Courseiva
Security and Compliance →hardMultiple Select

DOP-C02 Security and Compliance Practice Question

A DevOps team is designing a CI/CD pipeline that deploys a web application on Amazon ECS. The application must be compliant with PCI DSS, which requires encryption of data at rest and in transit, and logging of all access. Which THREE actions should the team implement to meet these requirements? (Choose THREE.)

⚠ Common exam trap

Candidates often confuse security best practices (like storing secrets in Parameter Store or using VPC endpoints) with mandatory compliance actions for encryption and logging, leading them to select options that are helpful but not directly required by PCI DSS for the specific three actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail and Amazon ECS logs to capture all API calls and container logs.

AWS CloudTrail captures all API calls to the AWS environment, providing an audit trail of who accessed what and when, which is required for PCI DSS logging. Amazon ECS logs (via CloudWatch Logs or FireLens) capture container-level access and application logs, ensuring comprehensive logging of all access to the application and underlying infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable AWS CloudTrail and Amazon ECS logs to capture all API calls and container logs.

    Why this is correct

    AWS CloudTrail records every API call made against the AWS account, including ECS, ECR, and other service actions, which is essential for auditing who did what and when. Amazon ECS logs, collected via the awslogs driver, capture container stdout/stderr for operational auditing and forensic analysis. Together they provide the necessary audit trail to verify compliance and detect unauthorized access or changes, directly addressing the requirement to capture all API calls and container logs.

  • ✗

    Store database credentials in AWS Systems Manager Parameter Store.

    Why it's wrong here

    AWS Systems Manager Parameter Store can store database credentials, but by default it does not encrypt parameter values; they are stored as plaintext unless you explicitly specify a KMS key. Using Parameter Store without KMS encryption leaves sensitive credentials exposed at rest, failing the security requirement for data protection. To correctly use it, you would need to configure a KMS customer master key and assign a SecureString parameter to ensure encryption.

  • ✗

    Use VPC endpoints to access ECS and ECR APIs.

    Why it's wrong here

    VPC endpoints for ECS and ECR keep API traffic within the AWS network, but they do not provide encryption of data in transit or any logging of access. Traffic over a VPC endpoint is still subject to the same TLS requirements for encryption, and endpoint access itself is not logged by CloudTrail as a security audit mechanism. They address network isolation, not the stated need for encryption-at-rest, encryption-in-transit, or auditing, so they are an incomplete security control.

  • ✓

    Enable ECS task definition encryption using AWS KMS for environment variables and sensitive data.

    Why this is correct

    Enabling ECS task definition encryption with AWS KMS ensures that sensitive data such as environment variables and other embedded secrets are encrypted at rest. KMS keys manage the encryption/decryption process, and IAM policies control who can use the key to decrypt those values. This meets the requirement for protecting sensitive data at rest, complementing the other controls for in-transit encryption and logging.

  • ✓

    Configure an Application Load Balancer (ALB) with an HTTPS listener using an SSL/TLS certificate.

    Why this is correct

    Configuring an Application Load Balancer with an HTTPS listener using an SSL/TLS certificate from ACM (or imported) encrypts all traffic between clients and the load balancer. This protects data in transit from eavesdropping and tampering, satisfying the requirement for encryption of data moving across the network. It is a distinct layer of defense, separate from the encryption-at-rest and auditing controls provided by KMS and CloudTrail/ECS logs.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.