS S3 security best practices. By enforcing this at the bucket level, you eliminate the risk of objects being inadvertently exposed to the internet.

Why this answer

Option A is correct because enabling S3 Block Public Access at the bucket level overrides any bucket policy or ACL that would otherwise grant public access, preventing accidental exposure of objects. Option D is correct because enabling default encryption (SSE-S3, SSE-KMS, or SSE-C) ensures all objects are encrypted at rest automatically, protecting data even if storage media is compromised. Option B is wrong because disabling versioning reduces recoverability from accidental deletes or overwrites and is not a security best practice.

Option C is wrong because HTTP transmits data in plaintext; HTTPS (TLS) should always be used to protect data in transit. Option E is wrong because granting public read access via ACLs exposes objects to anyone on the internet, directly undermining bucket security.

Exam trap

DVA-C02 often tests whether candidates confuse 'security best practice' with 'operational convenience' — options like disabling versioning or using HTTP sound simpler but are anti-patterns, and the exam expects you to reject them immediately.

293
MCQeasy

Refer to the exhibit. A developer attached this bucket policy to an S3 bucket. Users from the 192.0.2.0/24 network can access objects, but users from a different network (203.0.113.0/24) get access denied. What change should be made to allow both networks?

A.Add a new statement with a different Principal.
B.Change the Condition to aws:SourceIp: "203.0.113.0/24".
C.Remove the Condition block entirely.
D.Change the Condition to use a list of IP ranges: ["192.0.2.0/24", "203.0.113.0/24"].
AnswerD

AWS IAM policies support specifying multiple values for a single condition key by using a JSON array. When aws:SourceIp is assigned a list like ["192.0.2.0/24", "203.0.113.0/24"], the condition evaluates to true if the request originates from *any* of the IP ranges within that list. This correctly allows access from both the 192.0.2.0/24 and 203.0.113.0/24 networks, fulfilling the requirement in a single, concise policy statement.

Why this answer

The `aws:SourceIp` condition key accepts a list of IP ranges in an array format. By specifying both `192.0.2.0/24` and `203.0.113.0/24` in the condition, the bucket policy will grant access to requests originating from either network, resolving the access denied error for the second network.

Exam trap

The trap here is that candidates mistakenly think the `aws:SourceIp` condition key can only hold a single value, leading them to choose Option B, when in fact it accepts a list of IP ranges to allow multiple networks.

How to eliminate wrong answers

Option A is wrong because the `Principal` element in an S3 bucket policy specifies the AWS account or IAM entity allowed to access the bucket, not the network IP range; adding a different Principal would not fix the IP-based restriction. Option B is wrong because changing the condition to only `203.0.113.0/24` would deny access to the original `192.0.2.0/24` network, simply swapping which network is blocked. Option C is wrong because removing the `Condition` block entirely would allow all IP addresses to access the bucket, which is overly permissive and violates the principle of least privilege.

294
MCQmedium

A company is using an Application Load Balancer (ALB) to route traffic to a set of EC2 instances. The security team wants to ensure that only traffic from the ALB can reach the instances. Which security group configuration should be used?

A.Configure the EC2 instance security group to allow traffic from the ALB's private IP address range.
B.Configure the network ACL for the EC2 instance subnet to allow traffic from the ALB security group.
C.Configure the EC2 instance security group to allow traffic from the ALB security group.
D.Configure the EC2 instance security group to allow HTTP traffic from 0.0.0.0/0.
AnswerC

Configuring the EC2 instance security group to allow traffic from the ALB security group is the correct and most robust solution. By referencing the ALB's security group ID as the source in the EC2 instance's inbound rules, you dynamically permit traffic only from the network interfaces associated with that specific ALB. This ensures secure communication, automatically adapts to ALB scaling or underlying IP address changes, and adheres to the principle of least privilege by restricting access solely to the load balancer.

Why this answer

Option C is correct because security groups can reference other security groups as a source, so the EC2 instances' security group can allow inbound traffic specifically from the ALB's security group, ensuring only ALB-forwarded traffic reaches the instances. This approach is the AWS-recommended pattern and works regardless of the ALB's changing IP addresses. Option A is wrong because ALB IP addresses are dynamic and not a stable, manageable source.

Option B is wrong because network ACLs cannot reference security groups as a source; they only support CIDR-based rules. Option D is wrong because allowing HTTP from 0.0.0.0/0 exposes the instances to the entire internet, not just the ALB.

295
MCQhard

A company has an S3 bucket with versioning enabled. A developer accidentally deleted an object. What must be done to recover it?

A.Copy the object from another bucket
B.Restore the object from Glacier Deep Archive
C.Delete the delete marker
D.Enable versioning on the bucket
AnswerC

When versioning is enabled, deleting an object does not erase its data but instead inserts a delete marker as the new current version; removing that specific delete marker version makes the previous object version become current again, effectively undeleting the object without any data loss.

Why this answer

When versioning is enabled on an S3 bucket, a delete operation does not actually remove the object; instead, it inserts a delete marker that becomes the current version, hiding the previous versions. To recover the object, you must delete that delete marker, which promotes the prior object version back to being the current version and makes it accessible again. Option C is therefore correct.

Option A is wrong because no copy exists elsewhere, option B is wrong because Glacier Deep Archive is a storage class for archival data and is not involved in this recovery, and option D is wrong because versioning is already enabled and enabling it again would not restore the object.

296
MCQmedium

An application running on EC2 needs to access an S3 bucket. The security team wants to avoid using long-term access keys. What is the most secure approach?

A.Generate an access key and secret key for an IAM user and store them on the instance.
B.Create a new IAM user and store the credentials in S3 with bucket policies.
C.Use AWS Systems Manager Parameter Store to store the credentials and retrieve them at runtime.
D.Launch the EC2 instance with an IAM role that grants S3 access.
AnswerD

Launching an EC2 instance with an attached IAM role is the most secure and recommended method for granting AWS resource access. This approach leverages the instance metadata service to provide temporary, frequently rotated credentials to applications running on the instance. These credentials are never stored directly on the instance, eliminating the risk associated with static access keys and simplifying credential management and rotation.

Why this answer

Assigning an IAM role to an EC2 instance allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS) automatically via the instance metadata service. This eliminates the need to store, rotate, or manage long-term access keys, adhering to the security team's requirement for a credential-less approach. The IAM role's permissions policy grants the EC2 instance access to the S3 bucket, and the credentials are automatically rotated by AWS before they expire.

Exam trap

The trap here is that candidates often confuse 'secure storage' (like Parameter Store or Secrets Manager) with 'no long-term credentials at all,' failing to recognize that an IAM role provides temporary credentials that are inherently more secure and require no key management on the instance.

How to eliminate wrong answers

Option A is wrong because storing an access key and secret key on the EC2 instance introduces long-term static credentials that can be compromised if the instance is breached, violating the security team's requirement to avoid long-term access keys. Option B is wrong because storing IAM user credentials in S3 with bucket policies still relies on long-term access keys and adds unnecessary complexity; bucket policies cannot securely protect the credentials themselves from unauthorized access. Option C is wrong because while Systems Manager Parameter Store can securely store secrets, the EC2 instance still needs a mechanism (such as an IAM role) to retrieve them at runtime, and using Parameter Store with long-term credentials stored as parameters does not eliminate the underlying risk of managing static keys.

297
MCQmedium

Given the IAM policy above, what is the effective permission for an IAM user?

A.No access to the bucket.
B.Full access to the bucket including delete.
C.Read-only access to the bucket.
D.Full access to the bucket except delete.
AnswerC

The policy grants only s3:GetObject and s3:ListBucket actions, with no PutObject, DeleteObject or bucket-level write permissions attached. The IAM user can therefore retrieve and enumerate objects but cannot modify or remove them, giving read-only access.

Why this answer

The IAM policy grants only s3:GetObject and s3:ListBucket permissions, which allow reading objects and listing the bucket, and explicitly denies s3:DeleteObject. Since no write permissions (e.g., s3:PutObject) are granted, the effective permission is read-only access (list and get) with delete explicitly denied. Therefore, the user has read-only access to the bucket, not full access.

Exam trap

Candidates often misinterpret 'full access except delete' as including write permissions, but the policy only grants read and list actions. The explicit deny on delete does not add write permissions.

How to eliminate wrong answers

Option A is wrong because the policy grants read access (s3:GetObject and s3:ListBucket), so the user does have access to the bucket. Option B is wrong because the policy includes an explicit deny for s3:DeleteObject, which prevents full access including delete. Option C is wrong because the policy does not grant write permissions (e.g., s3:PutObject), but the user has read access plus the ability to list, which is not strictly read-only (though close); more importantly, the explicit deny on delete does not make it read-only—it still allows read and list actions, but the key point is that the correct answer is D, not C.

298
MCQmedium

A company runs an application on Amazon EC2 that needs to securely store database credentials. The security team requires that credentials be automatically rotated every 30 days to reduce the risk of compromise. The application must be able to retrieve the credentials at startup without storing them in code or configuration files. Which AWS service should the developer use?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store (SecureString)
C.AWS Key Management Service (KMS)
D.AWS Identity and Access Management (IAM) roles
AnswerA

AWS Secrets Manager is purpose-built for securely storing, managing, and automatically rotating sensitive application secrets, such as database credentials. It integrates directly with services like Amazon RDS to facilitate seamless, scheduled password rotation without requiring manual intervention, significantly enhancing security posture and reducing operational overhead. This capability directly addresses the requirement for automatic rotation.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, retrieve, and automatically rotate database credentials on a schedule (e.g., every 30 days) without requiring custom code. The application can retrieve credentials at startup via the Secrets Manager API using IAM permissions, eliminating the need to store secrets in code or configuration files. Secrets Manager natively supports automatic rotation for Amazon RDS, Redshift, and DocumentDB, and can be extended to other services via custom Lambda functions.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (SecureString) with Secrets Manager, overlooking that Parameter Store lacks native automatic rotation, which is a key requirement in the question.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store (SecureString) can store encrypted secrets but does not natively support automatic rotation of credentials; rotation would require custom automation via AWS Lambda or other services. Option C is wrong because AWS Key Management Service (KMS) is a key management and encryption service that does not store or rotate secrets; it only provides encryption keys for protecting data. Option D is wrong because AWS Identity and Access Management (IAM) roles provide temporary credentials for AWS service access, not for storing or rotating database credentials; they cannot be used to retrieve static secrets like database passwords.

299
MCQhard

A company has multiple AWS accounts managed under AWS Organizations. The security team requires that all Amazon S3 buckets with bucket names containing 'logs' must be encrypted with a specific KMS key (key ID: alias/logs-key) at rest. A developer must enforce this using an SCP (Service Control Policy). Which SCP effect and condition key should be used to deny any PutObject request that does not use the required KMS key?

A.Deny effect with a Condition: StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id
B.Deny effect with a Condition: StringEquals on s3:x-amz-server-side-encryption
C.Allow effect with a Condition: StringEquals on kms:RequestTag/key-id
D.Deny effect with a Condition: IpAddress on aws:SourceIp
AnswerA

This SCP will deny any PutObject request that specifies a KMS key that is not the required key. The StringNotEquals condition ensures that if the request does not use the specific key ID, the request is denied. This is the standard way to enforce encryption with a specific KMS key using SCPs.

Why this answer

SCPs use a Deny effect to block non-compliant requests. The condition key `s3:x-amz-server-side-encryption-aws-kms-key-id` with `StringNotEquals` ensures that any PutObject request that does not specify the exact KMS key alias/logs-key is denied. This enforces encryption with the required key for all S3 buckets containing 'logs' in their name.

Exam trap

The trap here is that candidates confuse `s3:x-amz-server-side-encryption` (which only checks encryption type) with `s3:x-amz-server-side-encryption-aws-kms-key-id` (which checks the specific KMS key), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption` only checks whether server-side encryption is enabled (e.g., AES256 or aws:kms), but does not verify the specific KMS key ID, so it cannot enforce the required key. Option C is wrong because Allow effects in SCPs are permissive and cannot deny non-compliant requests; also `kms:RequestTag/key-id` is not a valid condition key for S3 PutObject operations. Option D is wrong because `aws:SourceIp` restricts requests based on IP address, which is unrelated to encryption key enforcement.

300
MCQmedium

A developer is building a serverless application using AWS Lambda. The Lambda function needs to read messages from an Amazon SQS queue and write items to an Amazon DynamoDB table. The developer wants to follow the principle of least privilege and avoid hardcoding credentials. Which approach should the developer use to grant the Lambda function the necessary permissions?

A.Create an IAM role with the required permissions and configure it as the Lambda function's execution role. Lambda will assume this role automatically.
B.Create an IAM user with programmatic access and store the access key ID and secret access key as environment variables in the Lambda function configuration.
C.Attach an IAM policy directly to the Lambda function's resource policy that grants access to SQS and DynamoDB.
D.Store the AWS credentials in AWS Secrets Manager and have the Lambda function retrieve them at runtime using the Secrets Manager API.
AnswerA

Lambda functions assume an execution role to obtain temporary credentials for accessing AWS services. By attaching an IAM role with the necessary SQS and DynamoDB permissions, the function can securely interact with these services without hardcoded credentials. This follows least privilege and is the AWS-recommended approach for Lambda permissions.

Why this answer

The Lambda execution role is assumed by the function at runtime, providing temporary credentials with the permissions defined in the role's policies. This approach eliminates the need to manage long-term credentials and adheres to least privilege. Other methods either involve long-term credentials or misunderstand the purpose of resource policies.

Exam trap

The trap here is confusing Lambda resource policies with execution roles; resource policies control who can invoke the function, not what the function can access.

← PreviousPage 4 of 5 · 314 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.