Courseiva

CCNA Security and Compliance Questions

53 of 203 questions · Page 3/3 · Security and Compliance · Answers revealed

151
MCQhard

An organization uses AWS Key Management Service (KMS) with customer-managed keys. The security policy requires automatic key rotation every year. A DevOps engineer notices that the key material is not rotating as expected. What is the most likely cause?

A.The key was created by importing key material; automatic rotation is not supported for imported keys.
B.The key must be re-imported annually to enable rotation.
C.The key is not enabled for rotation due to a billing limit.
D.The key is in a 'Pending Deletion' state and cannot be rotated.
AnswerA

An AWS KMS customer master key with imported key material (Origin: EXTERNAL) cannot have automatic key rotation enabled, because rotation relies on the key material being generated and managed within AWS KMS. The import mechanism bypasses KMS's managed backing keys, so the service cannot automatically replace the backing key. To rotate such a key, you must manually create a new CMK or import new key material into the existing CMK.

Why this answer

Automatic key rotation is not supported for imported key material. Option B is wrong because KMS does not charge extra for automatic rotation. Option C is wrong because KMS does not require re-importing for rotation; it's simply not available.

Option D is wrong because the key state does not prevent rotation.

152
MCQmedium

A company stores sensitive customer data in an S3 bucket. The security team requires that all data be encrypted at rest using customer-managed KMS keys. Additionally, any attempt to upload an unencrypted object must be denied. Which S3 bucket policy should be used?

A.Deny s3:PutObject unless the request includes s3:x-amz-server-side-encryption: true
B.Allow s3:PutObject with condition s3:x-amz-server-side-encryption: AES256
C.Allow s3:PutObject with condition kms:EncryptionContext: department:finance
D.Deny s3:PutObject unless the request includes s3:x-amz-server-side-encryption: aws:kms
AnswerD

This explicit Deny is the correct approach because it denies any PutObject that does not include the x-amz-server-side-encryption header with the value 'aws:kms'. The value 'aws:kms' is the algorithm identifier for SSE-KMS, ensuring all uploaded objects are encrypted with a KMS-managed key. Because it is an explicit deny, even if another policy allows an unencrypted upload, this deny overrides it. This is the standard pattern for enforcing KMS encryption across an S3 bucket.

Why this answer

The condition 's3:x-amz-server-side-encryption':'aws:kms' in a Deny statement ensures that only requests with SSE-KMS encryption are allowed, blocking unencrypted uploads or uploads with other encryption types. Option A is wrong because 'true' is not a valid encryption type; the correct value is 'aws:kms'. Option B is wrong because it allows SSE-S3 (AES256), not KMS encryption.

Option C is wrong because it checks a KMS encryption context rather than the encryption header, and it does not deny unencrypted uploads.

153
Multi-Selecthard

A company is migrating to AWS and needs to comply with PCI DSS. They must encrypt all data at rest and in transit. Which THREE services or features should they use?

Select 3 answers
A.Elastic Load Balancing (ELB) with TLS termination.
B.AWS CloudTrail to log all API calls.
C.Amazon S3 server-side encryption (SSE-S3) for S3 objects.
D.AWS Key Management Service (KMS) to manage encryption keys.
E.AWS WAF to protect web applications.
AnswersA, C, D

A TLS-enabled ELB (ALB or NLB) terminates the TLS/SSL handshake with clients, decrypting traffic at the AWS edge and thereby providing the cryptographic controls required for cardholder data in transit under PCI DSS Requirement 4. It also allows you to attach an AWS Certificate Manager certificate and optionally re-encrypt traffic to backend targets, so the load balancer is a correct service for securing communications.

Why this answer

Elastic Load Balancing (ELB) with TLS termination ensures encryption of data in transit between clients and the load balancer, which is a PCI DSS requirement for protecting cardholder data over public networks. By terminating TLS at the ELB, you can offload the cryptographic overhead while maintaining compliance with the encryption-in-transit mandate.

Exam trap

The trap here is that candidates often confuse compliance-related services (like CloudTrail for logging or WAF for security) with encryption-specific services, leading them to select options that are valid for security but do not directly satisfy the encryption-at-rest and encryption-in-transit mandates of PCI DSS.

154
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The pipeline must scan container images for vulnerabilities before deploying to Amazon ECS. Which service should the engineer use to perform the vulnerability scan?

A.AWS WAF
B.Amazon ECR image scanning
C.AWS Config
D.Amazon GuardDuty
AnswerB

Amazon ECR image scanning automatically checks container images for known vulnerabilities (CVEs) by integrating with Amazon Inspector. In a CI/CD pipeline, you can invoke a scan after pushing an image to ECR, then retrieve findings via an API and block the deployment if critical vulnerabilities exist. This directly satisfies the requirement to identify known security vulnerabilities in images before they are deployed.

Why this answer

Amazon ECR image scanning is the correct service to perform vulnerability scans on container images before deployment to Amazon ECS. ECR provides both basic and enhanced scanning (using Amazon Inspector) that can identify vulnerabilities in container images. This integrates seamlessly with CI/CD pipelines to scan images as part of the build process.

Exam trap

DOP-C02 often tests the distinction between security services; candidates may confuse AWS WAF, GuardDuty, or Config with vulnerability scanning, but only ECR (or Inspector) provides container image scanning.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that protects against web exploits, not container vulnerabilities. Option C is wrong because AWS Config is a configuration auditing service, not a vulnerability scanner. Option D is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it does not scan container images for vulnerabilities.

155
MCQhard

A company is deploying a multi-tier application on AWS. The web tier must be publicly accessible, but the application tier must only be accessible from the web tier. The database tier should not be accessible from the internet at all. Which combination of security groups and network ACLs should be used?

A.Use security groups: allow 0.0.0.0/0 on all ports to web tier, allow all traffic between all instances.
B.Place all instances in the same security group with inbound rules allowing only ports 80/443 from 0.0.0.0/0.
C.Use security groups: allow 0.0.0.0/0 on port 80/443 to web tier, allow web tier security group to app tier, allow app tier security group to database tier.
D.Use network ACLs: allow 0.0.0.0/0 on port 80/443 to web subnet, allow web subnet to app subnet, allow app subnet to database subnet.
AnswerC

This is the correct multi-tier security group design because it enforces least privilege with instance-level granularity. The web tier security group allows only HTTP/S from the internet, the app security group allows traffic only from the web security group (not from any IP or CIDR), and the database security group allows only from the app security group. Using security group references instead of CIDR blocks means that any instance bearing the web SG is automatically allowed to reach the app tier, which makes scaling and instance replacement seamless without updating rules. This approach is stateful, so responses are automatically allowed, and it is far more secure than subnet-level NACL rules, which are stateless and cannot distinguish between instances within the same subnet.

Why this answer

The correct approach is to use security groups that enforce least privilege: allow public access to the web tier on ports 80/443, allow the web tier security group to access the app tier, and allow the app tier security group to access the database tier. This creates a chain of trust where each tier only accepts traffic from the previous tier.

Exam trap

DOP-C02 often tests the difference between security groups and network ACLs; candidates may choose network ACLs for instance-level control or forget that security groups can reference other security groups.

How to eliminate wrong answers

Option A is wrong because it allows all traffic between all instances and opens all ports to the web tier, violating least privilege. Option B is wrong because placing all instances in the same security group with only ports 80/443 open would not allow the app tier to communicate with the database tier on other ports, and it does not isolate tiers. Option D is wrong because network ACLs are stateless and subnet-level; while they can be used, the question asks for a combination of security groups and network ACLs, but option D only uses network ACLs and does not provide the granular instance-level control that security groups offer.

Moreover, the correct answer specifically uses security groups, which are stateful and better suited for this scenario.

156
Multi-Selectmedium

A DevOps engineer is tasked with encrypting data at rest for an Amazon RDS for MySQL database. Which TWO methods can achieve this?

Select 2 answers
A.Enable encryption when creating the DB instance using a customer-managed KMS key.
B.Enable encryption when creating the DB instance using the AWS managed KMS key.
C.Use the default RDS encryption with a customer-managed key without KMS.
D.Enable encryption on an existing unencrypted DB instance by modifying the instance.
E.Use client-side encryption with the RDS SDK.
AnswersA, B

Selecting encryption at DB instance creation with a customer-managed KMS key encrypts the underlying storage, snapshots and read replicas. This satisfies the data-at-rest constraint while giving the organisation control over key rotation and revocation, which an AWS managed key does not provide.

Why this answer

Option A is correct because when you create an RDS for MySQL DB instance you can enable storage encryption and choose a customer-managed AWS KMS key, which RDS uses to encrypt the underlying EBS storage, snapshots, and read replicas. Option B is also correct because RDS supports selecting the AWS managed KMS key (aws/rds) at creation time to encrypt the DB instance's storage, so encryption at rest is achieved without managing a custom key. Option C is wrong because RDS encryption always uses AWS KMS keys; there is no 'default RDS encryption with a customer-managed key without KMS.' Option D is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must encrypt a snapshot and restore it to a new encrypted instance.

Option E is wrong because client-side encryption with the RDS SDK is not a supported RDS at-rest encryption method for the database storage; RDS at-rest encryption is handled by KMS-backed storage encryption.

Exam trap

The trap is thinking that encryption can be enabled on an existing unencrypted RDS instance by modifying it, or that client-side encryption is a valid method for RDS at-rest encryption. Candidates might also confuse AWS managed keys with customer-managed keys, but both are valid for encryption. The key is to remember that encryption must be enabled at creation time, and you can choose either key type.

157
MCQmedium

A company uses AWS Organizations with SCPs to restrict access to services. The security team needs to ensure that no IAM user or role in any account can create or modify VPCs. Which SCP should be applied to the root OU?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:ModifyVpc","Resource":"*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:CreateVpc","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}
AnswerC

This SCP correctly denies both ec2:CreateVpc and ec2:ModifyVpc in a single Deny statement. Because an explicit Deny in an SCP overrides any Allow from IAM policies or other SCPs, this creates a hard boundary that blocks both creation and modification of VPCs across all accounts in the organization. The array format properly lists both actions to ensure complete coverage of the intended restriction.

Why this answer

It denies both the ec2:CreateVpc and ec2:ModifyVpc actions, which covers all operations that could create or modify VPCs. A service control policy (SCP) with a Deny effect overrides any Allow permissions, ensuring that no IAM user or role in any account under the root OU can perform these actions, even if attached IAM policies grant them.

Exam trap

The trap here is that candidates often focus on only one action (Create or Modify) and forget that both are needed to fully prevent VPC creation and modification, or they mistakenly think an Allow SCP can restrict access when SCPs are primarily used for Deny boundaries.

How to eliminate wrong answers

Option A is wrong because it only denies ec2:ModifyVpc, leaving the ec2:CreateVpc action unblocked, so users could still create new VPCs. Option B is wrong because it only denies ec2:CreateVpc, leaving ec2:ModifyVpc unblocked, so existing VPCs could still be modified. Option D is wrong because an Allow statement in an SCP does not restrict access; SCPs are used to deny or allow permissions, but an Allow SCP does not override other Deny policies and, more importantly, does not prevent the actions—it would actually permit them, which is the opposite of the security team's requirement.

158
MCQmedium

A DevOps engineer needs to securely store database credentials for an application running on EC2. The credentials must be rotated automatically every 30 days. Which solution meets these requirements?

A.Use AWS Secrets Manager to store the credentials and configure automatic rotation with the RDS rotation Lambda blueprint.
B.Store credentials in AWS Systems Manager Parameter Store and use a Lambda function to rotate them.
C.Store credentials in an S3 bucket encrypted with KMS and use S3 Lifecycle policies to rotate the objects.
D.Use IAM roles to grant the EC2 instance access to the database, eliminating the need for credentials.
AnswerA

AWS Secrets Manager is designed for managing database credentials and provides native automatic rotation. Its RDS rotation Lambda blueprint creates a Lambda function that updates the secret and the database user password on a defined schedule, without application changes. The service also tracks secret versions and supports KMS encryption, making it the secure, fully managed choice for this requirement.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, managing, and automatically rotating database credentials. It provides a built-in RDS rotation Lambda blueprint that can be configured to rotate credentials every 30 days without custom code. This fully managed rotation capability meets the requirement for automatic, scheduled rotation with minimal operational overhead.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store's ability to store secrets (with SecureString) with the automatic rotation capability, but Parameter Store lacks built-in rotation scheduling and requires custom Lambda code, making Secrets Manager the only fully managed solution for automatic credential rotation.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store does not natively support automatic rotation of credentials; while you can use a Lambda function to rotate them, this requires custom development and lacks the built-in rotation scheduling and integration with RDS that Secrets Manager provides. Option C is wrong because S3 Lifecycle policies are designed for object expiration and transition, not for rotating credential values; they cannot update the content of an object or trigger a credential change. Option D is wrong because IAM roles grant permissions to AWS services, not to databases; while IAM database authentication is supported for RDS (using an auth token), it eliminates the need for static credentials but does not involve rotating stored credentials every 30 days, and the question explicitly requires storing and rotating credentials.

159
MCQhard

A company runs a containerized application on Amazon ECS with Fargate. The application needs to access an S3 bucket. The Security team requires that the application never uses long-term credentials and that access is scoped to the specific ECS task. Which approach should be used?

A.Embed the IAM user credentials in the container image
B.Store AWS access keys in AWS Secrets Manager and retrieve them at runtime
C.Use an IAM role for the EC2 instance if using EC2 launch type
D.Create an IAM role for the ECS task and reference it in the task definition
AnswerD

Create an IAM role that defines the exact AWS API permissions the container needs, then specify that role in the task definition using the taskRoleArn parameter. The ECS agent—on Fargate or EC2—assumes this role on behalf of the task and exposes temporary credentials to the container via the ECS credential endpoint, so the SDK automatically rotates them. This is the recommended pattern because it scopes credentials to a single task, follows least privilege, and eliminates the need to manage any static access keys.

Why this answer

ECS tasks using the Fargate launch type can assume an IAM role that is specified in the task definition. This IAM role provides temporary credentials via the ECS task metadata endpoint, ensuring that the application never uses long-term credentials and that permissions are scoped precisely to that task. The Security team's requirements are fully met by this approach.

Exam trap

The trap here is that candidates may confuse the IAM role for the EC2 instance (Option C) with the ECS task role, or assume that Secrets Manager (Option B) is acceptable despite it still using long-term credentials, failing to recognize that Fargate tasks require a task-level IAM role for scoped, temporary access.

How to eliminate wrong answers

Option A is wrong because embedding IAM user credentials in the container image violates the requirement to never use long-term credentials and creates a security risk if the image is compromised. Option B is wrong because while Secrets Manager can securely store AWS access keys, those keys are still long-term credentials, which the Security team explicitly prohibits. Option C is wrong because the question specifies Fargate launch type, not EC2; an IAM role for the EC2 instance would not apply to Fargate tasks, and even with EC2 launch type, it would not scope access to the specific ECS task.

160
MCQmedium

A company uses AWS CodeBuild to build and test code. The build process needs to access a private Amazon RDS database to run integration tests. What is the most secure way to provide database credentials to the build project?

A.Store the credentials as environment variables in the build project configuration.
B.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter.
C.Store the credentials in AWS Secrets Manager and grant the CodeBuild service role permission to retrieve them.
D.Store the credentials in an encrypted S3 bucket and download them during the build phase.
AnswerC

AWS Secrets Manager is purpose-built for securely storing, rotating, and auditing access to secrets, with encryption via KMS at rest and in transit. By assigning the CodeBuild service role an IAM policy that allows secretsmanager:GetSecretValue for the specific secret, you can inject the secret directly into the build environment using the 'secrets-manager' environment variable type in the buildspec, ensuring the actual secret material never appears in logs, the console, or CloudFormation templates. Secrets Manager also provides automatic rotation (e.g., for RDS credentials), CloudTrail API logging for every retrieval, and fine-grained control through resource-based policies, making it the most secure and operationally efficient option for CodeBuild credential management.

Why this answer

AWS Secrets Manager is designed specifically for storing and rotating secrets such as database credentials, and it integrates natively with IAM so you can grant the CodeBuild service role fine-grained permission to retrieve the secret at build time. This avoids hardcoding credentials in the build project and supports automatic rotation, which is the most secure option. The CodeBuild service role can call secretsmanager:GetSecretValue, and the buildspec retrieves the secret dynamically.

Exam trap

DOP-C02 often tests the distinction between Secrets Manager (rotation, native secret management) and Parameter Store SecureString (encryption but no built-in rotation), tricking candidates into choosing the cheaper but less capable option.

How to eliminate wrong answers

Option A is wrong because environment variables in the build project configuration are visible in the CodeBuild console and API to anyone with project read access, and they are not rotated automatically. Option B is wrong because Parameter Store SecureString encrypts the value but does not provide native rotation or the same level of secret-management integration as Secrets Manager, and it is less suited for database credentials that require rotation. Option D is wrong because storing credentials in an S3 bucket, even encrypted, requires managing bucket policies and download logic, and it does not provide rotation or audit trails as cleanly as Secrets Manager.

161
MCQmedium

A company uses AWS Secrets Manager to rotate secrets for an RDS database. The rotation Lambda function fails with a timeout error. What is the most likely cause?

A.The Lambda function's execution role lacks the required IAM permissions.
B.The Lambda function is not configured to access the VPC where the RDS instance resides.
C.The secret rotation schedule is set to less than 24 hours.
D.The Lambda function does not have permission to access the S3 bucket.
AnswerB

For the rotation function to update credentials on RDS, it must be deployed inside the same VPC or have a route to it; if the Lambda function lacks VPC configuration, its ENI never gets a private IP in the RDS subnet. Each invocation then tries to open a socket to the database but has no network path, so it consumes the entire configured timeout and Secrets Manager reports rotation as failed. Merely granting IAM permissions for secretsmanager and RDS does not create network connectivity, so this is the root cause when the error is consistently a timeout rather than an access-denied.

Why this answer

The most likely cause of the timeout error is that the Lambda function is not configured to access the VPC where the RDS instance resides. When Secrets Manager rotates a secret for an RDS database, the rotation Lambda function must connect to the database to update the credentials. If the Lambda function is not attached to the same VPC (or a VPC with proper routing and security group rules), it cannot reach the RDS instance, causing network connection attempts to hang until the function times out.

Exam trap

The trap here is that candidates often confuse IAM permission errors (which produce immediate failures) with network connectivity issues (which cause timeouts), leading them to incorrectly select the IAM role option when the symptom is a timeout rather than an access denied error.

How to eliminate wrong answers

Option A is wrong because IAM permission issues typically result in an access denied error, not a timeout; the Lambda function would fail immediately with a 403 or similar, not hang until the timeout limit. Option C is wrong because the rotation schedule (e.g., every 24 hours or less) does not cause individual rotation executions to timeout; the schedule only controls how often rotation is triggered, not the duration of the Lambda invocation. Option D is wrong because Secrets Manager rotation for RDS does not require S3 bucket access; the Lambda function only needs network connectivity to the database and permissions to call Secrets Manager APIs, not S3.

162
MCQmedium

A DevOps engineer is troubleshooting an issue where an EC2 instance cannot access an S3 bucket. The instance has an IAM role attached with a policy that allows s3:GetObject. The S3 bucket policy explicitly denies access to the instance's role. What is the result?

A.Access is denied only if the bucket is encrypted
B.Access is allowed only if the instance is in the same region
C.Access is allowed because the IAM role allows it
D.Access is denied because the bucket policy explicitly denies
AnswerD

The bucket policy contains an explicit deny statement for the principal or action being attempted, and AWS IAM policy evaluation gives explicit deny statements absolute precedence over any allow statements from identity-based policies, resource-based policies, or permission boundaries. Even though the IAM role allows the s3:GetObject call, the explicit deny in the bucket policy forces the final decision to AccessDenied. This precedence is a deterministic, non-configurable part of AWS's authorization engine.

Why this answer

An explicit deny in any policy overrides any allow. The bucket policy deny takes precedence over the IAM role allow, so access is denied. Evaluation logic is that an explicit deny prevents access.

163
MCQhard

A company has a multi-account AWS environment managed by AWS Organizations. The DevOps team uses AWS CloudFormation StackSets to deploy a standard VPC across all member accounts. The security team has noticed that in some accounts, the VPC is being modified after deployment, allowing inbound SSH access from the internet. The team wants to automatically detect and remediate these changes. The current setup includes: AWS Config enabled in all accounts with a rule that checks for unrestricted SSH access; an SNS topic in the management account that receives compliance change notifications; and a Lambda function in the management account that can remediate by updating the security group rules. However, the remediation is not working consistently. What is the most likely reason, and what is the best solution?

A.The AWS Config rule is not evaluating correctly in member accounts.
B.The Lambda function's IAM role does not have permissions to modify security groups in member accounts.
C.The SNS topic is not delivering messages to the Lambda function due to cross-account access issues.
D.CloudFormation StackSets is overriding the changes, causing a race condition.
AnswerB

Remediation actions in AWS Config require the Lambda function to have an IAM role that is assumable in every member account where the rule runs. When using the AWS-provided remediation action 'AWS-ConfigureSecurityGroupChanges' or a custom Lambda function, that role must include permissions such as ec2:AuthorizeSecurityGroupIngress, ec2:RevokeSecurityGroupIngress, and similar actions scoped to the target security groups. Without those permissions, the Lambda execution fails with an AccessDenied error even though the event was delivered and the function started. This is the most direct cause of the failure because the rule is detecting and triggering correctly, but the remediation cannot modify the resources.

Why this answer

The Lambda function in the management account needs cross-account permissions to modify security groups in member accounts. The most likely issue is that the Lambda function's IAM role does not have the required permissions. The best solution is to use AWS Config conformance packs with remediation actions deployed to each member account, allowing local remediation.

Option A is incorrect because the Config rule itself detects the changes. Option C is incorrect because the SNS topic can deliver messages cross-account with proper permissions, but the remediation fails due to the Lambda role's lack of permissions. Option D is incorrect because StackSets are for initial deployment, not for ongoing compliance.

164
MCQmedium

An S3 bucket has the above bucket policy. What is the effect of this policy?

A.It allows anonymous access to the bucket over HTTPS
B.It denies all access to the bucket regardless of protocol
C.It denies access to the bucket if the request is not sent over HTTPS
D.It allows access only from specific IP addresses
AnswerC

This statement uses 'Deny' with the condition 'aws:SecureTransport': 'false', meaning that any time S3 sees a request to this bucket that did not use TLS/SSL, the condition is satisfied and the explicit deny applies, causing the request to be rejected. HTTPS requests have SecureTransport set to true, so they are not affected by this particular statement and may be allowed or denied based on other applicable policies. This is a standard pattern to enforce HTTPS-only access to S3 buckets.

Why this answer

The bucket policy denies access to the bucket if the request is not sent over HTTPS. This is a common security measure to enforce encryption in transit. The policy likely includes a condition that checks 'aws:SecureTransport' and denies if it is false, meaning any non-HTTPS request is blocked.

Exam trap

DOP-C02 often tests the interpretation of bucket policies with conditions, and candidates may misinterpret a deny for non-HTTPS as a blanket deny or an allow for anonymous access.

How to eliminate wrong answers

Option A is wrong because the policy denies non-HTTPS requests, so it does not allow anonymous access over HTTPS; it may allow HTTPS but not specifically anonymous. Option B is wrong because the policy does not deny all access; it only denies non-HTTPS requests, so HTTPS requests are still allowed. Option D is wrong because the policy does not restrict access based on IP addresses; it focuses on the protocol used.

165
MCQmedium

Refer to the exhibit. A DevOps engineer created an IAM role 'MyLambdaRole' for a Lambda function. The Lambda function needs to write logs to CloudWatch Logs. However, the function is not able to create log streams. What is the most likely missing configuration?

A.The role name is not prefixed with 'AWSLambda'.
B.The role does not have an inline or managed policy that grants permissions for CloudWatch Logs.
C.The role ARN is incorrectly formatted.
D.The trust policy does not allow Lambda to assume the role.
AnswerB

The correct issue is that this Lambda execution role lacks any inline or managed policy granting the required CloudWatch Logs permissions. Without a policy allowing logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, Lambda cannot write execution logs to CloudWatch, even though the trust policy is valid. This will cause runtime failures or missing log output, and is a common misconfiguration.

Why this answer

The IAM role must have an inline or managed policy that grants permissions for CloudWatch Logs actions such as logs:CreateLogStream and logs:PutLogEvents. Option A is incorrect because the role name does not need a prefix; the trust policy is what matters. Option C is incorrect because the role ARN format does not affect log stream creation.

Option D is incorrect because the trust policy allowing Lambda to assume the role is separate from the permissions to write logs; the question states the function is not able to create log streams, which indicates a permissions issue within the role's policies.

166
MCQhard

A company uses AWS CodePipeline to deploy a web application to an Auto Scaling group. The security team requires that all artifacts in the pipeline be encrypted at rest. The pipeline uses an S3 bucket as the artifact store. Which combination of actions should the DevOps engineer take to meet this requirement with minimal operational overhead?

A.Use AWS Certificate Manager to encrypt the artifacts.
B.Enable S3 default encryption with SSE-S3 on the artifact bucket.
C.Use an AWS Lambda function to encrypt artifacts after each pipeline stage.
D.Create a customer-managed KMS key and configure the pipeline to use it for artifact encryption.
AnswerB

Enabling S3 default encryption with SSE-S3 on the CodePipeline artifact bucket automatically encrypts every object with 256-bit AES keys managed by Amazon S3. This is the simplest native approach: once enabled, you need no key management, no pipeline role changes, and no application code modifications. CodePipeline writes artifacts as normal S3 PUTs, so the bucket-level default encryption covers all stages and runs with zero overhead.

Why this answer

Enabling S3 default encryption with SSE-S3 on the artifact bucket is the simplest way to encrypt all objects at rest with minimal operational overhead. SSES3 uses S3-managed keys, requiring no additional key management or permissions. Option A is wrong because AWS Certificate Manager provides TLS certificates, not encryption for S3 objects.

Option C is wrong because using a Lambda function to encrypt artifacts after each stage adds unnecessary complexity and does not automatically encrypt all artifacts, especially existing ones. Option D is wrong because creating a customer-managed KMS key introduces additional overhead for key management and permissions, which is not minimal.

167
MCQeasy

A developer wants to grant an EC2 instance read-only access to a specific S3 bucket. Which AWS mechanism should they use to securely provide credentials to the instance?

A.Set AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables in the AMI.
B.Create an IAM role with the required permissions and attach it to the EC2 instance as an instance profile.
C.Store AWS access keys in the EC2 user data script.
D.Retrieve the credentials from AWS Systems Manager Parameter Store using a custom script.
AnswerB

An IAM role attached as an instance profile is the AWS-recommended mechanism because the EC2 instance automatically assumes the role through the instance metadata service (IMDS), receiving temporary credentials from AWS STS that are valid for a limited duration and refreshed automatically by the SDK or CLI. This eliminates the need to store or manage long-lived access keys while letting you scope the role with a narrowly defined read-only policy, such as allowing only s3:GetObject or ec2:DescribeActions. The instance profile acts as the container for the role, and the per-instance trust policy ensures only instances with that profile can use the role, giving centralized control, easy revocation, and cross-account access when needed.

Why this answer

IAM roles with instance profiles provide temporary, automatically rotated credentials to EC2 instances via the AWS STS service. This eliminates the need to hardcode or store long-term access keys on the instance, adhering to the principle of least privilege and improving security posture.

Exam trap

The trap here is that candidates may think storing credentials in user data or an AMI is acceptable for automation, but the exam emphasizes that any static, long-term credentials on an instance are insecure and violate AWS best practices, whereas IAM roles provide secure, temporary, and automatically rotated credentials.

How to eliminate wrong answers

Option A is wrong because embedding AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY in an AMI creates static, long-term credentials that are difficult to rotate, can be exposed if the AMI is shared or copied, and violate security best practices. Option C is wrong because storing access keys in EC2 user data is insecure—user data is visible to anyone with access to the instance metadata (e.g., via http://169.254.169.254/latest/user-data) and keys are not automatically rotated. Option D is wrong because while Systems Manager Parameter Store can store credentials, it requires the instance to have an IAM role or static keys to retrieve them, and it does not natively provide automatic credential rotation or direct integration with EC2's credential provider chain; a custom script adds complexity and potential security gaps.

168
MCQeasy

A company wants to automatically detect and respond to suspicious activity in their AWS account. Which service should be used to generate alerts based on threat intelligence?

A.Amazon GuardDuty
B.AWS Config
C.Amazon Inspector
D.Amazon CloudWatch
AnswerA

Amazon GuardDuty is a managed threat detection service that continuously analyzes VPC Flow Logs, AWS CloudTrail management events, DNS logs, and, when enabled, EKS audit logs and S3 data events. It uses built-in threat intelligence feeds and machine learning to identify suspicious activity such as unusual API calls, reconnaissance behavior, or cryptocurrency mining, and produces findings that can trigger automated response via Amazon EventBridge. This makes it the purpose-built AWS service for automatically detecting and responding to suspicious activity.

Why this answer

Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity using machine learning, anomaly detection, and integrated threat intelligence feeds. It analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to generate findings and can trigger alerts via CloudWatch Events or Security Hub. This directly matches the requirement to detect and respond to suspicious activity based on threat intelligence.

Exam trap

The trap is conflating security services: candidates often pick Inspector for 'security' or CloudWatch for 'alerts,' but only GuardDuty is purpose-built for threat-intelligence-driven detection of suspicious activity.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it evaluates resource configurations against compliance rules, not threat intelligence or suspicious behavior. Option C (Amazon Inspector) is wrong because it performs vulnerability assessments on EC2 instances and container images, not continuous threat detection based on intelligence feeds. Option D (Amazon CloudWatch) is wrong because it is a monitoring and observability service for metrics, logs, and alarms; it does not natively ingest threat intelligence or generate security findings.

169
Multi-Selectmedium

Which TWO AWS services can be used to monitor and detect unauthorized access to AWS resources? (Choose two.)

Select 2 answers
A.AWS Shield
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS CloudTrail
E.AWS Config
AnswersB, D

Amazon GuardDuty is a continuous threat detection service that ingests and analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs. Using machine learning, anomaly detection, and integrated threat intelligence, it identifies reconnaissance, credential compromise, crypto-mining, and other unauthorized behavior. GuardDuty generates prioritized findings in the console and can trigger automated responses via Amazon EventBridge. Because it actively correlates across logs, it directly fulfills the 'monitor and detect unauthorized access' requirement.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior by analyzing VPC Flow Logs, DNS logs, and AWS CloudTrail management and data events. It uses machine learning and integrated threat intelligence to detect anomalies such as unusual API calls, crypto-mining activity, or compromised credentials, making it a correct choice for detecting unauthorized access.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration changes) with a security monitoring service, but Config does not analyze logs or detect unauthorized access; it only records resource state changes and evaluates compliance rules.

170
MCQeasy

A company wants to centrally manage user access to multiple AWS accounts using federated identity. Which AWS service should be used to create a single sign-on (SSO) solution?

A.AWS IAM Identity Center (AWS SSO)
B.AWS Organizations
C.AWS Directory Service for Microsoft Active Directory
D.Amazon Cognito
AnswerA

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is purpose-built to centrally manage workforce user access and single sign-on across multiple AWS accounts, business applications, and SAML 2.0-enabled apps. It lets you define permission sets that map users or groups to IAM roles in different accounts, and it integrates with identity providers like Active Directory or Okta. This directly addresses the requirement to centrally manage user access to multiple AWS accounts with SSO.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is purpose-built to centrally manage user access and permissions across multiple AWS accounts and applications from a single place. It allows you to create or connect your existing identity source (e.g., Active Directory, Okta, Azure AD) and then define fine-grained permission sets that map users or groups to specific roles in each account, enabling a true single sign-on (SSO) experience without needing to create IAM users in every account.

Exam trap

The trap here is that candidates often confuse AWS Organizations (which manages accounts and policies) with IAM Identity Center (which manages user identities and SSO), or they think that Directory Service alone provides SSO across accounts, when in fact it only provides the directory backend and requires an additional federation service like IAM Identity Center to bridge authentication to multiple AWS accounts.

How to eliminate wrong answers

Option B (AWS Organizations) is wrong because it provides centralized governance and policy management for multiple AWS accounts (e.g., via Service Control Policies), but it does not handle user authentication or SSO; it is a prerequisite for using IAM Identity Center but not the SSO solution itself. Option C (AWS Directory Service for Microsoft Active Directory) is wrong because it is a managed Microsoft AD directory service that can serve as an identity source, but it does not natively provide the multi-account permission management or SSO portal; you would still need IAM Identity Center to federate access across accounts. Option D (Amazon Cognito) is wrong because it is designed for customer-facing identity and access management for web and mobile applications, not for managing workforce access to AWS accounts or providing SSO across multiple AWS accounts.

171
Multi-Selecthard

A company's Security team wants to detect and alert on the creation of IAM users with console access. Which THREE services should be used?

Select 3 answers
A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon GuardDuty
E.Amazon CloudWatch Alarms
AnswersA, B, E

AWS CloudTrail is the authoritative audit service that records management events as API calls, including the CreateUser action that IAM user creation invokes. By enabling CloudTrail, your security team gains a detailed, tamper-evident log of who created which IAM user, from which source IP, and with what permissions. This event data can then be delivered to Amazon CloudWatch Logs for further processing and alerting, making CloudTrail the essential first step in a real-time monitoring pipeline.

Why this answer

CloudTrail logs the CreateUser and CreateLoginProfile API calls. CloudWatch Logs can receive CloudTrail logs and create metric filters. CloudWatch Alarms can trigger on the metric.

Config can track resource changes but not as efficient for alerting on API calls. GuardDuty does not specifically focus on IAM user creation.

172
MCQhard

A DevOps engineer manages a build account where CodeBuild projects run in a VPC to reach an internal artifact repository. The projects must pull a database password from AWS Secrets Manager at build time. The build role's IAM policy already grants secretsmanager:GetSecretValue on the secret ARN, but every build fails with a connection timeout when the AWS CLI attempts the call. The VPC has private subnets, a NAT gateway, and a VPC endpoint for Amazon S3 only. What is the MOST operationally efficient change that lets the builds retrieve the secret while keeping the traffic off the public internet?

A.Modify the build role's trust policy to allow secretsmanager.amazonaws.com to assume it, so the CLI call is authorized inside the VPC.
B.Create an interface VPC endpoint for secretsmanager in the build VPC, and attach a security group that allows HTTPS from the build subnet CIDR.
C.Enable public access on the secret and add an internet gateway route to the private subnet route tables so the CLI can reach the regional endpoint.
D.Add a gateway VPC endpoint for secretsmanager to the route tables of the private subnets so the CLI calls resolve to the endpoint.
AnswerB

This is correct because an interface endpoint (powered by AWS PrivateLink) places an elastic network interface for secretsmanager inside the subnet, so the CodeBuild container reaches the service privately without NAT or internet egress. The endpoint's security group must permit TCP 443 inbound from the build instances, which the scenario's S3 gateway endpoint cannot provide for Secrets Manager.

Why this answer

Interface VPC endpoints use AWS PrivateLink to create private ENIs in the subnet, letting CodeBuild reach Secrets Manager without NAT or internet egress. Because the endpoint is an ENI, its security group must allow inbound HTTPS from the build subnets, and the private DNS name for secretsmanager is resolved locally. Gateway endpoints only serve S3 and DynamoDB, so the existing S3 endpoint cannot cover this call.

Exam trap

The trap here is assuming that the existing Amazon S3 gateway endpoint, or any gateway endpoint type, can be extended to Secrets Manager, when only interface endpoints support that service.

173
MCQeasy

A company uses AWS Secrets Manager to rotate database credentials automatically. The rotation is configured to occur every 30 days. The DevOps engineer notices that the latest secret version is not being used by the application after rotation. The application is an EC2 instance that retrieves the secret using the AWS SDK. The engineer checks the secret and sees that the rotation succeeded and the new version is marked as 'AWSCURRENT'. The EC2 instance role has permissions to retrieve the secret. What is the most likely reason the application is still using the old secret?

A.The application caches the secret value and does not refresh it until the cache expires or the application is restarted.
B.The secret is in a different AWS Region than the application.
C.The EC2 instance does not have permission to call secretsmanager:GetSecretValue.
D.The rotation Lambda function is not updating the secret version label to AWSCURRENT.
AnswerA

The application caches the secret value and does not refresh it until the cache expires or the application is restarted. This is the classic stale-secret problem: even though Secrets Manager's AWSCURRENT label points to the new version, the boto3 or AWS SDK client-side cache still holds the old value. The application will continue to use the previous database credentials until the cache TTL elapses or the process is restarted. This perfectly matches the symptom of a successful retrieval that still yields outdated credentials.

Why this answer

The most likely reason is that the application caches the secret value in memory and does not refresh it until the cache expires or the application restarts. Even though the secret rotation succeeded and the new version is marked AWSCURRENT, the application continues to use the cached old credentials until it re-fetches the secret. This is a common issue with applications that retrieve secrets at startup and hold them.

Exam trap

DOP-C02 often tests the misconception that rotation automatically updates the application; candidates may overlook application-side caching and blame permissions or rotation configuration.

How to eliminate wrong answers

Option B is wrong because the secret being in a different Region would cause retrieval failures, but the question states the EC2 instance role has permissions and the secret is accessible; also, cross-region access is possible if configured. Option C is wrong because the question explicitly states the EC2 instance role has permissions to retrieve the secret. Option D is wrong because the question states the rotation succeeded and the new version is marked AWSCURRENT, so the Lambda is updating the label correctly.

174
Multi-Selecteasy

Which TWO AWS services can be used to monitor for unauthorized API calls in an AWS account? (Choose two.)

Select 2 answers
A.AWS Config
B.Amazon S3
C.Amazon CloudWatch Logs
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersD, E

AWS CloudTrail is the primary service for recording API activity in an AWS account, capturing every management and data event with details like the caller's identity, the action, the resource, and the timestamp. By enabling CloudTrail in all regions and with appropriate event types, you can inspect logs to identify unauthorized attempts, such as failed authentication or IAM policy denials. CloudTrail provides the raw evidence needed for security analysis and is the foundational data source for services like GuardDuty.

Why this answer

AWS CloudTrail (D) is correct because it records every API call made in the account as events, including the identity of the caller, source IP, and time, which lets you detect unauthorized or suspicious API activity. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management and data events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to surface findings such as anomalous or unauthorized API calls. AWS Config (A) is not the right choice because it evaluates resource configuration compliance and records configuration changes, not the authorization status of API callers.

Amazon S3 (B) is only object storage and does not monitor API activity. Amazon CloudWatch Logs (C) can store and query log data, but by itself it does not capture or detect unauthorized API calls without CloudTrail as the source.

Exam trap

DOP-C02 often tests whether candidates pick AWS Config (configuration compliance) or CloudWatch Logs (log storage) instead of CloudTrail and GuardDuty for detecting unauthorized API activity.

175
MCQeasy

Refer to the exhibit. This S3 bucket policy allows the root user of account 111122223333 to perform which actions?

A.Change the bucket policy
B.Delete objects from the bucket
C.Read and write objects in the bucket
D.List objects in the bucket
AnswerC

This policy grants the root principal s3:GetObject and s3:PutObject actions on the arn:aws:s3:::bucket/* resource. s3:GetObject allows downloading an object's data and metadata, while s3:PutObject allows uploading a new object or overwriting an existing one. Together, these actions explicitly authorize reading and writing objects inside the bucket, which is exactly what the question asks — making this the correct option.

Why this answer

The S3 bucket policy grants the root user of account 111122223333 permissions for s3:GetObject and s3:PutObject on the bucket's objects, which correspond to reading and writing objects. The policy does not include s3:DeleteObject, s3:ListBucket, or s3:PutBucketPolicy, so those actions are not allowed. Therefore, the root user can read and write objects in the bucket.

Exam trap

DOP-C02 often tests the distinction between object-level and bucket-level S3 permissions — candidates may assume that GetObject/PutObject also implies ListBucket or DeleteObject, which it does not.

How to eliminate wrong answers

Option A is wrong because changing the bucket policy requires s3:PutBucketPolicy, which is not granted in the policy. Option B is wrong because deleting objects requires s3:DeleteObject, which is absent. Option D is wrong because listing objects requires s3:ListBucket on the bucket resource, which is not included — the policy only grants object-level actions.

176
MCQhard

A company has a requirement to rotate database credentials every 30 days for an Amazon RDS for MySQL instance. The credentials are currently stored in AWS Secrets Manager. The DevOps engineer needs to implement automatic rotation without modifying the application code. Which solution should be used?

A.Create a scheduled job that runs every 30 days to update the secret in Secrets Manager with a new password.
B.Store the credentials in AWS Systems Manager Parameter Store and configure automatic rotation using a Lambda function.
C.Use the AWS RDS automatic password rotation feature, which automatically updates the password every 30 days.
D.Configure Secrets Manager to automatically rotate the secret every 30 days using a Lambda rotation function, and have the application retrieve the secret using the Secrets Manager API.
AnswerD

Secrets Manager natively supports rotation for RDS credentials through a managed Lambda function. The rotation function updates the password in the RDS database and then stores the new value in the secret, using staging labels like AWSCURRENT and AWSPENDING to ensure applications can always retrieve valid credentials. The application retrieves the current secret via the Secrets Manager API (for example, GetSecretValue), and effective caching keeps this cost-efficient. This exactly meets the requirement of rotating the database every 30 days while keeping the application functional.

Why this answer

AWS Secrets Manager natively supports automatic rotation of secrets using a Lambda function that updates both the secret in Secrets Manager and the password in the RDS MySQL instance. This solution meets the 30-day rotation requirement without modifying application code, as the application retrieves the current secret via the Secrets Manager API, which automatically handles versioning and caching.

Exam trap

The trap here is that candidates may confuse AWS Secrets Manager's automatic rotation with a simple scheduled update of the secret value, or mistakenly believe that RDS or Parameter Store have built-in rotation capabilities, when in fact only Secrets Manager with a Lambda rotation function provides a fully automated, code-free solution.

How to eliminate wrong answers

Option A is wrong because creating a scheduled job to update the secret in Secrets Manager does not change the password in the RDS instance, leaving the database credential out of sync. Option B is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of database credentials; it lacks the built-in rotation mechanism and Lambda integration that Secrets Manager provides. Option C is wrong because Amazon RDS does not have an automatic password rotation feature; password rotation must be implemented manually or via Secrets Manager with a Lambda function.

177
MCQeasy

A DevOps engineer needs to ensure that all API calls made to AWS are recorded for auditing purposes. Which AWS service should be used?

A.AWS CloudTrail
B.AWS Config
C.Amazon CloudWatch Logs
D.Amazon VPC Flow Logs
AnswerA

AWS CloudTrail is the correct answer because it is the native AWS service designed to record all API activity across your account. Every management event, including calls made by users, roles, or AWS services, is captured with details like the identity of the caller, source IP address, event time, request parameters, and response elements. By creating a trail, you can deliver these audit logs to an S3 bucket for long-term storage and enable CloudTrail Insights to detect anomalous API activity, which directly satisfies the requirement to ensure all API calls are audited.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This provides a complete audit trail of user activity and API usage, which is essential for auditing, security analysis, and compliance requirements.

Exam trap

The trap here is confusing AWS Config (which tracks resource configuration changes) with CloudTrail (which records API calls), as both are used for auditing but serve fundamentally different purposes.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it evaluates and records resource configuration changes over time, not API calls; it tracks resource state and compliance rules, not the API actions that caused changes. Option C (Amazon CloudWatch Logs) is wrong because it aggregates and stores log data from applications and AWS services, but it does not natively capture API call records; it requires CloudTrail to deliver logs to it. Option D (Amazon VPC Flow Logs) is wrong because it captures IP traffic metadata (source/destination IP, ports, protocol) for network interfaces in a VPC, not the API calls made to AWS services.

178
MCQmedium

A company uses AWS KMS to encrypt data in S3. The security team requires that the key material be rotated every 90 days. What should be done to meet this requirement?

A.Create a customer managed key and enable automatic yearly rotation.
B.Use an AWS managed key (SSE-S3) and enable rotation.
C.Use a custom key store with imported key material and enable automatic rotation.
D.Create a customer managed key and manually rotate it every 90 days.
AnswerD

Customer managed keys are the only KMS key type that supports manual rotation, allowing you to create a new key and update aliases as needed at any time. By manually rotating every 90 days, the company can enforce its required rotation policy while keeping the same alias or key ID for applications. This gives full control over rotation frequency, unlike automatic rotation which is fixed at yearly.

Why this answer

AWS KMS customer managed keys support manual rotation, which allows you to rotate the key material every 90 days as required. Automatic key rotation for customer managed keys is only available with a minimum rotation period of 365 days (yearly), so it cannot meet a 90-day requirement. Manual rotation creates a new backing key while retaining the old one for decryption of previously encrypted data, ensuring compliance with the 90-day rotation policy.

Exam trap

The trap here is that candidates assume automatic rotation can be configured to any interval, but AWS KMS only supports automatic rotation with a fixed 365-day period for customer managed keys, so a 90-day requirement forces manual rotation.

How to eliminate wrong answers

Option A is wrong because automatic yearly rotation for customer managed keys has a fixed period of 365 days, which cannot be changed to 90 days. Option B is wrong because AWS managed keys (SSE-S3) do not support user-controlled rotation; they are rotated automatically by AWS but the rotation schedule is not configurable and does not meet a specific 90-day requirement. Option C is wrong because a custom key store with imported key material does not support automatic rotation; you must manually re-import new key material to rotate, and automatic rotation is not available for imported keys.

179
MCQeasy

A company wants to automate patching of EC2 instances running Amazon Linux 2 while ensuring compliance with security policies. Which AWS service should be used?

A.AWS Trusted Advisor
B.Amazon Inspector
C.AWS Config
D.AWS Systems Manager Patch Manager
AnswerD

AWS Systems Manager Patch Manager is a purpose-built capability that automates the process of patching managed instances, whether they are EC2 instances or on-premises servers. It works in tandem with patch baselines, maintenance windows, and rate control to approve, schedule, and install patches, and it also reports patch compliance for the fleet. With the SSM Agent installed, Patch Manager uses a standard SSM document such as AWS-RunPatchBaseline to execute the patch operation, making it the correct choice for automated OS patching.

Why this answer

AWS Systems Manager Patch Manager automates the patching of EC2 instances, including Amazon Linux 2, by using patch baselines to define approved patches and compliance rules. It integrates with maintenance windows and State Manager to schedule and enforce patching, ensuring instances remain compliant with security policies without manual intervention.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (which finds vulnerabilities) with Patch Manager (which fixes them), or assume AWS Config can remediate patches directly, when in reality Config only evaluates compliance and requires a separate automation action (e.g., via Systems Manager Automation) to apply patches.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor is an advisory service that inspects your AWS environment and makes recommendations for cost optimization, performance, security, and fault tolerance, but it does not perform or automate patching of EC2 instances. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances for software vulnerabilities and unintended network exposure, but it does not apply patches or automate the patching process. Option C is wrong because AWS Config is a service that evaluates and records resource configurations against desired policies, enabling compliance auditing and change tracking, but it cannot directly patch instances or execute remediation actions like applying OS updates.

180
Multi-Selecthard

Which THREE measures can be taken to ensure that EC2 instances are compliant with a security policy that requires all instances to be in a VPC with specific tags? (Select THREE.)

Select 3 answers
A.Use AWS Config rules to detect non-compliant instances.
B.Use EC2 Auto Scaling to launch instances only in the correct VPC.
C.Apply an SCP that denies ec2:RunInstances unless the instance is in the correct VPC.
D.Use a custom AWS Lambda function triggered by CloudTrail to tag instances.
E.Use CloudWatch alarms to monitor instance launches.
AnswersA, C, D

AWS Config rules continuously evaluate EC2 instances against compliance criteria such as mandatory tags or VPC membership. When an instance violates a rule, Config marks it non-compliant and can trigger remediation actions like Lambda functions, but it does not block the initial launch. This makes it a detective control that identifies drift after the fact rather than preventing non-compliant resources from being created.

Why this answer

AWS Config rules can evaluate EC2 instances against a desired configuration, such as being in a VPC with specific tags. By using a custom or managed rule (e.g., 'required-tags' or 'ec2-instance-in-vpc'), you can detect non-compliant instances and trigger remediation actions. This provides continuous monitoring and reporting of compliance status without blocking the launch itself.

Exam trap

The trap here is that candidates confuse detective controls (AWS Config) with preventive controls (SCPs) or assume that monitoring tools like CloudWatch can enforce compliance, when in fact they only alert on operational metrics.

181
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to restrict the use of specific instance types across all accounts to reduce costs and enforce compliance. Which approach should be used?

A.Use AWS Config rules to detect non-compliant instance types
B.Apply a service control policy (SCP) to the root organizational unit to deny the instance types
C.Create IAM policies in each account to deny the use of the instance types
D.Use AWS CloudFormation templates to enforce instance type selection
AnswerB

Service control policies set the maximum available permissions for every principal in attached accounts, so a deny at the root organisational unit blocks those instance types organisation-wide. This centrally satisfies the cross-account restriction requirement without editing each account individually.

Why this answer

Service Control Policies (SCPs) in AWS Organizations set permission guardrails at the OU or account level and apply to all IAM principals within, including the root user. Attaching an SCP to the root OU that denies specific EC2 instance types enforces the restriction across every account in the organization in one place. This is the centralized, preventive control the scenario requires.

Exam trap

DOP-C02 often tests the preventive-vs-detective distinction — candidates pick AWS Config or CloudFormation because they 'enforce' compliance, but only SCPs provide centralized, preventive, org-wide restriction.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are detective, not preventive — they flag non-compliant resources after creation, which doesn't 'restrict' usage. Option C is wrong because per-account IAM policies are decentralized, error-prone, and don't apply to the root user or new accounts, defeating the 'across all accounts' requirement. Option D is wrong because CloudFormation templates only enforce instance types for resources provisioned through those templates — manual or other-tool provisioning bypasses them entirely.

182
MCQhard

A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB). They want to protect against SQL injection and cross-site scripting attacks. Which AWS service should be integrated with the ALB?

A.AWS Network Firewall
B.AWS WAF
C.AWS Shield Advanced
D.Amazon GuardDuty
AnswerB

AWS WAF is the correct choice because it is a fully managed web application firewall that attaches directly to an Application Load Balancer to inspect each incoming HTTP/HTTPS request at the application layer. It can block, allow, or count requests matching conditions such as SQL injection signatures, XSS patterns, IP reputation lists, geo restrictions, and header or body size limits. AWS-managed rule groups, including the OWASP Top 10 rule sets, provide ready-made protection, and WAF integrates natively with ALB to stop malicious traffic before it reaches the EC2 instances.

Why this answer

AWS WAF is a web application firewall that integrates directly with Application Load Balancers to inspect HTTP/HTTPS traffic. It uses managed rule groups to block common attack patterns like SQL injection (e.g., detecting malicious SQL keywords in query strings) and cross-site scripting (e.g., identifying script tags in user input). This makes it the correct choice for protecting web applications at Layer 7.

Exam trap

The trap here is that candidates confuse AWS WAF (Layer 7 application firewall) with AWS Network Firewall (Layer 3/4 stateful firewall) or AWS Shield (DDoS protection), not realizing that only WAF provides the specific rule sets needed for SQL injection and XSS mitigation.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall operates at Layers 3 and 4 (network and transport) and cannot inspect HTTP payloads for SQL injection or XSS patterns. Option C is wrong because AWS Shield Advanced provides DDoS protection at Layers 3/4 and 7 but does not include web application firewall rules for SQLi/XSS; it focuses on volumetric attack mitigation. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, not inline HTTP request inspection.

183
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to prevent an S3 bucket from being publicly accessible? (Choose two.)

Select 2 answers
A.Enable S3 Versioning on the bucket.
B.Enable S3 Block Public Access at the bucket level.
C.Enable S3 Server Access Logging.
D.Configure a bucket policy that explicitly denies anonymous access.
E.Configure a lifecycle policy to delete objects.
AnswersB, D

Amazon S3 Block Public Access provides a bucket-level setting that, when enabled, overrides all other public-access grants by ignoring bucket policies and object ACLs that allow public access, including those that grant access to `*`. This control is evaluated at the edge before any policy or ACL decision and is not overridable by explicit allow statements, making it a highly effective preventative measure. Because it is a native access control, enabling it immediately blocks both existing and future public exposure without requiring you to rewrite the bucket policy.

Why this answer

Enabling S3 Block Public Access at the bucket level provides a centralized, override-proof mechanism to prevent any public access to the bucket, regardless of other policies or ACLs. This setting blocks all public access by default, including access granted via bucket policies, access control lists (ACLs), or object-level permissions, and cannot be overridden by any other S3 configuration.

Exam trap

The trap here is that candidates may think enabling S3 Versioning or Server Access Logging can prevent public access, but these features are designed for data protection and auditing, not for access control enforcement.

184
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to secure a web application running on EC2 instances behind an Application Load Balancer? (Choose two.)

Select 2 answers
A.Configure the EC2 instance security group to allow inbound traffic from 0.0.0.0/0 on port 443.
B.Use a network ACL to allow inbound HTTP/S traffic only from the ALB's subnet.
C.Place the EC2 instances behind an Amazon CloudFront distribution.
D.Enable AWS WAF on the ALB to filter malicious requests.
E.Configure the EC2 instance security group to allow inbound traffic only from the ALB's security group.
AnswersD, E

Attaching AWS WAF to the Application Load Balancer adds a managed Layer 7 firewall that filters incoming HTTP(S) requests before they reach the target group. WAF can block common web exploits such as SQL injection, cross-site scripting (XSS), and excessive request patterns via rate-based rules, and it integrates with AWS Managed Rules for OWASP Top 10 protection. This is a required security action for a publicly exposed web workload because security groups alone only control transport-level access and cannot inspect payloads, and it can be used alongside AWS Shield for DDoS mitigation.

Why this answer

Correct answers are D and E. Option D: AWS WAF on the ALB helps filter out common web exploits. Option E: Configuring the EC2 security group to allow inbound traffic only from the ALB's security group ensures that direct access to instances is blocked, forcing traffic through the ALB.

Option A is incorrect because allowing all inbound traffic (0.0.0.0/0) on port 443 exposes instances directly to the internet, bypassing the ALB. Option B is incorrect: network ACLs are stateless and less granular than security groups; using a NACL to allow traffic from the ALB's subnet is not a recommended practice for instance-level security. Option C is incorrect: placing EC2 instances behind CloudFront is a content delivery optimization, not a security measure to protect the application layer; it does not replace the need for WAF or security group restrictions.

185
MCQhard

A DevOps engineer is troubleshooting a failed AWS CodeBuild project. The build fails with an error indicating that the IAM role does not have permission to describe Amazon ECR repositories. The role used by CodeBuild has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["ecr:GetAuthorizationToken","ecr:BatchCheckLayerAvailability","ecr:GetDownloadUrlForLayer","ecr:BatchGetImage"],"Resource":"*"}]}. What is the missing permission?

A.ecr:InitiateLayerUpload
B.ecr:GetRepositoryPolicy
C.ecr:ListImages
D.ecr:DescribeRepositories
AnswerD

ecr:DescribeRepositories is the exact IAM action required to call the ECR DescribeRepositories API, which CodeBuild uses to list repositories and retrieve their metadata (repository name, ARN, URI, creation timestamp, and image scanning configuration). If this permission is missing from the CodeBuild service role, any attempt to enumerate or describe repositories will fail with AccessDenied. This is the root cause of the failure in the scenario.

Why this answer

The error explicitly states the role lacks permission to 'describe Amazon ECR repositories,' which maps directly to the IAM action ecr:DescribeRepositories. This action is required by CodeBuild when it needs to verify the existence, URI, or configuration of an ECR repository before pulling an image. The existing policy only grants authentication and image-pull permissions (GetAuthorizationToken, BatchCheckLayerAvailability, GetDownloadUrlForLayer, BatchGetImage), none of which cover repository-level metadata inspection.

Exam trap

DOP-C02 often tests the confusion between ECR control-plane actions (DescribeRepositories, GetRepositoryPolicy, ListImages) and data-plane pull/push actions (BatchGetImage, GetDownloadUrlForLayer, InitiateLayerUpload), tricking candidates into selecting a related-sounding but incorrect ECR permission.

How to eliminate wrong answers

Option A is wrong because ecr:InitiateLayerUpload is a push-related permission used by docker push to start uploading image layers, not a describe operation. Option B is wrong because ecr:GetRepositoryPolicy retrieves the repository's resource-based policy document, which is unrelated to the describe-repositories API call and is not what CodeBuild requires to enumerate or inspect repositories. Option C is wrong because ecr:ListImages lists image tags/digests within a repository, not repository metadata; it would not satisfy a DescribeRepositories authorization failure.

186
MCQhard

A company uses AWS CodePipeline to deploy a web application. The pipeline uses artifacts stored in an S3 bucket. The Security team requires that all artifacts be encrypted in transit and at rest, and that the pipeline only access the bucket using a specific VPC endpoint. Which configuration meets these requirements?

A.Configure an IAM role for CodePipeline with a policy that allows s3:GetObject and s3:PutObject, and attach a bucket policy that allows only that role
B.Create a VPC endpoint for S3 and attach a bucket policy that denies access unless aws:SourceVpce matches the endpoint and aws:SecureTransport is true, and use S3 default encryption
C.Use an S3 bucket with a lifecycle policy to expire old artifacts
D.Enable S3 block public access and use SSE-S3 encryption on the bucket
AnswerB

This is the correct solution because it combines three complementary layers. The VPC endpoint for S3 (a gateway endpoint) ensures that all traffic to the bucket originates from within the company's VPC, and the bucket policy denies any request unless the aws:SourceVpce condition matches that endpoint, effectively blocking public internet access. The aws:SecureTransport condition forces all requests to use HTTPS, protecting data in transit from eavesdropping and man-in-the-middle attacks. Finally, enabling S3 default encryption (SSE-S3) ensures that artifact objects are encrypted at rest, so even if an object is somehow copied outside the bucket, its contents remain unintelligible without the encryption key. Together these controls satisfy both transit and at-rest encryption while restricting the attack surface to the VPC.

Why this answer

To enforce encryption in transit and at rest plus restrict access to a specific VPC endpoint, you need an S3 gateway or interface endpoint and a bucket policy that denies requests unless aws:SourceVpce matches the endpoint and aws:SecureTransport is true. S3 default encryption (SSE-S3) satisfies encryption at rest. This combination meets all stated requirements.

Exam trap

DOP-C02 often tests whether candidates realize that IAM policies alone cannot enforce encryption in transit or VPC endpoint restrictions—bucket policy conditions are required.

How to eliminate wrong answers

Option A is wrong because an IAM role and bucket policy alone do not enforce encryption in transit or restrict access to a VPC endpoint. Option C is wrong because a lifecycle policy only expires objects and does nothing for encryption or endpoint restriction. Option D is wrong because block public access and SSE-S3 do not enforce the VPC endpoint condition or encryption in transit.

187
MCQeasy

A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?

A.AWS Config
B.AWS CloudTrail
C.Amazon CloudWatch Logs
D.VPC Flow Logs
AnswerB

AWS CloudTrail is the native auditing service that records every API call made in the account, including calls from the console, SDKs, CLI, and other AWS services. Each event captures the identity of the caller, source IP, time, request and response elements, and the specific action invoked. This makes CloudTrail the correct and only service in this list that directly provides a complete API call history for auditing.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls.

Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.

188
MCQmedium

A company requires that all access to their S3 buckets be encrypted in transit. Which configuration achieves this?

A.Use CloudFront with the bucket as origin and enforce HTTPS only between viewer and CloudFront.
B.Enable default encryption on the bucket.
C.Use a bucket policy that denies requests when aws:SecureTransport is false.
D.Set the bucket policy to require SSE-KMS.
AnswerC

A bucket policy denying requests where `aws:SecureTransport` is false enforces HTTPS-only access, directly satisfying the in-transit encryption requirement. This condition evaluates the TLS state of each request, so any plain HTTP call to the bucket is rejected regardless of IAM permissions, ensuring all access is encrypted in transit.

Why this answer

Using a bucket policy with a condition that denies requests when `aws:SecureTransport` is `false` explicitly enforces encryption in transit for all access to the S3 bucket. This policy ensures that any HTTP (non-TLS) request is denied, while HTTPS requests are allowed, meeting the requirement that all access be encrypted in transit.

Exam trap

The trap here is confusing encryption in transit with encryption at rest; candidates often pick options like default encryption or SSE-KMS, which only address data at rest, not the requirement for HTTPS enforcement.

How to eliminate wrong answers

Option A is wrong because it only enforces HTTPS between the viewer and CloudFront, but the connection between CloudFront and the S3 origin can still be HTTP unless an additional policy or setting enforces HTTPS there, leaving a gap in transit encryption. Option B is wrong because default encryption on the bucket only encrypts data at rest (server-side encryption), not in transit; it does not enforce HTTPS for client connections. Option D is wrong because requiring SSE-KMS enforces encryption at rest using AWS KMS keys, but it does not control whether the data is transmitted over HTTPS or HTTP; transit encryption is a separate concern.

189
MCQhard

A company uses AWS Secrets Manager to rotate secrets for an RDS database. The rotation Lambda function fails with a timeout error. Which configuration change is MOST likely to resolve the issue?

A.Increase the Lambda function timeout.
B.Increase the Lambda function memory.
C.Place the Lambda function in the same VPC as the RDS instance.
D.Configure the Lambda function to retry on failure.
AnswerA

The Lambda rotation function must perform multiple sequential operations—connect to the RDS database, run an ALTER USER statement, and call UpdateSecret to store the new password—all of which can exceed the default 3-second timeout, especially during cold starts or slow network conditions. Increasing the function timeout directly prevents the execution from being terminated mid-rotation, allowing the full workflow to complete before Secrets Manager marks the step as failed. This is the correct fix because timeout errors indicate the function is being killed before finishing, not that it lacks compute resources or network access.

Why this answer

The Lambda function is timing out during the secret rotation process, which involves connecting to the RDS database, generating a new password, and updating the secret. Increasing the Lambda function timeout directly addresses the symptom by allowing more time for the rotation to complete, especially if the database response is slow or the network latency is high. This is the most direct fix for a timeout error, as the default Lambda timeout (3 seconds) is often insufficient for database operations.

Exam trap

The trap here is that candidates may confuse a timeout error with a connectivity error and incorrectly choose to place the Lambda in the same VPC, overlooking that the function must already be in the VPC to even attempt the rotation.

How to eliminate wrong answers

Option B is wrong because increasing memory can improve CPU performance but does not extend the maximum execution duration; timeout errors are resolved by increasing the timeout value, not memory. Option C is wrong because the Lambda function must already be in the same VPC as the RDS instance to connect to it; if it were not, the error would be a connection timeout or access denied, not a generic timeout. Option D is wrong because retrying on failure would only re-execute the same failing code, which would still timeout again; it does not address the root cause of insufficient execution time.

190
MCQhard

A company has a Lambda function that processes sensitive data and needs to access an RDS database. The security team requires that the database credentials are automatically rotated every 30 days. Which service should be used to store and rotate the credentials?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon DynamoDB
D.AWS IAM roles
AnswerA

AWS Secrets Manager is a purpose-built service for storing and managing database credentials and other sensitive secrets. It provides native automatic rotation, including native integration with Amazon RDS, Redshift, and DocumentDB, which enforces credential lifecycle management and reduces the operational burden of periodic rotation. Its resource-based policies and tight integration with AWS Lambda and IAM make it the correct, secure choice for handling sensitive data.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like RDS. It supports native, built-in rotation for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) without requiring custom Lambda functions. The automatic rotation can be scheduled at a desired interval (e.g., every 30 days) using a rotation schedule defined in the secret's configuration, and it integrates directly with RDS to update the credentials on both the secret and the database.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation and RDS integration, making it unsuitable for the 30-day rotation requirement.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of credentials; it is a hierarchical store for configuration data and secrets but requires custom automation (e.g., a Lambda function) to rotate values, and it lacks native integration with RDS for credential rotation. Option C is wrong because Amazon DynamoDB is a NoSQL database service, not a secrets management service; it cannot natively store or rotate credentials, and using it would require building custom encryption and rotation logic, violating the security team's requirement for automated rotation. Option D is wrong because AWS IAM roles are used to grant permissions to AWS resources (e.g., Lambda to access RDS) but cannot store or rotate database credentials; IAM roles provide temporary credentials for AWS API calls, not for database user passwords, and RDS database authentication via IAM is possible but does not involve storing or rotating static credentials.

191
Drag & Dropmedium

Drag and drop the steps to set up an AWS CloudFormation stack with a nested stack.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First upload the nested stack template, then create the parent template, then validate, then create stack, then monitor.

192
MCQmedium

A DevOps engineer is configuring AWS CodeBuild to build a project that requires access to an Amazon RDS database password stored in AWS Secrets Manager. The build must not expose the password in logs or environment variables. Which approach should the engineer use?

A.Store the password as a plaintext environment variable in the CodeBuild project and mark it as sensitive.
B.Embed the password directly in the buildspec.yml file and encrypt the file with AWS KMS.
C.Use the CodeBuild environment variable type SECRETS_MANAGER to reference the secret, and grant the service role permission to retrieve it.
D.Store the password in an Amazon S3 bucket with server-side encryption and have the build download it.
AnswerC

CodeBuild supports a SECRETS_MANAGER environment variable type that fetches the secret value at build time and injects it as an environment variable without storing it in the project configuration. The service role must have secretsmanager:GetSecretValue permission. This satisfies the requirement to avoid exposing the password in logs or static environment variables.

Why this answer

CodeBuild's SECRETS_MANAGER environment variable type retrieves the secret at runtime and injects it securely, avoiding storage in the project configuration. The service role must have permission to access the secret. This approach keeps the password out of logs and static environment variables, meeting the security requirement while simplifying secret management.

Exam trap

The trap here is believing that marking an environment variable as sensitive in CodeBuild hides it completely, when it only masks the value in logs and still stores it in plaintext.

193
MCQhard

A company runs a web application on Amazon ECS with Fargate launch type behind an Application Load Balancer (ALB). The application uses an RDS MySQL database. The security team performed a penetration test and discovered that the application is vulnerable to SQL injection. The development team has deployed a WAF web ACL to the ALB that includes rules to block SQL injection attacks. However, after the deployment, the application started returning 403 errors for legitimate requests, and the security team needs to investigate. The team also wants to ensure that only approved AWS services can access the RDS database. The current security groups are configured with a rule that allows inbound traffic from the ALB security group to the RDS database on port 3306. Which combination of actions should the security team take to resolve the issue and improve the security posture?

A.Disable the WAF rules that are causing false positives and add network ACLs to block all traffic to the database except from the ALB.
B.Remove the WAF web ACL and rely on security group ingress rules that allow all traffic from the VPC CIDR to the database.
C.Switch the WAF web ACL to count mode and add a second ALB in front of the database to filter traffic.
D.Switch the WAF web ACL to count mode while tuning the rules, and implement an IAM policy to restrict database access to specific AWS services using the aws:SourceArn condition key.
AnswerD

Switching to count mode allows monitoring and tuning of WAF rules to eliminate false positives while still detecting SQL injection. Implementing an IAM policy with the aws:SourceArn condition key restricts database access to only approved AWS services, enhancing security beyond network controls.

Why this answer

The correct answer. Switching the WAF web ACL to count mode allows the security team to monitor requests that would be blocked without actually blocking them, enabling them to fine-tune the rules to eliminate false positives while still protecting against SQL injection. Additionally, implementing an IAM policy with the aws:SourceArn condition key can restrict database access to only approved AWS services, such as Lambda functions or specific EC2 instances, enhancing the security posture beyond just network-level controls.

Option A is incorrect because disabling WAF rules would leave the application vulnerable, and network ACLs are stateless and not sufficient for fine-grained access control. Option B is incorrect because relying solely on security groups with VPC CIDR allows broad access and does not address the false positive issue. Option C is incorrect because adding a second ALB is unnecessary and does not solve the false positive problem, and using count mode alone without IAM policy does not address database access restrictions.

194
Multi-Selectmedium

A company needs to ensure that an EC2 instance can only be launched using a specific Amazon Machine Image (AMI) that has been approved by the security team. Which TWO actions should be taken?

Select 2 answers
A.Tag the approved AMI and use resource-based policies to allow only tagged AMIs.
B.Create an IAM policy that denies ec2:RunInstances unless the AMI ID matches the approved AMI.
C.Use an AWS Organizations service control policy (SCP) to restrict AMI usage across accounts.
D.Create an AWS Config rule to check that EC2 instances are launched from the approved AMI.
E.Enable CloudTrail to log all EC2 RunInstances calls and alert on unapproved AMIs.
AnswersB, C

An identity-based IAM policy can deny ec2:RunInstances unless the request's ec2:ImageId condition key matches the approved AMI ID. Because IAM policies are evaluated synchronously before the launch proceeds, this is a true preventive control that blocks the API call, not just an after-the-fact check. It can be attached to all relevant principals and combined with a Deny for a null ImageId to ensure every launch specifies an approved AMI.

Why this answer

An IAM policy with a condition for ec2:ImageId can restrict which AMIs can be used. Option C is correct because an SCP in AWS Organizations can enforce this across accounts. Option A is wrong because tagging does not enforce AMI usage.

Option D is wrong because AWS Config rules only detect non-compliance, not prevent. Option E is wrong because CloudTrail is for logging.

195
MCQhard

A company's security team suspects that an attacker has compromised an IAM user's access keys. The keys were used to launch instances in an unauthorized region. What is the FASTEST way to mitigate the threat?

A.Delete the IAM user.
B.Change the IAM user's password.
C.Rotate the access keys immediately.
D.Attach an AWS WAF to block the attacker's IP address.
AnswerC

Rotating the access keys means generating a new access key pair for the IAM user, updating dependent applications with the new credentials, and then deactivating and deleting the compromised keys. This immediately denies requests signed with the stolen keys because IAM checks key validity for every call, making it the fastest, least-disruptive way to stop the attacker.

Why this answer

Rotating the access keys immediately invalidates the compromised keys, preventing further unauthorized use without disrupting the IAM user's other permissions or requiring a full user recreation. This is the fastest mitigation because it directly revokes the attacker's access while allowing the legitimate user to continue using new keys after rotation.

Exam trap

The trap here is that candidates confuse password changes (console access) with access key rotation (programmatic access), or they overcorrect by deleting the entire user instead of simply rotating the compromised keys.

How to eliminate wrong answers

Option A is wrong because deleting the IAM user is an overly drastic measure that removes all permissions and associated resources, causing unnecessary downtime and operational overhead; it is not the fastest way to stop key-based access. Option B is wrong because changing the IAM user's password only affects console login credentials, not access keys, so it does nothing to mitigate the threat from compromised programmatic keys. Option D is wrong because AWS WAF is a web application firewall that operates at the application layer (HTTP/HTTPS) and cannot block IAM access key usage, which occurs at the AWS API level via Signature Version 4 signing.

196
MCQhard

A company uses AWS CodePipeline to deploy applications to AWS Lambda. The pipeline's source stage is connected to an AWS CodeCommit repository. The security team requires that all code changes are reviewed and approved by at least one team member before deployment. The team wants to automate the approval process as much as possible. Which solution should a DevOps engineer implement?

A.Use AWS CodeCommit approval rule templates to require at least one approval before code can be merged to the main branch.
B.Enable strict branch protection in CodeCommit to prevent direct pushes to the main branch.
C.Configure an approval action in CodePipeline after the source stage that requires manual approval.
D.Add a Lambda function in the pipeline that checks for code review status via the CodeCommit API and fails the pipeline if not approved.
AnswerA

CodeCommit approval rule templates can enforce a minimum number of approvals on pull requests for specified branches. This ensures code review before merge. Once merged, the pipeline can deploy automatically, meeting the automation goal. It integrates with CodeCommit and is the correct solution.

Why this answer

AWS CodeCommit approval rule templates allow you to define approval requirements for pull requests, such as a minimum number of approvals. By applying a template to the main branch, merges are blocked until the required approvals are met. This automates enforcement of code review before deployment, while the pipeline can still deploy automatically after merge.

Exam trap

The trap here is confusing branch protection with approval requirements; branch protection alone prevents direct pushes but does not mandate peer review, so it fails to enforce the approval requirement.

197
MCQeasy

A DevOps engineer must ensure that all API calls in an AWS account are logged for compliance. The logs should be stored in an S3 bucket with server-side encryption enabled. Which two services should be used together to meet these requirements?

A.AWS CloudTrail and Amazon CloudWatch Logs
B.AWS CloudTrail and Amazon S3
C.Amazon VPC Flow Logs and Amazon S3
D.AWS Config and AWS CloudTrail
AnswerB

CloudTrail records every API call as management or data events across the account, satisfying the logging requirement, while Amazon S3 provides the durable, server-side-encrypted destination bucket for those trail logs. Together they deliver the auditable, encrypted API activity record compliance demands.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, and it can deliver those event logs directly to an Amazon S3 bucket, where server-side encryption (SSE-S3 or SSE-KMS) can be enabled to meet the compliance requirement. This combination of CloudTrail and Amazon S3 (option B) satisfies both logging all API calls and storing them encrypted in S3. Option A is wrong because CloudWatch Logs is not the required encrypted S3 storage target for CloudTrail API logs.

Option C is wrong because VPC Flow Logs capture IP traffic metadata, not API calls. Option D is wrong because AWS Config records resource configuration changes, not all API calls, and pairing it with CloudTrail does not by itself provide the encrypted S3 log storage.

198
MCQhard

A company has a VPC with public and private subnets. They launch an EC2 instance in a private subnet that needs to download patches from the internet. Which solution is MOST secure and scalable?

A.Create a NAT Gateway in a public subnet and update the private route table.
B.Launch a proxy server in a public subnet and route traffic through it.
C.Assign an Elastic IP to the instance in the private subnet.
D.Use a VPC endpoint to the Amazon Linux repository.
AnswerA

A NAT Gateway is a fully managed service deployed in a public subnet with an Elastic IP. To grant a private subnet outbound internet access, you must add a route 0.0.0.0/0 to the private route table pointing to the NAT Gateway. This performs source NAT, translating private instance traffic to the gateway's Elastic IP, while dropping unsolicited inbound traffic. It is highly available and scales automatically, making it the recommended solution for outbound connectivity without exposing the instances.

Why this answer

A NAT Gateway resides in a public subnet, has an Elastic IP, and performs source NAT for outbound-only traffic from private subnets. Updating the private subnet's route table with 0.0.0.0/0 → NAT Gateway gives the EC2 instance internet egress for patch downloads without exposing it to inbound connections. It is managed, highly available within the AZ, and scales automatically, satisfying both the security and scalability requirements.

Exam trap

The trap here is confusing VPC endpoints (private access to AWS services) with general internet egress, leading candidates to pick option D when the question explicitly says 'download patches from the internet' — endpoints do not provide arbitrary internet access.

How to eliminate wrong answers

Option B is wrong because a self-managed proxy server in a public subnet introduces a single point of failure, requires patching and scaling effort, and is less secure than an AWS-managed NAT Gateway. Option C is wrong because an Elastic IP cannot be attached to an instance in a private subnet (no IGW route), and even if it could, it would expose the instance to inbound internet traffic, violating the 'most secure' requirement. Option D is wrong because a VPC endpoint only provides private connectivity to specific AWS services (e.g., S3, DynamoDB, or interface endpoints); it cannot reach arbitrary internet repositories like the Amazon Linux yum repos unless those are fronted by an AWS service endpoint, which they are not.

199
MCQeasy

A developer needs to allow an EC2 instance to read from an S3 bucket. Which is the most secure way to grant this access?

A.Use the root user credentials of the AWS account.
B.Store AWS access keys in the instance's user data and use them in the application.
C.Create an S3 bucket policy that allows the EC2 instance's public IP address.
D.Create an IAM role with an S3 read policy and attach it to the EC2 instance profile.
AnswerD

Create an IAM role with a policy such as s3:GetObject and s3:ListBucket, then attach it to the EC2 instance profile. The instance will automatically obtain temporary security credentials from AWS STS through the instance metadata service, which are rotated every few hours and never stored on disk. This follows least privilege, avoids long-lived keys, and is the AWS best practice for granting permissions to a running instance.

Why this answer

The most secure way to grant an EC2 instance access to an S3 bucket is to use an IAM role with an S3 read policy attached to the instance profile. This allows the instance to obtain temporary security credentials via the instance metadata service, avoiding hardcoded keys or exposing credentials. Option A is wrong because root credentials are overly privileged and should never be used for routine access.

Option B is wrong because storing access keys in user data is insecure—keys can be exposed through instance metadata or logs. Option C is wrong because bucket policies based on public IP addresses are not secure; IPs can change and other instances could have the same IP, plus S3 bucket policies should not rely on IP addresses for authentication. Option D is the correct approach because it uses IAM roles, the best practice for granting permissions to AWS services.

200
MCQhard

A company needs to audit all changes to security groups in a multi-account environment. The logs must be centrally stored and immutable. Which solution meets these requirements with minimal operational overhead?

A.Enable VPC Flow Logs in each VPC and aggregate them in Amazon CloudWatch Logs
B.Enable AWS CloudTrail in all accounts, deliver logs to a central S3 bucket with S3 Object Lock enabled
C.Enable Amazon GuardDuty and send findings to a central S3 bucket
D.Enable AWS Config rules to detect security group changes and store results in a central S3 bucket
AnswerB

CloudTrail is the only service that records management-plane API events such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup, including the requesting IAM principal, source IP, and request parameters. Delivering those trail logs to a centralized S3 bucket with S3 Object Lock enabled in compliance mode makes each log object write-once-read-many (WORM), preventing any user—even one with administrative privileges—from altering or deleting audit evidence, which satisfies the immutability and centralized audit requirements. Additionally, enabling CloudTrail in all accounts with a single organization trail and delivering to a central bucket provides a complete, tamper-proof, cross-account audit record of every security group change.

Why this answer

AWS CloudTrail records all API activity, including `AuthorizeSecurityGroupIngress`, `RevokeSecurityGroupIngress`, and related security group modifications, across every account. Delivering these logs to a central S3 bucket with S3 Object Lock (WORM) enabled satisfies both the audit requirement and the immutability requirement, and CloudTrail organization trails can be enabled once at the Organizations level for minimal operational overhead.

Exam trap

DOP-C02 often tests whether candidates conflate traffic-level logs (VPC Flow Logs) or detection findings (GuardDuty) with API-level audit logs (CloudTrail), and whether they recognize S3 Object Lock as the immutability mechanism.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata, not API calls that modify security groups, so they cannot audit configuration changes. Option C is wrong because GuardDuty is a threat detection service that produces findings, not an audit log of every security group change, and findings are not immutable by default. Option D is wrong because AWS Config records configuration changes and can evaluate compliance, but it does not natively provide immutable, tamper-evident log storage — S3 Object Lock must be layered on, and Config alone is not the audit log of API calls.

201
Multi-Selecteasy

Which TWO actions can help protect an AWS account's root user? (Choose TWO.)

Select 2 answers
A.Do not create access keys for the root user; use IAM users instead
B.Delete the root user after creating administrative IAM users
C.Enable multi-factor authentication (MFA) on the root user
D.Rotate the root user password every 30 days
E.Change the root user's email address to a group email
AnswersA, C

Root access keys are long-lived and carry unrestricted permissions that cannot be scoped down by any IAM policy. If they are leaked, the entire account is compromised, and because AWS does not allow you to restrict root credentials, the keys remain an unmanageable risk. Instead, create IAM users with only the necessary permissions, and use temporary credentials from AWS STS (roles) for programmatic access, so each request is authenticated with least privilege and can be audited.

Why this answer

Not creating access keys for the root user is a best practice because root access keys have full permissions and cannot be restricted. Option C is correct: enabling MFA adds an extra layer of security. Option B is wrong: the root user cannot be deleted.

Option D is wrong: rotating the password alone does not protect against unauthorized access; MFA is more important. Option E is wrong: changing the email to a group email does not inherently protect the account and may cause issues with account recovery.

202
MCQeasy

A DevOps engineer needs to grant an IAM user temporary access to an S3 bucket for exactly one hour. Which AWS service should be used to generate temporary credentials?

A.Amazon Cognito
B.AWS SSO
C.AWS STS
D.AWS IAM
AnswerC

AWS STS is the correct service for generating temporary credentials for an IAM user. APIs like GetSessionToken and AssumeRole return an access key ID, secret access key, and a session token that is valid for a specified duration (from 15 minutes up to 36 hours). The temporary credentials carry the same permissions as the IAM user's existing permissions (in the case of GetSessionToken) or the permissions defined in the assumed role's policy, making it ideal for short-lived access without rotating long-term keys.

Why this answer

AWS STS (Security Token Service) is the service that issues temporary, limited-privilege credentials via APIs like AssumeRole, GetSessionToken, and GetFederationToken. To grant an IAM user one-hour access to an S3 bucket, the engineer calls AssumeRole (or AssumeRoleWithSAML/WebIdentity) with a DurationSeconds of 3600 and attaches a scoped policy. STS returns an access key, secret key, and session token that expire automatically, which is exactly the temporary-credential requirement.

Exam trap

DOP-C02 often tests the confusion between IAM (which defines permissions) and STS (which issues temporary credentials) — candidates pick IAM because it 'manages access' without realizing IAM cannot generate session tokens.

How to eliminate wrong answers

Option A is wrong because Amazon Cognito is for federating end-user identities in web/mobile apps (user pools and identity pools) and issues tokens for app users, not for granting an existing IAM user temporary S3 access. Option B is wrong because AWS SSO (now IAM Identity Center) is a workforce identity federation and permission-set service — it can produce STS-backed sessions, but it is not the service you call to generate the temporary credentials themselves. Option D is wrong because AWS IAM manages users, groups, roles, and policies; IAM itself does not mint temporary credentials — it delegates that to STS.

203
MCQeasy

A company is using Amazon RDS for MySQL and needs to encrypt the database at rest. Which action should be taken to enable encryption?

A.Create a read replica with encryption enabled
B.Use AWS Secrets Manager to encrypt the data
C.Enable encryption when creating the DB instance
D.Modify the existing DB instance and enable encryption
AnswerC

Amazon RDS supports encryption at rest only as an attribute that is set during the initial Create DB instance operation. When you provision the instance, you choose to enable encryption and optionally select a customer-managed KMS key; this setting is permanently attached to that instance. If you skip this option at launch, you cannot enable it later—you must migrate data to a newly created encrypted instance.

Why this answer

Amazon RDS encryption at rest can only be enabled at the time the DB instance is created — you cannot enable it on an existing unencrypted instance. The correct action is therefore to enable encryption during creation (via the console, CLI, or API using the 'StorageEncrypted' parameter). Once enabled, RDS uses AWS KMS to encrypt the underlying storage, automated backups, read replicas, and snapshots.

Exam trap

The trap is believing RDS supports in-place encryption via 'Modify' — it does not; encryption must be set at creation or via snapshot restore.

How to eliminate wrong answers

Option A is wrong because a read replica of an unencrypted primary cannot itself be encrypted — encryption status is inherited from the source. Option B is wrong because AWS Secrets Manager stores and rotates credentials; it does not encrypt RDS data at rest. Option D is wrong because RDS does not support modifying an existing unencrypted instance to enable encryption; you must create a new encrypted instance (e.g., from a snapshot restore with encryption).

← PreviousPage 3 of 3 · 203 questions total

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.