Courseiva

CCNA Security and Compliance Questions

75 of 203 questions · Page 2/3 · Security and Compliance · Answers revealed

76
MCQeasy

A company wants to securely store database credentials used by an application running on Amazon EC2. The credentials should be automatically rotated every 90 days. Which AWS service should be used?

A.AWS IAM
B.AWS KMS
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is purpose-built for storing secrets like database credentials and natively supports automatic rotation through an integrated Lambda rotation function. It manages secret versions with AWSCURRENT and AWSPREVIOUS labels, allowing applications to reliably fetch rotated credentials without downtime. It also provides fine-grained access via IAM and resource policies, making it the correct service when the requirement is both secure storage and automatic rotation of database credentials.

Why this answer

AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, and it provides built-in automatic rotation every 90 days (or custom intervals) using Lambda functions. It integrates natively with Amazon RDS, Redshift, and DocumentDB for rotation. IAM and KMS do not store secrets, and Parameter Store does not offer automatic rotation natively.

Exam trap

The trap is confusing Parameter Store with Secrets Manager; candidates may think Parameter Store can rotate secrets automatically, but it does not—rotation is a key differentiator of Secrets Manager.

How to eliminate wrong answers

Option A is wrong because AWS IAM is for identity and access management, not for storing database credentials. Option B is wrong because AWS KMS is a key management service for encryption keys, not for storing secrets. Option C is wrong because AWS Systems Manager Parameter Store can store secrets, but it does not provide automatic rotation; rotation must be implemented manually or via custom automation.

77
MCQhard

A company requires that all secrets (e.g., database passwords) used by Lambda functions be rotated automatically every 30 days. Which combination of services should be used?

A.AWS CloudHSM and AWS Lambda
B.AWS Secrets Manager and AWS Lambda
C.AWS Systems Manager Parameter Store and AWS Lambda
D.AWS KMS and AWS Lambda
AnswerB

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating database credentials and other sensitive secrets, including integration with Amazon RDS, Redshift, and DocumentDB. The rotation feature uses an AWS Lambda function to update credentials on a schedule, ensuring that database passwords are cycled without manual intervention. Lambda can also retrieve secrets at runtime via the AWS SDK using IAM permissions, making it the correct and most appropriate pairing for the company's requirement.

Why this answer

AWS Secrets Manager is the correct choice because it natively supports automatic secret rotation on a configurable schedule (e.g., every 30 days) using a Lambda function as the rotation handler. Secrets Manager directly integrates with Lambda to invoke the rotation logic, updating the secret value and propagating the change to the target database or service without custom infrastructure. CloudHSM, Parameter Store, and KMS do not provide built-in, scheduled rotation of secrets with automatic Lambda invocation.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with AWS Secrets Manager (which is purpose-built for rotation), or they assume KMS or CloudHSM can manage secrets directly when they only handle encryption keys.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM is a hardware security module for key generation and cryptographic operations, not a service for storing or rotating secrets like database passwords; it lacks any built-in rotation scheduling or Lambda integration for secret rotation. Option C is wrong because AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation; any rotation would require custom orchestration and polling, whereas Secrets Manager provides managed rotation with a single API call. Option D is wrong because AWS KMS is a key management service for encryption keys, not a secret store; it cannot store or rotate secrets like database passwords, and while it can encrypt secrets stored elsewhere, it does not provide rotation logic.

78
Multi-Selecteasy

A company wants to enable AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team requires that logs be encrypted at rest and that any unauthorized deletion of log files be prevented. Which TWO actions should the security team take? (Choose TWO.)

Select 2 answers
A.Create a trail in the management account that applies to all accounts in the organization.
B.Enable default encryption with SSE-S3 on the S3 bucket where CloudTrail delivers logs.
C.Configure CloudTrail to send logs to Amazon CloudWatch Logs and enable encryption using an AWS KMS key.
D.Enable S3 Object Lock on the destination S3 bucket to prevent log file deletion.
E.Enable CloudTrail Insights to detect unusual API activity.
AnswersA, D

By creating an organization trail in the management account (using AWS Organizations), CloudTrail automatically logs API activity for all member accounts, including the management account itself, without needing to configure trails in each account. This centralizes governance and ensures the requirement of logging all API calls across the entire AWS environment is met, as organization trails deliver log files for every account to a single S3 bucket.

Why this answer

Enabling CloudTrail for all accounts in the organization ensures centralized logging. Option D is correct because S3 Object Lock prevents deletion of log files. Option B is incorrect because KMS with a customer managed key provides encryption, but the key must be created beforehand, not just enabled.

Option C is incorrect because CloudWatch Logs encryption uses KMS, not S3 SSE. Option E is incorrect because CloudTrail can be configured to log management events by default, and this is not about data events.

79
MCQmedium

A company's security policy requires that all data stored in Amazon S3 must be encrypted at rest using server-side encryption with customer-managed keys (SSE-KMS). When uploading an object via the AWS CLI, which parameter must be included to enforce this?

A.--kms-key-id <key-id>
B.--sse AES256
C.--encryption aws:kms
D.--server-side-encryption aws:kms
AnswerD

This is the S3 CLI parameter that explicitly requests server-side encryption with AWS KMS (SSE-KMS). Setting the value to `aws:kms` instructs S3 to use a customer master key (CMK) for encrypting the object at rest. When combined with `--kms-key-id`, it allows specifying a particular KMS key, but the presence of `--server-side-encryption aws:kms` alone satisfies the encryption requirement.

Why this answer

The correct parameter to enforce server-side encryption with AWS KMS (SSE-KMS) when uploading an object via the AWS CLI is --server-side-encryption aws:kms, which corresponds to option D. Option A is incorrect because --kms-key-id only specifies the key ID but does not enable encryption by itself; it must be combined with --server-side-encryption aws:kms. Option B is incorrect because --sse AES256 is not a valid AWS CLI parameter; the correct parameter for SSE-S3 is --server-side-encryption AES256.

Option C is incorrect because --encryption is not a valid AWS CLI parameter for server-side encryption.

80
Multi-Selectmedium

A DevOps engineer is responsible for securing a containerized application running on Amazon ECS with the Fargate launch type. The application needs to access an Amazon RDS database and an Amazon S3 bucket. The security team requires that credentials are not hardcoded and that access is least privilege. Which two actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Store the database credentials in AWS Secrets Manager and grant the ECS task role permission to retrieve them.
B.Configure the ECS task definition to use environment variables for the database password.
C.Use AWS Systems Manager Parameter Store to store the database credentials as plaintext strings.
D.Create an IAM user with programmatic access and embed the access keys in the container image.
E.Attach an IAM role to the ECS task that grants access to the S3 bucket and Secrets Manager secret.
AnswersA, E

Secrets Manager securely stores and rotates credentials. By granting the ECS task role permission to retrieve the secret, the application can fetch credentials at runtime without hardcoding them. This aligns with least privilege and eliminates static credentials in code or environment variables.

Why this answer

The secure approach is to use an IAM task role for AWS service access and AWS Secrets Manager for database credentials. The task role provides temporary credentials for S3 and Secrets Manager, while Secrets Manager securely stores and can rotate the database password. This combination avoids hardcoded credentials and supports least privilege.

Exam trap

The trap here is thinking that environment variables or Parameter Store plaintext are acceptable for secrets, when they lack encryption and rotation, and that an IAM user with embedded keys is safe when it is actually a major security risk.

81
MCQeasy

A company wants to centrally manage and apply policies across multiple AWS accounts in an AWS Organization. Which service should be used to define and enforce compliance rules?

A.AWS Organizations Service Control Policies (SCPs)
B.AWS Config rules
C.AWS CloudTrail
D.IAM policies
AnswerA

SCPs centrally govern the maximum available permissions for every IAM principal in all accounts within an AWS Organizations hierarchy. They act as guardrails that filter which actions a principal or root user can perform, regardless of any IAM policies that grant broader access, enabling cross-account policy enforcement.

Why this answer

AWS Organizations Service Control Policies (SCPs) are the correct choice because they centrally manage permissions across all accounts in an AWS Organization by defining maximum allowable permissions. SCPs act as a guardrail, restricting what member accounts can do, even if IAM policies within those accounts grant broader access. This makes SCPs the ideal service for enforcing compliance rules at the organization level.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which detect non-compliance) with SCPs (which enforce compliance), leading them to choose Config instead of SCPs for policy enforcement.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations for compliance against desired states, but they do not enforce or prevent actions; they only detect and report non-compliance. Option C is wrong because AWS CloudTrail records API activity for auditing and governance, but it cannot define or enforce policies—it is a logging service. Option D is wrong because IAM policies are attached to users, groups, or roles within a single account and cannot centrally manage permissions across multiple accounts in an AWS Organization.

82
MCQmedium

A DevOps engineer is troubleshooting a failed CodeBuild project. The build fails with an error: 'Access Denied: Unable to put object to S3.' The build project has an S3 bucket as the artifact store. What should the engineer do to resolve this issue?

A.Add s3:PutObject permission to the CodeBuild service role for the artifact bucket.
B.Enable server-side encryption on the artifact bucket.
C.Enable CloudWatch Logs for the build project.
D.Add s3:GetObject permission to the CodeBuild service role for the source bucket.
AnswerA

The CodeBuild service role is an IAM role that grants the build project permission to call AWS APIs. When CodeBuild uploads build artifacts to an S3 bucket, it must have the s3:PutObject action allowed on that artifact bucket. The failure occurs at the upload step because the role currently lacks write access; adding s3:PutObject to the role's policy for the artifact bucket's ARN resolves the AccessDenied error.

Why this answer

The error 'Access Denied: Unable to put object to S3' indicates the CodeBuild service role lacks s3:PutObject permission on the artifact bucket. CodeBuild assumes this role to upload build artifacts, so the fix is to attach an IAM policy granting s3:PutObject (and typically s3:GetBucketLocation, s3:ListBucket) for the artifact bucket to the CodeBuild service role.

Exam trap

DOP-C02 often tests the distinction between source bucket permissions (GetObject) and artifact bucket permissions (PutObject) — candidates confuse the two and apply the wrong S3 action.

How to eliminate wrong answers

Option B is wrong because enabling server-side encryption on the bucket does not grant write permissions — encryption is orthogonal to authorization, and the error is explicitly an access-denied issue. Option C is wrong because enabling CloudWatch Logs only improves logging visibility; it does not fix the underlying permission gap. Option D is wrong because s3:GetObject on the source bucket is for reading source code, not for writing artifacts — the error is about putting objects to the artifact store, not getting source objects.

83
MCQeasy

A DevOps engineer needs to allow an AWS Lambda function to write logs to Amazon CloudWatch Logs. What should the engineer do?

A.Attach an IAM role to the Lambda function's instance profile.
B.Attach an IAM policy to the Lambda execution role that allows logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents.
C.Generate an access key for the Lambda function and configure the function to use it.
D.Create a resource-based policy on the CloudWatch Logs log group that allows the Lambda function to write.
AnswerB

The execution role is the IAM identity that the Lambda service assumes on the function's behalf, and you must attach an identity-based policy with logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these actions, CloudWatch Logs will reject the function's log writes, causing request failures and missing log streams. This is the standard, least-privilege pattern for granting Lambda access to CloudWatch Logs in the same account.

Why this answer

Lambda functions assume an IAM execution role, and permissions to write to CloudWatch Logs must be granted via an IAM policy attached to that role. The policy needs logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents to allow the function to create the log group (if absent), create a log stream, and put log events. This is the standard, least-privilege way to grant Lambda logging permissions.

Exam trap

DOP-C02 often tests the misconception that Lambda uses instance profiles like EC2, or that resource-based policies on log groups can grant write access — both are wrong; permissions must come from the execution role.

How to eliminate wrong answers

Option A is wrong because Lambda does not use EC2 instance profiles — instance profiles are an EC2 construct for attaching roles to instances, not functions. Option C is wrong because embedding long-term access keys in a Lambda function is an anti-pattern that violates AWS security best practices and rotation requirements. Option D is wrong because CloudWatch Logs log groups do not support resource-based policies that grant write access to Lambda; access must come from the caller's identity-based policy on the execution role.

84
MCQeasy

An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the native AWS service that records every API call made in your account, including the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements. It captures management events for control-plane operations across AWS services, and can also log data events for S3 object-level activity and Lambda function invocations. CloudTrail delivers these logs to an S3 bucket (and optionally CloudWatch Logs) for long-term storage and analysis, making it the correct service for auditing all AWS API calls.

Why this answer

AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls.

Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.

85
Multi-Selectmedium

A company uses AWS CodePipeline for CI/CD. The security team requires that all code changes be scanned for secrets before deployment. The pipeline consists of a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The security team wants to automatically scan for secrets and block the pipeline if any secrets are found. Which THREE actions should the team take? (Choose THREE.)

Select 3 answers
A.Add a scanning action in the deploy stage to scan after deployment.
B.Configure the build project to fail the build if the scanning tool returns a non-zero exit code.
C.Add a scanning action in the build stage using a custom action or a third-party action from AWS Marketplace.
D.Configure an S3 bucket policy to deny access if secrets are detected.
E.Grant the CodeBuild service role permissions to retrieve the scanning tool from an S3 bucket.
AnswersB, C, E

CodeBuild treats any command that returns a non-zero exit code as a failed build, which immediately stops the pipeline and prevents the artifact from being promoted to the deploy stage. When a secret-scanning tool detects an issue, it exits with a non-zero code; configuring the build project to treat that as fatal ensures the pipeline is blocked before deployment. This is often implemented in the buildspec by running the scanner as the final command or using build phases with explicit failure handling.

Why this answer

Option B is correct because CodeBuild treats a non-zero exit code from a build command as a build failure, which stops the pipeline before the deploy stage and thereby blocks deployment when secrets are detected. Option C is correct because the build stage is the appropriate place to run a secret-scanning tool, and CodePipeline supports invoking it either as a custom action or via a pre-built third-party action from AWS Marketplace integrated into the build stage. Option E is correct because CodeBuild needs its service role to have the necessary permissions (for example, s3:GetObject on the specific bucket/object) to download the scanning tool or its dependencies from Amazon S3 during the build.

Option A is not appropriate because scanning after deployment is too late—secrets would already be exposed in the deployed environment, and CodeDeploy does not natively support a scanning action that blocks based on findings. Option D is incorrect because an S3 bucket policy cannot detect secrets in code and is unrelated to blocking a CodePipeline deployment based on scan results.

Exam trap

DOP-C02 often tests the misconception that scanning can happen in the deploy stage or that S3 bucket policies can detect secrets — the correct pattern is to scan in the build stage and fail the build on detection.

86
MCQeasy

A DevOps engineer is designing a CI/CD pipeline that deploys code to an EC2 instance. The engineer needs to securely store and retrieve database credentials used by the application. Which AWS service should be used?

A.Amazon S3 with server-side encryption
B.AWS Systems Manager Parameter Store
C.AWS Secrets Manager
D.AWS Key Management Service (KMS)
AnswerC

AWS Secrets Manager stores database credentials encrypted and supports automatic rotation, so the pipeline retrieves them at deploy time via IAM-scoped API calls instead of embedding them in code or instance user data, meeting the secure storage and retrieval requirement.

Why this answer

AWS Secrets Manager is designed to securely store, retrieve, and rotate secrets such as database credentials. It provides fine-grained access control, encryption at rest, and automatic rotation, making it ideal for CI/CD pipelines that need to access database credentials securely.

Exam trap

DOP-C02 often tests the distinction between Secrets Manager and Parameter Store. Candidates might choose Parameter Store because it's cheaper, but the question emphasizes secure storage and retrieval of database credentials, where Secrets Manager's rotation and management features are key.

How to eliminate wrong answers

Option A is wrong because Amazon S3 with server-side encryption is for storing objects, not managing secrets; it lacks automatic rotation and fine-grained access policies for secrets. Option B is wrong because AWS Systems Manager Parameter Store can store secrets, but it does not provide automatic rotation and is less feature-rich for secret management compared to Secrets Manager. Option D is wrong because AWS KMS is a key management service for encryption keys, not for storing and retrieving application secrets like database credentials.

87
MCQmedium

A DevOps engineer manages a fleet of EC2 instances in a private subnet. The instances must access an Amazon S3 bucket to read configuration files. The security team requires that all traffic to S3 be encrypted in transit and that the EC2 instances do not use the public internet. The engineer has already created an S3 gateway endpoint and attached it to the VPC route table. Which additional step should the engineer take to meet these requirements?

A.Modify the S3 bucket policy to deny requests where aws:SecureTransport is false.
B.Configure the EC2 instances to use an S3 interface endpoint instead of the gateway endpoint.
C.Attach an IAM role to the EC2 instances that allows s3:GetObject on the bucket.
D.Enable default encryption on the S3 bucket using AES-256.
AnswerA

Adding a bucket policy that denies requests when aws:SecureTransport is false enforces HTTPS for all access to the bucket. Combined with the gateway endpoint, traffic stays within the AWS network and is encrypted in transit. This directly meets both the encryption and private connectivity requirements.

Why this answer

The gateway endpoint provides private network routing, but encryption in transit must be enforced separately. A bucket policy that denies requests when aws:SecureTransport is false ensures that only HTTPS requests are allowed, satisfying the encryption requirement. IAM roles handle authorization, interface endpoints are an alternative connectivity method, and default encryption addresses data at rest, not in transit.

Exam trap

The trap here is assuming that a VPC gateway endpoint automatically encrypts traffic to S3, when it only provides private routing and still allows unencrypted HTTP requests unless a bucket policy enforces secure transport.

88
Multi-Selectmedium

A company wants to audit all changes to IAM policies in their AWS account. Which THREE services can be used to capture and alert on IAM policy changes? (Choose THREE.)

Select 3 answers
A.AWS Config
B.AWS CloudTrail
C.AWS Trusted Advisor
D.Amazon EventBridge
E.Amazon Inspector
AnswersA, B, D

AWS Config records configuration items for AWS::IAM::Policy and related resources, building a configuration history that shows exactly how IAM policy documents changed over time. It evaluates those configurations against custom or managed rules to detect noncompliant policies. This provides a persistent, queryable state timeline, which is the definitive way to audit all IAM policy changes after the fact.

Why this answer

AWS Config is correct because it continuously records resource configuration changes, including IAM policy changes, and can evaluate them against rules or configuration snapshots to detect and audit modifications. AWS CloudTrail is correct because it logs all API activity in the account, including IAM policy creation, modification, and deletion events (e.g., CreatePolicy, PutRolePolicy, AttachRolePolicy), providing the authoritative audit trail. Amazon EventBridge is correct because it can receive CloudTrail management events and match IAM policy change events via event patterns, then route them to targets such as SNS or Lambda for alerting.

AWS Trusted Advisor is not correct because it provides best-practice checks and recommendations, not a change audit or alerting mechanism for IAM policies. Amazon Inspector is not correct because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions, and does not capture IAM policy changes.

Exam trap

DOP-C02 often tests service-role confusion — candidates pick Inspector or Trusted Advisor for 'audit/alert' questions because they sound security-related, but only Config, CloudTrail, and EventBridge actually capture and act on IAM change events.

89
MCQhard

A company runs a web application on EC2 behind an Application Load Balancer (ALB). They want to protect against SQL injection and cross-site scripting (XSS) attacks. Which AWS service should they use?

A.Configure security groups to allow only HTTP/HTTPS traffic.
B.Configure network ACLs to block common attack patterns based on IP ranges.
C.Deploy AWS WAF in front of the ALB and create rules to block SQL injection and XSS.
D.Enable AWS Shield Advanced to protect the ALB.
AnswerC

AWS WAF is an application-layer firewall that can be associated with an Application Load Balancer and inspects each HTTP/HTTPS request for suspicious patterns. You can create custom rules and use AWS-managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet to automatically block SQL injection, cross-site scripting, and other common web exploits. These rules evaluate request components like headers, query strings, body, and cookies, which is exactly what is needed to stop these attacks before they reach the EC2 instances.

Why this answer

AWS WAF is a web application firewall that integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests for common attack patterns. It provides managed rule sets specifically designed to block SQL injection and cross-site scripting (XSS) attacks at the application layer, which is exactly what this scenario requires.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups, NACLs) or DDoS protection (Shield) with application-layer filtering, failing to recognize that only a web application firewall like AWS WAF can inspect HTTP payloads for injection attacks.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer (Layer 3/4) and only filter traffic based on IP addresses, ports, and protocols; they cannot inspect application-layer payloads for SQL injection or XSS patterns. Option B is wrong because network ACLs are stateless packet filters that also operate at the network layer and cannot parse HTTP request bodies or query strings for malicious content; blocking IP ranges does not prevent application-layer attacks. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks at the network and transport layers, but it does not include the application-layer inspection capabilities needed to detect and block SQL injection or XSS.

90
Multi-Selecthard

Which THREE components are necessary to implement a secure VPC with a public subnet and a private subnet that hosts a database? (Choose THREE.)

Select 3 answers
A.AWS Site-to-Site VPN connection.
B.Internet Gateway attached to the VPC.
C.NAT Gateway in the public subnet.
D.VPC Peering connection to a central VPC.
E.Security group for the database allowing traffic only from the application tier.
AnswersB, C, E

An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that provides bidirectional communication between the VPC and the internet. It is attached to the VPC and serves as the target for the 0.0.0.0/0 route in public subnet route tables, enabling resources with public IPs to send and receive internet traffic. Additionally, the IGW is a prerequisite for a NAT Gateway, because the NAT Gateway itself resides in the public subnet and relies on the IGW for outbound internet forwarding. Without an IGW, neither public nor private instances could reach the internet.

Why this answer

Option B is correct because an Internet Gateway attached to the VPC is required to give the public subnet's resources (such as a bastion host or load balancer) inbound and outbound connectivity to the internet. Option C is correct because a NAT Gateway placed in the public subnet allows instances in the private subnet to initiate outbound traffic (for patching, updates, etc.) to the internet without being directly reachable from it. Option E is correct because a security group on the database that permits traffic only from the application tier enforces least-privilege, instance-level access control, which is essential for securing the database in the private subnet.

Option A is not required because a Site-to-Site VPN is for connecting on-premises networks to AWS, not for building public/private subnet architecture. Option D is not required because VPC peering connects separate VPCs and is unrelated to creating public and private subnets within a single VPC.

Exam trap

DOP-C02 often tests whether candidates include unnecessary components like VPN or peering, when the core requirements are IGW, NAT Gateway, and security group scoping.

91
MCQeasy

A company wants to ensure that all S3 buckets are encrypted at rest by default. Which S3 feature should be enabled at the bucket level to automatically encrypt new objects?

A.S3 Object Lock
B.Bucket policy with a Deny for unencrypted uploads
C.S3 Versioning
D.Default encryption
AnswerD

Default encryption is a bucket-level setting that automatically applies server-side encryption (SSE-S3 or SSE-KMS) to all new objects, even when the upload request does not include encryption headers. When enabled, every PUT that does not explicitly specify an encryption method is wrapped with the bucket's configured encryption, thereby ensuring new objects are encrypted at rest. Note that default encryption only affects objects uploaded after the setting is enabled; existing objects require rewriting or a copy operation to be encrypted. It is the only option that actively encrypts data without relying on client behavior.

Why this answer

S3 default encryption allows you to set a default encryption behavior for a bucket, so that all new objects are encrypted at rest automatically. Bucket policies can enforce encryption but do not automatically encrypt. Object lock is for retention.

Versioning is for object versions.

92
MCQmedium

A company uses AWS Secrets Manager to store database credentials. The security team requires that secrets be automatically rotated every 30 days. Which rotation strategy should the engineer configure to meet this requirement with minimal operational overhead?

A.Manually rotate the secret every 30 days using the AWS CLI.
B.Store the secret in AWS Systems Manager Parameter Store with a SecureString parameter.
C.Enable automatic rotation using the pre-built Lambda rotation function for the database type.
D.Enable automatic rotation with a custom Lambda function.
AnswerC

Secrets Manager's pre-built Lambda rotation function (e.g., for Amazon RDS MySQL, PostgreSQL, Oracle, or SQL Server) is the correct choice because it provides a fully managed, automated rotation pattern that requires minimal configuration. When you enable rotation, Secrets Manager executes the Lambda on a configurable schedule (e.g., every 30 days), and the function updates the database password and the stored secret atomically using the Secrets Manager rotation sequence (createSecret, setSecret, testSecret, finishSecret). This ensures the secret and the database remain in sync with no temporary breakage and no custom code to write or maintain.

Why this answer

AWS Secrets Manager supports automatic rotation using pre-built Lambda rotation functions tailored to specific database types (e.g., Amazon RDS MySQL, PostgreSQL, Aurora). Enabling this built-in rotation with a 30-day schedule meets the requirement with minimal operational overhead because AWS manages the Lambda function, rotation logic, and secret update. This is the standard, lowest-effort approach for database credential rotation.

Exam trap

DOP-C02 often tests the trade-off between pre-built and custom rotation — candidates may over-engineer by choosing a custom Lambda when the pre-built function already supports the database type with minimal overhead.

How to eliminate wrong answers

Option A is wrong because manual rotation via CLI is error-prone, does not scale, and introduces significant operational overhead — the opposite of the requirement. Option B is wrong because Systems Manager Parameter Store with SecureString does not natively support automatic rotation of database credentials; it stores parameters but lacks built-in rotation for RDS-style secrets. Option D is wrong because a custom Lambda function requires the engineer to write, test, and maintain rotation logic, increasing operational overhead compared to the pre-built function.

93
Multi-Selecthard

A DevOps team needs to enforce that all S3 buckets in an AWS account are encrypted at rest. Which THREE steps should be taken to achieve this? (Choose THREE.)

Select 3 answers
A.Configure AWS Config rules to detect buckets without encryption
B.Use an S3 bucket policy to deny PutObject requests that do not include encryption headers
C.Enable S3 server access logging
D.Enable default encryption on each S3 bucket
E.Enable S3 Transfer Acceleration
AnswersA, B, D

AWS Config's managed rule s3-bucket-server-side-encryption-enabled detects buckets where default encryption is disabled and continuously evaluates the account's infrastructure. When a noncompliant bucket is found, Config can trigger a remediation action, such as an AutoRemediate SSM document that enables default encryption, turning detection into corrective enforcement. This is a control-plane enforcement of encryption at the bucket level, rather than preventing unencrypted object writes.

Why this answer

Option A is correct because AWS Config managed rules such as s3-bucket-server-side-encryption-enabled continuously evaluate buckets and flag any that lack default encryption, giving the team the detection and compliance visibility needed to enforce encryption at rest. Option B is correct because an S3 bucket policy with a Deny effect on s3:PutObject when the request lacks the s3:x-amz-server-side-encryption condition (or aws:SecureTransport-style encryption conditions) blocks unencrypted uploads, actively enforcing encryption for objects written to the bucket. Option D is correct because enabling default encryption (SSE-S3/AES-256 or SSE-KMS) on each bucket ensures all objects are encrypted at rest automatically, even if clients do not specify encryption headers.

Option C is not correct because S3 server access logging only records request details for auditing; it does not detect or enforce encryption. Option E is not correct because S3 Transfer Acceleration only speeds up uploads over long distances using edge locations and has no bearing on encryption at rest.

Exam trap

The trap is selecting tangential S3 features (access logging, Transfer Acceleration) that sound security- or performance-related but do not enforce or detect encryption at rest.

94
Multi-Selectmedium

A company needs to audit all changes to IAM policies in their AWS account. Which services can be used to track and log these changes? (Select TWO.)

Select 2 answers
A.Amazon S3
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersC, D

AWS Config is purpose-built for recording and evaluating configuration changes to AWS resources, including IAM policies. It continuously records the configuration state of IAM users, roles, groups, and their attached or inline policies, and maintains a configuration history with a timeline for each resource. You can query the configuration timeline to see what the policy document looked like before and after each change, making it the ideal service for auditing all changes to IAM policies.

Why this answer

AWS CloudTrail logs API calls, including IAM policy changes. AWS Config can track configuration changes to IAM resources. CloudWatch Logs stores logs but does not track changes itself.

GuardDuty is for threat detection. S3 is storage.

95
MCQhard

A company needs to enforce that all EC2 instances launched in an AWS account use a specific Amazon Machine Image (AMI) that is approved by the security team. Which combination of services should be used?

A.AWS Organizations SCP and AWS CloudTrail
B.AWS Config rule to check AMI ID and AWS Systems Manager Automation to remediate non-compliant instances
C.AWS Lambda and Amazon SNS
D.AWS CloudTrail and Amazon CloudWatch Events
AnswerB

AWS Config evaluates launched instances against a managed rule such as approved-ami-by-id, which checks whether the instance’s AMI ID is in an allowed list. When an instance is non-compliant, Config can automatically invoke an AWS Systems Manager Automation document (for example, to stop or terminate the instance), providing a self-healing enforcement loop. This is the recommended pattern for reactive enforcement where the desired AMI cannot be blocked at the API level by IAM or SCP policies.

Why this answer

AWS Config can evaluate whether EC2 instances use the approved AMI ID by creating a custom rule or using a managed rule, and AWS Systems Manager Automation can automatically remediate non-compliant instances (e.g., stop, terminate, or notify). This combination enforces the policy and provides automated remediation, which is the most effective way to ensure compliance.

Exam trap

DOP-C02 often tests the misconception that SCPs can enforce resource properties like AMI IDs, but SCPs only control API permissions, not resource configurations.

How to eliminate wrong answers

Option A is wrong because AWS Organizations SCPs cannot enforce AMI IDs; SCPs control API actions, not resource properties, and CloudTrail only logs API calls without enforcement. Option C is wrong because AWS Lambda and Amazon SNS can be used for custom enforcement but require significant custom code and do not provide built-in compliance evaluation; they are not a complete solution. Option D is wrong because CloudTrail and CloudWatch Events can detect and react to EC2 launches but do not enforce AMI usage; they are event-driven and reactive, not preventive or detective with remediation.

96
MCQeasy

A company needs to ensure that all API calls made to AWS are encrypted in transit. Which of the following is the correct way to enforce this?

A.Use an IAM policy with a condition that denies access unless the request uses HTTPS.
B.Configure security groups to allow only HTTPS traffic.
C.Use AWS Key Management Service (KMS) to create a key and require encryption.
D.Enable AWS CloudTrail to log all API calls.
AnswerA

An IAM policy is evaluated for every AWS API request, and the global condition key `aws:SecureTransport` returns `false` when the request was not sent over TLS/HTTPS. By attaching a policy that explicitly denies access when `aws:SecureTransport` is `false`, you enforce that all API calls must use HTTPS at the authorization layer. This is the correct, service-agnostic mechanism because IAM conditions apply uniformly to any supported AWS service, making it impossible to bypass via a non-HTTPS client.

Why this answer

All AWS API endpoints support HTTPS (TLS) by default. To enforce that all API calls are encrypted in transit, you can use an IAM policy with a condition that denies access unless the request uses HTTPS. Specifically, you can use the `aws:SecureTransport` condition key to require encrypted connections.

Option A is correct. Option B is incorrect because security groups control network traffic at the instance level but do not enforce encryption for API calls. Option C is incorrect because AWS KMS is used for managing encryption keys, not for enforcing HTTPS.

Option D is incorrect because AWS CloudTrail logs API activity but does not enforce encryption.

97
MCQeasy

A company has a security policy requiring that all IAM users use multi-factor authentication (MFA) to access the AWS Management Console. The DevOps engineer needs to enforce this policy. What is the simplest way to achieve this?

A.Use Amazon Cognito to require MFA for console access.
B.Create an IAM policy that denies all actions unless MFA is present, and attach it to all IAM users or groups.
C.Enable MFA delete on the root account.
D.Enable MFA on the S3 bucket policy.
AnswerB

Create an IAM policy that uses the 'aws:MultiFactorAuthPresent' condition key to deny actions when MFA is not present, for example: 'Condition': {'Bool': {'aws:MultiFactorAuthPresent': 'false'}}. Attach this policy to all IAM users or groups so that any API call made without MFA is rejected, while requests made with MFA succeed. This enforces MFA globally across all AWS services for the attached identities. Be sure to grant users permission to manage their own MFA devices beforehand to avoid lockout.

Why this answer

The simplest enforcement is an IAM policy that denies all actions unless the request is made with MFA, attached to users or groups. This uses the aws:MultiFactorAuthPresent condition key in a Deny statement, which blocks console and API access for users who have not authenticated with MFA. It is a native IAM mechanism requiring no additional services.

Exam trap

DOP-C02 often tests the difference between IAM policy conditions and service-specific features, tricking candidates into picking Cognito or S3 MFA Delete when the question is about IAM user console MFA enforcement.

How to eliminate wrong answers

Option A is wrong because Amazon Cognito is an identity service for customer-facing applications, not for enforcing MFA on IAM user console access. Option C is wrong because MFA Delete on the root account is an S3 bucket-level feature that protects object versions from deletion, not a console access control. Option D is wrong because S3 bucket policies govern access to S3 resources, not IAM user console authentication, and cannot enforce MFA at the console login level.

98
Multi-Selectmedium

A DevOps engineer is designing a secure CI/CD pipeline. Which TWO of the following are best practices for securing secrets in the pipeline?

Select 2 answers
A.Use encrypted environment variables in CodeBuild.
B.Store secrets in a parameter file in the source repository.
C.Hardcode secrets in CloudFormation template parameters.
D.Use S3 bucket policies to restrict access to secret files.
E.Store secrets in AWS Secrets Manager and retrieve them during the build.
AnswersA, E

CodeBuild allows you to define environment variables that are encrypted at rest with a customer-managed or AWS-managed KMS key and are never stored in buildspec or source control. These values are decrypted automatically in the build container at runtime, so the build commands can use them without exposing plaintext in the pipeline artifacts. Because CodeBuild also supports referencing Systems Manager Parameter Store or Secrets Manager values as environment variables, this approach centralizes secret access while retaining per-environment changes.

Why this answer

Options A and E are correct. Option A: CodeBuild allows environment variables to be encrypted using AWS KMS, which is a secure way to handle secrets in the pipeline. Option E: AWS Secrets Manager is a dedicated service for securely storing and retrieving secrets, and integrating it with the pipeline ensures secrets are not exposed.

Option B is incorrect because storing secrets in a parameter file in the source repository exposes them to anyone with repository access, violating security best practices. Option C is incorrect because hardcoding secrets in CloudFormation template parameters can lead to exposure in logs or template outputs, and is not secure. Option D is incorrect because while S3 bucket policies can restrict access, they do not encrypt the secrets themselves, and S3 is not designed for managing secrets; AWS Secrets Manager or Parameter Store are better choices.

99
Multi-Selecteasy

A company is using AWS KMS to encrypt data. Which TWO statements about AWS KMS key rotation are correct? (Choose TWO.)

Select 2 answers
A.Customer managed keys can be configured for automatic rotation
B.Keys imported into KMS support automatic rotation
C.Automatic rotation is enabled by default for customer managed keys
D.Automatic rotation can be disabled for AWS managed keys
E.AWS managed keys are automatically rotated every year
AnswersA, E

Customer managed keys can be configured for automatic rotation. Enabling this setting causes AWS KMS to automatically generate new key material for the CMK every 365 days, while retaining the previous material for decryption of existing ciphertext. You must explicitly opt in to this feature; it is not the default behavior.

Why this answer

Option A is correct because AWS KMS allows you to enable automatic rotation on customer managed keys, rotating the backing key material every year (365 days) while keeping the same key ID and ARN. Option E is correct because AWS managed keys are automatically rotated every year by AWS, with no configuration required or possible on the customer's part. Option B is incorrect because imported key material (keys with origin EXTERNAL) cannot be automatically rotated by KMS; you must manually rotate by re-importing new material.

Option C is incorrect because automatic rotation is opt-in for customer managed keys and is not enabled by default. Option D is incorrect because you cannot enable or disable rotation for AWS managed keys; AWS controls their rotation lifecycle entirely.

Exam trap

DOP-C02 often tests the distinction between customer managed keys (rotation configurable, off by default) and AWS managed keys (rotation mandatory every year, not configurable) — candidates frequently assume all KMS keys behave identically or that imported keys can auto-rotate.

100
Multi-Selecthard

Which THREE services can be used to protect a VPC from malicious traffic? (Choose 3.)

Select 3 answers
A.Network ACLs
B.Security Groups
C.AWS Shield
D.Amazon Route 53 Resolver
E.AWS Network Firewall
AnswersA, B, E

Network ACLs are a stateless firewall layer operating at the subnet boundary, inspecting traffic entering and leaving each subnet. Rules are evaluated in numeric order, and because they are stateless, you must explicitly allow both inbound and outbound traffic, including return traffic. By default, a custom Network ACL denies all traffic until you add allow rules, while the default NACL permits all traffic. This makes NACLs ideal for subnet-level deny lists and for enforcing broad boundaries, but they lack the stateful awareness of security groups.

Why this answer

Network ACLs (NACLs) are stateless, subnet-level firewalls that filter traffic based on rules evaluating source/destination IP, protocol, and port. They provide an additional layer of defense by explicitly allowing or denying inbound and outbound traffic at the subnet boundary, making them a correct choice for protecting a VPC from malicious traffic.

Exam trap

The trap here is that candidates often confuse AWS Shield (a DDoS protection service) with a VPC-level firewall, not realizing it operates at the edge/global layer and does not filter traffic within the VPC itself.

101
MCQhard

An organization wants to enforce that all Amazon S3 buckets are encrypted with SSE-S3. Which AWS service can be used to automatically remediate non-compliant buckets?

A.AWS CloudTrail
B.AWS Config rules with auto-remediation
C.IAM policies
D.AWS Service Catalog
AnswerB

AWS Config rules with auto-remediation are the correct choice because they provide continuous monitoring and automated correction. A managed rule like s3-bucket-server-side-encryption-enabled detects non-compliant buckets, and the associated remediation action (via SSM Automation or a custom Lambda) automatically applies SSE-S3 default encryption to the bucket. This is the only option that both detects existing non-compliant buckets and actively modifies their configuration to become compliant, satisfying the organization's requirement in real time.

Why this answer

AWS Config rules can evaluate whether S3 buckets have SSE-S3 encryption enabled and trigger automatic remediation actions via SSM Automation documents. This provides continuous compliance monitoring and enforcement without manual intervention, directly addressing the requirement to automatically remediate non-compliant buckets.

Exam trap

The trap is assuming that IAM policies or CloudTrail can enforce encryption, when only AWS Config provides the evaluation and auto-remediation capability for resource compliance.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail only records API activity and does not evaluate resource compliance or perform remediation. Option C is wrong because IAM policies control access permissions but cannot enforce encryption settings on S3 buckets or automatically remediate misconfigurations. Option D is wrong because AWS Service Catalog is used to create and manage approved IT service catalogs for provisioning, not for compliance monitoring or remediation of existing resources.

102
MCQhard

A company's security policy requires that all data in transit between on-premises and AWS is encrypted. Which AWS service provides a dedicated network connection with encryption?

A.AWS Transit Gateway
B.AWS Direct Connect + VPN
C.Amazon VPC peering
D.AWS Site-to-Site VPN over the internet
AnswerB

This pattern combines an AWS Direct Connect private or public virtual interface with an IPSec Site-to-Site VPN to create a dedicated, private, and encrypted link from your data center to AWS. Direct Connect ensures a consistent, low-latency connection that does not traverse the public internet, while the VPN overlay encrypts all IP traffic between your edge and the AWS virtual private gateway. The combination satisfies both the encryption mandate and the need for predictable, dedicated bandwidth, making it the best choice for this scenario.

Why this answer

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, and when combined with a VPN over that connection, it adds IPsec encryption. This satisfies the requirement for a dedicated connection with encryption. Direct Connect alone is not encrypted, so the VPN overlay is necessary.

Exam trap

DOP-C02 often tests the misconception that Direct Connect is encrypted by default; candidates must remember that encryption requires an additional VPN overlay.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks, but it does not provide a dedicated connection or encryption by itself. Option C is wrong because VPC peering connects VPCs within AWS, not on-premises to AWS, and it does not provide encryption. Option D is wrong because a Site-to-Site VPN over the internet is encrypted but does not provide a dedicated network connection; it uses the public internet.

103
Multi-Selectmedium

A company wants to implement a least-privilege security model for its IAM users. Which TWO practices should be applied?

Select 2 answers
A.Use IAM policy conditions to restrict access based on IP address or time of day.
B.Use only resource-based policies to manage permissions.
C.Attach the AdministratorAccess managed policy to all IAM users.
D.Use the AWS account root user for daily administrative tasks.
E.Grant permissions based on the specific actions and resources needed.
AnswersA, E

IAM policy conditions using the Condition element enable you to scope permissions by context keys such as aws:SourceIp or aws:CurrentTime. This allows you to enforce geofencing or business-hours-only access, reducing the blast radius of stolen credentials. For example, a Deny statement with a condition can block all access outside a corporate CIDR range.

Why this answer

IAM policy conditions allow you to restrict access based on attributes like IP address (using the `aws:SourceIp` condition key) or time of day (using `aws:CurrentTime`). This enforces least-privilege by limiting when and from where actions can be performed, reducing the attack surface without over-provisioning permissions.

Exam trap

The trap here is that candidates may think resource-based policies alone are sufficient for least-privilege (Option B), or that broad managed policies like AdministratorAccess can be justified for convenience, but the exam emphasizes that least-privilege requires granting only the specific actions and resources needed (Option E) combined with contextual restrictions (Option A).

104
MCQeasy

A DevOps engineer needs to ensure that all API calls made to AWS services are logged for auditing purposes. Which AWS service should be enabled?

A.AWS CloudTrail
B.AWS Config
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the purpose-built service that records every API call made in your AWS account as an event, including the identity of the caller, the source IP address, the requested action, and the response returned. It supports management events, data events, and CloudTrail Insights events, and it can deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for retention and analysis. As the only option that natively records API activity, CloudTrail is the correct choice for auditing all API calls.

Why this answer

AWS CloudTrail (option A) is the correct service because it records API calls made to AWS services for auditing, governance, and compliance. Option B (AWS Config) is used to evaluate resource configurations against desired policies, not to record API calls. Option C (VPC Flow Logs) captures network traffic information at the VPC level.

Option D (Amazon CloudWatch Logs) is a service for storing and monitoring log files from various sources, but does not itself record API calls.

105
MCQeasy

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?

A.AWS Shield Advanced
B.Amazon GuardDuty
C.AWS Network Firewall
D.AWS WAF
AnswerD

AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to inspect and filter HTTP(S) requests before they are forwarded to your EC2 instances. It provides managed rules specifically designed to detect and block common web exploits, including SQL injection and cross-site scripting, and you can define custom rules to handle unique business logic. This is the appropriate service to stop malicious requests from ever reaching the web server, directly addressing the requirement for protection against web exploits.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It allows you to create rules that filter and monitor HTTP(S) requests based on conditions such as IP addresses, HTTP headers, URI strings, and SQL injection or cross-site scripting patterns. By integrating with an Application Load Balancer, AWS WAF can inspect incoming traffic and block malicious requests before they reach the EC2 instances.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Shield or GuardDuty, mistakenly thinking that DDoS protection or general threat detection covers application-layer attacks like SQL injection and XSS, when in fact only a web application firewall (WAF) can inspect and filter HTTP request payloads at Layer 7.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced provides protection against Distributed Denial of Service (DDoS) attacks, not against application-layer exploits like SQL injection or XSS. Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not inspect or filter HTTP request payloads for web exploits. Option C is wrong because AWS Network Firewall is a managed firewall service that filters traffic at the network and transport layers (Layer 3/4) using stateful inspection and intrusion prevention, but it does not provide application-layer (Layer 7) inspection for SQL injection or XSS patterns.

106
MCQhard

A company is using AWS CloudFormation to deploy infrastructure. They need to ensure that all resources created by CloudFormation are tagged with a 'CostCenter' tag. The tag must be applied automatically to all resources in the stack. What should they do?

A.Use AWS Service Catalog to enforce tagging on all products.
B.Create an AWS Config rule to detect untagged resources and trigger auto-remediation.
C.Specify the tag in the CloudFormation stack's Tags parameter, which applies the tag to all resources in the stack.
D.Use a custom Lambda function as a CloudFormation hook to tag resources after creation.
AnswerC

When you specify a tag in the Tags parameter of the AWS CloudFormation stack, CloudFormation automatically applies that tag to every resource in the stack that supports tagging during stack creation and update operations. This is a native cloudformation capability that propagates the tag at launch time, ensuring the CostCenter tag is consistently applied without custom code or post-creation processing. Resources that do not support tagging are the only exceptions, but the tag is applied to all taggable resources as part of the stack lifecycle.

Why this answer

CloudFormation allows you to specify stack-level tags in the Tags parameter when creating or updating a stack. These tags are automatically propagated to all resources that support tagging within the stack, ensuring consistent cost allocation without additional custom logic or post-creation remediation.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing a reactive or custom approach (like AWS Config rules or Lambda hooks) when CloudFormation provides a built-in, declarative mechanism to apply tags automatically at stack creation time.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog is a service for creating and managing a catalog of approved products, not for enforcing tags on CloudFormation stacks directly; it can apply tags to provisioned products but does not automatically tag all resources within a stack. Option B is wrong because AWS Config rules are reactive—they detect non-compliant resources after creation and can trigger auto-remediation, but they do not prevent the initial creation of untagged resources and add latency and complexity. Option D is wrong because using a custom Lambda function as a CloudFormation hook to tag resources after creation is an unnecessary workaround; CloudFormation natively supports stack-level tags that are applied at creation time, making a custom hook redundant and less efficient.

107
Multi-Selectmedium

A company uses AWS Organizations to manage multiple accounts. The Security team wants to prevent member accounts from disabling AWS CloudTrail or deleting CloudTrail log files. Which TWO actions should the Security team take in the organization's management account? (Choose TWO.)

Select 2 answers
A.Create an SCP to deny cloudtrail:UpdateTrail.
B.Create an IAM policy in each member account to deny cloudtrail:StopLogging.
C.Create an SCP to deny s3:DeleteObject on the CloudTrail log bucket.
D.Enable AWS CloudTrail from the management account with organization trail.
E.Create an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswersC, E

Denying s3:DeleteObject via an SCP on the CloudTrail log bucket is correct because it directly protects the integrity of historical audit logs. Even if a user in a member account has IAM permissions to call cloudtrail:StopLogging or cloudtrail:DeleteTrail, they cannot destroy the existing evidence stored in S3, and the trail will continue to deliver new logs as long as it is active. This is a critical safeguard because attackers often attempt to delete logs to hide their activity, and SCPs provide a central, unchangeable control across all member accounts.

Why this answer

An SCP that denies s3:DeleteObject on the CloudTrail log bucket prevents member accounts from deleting log files stored in S3, even if they have full administrative permissions. This is a critical control to ensure log integrity and compliance with security policies.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM policies in member accounts can enforce controls, or they overlook that denying UpdateTrail is insufficient because StopLogging and DeleteTrail are separate actions that must also be blocked.

108
MCQmedium

A company uses Amazon Inspector to assess the security of EC2 instances. The security team receives an alert that a high-severity vulnerability (CVE-2023-XXXX) was found on an EC2 instance running a critical application. The application is behind an Application Load Balancer (ALB) and uses an Auto Scaling group. The vulnerability has a known patch, but patching requires a reboot. The security team needs to remediate the vulnerability with minimal downtime. Which approach should the team take?

A.Create a new launch template with an updated AMI that includes the patch. Update the Auto Scaling group to use the new launch template and perform a rolling update.
B.Remove the instance from the Auto Scaling group, disable health checks on the ALB, and apply the patch manually.
C.Use AWS Systems Manager Patch Manager to apply the patch on the instance without rebooting, then verify the vulnerability is resolved.
D.Stop the vulnerable instance, apply the patch, and start it again. Re-register it with the ALB.
AnswerA

Creating a new launch template with a fully patched AMI and updating the Auto Scaling group to use it enables an instance refresh, which performs a rolling replacement of all current instances without downtime. This immutable infrastructure pattern guarantees that every launched instance is patched from the start, eliminating any configuration drift. An instance refresh gradually replaces instances while respecting the ASG's health check and minimum capacity, so application availability is maintained throughout the process.

Why this answer

The correct approach is to bake the patch into a new AMI, create a new launch template, and perform a rolling update of the Auto Scaling group. This uses the immutable infrastructure pattern: new instances come up already patched, the ALB drains connections from old instances as they are replaced, and the rolling update maintains capacity throughout — achieving minimal downtime without manual intervention. It also ensures the fix persists across future scaling events and instance replacements.

Exam trap

DOP-C02 often tests whether candidates choose manual in-place patching (which causes downtime and drift) over immutable infrastructure with rolling updates — the trap is picking the option that sounds fastest but violates the ASG lifecycle and minimal-downtime requirement.

How to eliminate wrong answers

Option B is wrong because removing an instance from the ASG and disabling ALB health checks causes the instance to be replaced by the ASG (since it is no longer managed) and creates a window where the ALB cannot route traffic correctly — plus manual patching does not scale and leaves other instances vulnerable. Option C is wrong because the question states the patch requires a reboot, so Patch Manager cannot apply it without rebooting; even if it could, patching in place does not survive instance replacement and is not the minimal-downtime approach for an ASG. Option D is wrong because stopping an instance in an ASG triggers the ASG to replace it (or leaves it unhealthy), and re-registering with the ALB manually is error-prone and causes downtime for that instance.

109
MCQmedium

A DevOps engineer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a critical application. Which security practice should the engineer implement to prevent unauthorized changes to the pipeline?

A.Encrypt the pipeline artifacts using AWS KMS
B.Use SNS to send notifications when the pipeline is updated
C.Attach an IAM policy that uses a condition to allow only specific users or roles to modify the pipeline
D.Enable AWS CloudTrail and create a CloudWatch Events rule to notify on pipeline changes
AnswerC

Attaching an IAM policy that uses a condition such as aws:PrincipalArn to the CodePipeline administrative actions (for example, UpdatePipeline and CreatePipeline) is the correct preventive control. This restricts the set of principals who can modify the pipeline definition no matter how the request is made, and it can be combined with resource-level permissions and least-privilege scoping. It directly addresses unauthorized pipeline modifications at the authorization layer.

Why this answer

The most direct preventive control is an IAM policy with a condition that restricts who can call CodePipeline mutation APIs (UpdatePipeline, DeletePipeline, PutApprovalResult, etc.). By scoping permissions to specific users or roles via IAM conditions (e.g., aws:PrincipalArn, aws:SourceVpce), the engineer enforces least privilege and blocks unauthorized modifications at the API layer.

Exam trap

DOP-C02 often tests the difference between preventive controls (IAM policies, SCPs) and detective controls (CloudTrail, SNS, CloudWatch) — candidates frequently pick logging/notification answers when the question asks how to prevent unauthorized changes.

How to eliminate wrong answers

Option A is wrong because KMS encryption protects artifacts at rest but does nothing to prevent an authorized principal from modifying the pipeline definition — encryption is a confidentiality control, not an authorization control. Option B is wrong because SNS notifications are detective, not preventive — they alert after a change has already occurred. Option D is wrong because CloudTrail plus CloudWatch Events is also detective; it logs and notifies about pipeline changes but does not block them.

Only IAM policy conditions provide the preventive authorization control the question asks for.

110
Multi-Selecteasy

Which TWO AWS services can be used to centrally manage and enforce security policies across multiple accounts? (Choose 2.)

Select 2 answers
A.Amazon S3
B.Amazon CloudWatch
C.AWS Organizations
D.AWS Control Tower
E.AWS Lambda
AnswersC, D

AWS Organizations provides central management of multiple AWS accounts through hierarchical grouping into organizational units (OUs). It enables the creation and enforcement of service control policies (SCPs), which act as guardrails to restrict the maximum permissions of IAM roles and users across member accounts. SCPs can be attached to the root, OUs, or individual accounts, giving centralized, policy-based control over an entire enterprise environment.

Why this answer

AWS Organizations allows you to centrally manage and enforce security policies across multiple accounts by using Service Control Policies (SCPs). SCPs define the maximum permissions for accounts in an organization, enabling you to restrict access to services or actions without requiring per-account configuration. AWS Control Tower provides a managed service that automates the setup of a multi-account environment with pre-built guardrails, which are implemented using SCPs and AWS Config rules to enforce security and compliance policies consistently.

Exam trap

The trap here is that candidates often confuse AWS Organizations with AWS Control Tower, thinking they are mutually exclusive, but Control Tower actually builds on Organizations to provide a higher-level managed governance solution, making both correct for central policy enforcement.

111
Multi-Selecthard

A company needs to enforce that all IAM users must use multi-factor authentication (MFA) to perform any AWS Console actions. Which TWO steps should be taken to enforce this?

Select 2 answers
A.Attach the policy to all IAM users or a group containing all users
B.Create an SCP in AWS Organizations
C.Create an IAM policy that uses the aws:MultiFactorAuthPresent condition key to deny access if false
D.Set an account alias for the root user
E.Enable CloudTrail to log MFA usage
AnswersA, C

Attaching the policy to every IAM user—or more efficiently, to a group that contains all users—is the only way to make the MFA enforcement policy effective because IAM policies have no effect until they are attached to a principal. Group-based attachment centralizes administration; when a new user is added to the group, the same MFA requirement is automatically inherited. This is the correct deployment step for the policy described in the answer.

Why this answer

Option C is correct because an IAM policy that uses the aws:MultiFactorAuthPresent condition key with a Deny effect when the value is false is the standard mechanism to block console (and API) actions for users who have not authenticated with MFA. Option A is correct because such a policy only takes effect once it is attached to the relevant principals — attaching it to all IAM users or to a group that contains all users ensures every user is covered. Option B is not appropriate here because SCPs apply at the AWS Organizations OU/account level and cannot enforce per-IAM-user MFA for console sign-in within a single account.

Option D is irrelevant since an account alias only changes the sign-in URL and has no bearing on MFA enforcement. Option E is incorrect because CloudTrail only records API activity for auditing; it does not enforce MFA.

Exam trap

DOP-C02 often tests the pairing requirement — candidates pick the condition-key policy but forget it must be attached to users/groups, or they pick SCPs thinking account-level controls enforce user MFA.

112
Multi-Selecthard

Which THREE AWS services can be used to centrally manage and enforce security policies across multiple accounts in AWS Organizations? (Select THREE.)

Select 3 answers
A.AWS Config Conformance Packs
B.AWS Organizations Service Control Policies (SCPs)
C.AWS Systems Manager
D.AWS CloudTrail
E.AWS Firewall Manager
AnswersA, B, E

AWS Config Conformance Packs are collections of AWS Config rules and remediation actions that can be deployed across an entire AWS Organization. They enforce compliance by evaluating resource configurations against predefined templates and automatically remediating noncompliant resources. This enables centralized governance of security and operational best practices across all accounts, making them a correct answer for centrally managing compliance.

Why this answer

AWS Config Conformance Packs enable you to deploy and enforce a collection of AWS Config rules and remediation actions across multiple accounts and Regions in an AWS Organization. They provide a centralized way to ensure that resources comply with internal policies by using a YAML template that defines the rules and parameters, which are then applied to all member accounts via AWS Config aggregators and StackSets.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (audit logging) with a policy enforcement tool, or assume AWS Systems Manager can centrally enforce security policies across accounts, when it is actually designed for operational tasks like patch management and automation, not policy governance.

113
Multi-Selecteasy

Which TWO measures can be taken to protect data at rest in Amazon S3? (Select TWO.)

Select 2 answers
A.Enable S3 Server-Side Encryption (SSE-S3 or SSE-KMS)
B.Enable cross-region replication
C.Enable MFA Delete on the bucket
D.Create a bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header
E.Use S3 Transfer Acceleration
AnswersA, D

S3 Server-Side Encryption (SSE-S3 or SSE-KMS) transparently encrypts object data before it is written to disk and decrypts it when the object is read, using either S3-managed AES-256 keys or AWS KMS-managed customer keys. This ensures that objects stored in the bucket are unreadable without the appropriate decryption key, directly protecting data at rest. For SSE-KMS, the service also provides envelope encryption, key rotation, and fine-grained access control through IAM policies.

Why this answer

S3 Server-Side Encryption (SSE) and S3 Bucket Policies to deny unencrypted PUT requests are measures to protect data at rest. MFA Delete protects against accidental deletion, not encryption. Cross-region replication is for disaster recovery.

S3 Transfer Acceleration speeds up uploads.

114
MCQeasy

A DevOps engineer is configuring AWS CloudTrail to log all management events across all regions. The engineer wants to ensure that log files are encrypted at rest using a customer-managed KMS key. What is the correct way to achieve this?

A.Use SSE-C with a customer-provided key when uploading logs to S3.
B.Enable client-side encryption before delivering logs to S3.
C.Enable default encryption on the S3 bucket using SSE-S3.
D.Specify a KMS key ID in the CloudTrail trail configuration and grant CloudTrail permissions to use the key.
AnswerD

CloudTrail natively supports SSE-KMS: you configure the trail by specifying a KMS key ID (e.g., arn:aws:kms:region:account:key/key-id) and you must also grant CloudTrail the required permissions via the KMS key policy—specifically kms:GenerateDataKey and kms:Decrypt on the key. This lets CloudTrail encrypt each log file with a customer-managed AWS KMS key, giving you full lifecycle control, auditability, and the ability to disable or rotate the key as needed. Unlike SSE-S3 or SSE-C, this is the only option that both supports automated delivery and uses a customer-managed key.

Why this answer

AWS CloudTrail supports encryption at rest using a customer-managed AWS KMS key (SSE-KMS). To achieve this, you must specify the KMS key ID in the CloudTrail trail configuration and grant CloudTrail permissions to use that key via the key policy. Option A is wrong because CloudTrail does not support SSE-C (customer-provided keys); it only supports SSE-S3 or SSE-KMS.

Option B is wrong because client-side encryption is not a built-in CloudTrail feature and would require custom implementation. Option C is wrong because SSE-S3 uses S3-managed keys, not a customer-managed KMS key. Therefore, D is the only correct way to encrypt CloudTrail logs with a customer-managed KMS key.

115
MCQhard

A company uses a centralized AWS KMS customer master key (CMK) in the security account to encrypt data in S3 buckets across multiple accounts. The S3 buckets are accessed by EC2 instances in the same accounts. The security team wants to ensure that the CMK can only be used by authorized IAM roles in the member accounts. Which policy configuration should be used?

A.Attach an IAM policy to the IAM roles in the member accounts that allows kms:Decrypt on the CMK.
B.Add a statement to the KMS key policy that grants the IAM roles in the member accounts permission to use the key.
C.Create a service control policy (SCP) that allows kms:Decrypt for the CMK.
D.Use a VPC endpoint policy for KMS to allow access from the member accounts' VPCs.
AnswerB

In AWS KMS, a customer master key is always governed by a resource-based key policy in the account that owns the key. To allow principals in separate member accounts to use the CMK, the key policy must include a statement whose Principal element contains the ARN of the IAM role (or the member account root) and grants the required cryptographic actions, such as kms:Decrypt. This acts as the cross-account authorization; additionally, the member account's IAM policy must delegate those same actions to the role, because KMS requires that both the key policy allow the principal and the principal's IAM policy allow the action.

Why this answer

A KMS key policy is the primary resource-based policy that controls who can use a customer managed key, and it must explicitly grant the member-account IAM roles permission to use the key for cross-account access. Because the CMK lives in the security account and the roles live in member accounts, the key policy must include a statement allowing those external principals to call kms:Decrypt and related actions. Without this key policy statement, IAM policies in the member accounts alone cannot grant access to the cross-account key.

Exam trap

DOP-C02 often tests the misconception that an IAM policy in the member account is sufficient for cross-account KMS access, so candidates must remember that the key policy in the owning account must grant permission first and that SCPs only restrict, never grant.

How to eliminate wrong answers

Option A is wrong because an IAM policy attached to a role in a member account cannot by itself grant access to a CMK owned by another account; cross-account KMS access requires the key policy in the owning account to delegate permission to the external principal first. Option C is wrong because an SCP is an AWS Organizations guardrail that sets the maximum available permissions for accounts in an organization; it can only restrict, never grant, kms:Decrypt access to a CMK. Option D is wrong because a VPC endpoint policy controls which requests can traverse a VPC endpoint to KMS, but it does not grant cross-account permission to use a specific CMK and cannot substitute for the key policy.

116
MCQmedium

Refer to the exhibit. A security engineer sees this CloudTrail event. What action did the user 'admin' perform?

A.Encrypted data with a KMS key.
B.Rotated a KMS key.
C.Created a new KMS key.
D.Deleted a KMS key.
AnswerC

The event name "CreateKey" maps directly to the AWS KMS CreateKey API call, which is used to provision a new customer master key (CMK). In the CloudTrail log, the resources array contains the ARN of the newly created key (e.g., arn:aws:kms:region:account:key/key-id), confirming that a new symmetric or asymmetric KMS key was successfully created. This is the only action listed whose event name and resource type align with the observed log entry.

Why this answer

The CloudTrail event shows the API call CreateKey, which is the KMS operation that provisions a brand-new customer managed key. The event name in CloudTrail directly maps to the KMS API action, and CreateKey returns a new key ID with key state 'Enabled' and no key material yet until first use. This is distinct from Encrypt, RotateKey, or ScheduleKeyDeletion, each of which produces a different eventName.

Exam trap

The trap here is that candidates see 'KMS' and 'admin' in a CloudTrail snippet and assume the most common KMS operation (Encrypt) rather than reading the actual eventName field, which is the authoritative indicator of the action performed.

How to eliminate wrong answers

Option A is wrong because encryption with a KMS key generates an Encrypt event (or a GenerateDataKey event), not CreateKey, and the request parameters would include a keyId and plaintext, not key policy/spec fields. Option B is wrong because key rotation produces a RotateKeyOnDemand or EnableKeyRotation event and operates on an existing key ID, not a new one. Option D is wrong because deletion produces a ScheduleKeyDeletion event with a pendingDeletionWindowInDays parameter, and the key would move to Pending Deletion state rather than being created.

117
MCQhard

A company uses AWS Organizations with 20 accounts. The Security team has configured AWS CloudTrail to deliver logs from all accounts to a central S3 bucket (central-bucket). The bucket policy allows CloudTrail to write objects and uses SSE-S3 encryption. Recently, auditors found that some log files were missing for a few hours. The CloudTrail console shows that trails are enabled in all accounts. The central-bucket has default encryption enabled. What is the MOST likely cause of the missing logs?

A.The CloudTrail trail is not configured to deliver to the central bucket from all regions
B.The S3 bucket policy contains a deny condition that requires aws:SecureTransport to be true, but CloudTrail uses HTTP
C.The IAM role used by CloudTrail does not have s3:PutObject permission
D.The S3 bucket policy denies access unless the PutObject request includes the x-amz-server-side-encryption header with value AES256
AnswerD

This is the correct explanation: the S3 bucket policy includes a condition that requires the `x-amz-server-side-encryption` header to be present with a value of `AES256` on every PutObject request. CloudTrail, when delivering log files to S3, does not automatically include that header in its API call; it relies on the bucket's default encryption policy instead. As a result, CloudTrail's PutObject requests fail the policy condition and are denied, causing the log delivery gap. The intermittent nature could be due to CloudTrail's retry logic or the recent introduction of the policy condition, but the root cause is the header mismatch between the bucket policy and CloudTrail's request format.

Why this answer

The bucket policy denies PutObject requests that do not include the `x-amz-server-side-encryption` header with value `AES256`. CloudTrail does not include this header by default when delivering logs, so the requests are denied, causing missing logs. The bucket's default encryption (SSE-S3) does not override the bucket policy requirement.

Option D is correct because it directly addresses the policy condition that blocks CloudTrail writes. Options A, B, and C are incorrect: A refers to multi-region trails, but the issue is about encryption headers; B is wrong because CloudTrail uses HTTPS, not HTTP; C is wrong because the IAM role permissions are not the issue—the bucket policy is the cause.

118
Multi-Selectmedium

A financial services company is migrating its applications to AWS. The compliance team requires that all Amazon S3 buckets containing personally identifiable information (PII) must have server-side encryption enabled and block public access. The DevOps team discovers that some S3 buckets are not compliant. Which TWO actions should the team take to enforce these requirements automatically for all current and future buckets? (Select TWO.)

Select 2 answers
A.Enable AWS CloudTrail to log all S3 API calls and send alerts when noncompliant buckets are created.
B.Use AWS Config managed rules to detect noncompliant buckets and automatically remediate by applying encryption and blocking public access.
C.Attach an IAM permissions boundary to all users that prevents them from creating or modifying S3 buckets.
D.Apply an S3 bucket policy to each existing bucket that denies all access unless encryption is enabled.
E.Create an SCP that denies the s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions when the required settings are not specified.
AnswersB, E

AWS Config managed rules such as s3-bucket-public-read-prohibited and s3-bucket-default-encryption-enabled continuously evaluate bucket configurations against your compliance requirements. When a violation is detected, you can attach remediation actions, typically SSM Automation runbooks, to automatically apply default encryption and block public access. This combination of detection and corrective automation meets the enforcement need by actively fixing noncompliant buckets without requiring manual intervention.

Why this answer

To enforce these requirements automatically for all current and future buckets, the team should use AWS Config managed rules (e.g., s3-bucket-server-side-encryption-enabled and s3-bucket-public-read-prohibited) with auto-remediation to detect and automatically fix noncompliant buckets (option B). Additionally, an SCP that denies s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions when the required settings are not specified prevents noncompliant buckets from being created in the first place across all accounts (option E). Together, these provide preventive and corrective controls for all existing and future buckets.

Exam trap

The trap here is that candidates often confuse detective controls (like CloudTrail alerts) with preventive or corrective controls (like AWS Config auto-remediation or SCPs), leading them to select Option A instead of the automated enforcement mechanisms that actually fix noncompliant buckets.

119
MCQmedium

A company uses AWS Lambda functions to process sensitive data from an SQS queue. The Lambda function writes results to an S3 bucket. The security team requires that all data at rest in S3 be encrypted with a customer managed KMS key, and that the Lambda function only have access to decrypt the queue messages and encrypt the S3 objects. An IAM role is attached to the Lambda function. The engineer has configured the KMS key policy to allow the Lambda role to use the key. However, the Lambda function fails to write to S3 with a 'KMS access denied' error. The engineer verified that the S3 bucket has default encryption enabled with the same KMS key. Which additional step is most likely required?

A.Disable default encryption on the S3 bucket and configure the Lambda to use SSE-S3.
B.Add an inline policy to the Lambda role that allows kms:GenerateDataKey and kms:Encrypt actions for the KMS key.
C.Grant the Lambda role s3:PutObject permission on the bucket.
D.Modify the KMS key policy to allow the Lambda role to use the key without any conditions.
AnswerB

The correct fix is to add an inline policy to the Lambda execution role that explicitly permits kms:GenerateDataKey and kms:Encrypt on the customer managed KMS key. When the Lambda writes an object to S3 with SSE-KMS, S3 calls KMS on behalf of the principal to generate a data key and encrypt the object; without these actions, S3 surfaces an 'Access Denied' error from KMS. An inline policy on the role is a targeted way to provide these permissions because KMS authorization requires both a permissive key policy and an explicit grant on the IAM identity. This addresses the root cause: the role's identity policy lacks the KMS actions needed to complete the upload.

Why this answer

The KMS key policy alone is not sufficient — IAM policies must also grant the caller permission to use the key. When Lambda writes to an S3 bucket with SSE-KMS default encryption, S3 calls kms:GenerateDataKey on behalf of the Lambda execution role to obtain a data key for envelope encryption. Without kms:GenerateDataKey (and typically kms:Encrypt) in the Lambda role's identity-based policy, the request fails with 'KMS access denied' even though the key policy allows the role.

Exam trap

DOP-C02 often tests the misconception that a KMS key policy alone is sufficient for access — candidates forget that the caller's IAM identity policy must also grant the KMS action.

How to eliminate wrong answers

Option A is wrong because switching to SSE-S3 removes the customer managed KMS key requirement entirely and violates the security team's mandate for a CMK. Option C is wrong because s3:PutObject alone does not satisfy KMS authorization — the failure is a KMS access denied error, not an S3 permission error, so adding S3 permissions will not resolve it. Option D is wrong because the key policy already allows the Lambda role; loosening conditions does not address the missing IAM identity-based permission, and removing conditions weakens security unnecessarily.

120
MCQmedium

A company uses Amazon RDS for MySQL with Multi-AZ deployment. The security team requires that all data be encrypted at rest and that automated backups are also encrypted. Which configuration meets these requirements?

A.Use an S3 bucket policy to enforce encryption for backup files.
B.Enable encryption for the RDS instance using AWS KMS.
C.Enable encryption on automated backups only after creating a snapshot.
D.Enable encryption on the underlying EBS volumes using KMS.
AnswerB

Enabling RDS encryption with AWS KMS is the correct method because it transparently encrypts the DB instance's data at rest, its automated backups, and its snapshots using the same customer master key. For a Multi-AZ deployment, you should enable encryption either at instance creation or by restoring an encrypted snapshot, since encryption cannot be added to an existing unencrypted instance without a snapshot restore. This ensures compliance and data protection across all storage layers without requiring direct access to underlying storage.

Why this answer

Enabling encryption on the RDS instance using AWS KMS at creation time encrypts the data, automated backups, read replicas, and snapshots. Option A is incorrect because an S3 bucket policy cannot enforce encryption for RDS automated backups; RDS encryption must be handled at the instance level. Option C is incorrect because enabling encryption on automated backups after creating a snapshot does not encrypt the live database or future automated backups.

Option D is incorrect because encrypting the underlying EBS volumes separately does not automatically encrypt the RDS data, logs, or backups; RDS encryption must be enabled directly on the instance.

121
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to enforce that all S3 buckets across accounts are encrypted with AWS KMS. Which combination of controls should be used to enforce this?

A.Use an SCP to deny s3:PutBucketEncryption with encryption disabled, and AWS Config rules to detect non-compliant buckets.
B.Attach an IAM policy to all users denying s3:PutObject without KMS.
C.Use an SCP to deny s3:CreateBucket without encryption, and rely on CloudTrail to alert.
D.Use AWS Config rules only, with automatic remediation via Lambda.
AnswerA

An SCP at the root or OU level is the correct proactive control because it allows you to explicitly deny the s3:PutBucketEncryption API action when the encryption configuration is null or set to SSE-S3, effectively preventing any IAM principal from creating or modifying a bucket without server-side encryption. This works on all accounts in the organization, regardless of local IAM configurations, and blocks the disabling of encryption even after the bucket is created. AWS Config then acts as a detective layer: the managed rule s3-bucket-encryption-enabled continuously evaluates buckets and flags any that are non-compliant, including those that existed before the SCP was applied, ensuring full coverage through a defense-in-depth approach.

Why this answer

It combines preventive and detective controls. An SCP can deny the s3:PutBucketEncryption action unless the bucket is configured with KMS encryption, which prevents non-compliant buckets from being created or modified. AWS Config rules then detect any existing non-compliant buckets or changes that bypass the SCP, providing continuous compliance monitoring.

Exam trap

The trap here is that candidates often confuse object-level encryption (s3:PutObject) with bucket-level default encryption (s3:PutBucketEncryption), and fail to realize that an SCP is needed for preventive enforcement, not just detective or reactive controls.

How to eliminate wrong answers

Option B is wrong because it only controls s3:PutObject, which enforces encryption at the object level but does not prevent creation of unencrypted buckets or enforce bucket-level default encryption settings. Option C is wrong because relying solely on CloudTrail alerts provides only detective control after the fact, with no preventive enforcement to block non-compliant bucket creation. Option D is wrong because AWS Config rules with automatic remediation are reactive and may have a delay, whereas a preventive SCP is needed to block non-compliant actions in real time.

122
MCQhard

Given the above AWS CLI command output, which actions are allowed for the specified policy?

A.Only s3:GetObject is allowed
B.ec2:DescribeInstances and s3:GetObject are allowed; s3:ListBucket is denied
C.Only ec2:DescribeInstances is allowed
D.All three actions are allowed
AnswerB

This matches the policy's allow statements exactly. The IAM policy grants ec2:DescribeInstances (or ec2:Describe*) and s3:GetObject, so requests to describe EC2 instances and get S3 objects will succeed. s3:ListBucket is not covered by any allow statement, so it is denied either by an explicit Deny or by the default implicit deny that applies when no allow matches. The CLI simulation confirms this by returning 'allowed' for the two granted actions and 'denied' for s3:ListBucket.

Why this answer

The simulate-custom-policy command tests the specified policy against the given actions and resources. For ec2:DescribeInstances, the action is allowed because the policy includes ec2:Describe*. For s3:GetObject, the action is allowed because the policy explicitly allows s3:GetObject.

For s3:ListBucket, the action is not allowed because the policy only allows s3:GetObject, not s3:ListBucket. Therefore, ec2:DescribeInstances and s3:GetObject are allowed, while s3:ListBucket is denied. Option B is correct.

123
MCQmedium

A company uses AWS CodePipeline to deploy applications. The pipeline must deploy to an Amazon ECS cluster. The security team requires that all deployment actions be logged and auditable. Which configuration should be used?

A.Enable VPC Flow Logs for the ECS cluster's VPC.
B.Enable Amazon S3 server access logs for the artifact bucket used by CodePipeline.
C.Enable AWS CloudTrail to record all API calls made by CodePipeline.
D.Enable Amazon CloudWatch Logs for the CodePipeline.
AnswerC

AWS CloudTrail is the native audit service that records all API calls made by or on behalf of CodePipeline, including pipeline creation, stage updates, and StartPipelineExecution. Each event includes the identity of the caller, the time of the call, the source IP, and the request parameters, providing a complete and tamper-evident audit trail. This directly satisfies the requirement to log and audit deployment actions, making it the correct choice.

Why this answer

AWS CloudTrail records all API calls made to AWS services, including those made by CodePipeline when it invokes ECS deployment actions (such as UpdateService, RegisterTaskDefinition, or CreateDeployment). Enabling CloudTrail provides the audit trail required by the security team, capturing who made the call, when, from where, and what the request contained.

Exam trap

DOP-C02 often tests the difference between operational logging (CloudWatch Logs, which shows pipeline execution details) and security auditing (CloudTrail, which records API calls with identity and source) — candidates frequently pick CloudWatch Logs because it sounds like it covers 'logging,' but it lacks the audit-level detail required for security compliance.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata at the network interface level, not API-level actions — they cannot show which CodePipeline action invoked which ECS API. Option B is wrong because S3 server access logs only record requests to the artifact bucket (GET/PUT of artifacts), not the deployment API calls to ECS. Option D is wrong because CloudWatch Logs for CodePipeline captures pipeline execution logs and action output, but it is not a security audit trail of API calls and does not record the identity or source of API requests in the way CloudTrail does.

124
MCQhard

A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to block traffic from known malicious IP addresses before it reaches the ALB. What is the MOST effective approach?

A.Use AWS WAF with an IP set rule to block the malicious IP addresses.
B.Configure network ACLs on the ALB's subnet to block the malicious IPs.
C.Use AWS Network Firewall to inspect and block traffic at the VPC level.
D.Configure security groups to deny inbound traffic from the malicious IP addresses.
AnswerA

AWS WAF is the correct layer 7 filtering solution because it natively integrates with Application Load Balancers and provides managed IP sets that can be populated with the malicious source IPs. Through a Web ACL rule referencing the IP set, WAF blocks requests from those addresses before they reach the ALB, without affecting legitimate traffic. IP sets can be updated dynamically via API or Security Automation, making them practical for handling frequently changing attacker IP lists while providing access to AWS-managed rule groups for additional application-layer protection.

Why this answer

AWS WAF is the only service in the list that operates at Layer 7 and integrates natively with ALB, allowing IP set rules to block traffic before it reaches the application. An IP set rule in WAF explicitly matches source IPs and takes a block action, which is exactly what the security team requires. WAF is also managed and scalable, so it can handle large IP lists without impacting ALB performance.

Exam trap

DOP-C02 often tests the misconception that security groups can deny traffic or that network ACLs are the primary tool for blocking IPs at the ALB, when in fact AWS WAF is the correct service for Layer 7 IP blocking on ALB.

How to eliminate wrong answers

Option B is wrong because network ACLs are stateless and operate at Layer 3/4; they can block IPs but are associated with subnets, not ALBs, and would require managing rules on the ALB's subnet, which may affect other resources and lacks the granularity and integration of WAF. Option C is wrong because AWS Network Firewall is a VPC-level service that inspects traffic between VPCs or to the internet, but it does not integrate directly with ALB and is overkill for simply blocking IPs before the ALB; it also adds latency and complexity. Option D is wrong because security groups are allow-only (no deny rules) and operate at the instance level, not on the ALB; they cannot block specific IPs from reaching the ALB.

125
MCQmedium

A DevOps engineer needs to store database credentials for an application running on Amazon ECS. The credentials must be automatically rotated every 30 days and encrypted at rest. Which solution meets these requirements with the LEAST operational overhead?

A.Store credentials in AWS Systems Manager Parameter Store as SecureString.
B.Encrypt credentials with AWS KMS and store them in a versioned S3 bucket.
C.Embed credentials as environment variables in the ECS task definition.
D.Store credentials in AWS Secrets Manager and configure automatic rotation.
AnswerD

AWS Secrets Manager is purpose-built for storing database credentials, and when configured with automatic rotation, it natively rotates the password on a schedule using an attached Lambda function (e.g., the built-in rotation template for RDS). Secrets Manager also encrypts the secret at rest with AWS KMS, integrates with ECS via the 'secrets' parameter in the task definition, and requires no custom code to implement periodic credential changes, giving you the least operational overhead while meeting the security and compliance requirements.

Why this answer

AWS Secrets Manager is purpose-built for storing and managing secrets such as database credentials, and it natively supports automatic rotation via Lambda functions on a schedule (e.g., every 30 days). It encrypts secrets at rest using KMS by default and integrates directly with ECS task definitions via the secrets parameter, so credentials are injected at runtime without hardcoding. This delivers the required rotation and encryption with minimal operational overhead.

Exam trap

DOP-C02 often tests the distinction between Parameter Store and Secrets Manager — candidates pick Parameter Store because it is cheaper, forgetting that only Secrets Manager has native automatic rotation.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store SecureString encrypts values with KMS but has no built-in automatic rotation capability — you would have to build and maintain a custom rotation mechanism, adding operational overhead. Option B is wrong because storing KMS-encrypted credentials in a versioned S3 bucket provides encryption at rest but no rotation feature at all, and requires custom code to rotate and distribute credentials. Option C is wrong because embedding credentials as environment variables in the ECS task definition stores them in plaintext (visible to anyone with task definition read access) and provides neither encryption at rest nor rotation.

126
MCQeasy

An application running on EC2 needs to access an S3 bucket. To follow the principle of least privilege, what is the recommended approach?

A.Store AWS access keys in the application configuration
B.Create an IAM role with a policy allowing only necessary S3 actions and attach it to the EC2 instance
C.Use an S3 bucket policy to allow access from the EC2 instance's public IP
D.Configure the EC2 security group to allow outbound access to S3
AnswerB

Attaching an IAM role to the EC2 instance profile is the correct method because the instance automatically retrieves short-lived credentials from the instance metadata service (IMDS) and uses them to sign S3 API requests. The role's policy should only include the actions needed on the specific S3 bucket/prefix, satisfying least privilege and avoiding long-lived secrets entirely. These credentials are refreshed automatically, and access can be revoked by modifying the role, making change management clean and auditable.

Why this answer

The best practice is to create an IAM role with a policy that grants only the required S3 actions and attach the role to the EC2 instance. This avoids using long-term credentials. Access keys are long-term and insecure.

Bucket policy can be used but is not the most secure for instance access. Security group is for network access, not API access.

127
Multi-Selectmedium

A company is using AWS CloudTrail to log API events. The security team wants to ensure that log files are tamper-proof and available for incident investigation. Which TWO actions should be taken? (Choose TWO.)

Select 2 answers
A.Store logs in Amazon CloudWatch Logs.
B.Enable server-side encryption with S3-managed keys (SSE-S3).
C.Enable CloudTrail log file validation.
D.Enable S3 Object Lock on the S3 bucket storing the logs.
E.Use AWS KMS to encrypt the logs.
AnswersC, D

CloudTrail's log file validation writes digest files to the same S3 bucket every hour, each containing a SHA-256 hash of the current log file and a reference to the previous digest. This creates an unbroken hash chain that you can use to verify whether any log file was altered, deleted, or replayed after delivery. To use it, enable the validation and store digests in a separate prefix with a restrictive bucket policy. It is a detective control that detects tampering after the fact, making it the direct answer to protecting log integrity.

Why this answer

Option C is correct because enabling CloudTrail log file validation generates a digest file for each log file, allowing you to verify that logs have not been altered or deleted after delivery. Option D is correct because S3 Object Lock enforces WORM (write once, read many) protection, preventing log files from being overwritten or deleted during a defined retention period, which directly supports tamper-proofing and availability for investigations. Option A is not correct because CloudWatch Logs is a monitoring/log aggregation service and does not by itself provide tamper-proofing or immutability for CloudTrail log files.

Option B is not correct because SSE-S3 only provides encryption at rest and does not prevent modification or deletion of log files. Option E is not correct because AWS KMS encryption, while stronger in key control, still does not enforce immutability or tamper resistance on its own.

Exam trap

The trap is equating encryption with tamper-proofing — candidates pick SSE-S3 or KMS thinking encryption protects integrity, when only log file validation and Object Lock actually prevent or detect modification and deletion.

128
MCQmedium

A DevOps engineer needs to ensure that EC2 instances can access an S3 bucket without storing AWS credentials on the instances. Which solution meets this requirement?

A.Use an S3 bucket policy that grants access to the EC2 instance's public IP.
B.Store access keys in the EC2 user data script.
C.Create an IAM user and embed credentials in the application code.
D.Attach an IAM role to the EC2 instance with an S3 access policy.
AnswerD

An IAM role attached to the instance delivers temporary credentials through the instance metadata service, so the AWS SDK retrieves them automatically. This satisfies the no-stored-credentials constraint, unlike embedding access keys in code or on the instance filesystem.

Why this answer

Attaching an IAM role to an EC2 instance allows the instance to obtain temporary security credentials from the AWS STS service via the instance metadata service (IMDS). The EC2 instance can then use these credentials to access the S3 bucket without any long-term AWS credentials being stored on the instance. This is the AWS-recommended best practice for granting permissions to AWS services running on EC2.

Exam trap

The trap here is that candidates may think storing credentials in user data or application code is acceptable, but the DOP-C02 exam specifically tests the principle of using IAM roles to avoid long-term credential storage on EC2 instances.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy that grants access based on an EC2 instance's public IP is not a secure or reliable method; public IPs can change (unless using an Elastic IP) and do not authenticate the identity of the requester, making it vulnerable to spoofing and not a substitute for AWS credentials. Option B is wrong because storing access keys in the EC2 user data script exposes long-term credentials in plaintext within the instance's metadata and logs, violating the requirement to avoid storing credentials on the instance. Option C is wrong because embedding IAM user credentials in application code stores long-term access keys directly on the instance, which is insecure and contradicts the principle of using temporary credentials via IAM roles.

129
MCQhard

A company is migrating to AWS and has a requirement to encrypt all data at rest and in transit. They are using AWS KMS with Customer Master Keys (CMKs) for encryption. The DevOps engineer has set up an S3 bucket with default encryption using SSE-KMS. The bucket policy allows access only to a specific IAM role. The engineer also enabled S3 bucket versioning and MFA Delete. However, when the engineer tries to download an object using the AWS CLI with the IAM role, the command fails with 'AccessDenied'. The IAM role has the following permissions: s3:GetObject, s3:ListBucket, kms:Decrypt, kms:DescribeKey. What is the most likely missing permission?

A.The IAM role is missing kms:GenerateDataKey permission.
B.The IAM role is missing kms:Encrypt permission.
C.The IAM role is missing kms:CreateGrant permission.
D.The KMS key policy does not grant the IAM role permission to decrypt using the key.
AnswerD

For an IAM role to decrypt an object using a customer managed key, the KMS key policy must explicitly include the role (or an account principal with delegation) in a statement that allows kms:Decrypt. Even if the IAM role's permissions policy grants kms:Decrypt, KMS requires both the IAM policy and the key policy to authorize the action. If the key policy only allows a different principal or restricts access to specific roles, the decryption fails—this is the most direct cause of the error.

Why this answer

When an IAM role has kms:Decrypt but the KMS key policy does not grant that role access to the key, all KMS operations fail with AccessDenied. KMS requires BOTH the IAM policy and the key policy to allow the principal — the key policy is the primary gatekeeper, so a missing grant there is the most likely cause.

Exam trap

DOP-C02 often tests the misconception that IAM permissions alone are sufficient for KMS — candidates forget that the KMS key policy must also grant access, making the key policy the real gatekeeper.

How to eliminate wrong answers

Option A is wrong because kms:GenerateDataKey is only needed for uploads (PutObject), not for downloading/decrypting an existing object. Option B is wrong because kms:Encrypt is required to upload encrypted objects, not to download them. Option C is wrong because kms:CreateGrant is only needed when the caller must delegate key usage to another principal, which is not the case for a simple GetObject.

130
Multi-Selectmedium

A company is using AWS Secrets Manager to rotate database credentials automatically. The DevOps engineer needs to ensure that the rotation process is secure and does not cause downtime. Which THREE steps should the engineer take?

Select 3 answers
A.Disable automatic rotation for the old secret version.
B.Set up CloudWatch alarms to monitor rotation failures.
C.Use a separate database user for rotation that has permissions to change passwords.
D.Configure the Lambda rotation function to use a VPC endpoint for Secrets Manager.
E.Grant the Lambda rotation function IAM permissions to read and update the secret.
AnswersB, C, E

Setting up CloudWatch alarms on the Secrets Manager rotation Lambda function's failure metrics or on the RotationFailed event (via Amazon EventBridge and CloudTrail) is essential because rotation failures can occur silently without directly impacting the application. If a failure goes unnoticed, the secret may remain stale for an extended period; more critically, the Lambda might have created and stored a new version but failed to promote it to AWSCURRENT, leaving the database and Secrets Manager in an inconsistent state. An alarm ensures administrators are notified quickly to prevent both stale credential burnout and potential data-plane outages.

Why this answer

Option B is correct because CloudWatch alarms on the rotation Lambda's errors, invocation failures, and Secrets Manager rotation metrics let the engineer detect and respond to failed rotations before credentials become stale and cause authentication outages. Option C is correct because the rotation Lambda must authenticate to the database using a dedicated rotation user whose credentials are stored in the secret, and that user needs privileges to modify the password of the target user (for example ALTER USER ... IDENTIFIED BY) so the application user's credentials can be changed without manual intervention.

Option E is correct because the Lambda rotation function needs IAM permissions for secretsmanager:GetSecretValue, PutSecretValue, UpdateSecretVersionStage, and DescribeSecret so it can read the current secret, write the new version, and move the AWSCURRENT staging label to complete rotation. Option A is not needed because Secrets Manager automatically deprecates and removes old versions via staging labels; disabling rotation on an old version is not a valid or necessary step. Option D is not required because a VPC endpoint is only needed when the Lambda runs in a private VPC without NAT/internet access; it is an optional network-hardening measure, not one of the three required steps for secure, zero-downtime rotation.

Exam trap

DOP-C02 often tests whether candidates confuse network hardening (VPC endpoints) with the actual functional requirements for secure, zero-downtime secret rotation, causing them to select D instead of the IAM permission option.

131
MCQeasy

An organization wants to grant cross-account access to an S3 bucket in Account A to a user in Account B. Which policy configuration is required?

A.A bucket policy in Account A and an IAM user policy in Account B
B.An S3 bucket ACL granting access to the user in Account B
C.An IAM user policy in Account B allowing access to the bucket
D.A bucket policy in Account A granting access to the user in Account B
AnswerA

Combining a bucket policy in Account A that grants the IAM user ARN from Account B permissions on the target S3 bucket with an IAM user policy in Account B that approves the same actions is the standard method for cross-account S3 access. The bucket policy acts as the resource-based authorization, defining who can interact with the bucket and its objects; the IAM user policy acts as the identity-based authorization, allowing the user to invoke those S3 APIs. Without both explicit allows, the request is denied by AWS's default deny behavior.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) on the bucket in Account A granting access to the user in Account B, and an identity-based policy (IAM user policy) in Account B allowing the user to access the bucket. Option A correctly includes both policies. Option B is incorrect because S3 bucket ACLs are legacy and not recommended for cross-account access.

Option C is missing the bucket policy in Account A, so it is insufficient. Option D is missing the IAM user policy in Account B, so it is insufficient.

132
MCQmedium

A DevOps engineer needs to enforce encryption in transit for all traffic between a fleet of EC2 instances and an Application Load Balancer (ALB). The ALB is configured with a TLS listener. Which step should the engineer take to ensure end-to-end encryption?

A.Configure the target group to use HTTP protocol
B.Configure the target group to use HTTPS protocol and install a certificate on each EC2 instance
C.Use security group rules to enforce encryption
D.Terminate TLS at the ALB and use HTTP to instances
AnswerB

Configuring the target group for HTTPS forces the ALB to negotiate a TLS session with each EC2 instance, so backend traffic is encrypted as well. Each instance must present a valid certificate that the ALB trusts, typically installed on the instance's web server or TLS terminator, to complete the handshake. This provides encryption in transit across both the client-to-ALB and ALB-to-instance segments.

Why this answer

To enforce end-to-end encryption between the ALB and EC2 instances, the target group must use HTTPS protocol. This requires each EC2 instance to have a TLS certificate installed so that traffic from the ALB to the instances is encrypted. Option A is incorrect because HTTP does not encrypt traffic.

Option C is incorrect because security groups control network access but do not enforce encryption. Option D is incorrect because terminating TLS at the ALB and using HTTP to instances would leave the traffic between ALB and instances unencrypted.

133
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team wants to automatically rotate secrets every 30 days. The database is an Amazon RDS for PostgreSQL instance. The team has configured automatic rotation with a Lambda function that updates the password in RDS and Secrets Manager. However, after the first rotation, the application starts getting database connection errors. The application uses a connection string with the secret ARN and retrieves the secret from Secrets Manager at startup using the AWS SDK. Which of the following is the most likely cause of the connection errors?

A.The Lambda function is not configured with a sufficient timeout and is being throttled.
B.The application caches the secret at startup and does not refresh it after rotation.
C.The Lambda function does not have permission to update the secret in Secrets Manager.
D.The RDS instance has automatic password rotation enabled, which conflicts with Secrets Manager rotation.
AnswerB

The application reads the secret once at startup and holds it in memory, so after rotation the cached credentials no longer match the new RDS password, producing authentication failures. Refreshing the secret from Secrets Manager on each connection, or handling rotation-aware retrieval, resolves the connection errors.

Why this answer

If the application caches the secret at startup, it will not retrieve the updated password after rotation, causing connection errors. Option A is incorrect because a Lambda timeout or throttling would prevent the rotation from completing, but the rotation succeeded (new password set), so the issue is on the application side. Option C is incorrect because if the Lambda lacked permissions to update the secret, the rotation would have failed entirely, not just after the first rotation.

Option D is incorrect because Amazon RDS does not have built-in automatic password rotation; Secrets Manager manages the rotation, so there is no conflict.

134
MCQmedium

A company uses AWS Key Management Service (KMS) to encrypt data at rest in Amazon S3. The security team wants to ensure that only users with a specific attribute in their SAML assertion can decrypt the data. Which KMS key policy should be used?

A.Create an S3 bucket policy that denies kms:Decrypt unless the request includes a specific tag.
B.Modify the KMS key policy to include a condition that allows kms:Decrypt only if the SAML assertion contains the specific attribute.
C.Attach a resource-based policy to the S3 bucket that allows decryption only for users with the specific attribute.
D.Use an IAM policy that grants kms:Decrypt only if the user has the specific attribute.
AnswerB

KMS key policies are resource-based policies attached directly to the customer master key, and they are evaluated for every KMS API action against that key. The policy can include a Condition block that references SAML-derived session attributes, such as a session tag mapped from an attribute in the SAML assertion, to allow kms:Decrypt only when the expected attribute value is present. This is the correct approach because it centralizes the decryption restriction at the key resource itself, ensuring that any principal attempting to use the key must satisfy the condition regardless of their IAM permissions.

Why this answer

KMS key policies are resource-based policies that can use IAM condition keys. To enforce a requirement based on a SAML assertion, you must first configure the IAM role's trust policy to map the SAML attribute to a session tag using sts:TagSession. Then, the KMS key policy can include a condition such as aws:PrincipalTag/attribute_name to allow kms:Decrypt only when that session tag matches the expected value.

This ensures compliance at the key level, independent of S3 bucket policies. Note that saml:sub and other SAML condition keys are not supported in KMS key policies; they are only valid in IAM trust policies.

Exam trap

A common mistake is to think that S3 bucket policies can control KMS decryption or that KMS key policies can directly inspect SAML assertions. KMS key policies only see the principal (the IAM role or user) and its attributes/tags. To enforce a SAML attribute, you must first map it to a session tag in the role trust policy, then condition on that tag in the KMS key policy.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies cannot deny `kms:Decrypt`; KMS API calls are governed by KMS key policies and IAM policies, not S3 resource policies. Option C is wrong because S3 bucket policies control access to S3 operations (e.g., `s3:GetObject`), not KMS decryption permissions; they cannot enforce conditions on the KMS `Decrypt` action itself. Option D is wrong because IAM policies alone cannot enforce conditions based on SAML assertion attributes unless those attributes are first mapped to IAM session tags or roles; the requirement is to control decryption at the KMS key level, and a KMS key policy with a SAML condition is the direct and correct mechanism.

135
MCQmedium

A company uses AWS WAF to protect a web application behind an Application Load Balancer. The security team notices an increase in false positives blocking legitimate traffic. Which action should be taken to reduce false positives while maintaining security?

A.Remove the rate-based rule that is causing false positives.
B.Replace AWS WAF with AWS Shield Advanced.
C.Adjust the rate-based rule threshold to a higher value.
D.Change the rule action from 'Block' to 'Count'.
AnswerC

Increasing the rate-based rule's threshold is the appropriate response because the rule currently flags legitimate traffic when it should only block genuinely anomalous request floods. AWS WAF rate-based rules count requests that match a rule's conditions from a single source IP over a 1- or 5-minute evaluation window; if your legitimate users share an office IP or traverse a NAT gateway, their aggregate requests can exceed a threshold set too close to peak traffic. By raising the threshold above your historical maximum legitimate request volume per IP, you preserve protection against distributed or bot-driven floods while eliminating false positives from normal usage spikes.

Why this answer

Adjusting the rate-based rule threshold to a higher value allows more legitimate traffic while still blocking excessive requests. Option A: Removing the rule would weaken security. Option B: AWS Shield Advanced is a DDoS protection service, not a replacement for fine-tuning WAF rules.

Option D: Changing action to 'Count' logs requests but does not block them, reducing security.

Exam trap

Candidates often think that changing rule action to 'Count' is a good compromise, but it only logs and does not block, thus reducing security. The correct approach is to adjust the threshold.

136
Multi-Selecteasy

A DevOps engineer is tasked with auditing all AWS API calls made in the account for compliance purposes. The engineer needs to ensure that the audit logs are tamper-proof and stored cost-effectively. Which TWO services should the engineer use?

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.Amazon S3 with Object Lock enabled
D.Amazon CloudWatch Logs
E.AWS KMS
AnswersB, C

AWS CloudTrail is the principal service that logs all management, data, and insight API calls across an AWS account, capturing identity, request context, and response details. It is correct for this scenario because you need API-call logging, but to make the resulting log files truly tamper-proof you must configure CloudTrail to deliver them to an S3 bucket with Object Lock enabled. CloudTrail also supports log file integrity validation, yet that only detects tampering, whereas Object Lock prevents it.

Why this answer

AWS CloudTrail (B) is correct because it is the service that records all AWS API activity in an account as event logs, which is exactly what is needed to audit API calls for compliance. Amazon S3 with Object Lock enabled (C) is correct because CloudTrail delivers its logs to an S3 bucket, and S3 Object Lock provides WORM (write-once-read-many) protection so the logs cannot be altered or deleted, while S3 storage classes keep the cost low for long-term retention. AWS Config (A) is not correct because it records resource configuration changes and compliance state, not the full set of API calls.

Amazon CloudWatch Logs (D) is not correct because it is a log storage and monitoring service, not the API audit trail itself, and it lacks the immutable WORM guarantee. AWS KMS (E) is not correct because it provides encryption key management, which supports security but does not by itself create tamper-proof, cost-effective audit logs.

Exam trap

DOP-C02 often tests the distinction between CloudTrail (audit trail) and Config (configuration compliance), and between CloudWatch Logs (aggregation) and S3 Object Lock (immutability), tricking candidates into picking Config or CloudWatch for tamper-proof audit storage.

137
Multi-Selecthard

A company is designing a secure CI/CD pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy. The pipeline must deploy to an EC2 Auto Scaling group across multiple AWS accounts. The security requirements include: (1) no hardcoded credentials, (2) least privilege for cross-account access, (3) encrypted artifacts. Which THREE steps should the DevOps engineer implement? (Choose THREE.)

Select 3 answers
A.Use a customer-managed KMS key with a cross-account key policy to encrypt artifacts.
B.Store database credentials in AWS Secrets Manager and retrieve them in CodeBuild using the secrets manager action.
C.Store database credentials in AWS Systems Manager Parameter Store and retrieve them in CodeBuild.
D.Use AWS CodeCommit as the source repository with pull request approval rules.
E.Configure CodePipeline to assume an IAM role in the target account using a trust policy.
AnswersA, B, E

Using a customer-managed KMS key with a cross-account key policy is correct because CodePipeline stores build artifacts in S3, which must be encrypted. By default, AWS-managed keys are scoped to a single account, so to share artifacts with a target account you must use a customer-managed key and explicitly grant the target account's principals decrypt permission via a cross-account key policy. This provides secure, auditable cross-account artifact transfer without exposing the key material, and it lets you enforce encryption at rest with full control over key rotation and access.

Why this answer

Using a customer-managed KMS key with a cross-account key policy allows encrypting artifacts in CodePipeline's artifact store, ensuring that only authorized accounts can decrypt them, meeting the requirement for encrypted artifacts and least privilege. Option B is correct because storing database credentials in AWS Secrets Manager and retrieving them in CodeBuild using the secrets manager action avoids hardcoded credentials and provides secure, rotating credentials. Option E is correct because configuring CodePipeline to assume an IAM role in the target account using a trust policy enables cross-account deployment with least privilege, as the pipeline assumes a role with only necessary permissions.

Option C is incorrect because while SSM Parameter Store can store credentials, Secrets Manager is specifically designed for secrets management with automatic rotation and is more appropriate for database credentials. Option D is incorrect because CodeCommit with pull request approval rules is a source control practice, not directly addressing the security requirements of no hardcoded credentials, least privilege cross-account access, or encrypted artifacts.

138
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user requests an object from the 'example-bucket' bucket, specifically from the 'confidential' folder, over HTTP (not HTTPS). The source IP is within the 10.0.0.0/24 range. What will be the result of this request?

A.Denied, because the user does not have s3:GetObject permission on the confidential folder.
B.Allowed, because the Deny statement only applies to HTTPS.
C.Allowed, because the source IP is within the allowed range.
D.Denied, because the request uses HTTP and the Deny statement blocks it.
AnswerD

This is correct because an HTTP request sets the aws:SecureTransport context key to false, and the Deny statement is scoped to exactly that condition. The policy likely contains an Allow for the S3 action on the folder, but the explicit Deny for non-secure transport takes precedence under AWS's evaluation logic. As a result, the user's GET request over HTTP is denied, while the same request sent over HTTPS would be allowed if the other permissions match.

Why this answer

The IAM policy includes a Deny statement that blocks s3:GetObject when the request is not over HTTPS (aws:SecureTransport is false). Since the request uses HTTP, the condition evaluates to true and the explicit Deny overrides any Allow. Therefore the request is denied regardless of the source IP being in the allowed range.

Exam trap

DOP-C02 often tests the misconception that an Allow with matching IP or resource conditions can override an explicit Deny, when in fact explicit Deny always wins — candidates must remember the evaluation order.

How to eliminate wrong answers

Option A is wrong because the user does have s3:GetObject permission on the confidential folder via an Allow statement — the denial is due to the transport condition, not missing permissions. Option B is wrong because the Deny statement applies to non-HTTPS (HTTP) requests, not HTTPS; the condition aws:SecureTransport: false matches HTTP, so the Deny blocks HTTP, not HTTPS. Option C is wrong because while the source IP is within the allowed range, the explicit Deny for non-secure transport takes precedence over any Allow, so the IP condition does not save the request.

139
MCQhard

A company has a VPC with public and private subnets. An EC2 instance in the private subnet needs to download patches from the internet but must not be directly accessible from the internet. Which configuration allows this?

A.Set up a VPN connection to the company's on-premises network and route traffic through it.
B.Deploy a NAT gateway in a public subnet and route the private subnet's traffic through it.
C.Deploy a bastion host in the public subnet and configure the instance to use it.
D.Attach an internet gateway to the VPC and add a route to the private subnet route table.
AnswerB

Deploying a NAT gateway in a public subnet is the correct solution because it allows instances in a private subnet to initiate outbound IPv4 traffic to the internet while blocking any unsolicited inbound connections. A NAT gateway is a highly available, managed service that resides in a public subnet with an Elastic IP; the private subnet's route table simply adds a 0.0.0.0/0 route pointing to the NAT gateway. This preserves the instance's private reachability and satisfies the requirement without exposing it publicly.

Why this answer

A NAT gateway deployed in a public subnet allows instances in private subnets to initiate outbound traffic to the internet while preventing inbound connections from the internet. This matches the requirement for downloading patches without direct accessibility. Option B is correct.

Option A is incorrect because a VPN connection provides access to an on-premises network, not general internet access. Option C is incorrect because a bastion host provides SSH/RDP access to instances, not outbound internet connectivity for patch downloads. Option D is incorrect because attaching an internet gateway and adding a route to the private subnet route table would make the instances directly accessible from the internet, violating the requirement.

140
MCQeasy

A DevOps engineer needs to securely store and automatically rotate database credentials for a MySQL RDS instance. The credentials should be accessible to a Lambda function without hardcoding them. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.IAM roles for EC2
AnswerB

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating database credentials. It provides native integration with RDS, allowing you to configure automatic rotation on a schedule with a managed Lambda rotation function that updates credentials in both Secrets Manager and RDS. Fine-grained IAM policies can restrict access to specific secrets, and the service also supports cross-account access, making it the correct answer for securely storing and auto-rotating RDS credentials.

Why this answer

AWS Secrets Manager is the correct service because it allows you to store secrets, automatically rotate them for supported RDS databases, and retrieve them programmatically via the Lambda runtime using the Secrets Manager API. AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation for RDS. AWS KMS is used for managing encryption keys, not storing secrets.

IAM roles for EC2 provide permissions to EC2 instances but cannot store credentials.

141
Multi-Selecthard

Which THREE of the following are valid methods to enforce encryption at rest for Amazon EBS volumes? (Choose three.)

Select 3 answers
A.Enable EBS encryption by default in the account.
B.Use the AWS CLI to encrypt an existing volume in place.
C.Encrypt the volume when creating it through the AWS Management Console.
D.Attach the volume to an EC2 instance and use OS-level encryption.
E.Create an unencrypted snapshot of the volume, copy it with encryption, and create a new volume from the encrypted snapshot.
AnswersA, C, E

Enabling EBS encryption by default at the account level is a valid method because it automatically encrypts all new EBS volumes created in the account, using either the AWS managed key or a customer-managed KMS key. This setting is region-scoped and applies to volumes created from unencrypted snapshots when the snapshot is copied with encryption, but it does not retroactively encrypt existing unencrypted volumes. It is a control-plane safeguard that ensures any volume provisioned after enabling the setting is encrypted at rest without requiring per-volume configuration.

Why this answer

Enabling EBS encryption by default at the account level ensures all new volumes are encrypted. You can also encrypt volumes when creating them via the console or CLI. You cannot encrypt an existing volume directly; you must create a snapshot, copy it with encryption, and create a new volume.

Attaching a volume does not encrypt it.

142
MCQhard

A company has a requirement to store audit logs for 7 years. The logs are currently stored in Amazon S3 and are accessed infrequently. Which storage class provides the lowest cost while meeting the retention requirement?

A.S3 Intelligent-Tiering
B.S3 Standard
C.S3 Glacier Deep Archive
D.S3 One Zone-Infrequent Access
AnswerC

S3 Glacier Deep Archive is the lowest-cost storage class in S3, priced at approximately $0.00099 per GB-month, specifically designed for long-term retention of data expected to be accessed at most once per year. With a standard retrieval time of 12-48 hours, it is well suited for compliance archives like audit logs that must be retained for 7 years but rarely accessed. The 180-day minimum storage duration is irrelevant when the retention period is 84 months, and the storage cost is a fraction of even S3 Glacier Flexible Retrieval.

Why this answer

S3 Glacier Deep Archive is the lowest-cost storage class designed for long-term retention of data that is accessed rarely, with a minimum storage duration of 180 days. It meets the 7-year audit log retention requirement at the lowest cost among the options. It provides retrieval times of 12 hours, which is acceptable for infrequently accessed audit logs.

Exam trap

DOP-C02 often tests the misconception that S3 One Zone-IA or Intelligent-Tiering is the cheapest for long-term archival, but Glacier Deep Archive is specifically designed for the lowest cost at the expense of retrieval time.

How to eliminate wrong answers

Option A is wrong because S3 Intelligent-Tiering automatically moves data between access tiers but does not offer the lowest cost for long-term archival; it is designed for data with unknown or changing access patterns. Option B is wrong because S3 Standard is optimized for frequently accessed data and is the most expensive option for long-term storage. Option D is wrong because S3 One Zone-IA is for infrequently accessed data but stores data in a single Availability Zone and is not as cost-effective as Glacier Deep Archive for long-term retention; it also lacks the durability of multi-AZ storage.

143
MCQmedium

A DevOps team is deploying a web application on EC2 instances behind an ALB. The application must authenticate users using an external identity provider (IdP) that supports SAML 2.0. Which solution provides the simplest integration with the ALB?

A.Use Amazon Cognito user pools with SAML federation and integrate with ALB
B.Use AWS CloudFront with Lambda@Edge to validate SAML tokens
C.Install a SAML service provider library on each EC2 instance
D.Configure the ALB to use an SAML identity provider for authentication
AnswerD

Configuring the ALB to use an SAML identity provider lets the load balancer act as the relying party, terminating the SAML exchange at the edge of the AWS network. When an unauthenticated user requests a protected target group, the ALB redirects to the IdP, validates the returned assertion, sets an encrypted session cookie, and forwards the authenticated session details to the backend as HTTP headers. This makes authentication transparent to the EC2 instances, so no code changes are required and security is centralized at one access point.

Why this answer

The Application Load Balancer (ALB) natively supports SAML 2.0 identity provider (IdP) authentication. This allows the ALB to offload user authentication at the edge, validating SAML assertions directly and forwarding authenticated requests to the target EC2 instances without any application-level changes. This is the simplest integration as it requires no additional infrastructure or code on the EC2 instances.

Exam trap

The trap here is that candidates often overcomplicate the solution by assuming they need a separate identity service like Cognito or custom code, when the ALB itself can directly integrate with any SAML 2.0 IdP, making it the simplest and most AWS-native choice.

How to eliminate wrong answers

Option A is wrong because Amazon Cognito user pools with SAML federation require additional configuration and management of a Cognito user pool, adding unnecessary complexity when the ALB can directly authenticate against the external SAML IdP. Option B is wrong because AWS CloudFront with Lambda@Edge to validate SAML tokens is overly complex and not designed for SAML token validation; Lambda@Edge is better suited for lightweight request/response transformations, not full SAML assertion parsing and validation. Option C is wrong because installing a SAML service provider library on each EC2 instance requires application-level changes, certificate management, and session handling, which is more complex and less scalable than using the ALB's built-in SAML authentication.

144
Multi-Selecthard

A DevOps team is designing a solution to encrypt data at rest for an Amazon RDS for MySQL database. Which TWO actions should the team take? (Choose TWO.)

Select 2 answers
A.Enable encryption after creating the RDS instance by modifying the instance
B.Enable SSL/TLS for the RDS instance
C.Use AWS KMS to create a customer managed key and assign it to the RDS instance
D.Enable encryption at rest when creating the RDS DB instance
E.Store the database files in an encrypted S3 bucket
AnswersC, D

Assigning a customer managed key from AWS KMS to the RDS instance enables storage-level encryption of the underlying MySQL data volumes, satisfying the data-at-rest requirement. RDS integrates natively with KMS, so the DB instance, automated backups, read replicas and snapshots are all encrypted under that key.

Why this answer

Option D is correct because Amazon RDS encryption at rest must be enabled at the moment the DB instance is created — you select 'Enable encryption' in the create-database workflow, and RDS then encrypts the underlying storage, automated backups, read replicas, and snapshots with the chosen KMS key. Option C is correct because RDS encryption at rest is implemented through AWS KMS, so the team should create a customer managed key (CMK) in KMS and assign it to the DB instance during creation to control key rotation, policies, and audit via CloudTrail. Option A is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must restore from a snapshot into a new encrypted instance.

Option B is wrong because SSL/TLS secures data in transit between clients and the DB, not data at rest on storage. Option E is wrong because RDS manages its own storage volumes and does not store database files in an S3 bucket that you can encrypt.

Exam trap

The trap is assuming RDS encryption can be toggled on after creation like a parameter change; in reality it is set only at creation, and candidates must also distinguish at-rest encryption (KMS) from in-transit encryption (SSL/TLS).

145
MCQmedium

A security audit reveals that an S3 bucket contains objects that are not encrypted. The bucket is configured with default encryption using SSE-S3. What is the most likely reason that objects are unencrypted?

A.The objects were uploaded with server-side encryption using AWS KMS
B.The bucket policy denies SSE-S3 encryption
C.The objects were uploaded before default encryption was enabled
D.The objects were uploaded with SSE-C
AnswerC

S3 default encryption is a bucket-level setting that applies only to objects uploaded after the setting is enabled; it has no retroactive effect on objects that already exist. If the audit found unencrypted objects, the most plausible cause is that these objects were written before the bucket's default encryption was turned on, leaving them in their original, unencrypted state. Enabling default encryption at a later time does not trigger a re-encryption of existing data unless a separate process, such as S3 Batch Operations, is explicitly run.

Why this answer

S3 default encryption (SSE-S3) applies only to objects uploaded after the setting is enabled; it does not retroactively encrypt existing objects. Therefore, objects that appear unencrypted were most likely uploaded before default encryption was turned on. This is a common audit finding in buckets with historical data.

Exam trap

The trap is forgetting that default encryption is not retroactive — candidates often assume enabling it encrypts all objects, including pre-existing ones, which leads them to pick policy-based or KMS-related wrong answers.

How to eliminate wrong answers

Option A is wrong because SSE-KMS still results in encrypted objects — the audit would not flag them as unencrypted. Option B is wrong because bucket policies cannot deny SSE-S3 encryption in a way that leaves objects unencrypted; if a policy blocked encryption, the upload would fail, not store plaintext. Option D is wrong because SSE-C also encrypts objects (with customer-provided keys), so they would not be flagged as unencrypted.

146
MCQeasy

A company has an Amazon RDS for MySQL database that stores sensitive data. The security team requires encryption at rest and in transit. Which combination of options meets these requirements?

A.Use AWS Certificate Manager to issue a certificate for the RDS instance
B.Place the RDS instance in a private subnet and use VPC peering
C.Enable encryption at rest on the RDS instance and enforce SSL connections
D.Use AWS KMS to encrypt the database before inserting data and decrypt on read
AnswerC

Enabling RDS encryption at rest encrypts the underlying storage, automated backups, snapshots, and read replicas using AWS KMS AES-256 encryption, satisfying the data-at-rest requirement. Enforcing SSL connections (for example, by setting rds.force_ssl=1 or requiring ssl-mode in the client) encrypts data between the application and the database, covering data in transit. Note that enabling encryption at rest on an existing unencrypted MySQL instance requires restoring from an encrypted snapshot rather than modifying the instance in place, but together these controls fully address the stated security need.

Why this answer

Enabling encryption at rest on the RDS instance (via KMS) and enforcing SSL/TLS connections satisfies both requirements: encryption at rest protects data on disk, and SSL enforcement encrypts data in transit between the client and the database. RDS supports encryption at rest through KMS keys and SSL enforcement via parameter group settings (e.g., require_secure_transport for MySQL).

Exam trap

DOP-C02 often tests the distinction between encryption at rest and in transit — candidates pick network isolation (private subnet, VPC peering) or client-side KMS encryption, missing that RDS encryption at rest plus SSL enforcement is the correct combination.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager issues certificates for TLS termination on load balancers and CloudFront, not for RDS encryption at rest — it does not address data-at-rest encryption. Option B is wrong because a private subnet and VPC peering provide network isolation, not encryption — data at rest remains unencrypted and in-transit traffic within the VPC is not necessarily encrypted. Option D is wrong because client-side encryption with KMS before inserting data is application-level encryption, not RDS encryption at rest, and it does not enforce encryption in transit — it also complicates querying and is not the standard RDS approach.

147
Multi-Selectmedium

Which TWO actions can be taken to secure an Amazon S3 bucket that contains confidential data? (Choose TWO.)

Select 2 answers
A.Enable S3 Default Encryption.
B.Enable S3 Transfer Acceleration.
C.Enable S3 Cross-Region Replication.
D.Enable S3 Versioning.
E.Enable S3 Block Public Access.
AnswersA, E

S3 Default Encryption ensures that every object written to the bucket is automatically encrypted at rest, using either SSE-S3 (AES-256) or SSE-KMS (customer-managed KMS keys); SSE-C is not supported for default encryption. This protects the confidentiality of data at rest and helps satisfy compliance frameworks that mandate encryption. It is a direct security control for data confidentiality, but it does not control who can access the data.

Why this answer

Correct options: A and E. Option A: S3 Default Encryption ensures data is encrypted at rest automatically, a key security measure. Option E: S3 Block Public Access prevents public exposure of the bucket and its objects, a key security measure.

Option B (Transfer Acceleration) is for speed, not security. Option C (Cross-Region Replication) is for disaster recovery, not security. Option D (Versioning) helps with recovery from accidental deletions/overwrites, but does not directly secure data from unauthorized access.

148
MCQmedium

Refer to the exhibit. A security engineer finds this CloudTrail log entry. What is the most likely security concern?

A.The bucket is now publicly accessible
B.The bucket policy grants the root user full access
C.The root user performed an action that should have been done by an IAM user
D.The bucket policy allows only authenticated users to read objects
AnswerA

The CloudTrail event shows an s3:PutBucketPolicy call containing 'Principal': '*' and 'Effect': 'Allow' for 's3:GetObject'. That statement explicitly permits anonymous, unauthenticated access to all objects in the bucket. Since no condition restricts the requester and S3 object ownership permits the bucket owner to apply the policy, the bucket is now publicly accessible and every object is readable by anyone with the URL.

Why this answer

The CloudTrail log entry shows a PutBucketPolicy action that sets a bucket policy with principal '*', granting public read access to all objects in the bucket. This is a security concern because the bucket becomes publicly accessible, allowing anyone on the internet to read objects. Option A is correct because the bucket policy makes the bucket publicly accessible.

Option B is incorrect because the bucket policy does not grant the root user full access; it grants public access. Option C is incorrect because the action is performed by an IAM user (the user field shows 'arn:aws:iam::123456789012:user/admin'), not the root user. Option D is incorrect because the policy allows all principals (public) to read objects, not just authenticated users.

149
MCQmedium

A company is using AWS CodeBuild as part of its CI/CD pipeline. The build projects need to access a private Amazon ECR repository to pull Docker images. What is the MOST secure way to grant CodeBuild access to ECR?

A.Configure a VPC endpoint for ECR and allow CodeBuild to connect through it.
B.Store ECR credentials in AWS Systems Manager Parameter Store and retrieve them in the buildspec.
C.Create a service role for CodeBuild with an IAM policy that grants ECR pull access.
D.Use the AWS CLI to retrieve an ECR authorization token and pass it to Docker.
AnswerC

Creating a service role for CodeBuild and attaching an IAM policy with ECR pull permissions is the proper way to grant access. The service role is assumed by the CodeBuild build, and actions such as ecr:GetAuthorizationToken, ecr:BatchGetImage, and ecr:GetDownloadUrlForLayer allow Docker to pull the image. This approach uses temporary credentials and follows least-privilege principles, making it both secure and auditable. It is the only solution that directly addresses the permission requirement.

Why this answer

CodeBuild can assume an IAM service role with a policy that grants pull access to the ECR repository. This is the most secure approach because it avoids static credentials and leverages AWS identity and access management. Option A is wrong: a VPC endpoint provides private network connectivity to ECR but does not grant access; IAM permissions are still required.

Option B is wrong: storing ECR credentials in Parameter Store introduces static credentials that must be managed and rotated, making it less secure than using an IAM role. Option D is wrong: using the AWS CLI to retrieve an authorization token requires managing temporary credentials and is more complex; the service role approach is simpler and more secure.

150
MCQmedium

A company's security team requires that all API calls to AWS are logged for audit purposes. Which service should be enabled to capture and store these logs?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon VPC Flow Logs
AnswerA

AWS CloudTrail is the governance, compliance, and audit service that continuously logs every API call made to AWS across the entire account. Each event records the caller identity, source IP address, request parameters, and response elements, which directly satisfies the security team's requirement to audit all API activity. CloudTrail can also deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for long-term retention and automated analysis. It is the definitive service for answering who, what, and when regarding AWS API usage.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to log all API calls made to the AWS environment, including calls made via the AWS Management Console, AWS SDKs, command line tools, and higher-level AWS services. CloudTrail captures the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements, storing this information in a log file that can be delivered to an Amazon S3 bucket for long-term audit storage. This directly meets the security team's requirement to capture and store all API calls for audit purposes.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs with CloudTrail because both involve 'logging', but CloudWatch Logs is for application and system logs (e.g., from EC2 or Lambda), while CloudTrail is exclusively for AWS API call logs, and the question explicitly asks for 'API calls to AWS'.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because CloudWatch Logs is a service for monitoring, storing, and accessing log files from AWS resources (like EC2 instances, Lambda functions, or custom applications), not for capturing AWS API calls themselves; it can ingest CloudTrail logs as a data source but is not the primary service for API call logging. Option C (AWS Config) is wrong because AWS Config is a service that evaluates and records resource configuration changes and compliance over time, not the API calls that triggered those changes; it provides a configuration history but does not log the API requests. Option D (Amazon VPC Flow Logs) is wrong because VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC (e.g., source/destination IP, ports, protocol), not AWS API calls; it is a network-level logging feature, not an API-level audit trail.

← PreviousPage 2 of 3 · 203 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.