Courseiva

CCNA Security and Compliance Questions

75 of 203 questions · Page 1/3 · Security and Compliance · Answers revealed

1
MCQhard

A company uses AWS KMS to encrypt EBS volumes. The security team wants to ensure that EBS snapshots are shared with another account without exposing the underlying data. What is the correct approach?

A.Share the encrypted snapshot without modifying the KMS key policy.
B.Create an unencrypted copy of the snapshot and share it.
C.Share the encrypted snapshot and also share the KMS key with the target account.
D.Share the encrypted snapshot and update the KMS key policy to allow the target account to use the key.
AnswerD

To securely share an encrypted snapshot, the source account must share the snapshot and modify the KMS key policy to include a statement that grants the target account's root principal the kms:Decrypt and kms:CreateGrant permissions needed to use the customer managed key. After adding this cross-account authorization, the target account can create an encrypted EBS volume from the shared snapshot. The target account's IAM user or role must also have corresponding EBS and KMS permissions, but the key policy is the critical mechanism that enables cross-account decryption.

Why this answer

Sharing an encrypted EBS snapshot requires the KMS key policy to grant the target account permission to use the key (via kms:Decrypt and kms:CreateGrant). Without this, the target account cannot decrypt the snapshot to create volumes or copies. AWS KMS enforces that the key policy explicitly allows cross-account access, and the target account must have the corresponding IAM permissions.

Exam trap

The trap here is that candidates often confuse sharing the KMS key itself (which is impossible) with updating the key policy to grant cross-account usage, leading them to select Option C.

How to eliminate wrong answers

Option A is wrong because sharing an encrypted snapshot without modifying the KMS key policy denies the target account the ability to decrypt the snapshot, making it unusable. Option B is wrong because creating an unencrypted copy of an encrypted snapshot would expose the underlying data in plaintext, violating the security requirement. Option C is wrong because sharing the KMS key with the target account is not a supported operation; KMS keys cannot be shared or transferred; instead, you must update the key policy to grant cross-account usage permissions.

2
MCQeasy

A DevOps engineer needs to ensure that all API calls made to AWS are logged for compliance. The logs must be stored in S3 for at least 7 years. Which AWS service should they use?

A.VPC Flow Logs
B.AWS Config
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

CloudTrail records every API call across the account, including the identity, source IP and timestamp, and delivers these events to an S3 bucket. This satisfies the requirement to log all API calls, with S3 lifecycle policies retaining the logs for the mandated seven years.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity, source IP, and timestamp, and can deliver log files to an S3 bucket for long-term retention. The requirement to store logs for at least 7 years aligns with CloudTrail's ability to integrate with S3 lifecycle policies for archival or deletion after a specified period.

Exam trap

The trap here is that candidates often confuse CloudTrail with CloudWatch Logs or AWS Config, thinking that any logging service can capture API calls, but only CloudTrail is designed specifically for auditing AWS API activity.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) for VPCs, not API calls to AWS services. Option B is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not log API calls. Option C is wrong because Amazon CloudWatch Logs is designed for real-time monitoring and log storage from applications and AWS services, but it is not the primary service for auditing AWS API calls; CloudTrail is the dedicated service for that purpose.

3
MCQhard

A company wants to enforce that S3 buckets are not publicly accessible. Which AWS service can continuously monitor and automatically remediate non-compliant buckets?

A.AWS Config
B.Amazon Macie
C.AWS Security Hub
D.AWS Trusted Advisor
AnswerA

AWS Config is the correct service because it offers managed rules specifically for detecting S3 public access, such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. These rules can be evaluated continuously, and when a violation is found, AWS Config can automatically invoke remediation actions through SSM automation documents, such as removing the public policy. This provides a continuous, automated enforcement mechanism that goes beyond simple detection, making it the only listed service capable of enforcing the requirement.

Why this answer

AWS Config continuously records resource configuration changes and evaluates them against Config rules, including the managed rule `s3-bucket-public-read-prohibited` and `s3-bucket-public-write-prohibited`. When a bucket becomes non-compliant, Config can trigger an SSM Automation document (via a remediation action) to automatically block public access, making it the service that both monitors and remediates.

Exam trap

DOP-C02 often tests the difference between detection and remediation — candidates pick Security Hub or Macie because they 'monitor' security, but only Config has native auto-remediation via SSM Automation.

How to eliminate wrong answers

Option B is wrong because Amazon Macie is a data-security service that discovers and classifies sensitive data (PII, credentials) in S3 — it does not evaluate bucket ACLs or policies for public access and cannot remediate them. Option C is wrong because AWS Security Hub aggregates and normalizes findings from other services (including Config) but does not itself perform continuous configuration evaluation or automatic remediation. Option D is wrong because Trusted Advisor provides advisory checks and recommendations but has no continuous evaluation engine or auto-remediation capability — it is a point-in-time best-practice report.

4
MCQeasy

A company uses AWS Secrets Manager to store database credentials for a legacy application running on an on-premises server. The application retrieves the secret via the AWS SDK. Recently, the database password was rotated in Secrets Manager, but the application continued to use the old password and failed to connect. The application code is correct and uses the latest SDK. The IAM role attached to the server has the secretsmanager:GetSecretValue permission. What is the MOST likely cause?

A.The IAM role does not have permission to list secrets
B.The application is using the wrong secret ID
C.The secret rotation Lambda function is failing
D.The application is caching the secret and not refreshing it after rotation
AnswerD

The AWS SDK and AWS Secrets Manager client-side caching libraries cache secret values in memory with a default TTL (e.g., 1 hour in Java) to reduce API calls. After rotation, the cached entry still holds the old AWSCURRENT value, and the application will keep using it until the cache expires or an explicit cache refresh is triggered. To fix this, the application must implement rotation-aware behavior, such as forcing a cache reload on authentication failure, shortening the TTL, or using the cached secret's version ID and comparing it to the newly fetched AWSCURRENT version. Without refreshing, the application is pinned to the pre-rotation secret indefinitely within the cache window.

Why this answer

The AWS SDK does not automatically re-fetch a secret on every call unless the application explicitly calls GetSecretValue again. Many applications cache the secret in memory (or in a local config) at startup for performance, so after Secrets Manager rotates the credential, the app keeps using the stale value. Since the IAM permission and SDK are correct, the most likely cause is client-side caching without a refresh mechanism.

Exam trap

The trap here is assuming that because the SDK is 'latest' and IAM is correct, the problem must be server-side (rotation Lambda or secret ID) — DOP-C02 often tests the client-side caching behaviour of Secrets Manager consumers.

How to eliminate wrong answers

Option A is wrong because secretsmanager:ListSecrets is only needed to enumerate secret names, not to retrieve a specific secret value — GetSecretValue is sufficient for the app's retrieval. Option B is wrong because an incorrect secret ID would cause a ResourceNotFoundException immediately, not a failure that appears only after a rotation. Option C is wrong because a failing rotation Lambda would leave the old password valid in the database, so the app would still connect successfully — the symptom described is the opposite.

5
Multi-Selectmedium

Which TWO actions can be taken to protect an S3 bucket from being publicly accessible? (Select TWO.)

Select 2 answers
A.Use an SCP to deny s3:PutBucketPolicy.
B.Enable default encryption on the bucket.
C.Enable S3 Block Public Access settings on the bucket.
D.Enable MFA Delete on the bucket.
E.Use CloudFront to serve the bucket content.
AnswersA, C

An SCP (Service Control Policy) is a preventive guardrail applied at the AWS Organizations level, and it can deny the s3:PutBucketPolicy action for all IAM principals within an account or OU. This ensures that even if a user has an IAM policy granting s3:PutBucketPolicy, they cannot attach a bucket policy that would grant public access, because the SCP takes precedence. It is an effective way to enforce a 'no public buckets' rule across the entire organization.

Why this answer

An SCP (Service Control Policy) can explicitly deny the s3:PutBucketPolicy action at the AWS Organizations level, which prevents any IAM principal in affected accounts from attaching a public bucket policy. This is a preventive guardrail that overrides any permissive IAM permissions, ensuring the bucket cannot be made publicly accessible via policy statements.

Exam trap

The trap here is that candidates often confuse security features like encryption or MFA Delete with access control mechanisms, failing to recognize that only explicit policy restrictions (SCP or Block Public Access) can prevent public accessibility.

6
MCQhard

Refer to the exhibit. The S3 bucket policy is applied to a bucket. An application attempts to upload an object to the bucket using HTTP (not HTTPS). What will happen?

A.The upload fails because the condition matches HTTP requests
B.The upload succeeds if the bucket also has an allow policy for the user
C.The upload succeeds because there is no explicit allow statement
D.The upload fails because the bucket policy does not allow any access
AnswerA

The upload fails because the S3 bucket policy contains an explicit Deny statement whose condition key `aws:SecureTransport` evaluates to `false` for any HTTP request. Since the request was made over HTTP rather than HTTPS, the condition is satisfied and S3 returns 403 Forbidden, regardless of any IAM permissions that would otherwise permit the PutObject action. An explicit deny always takes precedence over any allow.

Why this answer

The bucket policy includes an explicit deny for all S3 actions when aws:SecureTransport is false (i.e., HTTP). This deny overrides any allow policies, so the upload fails. Option A is correct because the condition matches HTTP requests.

Option B is incorrect because the explicit deny overrides any allow. Option C is incorrect because the deny is explicit, so the condition is evaluated. Option D is incorrect because the policy only denies HTTP, not HTTPS.

7
MCQmedium

A DevOps engineer manages a CI/CD pipeline that builds and deploys a containerized application to an Amazon ECS cluster. The pipeline runs on an EC2 instance and needs to retrieve a secret from AWS Secrets Manager to pass to the ECS task definition. The secret must not be stored on the instance or in the pipeline's code. The engineer wants to grant the pipeline the least privilege necessary to retrieve only that specific secret. Which approach should be taken?

A.Store the secret in an environment variable in the EC2 instance's user data and reference it in the pipeline.
B.Use AWS Systems Manager Parameter Store to store the secret as a SecureString parameter, and grant the instance's IAM role access to that parameter.
C.Create an IAM role for the EC2 instance with a policy that allows secretsmanager:GetSecretValue on the specific secret's ARN, and attach it to the instance profile.
D.Create an IAM user with programmatic access and a policy that allows secretsmanager:GetSecretValue on all secrets, then store the access keys in AWS CodePipeline as a secret parameter.
AnswerC

This approach uses an IAM role attached to the instance profile, providing temporary credentials to the pipeline. The policy scopes permissions to only the specific secret's ARN, adhering to least privilege. The secret is retrieved at runtime and never stored on the instance or in code.

Why this answer

The requirement is to retrieve a secret from AWS Secrets Manager without storing it on the instance or in code, and with least privilege. Attaching an IAM role to the EC2 instance with a policy scoped to the specific secret's ARN provides temporary credentials and restricts access. This is the most secure and operationally sound solution.

Exam trap

The trap here is assuming that storing secrets in user data or environment variables is acceptable for production pipelines, when it exposes credentials to anyone with instance access.

8
Matchingmedium

Match each AWS security and identity service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manages users, groups, roles, and permissions

Creates and manages encryption keys

Rotates and manages secrets like database credentials

DDoS protection service

Web application firewall

Why these pairings

IAM handles access control, AWS Organizations manages multi-account structure, and AWS Shield protects against DDoS attacks. The distractors incorrectly swap these definitions.

9
MCQmedium

A DevOps engineer needs to securely store and automatically rotate database credentials for a web application running on Amazon ECS. Which solution should be used?

A.Use AWS KMS to generate and rotate a data key for encrypting the credentials in a file on ECS.
B.Store the credentials in AWS Systems Manager Parameter Store as a SecureString. Use a Lambda function to rotate them.
C.Store the credentials in AWS Secrets Manager and configure rotation. Grant the ECS task IAM role permission to retrieve the secret.
D.Use AWS Certificate Manager to store the credentials as a certificate.
AnswerC

AWS Secrets Manager natively supports automatic rotation of secrets with a configurable rotation schedule, using a Lambda function that updates the secret in both Secrets Manager and the target database. The ECS task assumes an IAM role whose permissions include secretsmanager:GetSecretValue, allowing the container to fetch the current password at runtime without embedding it in the task definition. This approach centralizes secret storage, enables rotation without redeploying the ECS service, and follows AWS best practices for managing database credentials.

Why this answer

AWS Secrets Manager can store database credentials and automatically rotate them on a schedule. The ECS task can retrieve the credentials using the Secrets Manager secret. Option C is correct.

Option A (AWS KMS) is for encryption keys, not credential rotation. Option B (SSM Parameter Store) can store secrets but does not support automatic rotation. Option D (AWS Certificate Manager) is for SSL/TLS certificates.

10
Multi-Selecthard

Which THREE are features of AWS Key Management Service (KMS) that help with compliance requirements? (Choose 3)

Select 3 answers
A.Automatic password generation for databases.
B.Automatic key rotation every year (optional).
C.Key policies to control access to keys.
D.Integration with AWS CloudTrail for auditing key usage.
E.Automatic deletion of keys after a specified period.
AnswersB, C, D

KMS offers optional automatic rotation of customer-managed keys on an annual basis. When enabled, KMS generates new backing key material each year while preserving the old material so that previously encrypted data can still be decrypted. This feature helps meet compliance requirements for cryptographic key lifecycle management.

Why this answer

AWS KMS supports optional automatic annual key rotation for customer managed keys. This helps meet compliance frameworks (e.g., PCI DSS, SOC, HIPAA) that require periodic cryptographic key rotation to limit the amount of data encrypted under a single key. When enabled, KMS automatically rotates the key material once per year, creating a new backing key while retaining the old one for decryption of previously encrypted data.

Exam trap

The trap here is that candidates confuse KMS key rotation with the automatic deletion or expiry of keys, or they mistakenly associate KMS with password generation features that belong to other AWS services like Secrets Manager.

11
MCQmedium

A company wants to centralize IAM user management across multiple AWS accounts. The company currently uses individual IAM users in each account. What is the BEST practice for centralized access control?

A.Use AWS Organizations and AWS IAM Identity Center (AWS SSO) to manage users centrally.
B.Create the same IAM users in each account with identical permissions.
C.Create IAM roles in each account and allow cross-account access from a central account.
D.Use IAM federation with an external identity provider and assign permissions based on SAML attributes.
AnswerA

AWS IAM Identity Center (formerly AWS SSO) integrates natively with AWS Organizations, providing a single place to manage users and groups and then assign them access across multiple AWS accounts. It uses permission sets to define IAM policies that are applied consistently to accounts, and it issues short-term AWS credentials, eliminating the need to create and rotate IAM users. This is the only option that genuinely centralizes user management while preserving fine-grained, auditable access control.

Why this answer

AWS IAM Identity Center (successor to AWS SSO) combined with AWS Organizations is the AWS-recommended best practice for centralizing workforce identity and access across multiple accounts. It provides a single place to manage users and groups, assign permission sets to accounts/OUs, and federate to external IdPs if desired — eliminating per-account IAM user sprawl. This is the canonical 'centralized access management' answer for multi-account environments.

Exam trap

The trap is confusing 'centralized access' with 'cross-account roles' — candidates pick option C because cross-account roles sound centralized, but the exam expects IAM Identity Center as the AWS-recommended best practice for multi-account user management.

How to eliminate wrong answers

Option B is wrong because duplicating IAM users across accounts creates credential sprawl, inconsistent permissions, and no single source of truth — it is explicitly an anti-pattern AWS advises against. Option C is wrong because while cross-account IAM roles are a valid pattern, they still require managing identities and trust relationships per account and do not provide centralized user lifecycle management the way Identity Center does; it is a partial solution, not the best practice. Option D is wrong because IAM federation with an external IdP is a component of a solution but by itself does not centralize account assignments across an AWS Organization — Identity Center is the AWS-native service that wraps federation plus centralized permission assignment.

12
Multi-Selectmedium

A company is designing a secure CI/CD pipeline. Which TWO actions should be taken to protect secrets (e.g., API keys) used in the pipeline? (Choose TWO.)

Select 2 answers
A.Encrypt secrets with AWS KMS and store the encrypted value in the source code
B.Store secrets in AWS Secrets Manager
C.Use IAM roles to grant the CI/CD service access to secrets
D.Store secrets in plaintext in the buildspec file
E.Pass secrets as environment variables in the build
AnswersB, C

AWS Secrets Manager is the correct choice because it natively stores secrets as encrypted objects with fine-grained IAM policies, automatic rotation for both AWS and custom secrets, and direct integration with services like CodeBuild, RDS, and Lambda. The pipeline retrieves a reference to the secret at build time, so the material value never appears in source control, buildspec files, or logs. Secrets Manager also logs every retrieval via CloudTrail, enabling security auditing and immediate revocation if a secret is compromised.

Why this answer

Option B is correct because AWS Secrets Manager is purpose-built to store, encrypt (using KMS), and rotate sensitive values such as API keys, so the pipeline retrieves them at runtime rather than embedding them in code or config. Option C is correct because granting the CI/CD service an IAM role with least-privilege permissions to read specific secrets enables secure, credential-free access via temporary STS credentials instead of long-lived static keys. Option A is wrong because even KMS-encrypted secrets committed to source code expose the ciphertext to anyone with repo access and risk decryption-key misuse.

Option D is wrong because plaintext secrets in a buildspec file are directly readable in the repository and build logs. Option E is wrong because environment variables can leak through logs, process listings, and child processes, and are not a secure secret-management mechanism on their own.

Exam trap

DOP-C02 often tests the misconception that encrypting secrets and committing them to source control is acceptable, when the correct pattern is to keep secrets entirely out of code and retrieve them at runtime via IAM-authorized services.

13
Multi-Selecthard

A DevOps team is designing a CI/CD pipeline that deploys a web application on Amazon ECS. The application must be compliant with PCI DSS, which requires encryption of data at rest and in transit, and logging of all access. Which THREE actions should the team implement to meet these requirements? (Choose THREE.)

Select 3 answers
A.Enable AWS CloudTrail and Amazon ECS logs to capture all API calls and container logs.
B.Store database credentials in AWS Systems Manager Parameter Store.
C.Use VPC endpoints to access ECS and ECR APIs.
D.Enable ECS task definition encryption using AWS KMS for environment variables and sensitive data.
E.Configure an Application Load Balancer (ALB) with an HTTPS listener using an SSL/TLS certificate.
AnswersA, D, E

AWS CloudTrail records every API call made against the AWS account, including ECS, ECR, and other service actions, which is essential for auditing who did what and when. Amazon ECS logs, collected via the awslogs driver, capture container stdout/stderr for operational auditing and forensic analysis. Together they provide the necessary audit trail to verify compliance and detect unauthorized access or changes, directly addressing the requirement to capture all API calls and container logs.

Why this answer

AWS CloudTrail captures all API calls to the AWS environment, providing an audit trail of who accessed what and when, which is required for PCI DSS logging. Amazon ECS logs (via CloudWatch Logs or FireLens) capture container-level access and application logs, ensuring comprehensive logging of all access to the application and underlying infrastructure.

Exam trap

The trap here is that candidates often confuse security best practices (like storing secrets in Parameter Store or using VPC endpoints) with mandatory compliance actions for encryption and logging, leading them to select options that are helpful but not directly required by PCI DSS for the specific three actions.

14
MCQhard

A company's security team notices that an IAM user has permissions to terminate EC2 instances but should only be allowed to stop them. The current policy allows ec2:TerminateInstances. What is the most secure way to prevent termination while allowing stop?

A.Use an SCP to deny ec2:TerminateInstances for the entire account.
B.Modify the existing policy to include ec2:StopInstances and remove ec2:TerminateInstances.
C.Add a Deny statement for ec2:TerminateInstances with a condition for the user's ARN.
D.Attach a separate managed policy that denies ec2:TerminateInstances to the user.
AnswerC

Placing an explicit Deny on ec2:TerminateInstances with a condition key like aws:PrincipalArn set to the user's ARN directly and narrowly blocks only that principal from terminating instances. This Deny overrides any Allow for the action, regardless of other policies, while leaving the user's ability to stop instances intact and preserving permissions for all other IAM principals.

Why this answer

The most secure because adding a Deny statement for ec2:TerminateInstances with a condition for the user's ARN explicitly blocks the termination action, regardless of any other policies that might allow it. Option A is wrong because an SCP affects the entire account, not just the user, and may be too broad. Option B is wrong because simply modifying the policy to include ec2:StopInstances and remove ec2:TerminateInstances does not prevent termination if the user has other policies that grant ec2:TerminateInstances.

Option D is wrong because attaching a separate Deny policy is effective but less direct and more complex than adding a Deny in the same policy.

15
MCQmedium

A DevOps engineer is designing a CI/CD pipeline that deploys to production. The security team mandates that all code changes must be reviewed and signed off by two senior developers before deployment. How can this be enforced?

A.Use CloudWatch Events to trigger a manual approval step in CodePipeline.
B.Restrict push access to the production branch to only the two senior developers.
C.Use AWS Lambda to send a notification when a change is pushed.
D.Set up a pull request approval rule in CodeCommit requiring two approvals.
AnswerD

Setting up a pull request approval rule in CodeCommit requires at least two approvals from IAM principals (other than the commit author) before the pull request can be merged. This is a native CodeCommit feature that enforces the two-person review rule at the source, allowing the pipeline to deploy only code that has passed the mandated review process. The approval rule can also be associated with the repository's target branch (e.g., production) and automatically applies to all PRs targeting that branch, making it the correct control to meet the requirement.

Why this answer

CodeCommit's pull request approval rules allow you to require a specific number of approvals before a pull request can be merged. By configuring an approval rule template that requires two approvals from senior developers, you enforce the mandatory code review and sign-off before any change is merged into the production branch, which then triggers the CI/CD pipeline.

Exam trap

The trap here is that candidates often confuse deployment-stage approvals (like CodePipeline manual approval) with pre-merge code review approvals, failing to recognize that the security requirement must be enforced at the source code repository level before the pipeline even starts.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events can trigger a manual approval step in CodePipeline, but this only enforces approval at the deployment stage, not the code review and sign-off requirement before the change is even merged into the production branch. Option B is wrong because restricting push access to only two senior developers does not enforce a mandatory two-person review process; a single developer could still push directly without any review. Option C is wrong because using Lambda to send a notification when a change is pushed does not enforce any approval or review requirement; it merely informs stakeholders without blocking the change.

16
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to secure an AWS account root user? (Choose 2.)

Select 2 answers
A.Share the root user password with the team.
B.Create an IAM role for the root user.
C.Delete or disable the root user access keys.
D.Use the root user for daily administrative tasks.
E.Enable multi-factor authentication (MFA) for the root user.
AnswersC, E

Deleting or disabling root user access keys removes long-lived credentials that cannot be scoped by IAM policies and are frequently exposed through code commits or misconfigured tooling. Since the root user bypasses permission boundaries entirely, eliminating its programmatic keys satisfies the stem's requirement to secure the account's most privileged identity.

Why this answer

Option C is correct because deleting or disabling the root user's access keys eliminates a long-lived, highly privileged credential that could be used for programmatic access; AWS best practice is to have no access keys on the root user at all. Option E is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the account's most powerful identity. Options A, B, and D are not appropriate: sharing the root password violates least privilege and accountability, IAM roles cannot be created for or assumed by the root user (roles are for IAM principals), and using root for daily administrative tasks contradicts the practice of using scoped IAM users or roles for routine work.

Exam trap

DOP-C02 often tests the misconception that the root user can be secured by creating an IAM role or that it should be used for administrative tasks, when in fact the root user cannot assume roles and should be used only for a limited set of account-level operations.

17
MCQeasy

A company wants to centrally manage and audit access to AWS KMS keys across multiple accounts. Which AWS feature should be used?

A.AWS Config aggregated rules
B.Cross-account IAM roles
C.AWS CloudTrail with organization trail
D.AWS Organizations tag policies
AnswerC

An organization trail in AWS CloudTrail is created once in the management account of AWS Organizations and automatically delivers management events from every member account to a single central S3 bucket, with optional CloudWatch Logs delivery for real-time monitoring. This gives a centralized, near-complete audit record of who made API calls, the service called, source IP, and timestamp across all accounts, which directly satisfies both central management and audit requirements. Because the trail is organization-scoped, it captures activity for existing and future accounts, making it the native AWS solution for cross-account audit logging.

Why this answer

AWS CloudTrail with an organization trail can log all API calls, including KMS key usage, across multiple accounts in an AWS Organization. This provides centralized audit logging for KMS key access. Option A (AWS Config aggregated rules) can evaluate resource compliance but does not audit key usage.

Option B (Cross-account IAM roles) allows access but not centralized auditing. Option D (AWS Organizations tag policies) manage tags, not auditing. Therefore, option C is correct.

18
MCQhard

A DevOps engineer needs to ensure that an S3 bucket policy enforces encryption in transit for all access. Which policy statement should be added?

A.{"Effect":"Deny","Condition":{"StringEquals":{"aws:SecureTransport":"true"}}}
B.{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
C.{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"true"}}}
D.{"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
AnswerD

This is the correct pattern: it explicitly denies any request where aws:SecureTransport equals false, meaning only HTTPS connections are permitted. An explicit deny overrides all other allow outcomes, so this robustly enforces TLS regardless of any other policies. The condition uses Bool, which is proper for boolean keys like aws:SecureTransport.

Why this answer

To enforce encryption in transit, the S3 bucket policy must deny requests that are not using SSL/TLS. The condition key aws:SecureTransport is a boolean that is true when the request uses HTTPS and false when it uses HTTP. Therefore, a Deny statement with a condition that aws:SecureTransport is false blocks all unencrypted (HTTP) access, effectively enforcing encryption in transit.

Exam trap

DOP-C02 often tests whether candidates confuse the boolean logic of aws:SecureTransport, leading them to select an Allow statement or a Deny with the wrong boolean value, instead of the correct Deny with false.

How to eliminate wrong answers

Option A is wrong because it uses StringEquals with 'true' and a Deny effect, which would deny all HTTPS requests, the opposite of the intended enforcement. Option B is wrong because it uses Allow with a condition that aws:SecureTransport is false, which would explicitly allow unencrypted requests, violating the requirement. Option C is wrong because it uses Allow with a condition that aws:SecureTransport is true, which allows HTTPS but does not deny HTTP; an explicit deny is needed to block unencrypted access.

19
MCQmedium

A company is using AWS Secrets Manager to store database credentials for a multi-tier application. The application runs on EC2 instances in an Auto Scaling group. The DevOps engineer has configured the instances to retrieve the secret at boot time using a script that calls the AWS CLI. Recently, the security team discovered that the secret was exposed in the instance's user data logs. The engineer needs to implement a more secure method to access the secret without storing it in user data. The application code can be modified. The environment uses IAM roles for EC2. Which solution best meets the security requirements?

A.Store the secret in a configuration file on the EC2 instance and encrypt the file system.
B.Store the secret in AWS Systems Manager Parameter Store and retrieve it via the AWS CLI at boot time.
C.Modify the application code to use the AWS SDK to retrieve the secret from Secrets Manager using the instance's IAM role.
D.Use a KMS key to encrypt the secret and store the encrypted value in user data.
AnswerC

Using the AWS SDK inside the application to retrieve the secret from Secrets Manager is the correct pattern because the secret is fetched at runtime, encrypted in transit, and never written to user data, environment variables, or disk. The EC2 instance profile's IAM role gives the SDK temporary, automatically rotated credentials, so no hard-coded access keys or CLI scripts are required. This approach leverages Secrets Manager's built-in rotation, CloudTrail auditing, and fine-grained IAM policies that can limit which secrets a given instance role can read, and it lets the SDK cache the secret to minimize latency while still respecting rotation.

Why this answer

The most secure and operationally sound approach is to have the application retrieve the secret at runtime using the AWS SDK, authenticating via the EC2 instance profile (IAM role). This eliminates any need to embed the secret in user data, config files, or environment variables, and it leverages Secrets Manager's native rotation, versioning, and audit trail. Because the environment already uses IAM roles for EC2, no additional credential management is required.

Exam trap

DOP-C02 often tests the misconception that 'encrypting' a secret in user data makes it safe — candidates forget that user data is readable via the EC2 API and IMDS, so ciphertext plus accessible decryption is still a leak.

How to eliminate wrong answers

Option A is wrong because storing the secret in a config file — even on an encrypted filesystem — still leaves the plaintext secret on disk and in any backups or snapshots, and it does not address rotation or access auditing. Option B is wrong because retrieving from Parameter Store via the AWS CLI at boot time still requires the secret value to be handled by a script, and if that script or its output is logged (as in the original incident), the secret can leak again; Parameter Store also lacks Secrets Manager's native rotation for RDS credentials. Option D is wrong because encrypting the secret with KMS and storing the ciphertext in user data still exposes the ciphertext to anyone who can read user data, and the instance must decrypt it — the decryption key or role permissions become the weak link, and user data is visible in the console and API.

20
MCQeasy

A DevOps engineer is configuring AWS Config rules to detect non-compliant security groups. The rule should trigger if any security group allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS managed Config rule should be used?

A.vpc-sg-open-only-to-authorized-ports
B.ec2-security-group-attached-to-eni
C.restricted-ssh
D.incoming-ssh-disabled
AnswerC

The managed rule restricted-ssh directly evaluates security group rules for inbound TCP port 22 and determines if any rule allows access from 0.0.0.0/0 or ::/0. When the rule finds an IPv4 or IPv6 inbound rule that permits SSH from all IP addresses, it marks the security group as noncompliant; this is exactly the condition a DevOps engineer would target to detect publicly exposed SSH.

Why this answer

'restricted-ssh' is the managed rule that checks for SSH access from 0.0.0.0/0. Option A is wrong because 'vpc-sg-open-only-to-authorized-ports' is not specific to SSH. Option B is wrong because 'ec2-security-group-attached-to-eni' checks attachment, not rules.

Option D is wrong because 'incoming-ssh-disabled' is not a managed rule.

21
Multi-Selecteasy

A DevOps engineer needs to restrict access to an S3 bucket so that only users from a specific AWS account can read objects. Which TWO methods can achieve this?

Select 2 answers
A.Create an IAM role in the source account with read access to the bucket, and allow users in that account to assume the role.
B.Enable S3 Block Public Access on the bucket.
C.Generate pre-signed URLs for each object and distribute them only to users in the target account.
D.Write a bucket policy that uses the aws:SourceAccount condition to allow access only from the specific account.
E.Set a bucket ACL that grants read access to the target account's canonical ID.
AnswersA, D

Creating an IAM role in the source account with read access to the bucket, and allowing users in that account to assume the role, grants cross-account access by using the role as the principal identity. This approach leverages AWS STS trusts so the bucket policy can restrict the principal to the role's ARN, ensuring only users who assume that role can list and read objects. It avoids permanent cross-account credentials and gives you central control over who may assume the role.

Why this answer

An IAM role in the source account can be granted read access to the S3 bucket via a bucket policy that allows the role's ARN. Users in the source account assume this role, which temporarily provides them with the necessary permissions to read objects. This cross-account access pattern is secure and follows AWS best practices for delegating access across accounts.

Exam trap

The trap here is that candidates often confuse bucket ACLs (Option E) with bucket policies, thinking ACLs can restrict access to a specific account, but ACLs only grant access to the entire account (not individual users) and lack the condition keys needed for fine-grained control.

22
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team needs to automatically rotate the secrets every 30 days. Which action should be taken?

A.Enable automatic rotation on the secret and configure the rotation interval to 30 days
B.Manually rotate the secret every 30 days using the AWS Management Console
C.Store the secret in AWS Systems Manager Parameter Store and use a scheduled Lambda to update it
D.Use AWS KMS to rotate the secret by re-encrypting with a new key
AnswerA

Secrets Manager natively supports automatic rotation by invoking a configurable Lambda function that updates both the database credential and the secret value. Setting the rotation interval to 30 days on the secret ensures the database password is rotated without any manual intervention or custom infrastructure. The rotation Lambda must have permission to modify the database and call the UpdateSecret API, and the interval can be adjusted to meet compliance requirements.

Why this answer

AWS Secrets Manager supports automatic rotation of secrets using a Lambda rotation function. By enabling automatic rotation and setting the rotation interval to 30 days, the secret is rotated automatically without manual intervention. This meets the security team's requirement for automatic rotation every 30 days.

Exam trap

DOP-C02 often tests the confusion between secret rotation and KMS key rotation, tricking candidates into selecting KMS when the requirement is to rotate the secret value itself.

How to eliminate wrong answers

Option B is wrong because manual rotation does not meet the requirement for automatic rotation and is error-prone. Option C is wrong because Systems Manager Parameter Store does not natively support automatic rotation of secrets; it would require custom scripting and is not the recommended approach for database credentials. Option D is wrong because AWS KMS key rotation is for rotating the encryption key, not the secret value itself; it does not rotate the database credentials.

23
MCQhard

A company uses AWS Organizations with multiple accounts. The security team requires that all newly created S3 buckets in any account automatically have default encryption enabled and block public access. Which solution is MOST operationally efficient?

A.Use AWS CloudTrail to monitor bucket creation and trigger a Lambda function to apply settings
B.Apply a service control policy (SCP) that denies creation of buckets without encryption and public access block
C.Create a bucket policy on each existing bucket and rely on developers to apply it to new buckets
D.Use AWS Config rules to detect non-compliant buckets and send notifications
AnswerB

An SCP is a preventive, organization-wide control enforced by AWS Organizations before the action is authorized; it cannot be overridden by any IAM policy within the account. To deny non-compliant creation, you attach to the root/OU a policy that denies s3:CreateBucket with a StringNotEquals condition on s3:x-amz-server-side-encryption and a StringNotEquals condition on s3:x-amz-public-access-block, so only requests meeting both criteria succeed. This approach automatically covers every existing and future account and bucket without custom code or manual catch-up.

Why this answer

The most operationally efficient solution is to use an SCP in AWS Organizations that denies creation of S3 buckets without default encryption and public access block. This enforces the security requirements at the organization level, preventing non-compliant bucket creation across all accounts without additional automation. Option A relies on CloudTrail and Lambda, which is reactive and adds complexity.

Option C is manual and not scalable. Option D uses AWS Config to detect non-compliant buckets but requires additional remediation steps, making it less efficient than a preventive SCP.

24
MCQhard

A company is using AWS CloudFormation to deploy infrastructure. The security team wants to ensure that any changes to IAM roles must be reviewed and approved by a security engineer before deployment. The DevOps engineer needs to implement a gating mechanism. Which approach should the engineer use?

A.Use AWS Config to detect changes to IAM roles and trigger a Lambda function that reverts the change.
B.Apply a service control policy that denies iam:CreateRole and iam:UpdateAssumeRolePolicy across the organization.
C.Add a condition to the IAM policy that requires MFA for any CloudFormation action.
D.Create a CodePipeline that deploys CloudFormation stacks and include a manual approval step for changes that modify IAM resources.
AnswerD

A CodePipeline that deploys CloudFormation stacks can include a manual approval stage, which acts as a preventive control that pauses the pipeline before the stack update executes. The pipeline can detect when a change set modifies IAM resources—for example, by comparing the template or reviewing the change set—and conditionally require an approval step. This ensures a second person reviews the IAM changes before they are applied, satisfying the separation-of-duties requirement. Manual approval is a standard AWS pattern for production governance and is far more effective than post-hoc detection or MFA alone.

Why this answer

AWS CodePipeline can include a manual approval step before deploying CloudFormation stacks, allowing the security engineer to review and approve any changes to IAM roles. Option A is incorrect because AWS Config only detects changes after they occur; it cannot prevent deployment. Option B is incorrect because a service control policy would deny all IAM role creation across the organization, which is too restrictive and not a gating mechanism.

Option C is incorrect because requiring MFA for CloudFormation actions does not specifically gate changes to IAM resources.

25
Multi-Selectmedium

Which THREE are components of the AWS Shared Responsibility Model? (Choose THREE.)

Select 3 answers
A.AWS is responsible for patching customer applications on EC2
B.Customers are responsible for managing IAM users and permissions
C.AWS is responsible for managing customer IAM roles
D.Customers are responsible for securing their data in the cloud
E.AWS is responsible for the security of the cloud infrastructure
AnswersB, D, E

IAM is a customer-controlled service: customers define users, groups, roles, policies, and permission boundaries, and they are accountable for the identity and access management decisions they implement. AWS provides the IAM service itself and keeps its control plane available, but it does not create, modify, or assume customer identities or make authorization decisions on the customer's behalf. Correctly scoping least-privilege IAM policies, enabling multi-factor authentication, and rotating credentials are customer responsibilities that directly impact the security of everything deployed in the account.

Why this answer

Option B is correct because under the AWS Shared Responsibility Model, identity and access management — including creating, managing, and rotating IAM users, groups, roles, and policies — is a customer responsibility in the cloud. Option D is correct because customers are always responsible for the security and classification of their own data, including encryption choices and access controls, regardless of which AWS service is used. Option E is correct because AWS is responsible for security OF the cloud, meaning the physical facilities, hardware, networking, and foundational services that underpin the AWS global infrastructure.

Option A is incorrect because patching guest operating systems and customer applications on EC2 is the customer's responsibility, not AWS's. Option C is incorrect because managing customer IAM roles is a customer task; AWS only provides and secures the IAM service itself.

Exam trap

DOP-C02 often tests the Shared Responsibility Model; candidates may incorrectly assume AWS manages IAM roles or patches customer applications, but those are customer responsibilities.

26
MCQmedium

An S3 bucket has the above bucket policy. What is the net effect on GetObject requests?

A.All anonymous users can read objects
B.All requests are denied
C.Only requests from IP range 192.0.2.0/24 are allowed
D.Only authenticated users can read objects
AnswerC

The net effective policy is that only clients with source IP addresses in 192.0.2.0/24 are permitted to read objects. The Allow statement grants s3:GetObject to Principal "*", but the Deny statement with NotIpAddress of that range blocks all other source IPs; because explicit deny overrides allow, the condition on the deny becomes the controlling factor. This creates a whitelist: any request not coming from 192.0.2.0/24, even an authenticated AWS identity, is denied, while any request from that range, including anonymous users, is allowed.

Why this answer

The bucket policy grants s3:GetObject to everyone (Principal "*") but wraps it in a Condition restricting the source to the 192.0.2.0/24 CIDR via aws:SourceIp. Because the Allow statement is conditional, only requests originating from that IP range satisfy the policy and are permitted; all other requests are implicitly denied since S3 is deny-by-default. The net effect is that GetObject succeeds only for callers inside 192.0.2.0/24.

Exam trap

The trap is reading Principal "*" and jumping to 'public access' or 'all denied' without noticing the Condition block — DOP-C02 frequently tests whether you evaluate the entire policy statement, including conditions, before deciding the net effect.

How to eliminate wrong answers

Option A is wrong because the Principal "*" is not unconditional — the aws:SourceIp condition narrows the grant, so anonymous users outside the CIDR are denied. Option B is wrong because the policy contains an explicit Allow that is satisfied for in-range requests, so not all requests are denied. Option D is wrong because the policy does not reference authentication or IAM principals at all; it is an IP-based condition, and an anonymous caller from inside 192.0.2.0/24 would actually be allowed.

27
MCQmedium

A DevOps engineer created the IAM policy shown in the exhibit and attached it to a user. The user tries to upload an object to my-bucket without specifying the ACL. Why does the upload fail?

A.The Effect should be Deny for this policy to work
B.The resource ARN is incorrect; it should be arn:aws:s3:::my-bucket
C.The user does not have permission to list the bucket
D.The policy condition requires the ACL to be bucket-owner-full-control, but the user did not specify it
AnswerD

Correct — the policy's Condition uses StringEquals to require the s3:x-amz-acl value of bucket-owner-full-control on every PutObject request. When the user's PutObject request does not specify that exact ACL (either omits the x-amz-acl header or sets it to another value), the condition evaluates false. IAM authorization is deny-by-default: without an explicitly matching allow statement, the request is implicitly denied, producing the denied message. The user must include x-amz-acl: bucket-owner-full-control, or the policy must be adjusted if that enforcement is not desired.

Why this answer

The policy condition requires the ACL to be 'bucket-owner-full-control'. If the user does not specify an ACL, the default is usually 'private', which does not satisfy the condition. Therefore the action is denied.

The resource ARN is correct. The action is allowed. The condition specifies StringEquals, which is correct for comparison.

28
MCQeasy

A company uses AWS CodeBuild for CI/CD. The build project needs to access a private S3 bucket to download artifacts. What is the MOST secure way to grant access?

A.Embed the access keys in the buildspec.yml file.
B.Create an IAM role with read access to the bucket and attach it to the CodeBuild project.
C.Use an S3 bucket policy that grants public read access.
D.Store AWS access keys in CodeBuild environment variables.
AnswerB

An IAM role attached to the CodeBuild project supplies temporary credentials scoped to the required S3 read permissions, avoiding long-lived access keys stored in buildspec or environment variables. This satisfies least-privilege access to the private bucket.

Why this answer

Attaching an IAM role to the CodeBuild project allows CodeBuild to assume temporary credentials via the AWS STS service, eliminating the need to store any long-lived secrets. The role's policy can be scoped to only the specific S3 bucket and actions required, following least privilege. This is the AWS-recommended pattern for service-to-service authentication.

Exam trap

DOP-C02 often tests whether candidates confuse 'convenient' credential storage (env vars, buildspec) with 'secure' credential storage (IAM roles), so any answer that hardcodes or stores static keys is a distractor.

How to eliminate wrong answers

Option A is wrong because embedding access keys in buildspec.yml stores long-lived credentials in source control, where they can be leaked, committed to Git history, or exposed in build logs. Option C is wrong because granting public read access to a private bucket exposes the artifacts to anyone on the internet and violates least privilege. Option D is wrong because environment variables in CodeBuild are visible in the console and build logs, and static IAM user keys are long-lived and must be rotated manually.

29
Multi-Selecteasy

Which TWO are best practices for securing an Amazon RDS database? (Choose 2)

Select 2 answers
A.Enable public accessibility for easy management.
B.Use a single Availability Zone to reduce complexity.
C.Launch the RDS instance in a private subnet.
D.Enable encryption at rest using AWS KMS.
E.Grant direct IAM user access to the database.
AnswersC, D

Launching the RDS instance in a private subnet that has no route to an internet gateway prevents any direct inbound connection from the public internet, including attempts to exploit database vulnerabilities. Only resources inside the VPC, such as application servers in private subnets or a bastion host, can reach the database, and those connections can be further restricted by security groups and NACLs. This is a core network security control that reduces the attack surface and is a mandatory requirement for many compliance frameworks.

Why this answer

Option C is correct because launching the RDS instance in a private subnet removes it from the public internet, so only resources inside the VPC (or connected via VPN/Direct Connect or a bastion) can reach the database endpoint, which is a core network-isolation best practice. Option D is correct because enabling encryption at rest with AWS KMS protects stored data, automated backups, read replicas, and snapshots, satisfying compliance and data-protection requirements. Option A is wrong because public accessibility exposes the database to internet-based attacks and is not recommended; management should be done via private networking or a bastion.

Option B is wrong because a Single-AZ deployment creates a single point of failure and does not improve security; Multi-AZ is preferred for availability. Option E is wrong because granting direct IAM user access to the database bypasses proper database authentication and least-privilege controls; IAM should be used for AWS API access, not direct DB logins.

Exam trap

DOP-C02 often tests the misconception that public accessibility or single-AZ simplifies management — candidates pick convenience options that violate the shared responsibility model's security and availability best practices.

30
MCQmedium

A DevOps engineer manages a CI/CD pipeline that builds Docker images and pushes them to Amazon ECR. The security team requires that every image be scanned for known vulnerabilities before deployment, and that the pipeline fail if any critical severity findings are detected. The engineer enables scan on push for the repository. Which additional step must be added to the pipeline to meet the requirement?

A.Use AWS Config to evaluate the ECR image scan results and trigger an AWS Lambda function that stops the pipeline.
B.Configure the ECR repository to block pushes of images that contain critical vulnerabilities.
C.Use the ECR DescribeImageScanFindings API to retrieve the scan results and fail the pipeline if any finding has a severity of CRITICAL.
D.Enable Amazon Inspector and configure it to fail the CodePipeline stage when critical findings are detected.
AnswerC

Enabling scan on push only initiates the scan; the pipeline must actively retrieve the results. Calling DescribeImageScanFindings returns the severity counts and individual findings, allowing the pipeline to evaluate them and fail when CRITICAL findings exist. This directly satisfies the requirement to block deployment based on critical vulnerabilities.

Why this answer

ECR scan on push generates vulnerability findings but does not enforce any action. To gate the pipeline, the engineer must call DescribeImageScanFindings after the push and evaluate the severity counts. If any CRITICAL finding exists, the pipeline should fail.

This is the standard pattern for integrating ECR image scanning into a CI/CD workflow and meets the security team's requirement.

Exam trap

The trap here is assuming that enabling scan on push automatically blocks vulnerable images from being pushed or deployed, when it only produces findings that must be evaluated separately.

31
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no member account can disable AWS CloudTrail or delete CloudTrail logs. What is the most effective way to enforce this control?

A.Require all accounts to use the same CloudTrail trail.
B.Apply a Service Control Policy that denies cloudtrail:DeleteTrail and cloudtrail:StopLogging.
C.Create an IAM policy in each account that denies cloudtrail:DeleteTrail.
D.Configure CloudTrail to log to an S3 bucket in a centralized logging account and deny access to the bucket from member accounts.
AnswerB

A Service Control Policy (SCP) applied at the organization root or an organizational unit is the correct mechanism because it acts as a permission boundary that all IAM principals—including the account root user—cannot override. By explicitly denying cloudtrail:DeleteTrail and cloudtrail:StopLogging, the SCP ensures that even a full account administrator cannot disable the trail or stop event delivery. Since member account admins lack permission to modify or detach SCPs, this provides an immutable, centralized control that persists regardless of individual account settings.

Why this answer

A Service Control Policy (SCP) applied at the organization or OU level is the most effective way to prevent member accounts from disabling CloudTrail or deleting logs because SCPs are enforced by AWS Organizations and cannot be overridden by account-level IAM policies, including root user actions. Denying cloudtrail:DeleteTrail and cloudtrail:StopLogging at the SCP level creates a hard guardrail across all accounts in scope. This is the canonical AWS Organizations security control pattern.

Exam trap

DOP-C02 often tests the difference between 'configuration' controls (same trail, central bucket) and 'enforcement' controls (SCP deny) — candidates pick the central S3 bucket because it sounds like a security best practice, missing that it does not block the StopLogging API call.

How to eliminate wrong answers

Option A is wrong because requiring all accounts to use the same trail does not prevent anyone from stopping or deleting it — it only standardizes configuration, not enforcement. Option C is wrong because an IAM policy in each account can be modified or deleted by account administrators (or root), so it is not a durable guardrail; it also requires per-account maintenance and can be bypassed. Option D is wrong because centralizing logs in an S3 bucket protects log retention but does not stop a member account from calling StopLogging or DeleteTrail on its own trail — the control must block the API call itself.

32
Multi-Selecthard

A company is using AWS Lambda to process sensitive data. The security team requires that the Lambda function only be invoked from within a specific VPC and that the function's environment variables be encrypted at rest. Which TWO actions should the DevOps engineer take to meet these requirements?

Select 2 answers
A.Enable AWS KMS encryption for the Lambda function's environment variables using a customer-managed key.
B.Enable encryption for CloudWatch Logs using a KMS key.
C.Configure the Lambda function to be VPC-enabled and set up a VPC endpoint for Lambda.
D.Assign an IAM execution role with permissions to access a KMS key.
E.Attach a resource-based policy to the Lambda function that denies invoke unless the request comes from the VPC.
AnswersA, C

Enabling AWS KMS encryption for the Lambda function's environment variables with a customer-managed key directly protects the sensitive values at rest. When you configure this, Lambda uses the selected customer master key to encrypt the environment-variable payload before storing it as part of the function configuration. This replaces the default aws/lambda managed key, giving you independent control, rotation, and audit trails through CloudTrail for encryption and decryption operations.

Why this answer

Using a customer-managed KMS key to encrypt the Lambda function's environment variables satisfies the encryption at rest requirement. Option C is correct because configuring the Lambda function to be VPC-enabled and setting up a VPC endpoint for Lambda restricts invocation to within the specific VPC. Option B is incorrect because encrypting CloudWatch Logs does not encrypt the Lambda environment variables.

Option D is incorrect because assigning an IAM execution role with KMS permissions is necessary but not sufficient; the encryption is enabled by configuring KMS on the function. Option E is incorrect because resource-based policies cannot restrict invocation to VPC origin alone; VPC configuration and endpoints are required.

33
Multi-Selecthard

A company wants to monitor and detect anomalous API calls in their AWS account. Which THREE AWS services should they use together to achieve this?

Select 3 answers
A.AWS CloudTrail
B.Amazon Inspector
C.Amazon CloudWatch Logs
D.AWS Config
E.Amazon GuardDuty
AnswersA, C, E

AWS CloudTrail is the primary service that records all API activity in an AWS account, capturing the identity, time, source IP, and request parameters for every call. Enabling CloudTrail across all regions and using events to build a baseline of expected behavior lets security teams flag anomalies such as unusual IAM roles, foreign IP addresses, or credential changes. It is the foundational data source for API-level anomaly detection, and its Insights feature can automatically identify unusual API patterns like mass resource deletion or unusual access timing.

Why this answer

AWS CloudTrail is correct because it records all API calls made in the AWS account, providing the raw data needed to detect anomalous activity. By enabling CloudTrail on all regions and logging to a centralized S3 bucket, you capture the identity, source IP, and request parameters for every API call, which is essential for anomaly detection.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), or they think Amazon Inspector (a vulnerability scanner) can detect anomalous API behavior when it is designed for a completely different purpose.

34
MCQeasy

A DevOps engineer is designing an AWS Lambda function that needs to read secrets from AWS Secrets Manager. What is the most secure way to provide the Lambda function access to the secret?

A.Assign an IAM execution role to the Lambda function with a policy that allows secretsmanager:GetSecretValue on the specific secret.
B.Store the secret in AWS Systems Manager Parameter Store and grant the Lambda function access to the parameter.
C.Encrypt the secret using AWS KMS and pass the encrypted value as an environment variable.
D.Store the secret in an environment variable in the Lambda function.
AnswerA

Attaching an IAM execution role with a least-privilege policy that allows secretsmanager:GetSecretValue on the specific secret ARN is the recommended pattern because it keeps the secret out of the function configuration and gives you native rotation, versioning, and CloudTrail audit events. If the secret is encrypted with a customer-managed KMS key, you must also grant kms:Decrypt on that key, but the default AWS-managed key used by Secrets Manager requires no additional KMS action. This lets the function call GetSecretValue at runtime and parse the returned JSON string without exposing the raw secret in environment variables or source code.

Why this answer

The most secure approach is to give the Lambda function an IAM execution role whose policy grants secretsmanager:GetSecretValue scoped to the specific secret's ARN. Lambda assumes this role at runtime, so no credentials are stored in code or configuration, and the secret value is retrieved dynamically, allowing rotation without redeployment. This follows least privilege and avoids hardcoding secrets.

Exam trap

DOP-C02 often tests the misconception that encrypting a secret and storing it in an environment variable is secure, when the correct pattern is runtime retrieval via an IAM execution role scoped to the specific secret.

How to eliminate wrong answers

Option B is wrong because Parameter Store (especially the standard tier) is not designed for secret rotation and lacks native rotation integration; while SecureString exists, Secrets Manager is the purpose-built service and the question specifies Secrets Manager. Option C is wrong because passing an encrypted value as an environment variable still exposes ciphertext in the function configuration and requires the function to hold KMS decrypt permissions and manage decryption logic — it also doesn't benefit from rotation. Option D is wrong because storing the secret in a plaintext environment variable exposes it in the Lambda console, CloudFormation templates, and logs, and requires redeployment to rotate — a clear security anti-pattern.

35
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team has implemented a service control policy (SCP) that denies the creation of IAM users and roles with full admin access. The SCP is attached to all accounts. However, a DevOps engineer in a member account reports that they are able to create an IAM role with an administrator access policy attached. The engineer uses the AWS Management Console to create the role. The SCP is confirmed to be in place. What is the most likely reason the SCP is not preventing the role creation?

A.SCPs are not inherited by member accounts from the root.
B.The SCP is not attached to the member account's root organizational unit.
C.The engineer's IAM policy allows iam:CreateRole and overrides the SCP.
D.The SCP only denies iam:CreateUser, but the engineer is creating a role (iam:CreateRole).
AnswerD

The SCP only denies the iam:CreateUser action, which means it does not restrict the engineer's ability to create IAM roles. IAM role creation is governed by the iam:CreateRole permission, which is not covered by the SCP's deny statement. As a result, the engineer can create a new administrative role, attach a permissive policy to it, and assume that role to bypass the intended restrictions and achieve privilege escalation.

Why this answer

The SCP in question denies only the iam:CreateUser action, but the engineer is creating an IAM role, which requires the iam:CreateRole action. SCPs provide an explicit deny for actions they list; they do not block actions they do not list. Since the SCP does not deny iam:CreateRole, the engineer's IAM policy (which allows iam:CreateRole) is effective.

SCPs are inherited by member accounts and, when correctly attached, cannot be overridden by IAM policies; however, they only apply to the actions they explicitly specify.

Exam trap

Candidates often assume that an SCP denying creation of IAM users automatically covers roles, or that SCPs block all administrative actions. In this case, the SCP only prevents user creation, not role creation.

36
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores sensitive user data in an S3 bucket. A Security Engineer needs to ensure that the EC2 instances can only access the specific S3 bucket and no other AWS services. Which solution meets these requirements?

A.Attach a bucket policy to the S3 bucket that allows access only from the ALB's security group.
B.Create an IAM role with a policy that grants s3:PutObject and s3:GetObject access to the specific bucket, and attach the role to the EC2 instances as an instance profile.
C.Configure a VPC endpoint for S3 and modify the route table to route S3 traffic through the endpoint.
D.Create a security group that allows outbound HTTPS traffic only to the S3 bucket's IP address range.
AnswerB

An instance profile supplies temporary AWS credentials to the EC2 instance via the instance metadata service, and the attached IAM role's policy can be scoped to the exact bucket and the required actions. This provides least-privilege access, ensuring the instances can read and write only that bucket without long-lived keys or additional service permissions. Because IAM policies explicitly identify the resource (the bucket ARN) and the actions, no other AWS service or bucket is accessible unless separately allowed.

Why this answer

Creating an IAM role with a policy that grants s3:PutObject and s3:GetObject access only to the specific S3 bucket, and attaching that role to the EC2 instances as an instance profile, ensures that the instances can only access that bucket. This method uses AWS Identity and Access Management (IAM) to restrict permissions per resource. Option A is incorrect because an S3 bucket policy restricting access to the ALB's security group cannot control what the instances themselves do; the instances can still access S3 directly if they have credentials.

Option C is incorrect because a VPC endpoint for S3 provides private connectivity but does not restrict which resources the instances can access; it only ensures traffic stays within the AWS network. Option D is incorrect because security groups cannot filter traffic based on S3 bucket names or policies; they only filter IP addresses and ports, and S3 uses HTTPS which is not restrictable by security group to a specific bucket.

37
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets have encryption enabled. They need a preventive control that applies to all current and future accounts. Which approach should they use?

A.Use a service control policy (SCP) in the Organizations root to deny PutBucketEncryption actions when encryption settings do not include AES256 or aws:kms.
B.Use AWS Config rules to detect unencrypted buckets and automatically apply encryption using a remediation action.
C.Enable AWS CloudTrail to log all S3 API calls and send alerts when non-compliant buckets are created.
D.Create an IAM policy in each account that denies PutBucketEncryption unless encryption is enabled.
AnswerA

A service control policy (SCP) attached at the Organizations root is a preventive guardrail that applies to every account in the organization, including accounts created later. By using the s3:x-amz-server-side-encryption condition key with values AES256 or aws:kms, you can deny any PutBucketEncryption call that attempts to use a different encryption type, such as SSE-C or no encryption. This works because SCPs filter permitted API actions before they reach IAM, and they cannot be overridden by account administrators, making them the correct way to enforce encryption settings organization-wide.

Why this answer

A service control policy (SCP) applied at the Organizations root can deny the creation or modification of S3 buckets that do not have encryption enabled, specifically requiring AES256 or aws:kms. This is a preventive control that applies to all current and future accounts in the organization, as SCPs are inherited by all accounts and cannot be overridden by IAM policies within those accounts.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), or assume that IAM policies applied per account are sufficient for organization-wide enforcement, failing to recognize that SCPs are the only mechanism that applies uniformly to all accounts, including future ones.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are detective, not preventive; they can detect non-compliant buckets and trigger remediation, but they do not prevent the non-compliant action from occurring in the first place. Option C is wrong because CloudTrail is a logging service that records API calls after they happen; it cannot prevent the creation of unencrypted buckets, only alert on them. Option D is wrong because IAM policies are account-specific and must be manually applied to each account; they do not scale to future accounts automatically and can be overridden by account administrators with sufficient permissions.

38
MCQeasy

A company uses AWS CloudTrail to log all API calls across multiple accounts. The logs are stored in an S3 bucket in the management account. The security team wants to ensure that the logs are not tampered with and that any unauthorized modification is detected. The DevOps engineer has enabled CloudTrail log file integrity validation. The engineer also sets up an S3 lifecycle policy to transition logs to Glacier after 90 days. Additionally, the engineer enables S3 server access logging and sends the logs to a different bucket. A few months later, the security team suspects that some logs have been deleted. The engineer checks the CloudTrail digest files and finds that the latest digest file is missing. What is the most likely cause?

A.The S3 lifecycle policy transitions objects to Glacier after 90 days, causing the digest file to appear missing when listing the bucket without filtering by storage class.
B.The S3 bucket has default encryption enabled, causing the digest files to be unreadable.
C.The server access logging is writing access logs to the same bucket, causing overwrites.
D.The S3 bucket has Object Lock enabled, which prevents deletion of any objects.
AnswerA

While the scenario describes a transition to Glacier (not expiration), the lifecycle policy is still the cause: the digest file is moved to Glacier and becomes inaccessible, appearing missing. This is the most likely cause among the options.

Why this answer

CloudTrail log file integrity validation stores digest files in the same S3 bucket as the logs. The lifecycle policy transitions all objects, including digest files, to Glacier after 90 days. When objects are transitioned to Glacier, they remain in the bucket but are not readily accessible via standard S3 list operations unless you specifically request the Glacier storage class.

As a result, the latest digest file may appear missing, leading to the assumption that logs were deleted.

39
MCQeasy

A company wants to encrypt data at rest in Amazon S3 using server-side encryption. Which AWS service can automatically manage the encryption keys with minimal configuration?

A.SSE-C
B.SSE-KMS
C.SSE-S3
D.Client-side encryption
AnswerC

SSE-S3 is correct because it is Amazon S3's built-in server-side encryption that requires no additional configuration that the customer must perform. With SSE-S3, Amazon owns and manages the encryption keys on your behalf, using AES-256 with 256-bit keys, and applies encryption automatically to new objects written to S3. This provides a simple, fully managed, and effortless way to encrypt data at rest, aligning exactly with the stated requirement.

Why this answer

SSE-S3 (Server-Side Encryption with S3-Managed Keys) is the correct answer because it requires minimal configuration: you simply enable it on the bucket or object, and AWS fully manages the encryption keys, including rotation and protection, without any additional setup or key management overhead.

Exam trap

The trap here is that candidates often confuse SSE-S3 with SSE-KMS, assuming that any key management service (KMS) is required for automated encryption, but SSE-S3 provides fully automated key management with even less configuration than SSE-KMS.

How to eliminate wrong answers

Option A (SSE-C) is wrong because it requires you to provide and manage your own encryption keys, which adds configuration complexity and does not automate key management. Option B (SSE-KMS) is wrong because while it automates key management, it requires you to create and configure a KMS key, set IAM policies, and optionally manage key rotation, which is more configuration than SSE-S3. Option D (Client-side encryption) is wrong because it requires you to encrypt data before uploading to S3, meaning you must manage keys and encryption logic entirely on the client side, which is the opposite of minimal configuration.

40
Multi-Selecteasy

A company wants to protect its AWS account credentials. Which TWO practices are recommended by AWS? (Choose TWO.)

Select 2 answers
A.Generate and share access keys for all users.
B.Store IAM user passwords in a shared document.
C.Enable multi-factor authentication (MFA) for privileged users.
D.Use the root user for daily administrative tasks.
E.Use IAM roles for applications that require AWS access.
AnswersC, E

Enabling MFA for privileged users requires a second authentication factor, so a stolen or phished password alone cannot produce a console login or an authenticated API call. This control directly blocks account takeover from reused passwords, keylogging, or credential stuffing, because the attacker must also possess the virtual or hardware token. AWS recommends enforcing MFA with an IAM policy that explicitly denies actions unless aws:MultiFactorAuthPresent is true, which makes MFA mandatory rather than optional.

Why this answer

Option C is correct because AWS recommends enabling multi-factor authentication (MFA) for privileged users, adding a second authentication factor (such as a virtual MFA device, hardware TOTP token, or FIDO2 security key) so that a stolen password alone cannot compromise the account. Option E is correct because IAM roles provide temporary credentials via AWS STS (AssumeRole), so applications, EC2 instances, and Lambda functions can access AWS services without embedding long-lived access keys in code or configuration. Option A is wrong because AWS advises against generating and sharing access keys; keys are long-lived credentials that should be rotated and never shared, and permissions should be granted per identity.

Option B is wrong because storing IAM user passwords in a shared document exposes credentials; passwords should be managed with strong policies and never stored in plaintext shared locations. Option D is wrong because the root user has unrestricted access and AWS strongly recommends locking away root credentials, enabling MFA on root, and using IAM users or roles with least privilege for daily administrative tasks.

Exam trap

DOP-C02 often tests the misconception that access keys are the standard way to grant AWS access to applications, when in fact IAM roles with temporary credentials are the recommended approach.

41
MCQeasy

A company wants to automate the rotation of IAM user access keys every 90 days. Which AWS service can be used to achieve this?

A.Store the access keys in AWS Secrets Manager and enable automatic rotation.
B.Use AWS CloudTrail to detect old keys and send notifications to administrators.
C.Use IAM's built-in access key rotation feature.
D.Use AWS Config with a custom Lambda function to rotate keys when they are older than 90 days.
AnswerD

AWS Config enables this by hosting a custom rule that invokes a Lambda function on a schedule using the rule's 'maximum execution frequency' setting, evaluating all IAM users' access keys for age. The Lambda function can use IAM API calls such as ListAccessKeys and GetAccessKeyLastUsed to identify keys older than 90 days, then rotate them by creating a new access key, deactivating the old key, and deleting the old key after a grace period. This is a well-known pattern because AWS Config provides the periodic orchestration and compliance evaluation while Lambda handles the actual IAM operations.

Why this answer

AWS IAM does not have a built-in automatic rotation feature for access keys. AWS Secrets Manager can store secrets and rotate them, but it does not natively rotate IAM access keys; it supports rotation for RDS, Redshift, and DocumentDB, but not IAM. AWS CloudTrail is a logging service and cannot rotate keys.

However, AWS Config can be used with a custom AWS Lambda function to create a rule that triggers rotation when access keys are older than 90 days. Therefore, option D is the correct answer.

42
Multi-Selecteasy

Which TWO AWS services can be used to manage secrets and database credentials securely? (Choose TWO.)

Select 2 answers
A.AWS CloudFormation
B.AWS Secrets Manager
C.Amazon S3
D.AWS Identity and Access Management (IAM)
E.AWS Systems Manager Parameter Store
AnswersB, E

AWS Secrets Manager is a purpose-built service for centrally managing the entire secret lifecycle, including storing, retrieving, and automatically rotating secrets such as database credentials, API keys, and OAuth tokens. It enforces fine-grained IAM access policies, integrates with AWS KMS for encryption, and supports automatic rotation via AWS Lambda with built-in integrations for RDS, Redshift, and DocumentDB. This makes it the most comprehensive choice for managing secrets.

Why this answer

AWS Secrets Manager is purpose-built for securely storing, rotating, and managing secrets such as database credentials, API keys, and other sensitive data. It provides built-in integration with Amazon RDS, Redshift, and DocumentDB to automatically rotate credentials on a schedule, eliminating the need for manual updates. This makes it a correct choice for the question's requirement to manage secrets and database credentials securely.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secure strings) with a full secrets management solution, but Parameter Store lacks native automatic rotation and is better suited for configuration data rather than database credentials that require scheduled rotation.

43
MCQeasy

A company is using AWS KMS to encrypt data at rest for S3 objects. The security team wants to rotate the KMS key annually. Which action should the team take to implement automatic key rotation?

A.Enable automatic key rotation when creating the KMS key
B.Create a new key manually each year and update the S3 bucket policy
C.Use AWS Certificate Manager (ACM) to rotate the KMS key
D.Use an AWS managed key, which rotates automatically every year
AnswerA

Enabling automatic key rotation on a customer-managed KMS key at creation schedules KMS to generate new cryptographic material every 365 days while preserving the same key ID, ARN, and aliases. S3 bucket policies and IAM policies still reference the same key, so no re-encryption of existing objects or policy updates are required. KMS automatically keeps all versions of the backing material available for decryption, so data encrypted before rotation remains decryptable without interruption.

Why this answer

AWS KMS supports automatic annual key rotation for customer managed keys (CMKs) when enabled at creation or via the key's rotation configuration. Once enabled, KMS automatically rotates the key material every 365 days, creating a new backing key while retaining the old one for decryption of previously encrypted data. This satisfies the security team's requirement without manual intervention.

Exam trap

The trap here is that candidates may confuse AWS managed keys (which rotate automatically but cannot be configured by the customer) with customer managed keys (which require explicit enabling of automatic rotation), leading them to select Option D incorrectly.

How to eliminate wrong answers

Option B is wrong because manually creating a new key each year and updating the S3 bucket policy is not automatic rotation and introduces operational overhead and potential misconfiguration. Option C is wrong because AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for rotating KMS keys; ACM has no integration with KMS key rotation. Option D is wrong because AWS managed keys (e.g., aws/s3) do rotate automatically, but they are not customer managed keys; the question implies the company is using a customer managed key (since they want to control rotation), and AWS managed keys cannot be configured for rotation by the customer.

44
MCQmedium

A DevOps engineer receives an alert that an EC2 instance has been compromised. The instance is part of an Auto Scaling group. What is the first step the engineer should take to isolate the instance?

A.Create a snapshot of the instance's root volume
B.Detach the instance from the Auto Scaling group and remove it from the load balancer
C.Create an AMI of the instance for analysis
D.Terminate the instance immediately
AnswerB

Detaching the instance from the Auto Scaling group and removing it from the load balancer is the correct first step because it immediately stops new traffic from reaching the instance while also preventing the ASG from automatically replacing or terminating it. This preserves the running state for forensic collection, including memory and volatile data, and allows you to investigate safely without the instance being scaled away or continuing to affect production traffic. The instance stays alive but is decoupled from both the horizontal scaling and the request path.

Why this answer

The first step to isolate a compromised EC2 instance in an Auto Scaling group is to detach it from the Auto Scaling group and remove it from the load balancer. This stops all incoming traffic to the instance, preventing further damage or data exfiltration while preserving the instance for forensic analysis. Option A (snapshot) is useful for preserving evidence but does not isolate the instance.

Option C (AMI) similarly does not provide immediate isolation. Option D (terminate) may destroy evidence and should only be done after investigation.

45
MCQeasy

A company wants to encrypt data at rest in Amazon S3 using server-side encryption with AWS Key Management Service (SSE-KMS) and enforce that all new objects are encrypted. Which bucket policy statement should be added?

A.{"Effect":"Deny","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket/*","Condition":{"StringNotEquals":{"s3:ServerSideEncryption":"awskms"}}}
B.{"Effect":"Deny","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket/*","Condition":{"StringEquals":{"s3:x-amz-server-side-encryption-aws-kms-key-id":"arn:aws:kms:us-east-1:123456789012:key/1234-5678-9012"}}}
C.{"Effect":"Deny","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption-aws-kms-key-id":"arn:aws:kms:us-east-1:123456789012:key/1234-5678-9012"}}}
D.{"Effect":"Deny","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"AES256"}}}
AnswerC

Using `StringNotEquals` on the KMS key ID correctly denies every `PutObject` request whose encryption key is not the specified ARN. This ensures that only objects encrypted with the designated customer-managed KMS key can be written to the bucket, enforcing SSE-KMS with that exact key.

Why this answer

Option C uses the valid condition key `s3:x-amz-server-side-encryption-aws-kms-key-id` with `StringNotEquals` to deny `s3:PutObject` if the request does not include the specified KMS key ID. This enforces that all new objects are encrypted with that specific KMS key. Option A is incorrect because `s3:ServerSideEncryption` is not a valid condition key for S3.

Option B is incorrect because it uses `StringEquals` instead of `StringNotEquals`, causing it to deny requests that include the specified KMS key, which prevents the use of SSE-KMS. Option D is incorrect because it uses `s3:x-amz-server-side-encryption` with value `AES256`, which enforces SSE-S3, not SSE-KMS.

Exam trap

Candidates might confuse the condition keys or the string comparison operators. `s3:x-amz-server-side-encryption` checks the encryption algorithm (e.g., AES256 or aws:kms), while `s3:x-amz-server-side-encryption-aws-kms-key-id` checks the specific KMS key ID. Also, `StringNotEquals` is used to deny if a required condition is not met, whereas `StringEquals` with deny can accidentally block valid requests.

46
Multi-Selectmedium

A security engineer is designing a secure VPC architecture for a web application. The application must be isolated from the internet and only accessible through a load balancer. Which TWO actions should the engineer take?

Select 2 answers
A.Place the EC2 instances in a private subnet with no internet gateway attachment.
B.Attach an Internet Gateway to the VPC and route the private subnet to it.
C.Configure a network ACL on the private subnet to allow inbound traffic on all ephemeral ports.
D.Configure the security group for the EC2 instances to allow traffic only from the ALB's security group.
E.Set up an AWS Direct Connect connection for the instances to access the internet.
AnswersA, D

Placing the EC2 instances in a private subnet with no internet gateway (IGW) route ensures they cannot receive unsolicited inbound traffic from the internet. The ALB, deployed in a public subnet, is the only intentional ingress point; it forwards traffic to the instances over the private VPC network, which does not require an IGW. This design prevents direct exposure of instance IPs and relies on the security group to restrict traffic to just the ALB's interface.

Why this answer

Placing EC2 instances in a private subnet without an internet gateway ensures they have no direct path to the internet, meeting the isolation requirement. This forces all traffic to and from the instances to go through the load balancer, which is the only entry point for the application.

Exam trap

The trap here is that candidates often confuse the need for a network ACL to allow ephemeral ports (Option C) as a necessary step for inbound traffic from the ALB, but security groups handle stateful filtering and the ALB's security group is the correct source, while network ACLs are stateless and require explicit rules for both inbound and outbound traffic, which is not the primary action for isolation.

47
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team requires that all traffic to the ALB must be encrypted (HTTPS) and that the ALB must only accept traffic from CloudFront. The DevOps engineer has configured CloudFront with an origin pointing to the ALB, and the ALB has a listener on port 443 with a valid SSL certificate. The engineer also added a security group rule to the ALB that allows HTTPS traffic only from CloudFront's IP ranges. However, users are reporting intermittent 503 errors. The engineer checks CloudFront logs and sees that some requests are failing with 'Origin Connect Error'. What is the most likely cause?

A.The ALB has a Web Application Firewall (WAF) that is blocking requests from CloudFront.
B.The security group rule is using an outdated list of CloudFront IP ranges, and CloudFront has added new IP ranges that are being blocked.
C.The SSL certificate on the ALB is not trusted by CloudFront, causing handshake failures.
D.The ALB idle timeout is set too low, causing CloudFront to close connections prematurely.
AnswerB

CloudFront's origin-facing IP ranges change periodically, so a static security group rule based on a previously captured list will block newer edge locations. Those blocked connections surface as 'Origin Connect Error' and intermittent 503s, matching the stem's requirement that the ALB accept traffic only from CloudFront.

Why this answer

CloudFront publishes its origin-facing IP ranges in the managed prefix list (com.amazonaws.global.cloudfront.origin-facing) and updates it periodically. If the ALB security group was configured with a static, manually copied list of CloudFront IPs, newly added edge locations will connect from IPs not in the allow list, and the ALB will drop the TCP handshake — producing 'Origin Connect Error' in CloudFront logs and 503s to users. The correct fix is to reference the AWS-managed prefix list rather than hardcoded CIDRs.

Exam trap

DOP-C02 often tests the misconception that a static snapshot of CloudFront IP ranges is sufficient for origin lockdown, when in fact AWS updates these ranges continuously and only the managed prefix list stays current.

How to eliminate wrong answers

Option A is wrong because a WAF blocking requests would return an HTTP 403 from the ALB, not an 'Origin Connect Error' — WAF operates at layer 7 after the TCP connection succeeds. Option C is wrong because CloudFront does not validate the origin's certificate against a public CA trust chain the way a browser does; it accepts the origin certificate during the TLS handshake as long as it is valid for the origin domain, so an untrusted cert would not cause intermittent connect errors. Option D is wrong because an idle timeout mismatch would cause sporadic 504 Gateway Timeout errors on long-running requests, not 'Origin Connect Error' on connection establishment.

48
Multi-Selectmedium

Which TWO actions are effective ways to protect an AWS account root user? (Choose 2)

Select 2 answers
A.Use a strong, complex password and change it every 90 days.
B.Use the root user for everyday administrative tasks.
C.Enable multi-factor authentication (MFA) on the root user.
D.Rotate the root user password every 30 days.
E.Delete or disable the root user access keys.
AnswersC, E

Enabling multi-factor authentication (MFA) on the root user is a foundational AWS Well-Architected security control because it adds a second authentication factor, typically a hardware token or virtual device, that an attacker cannot easily replicate. Even if the root password is stolen through phishing, keylogging, or a data breach, MFA prevents unauthorized sign-in without the physical or virtual device. AWS documentation lists root user MFA as a mandatory security recommendation, and it is one of the only two effective protective actions among the presented options — the other being the removal of root access keys — because it directly defeats password-only compromise.

Why this answer

Option C is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the highly privileged root account. Option E is correct because root user access keys grant programmatic access with full account privileges, and AWS best practice is to delete them or, if they cannot be deleted, disable and rotate them so they cannot be abused. Options A and D are not the recommended controls: AWS does not require or recommend periodic root password rotation as a primary protection, and password complexity alone does not mitigate credential theft.

Option B is incorrect because using the root user for everyday administrative tasks violates least privilege and greatly increases the blast radius of a compromise; instead, create IAM users or roles with the needed permissions.

Exam trap

The trap is selecting password rotation options (A, D) as 'security best practices' when AWS explicitly deprioritizes rotation in favor of MFA and eliminating root access keys.

49
MCQhard

A company has an AWS Lambda function that processes sensitive data. The function needs to access an RDS database with credentials stored in Secrets Manager. What is the MOST secure way to grant the Lambda function access to the secret?

A.Use AWS KMS to encrypt the credentials and pass them as parameters.
B.Attach an IAM role to the Lambda function with permissions to read the secret and retrieve it at runtime.
C.Store the credentials directly in the Lambda function's environment variables.
D.Use Lambda environment variables with encryption enabled.
AnswerB

Attaching an IAM role to the Lambda function and granting it permissions to read the secret from AWS Secrets Manager (or Systems Manager Parameter Store) at runtime ensures that the plaintext credential never exists in the code, deployment package, or configuration. The Lambda service uses the execution role to obtain temporary credentials, and the secret is retrieved over a secure AWS API call, enabling least-privilege access, automatic rotation, and CloudTrail auditing. This is the AWS recommended pattern because the secret remains under the management of a purpose-built service, and the function only receives it during the invocation.

Why this answer

Attaching an IAM role to the Lambda function and granting it secretsmanager:GetSecretValue for the specific secret is the AWS-native, most secure pattern. The Lambda execution role provides temporary, automatically rotated credentials via STS, and the secret is fetched at runtime so it is never stored in code, environment variables, or configuration. This also enables CloudTrail auditing of every secret access.

Exam trap

DOP-C02 often tests the misconception that 'encrypted environment variables' are secure — candidates miss that encryption at rest does not protect the decrypted value at runtime and lacks rotation and auditability.

How to eliminate wrong answers

Option A is wrong because passing KMS-encrypted credentials as parameters still requires the caller to hold and transmit the ciphertext and the decryption capability, and it bypasses Secrets Manager's rotation and audit features. Option C is wrong because plaintext credentials in environment variables are visible in the Lambda console, CloudFormation templates, and any logging that dumps the environment — a direct secret exposure. Option D is wrong because Lambda environment variable encryption only protects data at rest with a KMS key; the decrypted value is still injected into the runtime and visible to anyone with lambda:GetFunctionConfiguration, and it does not support rotation.

50
MCQeasy

The AWS Config rule 's3-bucket-ssl-requests-only' returns NON_COMPLIANT for the bucket 'my-bucket'. What does this mean?

A.The bucket's policy does not deny requests that are not using SSL.
B.The bucket is publicly accessible.
C.The bucket does not have server access logging enabled.
D.The bucket does not have default encryption enabled.
AnswerA

The AWS Config rule 's3-bucket-ssl-requests-only' requires a bucket policy that explicitly denies requests when aws:SecureTransport is false. If the policy lacks such a deny statement, the rule evaluates as NON_COMPLIANT, which is reported as 'no' in Config. Merely allowing HTTPS is insufficient; the rule demands a positive deny of HTTP to make the intent explicit and enforceable.

Why this answer

The AWS Config rule 's3-bucket-ssl-requests-only' checks whether the bucket policy denies requests that are not using SSL (i.e., HTTP). If it returns NON_COMPLIANT, it means the bucket policy does not have a statement that denies non-SSL requests, so the bucket is not enforcing SSL-only access.

Exam trap

DOP-C02 often tests the specific purpose of AWS Config rules, confusing SSL-requests-only with public access or encryption rules.

How to eliminate wrong answers

Option B is wrong because public accessibility is evaluated by a different rule, such as 's3-bucket-public-read-prohibited'. Option C is wrong because server access logging is checked by 's3-bucket-logging-enabled'. Option D is wrong because default encryption is checked by 's3-bucket-server-side-encryption-enabled' or similar.

51
MCQeasy

A company wants to centralize audit logs from multiple AWS accounts into a single S3 bucket. The logs must be encrypted at rest using a KMS key. Which solution is the MOST secure and scalable?

A.Create an IAM role in each account and manually copy logs to a central bucket
B.Configure each account's CloudTrail to send logs to a central S3 bucket with a bucket policy that grants cross-account permissions
C.Use Amazon Kinesis Data Firehose to stream logs to S3
D.Use AWS Config rules to aggregate logs into a central bucket
AnswerB

This is the standard pattern: configure CloudTrail in each AWS account (or use an organization trail) to deliver log files directly to a central S3 bucket, and attach a bucket policy that grants the CloudTrail service principal from each source account permission to write objects (s3:PutObject, s3:GetBucketAcl). This approach is fully automated, idempotent, and preserves log integrity. For additional security, you can enable SSE-KMS, but the KMS key policy must also allow the CloudTrail service for each account.

Why this answer

Configuring each account's CloudTrail to deliver logs directly to a central S3 bucket with a bucket policy granting cross-account permissions is the most secure and scalable solution. It uses native AWS service integration, avoids custom code, and supports KMS encryption at rest. The bucket policy enforces least privilege and can require SSE-KMS with a specific key.

Exam trap

The trap is overcomplicating the solution with streaming services (Kinesis) or manual copying — candidates often overlook the native, scalable CloudTrail-to-S3 cross-account pattern that AWS explicitly supports.

How to eliminate wrong answers

Option A is wrong because manually copying logs with IAM roles is error-prone, not scalable, and lacks real-time delivery. Option C is wrong because Kinesis Data Firehose is a streaming delivery service that adds complexity and cost; it is not the standard pattern for centralized CloudTrail log aggregation. Option D is wrong because AWS Config rules evaluate compliance and do not aggregate CloudTrail logs into S3.

52
MCQeasy

A DevOps engineer needs to store secrets such as database passwords for a serverless application. Which AWS service is most appropriate?

A.Amazon DynamoDB with encryption
B.Amazon S3 with server-side encryption
C.AWS Systems Manager Parameter Store (SecureString)
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is a purpose-built service for managing secrets, offering native automatic rotation with Lambda, fine-grained IAM permissions using resource-based policies, and built-in integration with services like RDS, Redshift, and DocumentDB. It supports secret versioning and staged rotation, enforces least-privilege with Secrets Manager resource policies, and provides auditability via CloudTrail. This makes it the ideal choice when the requirement is a managed secrets store with automated lifecycle management.

Why this answer

AWS Secrets Manager is the most appropriate service because it is specifically designed to manage secrets like database passwords, with automatic rotation, encryption, and fine-grained access control. Option A (DynamoDB) is a database, not a secrets manager. Option B (S3) can store encrypted data but lacks built-in secret rotation and management.

Option C (Systems Manager Parameter Store SecureString) can store secrets but does not support automatic rotation, making Secrets Manager the better choice.

53
MCQmedium

Refer to the exhibit. A CloudTrail trail named ManagementTrail is configured as shown. Which events will be logged?

A.Only read management events.
B.Only write management events.
C.Only S3 data events.
D.All management events for the account.
AnswerD

The trail configuration is set to capture all management events for the AWS account. ReadWriteType:All ensures both read and write management operations are logged, while IncludeManagementEvents:true explicitly enables this type of logging. Because the DataResources array is empty, the trail is not configured for data events and focuses entirely on the control plane across all services. This matches the described behavior: the trail logs every management event, making this the correct answer.

Why this answer

The CloudTrail trail named ManagementTrail is configured to log management events, and by default, when you create a trail in the CloudTrail console, it logs both read and write management events unless you specifically choose to log only one type. The exhibit shows no filtering for read-only or write-only events, so all management events (both read and write) for the account will be logged. This is the standard behavior for a trail that does not have an event selector restricting the event type.

Exam trap

AWS often tests the misconception that a trail named 'ManagementTrail' only logs management events of a specific type (read or write), but the default behavior is to log all management events unless an explicit event selector is configured to filter them.

How to eliminate wrong answers

Option A is wrong because selecting 'Only read management events' would require explicitly configuring an event selector with ReadOnly set to true, which is not shown in the exhibit. Option B is wrong because selecting 'Only write management events' would require explicitly configuring an event selector with ReadOnly set to false, which is not shown. Option C is wrong because S3 data events are not management events; they are a separate category that must be explicitly enabled via event selectors, and the exhibit shows no such configuration.

54
MCQhard

A company uses Amazon Inspector to scan EC2 instances for vulnerabilities. The security team discovers that a critical vulnerability is present on an instance, but the instance is part of an Auto Scaling group. What is the MOST efficient way to remediate this vulnerability while ensuring the Auto Scaling group remains operational?

A.Patch the instance manually via SSH, then create a new AMI from it and update the launch configuration.
B.Detach the instance from the Auto Scaling group, patch it, and reattach it.
C.Use AWS Systems Manager Patch Manager to patch the instance and then set the instance to not receive future updates.
D.Create a new AMI with the patch, update the Auto Scaling group's launch template, and terminate instances one by one to trigger replacement.
AnswerD

This is the correct approach because it maintains a clean, versioned baseline: you create a new AMI that includes the patch, update the Auto Scaling group's launch template to reference that AMI, and then perform a rolling replacement of existing instances. Terminating instances one by one (or using instance refresh) ensures that the ASG launches new instances from the patched AMI, maintaining availability and minimizing disruption during the update. This aligns with infrastructure-as-code and immutable infrastructure practices, ensuring that all current and future instances are consistently patched and that the launch template is the single source of truth.

Why this answer

The immutable-infrastructure approach — build a patched AMI, update the Auto Scaling group's launch template, and roll instances — ensures every new instance is born patched and the ASG maintains capacity throughout. Terminating instances one by one triggers replacement with the new AMI while the group stays operational.

Exam trap

DOP-C02 often tests whether candidates realise that updating a launch template or configuration alone does not patch running instances — you must trigger replacement, and the most efficient answer preserves ASG capacity.

How to eliminate wrong answers

Option A is wrong because patching a single instance manually and creating an AMI from it is slow, error-prone, and does not scale — other instances in the ASG remain vulnerable, and the launch configuration update alone does not replace existing instances. Option B is wrong because detaching an instance from the ASG reduces capacity and leaves the patched instance unmanaged; it also does not fix the other instances. Option C is wrong because Systems Manager Patch Manager can patch instances, but setting the instance to 'not receive future updates' is the opposite of good hygiene and does not address the AMI or future instances.

55
Multi-Selectmedium

Which TWO actions are best practices for securing an AWS account root user? (Select TWO.)

Select 2 answers
A.Use the root user for daily administrative tasks
B.Create access keys for the root user to use with CLI
C.Create an IAM user with administrator access and use that instead
D.Enable multi-factor authentication (MFA) for the root user
E.Delete the root user after creating an IAM admin user
AnswersC, D

This is a best practice because IAM users can have permissions scoped and credentials rotated independently. An administrator user with the AdministratorAccess managed policy can perform all tasks except account-level root-only actions, while enabling CloudTrail auditing, MFA, and password rotation. Avoid using root for daily work, as IAM users provide traceability and control.

Why this answer

Best practices for root user include enabling MFA, using a strong password, and not using root for daily tasks. Deleting the root user is not possible. Access keys should not be created for root user.

56
MCQhard

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to download an object from the S3 bucket 'example-bucket' from an IP address of 10.1.2.3. What will happen?

A.The request is denied because the policy does not include a Deny statement.
B.The request is denied because the policy does not explicitly allow the action.
C.The result depends on the bucket policy.
D.The request is allowed because the condition matches the IP address.
AnswerD

This is correct because the policy's condition uses the IpAddress operator to restrict access to requests originating from IP addresses within the CIDR range 10.0.0.0/8. The source IP address of the request, 10.1.2.3, falls within that range (since 10.1.2.3 is between 10.0.0.0 and 10.255.255.255). Therefore, the condition in the Allow statement evaluates to true, and the action is allowed.

Why this answer

The IAM policy includes a condition that allows s3:GetObject only if the request originates from an IP address within the 10.0.0.0/8 range. The user's IP 10.1.2.3 falls within this range, so the condition is satisfied and the action is allowed. Option A is wrong because a Deny statement is not required; an explicit Allow with a condition is sufficient.

Option B is wrong because the policy does explicitly allow the action when the condition is met. Option C is wrong because the bucket policy is not specified and the IAM policy already grants permission; the result does not depend on the bucket policy unless it explicitly denies, but no such policy is shown.

57
MCQhard

A company is using AWS CodePipeline to deploy a web application across multiple AWS accounts using CloudFormation stack sets. The pipeline is in the tools account, and it deploys to production account. The security team requires that all CloudFormation changes to production account be reviewed and approved by a senior engineer. Which approach meets this requirement?

A.Use AWS CloudTrail to monitor deployments and send notifications for review.
B.Configure an IAM policy that denies CloudFormation actions in the production account except for a specific role used by the senior engineer.
C.Add a manual approval step in the CodePipeline before the CloudFormation deployment stage.
D.Use a service control policy (SCP) to prevent CloudFormation changes from the tools account.
AnswerC

A manual approval action pauses the pipeline before the CloudFormation deploy stage, so a senior engineer must review and approve changes before they reach the production account. This enforces the required human gate on production changes.

Why this answer

Adding a manual approval step in CodePipeline before the CloudFormation deployment stage allows a senior engineer to review and approve changes, meeting the security requirement. Option A is incorrect because CloudTrail only logs actions after they occur and does not provide a review mechanism. Option B is incorrect because denying CloudFormation actions to all but a specific role would prevent the pipeline from deploying unless it uses that role, but it does not enforce a manual review process.

Option D is incorrect because SCPs are preventive controls that block actions, not a mechanism for manual approval.

58
MCQmedium

A security audit reveals that an IAM user has long-term access keys that have not been rotated in over 90 days. What is the most secure way to enforce key rotation?

A.Use an AWS Lambda function to automatically rotate keys.
B.Manually rotate keys every 90 days.
C.Use IAM roles instead of long-term access keys.
D.Delete the user and create a new one.
AnswerC

IAM roles are the AWS-recommended alternative because they do not require long-term secrets at all: a principal assumes a role through the AWS Security Token Service (STS) and receives temporary credentials with a configurable lifetime (up to 12 hours for role sessions) that are automatically rotated and expire. These credentials can be further constrained by session policies, preventing privilege escalation, and eliminate the operational burden of rotating static access keys, making them far more secure and auditable.

Why this answer

A custom Lambda function to rotate keys requires you to build and maintain the rotation logic, permission grants, and secret distribution yourself - AWS IAM has no native, built-in automatic key-rotation feature for access keys, so this approach is at best a partial mitigation with real engineering overhead, and it still leaves long-term static credentials in play between rotations. IAM roles are the superior fix because they remove the need for any long-term key or rotation logic at all.

Exam trap

The trap here is that candidates focus on 'rotation' as a process (automated or manual) rather than recognizing that the most secure solution is to eliminate the need for rotation entirely by using IAM roles with temporary credentials.

How to eliminate wrong answers

Option A is wrong because while a Lambda function can automate key rotation, it still relies on long-term access keys (the user still exists with keys that must be rotated), and implementing such a solution introduces complexity, potential security gaps (e.g., Lambda execution role permissions), and does not eliminate the fundamental risk of long-term credentials. Option B is wrong because manual rotation every 90 days is error-prone, relies on human compliance, and does not address the underlying security issue that long-term keys can be exfiltrated and used for extended periods before detection. Option D is wrong because deleting and recreating the user does not solve the problem—the new user would still have long-term access keys that require rotation, and this approach disrupts workflows without addressing the root cause.

59
MCQeasy

A DevOps engineer needs to rotate database credentials stored in AWS Secrets Manager automatically every 30 days. What is the simplest way to achieve this?

A.Enable automatic rotation in Secrets Manager with a rotation interval of 30 days.
B.Store the credentials in Systems Manager Parameter Store and use a scheduled automation to update them.
C.Create a CloudWatch Events rule that triggers a Lambda function to rotate the secret.
D.Write a custom Lambda function that rotates the secret and schedule it with CloudWatch Events.
AnswerA

Secrets Manager automatically rotates the secret on a schedule you define (e.g., 30 days) using a built-in Lambda template tailored to your database engine, such as RDS for PostgreSQL or MySQL. Because the rotation orchestration—including updating the secret and testing it against the database—is handled entirely by the service, you avoid writing or maintaining custom code and scheduling components. This gives you a fully managed, auditable rotation process with no operational overhead beyond configuring the interval.

Why this answer

AWS Secrets Manager has built-in automatic rotation: you enable it on the secret, specify a rotation interval (e.g., 30 days), and provide a Lambda rotation function (AWS provides templates for RDS, Redshift, DocumentDB). This is the simplest, fully managed approach and requires no custom scheduling infrastructure.

Exam trap

The trap is over-engineering — candidates pick the custom Lambda + CloudWatch Events option because it sounds more 'controlled', but the exam rewards the managed, built-in rotation feature when the requirement is simply periodic rotation.

How to eliminate wrong answers

Option B is wrong because Systems Manager Parameter Store does not natively rotate secrets — you would have to build and schedule the rotation logic yourself, which is more complex than Secrets Manager's built-in feature. Option C is wrong because creating a CloudWatch Events rule to trigger a Lambda is exactly what Secrets Manager does internally; doing it manually adds unnecessary components and management overhead. Option D is wrong because writing a custom Lambda and scheduling it with CloudWatch Events reimplements functionality Secrets Manager already provides out of the box, violating the 'simplest way' requirement.

60
MCQeasy

A DevOps engineer needs to securely store database credentials for an application running on Amazon ECS. Which AWS service should be used to manage the credentials and provide them to the ECS tasks?

A.AWS Secrets Manager
B.Amazon S3 with server-side encryption
C.AWS Systems Manager
D.AWS Systems Manager Parameter Store
AnswerA

AWS Secrets Manager is the correct choice because it is a purpose-built service for securely storing and managing database credentials, API keys, and other secrets. It provides native automatic rotation of database credentials via Lambda, fine-grained IAM-based access control, and built-in audit integration with AWS CloudTrail and Amazon EventBridge. Unlike generic storage services, Secrets Manager caches secrets securely and enforces resource-based policies, making it the only fully managed solution that directly addresses the requirements.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials, and it integrates natively with ECS so tasks can inject secrets as environment variables or in log configuration. It supports automatic rotation via Lambda, which is ideal for database credentials. ECS task definitions reference Secrets Manager secrets using the secrets block with valueFrom.

Exam trap

DOP-C02 often tests the distinction between Secrets Manager and Parameter Store — candidates pick Parameter Store for database credentials, but Secrets Manager is preferred when automatic rotation and native secret management are required.

How to eliminate wrong answers

Option B is wrong because S3 with SSE stores objects but is not designed for secret management, lacks native rotation, and requires custom code to retrieve and inject credentials. Option C is wrong because AWS Systems Manager is a broad operational service (patch management, run command, session manager); while it includes Parameter Store, the service itself is not the credential-management answer. Option D is wrong because Systems Manager Parameter Store can store SecureString parameters, but it lacks built-in automatic rotation and is better suited for configuration data; Secrets Manager is the recommended service for database credentials with rotation.

61
MCQmedium

A company needs to store audit logs for 7 years to meet compliance requirements. Which S3 storage class is the most cost-effective for long-term archival?

A.S3 Glacier Deep Archive
B.S3 Intelligent-Tiering
C.S3 Standard
D.S3 Glacier Flexible Retrieval
AnswerA

S3 Glacier Deep Archive is the lowest-cost storage class in Amazon S3, designed for long-term retention of data accessed at most once or twice per year. With a per-GB storage price that is significantly lower than both Standard and Glacier Flexible Retrieval, it is the most cost-effective choice for a 7-year compliance archive where retrieval latency of up to 12 hours is acceptable. This makes it the correct answer for the stated requirement.

Why this answer

S3 Glacier Deep Archive is the lowest-cost S3 storage class, designed for data accessed less than once per year, with a standard retrieval time of 12 hours and a minimum storage duration of 180 days. For 7-year audit log retention where retrieval is rare and compliance-driven, it is the most cost-effective choice.

Exam trap

DOP-C02 often tests the confusion between Glacier Flexible Retrieval and Glacier Deep Archive, so candidates who pick Flexible Retrieval for 'archival' miss the cost-effectiveness requirement for rarely accessed data.

How to eliminate wrong answers

Option B is wrong because S3 Intelligent-Tiering adds monitoring and automation charges and is optimized for unknown or changing access patterns, not predictable long-term archival. Option C is wrong because S3 Standard is the most expensive class and is meant for frequently accessed data, making 7-year retention prohibitively costly. Option D is wrong because S3 Glacier Flexible Retrieval costs more than Deep Archive and offers faster retrieval (minutes to hours), which is unnecessary for compliance logs that are rarely accessed.

62
MCQeasy

A company wants to centralize logging of all API calls made within their AWS account for auditing. Which service should they use?

A.Amazon S3 access logs
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the native AWS service that records all management-plane API calls made by IAM users, roles, and AWS services, along with data-plane events for supported services. Each event includes the identity of the caller, the source IP address, the request parameters, and the response, enabling a complete audit trail. CloudTrail can be configured with a multi-region trail or an organization trail to centralize logging across all accounts and regions, making it the correct choice for centralized API call logging.

Why this answer

AWS CloudTrail is the service designed to log all API calls made within an AWS account, providing a detailed audit trail of actions taken by users, roles, and services. It records API activity across the AWS Management Console, SDKs, CLI, and other services. CloudTrail logs can be delivered to S3 and CloudWatch Logs for analysis.

Exam trap

DOP-C02 often tests the difference between CloudTrail and other logging services, and candidates might confuse VPC Flow Logs or S3 access logs with API auditing, but the trap is not recognizing CloudTrail's scope.

How to eliminate wrong answers

Option A is wrong because Amazon S3 access logs only record requests made to S3 buckets, not all API calls across the account. Option C is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option D is wrong because Amazon CloudWatch Logs is a log storage and analysis service, but it does not itself capture API calls; it can receive CloudTrail logs but is not the source.

63
MCQmedium

An organization has a compliance requirement to automatically detect and alert on any IAM user creation in all AWS accounts. Which combination of services should be used to meet this requirement?

A.Amazon GuardDuty and Amazon SNS
B.Amazon S3 server access logs and Amazon Athena
C.AWS Config and AWS Lambda
D.AWS CloudTrail and Amazon CloudWatch Events
AnswerD

CloudTrail is the authoritative audit service that records every management API call, including the IAM CreateUser event, along with details such as the requesting IAM principal, source IP address, and timestamps. You can configure CloudWatch Events (or Amazon EventBridge) with an event pattern that matches `"eventSource": "iam.amazonaws.com"` and `"eventName": "CreateUser"`, and route matching events to an SNS topic or Lambda function for immediate notification. This provides the real-time, event-driven alerting that directly satisfies a compliance requirement to automatically detect and respond to IAM user creation.

Why this answer

AWS CloudTrail captures all IAM user creation events as `CreateUser` API calls. Amazon CloudWatch Events (now Amazon EventBridge) can be configured with a rule that matches this specific event pattern and triggers an alert via Amazon SNS. This combination provides real-time detection and notification without custom code.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates resource configurations) with CloudTrail (which records API activity), leading them to select Option C, but AWS Config cannot trigger alerts on API call events like `CreateUser`; it only reacts to configuration changes after they have occurred.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide a native mechanism to trigger custom alerts on specific IAM user creation events; it focuses on anomalies and threats, not compliance-driven event monitoring. Option B is wrong because Amazon S3 server access logs record requests made to an S3 bucket, not IAM user creation events, and using Athena to query them would require a separate mechanism to capture CloudTrail logs into S3, adding latency and complexity; this approach is not designed for real-time alerting on IAM actions. Option C is wrong because AWS Config evaluates resource configurations against rules and can detect changes, but it is not designed for real-time event-driven alerting on API calls; it operates on configuration snapshots and compliance evaluations, not on streaming API events like `CreateUser`.

64
MCQeasy

A company uses AWS KMS to encrypt data in S3. They want to audit who used which KMS key and when. Which AWS service should they use?

A.Amazon CloudWatch
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

AWS CloudTrail is the correct answer because it records KMS API calls as data events, providing the principal, key ID, source IP address, and timestamp for each operation. When data events are enabled for a customer master key, CloudTrail captures every Encrypt, Decrypt, GenerateDataKey, and ScheduleKeyDeletion call, which is exactly what is needed to audit encryption usage. This KMS activity is delivered as a JSON event to an S3 bucket (and optionally to CloudWatch Logs), forming a durable, tamper-evident audit trail for compliance and security investigations.

Why this answer

AWS CloudTrail is the correct service because it records all AWS KMS API calls, including the key ID, the principal who made the request, the time of the request, and the source IP address. These logs are delivered to an S3 bucket and can be queried using CloudTrail Insights or Athena to audit KMS key usage for S3 decryption events.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (which can store logs) with CloudTrail (which captures the API audit trail), leading them to pick CloudWatch because they think 'audit logs' are just logs, but only CloudTrail records the specific KMS API calls needed for key usage auditing.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring service for metrics, alarms, and logs, but it does not natively capture the detailed API-level audit trail of KMS key usage; it can only visualize CloudTrail events if they are streamed to it. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail events for malicious activity, but it is not designed to provide a direct audit log of who used which KMS key and when. Option D is wrong because AWS Config is a resource inventory and compliance service that tracks configuration changes to AWS resources, not the API calls that use KMS keys for encryption or decryption operations.

65
MCQmedium

A company wants to automate the rotation of IAM user access keys every 90 days. Which AWS service should be used to implement this rotation?

A.AWS Lambda with custom rotation logic
B.AWS Config
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
AnswerA

Correct. AWS Lambda with custom rotation logic is the required approach since no other AWS service natively rotates IAM user access keys. You can write a Lambda function to generate new keys, update the IAM user, and handle the rotation schedule.

Why this answer

AWS Lambda with custom rotation logic is the correct service to automate IAM user access key rotation because AWS does not provide a native service that automatically rotates IAM access keys. AWS Secrets Manager can rotate secrets for databases and other services, but it does not support rotating IAM user access keys. Therefore, the recommended approach is to implement a custom Lambda function that generates new keys, updates the user, and manages the rotation lifecycle.

Option B (AWS Config) only monitors compliance, not credentials. Option D (Systems Manager Parameter Store) stores secrets but lacks rotation capabilities for IAM keys.

66
MCQeasy

A DevOps engineer needs to grant cross-account access to an S3 bucket in Account A for a user in Account B. Which combination of policies is required?

A.An S3 bucket policy in Account A and an IAM policy in Account B.
B.An IAM role in Account A and an IAM policy in Account B.
C.Only an IAM policy in Account B.
D.Only an S3 bucket policy in Account A.
AnswerA

For cross-account S3 access, both an S3 bucket policy in the owning account (Account A) that explicitly allows the external principal (e.g., an IAM user or role in Account B) to perform the desired actions, and an IAM policy in Account B that grants that same principal permission to call S3 on the bucket ARN are required. AWS evaluates identity-based policies and resource-based policies together, so a request succeeds only if both sides explicitly allow it. Without either, the request is implicitly denied.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (the S3 bucket policy in Account A) that grants the necessary permissions to the principal from Account B, and an identity-based policy (an IAM policy in Account B) attached to the user that allows the S3 actions. The bucket policy explicitly authorizes the external user (by ARN), while the IAM policy ensures the user has the required permissions to initiate the request. Without both, the request will fail due to the lack of either resource-side authorization or identity-side authorization.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, forgetting that the external user must also have an IAM policy that explicitly allows the S3 actions, leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because an IAM role in Account A would require the user in Account B to assume the role, which is a different mechanism (role-based cross-account access) and does not directly grant access via a bucket policy; the question specifically asks for granting access to an S3 bucket, not using role assumption. Option C is wrong because an IAM policy in Account B alone cannot grant access to a resource in Account A; the resource owner (Account A) must also authorize the access via a bucket policy or ACL. Option D is wrong because an S3 bucket policy in Account A alone is insufficient; the user in Account B must also have an IAM policy that allows the S3 actions, as the bucket policy only authorizes the external principal but does not grant the user permission to make the request.

67
MCQeasy

A company is using Amazon S3 to store sensitive data. The security team mandates that all data must be encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS). The DevOps engineer must ensure that any new objects uploaded to the bucket are automatically encrypted. What should the engineer do?

A.Enable CORS on the bucket to allow encrypted uploads.
B.Apply a bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header with aws:kms.
C.Enable default encryption on the S3 bucket and select AWS-KMS as the encryption method.
D.Enable S3 Versioning to protect encrypted objects.
AnswerC

Enabling default encryption on an S3 bucket with AWS-KMS selected ensures that every new object is automatically encrypted at rest using SSE-KMS, regardless of whether the upload request includes any encryption headers. This uses envelope encryption with a customer-managed KMS key, offering centralized key management, separate permissions for key access, and an audit trail of key usage. It is the correct approach because it is a direct, bucket-level setting that protects sensitive data without requiring client changes or policy-based request rejections.

Why this answer

Enabling default encryption on the S3 bucket with SSE-KMS ensures that all objects uploaded to the bucket are automatically encrypted at rest with AWS KMS. Option A is incorrect because CORS is for cross-origin requests and does not affect encryption. Option B is incorrect because while a bucket policy can enforce encryption headers, it does not provide default encryption; it only denies requests without the header, and default encryption is a simpler and more reliable method.

Option D is incorrect because versioning does not encrypt data.

68
MCQhard

A company is running a critical application on an Amazon EC2 instance that needs to access an S3 bucket. The application must use temporary credentials that automatically rotate. The DevOps engineer must ensure that the credentials are never stored on disk. Which approach meets these requirements?

A.Store the credentials in AWS Secrets Manager and retrieve them at application startup.
B.Attach an IAM role to the EC2 instance and use the instance profile to obtain temporary credentials from the instance metadata service.
C.Use AWS Systems Manager Parameter Store to store the credentials and retrieve them using the EC2 instance's IAM role.
D.Generate an access key and secret key for an IAM user and store them in a configuration file on the EC2 instance.
AnswerB

The best practice is to attach an IAM role to the EC2 instance; the instance profile exposes temporary security credentials via the Instance Metadata Service (IMDSv2), which the AWS SDKs automatically load and refresh. These credentials are short-lived, rotated automatically, and never written to disk, so no secret material is present in the file system, environment variables, or configuration files. This eliminates the need to manage access keys manually and reduces the risk of exposure if the instance is compromised.

Why this answer

Attaching an IAM role to the EC2 instance and using the instance profile allows the application to obtain temporary credentials from the EC2 instance metadata service (IMDS). These credentials are automatically rotated by AWS before they expire, and they are never stored on disk—they are fetched on-demand from the metadata endpoint (http://169.254.169.254/latest/meta-data/iam/security-credentials/). This satisfies both the requirement for automatic rotation and the prohibition against disk storage.

Exam trap

The trap here is that candidates may confuse AWS Secrets Manager or Parameter Store with a solution for automatic credential rotation, not realizing that those services store static secrets unless explicitly configured with rotation via Lambda, whereas an IAM instance profile inherently provides automatically rotating temporary credentials without any disk storage.

How to eliminate wrong answers

Option A is wrong because while AWS Secrets Manager can store and rotate credentials, the application would still need to retrieve and hold them in memory, and the credentials stored there are long-term IAM user keys or secrets, not automatically rotating temporary credentials from an instance profile. Option C is wrong because AWS Systems Manager Parameter Store can store credentials, but it does not inherently rotate them; the stored credentials would be static unless manually updated, and the application would still need to handle them in memory, not leveraging the automatic rotation of instance metadata service credentials. Option D is wrong because storing access keys and secret keys in a configuration file on disk directly violates the requirement that credentials never be stored on disk, and these static credentials do not automatically rotate.

69
Multi-Selectmedium

Which TWO of the following are benefits of using AWS Certificate Manager (ACM) to manage SSL/TLS certificates? (Choose two.)

Select 2 answers
A.Ability to use the same certificate on multiple EC2 instances.
B.Support for wildcard certificates only.
C.Automatic renewal of certificates.
D.Integration with Elastic Load Balancing and Amazon CloudFront.
E.Free certificates for use on any AWS service.
AnswersC, D

ACM automatically renews issued certificates when they are deployed on supported services, provided the domain validation remains valid, which spares engineers from manually tracking expiration dates. This automated lifecycle management is a key operational benefit because it prevents unexpected service interruptions caused by expired certificates. The renewal process works silently in the background, reissuing certificates before the current one expires, making it a primary reason organizations choose ACM.

Why this answer

Option C is correct because ACM automatically renews certificates that it issued and manages, as long as the certificate is in use and the domain validation remains valid, eliminating manual renewal overhead. Option D is correct because ACM certificates can be directly associated with Elastic Load Balancing (ALB/NLB) and Amazon CloudFront distributions, enabling seamless deployment of TLS termination without exporting private keys. Option A is not a listed benefit because ACM-issued public certificates cannot be exported or installed directly on EC2 instances; you must use services like ELB, CloudFront, or API Gateway.

Option B is incorrect because ACM supports both wildcard and non-wildcard (single-domain and multi-domain/SAN) certificates. Option E is incorrect because ACM public certificates are free only for integrated AWS services, not for arbitrary AWS services or exportable use, and ACM Private CA certificates incur cost.

70
MCQmedium

A company is using AWS CloudTrail to log API calls. The security team needs to ensure that log files are tamper-proof and can be used to verify integrity. Which feature should be enabled?

A.Server-side encryption (SSE-S3)
B.CloudTrail log file integrity validation
C.S3 Object Lock
D.MFA delete on the S3 bucket
AnswerB

CloudTrail log file integrity validation is purpose-built for exactly this need: it delivers signed digest files to your S3 bucket that cover the log files and link together in a hash chain. Each digest contains the SHA-256 hash of the prior digest and the current log files, and is signed with a private key by CloudTrail. You can use the corresponding public key to verify both the authenticity and the integrity of the logs, which lets you detect any modification, deletion, or forgery. Enabling this feature ensures that your audit trail itself is trustworthy, which is a key defense against attackers trying to cover their tracks by altering logs.

Why this answer

CloudTrail log file integrity validation uses SHA-256 hashing and digital signing to ensure logs have not been tampered with. S3 object lock prevents deletion but not modification. MFA delete protects deletion but not modification.

SSE encrypts data at rest but does not protect integrity.

71
Multi-Selectmedium

A company uses AWS Organizations with SCPs to enforce security policies. The security team needs to ensure that no IAM user or role can disable AWS CloudTrail or delete CloudTrail logs. Which TWO approaches should be combined to achieve this? (Choose TWO.)

Select 2 answers
A.Use a service control policy to deny s3:DeleteObject on the CloudTrail S3 bucket.
B.Enable MFA Delete on the CloudTrail S3 bucket.
C.Apply an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail for all accounts.
D.Enable CloudTrail log file validation.
E.Attach an IAM policy to all users denying cloudtrail:StopLogging.
AnswersA, C

An SCP denying s3:DeleteObject on the CloudTrail bucket prevents any account within the organization from deleting or overwriting the log objects that CloudTrail writes. This augments the previous SCP by protecting the evidence trail itself, not just the trail configuration. It is a preventive control at the organizational boundary, ensuring that even an administrator who manages to disable the trail cannot destroy historical log data that would reveal the actions.

Why this answer

To prevent IAM users and roles from disabling CloudTrail or deleting logs, a combination of two preventive controls is needed. Option A applies a service control policy (SCP) that denies s3:DeleteObject on the CloudTrail S3 bucket, preventing log deletion at the organizational level. Option C applies an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, preventing disabling of CloudTrail itself.

Both SCPs cannot be overridden by account administrators. Option D (log file validation) is a detective control—it detects tampering or deletion after it occurs, but does not prevent the action. Options B (MFA Delete) and E (IAM policy) are weaker or can be overridden, making them less reliable for this requirement.

Exam trap

Candidates often mistake detective controls (like log validation) for preventive controls. The question specifically asks for approaches that ensure no user or role can disable or delete—this requires preventive measures that block the action entirely.

72
MCQeasy

A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all new member accounts automatically receive a specific AWS Config rule to require encryption on Amazon EBS volumes. Which solution meets this requirement with the least operational overhead?

A.Use an SCP to deny the creation of unencrypted EBS volumes and use AWS Config to detect noncompliant volumes.
B.Use a service control policy (SCP) to deny the ability to disable the AWS Config rule and use a custom AWS Config rule that evaluates EBS encryption.
C.Use an AWS Config aggregator in the management account to monitor compliance across accounts.
D.Use AWS CloudFormation StackSets to deploy a stack with the Config rule to all existing and new accounts.
AnswerD

AWS CloudFormation StackSets let you define a stack containing the AWS Config rule once and deploy it to specified accounts across the organization. With service-managed StackSets, you can enable automatic deployment so that any new account added to the organization is automatically provisioned with the stack, ensuring the Config rule exists in every account. This centrally manages the rule's lifecycle and avoids needing per-account manual setup, making it the appropriate solution.

Why this answer

AWS CloudFormation StackSets can deploy a stack containing the AWS Config rule across all accounts in the organization, and with automatic deployment enabled, new accounts automatically receive the stack. This centrally manages the rule with minimal operational overhead. Option B is incorrect because SCPs only deny API actions and cannot deploy a Config rule; they would need a separate mechanism to deploy the rule initially.

Exam trap

The trap is that candidates may believe an SCP can be used to enforce a Config rule, but SCPs only deny or allow actions; they don't deploy configurations. The correct approach uses StackSets or organization-level Config rules for automatic deployment.

How to eliminate wrong answers

Option A is wrong because an SCP that denies the creation of unencrypted EBS volumes does not enforce an AWS Config rule; it only prevents creation but does not detect or remediate existing noncompliant volumes, and it does not automatically deploy the Config rule to new accounts. Option C is wrong because an AWS Config aggregator only provides a centralized view of compliance across accounts but does not enforce or deploy the Config rule to new accounts. Option D is wrong because CloudFormation StackSets require manual setup and ongoing management to deploy to new accounts as they are added, which introduces higher operational overhead compared to using organization-level AWS Config rules or SCPs.

73
MCQmedium

A company has a multi-account AWS environment using AWS Organizations. They want to centrally manage user access to all accounts using single sign-on (SSO) and enforce multi-factor authentication (MFA). Which service should they use?

A.Use AWS Secrets Manager to store and rotate IAM user credentials.
B.Create IAM users in each account and share the credentials securely.
C.Use Amazon Cognito user pools with an identity broker.
D.Use AWS IAM Identity Center (AWS SSO) to manage access and enforce MFA.
AnswerD

AWS IAM Identity Center centralizes workforce identity and builds on AWS Organizations to give users SSO access to all accounts via permission sets, which define granular IAM role permissions. It enforces MFA with policy settings such as requiring MFA for all users or context-dependent MFA, and supports both its built-in directory and external identity providers. Users sign in once at the portal or via the CLI, and IAM Identity Center automatically creates temporary credentials for each account.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized place to manage user access and permissions across all AWS accounts in an AWS Organization. It natively supports enforcing multi-factor authentication (MFA) through an identity source (e.g., the built-in identity store or an external IdP) and integrates directly with AWS Organizations to grant single sign-on access without needing to create IAM users in each account.

Exam trap

The trap here is that candidates often confuse Amazon Cognito (a customer identity service) with workforce identity management, or assume that storing credentials in Secrets Manager or creating per-account IAM users is a viable centralized solution, when in fact AWS IAM Identity Center is the only service designed for multi-account SSO with MFA enforcement in an AWS Organizations context.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is designed to securely store and rotate secrets (like database credentials or API keys), not to manage user identities or enforce MFA for SSO access. Option B is wrong because creating IAM users in each account and sharing credentials manually violates the principle of least privilege, creates a massive administrative overhead, and does not provide centralized SSO or consistent MFA enforcement across accounts. Option C is wrong because Amazon Cognito user pools are intended for customer-facing identity and access management for web and mobile applications, not for managing workforce access to AWS accounts via SSO with MFA enforcement across an AWS Organization.

74
MCQhard

A DevOps team is deploying a multi-tier application on AWS. The application must comply with PCI DSS. Which combination of services should be used to encrypt data in transit between the web tier and the application tier?

A.AWS Certificate Manager (ACM) and Application Load Balancer (ALB)
B.AWS CloudHSM and Classic Load Balancer
C.AWS KMS and VPC Peering
D.AWS WAF and Amazon CloudFront
AnswerA

ACM issues and automatically renews public or private TLS certificates that integrate natively with an ALB's HTTPS listener, allowing the ALB to terminate TLS and encrypt traffic between the client and load balancer. For multi-tier architectures, the ALB can front each layer (e.g., web and application), providing encrypted inter-tier communication without manual certificate deployment or key management. This approach leverages AWS-managed distribution, per-listener policies, and SNI support, directly addressing the requirement for in-transit encryption.

Why this answer

AWS Certificate Manager (ACM) provisions and manages the TLS certificates, and an Application Load Balancer (ALB) terminates TLS and re-encrypts traffic to backend targets, providing encryption in transit between the web tier and the application tier. This combination is the standard AWS pattern for PCI DSS-compliant in-transit encryption on a multi-tier application.

Exam trap

The trap is picking KMS or CloudHSM for 'encryption' — candidates forget that KMS encrypts data at rest and CloudHSM stores keys, while encryption in transit requires TLS, which on AWS means ACM plus a load balancer that terminates and re-encrypts.

How to eliminate wrong answers

Option B is wrong because CloudHSM is a hardware security module for key storage and cryptographic operations, not a load-balancing or TLS-termination service, and Classic Load Balancer is a legacy offering that lacks the modern TLS policy and target-group features needed for tier-to-tier encryption. Option C is wrong because KMS is a key management service and VPC Peering is a network connectivity feature — neither encrypts traffic in transit between tiers. Option D is wrong because AWS WAF is a web application firewall that filters HTTP requests and CloudFront is a CDN — neither provides the TLS termination and re-encryption needed between the web and application tiers.

75
MCQhard

A DevOps engineer executed the CLI command shown in the exhibit. After creation, the security team requires that the log files be encrypted with a KMS key that is rotated every 90 days. The current key is a customer managed key with automatic rotation enabled set to 365 days. What should the engineer do to meet the requirement?

A.Use the existing key and change the rotation period in KMS
B.Disable automatic rotation and manually rotate the key every 90 days
C.Modify the KMS key to set the rotation period to 90 days
D.Create a new KMS key with automatic rotation set to 90 days and update the trail with the new key
AnswerD

To achieve a 90-day automatic rotation, you must create a new symmetric customer managed key with `--rotation-period-in-days 90` in the `create-key` CLI call and then associate it with the trail using `update-trail --kms-key-id <new-key-arn>`. After updating, CloudTrail will use the new key to encrypt future log files, and the new key's key policy must include CloudTrail's account and the required `kms:GenerateDataKey` and `kms:Decrypt` permissions. Existing log files remain encrypted under the old key, so that key should still be available for decryption.

Why this answer

The requirement is to encrypt log files with a KMS key that rotates every 90 days. The current key rotates every 365 days, and you cannot change the rotation period of an existing customer managed key; you must create a new key with the desired rotation period. Once created, you update the CloudTrail trail to use the new key by specifying the --kms-key-id parameter.

Option D correctly describes this process. Option A is wrong because you cannot change the rotation period of an existing key. Option B is wrong because manually rotating a key does not meet the automatic rotation requirement and is not recommended.

Option C is wrong because you cannot modify the rotation period of an existing key.

Page 1 of 3 · 203 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.