Courseiva

CCNA Security Questions

14 of 314 questions · Page 5/5 · Security · Answers revealed

301
MCQeasy

A developer wants to ensure that an S3 bucket only allows HTTPS requests. What S3 bucket policy condition should be used?

A.aws:CurrentTime
B.aws:MultiFactorAuthPresent
C.aws:SourceIp
D.aws:SecureTransport
AnswerD

The aws:SecureTransport condition key specifically evaluates whether the incoming request to an S3 bucket was made using HTTPS (TLS/SSL). When set to "true" in a bucket policy, it mandates that all interactions with the bucket must occur over an encrypted connection, effectively preventing unencrypted HTTP requests. This directly addresses the requirement to ensure that the S3 bucket only allows secure, encrypted data transfer.

Why this answer

The aws:SecureTransport condition checks whether the request was sent using SSL/TLS, effectively enabling HTTPS-only access. Option A is incorrect because aws:CurrentTime is used to allow or deny access based on the time of the request. Option B is incorrect because aws:MultiFactorAuthPresent checks if the requester authenticated with multi-factor authentication.

Option C is incorrect because aws:SourceIp is used to restrict requests based on the source IP address.

302
MCQmedium

Refer to the exhibit. A developer deploys this CloudFormation template. The Lambda function needs to write objects to an S3 bucket named 'my-app-bucket'. What must the developer add to the template?

A.Add an S3 bucket policy allowing the Lambda function's ARN to write objects.
B.Add a policy statement to LambdaExecutionRole allowing 's3:*' on 'arn:aws:s3:::my-app-bucket'.
C.Add a KMS key policy to allow the Lambda function to use a customer managed key.
D.Add a new policy statement to LambdaExecutionRole allowing 's3:PutObject' on 'arn:aws:s3:::my-app-bucket/*'.
AnswerD

This is the correct solution as it precisely grants the necessary permissions while adhering to the principle of least privilege. Attaching a policy statement to the 'LambdaExecutionRole' is the standard method for providing a Lambda function with permissions to interact with other AWS services. The 's3:PutObject' action is the specific permission required to write objects, and 'arn:aws:s3:::my-app-bucket/*' correctly scopes this permission to all objects within the specified S3 bucket.

Why this answer

The Lambda function requires an IAM policy attached to its execution role to grant permissions for specific S3 actions. The `s3:PutObject` action on the `arn:aws:s3:::my-app-bucket/*` resource ARN precisely allows writing objects to the bucket, following the principle of least privilege. Without this policy statement, the Lambda function will receive an access denied error when trying to write to S3.

Exam trap

The trap here is that candidates often confuse bucket-level ARNs with object-level ARNs, selecting overly permissive options like `s3:*` on the bucket ARN instead of scoping the exact action and resource, or incorrectly assuming an S3 bucket policy is needed for same-account Lambda access.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy is used to grant cross-account access or public access, not to grant permissions to a Lambda function within the same account; the Lambda function's execution role is the correct mechanism. Option B is wrong because it uses a wildcard `s3:*` action and the bucket-level ARN `arn:aws:s3:::my-app-bucket` instead of the object-level ARN `arn:aws:s3:::my-app-bucket/*`, which is overly permissive and does not correctly scope the `s3:PutObject` permission to objects within the bucket. Option C is wrong because there is no indication that the S3 bucket uses a customer managed KMS key; the question only states the Lambda function needs to write objects, and KMS key policy is only relevant if server-side encryption with KMS is enabled, which is not mentioned.

303
MCQmedium

A developer is using CloudFront to serve content from an S3 bucket. The bucket contains sensitive data and should only be accessible through CloudFront. How can the developer enforce this?

A.Set the bucket policy to allow access only from CloudFront IP addresses.
B.Set the bucket policy to allow access only from AWS services.
C.Set the bucket policy to allow public read access and use CloudFront signed URLs.
D.Create an origin access identity (OAI) and grant it read access in the bucket policy.
AnswerD

Creating an Origin Access Identity (OAI) and granting it read access in the S3 bucket policy is the recommended and most secure method. The OAI acts as a virtual user for your CloudFront distribution, allowing only that specific distribution to retrieve content from the S3 bucket. This prevents direct public access to the S3 bucket while enabling CloudFront to serve the content securely to end-users.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with your distribution. By configuring the S3 bucket policy to grant read access only to that OAI, you ensure that content can only be retrieved via CloudFront, not directly from the S3 endpoint. This enforces the requirement that the bucket is accessible exclusively through CloudFront.

Exam trap

The trap here is that candidates often assume restricting by CloudFront IP addresses (Option A) is a valid approach, but AWS explicitly warns that CloudFront IP ranges are not static and should not be used for access control in bucket policies.

How to eliminate wrong answers

Option A is wrong because CloudFront IP addresses are not static and can change over time; using them in a bucket policy would require constant updates and is not a supported or reliable method for restricting access. Option B is wrong because there is no generic 'AWS services' principal in S3 bucket policies; you must specify a specific service principal or user, and this approach would not restrict access to CloudFront only. Option C is wrong because allowing public read access defeats the purpose of restricting access to CloudFront; signed URLs can control who accesses content via CloudFront, but the bucket itself would remain publicly accessible, violating the requirement.

304
MCQhard

A Lambda function needs to write logs to CloudWatch Logs. The developer attaches an IAM role with a policy that allows logs:CreateLogGroup and logs:PutLogEvents. However, logs are not appearing. What is the most likely cause?

A.The Lambda function is not configured to use a VPC.
B.The IAM role does not have a trust policy that allows Lambda to assume it.
C.The IAM policy does not include logs:CreateLogStream.
D.The CloudWatch Logs log group does not exist.
AnswerC

For a Lambda function to successfully write logs to CloudWatch Logs, its execution role requires specific permissions. While `logs:PutLogEvents` is necessary to transmit the actual log data, the function also crucially needs `logs:CreateLogStream` to establish a new log stream within the designated log group if one does not already exist for that particular invocation or execution environment. Without this `CreateLogStream` permission, the function cannot initialize the required logging infrastructure, leading to a failure in log delivery, even if it possesses the permission to put events.

Why this answer

Lambda requires the `logs:CreateLogStream` permission to create a log stream within a log group before it can write log events. Without this permission, the function can create the log group but cannot create the individual log stream needed to store log entries, causing logs to silently fail to appear.

Exam trap

The trap here is that candidates assume `logs:CreateLogGroup` and `logs:PutLogEvents` are sufficient, overlooking the mandatory `logs:CreateLogStream` permission required for the log stream creation step between group creation and event writing.

How to eliminate wrong answers

Option A is wrong because Lambda functions can write logs to CloudWatch Logs without being in a VPC; VPC configuration affects network access but not log delivery. Option B is wrong because the Lambda function already has an IAM role attached, meaning the trust policy (which allows Lambda to assume the role) was already validated when the role was assigned to the function. Option D is wrong because CloudWatch Logs automatically creates the log group if it does not exist when the Lambda function first invokes, provided the IAM policy includes `logs:CreateLogGroup`.

305
Multi-Selecteasy

Which of the following are valid ways to secure access to an Amazon S3 bucket? (Choose TWO.)

Select 2 answers
A.Bucket policies
B.CloudFront distribution
C.IAM policies
D.Network ACLs
E.Security groups
AnswersA, C

Bucket policies are resource-based access policies directly attached to an S3 bucket, defining who (principals like IAM users, roles, or other AWS accounts) can perform which actions (e.g., GetObject, PutObject) on the objects within that specific bucket. They are fundamental for granting cross-account access, defining public access configurations, or restricting access based on IP addresses. These policies act as a primary access control layer, evaluated directly by the S3 service upon every request to the bucket.

Why this answer

Bucket policies are a form of resource-based policy that you attach directly to an S3 bucket. They allow you to grant or deny access to the bucket and its objects for principals (users, roles, or AWS accounts) using the AWS JSON policy language. This is a primary and native way to control access to S3 resources, making option A correct.

Exam trap

The trap here is that candidates confuse network-level security controls (like NACLs and Security Groups) with resource-level access controls, mistakenly thinking they can be applied to S3 buckets, which are global services not bound to a VPC subnet.

306
MCQmedium

A company is using Amazon Cognito for user authentication. The developers need to add multi-factor authentication (MFA) for security. Which Cognito feature should be enabled?

A.Cognito Sync
B.Cognito User Pools with MFA configuration
C.Cognito Developer Authenticated Identities
D.Cognito Identity Pools
AnswerB

Cognito User Pools are the identity store and authentication service in Cognito, and they include a native MFA configuration option supporting SMS text message codes or TOTP authenticator apps, which can be set to off, optional, or required per user pool, directly satisfying the requirement to add MFA.

Why this answer

Amazon Cognito User Pools support multi-factor authentication (MFA) configurations, including SMS and TOTP. Option A is incorrect because Cognito Sync is used for synchronizing user data across devices, not for authentication or MFA. Option C is incorrect because Developer Authenticated Identities is a feature for custom authentication flows, not directly for enabling MFA.

Option D is incorrect because Cognito Identity Pools provide federated identities for accessing AWS resources, but MFA is configured at the User Pool level.

307
Multi-Selectmedium

A developer is troubleshooting an issue where an IAM user cannot perform 's3:ListBucket' on a bucket. Which THREE factors could cause this denial?

Select 3 answers
A.The bucket is in a different region than the user's default region.
B.An explicit deny statement in the bucket policy.
C.The bucket is encrypted with AWS KMS.
D.The user has a permissions boundary that does not include s3:ListBucket.
E.The user's IAM policy does not include s3:ListBucket.
AnswersB, D, E

AWS IAM policy evaluation logic dictates that an explicit Deny statement always overrides any Allow statements, regardless of where the Allow is defined (e.g., in the user's identity-based policy). If the S3 bucket policy contains an explicit Deny for the s3:ListBucket action for the specific user or a group they belong to, this Deny will take precedence and prevent the user from listing the bucket's contents, even if their IAM policy allows it.

Why this answer

Option B is correct because an explicit Deny in a bucket policy always overrides any Allow in an identity-based policy, so a Deny on s3:ListBucket would block the user regardless of other permissions. Option D is correct because a permissions boundary sets the maximum permissions an IAM user can have; if s3:ListBucket is not within the boundary, the effective permissions cannot include it even if an identity policy allows it. Option E is correct because s3:ListBucket must be explicitly granted in an identity-based policy (or another applicable policy) for the user to list the bucket, and its absence results in an implicit deny.

Option A is not correct because S3 bucket access is not restricted by the user's default region; region only affects endpoint routing, not authorization. Option C is not correct because KMS encryption affects access to object data via kms:Decrypt, not the s3:ListBucket permission itself.

Exam trap

Candidates often forget that a permissions boundary acts as a maximum permission limit. If an action (like s3:ListBucket) is not explicitly allowed in the permissions boundary, the user cannot perform that action, even if their identity-based IAM policy explicitly allows it.

308
MCQeasy

A developer needs to allow an IAM user to stop and start EC2 instances but not terminate them. Which IAM policy effect and action combination should be used?

A.Allow ec2:StopInstances and ec2:StartInstances
B.Allow ec2:StopInstances, ec2:StartInstances, and ec2:TerminateInstances
C.Deny ec2:TerminateInstances
D.Allow ec2:StartInstances and ec2:TerminateInstances
AnswerA

Granting only ec2:StartInstances and ec2:StopInstances gives the IAM user exactly the actions needed to power instances on and off while omitting ec2:TerminateInstances entirely, so any attempt to terminate an instance is implicitly denied by IAM's default-deny behavior, satisfying the requirement precisely.

Why this answer

It explicitly allows ec2:StopInstances and ec2:StartInstances, which grants the needed permissions without allowing ec2:TerminateInstances. Option B is incorrect because it includes ec2:TerminateInstances, which would allow termination, contrary to the requirement. Option C is incomplete: although it denies ec2:TerminateInstances, it does not allow ec2:StopInstances or ec2:StartInstances, so the user would not have the required start/stop permissions.

Option D is incorrect because it allows ec2:TerminateInstances.

309
MCQhard

An S3 bucket policy allows GetObject from another account, but objects encrypted with SSE-KMS still return AccessDenied. Which additional authorization is required?

A.The caller must be allowed to use the KMS key for decrypt operations
B.The caller must own the destination VPC
C.The bucket must enable static website hosting
D.The object key must end with .kms
AnswerA

When an S3 object is encrypted using Server-Side Encryption with AWS KMS (SSE-KMS), the requesting principal requires explicit kms:Decrypt permissions on the associated KMS key. Even if the S3 bucket policy grants s3:GetObject to another account, the cross-account caller cannot retrieve the object's plaintext data without the necessary KMS key usage permissions. This dual authorization ensures robust data protection by separating storage access from encryption key access.

Why this answer

When an S3 object is encrypted with SSE-KMS, the S3 bucket policy granting GetObject access is not sufficient because S3 must also decrypt the object before returning it. The AWS KMS key policy must grant the caller kms:Decrypt permission, and the caller's IAM policy must also allow kms:Decrypt on the specific KMS key. Without this additional KMS authorization, S3 returns AccessDenied even if the bucket policy allows GetObject.

Exam trap

The trap here is that candidates assume a bucket policy granting s3:GetObject is sufficient for all objects, forgetting that SSE-KMS adds a separate authorization layer via KMS key policies that must explicitly allow the decrypt operation.

How to eliminate wrong answers

Option B is wrong because VPC ownership is irrelevant to S3 object access; S3 bucket policies and KMS permissions control cross-account access, not network ownership. Option C is wrong because static website hosting is a feature for serving public content and has no bearing on KMS-encrypted object access or cross-account authorization. Option D is wrong because the object key suffix has no effect on KMS authorization; SSE-KMS encryption is determined by the object's encryption settings, not its filename.

310
Multi-Selecteasy

Which TWO are features of AWS Identity and Access Management (IAM)? (Choose 2)

Select 2 answers
A.Encrypt S3 objects automatically
B.Monitor network traffic
C.Define fine-grained permissions with policies
D.Manage EC2 instance lifecycle
E.Create and manage IAM users and groups
AnswersC, E

IAM policies are the core mechanism for defining fine-grained permissions. You can craft JSON-based identity policies that specify exactly which actions are allowed or denied on which resources, under what conditions (e.g., source IP, MFA presence, time of day). This allows least-privilege access control at the resource and API-action level, central to IAM's purpose.

Why this answer

Option C is correct because IAM's core purpose is to define fine-grained permissions using JSON policy documents that specify which principals can perform which actions on which resources under which conditions. Option E is correct because IAM natively provides identity management, allowing you to create and manage IAM users, groups, and roles, and attach policies to them for access control. Option A is incorrect because automatic S3 object encryption is a feature of Amazon S3 (e.g., SSE-S3, SSE-KMS, or default bucket encryption), not IAM.

Option B is incorrect because network traffic monitoring is handled by services such as VPC Flow Logs, CloudWatch, or GuardDuty, not IAM. Option D is incorrect because EC2 instance lifecycle management is performed through EC2, Auto Scaling, or EC2 Instance Lifecycle policies, not IAM.

Exam trap

DVA-C02 often tests the misconception that IAM performs encryption or network monitoring, when IAM is strictly an identity and access control service — encryption and traffic monitoring belong to KMS/S3 and VPC Flow Logs/GuardDuty respectively.

311
Multi-Selectmedium

Which THREE components are required to enable encryption in transit for an Application Load Balancer? (Choose THREE.)

Select 3 answers
A.A security group rule allowing inbound traffic on port 443
B.An SSL/TLS certificate from ACM or uploaded to IAM
C.A listener configured on port 443 with the certificate
D.Server Name Indication (SNI) support
E.An HTTP to HTTPS redirect rule
AnswersA, B, C

To enable encryption, the Application Load Balancer (ALB) must be able to receive incoming encrypted traffic from clients. A security group rule allowing inbound traffic on port 443 (HTTPS) is fundamental, as it acts as a virtual firewall, explicitly permitting the necessary TLS communication to reach the ALB. Without this rule, client connections attempting to establish an encrypted session would be blocked at the network layer, preventing any encryption from occurring.

Why this answer

A security group rule allowing inbound traffic on port 443 is required because the Application Load Balancer (ALB) must accept HTTPS traffic from clients. Without this rule, the ALB's network interface will drop encrypted connections, preventing any TLS handshake from completing. This ensures that traffic between clients and the ALB is encrypted in transit.

Exam trap

The trap here is that candidates often confuse optional features like SNI or redirect rules as mandatory requirements, when in fact only the security group rule, the certificate, and the listener on port 443 are strictly necessary for encryption in transit.

312
MCQeasy

A developer needs to grant an IAM user access to an S3 bucket for read-only operations. Which IAM policy action should be used?

A.s3:PutObject
B.s3:DeleteObject
C.s3:ListBucket
D.s3:GetObject
AnswerD

s3:GetObject is the specific action that permits downloading an object's content from S3, and it carries no ability to write, overwrite, or delete anything, making it the precise, minimal permission that satisfies a read-only access requirement for retrieving object data.

Why this answer

S3:GetObject allows reading objects from S3, which is required for read-only operations. Option A (s3:PutObject) allows writing, option B (s3:DeleteObject) allows deletion, and option C (s3:ListBucket) allows listing bucket contents but not reading object content, so none of these provide read-only access.

313
MCQeasy

A developer is using the AWS CLI to upload a file to an S3 bucket with server-side encryption. The bucket is configured with default encryption (SSE-S3). The developer wants to ensure the object is encrypted with SSE-KMS instead. What should the developer do?

A.Use the --kms-key-id parameter with a KMS key ARN
B.Use the --sse aws:kms parameter when uploading
C.No action needed; the bucket default encryption will apply
D.Change the bucket policy to require SSE-KMS
AnswerB

This is the correct action. To ensure a file is encrypted with Server-Side Encryption with AWS KMS (SSE-KMS) during an AWS CLI upload, the --sse aws:kms parameter must be explicitly specified. This parameter instructs S3 to use KMS for encryption. If a specific KMS key is desired, it can be combined with the --kms-key-id parameter; otherwise, S3 will use the default AWS managed key for S3 in the account.

Why this answer

The developer must explicitly specify the server-side encryption method at the time of upload using the `--sse aws:kms` parameter in the AWS CLI. This overrides the bucket's default SSE-S3 encryption, ensuring the object is encrypted with SSE-KMS. Without this parameter, the object inherits the bucket's default encryption (SSE-S3), regardless of any other settings.

Exam trap

The trap here is that candidates assume bucket default encryption always applies to all objects, but in reality, request-level encryption parameters take precedence over bucket defaults, and the developer must explicitly specify SSE-KMS to override SSE-S3.

How to eliminate wrong answers

Option A is wrong because the `--kms-key-id` parameter is used to specify a specific KMS key ARN when SSE-KMS is already selected, but it does not enable SSE-KMS by itself; the `--sse aws:kms` parameter must also be provided. Option C is wrong because the bucket's default encryption (SSE-S3) will apply automatically, which does not meet the developer's requirement for SSE-KMS; the default is not overridden without explicit request-level parameters. Option D is wrong because changing the bucket policy to require SSE-KMS only enforces that objects must be encrypted with SSE-KMS at the bucket level, but the developer still needs to specify `--sse aws:kms` in the upload command to comply with that policy and achieve the desired encryption.

314
MCQeasy

An application running on EC2 instances needs to access an S3 bucket securely. Which of the following is the BEST practice for managing credentials?

A.Store the AWS access key and secret key in a configuration file on the EC2 instance.
B.Use an IAM user with programmatic access and attach a policy allowing S3 access.
C.Launch the EC2 instance with an IAM role that grants S3 access.
D.Use a shared secret key stored in AWS Secrets Manager and retrieve it at runtime.
AnswerC

Launching an EC2 instance with an IAM role is the AWS best practice for granting applications secure access to AWS services like S3. An IAM role provides temporary security credentials that are automatically rotated and delivered to the instance via the instance metadata service. This eliminates the need to embed or manage long-term access keys on the instance, significantly reducing the risk of credential compromise and simplifying credential management, aligning with the principle of least privilege.

Why this answer

Assigning an IAM role to an EC2 instance is the AWS-recommended best practice for securely granting permissions to AWS services. The instance automatically obtains temporary security credentials from the instance metadata service (IMDS), eliminating the need to hardcode or manage long-term access keys. This approach follows the principle of least privilege and avoids the security risks of storing credentials on disk.

Exam trap

The trap here is that candidates often confuse IAM users with IAM roles, mistakenly thinking that creating a dedicated IAM user with programmatic access is a secure practice, when in fact IAM roles are the correct and secure method for EC2-to-S3 access because they eliminate the need to manage long-term credentials.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in a configuration file on the EC2 instance is a security risk; if the instance is compromised, the credentials are exposed and can be used indefinitely. Option B is wrong because using an IAM user with programmatic access requires distributing and managing long-term access keys, which violates the AWS security best practice of using IAM roles for EC2 workloads. Option D is wrong because while AWS Secrets Manager securely stores secrets, retrieving a shared secret key at runtime still introduces a long-term credential that must be managed and rotated, whereas an IAM role provides temporary, automatically rotated credentials without any secret management overhead.

← PreviousPage 5 of 5 · 314 questions total

Ready to test yourself?

Try a timed practice session using only Security questions.