Courseiva

CCNA Design Secure Questions

75 of 293 questions · Page 2/4 · Design Secure topic · Answers revealed

76
MCQmedium

A financial services company runs a three-tier web application on AWS. The application tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. A security audit reveals that the application instances are receiving large volumes of unwanted traffic directly from the internet on port 443, bypassing the load balancer. The company wants to ensure that only traffic from the ALB can reach the application instances, while allowing the instances to download software updates from the internet. What should a solutions architect recommend?

A.Modify the network ACL on the application subnets to deny inbound traffic on port 443 from all sources except the ALB's private IP addresses.
B.Attach an AWS WAF web ACL to the ALB and create a rule to block all IP addresses except those in the ALB's subnet CIDR range.
C.Move the application instances to a placement group and enable enhanced networking to prevent direct internet access.
D.Configure the application instances' security group to allow inbound traffic only from the ALB's security group, and place the instances in private subnets with a NAT gateway for outbound internet access.
AnswerD

Referencing the ALB's security group as the source in the instances' inbound rule ensures only traffic that passed through the load balancer is accepted. Placing instances in private subnets removes direct internet routing, and a NAT gateway provides outbound-only internet access for updates, satisfying both requirements without exposing the instances.

Why this answer

The most secure and operationally sound approach is to use security group referencing so that the instances accept traffic only from the load balancer, and to remove direct internet exposure by placing instances in private subnets. A NAT gateway then allows outbound updates. This combination enforces the traffic path through the ALB while preserving necessary outbound connectivity.

Exam trap

The trap here is assuming that an AWS WAF rule or a network ACL can restrict traffic that reaches instances directly, when only security group referencing combined with private subnets removes the direct path.

77
MCQmedium

Developers for a e-learning platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?

A.Disable CloudTrail during troubleshooting
B.Use IAM Identity Center permission sets with time-bound access processes and CloudTrail auditing
C.Attach AdministratorAccess permanently to every developer role
D.Create shared administrator access keys for the team
AnswerB

Federated access with permission sets and audited temporary assignments reduces standing privilege.

Why this answer

IAM Identity Center permission sets allow you to define fine-grained permissions and assign them to users or groups with time-bound access (e.g., using a session duration or approval workflow). Combined with CloudTrail, every API call made during the elevated session is logged for audit, meeting the security team's requirements for approvals, expiry, and audit logging.

Exam trap

The trap here is that candidates may think IAM roles with a trust policy and temporary credentials are sufficient, but they overlook that IAM Identity Center provides centralized, time-bound permission sets with built-in approval workflows and audit integration, which is the best fit for the given requirements.

How to eliminate wrong answers

Option A is wrong because disabling CloudTrail during troubleshooting would eliminate audit logging, directly violating the security team's requirement for audit logging. Option C is wrong because permanently attaching AdministratorAccess to every developer role grants unrestricted, persistent elevated access with no expiry or approval process, violating the principle of least privilege and the need for time-bound access. Option D is wrong because creating shared administrator access keys for the team removes individual accountability, prevents proper audit trails (as actions cannot be attributed to a specific user), and provides no expiry or approval mechanism.

78
Multi-Selecthard

A third-party payroll vendor in another AWS account must assume a role in your account to write a daily settlement file to Amazon S3. You want to prevent confused-deputy attacks and make every assumed session traceable in CloudTrail back to an individual vendor user. Which three trust-policy or session controls should be used? Select three.

Select 3 answers
A.Specify the exact vendor role ARN as the trusted principal in the role trust policy.
B.Require an external ID in the trust policy conditions.
C.Require sts:SourceIdentity when the vendor assumes the role.
D.Use a wildcard principal and rely on the S3 bucket policy to narrow access later.
E.Give the vendor long-term IAM user credentials in your account for easier auditing.
AnswersA, B, C

The trust policy should name only the specific vendor role that is allowed to assume the role in your account. Restricting the principal minimizes the trust boundary and prevents unrelated identities from attempting the assumption path.

Why this answer

Specifying the exact vendor role ARN as the trusted principal in the trust policy ensures that only that specific role in the vendor's account can assume the role, preventing any other entity from impersonating the vendor. This is a key control to limit the trust boundary and avoid confused-deputy attacks.

Exam trap

The trap here is that candidates often think a bucket policy alone can control role assumption, but it cannot—the trust policy is the only mechanism to restrict which external principals can assume a role, and confused-deputy protections require explicit conditions like external ID and source identity.

Why the other options are wrong

D

Using a wildcard principal in the trust policy would allow any AWS principal to assume the role, violating the principle of least privilege and failing to prevent confused-deputy attacks. The S3 bucket policy cannot restrict who assumes the role, only what the assumed role can access.

E

Option E suggests giving the vendor long-term IAM user credentials in your account, which violates the principle of least privilege and makes auditing harder because actions are tied to a shared credential rather than individual vendor users. It also does not prevent confused-deputy attacks or ensure traceability to individual vendor users.

79
MCQeasy

Several EC2 instances in different Availability Zones need to read and write the same shared file system. The file storage should stay available if one AZ has a problem. Which service should the team choose?

A.Amazon EBS
B.Amazon EFS
C.Amazon S3 only
D.Instance store
AnswerB

Amazon EFS is a managed shared file system that can be mounted by multiple EC2 instances across multiple Availability Zones. It is a strong fit when applications need the same files at the same time and must remain available even if one AZ experiences issues. The service is highly available by design and reduces operational work compared with self-managed file servers.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently by multiple EC2 instances across different Availability Zones. It is designed for high availability and durability by storing data redundantly across multiple AZs within a region, ensuring continued access even if one AZ fails.

Exam trap

The trap here is that candidates often confuse EBS Multi-Attach (which only supports a limited number of instances in the same AZ and requires a cluster-aware file system) with the true multi-AZ shared file system capability of EFS.

Why the other options are wrong

A

Amazon EBS volumes are tied to a single Availability Zone and cannot be shared across multiple EC2 instances in different AZs, so they cannot provide the required shared file system with cross-AZ availability.

C

Amazon S3 is object storage, not a shared file system; EC2 instances cannot mount S3 as a POSIX-compliant file system for concurrent read/write access. It also does not provide file locking or low-latency file operations needed for shared file systems.

80
MCQmedium

A SaaS vendor will access your AWS resources by assuming an IAM role in your account. You want to prevent confused-deputy attacks and ensure the vendor can only assume the role using an agreed external identifier. Your role trust policy currently allows sts:AssumeRole from the vendor’s principal, but it does not include any external ID protection. Which change is the best next step?

A.Add a condition to the trust policy: Condition = {"StringEquals": {"sts:ExternalId": "vendor-agreed-id"}}.
B.Add a condition to the trust policy: Condition = {"IpAddress": {"aws:SourceIp": "203.0.113.0/24"}}.
C.Remove sts:AssumeRole and replace it with sts:AssumeRoleWithWebIdentity to use the vendor’s browser-based tokens.
D.Add a condition to the role permissions policy (not the trust policy) requiring aws:PrincipalTag/ExternalId to equal the external identifier.
AnswerA

Using sts:ExternalId in the trust policy ensures only assume-role requests presenting the correct external identifier are allowed. This directly mitigates confused-deputy attacks by binding authorization to a value the vendor must know. It also keeps the permissions model clean, because the check is enforced during the STS AssumeRole request.

Why this answer

The `sts:ExternalId` condition key is specifically designed to prevent confused-deputy problems. By adding `{"StringEquals": {"sts:ExternalId": "vendor-agreed-id"}}` to the trust policy, you ensure that the vendor must provide the agreed external ID in the `AssumeRole` API call, which only the legitimate vendor knows. This prevents a malicious third party from tricking the vendor into assuming a role in your account on their behalf.

Exam trap

The trap here is that candidates often confuse where to place the condition (trust policy vs. permissions policy) or mistakenly think IP-based restrictions or changing the API action are appropriate solutions for confused-deputy prevention.

Why the other options are wrong

B

The question requires protection against confused-deputy attacks using an external ID, not IP-based restrictions. The vendor's IP addresses may change or be shared, and IP conditions do not prevent a different vendor from using the same role.

C

This option is wrong because the question is about preventing confused-deputy attacks when a vendor assumes an IAM role, which requires sts:AssumeRole with an external ID condition, not sts:AssumeRoleWithWebIdentity, which is used for federated users with web identity tokens (e.g., from Amazon Cognito, Google, or Facebook).

D

The permissions policy controls what actions the role can perform, not who can assume it. The external ID check must be in the trust policy to prevent confused-deputy attacks during role assumption.

81
MCQhard

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to allow an on-premises data center (192.168.0.0/24) to access a web application running on EC2 instances in a private subnet. The security team wants to ensure that only HTTP and HTTPS traffic from the on-premises network is allowed, and that the traffic is encrypted in transit. Which combination of AWS services should they use?

A.Set up an AWS Site-to-Site VPN connection and configure security groups to allow HTTP/HTTPS from 192.168.0.0/24.
B.Set up an AWS Transit Gateway with a VPN attachment and configure security groups to allow all traffic from 192.168.0.0/24.
C.Set up an AWS Client VPN endpoint and configure security groups to allow HTTP/HTTPS from the VPN client CIDR.
D.Set up an AWS Direct Connect connection and configure network ACLs to allow HTTP/HTTPS from 192.168.0.0/24.
AnswerA

An AWS Site-to-Site VPN provides an encrypted tunnel over the internet between the on-premises network and the VPC. Security groups on the EC2 instances can be configured to allow inbound HTTP (port 80) and HTTPS (port 443) only from the on-premises CIDR. This meets the requirements for encryption in transit and restricted traffic.

Why this answer

An AWS Site-to-Site VPN creates an encrypted tunnel between the on-premises network and the VPC, ensuring data in transit is protected. Security groups can then be configured to allow only HTTP and HTTPS traffic from the specific on-premises CIDR block, restricting access to the required ports. This combination satisfies both the encryption and traffic restriction requirements.

Exam trap

The trap here is assuming that AWS Direct Connect encrypts traffic by default; it does not, and would require an additional VPN for encryption.

82
MCQhard

A order processing API must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

A.Run a daily Lambda function to encrypt unencrypted volumes
B.Enable VPC Flow Logs
C.Use an SCP that denies ec2:CreateVolume when the encrypted condition is false
D.Tag encrypted volumes after creation
AnswerC

An SCP denying `ec2:CreateVolume` when the `ec2:Encrypted` condition key is false blocks unencrypted volume creation across every account in the organisation, regardless of IAM permissions. This preventive guardrail satisfies the requirement that only encrypted EBS volumes can be created, unlike detective controls or default encryption settings.

Why this answer

Service Control Policies (SCPs) are a preventive control that can deny the ec2:CreateVolume API call when the encryption condition (ec2:Encrypted) is false. This ensures that no unencrypted EBS volumes can be created at the account level, regardless of IAM permissions. SCPs operate at the AWS Organizations root, OU, or account level and are evaluated before any IAM policies, making them the strongest preventive mechanism.

Exam trap

The trap here is confusing detective/reactive controls (like Lambda remediation) with preventive controls (like SCPs), leading candidates to choose a solution that fixes the problem after it occurs rather than blocking it entirely.

How to eliminate wrong answers

Option A is wrong because running a daily Lambda function to encrypt unencrypted volumes is a detective/reactive control, not a preventive one; it does not block the creation of unencrypted volumes and leaves a window of exposure. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and have no ability to enforce encryption policies on EBS volumes; they are a monitoring tool, not a preventive control. Option D is wrong because tagging encrypted volumes after creation is a labeling action that does not prevent unencrypted volumes from being created; it is a detective or organizational control, not a preventive one.

83
MCQeasy

A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses. Which AWS service should be used to meet these requirements?

A.Amazon GuardDuty
B.AWS Shield Advanced
C.AWS WAF
D.AWS Network Firewall
AnswerC

AWS WAF inspects HTTP and HTTPS requests and can block common exploits such as SQL injection and cross-site scripting using managed rule groups. It also supports rate-based rules that count requests from a source IP over a time window, which meets the rate-limiting requirement. Associating a web ACL with the Application Load Balancer provides the needed protection.

Why this answer

AWS WAF is the service designed to filter and monitor HTTP requests at the application layer. It provides managed rule groups that block SQL injection and cross-site scripting, and rate-based rules that limit requests from specific IP addresses. Associating a web ACL with the Application Load Balancer enforces these protections directly on incoming traffic, meeting both requirements.

Exam trap

The trap here is confusing DDoS protection with application-layer exploit protection, when AWS Shield Advanced addresses volumetric attacks while AWS WAF handles HTTP-level filtering and rate limiting.

84
Multi-Selectmedium

A data lake stores raw files in a single Amazon S3 bucket that is shared by three internal analytics teams. Each team should access only its own prefix, and the company wants to eliminate ACL management because objects come from multiple producers. Which three changes should the architect make? Select three.

Select 3 answers
A.Create a separate S3 access point for each team and scope it to that team’s prefix.
B.Leave ACLs enabled so each producer can grant permissions directly on uploaded objects.
C.Set Object Ownership to Bucket owner enforced so ACLs are disabled.
D.Use bucket or access point policies to restrict access to the allowed principals and prefixes.
E.Make the bucket public and rely on application-layer authorization for data protection.
AnswersA, C, D

An S3 access point gives each team a distinct hostname and policy scoped to its own prefix, so a single shared bucket can be partitioned without duplicating data. This enforces per-team prefix isolation while access point policies replace per-object ACL grants.

Why this answer

Option A is correct because S3 access points provide a dedicated endpoint per team, and each access point can be scoped with a policy limited to that team's prefix, giving clean per-team isolation without duplicating buckets. Option C is correct because setting Object Ownership to Bucket owner enforced disables ACLs entirely, so the bucket owner automatically owns every object and ACL management is eliminated, which matches the requirement that objects come from multiple producers. Option D is correct because bucket policies and access point policies are the IAM-based mechanism that restricts each team to its allowed principals and prefixes once ACLs are disabled.

Option B is wrong because leaving ACLs enabled keeps the ACL management burden the company wants to remove. Option E is wrong because making the bucket public exposes the data and application-layer authorization does not replace S3-level access control.

Exam trap

The trap here is that candidates may think ACLs are necessary for multi-producer environments, but AWS recommends disabling ACLs and using bucket policies or access point policies with Object Ownership set to 'Bucket owner enforced' to simplify access control.

Why the other options are wrong

B

Leaving ACLs enabled contradicts the requirement to eliminate ACL management, and ACLs do not restrict access by prefix—they grant permissions on individual objects, which is not scalable for multiple producers and teams.

85
MCQmedium

You use Amazon CloudFront in front of a private content S3 origin. To mitigate an OWASP Top 10 issue, you created a WAF web ACL and associated it to the CloudFront distribution, but attacks are still reaching the origin. CloudWatch logs show the web ACL rules never match for the CloudFront requests. What is the most likely configuration mistake?

A.The WAF web ACL intended for CloudFront must be created in the us-east-1 (N. Virginia) region (CloudFront scope), even if the rest of the stack is in another region.
B.WAF rules only evaluate requests after they reach the origin, so the absence of matches means the origin is blocking traffic first.
C.For CloudFront, you must use a regional WAF endpoint and cannot use a global web ACL.
D.WAF web ACL rules never apply to signed URLs or signed cookies, so the web ACL is bypassed by design.
AnswerA

CloudFront-scoped WAF web ACLs use a global scope that is provisioned/managed in us-east-1. Creating the web ACL in the wrong region (or with the wrong scope) prevents CloudFront from evaluating the expected web ACL rules, which would lead to no rule matches in logs.

Why this answer

When using AWS WAF with CloudFront, the web ACL must be created in the US East (N. Virginia) region (us-east-1) because CloudFront is a global service that only supports WAF web ACLs with a global scope, which are always defined in us-east-1. If the web ACL is created in any other region, it will be a regional web ACL and cannot be associated with a CloudFront distribution, causing the rules to never be evaluated against incoming requests.

This explains why CloudWatch logs show no rule matches—the web ACL is effectively not attached to the CloudFront distribution.

Exam trap

The trap here is that candidates assume WAF web ACLs can be created in any region for CloudFront, not realizing that CloudFront requires a global-scope web ACL that must be created in us-east-1, regardless of where the origin or other resources reside.

Why the other options are wrong

B

WAF rules evaluate requests before they reach the origin, not after. The absence of matches indicates the web ACL is not being applied to CloudFront traffic, not that the origin is blocking requests.

C

CloudFront requires a global (CloudFront scope) web ACL, not a regional one. Associating a regional WAF web ACL with CloudFront is not supported, but the mistake here is that the web ACL was created in the wrong region (not us-east-1), not that it was regional.

D

WAF rules do apply to requests using signed URLs or signed cookies; the web ACL evaluates all requests that reach CloudFront, regardless of authentication method. The issue here is that the web ACL is not being applied at all because it was created in the wrong region.

86
MCQeasy

A team wants to delegate IAM management to developers, but must ensure developers can never grant themselves permissions beyond a specific limit. Which AWS mechanism best matches this requirement?

A.Use an IAM permission boundary on roles/users that developers create, so the developers’ effective permissions are capped by the boundary policy.
B.Rely only on their IAM managed policies and instruct developers to self-check against internal guidelines.
C.Use a service control policy (SCP) that applies only to the developers’ IAM users in the account.
D.Use a KMS key policy to restrict IAM actions, because IAM actions can be controlled with KMS.
AnswerA

Permission boundaries constrain the maximum permissions that an identity can receive. Even if developers attach an identity policy that allows broader actions, the effective permissions are limited to the intersection of the identity policy and the boundary.

Why this answer

IAM permission boundaries are the correct mechanism because they allow a developer to create IAM roles or users, but explicitly cap the maximum permissions those entities can have. The boundary policy acts as a ceiling, so even if a developer attaches a permissive managed policy, the effective permissions are the intersection of the boundary and the attached policy. This directly enforces the requirement that developers cannot grant themselves permissions beyond a specific limit.

Exam trap

The trap here is confusing service control policies (SCPs) with permission boundaries, as both can limit permissions, but SCPs apply account-wide and cannot be selectively applied to only developers' IAM users, while permission boundaries are attached directly to the IAM entity.

Why the other options are wrong

B

Option B relies on manual self-policing without any technical enforcement, which cannot prevent developers from granting themselves permissions beyond the specified limit. AWS IAM has no built-in mechanism to enforce internal guidelines automatically.

C

Service control policies (SCPs) apply to all IAM users and roles in an AWS account, not just to specific developers' IAM users. SCPs cannot target individual users; they apply at the account, OU, or organization level.

D

KMS key policies control access to KMS keys, not IAM actions. They cannot restrict IAM permissions or prevent developers from granting themselves elevated IAM privileges.

87
MCQmedium

A company runs a two-tier web application on Amazon EC2 instances in a public subnet. The EC2 instances must access an Amazon Aurora MySQL DB cluster in private subnets. A security engineer must ensure that only the web tier can reach the database on port 3306, and that no other resources in the VPC can connect. Which combination of security group configuration and subnet placement should the engineer implement?

A.Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the CIDR block of the public subnet, and place the Aurora cluster in private subnets.
B.Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the security group attached to the EC2 instances, and place the Aurora cluster in the same public subnet as the EC2 instances.
C.Attach a network ACL to the private subnets that allows inbound TCP 3306 from the public subnet CIDR block, and rely on the default security group for the Aurora cluster.
D.Attach a security group to the Aurora cluster that allows inbound TCP 3306 from the security group attached to the EC2 instances, and place the Aurora cluster in private subnets.
AnswerD

Referencing the web tier's security group as the source in the database security group's inbound rule allows any instance that carries that security group to connect on 3306, regardless of its private IP address. Placing Aurora in private subnets removes any route to the internet, so only resources inside the VPC can attempt a connection, satisfying the least-privilege requirement.

Why this answer

The secure pattern is to keep the database in private subnets and use a security group inbound rule that references the web tier's security group as the source. Security group references are evaluated dynamically, so only instances carrying that group can open a connection on the database port, and private subnet placement prevents any inbound path from the internet.

Exam trap

The trap here is assuming that specifying the public subnet CIDR block in the database security group is equivalent to allowing only the web tier, when in fact a CIDR rule permits every resource in that subnet.

88
MCQmedium

A mobile app reads the same product catalog items repeatedly throughout the day. The DynamoDB table is already properly keyed, but read latency is still a problem during sales events. The team can tolerate eventually consistent reads and wants the least disruptive change. What should they add?

A.Add a global secondary index for every frequently viewed product attribute.
B.Enable DynamoDB Accelerator to cache frequently accessed items in memory.
C.Switch the table to on-demand capacity mode to reduce latency.
D.Move the catalog to Aurora and use a read replica for every region.
AnswerB

DynamoDB Accelerator, or DAX, is the best fit for repeated reads of the same items when eventual consistency is acceptable. It provides an in-memory cache in front of DynamoDB and can dramatically reduce read latency for hot catalog items during traffic spikes. Because the table schema is already sound, DAX adds performance without forcing a redesign of keys or access patterns.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache that reduces read latency for frequently accessed items by orders of magnitude, from single-digit milliseconds to microseconds. Since the team can tolerate eventually consistent reads, DAX is ideal because it caches read results and serves them without additional DynamoDB read capacity consumption, making it the least disruptive change — no schema changes or application rewrites are required.

Exam trap

The trap here is that candidates often confuse throughput scaling (on-demand capacity) with latency reduction, or they over-engineer the solution by migrating to a different database when a simple caching layer (DAX) is the least disruptive and most cost-effective fix.

Why the other options are wrong

A

Adding a GSI for every frequently viewed attribute does not reduce read latency for repeated reads of the same items; it adds storage and write costs without addressing the latency caused by repeated reads from disk.

C

Switching to on-demand capacity mode addresses throughput provisioning, not read latency. Latency issues from repeated reads are better solved by caching, not capacity mode changes.

D

Moving to Aurora and using read replicas is a much more disruptive change than enabling DAX, and it does not address the core issue of caching frequently accessed items in memory for low-latency reads. Aurora is a relational database, not a key-value store like DynamoDB, and the question specifies the team wants the least disruptive change.

89
MCQmedium

A claims portal stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured?

A.S3 server access logging
B.S3 versioning only
C.S3 Object Lock in compliance mode with an appropriate retention period
D.S3 lifecycle expiration after seven years
AnswerC

S3 Object Lock in compliance mode enforces a write-once-read-many (WORM) model where every object version is locked for a specified retention period. During that period, neither the object owner, the bucket owner, nor even the AWS root user can overwrite or delete the object; any such attempt fails. This makes it the only option that provides true immutability and regulatory-grade protection, such as meeting SEC Rule 17a-4 requirements, for audit log storage.

Why this answer

C is correct because S3 Object Lock in compliance mode enforces a write-once-read-many (WORM) model that prevents any user, including the root user, from overwriting or deleting objects for the specified retention period. This meets the compliance team's requirement that logs cannot be altered or removed for seven years, as compliance mode provides the highest level of protection and cannot be bypassed or shortened.

Exam trap

The trap here is that candidates often confuse versioning (which only preserves history but allows deletion via delete markers) with Object Lock's ability to enforce immutability, or they mistakenly think server access logging or lifecycle policies can prevent data modification.

How to eliminate wrong answers

Option A is wrong because S3 server access logging only records requests made to the bucket (audit trail), but does not prevent overwrites or deletions of existing objects. Option B is wrong because S3 versioning alone preserves previous versions of objects but does not prevent deletion of the current version or overwriting of object data; a delete marker can still be placed, and objects can be permanently deleted if versioning is suspended. Option D is wrong because S3 lifecycle expiration after seven years would automatically delete objects after that period, but it does not prevent premature deletion or overwriting before the seven-year mark.

90
MCQeasy

You want to protect an Application Load Balancer (ALB) from common web exploits using AWS WAF. The application is not using CloudFront. Which AWS WAF deployment scope should you choose so the WAF rules apply to the ALB?

A.Use AWS WAF regional scope (associate the web ACL with the ALB resource)
B.Use AWS WAF CloudFront (global) scope and associate the web ACL with the ALB
C.Use AWS Shield Advanced and rely on it to inspect payloads for SQL injection and XSS
D.Use security groups only, because they can detect SQL injection patterns in HTTP requests
AnswerA

ALBs are regional resources. When you protect an ALB without CloudFront, you should use the regional WAF scope and associate the web ACL directly with the ALB, so WAF can inspect incoming requests destined for that ALB.

Why this answer

AWS WAF offers two deployment scopes: regional and CloudFront (global). Since the application is using an Application Load Balancer (ALB) without CloudFront, you must choose the regional scope. This allows you to associate the web ACL directly with the ALB resource, enabling AWS WAF to inspect HTTP/HTTPS requests for common web exploits like SQL injection and cross-site scripting (XSS) at the regional endpoint.

Exam trap

The trap here is that candidates may assume AWS WAF always requires CloudFront or that Shield Advanced provides application-layer inspection, but the exam tests the specific requirement that regional WAF is the only option for ALB without CloudFront.

Why the other options are wrong

B

AWS WAF with CloudFront (global) scope can only be associated with CloudFront distributions, not with Application Load Balancers. Since the application is not using CloudFront, this scope cannot protect the ALB.

C

AWS Shield Advanced provides DDoS protection, not application-layer web exploit detection like SQL injection or XSS. It does not inspect payloads for these threats; that is the role of AWS WAF.

D

Security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer payloads for SQL injection or XSS patterns; they only filter based on IP addresses, ports, and protocols.

91
MCQhard

A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.

A.Store the database password in user data
B.IAM database authentication for RDS with an EC2 instance role
C.Use a security group rule that allows only application instances
D.Embed the database password in the AMI
AnswerB

IAM database authentication for RDS with an EC2 instance role is the correct approach because it lets the application generate a short-lived (15-minute) authentication token using SigV4, eliminating any stored database password. The EC2 instance assumes an instance role with rds-db:connect permissions, and the application presents the token to PostgreSQL over SSL; RDS validates the token against IAM rather than a static password. This provides centralized credential management via IAM roles, automatic rotation of credentials, and ensures no secret is baked into configurations, user data, or code.

Why this answer

IAM database authentication for RDS allows EC2 instances to authenticate to PostgreSQL using a short-lived token generated via the IAM instance profile, eliminating the need to store credentials on the instance. The token is obtained by calling the RDS generate_db_auth_token API with the instance's IAM role, and it is valid for 15 minutes by default. This approach satisfies the requirement for short-lived credentials and avoids custom operational scripts.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with authentication mechanisms, or assume that storing credentials in user data or AMIs is acceptable because they are 'hidden' from the OS, when in fact they are still long-lived and accessible via metadata or AMI inspection.

How to eliminate wrong answers

Option A is wrong because storing the database password in user data leaves it in plaintext on the instance metadata, which is accessible to any process or user with access to the instance, and it does not provide short-lived credentials. Option C is wrong because security group rules only control network access at the transport layer; they do not handle authentication or credential management, so credentials would still need to be stored on the instance. Option D is wrong because embedding the database password in the AMI hard-codes a long-lived credential into the image, which violates the requirement to avoid storing credentials on EC2 and does not provide short-lived credentials.

92
MCQmedium

A team runs an application on Amazon EC2 that connects to an Aurora database. The database password must rotate automatically every 30 days, and the application should retrieve the current secret at runtime using an IAM role. Which AWS service is the best fit?

A.AWS Systems Manager Parameter Store standard parameters.
B.AWS Secrets Manager with rotation enabled.
C.AWS KMS, because KMS stores credentials and rotates them automatically.
D.Amazon S3 with server-side encryption and versioning.
AnswerB

Secrets Manager is designed for secure secret storage with built-in rotation support and fine-grained access through IAM. In this case, the application can retrieve the current database credentials at runtime with its EC2 role, while the secret is rotated on a schedule without embedding passwords in code. This reduces operational risk, improves auditability, and avoids manual password changes that often cause outages.

Why this answer

AWS Secrets Manager is the best fit because it natively supports automatic rotation of database credentials on a schedule (e.g., every 30 days) and integrates directly with Amazon RDS/Aurora to update the password. The application can retrieve the current secret at runtime using an IAM role attached to the EC2 instance, without hardcoding credentials. Secrets Manager also provides built-in secret rotation with Lambda, ensuring zero downtime during password changes.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with Secrets Manager, or incorrectly assume KMS can store and rotate credentials because it handles encryption keys.

Why the other options are wrong

A

Systems Manager Parameter Store standard parameters do not support automatic rotation of secrets; they require manual updates or custom automation, whereas the question mandates automatic rotation every 30 days.

C

AWS KMS is a key management service for encryption keys, not a service for storing or rotating database passwords. It does not provide automatic rotation of secrets or direct retrieval by applications via IAM roles.

D

Amazon S3 with server-side encryption and versioning does not provide automatic password rotation or native integration with IAM roles for runtime secret retrieval; it is designed for object storage, not dynamic secrets management.

93
Matchinghard

Match each database availability event to the AWS failover behavior that best describes it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

The standby in another Availability Zone is promoted, and the same database endpoint remains in use after a brief reconnect.

Aurora promotes another healthy instance to writer while the shared storage layer stays intact across Availability Zones.

A manual failover can be triggered so the standby becomes primary before the reboot finishes.

Only that reader is removed from the reader set; the cluster can still serve read traffic through the remaining healthy readers.

Why these pairings

Multi-AZ RDS automatically fails over to standby; read replicas require manual redirect; Aurora uses replicas for failover; without replicas, Aurora recovers in-place.

94
MCQeasy

A startup runs a public web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in a public subnet and currently allow SSH from 0.0.0.0/0 so that engineers can troubleshoot. Auditors flagged this exposure. Engineers still need occasional shell access to the instances, and the company wants the access to be auditable per engineer without managing bastion hosts or distributing key pairs. Which solution best meets these requirements?

A.Keep the instances in the public subnet, restrict SSH to the corporate office CIDR, and distribute a shared PEM key pair to all engineers through AWS Secrets Manager.
B.Move the instances to private subnets, remove the inbound SSH rule, and grant engineers access through AWS Systems Manager Session Manager with IAM policies and session logging to Amazon S3 and CloudWatch Logs.
C.Attach an EC2 instance profile granting AmazonSSMManagedInstanceCore to the instances and open port 22 only to the VPC CIDR so Session Manager can reach the instances.
D.Deploy a bastion host in a public subnet with a security group that allows SSH only from the corporate CIDR, and have engineers forward through it to reach the instances.
AnswerB

Session Manager connects to instances through the Systems Manager agent without inbound ports or a bastion host, so the SSH rule can be deleted entirely. Access is governed by IAM, so each engineer's session is attributable, and session logging to Amazon S3 and CloudWatch Logs produces the audit trail the auditors requested without distributing or rotating SSH key pairs.

Why this answer

Session Manager removes the need for inbound SSH, bastion hosts, and key pairs by having the Systems Manager agent establish outbound connections to the service. IAM policies determine which engineers can start sessions on which instances, giving per-person attribution, and session logging to Amazon S3 and CloudWatch Logs satisfies the audit requirement without exposing any listening port.

Exam trap

The trap here is assuming Session Manager requires an open SSH port or a bastion host to function, when the agent only needs outbound connectivity to Systems Manager endpoints.

95
MCQmedium

A Lambda function for a claims portal needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

A.AWS Systems Manager Parameter Store SecureString without automation
B.An encrypted object in Amazon S3
C.A KMS-encrypted Lambda environment variable
D.AWS Secrets Manager with rotation enabled
AnswerD

AWS Secrets Manager with rotation enabled stores the database credentials as a secret encrypted with a KMS key and automatically invokes a rotation Lambda function on a schedule to change the password. The Lambda can call GetSecretValue to fetch the current credentials, and the managed rotation eliminates manual credential updates, making it the right choice.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, automatically rotating, and managing secrets like database passwords. It supports automatic rotation every 30 days via a built-in Lambda rotation function, and it avoids storing the password in environment variables, which are visible in the Lambda console and logs.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store SecureString with Secrets Manager, assuming Parameter Store can also handle automatic rotation, but Parameter Store lacks native rotation capabilities and requires custom automation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store SecureString can store encrypted secrets but does not support automatic rotation without additional custom automation (e.g., a scheduled Lambda function). Option B is wrong because an encrypted object in Amazon S3 requires manual management of encryption keys and rotation, and the Lambda function would need to download and decrypt the object each time, adding complexity and latency. Option C is wrong because a KMS-encrypted Lambda environment variable, while encrypted at rest, is still stored as an environment variable that can be exposed in the Lambda function's configuration, logs, or error messages, and it does not support automatic rotation.

96
MCQmedium

An application encrypts data directly with AWS KMS using an encryption context. Your KMS key policy includes a condition that allows kms:Decrypt only when the encryption context contains: "purpose" = "myapp-secrets" After a deployment, decryption fails. CloudTrail shows kms:Decrypt was called, but it was denied by the key policy due to the encryption context condition. What is the best fix?

A.Update the application code to supply the correct encryption context "purpose" = "myapp-secrets" when calling decrypt (and encrypt if rotating).
B.Add kms:Decrypt to the IAM role attached to the application without changing the key policy.
C.Disable the encryption context condition in the KMS key policy to avoid future failures.
D.Rotate the KMS key immediately and re-encrypt all secrets with a different key ID.
AnswerA

The correct fix is to make the decryption call supply the exact encryption context used at encryption time, i.e., `"purpose" = "myapp-secrets"`. AWS KMS treats the encryption context as authenticated additional data (AAD): it is not stored encrypted, but it must be provided during decryption or the operation fails. If the KMS key policy condition requires `kms:EncryptionContext:purpose` to equal that value, then every decrypt request must include that context key and value to satisfy the policy. Updating the application code to consistently pass this context—both when encrypting new secrets and when decrypting existing ones—resolves the failure without weakening the key policy or forcing key rotation, and it preserves the integrity check that the context provides.

Why this answer

The decryption failure is directly caused by the application not supplying the required encryption context in the decrypt call. The KMS key policy condition explicitly requires the encryption context to include 'purpose'='myapp-secrets' for kms:Decrypt. Without this context, the request is denied regardless of IAM permissions.

Updating the application code to pass the correct encryption context during both encrypt and decrypt operations resolves the issue.

Exam trap

The trap here is that candidates may think IAM permissions alone can override key policy conditions, but KMS requires both IAM and key policy to allow an action, and conditions in the key policy are evaluated strictly.

How to eliminate wrong answers

Option B is wrong because adding kms:Decrypt to the IAM role does not override the key policy condition; KMS requires both IAM permissions and key policy to allow the action, and the key policy condition explicitly denies decryption without the correct encryption context. Option C is wrong because disabling the encryption context condition weakens security by removing a critical access control that ensures only authorized applications with the correct context can decrypt data. Option D is wrong because rotating the KMS key does not address the root cause—the encryption context mismatch—and re-encrypting with a different key ID would still fail if the application does not supply the required context.

97
MCQhard

A company uses AWS Organizations to manage multiple AWS accounts. A security engineer needs to prevent any IAM user in the organization from disabling AWS CloudTrail logging in any account. The solution must apply automatically to all existing and future accounts. What should the security engineer do?

A.Enable AWS CloudTrail organization trail and configure an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
B.Create an IAM policy that denies the cloudtrail:StopLogging action and attach it to all IAM users in each account.
C.Use AWS Config to monitor CloudTrail configuration changes and trigger an AWS Lambda function to re-enable logging if it is stopped.
D.Create an IAM role in each account with a permissions boundary that denies cloudtrail:StopLogging and assign it to all users.
AnswerA

An organization trail applies to all accounts in the organization, and an SCP can deny the specific actions that would disable logging. SCPs are inherited by all accounts, including future ones, and affect all principals, including root users. This combination ensures CloudTrail cannot be disabled, meeting the requirement with minimal ongoing effort.

Why this answer

Service control policies (SCPs) in AWS Organizations provide centralized control over the maximum available permissions for all accounts. By denying cloudtrail:StopLogging and cloudtrail:DeleteTrail, the SCP ensures that no principal, including root, can disable the organization trail. This solution automatically applies to all current and future accounts, satisfying the requirement.

Exam trap

The trap here is thinking that IAM policies or permissions boundaries applied per-account can enforce organization-wide restrictions, when only SCPs can centrally deny actions across all accounts and principals, including root users.

98
MCQeasy

A team runs a CPU-intensive image processing service on Amazon EC2. The service spends most of its time resizing and compressing images, and the team wants the best price-performance starting point for compute-heavy work. Which EC2 instance family should they choose?

A.Memory optimized instances
B.Compute optimized instances
C.Storage optimized instances
D.General purpose instances
AnswerB

Compute optimized instances, such as the C5 or C6g families, provide the highest vCPU-to-memory ratio and are purpose-built for CPU-intensive workloads like image processing, scientific modeling, and video encoding. Their enhanced clock speeds and sustained compute performance directly target the processing bottleneck, making them the most efficient and cost-effective choice for this workload.

Why this answer

Compute optimized instances (C family) are designed for workloads that benefit from high-performance processors, such as batch processing, media transcoding, and image processing. Since the team's service is CPU-intensive (resizing and compressing images), the C family provides the best price-performance starting point for compute-heavy work.

Exam trap

The trap here is that candidates may confuse 'CPU-intensive' with 'memory-intensive' or 'storage-intensive' and choose a general purpose instance (D) thinking it is a safe default, but the question specifically asks for the best price-performance starting point for compute-heavy work, which is the compute optimized family.

Why the other options are wrong

A

Memory optimized instances are designed for workloads that process large datasets in memory, not for CPU-intensive tasks like image resizing and compression, which primarily require high compute power.

C

Storage optimized instances are designed for workloads with high sequential I/O access to large datasets on local storage, not for CPU-intensive image processing tasks like resizing and compressing images.

D

General purpose instances balance compute, memory, and networking, but for CPU-intensive image processing, compute optimized instances offer better price-performance due to higher vCPU count and faster clock speeds.

99
MCQeasy

You use a customer managed AWS KMS key (CMK) to encrypt objects in an S3 bucket using SSE-KMS. A specific IAM role must be able to decrypt objects. Where should you grant kms:Decrypt permissions so that the role can decrypt data encrypted with that CMK?

A.In the KMS key policy, allowing kms:Decrypt (and any other required KMS permissions) for the role’s principal ARN.
B.Only in the S3 bucket policy by granting s3:GetObject, because S3 bucket policy controls decryption.
C.Only in the IAM role identity policy; the KMS key policy does not need changes for SSE-KMS.
D.By enabling S3 default encryption; KMS permissions are automatically granted to all IAM roles in the account.
AnswerA

With SSE-KMS, KMS decryption is authorized by KMS for the specific CMK. The CMK key policy is a primary authorization layer; if the key policy does not allow kms:Decrypt for the role (or a matching principal), S3 requests that require KMS decryption will fail even if the S3 or IAM identity policies allow s3:GetObject.

Why this answer

When using a customer managed KMS key (CMK) with SSE-KMS, the KMS key policy is the primary access control mechanism. To allow a specific IAM role to decrypt objects, you must grant kms:Decrypt (and typically kms:DescribeKey) in the key policy for that role's principal ARN. Without this explicit permission in the key policy, the role will be denied decryption even if it has s3:GetObject permissions, because KMS enforces its own authorization.

Exam trap

The trap here is that candidates assume S3 bucket policies or IAM identity policies alone are sufficient for decryption, forgetting that KMS enforces its own authorization layer and the key policy is the gatekeeper for all KMS operations.

Why the other options are wrong

B

S3 bucket policies control S3 actions like s3:GetObject, but they cannot grant KMS permissions. Decrypting SSE-KMS objects requires explicit kms:Decrypt permission on the CMK, which must be granted via the KMS key policy or an IAM policy that the key policy allows.

C

The KMS key policy must explicitly grant kms:Decrypt to the IAM role; without it, the role cannot decrypt objects even if it has an IAM policy allowing kms:Decrypt, because KMS key policies control access to the CMK and can override IAM policies.

D

Enabling S3 default encryption does not automatically grant KMS permissions to IAM roles; you must explicitly grant kms:Decrypt in the key policy or IAM policy for the role to decrypt objects encrypted with a customer managed CMK.

100
Multi-Selecthard

A company is designing a secure architecture for an internal microservices application running on Amazon ECS with the Fargate launch type. The security team wants each microservice to have its own fine-grained permissions to access specific AWS resources, and wants to avoid storing long-term AWS credentials in the container images or task definitions. The company also wants to encrypt data in transit between services. (Choose two.)

Select 2 answers
A.Enable AWS PrivateLink for communication between microservices and use TLS termination at the Network Load Balancer.
B.Attach an IAM user access key to each container through a mounted Amazon EFS volume.
C.Store AWS credentials in AWS Secrets Manager and inject them as environment variables in the task definition.
D.Implement mutual TLS between microservices using AWS App Mesh with certificate management through AWS Certificate Manager Private CA.
E.Use an ECS task IAM role for each microservice with a least-privilege policy attached.
AnswersD, E

AWS App Mesh provides service-to-service communication control and supports mutual TLS, where both sides present certificates to authenticate and encrypt traffic. Integrating with ACM Private CA allows the mesh to issue and rotate certificates automatically. This satisfies the requirement to encrypt data in transit between microservices and adds identity verification, which is a strong security control for internal microservices.

Why this answer

ECS task IAM roles provide each microservice with temporary, scoped credentials without storing secrets in images or task definitions, meeting the fine-grained permission and credential-hygiene requirements. AWS App Mesh with mutual TLS encrypts and authenticates service-to-service traffic using certificates from ACM Private CA, satisfying the in-transit encryption requirement. Together they form a least-privilege, encrypted microservices architecture.

Exam trap

The trap here is assuming that injecting secrets as environment variables or using PrivateLink alone provides the same security as task roles and mutual TLS.

101
MCQmedium

Your AWS Organization uses a Service Control Policy (SCP) that includes a Deny statement for secretsmanager:GetSecretValue for all member accounts in the "Finance" OU when requests are made outside us-east-1. An application role has an IAM policy that allows secretsmanager:GetSecretValue for the required secret in us-west-2. In us-west-2, requests fail with AccessDenied. What is the most appropriate action?

A.Update the application role IAM policy to include us-west-2 in the resource ARN.
B.Create a permission boundary that removes the deny behavior for the member account.
C.Modify the SCP to allow secretsmanager:GetSecretValue in us-west-2 for the Finance OU (if that aligns with policy intent), or move the workload to us-east-1.
D.Use sts:AssumeRole into another account that is not in the Finance OU to bypass the SCP.
AnswerC

Because the SCP contains an explicit Deny based on region and OU, the correct remedy is to change the SCP conditions (or operate within allowed regions). SCP evaluation is performed before/independent of IAM identity policies for the permission decision.

Why this answer

SCPs are deny-by-default and act as an outer boundary on all IAM policies in member accounts. Even if the application role's IAM policy allows secretsmanager:GetSecretValue in us-west-2, the SCP's explicit Deny for requests outside us-east-1 overrides that allow. The correct fix is either to modify the SCP to permit the action in us-west-2 (if that aligns with organizational intent) or to relocate the workload to us-east-1, because SCPs cannot be overridden by any IAM policy within the account.

Exam trap

The trap here is that candidates assume IAM policies alone control access and forget that SCPs act as a global deny filter that cannot be bypassed by any IAM-level configuration, leading them to incorrectly choose options that modify IAM policies or use cross-account roles.

How to eliminate wrong answers

Option A is wrong because the IAM policy already allows the action for the secret in us-west-2 (the resource ARN is not the issue); the failure is caused by the SCP's Deny, not a missing resource ARN. Option B is wrong because permission boundaries restrict the maximum permissions an IAM role can have, but they cannot override an SCP Deny; SCPs are evaluated before permission boundaries and a Deny in an SCP always takes precedence. Option D is wrong because assuming a role in another account does not bypass SCPs; the SCP applies to all principals in the member account, and the assumed role would still be subject to the SCP of the target account if it is also in the Finance OU, or the SCP of the source account if the trust policy is evaluated.

102
MCQmedium

A web application for a order processing API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

A.Security groups on the application instances
B.Network ACLs on the public subnets
C.AWS WAF associated with the Application Load Balancer
D.AWS Shield Advanced only
AnswerC

AWS WAF is a managed web application firewall that inspects HTTP and HTTPS requests at layer 7 and can be associated with an Application Load Balancer to filter traffic before it reaches backend instances. It supports AWS-managed rule groups, including the SQL database and cross-site scripting rule sets, that examine request components such as headers, query strings, and body payloads. When deployed on an ALB, WAF can block or allow requests in real time based on those rules, directly mitigating the specific attacks described.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS) attacks. By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP/HTTPS requests based on customizable rules, providing application-layer protection with minimal operational overhead since AWS manages the underlying infrastructure and rule updates.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups and network ACLs) with application-layer protection, assuming they can filter HTTP-level attacks, when in fact only AWS WAF can inspect and block SQL injection and XSS at the application layer.

How to eliminate wrong answers

Option A is wrong because security groups act as a virtual firewall at the instance level, controlling inbound and outbound traffic based on IP addresses and ports; they do not inspect application-layer payloads and cannot detect or block SQL injection or XSS attacks. Option B is wrong because network ACLs are stateless, subnet-level filters that evaluate traffic based on IP addresses, ports, and protocols; they lack the ability to parse HTTP request bodies or headers for malicious patterns. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric attacks but does not include application-layer filtering for SQL injection or XSS; it must be combined with AWS WAF for such threats.

103
MCQmedium

A solutions architect is designing an S3 bucket for a healthcare document service. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

A.Enable server access logging on the bucket
B.Enable S3 Transfer Acceleration
C.Create an IAM policy that denies s3:GetObject to anonymous users
D.Enable S3 Block Public Access at the account or bucket level
AnswerD

S3 Block Public Access at the account or bucket level provides four protective settings that prohibit public ACLs, ignore existing public ACLs, block public bucket policies, and restrict any bucket policy that would grant public access. For a healthcare document service, this acts as a strict guardrail that nullifies any accidental public exposure, regardless of how a bucket policy or ACL is configured. Since the settings are enforced centrally, they provide comprehensive coverage against bucket misconfiguration.

Why this answer

S3 Block Public Access provides a definitive override that prevents any public access to objects, regardless of bucket policies or object ACLs. When enabled at the account or bucket level, it blocks all public access settings, ensuring that even if a developer later adds an overly broad bucket policy, the objects remain inaccessible to anonymous users. This is essential for compliance with healthcare regulations like HIPAA, where data must never be publicly exposed.

Exam trap

The trap here is that candidates often think an IAM policy can block anonymous users, but IAM policies never apply to unauthenticated requests—only bucket policies and S3 Block Public Access can control anonymous access.

How to eliminate wrong answers

Option A is wrong because enabling server access logging only records requests made to the bucket; it does not prevent public access or enforce any security controls. Option B is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances using AWS edge locations; it has no impact on access permissions or public accessibility. Option C is wrong because an IAM policy that denies s3:GetObject to anonymous users is not effective—IAM policies apply only to authenticated IAM principals, not to anonymous (unauthenticated) users; anonymous access is controlled by bucket policies and ACLs, not IAM.

104
MCQmedium

A partner company needs read-only access to reports in an S3 bucket for a e-learning platform. The partner has its own AWS account. What is the most secure scalable access pattern?

A.Copy the objects to a public website bucket
B.Create an IAM user in the company account and share the access keys
C.Create a bucket policy that grants the partner role least-privilege access to the required prefix
D.Make the objects public and rely on difficult-to-guess object names
AnswerC

A bucket policy is a resource-based policy that can explicitly grant the partner's IAM role cross-account access to a specific prefix, such as s3:GetObject on arn:aws:s3:::reports/partner/*. This approach adheres to least privilege by restricting actions to only what is required (e.g., GetObject, ListBucket on that prefix) and by naming a specific external principal. It also avoids sharing long-term keys because the partner role will assume the role using its own credentials, and the policy can be updated or removed centrally by the bucket owner.

Why this answer

It uses a resource-based bucket policy that grants the partner's AWS account (via its root user or an IAM role) least-privilege read-only access to a specific prefix. This approach avoids sharing long-term credentials, leverages AWS's cross-account trust mechanism, and scales securely without managing additional IAM users.

Exam trap

The trap here is that candidates often choose Option B (sharing IAM user credentials) because it seems straightforward, but AWS recommends cross-account roles with bucket policies for secure, auditable, and scalable access without managing external users.

How to eliminate wrong answers

Option A is wrong because copying objects to a public website bucket removes all access control, exposing data to the internet and violating the principle of least privilege. Option B is wrong because creating an IAM user in the company account and sharing access keys introduces long-term static credentials that must be rotated, can be leaked, and do not scale across multiple partner accounts. Option D is wrong because making objects public with difficult-to-guess names relies on security through obscurity, which is not a secure pattern—objects can be discovered via enumeration or leaks, and S3 does not enforce access control based on name complexity.

105
MCQmedium

A partner company needs read-only access to reports in an S3 bucket for a customer analytics portal. The partner has its own AWS account. What is the most secure scalable access pattern?

A.Make the objects public and rely on difficult-to-guess object names
B.Create a bucket policy that grants the partner role least-privilege access to the required prefix
C.Copy the objects to a public website bucket
D.Create an IAM user in the company account and share the access keys
AnswerB

A resource policy can grant cross-account access to a specific external role and prefix.

Why this answer

A bucket policy that grants the partner's IAM role (from the partner's AWS account) least-privilege access to a specific prefix is the most secure and scalable pattern. This uses cross-account IAM roles, avoiding long-term credentials and allowing the partner to manage their own users and permissions. The bucket policy explicitly trusts the partner's AWS account, and the partner assumes the role to access only the required objects, following the principle of least privilege.

Exam trap

The trap here is that candidates often choose Option D (sharing IAM user access keys) because it seems straightforward, but the exam tests the understanding that cross-account IAM roles are more secure and scalable than sharing static credentials.

How to eliminate wrong answers

Option A is wrong because making objects public with difficult-to-guess names relies on security through obscurity, which is not a secure pattern; objects can be discovered via enumeration or accidental exposure, and it violates AWS's shared responsibility model. Option C is wrong because copying objects to a public website bucket exposes the data to the internet without any access control, which is insecure and does not scale for read-only access by a specific partner. Option D is wrong because creating an IAM user in the company account and sharing access keys introduces long-term static credentials that must be rotated and managed, increasing the risk of leakage; it also does not scale across multiple partners and violates the principle of using IAM roles for cross-account access.

106
MCQmedium

Company A runs an internal app in account A. The app needs to upload objects to an S3 bucket in account B. When the app calls S3, it receives AccessDenied for s3:PutObject. The team already created an IAM role in account B named UploadRole with a policy allowing s3:PutObject. They did not yet set up any trust relationship. Which change most directly fixes the access problem with least privilege?

A.Create IAM user access keys in account A and attach the UploadRole policy directly to those keys.
B.Update the trust policy on UploadRole (account B) to allow sts:AssumeRole from the app’s IAM role or principal in account A.
C.Add s3:PutObject permissions to the bucket policy in account B for all principals in account A.
D.Attach an SCP (service control policy) in AWS Organizations to deny sts:AssumeRole unless the caller uses an MFA device.
AnswerB

A cross-account role requires both an IAM permissions policy and a trust policy. The trust policy must allow the specific principal in account A to call sts:AssumeRole into account B’s role. With that trust in place, the app can obtain temporary credentials and then use the UploadRole permissions for s3:PutObject.

Why this answer

The app in account A needs to assume the UploadRole in account B to gain s3:PutObject permissions. Without a trust policy on UploadRole that allows sts:AssumeRole from the app's IAM principal in account A, the role cannot be assumed, resulting in AccessDenied. Updating the trust policy directly establishes the cross-account trust relationship with least privilege, as it grants only the necessary assume-role capability.

Exam trap

The trap here is that candidates often think bucket policies alone can solve cross-account access, but without a trust policy on the IAM role, the app cannot assume the role to obtain the required permissions.

Why the other options are wrong

A

IAM user access keys are long-term credentials and do not solve cross-account access; the app in account A needs to assume a role in account B, not use a user with a policy attached directly.

C

Option C grants s3:PutObject to all principals in account A, which violates least privilege by not restricting to the specific app role, and it does not address the missing trust relationship needed for cross-account access via role assumption.

D

The problem is lack of cross-account trust, not an SCP. SCPs deny actions at the OU/account level but don't grant permissions; they would only block access if already allowed, and here no trust exists.

107
MCQmedium

A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.

A.A VPC endpoint policy
B.API keys only
C.JWT authorizer configured for the OpenID Connect issuer
D.IAM authorization for all internet users
AnswerC

A JWT authorizer configured for the OpenID Connect issuer is the correct choice because API Gateway can automatically fetch the OIDC provider's JSON Web Key Set (JWKS) to validate the JWT signature, expiry, issuer, and audience. This allows the API to authenticate users who received tokens from a trusted OIDC-compatible identity provider (such as Amazon Cognito or Auth0) without managing a custom Lambda authorizer or session state. It also supports scopes and claims for fine-grained authorization, making it a low-operational-overhead and secure solution for public internet users.

Why this answer

C is correct because the scenario requires standards-based token authentication from an external OpenID Connect (OIDC) provider, and API Gateway's JWT authorizer natively validates JWTs issued by OIDC providers without requiring custom code. This authorizer verifies the token's signature, expiry, and issuer against the OIDC discovery endpoint, meeting the requirement to avoid custom operational scripts.

Exam trap

The trap here is that candidates often confuse API keys (simple identification) with token-based authentication (JWT/OIDC), or incorrectly assume IAM authorization can be used for external identity federation without custom Lambda authorizers or STS-based token exchange.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint policy controls access to API Gateway via VPC endpoints, not authentication for internet clients using OIDC tokens. Option B is wrong because API keys only provide simple identification and throttling, not authentication or authorization based on standards-based tokens from an external OIDC provider. Option D is wrong because IAM authorization is designed for AWS-authenticated principals (e.g., IAM users/roles), not for internet users presenting tokens from an external OIDC provider, and it would require custom scripts to map OIDC tokens to IAM roles.

108
MCQeasy

A production application stores critical data on an Amazon EBS volume. The team wants a simple backup method that allows the volume to be restored later if the server is lost. What should they use?

A.Amazon S3 bucket versioning
B.Amazon EBS snapshots
C.AWS Security Hub
D.Amazon CloudFront invalidations
AnswerB

EBS snapshots are the native backup mechanism for EBS volumes. They capture point-in-time copies that can later be used to create a new volume, making them a simple and reliable way to restore data after a server or volume loss. Snapshots are incremental, so repeated backups are efficient and suitable for ongoing protection.

Why this answer

Amazon EBS snapshots are the correct choice because they provide a simple, incremental backup method for EBS volumes. Snapshots capture the data on the volume at a specific point in time and are stored in Amazon S3, allowing the volume to be restored to a new EC2 instance if the original server is lost. This directly meets the requirement for a backup that enables restoration after server failure.

Exam trap

The trap here is that candidates might confuse EBS snapshots with S3 versioning, thinking that S3 can directly back up EBS volumes, but EBS snapshots are the native, designed service for this purpose.

Why the other options are wrong

A

Amazon S3 bucket versioning protects objects within S3 from accidental deletion or overwrite, but it does not back up EBS volumes. EBS volumes are block-level storage attached to EC2 instances, and S3 versioning cannot capture or restore the volume's state.

C

AWS Security Hub is a security posture management service that aggregates and prioritizes security findings from various AWS services; it does not provide backup or restore capabilities for EBS volumes.

D

CloudFront invalidations are used to remove cached content from edge locations, not for backing up or restoring EBS volumes.

109
MCQmedium

A team wants detective controls to investigate suspected exfiltration from an S3 bucket. They need to know when objects are accessed (GetObject) and also when new encrypted objects are written. They already enabled AWS CloudTrail for management events, but their investigation shows no visibility into object-level reads/writes in the logs they review. Which CloudTrail configuration change most directly provides the missing object-level visibility?

A.Enable CloudTrail data events for the specific S3 bucket so that GetObject and PutObject operations are logged at the object level.
B.Enable AWS Config delivery to a separate bucket and create a rule to detect noncompliant S3 policies; this will automatically generate GetObject logs.
C.Turn on VPC Flow Logs for the VPC hosting the S3 gateway endpoint, because network logs show S3 object read and write details.
D.Add an S3 bucket policy that denies all GetObject requests unless the caller uses TLS; the denial events will create investigation logs automatically.
AnswerA

CloudTrail management events cover control-plane activity, not per-object access details in S3. Enabling S3 data events (object-level logging) causes CloudTrail to record events like GetObject and PutObject for the targeted bucket and prefixes. This directly addresses the missing visibility symptom described. It also limits logging scope when you specify the bucket/prefix.

Why this answer

CloudTrail management events do not include object-level operations like GetObject or PutObject. By enabling CloudTrail data events for the specific S3 bucket, you capture object-level read (GetObject) and write (PutObject) API calls, including those for encrypted objects, providing the missing visibility for detective controls.

Exam trap

The trap here is that candidates confuse management events (which log bucket-level operations like CreateBucket) with data events (which log object-level operations like GetObject), assuming management events cover all S3 activity.

Why the other options are wrong

B

AWS Config does not generate GetObject logs; it tracks resource configuration changes and compliance, not data plane operations like S3 object access.

C

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) but do not log S3 API operations like GetObject or PutObject; they lack object-level details.

D

Denial events from a bucket policy that denies GetObject requests do not provide visibility into successful object access or writes; they only log denied attempts, not the actual GetObject or PutObject operations needed for detective controls.

110
MCQmedium

A high-frequency trading analytics service runs on several EC2 instances in the same Availability Zone. The application exchanges small messages between nodes and is sensitive to microsecond-level network latency. Which design best meets the requirement?

A.Place the instances in a cluster placement group in one Availability Zone.
B.Place the instances in a spread placement group across multiple Availability Zones.
C.Place the instances in a partition placement group within one Availability Zone.
D.Deploy the instances behind an Application Load Balancer in multiple Availability Zones.
AnswerA

A cluster placement group places instances physically close together within one Availability Zone, which improves network throughput and reduces latency between nodes. That is the right fit for tightly coupled workloads that exchange frequent small messages and need the lowest possible east-west latency. It also keeps the design simple because the application already runs in a single AZ.

Why this answer

A cluster placement group is designed for low-latency, high-throughput scenarios by placing instances in a single Availability Zone with non-blocking, fully bisectioned bandwidth and microsecond-level latency. This meets the requirement for microsecond-sensitive inter-node communication in high-frequency trading.

Exam trap

The trap here is that candidates confuse 'fault isolation' (spread/partition groups) with 'performance optimization' (cluster groups), or assume a load balancer can reduce latency when it actually adds overhead.

Why the other options are wrong

B

Spread placement groups are designed to reduce correlated failures by placing instances across distinct hardware, but they do not provide the low-latency, high-bandwidth network performance required for microsecond-level latency. Additionally, placing instances across multiple Availability Zones increases network distance and latency.

C

Partition placement groups are designed to reduce correlated hardware failures for large distributed workloads like HDFS or Cassandra, not to minimize network latency. They do not provide the low-latency, high-bandwidth network performance required for microsecond-level inter-node communication.

D

An Application Load Balancer (ALB) operates at Layer 7 and introduces significant latency (milliseconds), which is unacceptable for microsecond-sensitive trading. It also distributes traffic across AZs, increasing latency further.

111
MCQeasy

You manage multiple AWS accounts under AWS Organizations. A compliance requirement states: no account is allowed to create new IAM access keys for IAM users. Local administrators may attempt to override permissions. Which mechanism should you use to enforce this guardrail across all accounts?

A.An IAM permissions policy attached to a role that only your security team uses
B.An Organizations service control policy (SCP) that explicitly denies CreateAccessKey
C.A KMS key policy that blocks key creation and reuse
D.A permission boundary on a single IAM role
AnswerB

SCPs provide guardrails that apply to all principals in member accounts. By explicitly denying the IAM action at the organization level, you can prevent access key creation even if local IAM policies would otherwise allow it.

Why this answer

An SCP is the correct mechanism because it operates at the AWS Organizations root, OU, or account level to define a central guardrail that cannot be overridden by any IAM principal, including account administrators. By explicitly denying the `iam:CreateAccessKey` action, the SCP ensures that no IAM user in any account can create new access keys, fulfilling the compliance requirement across all accounts.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permission boundaries or think that a restrictive IAM policy on a single role can enforce a global guardrail, but only SCPs provide organization-wide, unoverridable control over all principals.

Why the other options are wrong

A

An IAM permissions policy attached to a role used only by the security team cannot enforce a guardrail across all accounts because it only applies to principals assuming that role, not to all IAM users in every account. Local administrators in other accounts can still create access keys unless explicitly denied by a centralized policy like an SCP.

C

KMS key policies control encryption key usage, not IAM user actions like creating access keys. They cannot enforce a guardrail against IAM operations across accounts.

D

A permission boundary applies only to a single IAM role, not to all users and roles across multiple accounts, so it cannot enforce the guardrail organization-wide.

112
MCQeasy

A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?

A.Allow secretsmanager:GetSecretValue on all secrets using Resource: "*"
B.Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service
C.Allow secretsmanager:* on the secret name prefix using a wildcard pattern
D.Allow secretsmanager:GetSecretValue on the AWS account root ARN
AnswerB

Restricting the Resource to the exact Secrets Manager secret ARN limits retrieval to only that secret. This minimizes exposure and follows least-privilege practices. (If the secret is encrypted with a customer-managed KMS key, additional KMS permissions may be required for decrypting the ciphertext, but the Secrets Manager permission itself should still be scoped tightly.)

Why this answer

It grants the minimum necessary permission—secretsmanager:GetSecretValue—scoped to the exact Amazon Resource Name (ARN) of the secret the microservice needs. This follows the AWS least-privilege principle by restricting access to a single action on a single resource, preventing the microservice from reading other secrets even if compromised.

Exam trap

The trap here is that candidates often choose a broad wildcard or 'all resources' permission (Option A or C) thinking it simplifies management, but the SAA-C03 exam consistently tests the principle of least privilege by requiring the most restrictive resource and action scope.

How to eliminate wrong answers

Option A is wrong because using Resource: '*' allows the microservice to retrieve any secret in the account, violating least privilege by granting broad read access. Option C is wrong because allowing secretsmanager:* on a wildcard prefix grants all Secrets Manager actions (including rotation, deletion, and tagging) on multiple secrets, far exceeding the single read requirement. Option D is wrong because the AWS account root ARN is not a valid resource ARN for Secrets Manager; secrets are identified by their own ARNs, not the root account ARN.

113
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only to users from a specific IP range, and the company wants to protect against common web exploits such as SQL injection and cross-site scripting. The company also wants to monitor and rate-limit requests from specific IP addresses. Which solution should a solutions architect implement?

A.Configure an AWS WAF web ACL with rules for IP matching, SQL injection, and cross-site scripting, and associate it with the ALB. Use rate-based rules to limit requests from specific IPs.
B.Deploy AWS Firewall Manager to create a security policy that includes AWS WAF rules for IP matching and rate limiting, and apply it to the ALB.
C.Configure an Amazon CloudFront distribution in front of the ALB, use AWS WAF with the CloudFront distribution, and set up geo-restriction to allow only specific IPs.
D.Use security groups on the ALB to allow traffic only from the specific IP range, and enable AWS Shield Advanced for protection against web exploits.
AnswerA

AWS WAF can be associated with an ALB to inspect incoming traffic. It provides managed rule groups for SQL injection and cross-site scripting, and you can create IP match conditions to allow only specific IP ranges. Rate-based rules automatically block IPs that exceed a request threshold, meeting the rate-limiting requirement. This is the most direct and effective solution.

Why this answer

AWS WAF integrated with the ALB provides the required protections: IP matching to restrict access to a specific IP range, managed rules for SQL injection and cross-site scripting, and rate-based rules to limit requests from specific IPs. This solution directly addresses all requirements without unnecessary components.

Exam trap

The trap here is confusing AWS Shield Advanced with AWS WAF; Shield protects against DDoS attacks, while WAF protects against application-layer exploits like SQL injection.

114
MCQeasy

A Lambda function processes CPU-heavy JSON transformations and often runs slower than expected. The team wants to improve performance without changing the code. What should they try first?

A.Increase the Lambda memory setting
B.Move the function to Amazon S3
C.Change the function to an ALB target
D.Disable CloudWatch logging
AnswerA

Increasing the Lambda memory setting directly allocates more proportional vCPU power to the function. This is crucial for CPU-heavy JSON transformations because it provides the necessary computational resources to execute the intensive processing faster. By boosting the available vCPU, the function can complete its work more efficiently, directly addressing the performance constraint of slow execution without requiring any code modifications.

Why this answer

Increasing the Lambda memory setting allocates more CPU power proportionally, as AWS Lambda allocates CPU credits linearly with memory (up to 10,240 MB). For CPU-heavy JSON transformations, this directly reduces execution time without any code changes, making it the simplest and most effective first step.

Exam trap

The trap here is that candidates assume performance issues must be solved by code optimization or architectural changes, overlooking that Lambda's memory setting directly controls CPU power, making it the simplest fix for CPU-bound functions.

Why the other options are wrong

B

Moving a Lambda function to Amazon S3 is not possible because S3 is a storage service, not a compute service. Lambda functions cannot be hosted or executed on S3.

C

Changing the function to an ALB target does not improve CPU-heavy JSON transformation performance; it only changes how the function is invoked, not its execution resources.

D

Disabling CloudWatch logging does not improve CPU-bound performance; it only reduces logging overhead, which is negligible for CPU-heavy transformations.

115
MCQmedium

A legacy market-data service runs on EC2 and exposes a custom TCP protocol. Clients must connect over TCP with very low latency, and the team wants static IP addresses at the load-balancing layer. Which AWS service is the best fit?

A.Application Load Balancer, because it provides advanced routing for all protocols.
B.Network Load Balancer, because it supports TCP, static IPs, and very low latency.
C.Amazon API Gateway, because it can front any network protocol with throttling.
D.Amazon CloudFront, because it can route traffic to EC2 instances at the edge.
AnswerB

A Network Load Balancer is the best fit for a custom TCP service that needs extremely low latency and static IP addresses. NLB operates at Layer 4, preserves high throughput, and is commonly used when protocol simplicity and performance matter more than application-layer routing features. It matches the workload's network requirements without adding unnecessary HTTP-specific behavior.

Why this answer

The Network Load Balancer (NLB) operates at Layer 4, supports TCP traffic natively, provides static IP addresses per Availability Zone, and delivers very low latency by processing packets without inspecting application-layer headers. This makes it the ideal choice for a legacy market-data service that requires a custom TCP protocol and fixed IPs at the load-balancing layer.

Exam trap

The trap here is that candidates often confuse the ALB's 'advanced routing' capabilities with support for all protocols, but ALB is strictly Layer 7 and cannot handle raw TCP or custom protocols, making NLB the only correct choice for TCP with static IPs and low latency.

Why the other options are wrong

A

Application Load Balancer does not support TCP at the transport layer; it operates at Layer 7 (HTTP/HTTPS) and cannot handle custom TCP protocols. It also does not provide static IP addresses.

C

Amazon API Gateway does not support custom TCP protocols; it only handles HTTP/HTTPS and WebSocket traffic, and it does not provide static IP addresses at the load-balancing layer.

116
MCQeasy

A database administrator wants a regular backup of an Amazon RDS database so the team can restore to a recent point in time if needed. Which AWS feature should they use?

A.RDS automated backups and snapshots
B.Amazon Route 53 alias records
C.Security groups
D.AWS WAF rules
AnswerA

RDS automated backups are enabled by default and provide a daily snapshot of the database plus transaction logs captured every five minutes. This combination enables point-in-time recovery to any second within the configured retention window, which can be set from 1 to 35 days. Manual snapshots, on the other hand, are user-initiated, persist indefinitely, and provide a baseline that can be used to restore a database after the automated retention period has lapsed. Together, these backup mechanisms are purpose-built for database recovery and are the correct way to ensure backup and restore capability for Amazon RDS.

Why this answer

Amazon RDS automated backups and snapshots provide the ability to restore a database to any point within the backup retention period (up to 35 days). Automated backups include transaction logs for point-in-time recovery, while manual snapshots are user-initiated backups stored until explicitly deleted. This directly meets the requirement for regular backups and point-in-time restore capability.

Exam trap

The trap here is that candidates may confuse security groups or WAF rules with backup mechanisms because they are common security services, but they have no role in data persistence or recovery.

Why the other options are wrong

B

Amazon Route 53 alias records are used for DNS routing, not for database backup or point-in-time recovery of RDS instances.

C

Security groups act as a virtual firewall for controlling inbound and outbound traffic to RDS instances, but they do not provide backup or point-in-time recovery capabilities.

D

AWS WAF rules are used to filter and monitor HTTP/HTTPS traffic to protect web applications from common web exploits, not for database backup or point-in-time recovery.

117
MCQmedium

An application runs on EC2 instances in private subnets behind an Application Load Balancer (ALB). Security groups allow inbound HTTPS (443) from the ALB’s security group to the instance security group, and outbound from instances is set to allow ephemeral ports. Despite this, clients see connection timeouts. After reviewing network ACLs, you find the NACL associated with the instance subnet has an inbound allow for destination port 443, but it does not have a corresponding outbound allow for ephemeral ports. What is the most likely reason the traffic fails, and what should be updated?

A.NACLs are stateless, so you must update the NACL to allow the return (outbound) ephemeral port range; security groups alone cannot override a blocked NACL.
B.NACLs are stateful and automatically track connections; the fix is to add a new inbound rule to the security group for client source ports.
C.The issue is caused by ALB health checks; configure a new target group health check on port 80 so traffic can be routed.
D.Because instances are in private subnets, add a NAT gateway so return traffic can reach the internet over dynamic routing.
AnswerA

NACLs are stateless, so return traffic from instances to clients on ephemeral ports needs an explicit outbound allow; the missing rule drops responses, causing timeouts. Security groups are stateful and cannot bypass a NACL denial.

Why this answer

Network ACLs are stateless, meaning they do not automatically allow return traffic. Even though the security group allows inbound HTTPS from the ALB, the NACL blocks the response traffic because it lacks an outbound rule for ephemeral ports (typically 1024-65535). Since NACLs are evaluated before security groups, a missing outbound allow rule causes the connection to time out.

Exam trap

The trap here is that candidates assume security groups alone handle all traffic filtering, forgetting that NACLs are stateless and require explicit outbound rules for return traffic, especially for ephemeral ports.

Why the other options are wrong

B

NACLs are stateless, not stateful; they do not automatically track connections. The issue is missing outbound ephemeral port rules in the NACL, not security group inbound rules for client source ports.

C

The question describes connection timeouts due to missing outbound NACL rules for ephemeral ports, not health check failures. ALB health checks are not mentioned as failing, and changing the health check port does not address the stateless NACL issue.

D

The issue is not about internet connectivity; instances are in private subnets but the ALB is in a public subnet and handles internet-facing traffic. A NAT gateway is for outbound internet access from private instances, not for fixing return traffic blocked by a stateless NACL.

118
MCQmedium

A company runs a three-tier web application on AWS. The database tier uses Amazon Aurora MySQL, and the application tier runs on Amazon EC2 instances behind an Application Load Balancer. A security audit reveals that the database credentials are stored in plaintext in a configuration file on the EC2 instances, and the same credentials have been in use for over a year. The security team must eliminate hardcoded credentials and ensure automatic rotation of the database password every 30 days without modifying application code to handle rotation events. Which solution meets these requirements with the LEAST operational overhead?

A.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and configure automatic rotation using a custom Lambda function that updates the parameter.
B.Store the database credentials in an encrypted Amazon S3 object and use an AWS Lambda function triggered by Amazon EventBridge to rotate the password and update the object every 30 days.
C.Store the database credentials in AWS Secrets Manager and enable automatic rotation using a Lambda rotation function. Grant the EC2 instance role permission to call secretsmanager:GetSecretValue.
D.Use IAM database authentication for Aurora MySQL so that the EC2 instances authenticate using their IAM role, eliminating the need for a database password.
AnswerC

AWS Secrets Manager natively supports automatic rotation of database credentials for Amazon Aurora MySQL by using a provided Lambda rotation function. The application retrieves the secret at runtime via the AWS SDK, and the EC2 instance role grants access through secretsmanager:GetSecretValue. This eliminates hardcoded credentials and rotates the password every 30 days without requiring application code changes to handle rotation events.

Why this answer

AWS Secrets Manager is designed for this exact use case: it stores database credentials securely and provides managed rotation for Amazon Aurora MySQL without custom code. The EC2 instance role grants access to the secret, and the application retrieves it at runtime. This removes hardcoded credentials and automates password rotation every 30 days, meeting the requirements with minimal operational effort.

Exam trap

The trap here is assuming that AWS Systems Manager Parameter Store provides automatic rotation for database credentials, when in fact it only stores parameters and requires a custom rotation implementation.

119
MCQhard

Based on the exhibit, a company wants EC2 instances in private subnets to access Amazon S3 without using a NAT gateway, and bucket access must be allowed only when requests come through the approved VPC endpoint. Which design is the most appropriate?

A.Use the S3 gateway VPC endpoint and keep the bucket policy that denies requests unless aws:SourceVpce matches the approved endpoint.
B.Use an interface VPC endpoint for S3 only, because gateway endpoints cannot be used with bucket policies.
C.Add a NAT gateway and remove the bucket policy condition because the NAT route will automatically secure the S3 traffic.
D.Move the bucket policy restriction to a security group attached to the S3 bucket so only the VPC endpoint can reach it.
AnswerA

For S3, a gateway VPC endpoint is the correct private-connectivity option for EC2 instances in private subnets. The route table sends S3 prefix-list traffic to the gateway endpoint, so requests stay on the AWS network instead of traversing a NAT gateway or the public internet. The bucket policy condition on aws:SourceVpce then ensures that even valid AWS-authenticated requests are accepted only when they arrive through the approved endpoint ID.

Why this answer

An S3 gateway VPC endpoint allows EC2 instances in private subnets to access S3 without traversing the internet or requiring a NAT gateway. By adding a bucket policy condition that denies access unless `aws:SourceVpce` matches the approved VPC endpoint ID, you ensure that only requests originating from that specific endpoint are allowed, meeting the security requirement.

Exam trap

The trap here is that candidates often confuse gateway endpoints with interface endpoints, assuming gateway endpoints cannot enforce bucket policies, or they mistakenly think security groups can be applied to S3 buckets, leading them to choose option D.

How to eliminate wrong answers

Option B is wrong because gateway endpoints for S3 can absolutely be used with bucket policies; in fact, the `aws:SourceVpce` condition is specifically designed for gateway endpoints. Option C is wrong because adding a NAT gateway would route traffic through the internet, which is unnecessary and violates the requirement to avoid using a NAT gateway; also, removing the bucket policy condition would leave the bucket open to any request, not just those through the VPC endpoint. Option D is wrong because S3 buckets do not support security groups; security groups are network-level constructs for EC2 instances and cannot be attached to S3 buckets.

120
MCQeasy

An order-processing application becomes slow when traffic spikes. The frontend should stay responsive even if downstream workers are temporarily overloaded. What should the team add to the design?

A.Amazon SQS queue between the frontend and the workers
B.A larger NAT Gateway
C.A single bigger EC2 instance for the worker
D.An Amazon Route 53 health check on the frontend
AnswerA

Amazon SQS acts as a durable buffer between the frontend and the worker instances, so incoming orders are immediately acknowledged and stored in the queue while workers consume messages at a pace they can handle. During a traffic spike, the queue absorbs the burst, preventing the frontend from being overwhelmed and allowing workers to scale out independently. It also provides at-least-once delivery and retries, which improves resilience when processing is temporarily slow or fails.

Why this answer

Adding an Amazon SQS queue between the frontend and the workers decouples the components, allowing the frontend to remain responsive by immediately offloading requests to the queue even when downstream workers are overloaded. The workers can then process messages at their own pace, and the queue acts as a buffer to absorb traffic spikes without blocking the frontend.

Exam trap

The trap here is that candidates often confuse scaling solutions (like larger instances or NAT Gateways) with decoupling patterns, failing to recognize that asynchronous message queuing is the correct approach to keep the frontend responsive under load.

Why the other options are wrong

B

A larger NAT Gateway increases outbound bandwidth but does not decouple the frontend from workers; it does not help the frontend stay responsive when workers are overloaded.

C

Scaling vertically to a single bigger EC2 instance does not address traffic spikes that overwhelm workers; it creates a single point of failure and does not provide elasticity or decoupling. The frontend would still block if the single worker is overloaded.

D

Route 53 health checks monitor endpoint availability and trigger DNS failover, but they do not decouple the frontend from downstream workers or absorb traffic spikes. The frontend would still directly invoke workers, causing overload and slowdowns.

121
MCQmedium

A public API for a financial reporting platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

A.JWT authorizer configured for the OpenID Connect issuer
B.IAM authorization for all internet users
C.API keys only
D.A VPC endpoint policy
AnswerA

A JWT authorizer is the correct choice because it natively validates RS256-signed OAuth2/OIDC tokens against the issuer's JSON Web Key Set (JWKS) without requiring custom Lambda code. For a financial reporting platform, it lets you use an existing enterprise identity provider (e.g., Auth0, Okta, Azure AD) so users authenticate with standard SSO, and you can enforce per-user scopes and claims. API Gateway automatically checks token expiry, issuer, and audience, giving low operational overhead while keeping authentication separate from application logic.

Why this answer

The scenario requires standards-based token authentication from an external OpenID Connect (OIDC) provider. API Gateway's JWT authorizer can validate JSON Web Tokens (JWTs) directly against the OIDC issuer's well-known configuration (JWKS URI) without custom Lambda code, making it the simplest and most secure choice for token-based authentication.

Exam trap

The trap here is that candidates often confuse IAM authorization (for AWS internal services) with token-based authentication for external clients, or they assume API keys alone are sufficient for security, ignoring the requirement for standards-based token validation.

How to eliminate wrong answers

Option B is wrong because IAM authorization is designed for AWS principals (users/roles) using Signature Version 4 signing, not for internet clients with external OIDC tokens. Option C is wrong because API keys only provide basic identification and rate limiting, not authentication or authorization against a standards-based token issuer. Option D is wrong because a VPC endpoint policy controls access to the API Gateway via VPC endpoints, not authentication of client tokens from an external OIDC provider.

122
MCQeasy

An S3 bucket uses a customer-managed KMS key as the default for SSE-KMS encryption. A service role will upload objects using s3:PutObject. Assuming the role already has permission to write to the bucket, which KMS permission is most directly required for the role to let S3 encrypt the object during upload?

A.kms:GenerateDataKey (and optionally kms:DescribeKey)
B.kms:Decrypt only
C.kms:CreateAlias and kms:UpdateAlias only
D.kms:ScheduleKeyDeletion and kms:CancelKeyDeletion only
AnswerA

For SSE-KMS uploads, S3 uses KMS to generate a data key for encrypting the object. kms:GenerateDataKey is the direct permission required for that flow. kms:DescribeKey can be useful for validation or troubleshooting, but it is not the core cryptographic permission.

Why this answer

When S3 uses SSE-KMS with a customer-managed KMS key, the service calls KMS to generate a data key for encrypting the object. The s3:PutObject operation requires the caller to have kms:GenerateDataKey permission on the KMS key so that S3 can obtain the plaintext and encrypted versions of the data key. Optionally, kms:DescribeKey may be needed for S3 to verify the key exists, but kms:GenerateDataKey is the most directly required permission.

Exam trap

The trap here is that candidates often confuse kms:Decrypt (needed for GET/read operations) with kms:GenerateDataKey (needed for PUT/write operations), or they assume any KMS permission will work because S3 handles encryption transparently.

How to eliminate wrong answers

Option B is wrong because kms:Decrypt is used for reading or decrypting objects, not for uploading new objects with SSE-KMS. Option C is wrong because kms:CreateAlias and kms:UpdateAlias are for managing key aliases, not for encrypting data during upload. Option D is wrong because kms:ScheduleKeyDeletion and kms:CancelKeyDeletion are key lifecycle management actions, unrelated to the encryption process for PutObject.

123
MCQeasy

A CI pipeline needs to upload build artifacts only to s3://ci-artifacts/uploads/*. You also want the pipeline to list only objects under uploads/ to verify that the upload succeeded. Which IAM policy approach is the best fit for least privilege?

A.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts with a condition that restricts s3:prefix to uploads/.
B.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts without any prefix condition.
C.Allow s3:GetObject on arn:aws:s3:::ci-artifacts/uploads/* so the pipeline can confirm artifacts exist.
D.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and also allow s3:DeleteObject on arn:aws:s3:::ci-artifacts/uploads/*.
AnswerA

This scopes object writes to only the uploads/ prefix (resource-level restriction for s3:PutObject) and scopes object listing to only that same prefix by restricting the ListBucket request via the s3:prefix condition key (bucket-level authorization for s3:ListBucket).

Why this answer

It grants the minimum required permissions: s3:PutObject on the specific uploads/ path for uploading artifacts, and s3:ListBucket on the bucket with a condition restricting the s3:prefix to uploads/ to list only objects under that prefix. This follows the least privilege principle by scoping both actions to the exact resources needed.

Exam trap

The trap here is that candidates often confuse s3:GetObject with s3:ListBucket for verifying uploads, or they forget to restrict the s3:prefix condition on ListBucket, leading to overly permissive policies.

Why the other options are wrong

B

Option B allows s3:PutObject on all objects under ci-artifacts (not just uploads/), violating the least privilege requirement to restrict uploads to uploads/*. Additionally, it grants s3:ListBucket without a prefix condition, allowing listing of all objects in the bucket, which is broader than needed.

C

The pipeline needs to upload artifacts (PutObject) and list objects (ListBucket) to verify uploads, not download them. GetObject is for reading object content, which is not required for verification.

D

Option D includes s3:DeleteObject, which is not required for the pipeline's tasks of uploading and listing artifacts. Granting unnecessary permissions violates the principle of least privilege.

124
MCQmedium

A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

A.Enable S3 Block Public Access at the account or bucket level
B.Create an IAM policy that denies s3:GetObject to anonymous users
C.Enable server access logging on the bucket
D.Enable S3 Transfer Acceleration
AnswerA

S3 Block Public Access provides a centralized, account- or bucket-level safety net that overrides both bucket policies and object ACLs. When enabled, the IgnorePublicAcls and BlockPublicPolicy settings cause S3 to reject any attempt to make objects publicly accessible via a public ACL or a policy that grants public access. This is the definitive control for a claims portal because it closes the two most common misconfiguration paths, ensuring claim documents remain private even if an administrator accidentally attaches a permissive policy.

Why this answer

S3 Block Public Access provides a definitive override that prevents any public access to objects, regardless of bucket policies or object ACLs. By enabling this setting at the account or bucket level, the architect ensures that even if a developer later adds an overly broad bucket policy, the S3 service will block all public access. This is the only option that directly and permanently prevents public exposure.

Exam trap

The trap here is that candidates often think an IAM deny policy (Option B) is sufficient, but they miss that bucket policies can grant access to anonymous users independently of IAM, making S3 Block Public Access the only reliable safeguard.

How to eliminate wrong answers

Option B is wrong because an IAM policy that denies s3:GetObject to anonymous users does not block access granted via a bucket policy that explicitly allows public access; bucket policies can override IAM policies for anonymous principals. Option C is wrong because server access logging only records requests to the bucket, it does not enforce any access restrictions. Option D is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances, it has no effect on access control or public accessibility.

125
Multi-Selecthard

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The architecture review board prefers a managed AWS-native control.

Select 2 answers
A.Interface VPC endpoint for Systems Manager
B.Internet gateway attached to the VPC
C.NAT gateway in each Availability Zone
D.Gateway VPC endpoint for Amazon S3
AnswersA, D

Interface VPC endpoints for Systems Manager are powered by AWS PrivateLink and create a private elastic network interface with a private IP address in each subnet. This allows instances in private subnets to communicate with the Systems Manager service (including the SSM agent and Parameter Store) without any internet-facing resources like NAT gateways or internet gateways. This is the correct and secure method for private instances to access Systems Manager.

Why this answer

Interface VPC endpoints (AWS PrivateLink) for Systems Manager allow EC2 instances in private subnets to access Parameter Store without traversing the internet. Gateway VPC endpoints for S3 provide a highly available, managed route to S3 via the VPC route table, requiring no NAT or internet gateway. Both are AWS-native, managed services that meet the architecture review board's preference.

Exam trap

The trap here is that candidates often confuse gateway VPC endpoints (for S3 and DynamoDB) with interface endpoints (for most other AWS services), or incorrectly assume NAT gateways are required for all private subnet outbound traffic, when managed endpoints can bypass the internet entirely.

126
MCQmedium

Account B has an IAM role that includes kms:Decrypt for a specific KMS key ARN in account A. However, when the role tries to read an S3 object encrypted with that CMK, the application fails with AccessDenied: not authorized to perform kms:Decrypt. CloudTrail shows the KMS API call is denied by key policy. What is the most secure and correct fix?

A.Update the IAM role in account B to include kms:Encrypt and kms:GenerateDataKey; then kms:Decrypt will start working automatically.
B.Update the KMS key policy in account A to allow the account B role principal to use kms:Decrypt on the key.
C.Disable key policy for the CMK by switching to S3-managed encryption, because KMS key policies are always enforced regardless of grants.
D.Create an SCP in account A that allows kms:Decrypt for all accounts, avoiding changes to the key policy.
AnswerB

Cross-account use of a CMK requires the KMS key policy (in the CMK’s account) to allow the external principal to perform kms:Decrypt. Since CloudTrail shows the denial is by key policy, updating the key policy to grant the account B role kms:Decrypt on the specific key is the correct and least-privilege solution.

Why this answer

Cross-account access to a customer managed KMS key (CMK) requires the key policy to explicitly grant the external IAM role principal the necessary permissions (e.g., kms:Decrypt). Even if the IAM role in Account B has an IAM policy allowing kms:Decrypt, the KMS key policy in Account A acts as a resource-based policy that must also allow the action; without this, the request is denied by the key policy, as shown in CloudTrail.

Exam trap

The trap here is that candidates often assume IAM permissions alone are sufficient for cross-account KMS operations, forgetting that KMS key policies are resource-based and must explicitly grant access to external principals.

How to eliminate wrong answers

Option A is wrong because adding kms:Encrypt and kms:GenerateDataKey to the IAM role does not resolve the key policy denial; the issue is the key policy in Account A, not the IAM permissions in Account B, and kms:Decrypt does not automatically work from other actions. Option C is wrong because disabling the CMK and switching to S3-managed encryption (SSE-S3) is not a secure fix for cross-account access; it removes customer control over encryption keys and does not address the need for cross-account KMS decryption. Option D is wrong because SCPs (Service Control Policies) are used to restrict permissions within an AWS organization, not to grant cross-account access; they cannot override a key policy denial, and creating an SCP that allows kms:Decrypt for all accounts would be insecure and ineffective.

127
MCQmedium

Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?

A.Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.
B.Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.
C.Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.
D.Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.
AnswerB

For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.

Why this answer

The application is failing because AppServerRole lacks the necessary permissions to use the customer-managed KMS key for decrypting S3 objects. By updating the KMS key policy or adding a grant to allow the role to perform `kms:Decrypt` and `kms:GenerateDataKey` operations, you restore access while maintaining encryption at rest with customer-managed KMS controls.

Exam trap

The trap here is that candidates often assume S3 bucket policies alone control access to encrypted objects, forgetting that SSE-KMS requires separate KMS key permissions that must be explicitly granted to the IAM role or user.

Why the other options are wrong

A

Changing to SSE-S3 removes customer-managed KMS controls, violating the requirement to keep encryption at rest with customer-managed KMS.

C

Moving the EC2 instance into the same Availability Zone as the S3 bucket does not resolve encryption errors related to KMS permissions, as S3 is a regional service and Availability Zone placement does not affect KMS authorization.

D

Attaching AmazonS3FullAccess does not bypass KMS authorization; S3 still requires KMS permissions to decrypt objects encrypted with customer-managed KMS keys, so the application would still fail.

128
MCQmedium

A media company has users around the world uploading 1 to 5 GB files directly to a single Amazon S3 bucket. Upload times are slow from distant regions, but the app must keep using S3 as the destination. What should the architects enable to improve upload performance?

A.Amazon CloudFront for origin caching of uploaded files.
B.Amazon S3 Transfer Acceleration on the bucket.
C.Provisioned IOPS EBS volumes attached to a transfer server.
D.Amazon EFS with a mount target in each Region.
AnswerB

S3 Transfer Acceleration improves upload performance over long distances by routing traffic through AWS edge locations and optimized network paths to the target bucket. This is a strong fit for globally distributed users uploading large files directly to S3. It preserves the same storage destination while making the transfer path faster and more consistent for remote clients.

Why this answer

Amazon S3 Transfer Acceleration (B) uses AWS edge locations to accelerate uploads over the public internet. When a user uploads a file, the data is sent to the nearest edge location via optimized network paths, then forwarded over AWS's private backbone to the S3 bucket. This reduces latency and improves throughput for large files (1–5 GB) from distant regions, directly addressing the slow upload times while keeping S3 as the destination.

Exam trap

The trap here is confusing CloudFront's edge caching for downloads with S3 Transfer Acceleration's edge-based upload optimization, leading candidates to select CloudFront (A) even though it does not improve upload performance to S3.

Why the other options are wrong

A

CloudFront is a content delivery network for caching and accelerating downloads, not uploads. It does not improve upload performance to an S3 bucket because uploads go directly to the origin, not through CloudFront.

C

Provisioned IOPS EBS volumes attached to a transfer server do not improve upload speeds to S3; they improve disk I/O for an intermediate server, but the bottleneck is network latency to S3, not local disk performance.

D

Amazon EFS is a shared file system for EC2 instances, not a direct upload destination for users. The question requires users to upload directly to S3, and EFS cannot replace S3 as the upload target.

129
MCQmedium

A web application for a mobile banking backend is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

A.Security groups on the application instances
B.AWS WAF associated with the Application Load Balancer
C.Network ACLs on the public subnets
D.AWS Shield Advanced only
AnswerB

AWS WAF is a Layer 7 (application-layer) firewall that you can associate with an Application Load Balancer to inspect every HTTP/HTTPS request before it is forwarded to backend instances. It can examine the entire request—including URI, query strings, headers, body, and cookies—and enforce custom rules or AWS managed rule groups specifically designed to block SQL injection and cross-site scripting. This makes it the correct service to protect the mobile banking backend from the described web attacks.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP(S) requests based on rules that block these attack patterns, all without managing any infrastructure. This provides the required protection with minimal operational overhead because AWS WAF is a fully managed service that integrates directly with ALB.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with application-layer protection, assuming that blocking ports or IP ranges is sufficient to stop web application attacks like SQL injection and XSS.

How to eliminate wrong answers

Option A is wrong because security groups act as a virtual firewall at the instance level, controlling inbound and outbound traffic based on IP addresses and ports; they cannot inspect application-layer payloads for SQL injection or XSS patterns. Option C is wrong because network ACLs are stateless, operate at the subnet level, and only filter traffic based on IP addresses, ports, and protocols — they have no capability to parse HTTP request bodies or headers for malicious content. Option D is wrong because AWS Shield Advanced provides DDoS protection and cost protection against scaling, but it does not include the application-layer rule sets needed to block SQL injection or XSS attacks; those require a web application firewall like AWS WAF.

130
MCQeasy

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be reachable only from a specific corporate CIDR range, and the instances must not be directly reachable from the internet. Which combination of security group configurations meets these requirements?

A.Allow inbound HTTP and HTTPS from 0.0.0.0/0 on the load balancer security group, and allow inbound HTTP from the load balancer security group on the instance security group.
B.Allow inbound HTTP and HTTPS from the corporate CIDR range on the instance security group, and allow outbound traffic to the load balancer security group.
C.Allow inbound HTTP and HTTPS from the corporate CIDR range on both the load balancer security group and the instance security group.
D.Allow inbound HTTP and HTTPS from the corporate CIDR range on the load balancer security group, and allow inbound HTTP from the load balancer security group on the instance security group.
AnswerD

Restricting the load balancer security group to the corporate CIDR range limits access to the approved network. Referencing the load balancer security group as the source in the instance security group allows only traffic forwarded by the load balancer, so the instances are not directly reachable from the internet. This matches both requirements.

Why this answer

The load balancer security group should allow only the corporate CIDR range on the listener ports, and the instance security group should allow traffic only from the load balancer security group. Referencing a security group as a source is the cleanest way to allow traffic from the load balancer without hardcoding its IP addresses, and it prevents direct client access to the instances.

Exam trap

The trap here is putting the corporate CIDR range on the instance security group, which permits clients to bypass the load balancer rather than forcing all traffic through it.

131
MCQhard

A SaaS vendor’s automation account in Account B needs to assume a role in a customer account in Account A to read a specific S3 bucket and publish a deployment status file. The customer is worried about confused deputy attacks because multiple customers use the same vendor software. Which trust-policy design best meets the requirement?

A.Allow the Account B root principal to assume the role if the caller knows the role ARN.
B.Allow only the vendor’s specific IAM principal to assume the role and require a unique sts:ExternalId condition.
C.Attach a permissions boundary to the role so that the vendor cannot exceed the approved permissions.
D.Require MFA for the role assumption because it ensures only the vendor’s production automation can use the role.
AnswerB

This is the standard confused deputy protection pattern for third-party cross-account access. The trust policy limits who can call AssumeRole, and the sts:ExternalId condition lets the customer require a customer-specific value that the vendor must supply. That prevents another customer or a malicious party from reusing the same role ARN successfully.

Why this answer

The `sts:ExternalId` condition is specifically designed to prevent the confused deputy problem in cross-account role assumptions. By requiring a unique external ID that only the customer knows, the customer ensures that the vendor's automation can only assume the role when acting on behalf of that specific customer, even if multiple customers use the same vendor software.

Exam trap

The trap here is that candidates often confuse MFA or permissions boundaries as solutions for the confused deputy problem, when in fact only the `sts:ExternalId` condition directly mitigates this specific threat by providing a customer-specific identifier in the trust policy.

How to eliminate wrong answers

Option A is wrong because allowing the Account B root principal to assume the role based solely on knowing the role ARN provides no protection against confused deputy attacks; any IAM entity in Account B (including compromised or malicious principals) could assume the role. Option C is wrong because a permissions boundary limits the maximum permissions the role can grant, but it does not address the confused deputy threat; it controls scope, not identity verification. Option D is wrong because requiring MFA ensures the caller is authenticated via a second factor, but it does not prevent a confused deputy scenario where the vendor's automation could be tricked into assuming the role on behalf of a different customer; MFA does not provide a customer-specific identifier.

132
MCQmedium

A security analyst needs to let an external vendor (AWS account 555566667777) read data from a set of internal resources in your AWS account. You created an IAM role called VendorReadRole with a policy that allows the required API calls. However, when the vendor tries to access, CloudTrail shows the call fails at AssumeRole with: "Not authorized to perform: sts:AssumeRole". What is the most appropriate fix?

A.Add an allow statement for the vendor in the role’s trust policy to permit sts:AssumeRole from the vendor account (and include any required ExternalId condition).
B.Attach the same allow policy to the vendor account’s existing IAM user so the user can call sts:AssumeRole directly into your role.
C.Replace the AssumeRole call with GetCallerIdentity so the vendor can infer permissions without assuming the role.
D.Enable MFA on the vendor’s IAM user and require MFA for your role using condition keys in the permissions policy.
AnswerA

To grant an external vendor access to your AWS resources, you must edit the role's trust policy to include a principal from the vendor account and an action of sts:AssumeRole. This trust relationship is the only mechanism that authorizes a foreign principal to assume your role; the permissions policy alone cannot authorize cross-account assumption. Adding an ExternalId condition prevents the confused deputy problem by ensuring the role is assumed only for your intended vendor, not a third party using the same role.

Why this answer

The error 'Not authorized to perform: sts:AssumeRole' indicates that the role's trust policy does not grant the external AWS account (555566667777) permission to assume the role. The trust policy must include an Allow statement with the sts:AssumeRole action, specifying the external account as the principal, and optionally an ExternalId condition to prevent the confused deputy problem. Without this trust policy configuration, even if the permissions policy allows the required API calls, the vendor cannot assume the role.

Exam trap

The trap here is that candidates often confuse the role's permissions policy (which defines what actions the role can perform) with the trust policy (which defines who can assume the role), leading them to incorrectly modify the permissions policy or the vendor's IAM user instead of the trust policy.

Why the other options are wrong

B

The trust policy on the IAM role must explicitly allow the external account to assume the role; attaching a policy to the vendor's IAM user does not grant cross-account sts:AssumeRole permissions because the role's trust policy controls who can assume it.

C

GetCallerIdentity does not grant cross-account access; it only returns details about the caller's own identity. The vendor needs to assume a role to access resources in the other account, not just check who they are.

D

The error is 'Not authorized to perform: sts:AssumeRole', which is a trust policy issue, not a permissions policy issue. Enabling MFA on the vendor's IAM user and adding an MFA condition to the role's permissions policy does not grant the vendor permission to assume the role; the trust policy must explicitly allow the vendor account to call sts:AssumeRole.

133
MCQmedium

A public API for a e-learning platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

A.A VPC endpoint policy
B.IAM authorization for all internet users
C.API keys only
D.JWT authorizer configured for the OpenID Connect issuer
AnswerD

The JWT authorizer configured for the OpenID Connect issuer is the correct choice because it validates the JWT's signature, expiry, issuer, and audience against the OIDC provider's public keys (JWKS), requiring no custom Lambda or additional infrastructure. It integrates directly with any standards-compliant IdP—such as Auth0, Okta, or the platform's existing identity service—so users' existing login tokens are recognized. This approach authenticates every request with low latency and minimal operational overhead while supporting fine-grained scopes and claims for authorization.

Why this answer

API Gateway supports JWT authorizers that validate JSON Web Tokens (JWTs) issued by an external OpenID Connect (OIDC) provider. This allows the API to authenticate clients using standards-based tokens without managing a custom Lambda authorizer, and it directly integrates with the OIDC issuer's JWKS endpoint to verify token signatures.

Exam trap

The trap here is that candidates often confuse API keys (which only identify the caller for usage plans) with authentication mechanisms, or assume IAM authorization can validate third-party OIDC tokens, when in fact IAM authorization requires AWS credentials, not external tokens.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint policy controls access to API Gateway from within a VPC, not authentication for internet-based clients using OIDC tokens. Option B is wrong because IAM authorization is designed for AWS-authenticated principals (e.g., IAM users, roles) and does not validate tokens from external OpenID Connect providers; it uses AWS Signature Version 4, not OIDC tokens. Option C is wrong because API keys only provide simple rate limiting and usage plans, not authentication or authorization; they do not validate the identity of the caller or support OIDC token verification.

134
MCQmedium

A Lambda function for a healthcare document service needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

A.A KMS-encrypted Lambda environment variable
B.An encrypted object in Amazon S3
C.AWS Systems Manager Parameter Store SecureString without automation
D.AWS Secrets Manager with rotation enabled
AnswerD

AWS Secrets Manager is purpose-built for storing secrets and, when rotation is enabled, it automatically rotates the secret value on a schedule using an associated Lambda function. It also keeps previous versions during rotation so applications can continue to work while the new secret is being tested, and it integrates natively with services like RDS, Redshift, and DocumentDB. This directly satisfies the need for automated secret rotation and eliminates the operational overhead of manually updating credentials.

Why this answer

AWS Secrets Manager is the correct choice because it is designed specifically for storing and automatically rotating database credentials. It supports native rotation for Amazon RDS, Redshift, and DocumentDB with a built-in Lambda rotation function, and it can rotate secrets on a schedule (e.g., every 30 days) without storing the password in environment variables. This meets the healthcare document service's requirement for automatic rotation and secure storage.

Exam trap

The trap here is that candidates often confuse Systems Manager Parameter Store (which can store SecureStrings) with Secrets Manager, but Parameter Store lacks automatic rotation, making it unsuitable for a 30-day rotation requirement without additional custom automation.

How to eliminate wrong answers

Option A is wrong because storing a KMS-encrypted password in a Lambda environment variable does not support automatic rotation; you would have to manually update the environment variable and redeploy the function. Option B is wrong because an encrypted object in Amazon S3 is a static storage mechanism with no built-in rotation capability, and accessing it requires managing S3 permissions and decryption logic manually. Option C is wrong because AWS Systems Manager Parameter Store SecureString without automation can store a secure password but lacks native rotation scheduling; you would need to build a custom rotation solution, whereas Secrets Manager provides this out of the box.

135
MCQeasy

A company serves a public API through a CloudFront distribution. They want to automatically block common web exploits (for example, OWASP Top 10–style threats) without building custom detection logic. Which AWS service configuration best meets the goal?

A.Enable AWS WAF with AWS Managed Rules and associate the web ACL with the CloudFront distribution.
B.Enable AWS Shield Advanced only; it fully replaces the need for WAF rule evaluation.
C.Attach a security group rule to the ALB to block malicious patterns based on HTTP request bodies.
D.Use Security Hub to block requests automatically when it detects suspicious activity.
AnswerA

AWS WAF inspects HTTP(S) requests and applies allow/block decisions based on rule matches. AWS Managed Rules provide prebuilt protections for common threat patterns, and attaching the WAF web ACL to CloudFront applies filtering at the edge.

Why this answer

AWS WAF with AWS Managed Rules provides pre-configured rule sets specifically designed to block common web exploits, including OWASP Top 10 threats, without requiring custom detection logic. By associating the web ACL with a CloudFront distribution, the filtering occurs at the edge, protecting the origin from malicious traffic before it reaches the application.

Exam trap

The trap here is confusing AWS Shield Advanced (which handles volumetric DDoS attacks) with AWS WAF (which handles application-layer threats like OWASP Top 10), leading candidates to believe Shield alone can replace WAF rule evaluation.

How to eliminate wrong answers

Option B is wrong because AWS Shield Advanced provides DDoS protection and cost mitigation, but it does not include application-layer rule evaluation for OWASP Top 10 threats; it is not a replacement for WAF. Option C is wrong because security groups operate at the network layer (Layer 3/4) and cannot inspect HTTP request bodies or application-layer payloads to block patterns like SQL injection or XSS. Option D is wrong because AWS Security Hub is a security posture management service that aggregates findings and does not have the capability to automatically block requests in real-time; it lacks inline traffic inspection and enforcement actions.

136
MCQmedium

A healthcare analytics company stores protected health information in an Amazon S3 bucket. An application running on Amazon EC2 instances in a private subnet must upload objects to the bucket using temporary credentials. The security team requires that the EC2 instances never store long-term AWS credentials on disk, and that access be limited to only the specific S3 bucket. Which solution meets these requirements?

A.Configure the S3 bucket policy to allow access from the EC2 instances' private IP addresses, and disable IAM authentication for the bucket.
B.Attach an IAM role to the EC2 instance profile with a policy granting s3:PutObject on the specific bucket, and let the AWS SDK retrieve temporary credentials automatically.
C.Generate a presigned URL for each upload using a role with broad S3 permissions, and distribute the URLs to the EC2 instances.
D.Create an IAM user with an access key, store the key in AWS Secrets Manager, and configure the application to retrieve it at runtime.
AnswerB

Attaching an IAM role to the instance profile allows the AWS SDK to obtain temporary credentials from the instance metadata service automatically. No long-term keys are stored on disk, and the attached policy can be scoped to grant only s3:PutObject on the specific bucket. This satisfies both the no-stored-credentials and least-privilege requirements with minimal operational overhead.

Why this answer

The requirement is temporary credentials without on-disk secrets, scoped to one bucket. An IAM role attached to the EC2 instance profile delivers rotating credentials through the instance metadata service, and the role's policy can be limited to the required S3 actions on the specific bucket. Long-term keys, presigned URLs, and IP-based policies do not satisfy the no-stored-credential and least-privilege conditions.

Exam trap

The trap here is assuming that storing long-term access keys in Secrets Manager converts them into temporary credentials.

137
MCQmedium

A static website uses an Amazon S3 bucket as the origin for an Amazon CloudFront distribution. The team accidentally configured the S3 bucket policy to allow s3:GetObject to Principal "*", so objects are accessible via direct S3 URLs. They want to ensure objects are retrievable only through CloudFront. What is the best corrective action?

A.Remove public access from the bucket and update the bucket policy to allow GetObject only from CloudFront using the distribution’s SourceArn (and use CloudFront origin access control or origin access identity).
B.Enable S3 static website hosting and disable CloudFront, because website hosting blocks direct object URL access.
C.Add a WAF rule that rate-limits requests to the S3 bucket domain to make direct access impractical.
D.Turn on S3 object versioning so that attackers cannot read previous objects.
AnswerA

Configure the S3 bucket to block all public access, then attach a bucket policy that grants s3:GetObject only to the CloudFront origin access control (OAC) identity, using the aws:SourceArn condition to restrict the principal to the exact CloudFront distribution ARN. This creates a hardened origin where the S3 bucket rejects any direct anonymous requests from the internet, while CloudFront's authenticated requests are permitted. Using OAC or OAI ensures the bucket owner has to intentionally authorize only that distribution, eliminating the common mistake of leaving objects publicly readable.

Why this answer

The S3 bucket policy currently allows s3:GetObject from any principal, making objects publicly accessible via direct S3 URLs. By removing public access and updating the policy to restrict GetObject to only requests that originate from the CloudFront distribution (using either Origin Access Control or Origin Access Identity), objects become retrievable exclusively through CloudFront, preventing direct S3 access.

Exam trap

The trap here is that candidates may think enabling S3 static website hosting or versioning solves the access control issue, but neither changes the bucket policy—only explicitly restricting the policy to CloudFront’s identity prevents direct S3 URL access.

How to eliminate wrong answers

Option B is wrong because enabling S3 static website hosting does not block direct object URL access; the S3 website endpoint is separate from the REST API endpoint, but the bucket policy still controls access, and objects remain accessible via direct S3 URLs unless the policy is restricted. Option C is wrong because a WAF rule applied to the S3 bucket domain is ineffective—WAF is a CloudFront feature and cannot be attached directly to an S3 bucket endpoint; rate-limiting would not prevent direct access, only reduce its frequency. Option D is wrong because enabling object versioning does not restrict access; it only preserves previous object versions, and without a restrictive bucket policy, all versions remain publicly accessible via direct S3 URLs.

138
MCQmedium

A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

A.API keys only
B.JWT authorizer configured for the OpenID Connect issuer
C.IAM authorization for all internet users
D.A VPC endpoint policy
AnswerB

A JWT authorizer validates the token signature against the OpenID Connect issuer's published JWKS and checks claims such as audience and expiry. This satisfies the requirement that clients authenticate with standards-based tokens from an external OpenID Connect provider, which IAM authorization or API keys cannot validate.

Why this answer

The scenario requires standards-based token authentication from an external OpenID Connect (OIDC) provider. API Gateway's JWT authorizer natively validates JSON Web Tokens (JWTs) issued by OIDC providers by verifying the token's signature against the provider's JWKS endpoint, checking the `iss` and `aud` claims, and enforcing token expiration. This directly meets the requirement without needing custom Lambda authorizers or additional infrastructure.

Exam trap

The trap here is that candidates confuse API keys (which are static and not standards-based) with JWT tokens (which are cryptographically signed and verifiable), or assume IAM authorization can be used for external identities without understanding that IAM requires AWS credentials, not OIDC tokens.

How to eliminate wrong answers

Option A is wrong because API keys only provide simple identification and rate limiting, not authentication or authorization; they do not validate token signatures, claims, or issuer trust. Option C is wrong because IAM authorization is designed for AWS internal identities (IAM users/roles) and requires AWS Signature V4 signing, which is not compatible with external OIDC tokens or internet-based clients without custom signing logic. Option D is wrong because a VPC endpoint policy controls access to API Gateway via VPC endpoints, not authentication; it cannot validate OIDC tokens or handle client identity from the public internet.

139
MCQmedium

A company runs a two-tier web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The EC2 instances must access an Amazon Aurora MySQL DB cluster. A security engineer must ensure that only these EC2 instances can connect to the database, and that no credentials are stored on the instances. What should the security engineer do?

A.Create a VPC endpoint for Aurora and attach an IAM policy that allows only the EC2 instance role to use the endpoint.
B.Configure the DB cluster security group to allow inbound MySQL traffic from the EC2 instances' security group, and enable IAM database authentication on the cluster.
C.Store the Aurora master credentials in AWS Secrets Manager and grant the EC2 instance role permission to retrieve the secret at boot.
D.Place the DB cluster in a private subnet and attach an AWS WAF web ACL to the cluster endpoint to filter incoming connections.
AnswerB

Referencing the EC2 instances' security group as the source in the DB cluster security group allows only those instances to reach port 3306, and IAM database authentication lets the application generate a short-lived authentication token from its IAM role instead of storing a database password on the instance.

Why this answer

Restricting the Aurora security group to the EC2 instances' security group enforces network-level isolation so only those instances can open a MySQL session. Enabling IAM database authentication lets the application use its IAM role to obtain a temporary token, so no long-lived database password is stored on the instances, satisfying both the access and credential requirements.

Exam trap

The trap here is assuming that moving credentials into Secrets Manager also restricts which hosts can connect, when network access control and credential management are separate concerns.

140
MCQeasy

A company’s private workload in a VPC uploads objects to an S3 bucket. Security requires that S3 requests are allowed only when they traverse a specific S3 Gateway VPC Endpoint (vpce-0abc123example). Which change best enforces this restriction at the S3 bucket level?

A.Add an S3 bucket policy Deny statement for s3:PutObject when aws:sourceVpce is not equal to vpce-0abc123example.
B.Add an S3 bucket policy Deny statement that blocks requests unless the principal uses MFA.
C.Enable Block Public Access and remove the public bucket policy statement.
D.Attach an IAM policy to the workload role that allows s3:PutObject only to the bucket ARN.
AnswerA

A bucket policy can use the request context key aws:sourceVpce to distinguish requests that came through a particular VPC endpoint. Using a Deny with a condition such as StringNotEquals on aws:sourceVpce blocks PutObject unless the request reached S3 via that specific Gateway Endpoint. Requests that arrive by other network paths will not match the required endpoint ID and will be denied.

Why this answer

It uses an S3 bucket policy with a Deny statement that explicitly denies any s3:PutObject request unless the request originates from the specified VPC Endpoint (vpce-0abc123example). The aws:sourceVpce condition key evaluates the VPC endpoint ID from which the request is made, ensuring that only traffic through that specific Gateway VPC Endpoint is allowed. This enforces the security requirement at the bucket level, overriding any other policies that might allow access from other sources.

Exam trap

The trap here is that candidates often confuse IAM policies (which control who can act) with bucket policies (which control how and from where access is allowed), leading them to choose an IAM-based solution (Option D) that does not enforce the network-level restriction required by the scenario.

How to eliminate wrong answers

Option B is wrong because requiring MFA does not restrict requests to a specific VPC Endpoint; it only adds an authentication factor, which does not enforce the network-level restriction. Option C is wrong because Block Public Access and removing public policies prevent public access but do not restrict requests to a specific VPC Endpoint; private traffic from other sources (e.g., the internet via a NAT gateway) would still be allowed. Option D is wrong because an IAM policy attached to the workload role controls what the role can do but does not restrict the network path; the workload could still send requests from any network interface, not just the specified VPC Endpoint.

141
MCQmedium

A company runs an EC2 Auto Scaling group behind an internet-facing Application Load Balancer. The security team must ensure that the instances accept HTTP traffic only from the ALB and never directly from the internet, while the ALB itself must accept traffic only from a specific corporate CIDR range. Which combination of security group configurations should a solutions architect implement?

A.Create an inbound rule on the instance security group allowing TCP 80 from 0.0.0.0/0, and an inbound rule on the ALB security group allowing TCP 80 from the corporate CIDR range.
B.Create an inbound rule on the instance security group allowing TCP 80 from the ALB's security group, and an inbound rule on the ALB security group allowing TCP 80 from the corporate CIDR range.
C.Create an inbound rule on the instance security group allowing TCP 80 from the corporate CIDR range, and an inbound rule on the ALB security group allowing TCP 80 from the ALB's security group.
D.Create an inbound rule on the instance security group allowing TCP 80 from the corporate CIDR range, and an inbound rule on the ALB security group allowing TCP 80 from 0.0.0.0/0.
AnswerB

Referencing the ALB's security group as the source means only traffic that the ALB forwards can reach the instances, regardless of the instances' public IPs. Restricting the ALB security group to the corporate CIDR range enforces the second requirement. This is the standard two-tier security group pattern and satisfies both conditions without extra infrastructure.

Why this answer

The secure pattern is to make the instances trust only the load balancer by referencing the ALB's security group as the source, and to make the ALB trust only the intended clients by scoping its inbound rule to the corporate CIDR range. This creates a chained trust model where the instances never accept direct internet connections and the ALB is not exposed beyond the approved network range.

Exam trap

The trap here is assuming the instances can match on the original client CIDR, when the ALB rewrites the source address so only a security group reference reliably identifies the load balancer.

142
MCQmedium

A healthcare company stores patient imaging studies in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A security audit reveals that a former employee's IAM user still has s3:GetObject permissions on the bucket. The company wants to ensure the former employee can no longer decrypt any objects, even if they somehow regain S3 access, without affecting other users or applications. What should a security engineer do?

A.Disable the customer managed KMS key used for the bucket encryption.
B.Add a bucket policy that denies s3:GetObject to the former employee's IAM user ARN.
C.Enable S3 Block Public Access on the bucket and rotate the IAM user's access keys.
D.Update the KMS key policy to explicitly deny the former employee's IAM user the kms:Decrypt action.
AnswerD

SSE-KMS requires the caller to have kms:Decrypt permission on the customer managed key in addition to s3:GetObject. Adding an explicit deny for the former employee in the key policy guarantees they cannot decrypt objects even if IAM or bucket policies later grant S3 access, because an explicit deny in the key policy overrides any allow. This achieves targeted revocation without impacting other principals.

Why this answer

With SSE-KMS, decryption requires both S3 read permission and kms:Decrypt on the customer managed key. Adding an explicit deny for the former employee in the KMS key policy ensures they cannot decrypt objects even if S3 access is accidentally restored, while leaving other principals unaffected. Bucket-level or access key actions do not remove the cryptographic capability, and disabling the key would break access for everyone.

Exam trap

The trap here is assuming that removing S3 permissions alone is sufficient, when SSE-KMS decryption also requires kms:Decrypt authorization on the key.

143
MCQmedium

A backup process restores a 2 TB production database from an EBS snapshot onto a new volume. During the first hours after restore, the application sees slow reads whenever previously unused blocks are accessed. What is the best way to avoid this performance issue in future restores?

A.Increase the volume size to give the database more free space.
B.Enable Fast Snapshot Restore on the snapshots used for recovery.
C.Move the database files to Amazon EFS after the restore completes.
D.Use magnetic standard volumes because they avoid snapshot hydration delays.
AnswerB

Fast Snapshot Restore removes the initial performance penalty that occurs when a restored EBS volume reads blocks that have not yet been hydrated. By pre-warming the snapshot data in the target AZ, it helps ensure consistent read performance immediately after restore. This is especially valuable for databases and other workloads that must recover quickly without waiting for the background hydration process.

Why this answer

When an EBS volume is restored from a snapshot, it is lazily loaded from Amazon S3 in the background. Accessing data blocks that have not yet been loaded triggers a read penalty because the volume must fetch them from S3 before serving the I/O. Enabling Fast Snapshot Restore (FSR) pre-warms the snapshot data so that restored volumes have full performance immediately, eliminating the slow reads on first access.

Exam trap

The trap here is that candidates may think increasing volume size or switching to a different storage class will fix the lazy hydration delay, but only Fast Snapshot Restore directly addresses the root cause by pre-initializing the data blocks.

Why the other options are wrong

A

Increasing volume size does not address the 'first touch' latency caused by lazy loading of data from snapshot to S3; it only provides more storage capacity.

C

Moving database files to Amazon EFS after restore does not address the slow reads caused by lazy loading of data from EBS snapshots (snapshot hydration). EFS is a network file system with its own performance characteristics and does not eliminate the need to initialize EBS blocks.

D

Magnetic standard volumes (st1/sc1) also suffer from snapshot hydration delays and have lower baseline performance than gp2/gp3, making them unsuitable for avoiding slow reads on previously unused blocks.

144
MCQeasy

A startup stores application configuration files in an Amazon S3 bucket. The security team wants to ensure that objects in the bucket are encrypted at rest with keys that the company manages and can rotate on its own schedule. Which S3 encryption option should a solutions architect choose?

A.Server-side encryption with AWS KMS keys (SSE-KMS) using a customer managed key.
B.Server-side encryption with customer-provided keys (SSE-C).
C.Client-side encryption with an AWS KMS key before uploading objects to the bucket.
D.Server-side encryption with Amazon S3 managed keys (SSE-S3).
AnswerA

SSE-KMS with a customer managed key lets the company control the key policy, define who can use the key, and configure automatic key rotation on a schedule the company chooses. This meets the requirement for company-managed keys with controllable rotation, and it also provides an audit trail of key usage through AWS CloudTrail, which is valuable for compliance.

Why this answer

SSE-KMS with a customer managed key gives the company ownership of the key policy, the ability to enable and schedule automatic key rotation, and CloudTrail visibility into key usage. The other S3 encryption options either leave key management to AWS, require the application to supply keys per request, or move encryption entirely to the client, none of which matches the requirement for company-managed, rotatable keys.

Exam trap

The trap here is assuming SSE-S3 allows customer-controlled rotation, when SSE-S3 keys are fully managed by AWS and cannot be rotated on a customer-defined schedule.

145
MCQmedium

Based on the exhibit, what is the most appropriate fix so the workload in Account A can access the S3 bucket in Account B without using long-lived access keys?

A.Create an IAM role in Account B, trust Account A's AppRole to assume it with STS, and then access the bucket using temporary credentials.
B.Attach AmazonS3FullAccess to the instance profile role in Account A and keep using the same direct access path.
C.Add an SCP to Account A that allows S3 actions against buckets in Account B.
D.Enable S3 versioning on the bucket so cross-account requests are automatically trusted.
AnswerA

Assuming a role in the target account is a clean cross-account pattern that uses temporary credentials instead of static keys. The trust policy in Account B controls who may assume the role, and the role in B can then be given the exact S3 permissions needed. This is easy to revoke centrally by changing the trust relationship or role policy.

Why this answer

It uses AWS Security Token Service (STS) to allow the workload in Account A to assume an IAM role in Account B, obtaining temporary credentials that grant access to the S3 bucket. This eliminates the need for long-lived access keys and follows the principle of least privilege, as the role can be scoped to specific S3 actions and resources.

Exam trap

The trap here is that candidates often confuse SCPs with resource-based policies or assume that attaching a managed policy to an instance profile automatically grants cross-account access, overlooking the need for explicit trust and bucket policies in the target account.

Why the other options are wrong

B

Option B is wrong because attaching AmazonS3FullAccess to the instance profile role in Account A does not grant cross-account access to an S3 bucket in Account B. The bucket's bucket policy must explicitly allow the role from Account A, and using long-lived access keys is not avoided.

C

SCPs (Service Control Policies) are used to restrict permissions in AWS Organizations accounts, not to grant cross-account access. They cannot allow actions; they only deny or limit permissions. Thus, adding an SCP to Account A does not enable the workload to access the S3 bucket in Account B.

D

Enabling S3 versioning does not grant cross-account access permissions; it only preserves object versions. Cross-account access requires explicit IAM policies and bucket policies, not versioning.

146
MCQmedium

A company hosts a image sharing application on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

A.AWS Systems Manager Session Manager with the required instance role
B.An internet gateway attached to the private subnet
C.A public Elastic IP address on each instance
D.A bastion host with SSH open to 0.0.0.0/0
AnswerA

AWS Systems Manager Session Manager gives you encrypted, browser-based shell access to EC2 instances without opening any inbound ports. The instance must have the SSM agent installed and be assigned an IAM instance role with AmazonSSMManagedInstanceCore, allowing it to poll the SSM API over TLS. User access is governed by IAM policies and all shell activity is logged to CloudTrail and optionally S3/CloudWatch Logs, giving audited secure administration.

Why this answer

AWS Systems Manager Session Manager allows administrators to establish secure shell (SSH) or PowerShell (RDP) sessions to EC2 instances without opening any inbound ports. It uses the SSM Agent and the AWS Systems Manager service, which initiates outbound connections to the AWS cloud over HTTPS (port 443). The required instance role grants permissions for the agent to communicate with Systems Manager, enabling secure, auditable access without public IP addresses or bastion hosts.

Exam trap

The trap here is that candidates often default to a bastion host (Option D) as a traditional solution, but fail to recognize that a bastion host still requires opening SSH/RDP to the internet (even if only to the bastion), which violates the 'without opening SSH or RDP ports to the internet' constraint.

How to eliminate wrong answers

Option B is wrong because an internet gateway attached to a private subnet does not provide direct connectivity to instances; it only enables outbound internet access via a NAT device, and does not allow inbound administrative connections without opening ports. Option C is wrong because assigning a public Elastic IP address to each instance would expose them to the internet, requiring SSH or RDP ports to be open, which violates the requirement to not open those ports. Option D is wrong because a bastion host with SSH open to 0.0.0.0/0 exposes the bastion to the entire internet, creating a security risk and still requires opening SSH (port 22) to the internet, which directly contradicts the requirement.

147
Multi-Selecthard

A reporting application in Account B must read files from an S3 bucket in Account A. The bucket contains objects encrypted with a customer managed KMS key in Account A. The application role in Account B already has an identity policy allowing s3:GetObject on the bucket prefix, but requests still fail with AccessDenied. Which two changes are required for the application to read the objects? Select two.

Select 2 answers
A.Add a bucket policy in Account A that allows the Account B role to perform s3:GetObject on the required prefix.
B.Add the Account B role to the KMS key policy in Account A with permission to use kms:Decrypt.
C.Attach an IAM policy in Account B that grants s3:* on the bucket and its objects.
D.Create an S3 gateway endpoint in Account B so the application can reach the bucket privately.
E.Add an SCP in Account A that allows the Account B role to bypass KMS encryption checks.
AnswersA, B

Cross-account S3 access requires a resource-based permission on the bucket. The bucket policy must explicitly allow the external role to read the needed prefix, otherwise the bucket owner blocks the request even if the role's identity policy allows it.

Why this answer

Cross-account S3 access requires the destination account (Account A) to explicitly grant access via a bucket policy that allows the source account's role (Account B) to perform s3:GetObject on the specified prefix. Without this bucket policy, the S3 service in Account A will deny the request, even if the IAM identity policy in Account B permits the action. Option B is correct because the objects are encrypted with a customer managed KMS key in Account A; the application role in Account B must be added to the KMS key policy with kms:Decrypt permission to decrypt the objects during retrieval.

Both the S3 bucket policy and the KMS key policy are required for cross-account encrypted access.

Exam trap

The trap here is that candidates often assume a cross-account IAM role with s3:GetObject permission is sufficient, overlooking that S3 bucket policies and KMS key policies are separate authorization layers that must explicitly allow the external principal, especially when objects are encrypted with a customer managed KMS key.

Why the other options are wrong

C

The application role in Account B already has an identity policy allowing s3:GetObject on the bucket prefix, so adding another IAM policy granting s3:* is redundant and does not address the cross-account permission issue or the KMS key policy requirement.

D

The error is AccessDenied, not connectivity issues. S3 Gateway Endpoints only provide private network access to S3, but do not grant IAM permissions or resolve KMS decryption authorization failures.

E

SCPs (Service Control Policies) cannot grant permissions; they only restrict permissions. Additionally, SCPs cannot bypass KMS encryption checks; the KMS key policy must explicitly allow the Account B role to use kms:Decrypt.

148
MCQmedium

A financial services company runs an internal web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must authenticate employees against the corporate identity provider (IdP) that supports SAML 2.0, and the company wants to avoid managing custom sign-in code. Which solution should a solutions architect recommend?

A.Create an IAM SAML identity provider and attach an IAM role to the EC2 instance profile so the instance can call the IdP.
B.Store the IdP SAML metadata in AWS Secrets Manager and have the application parse the SAML assertion on each request.
C.Configure the ALB to use an Amazon Cognito user pool as an authentication action, and federate the corporate IdP with the user pool.
D.Place AWS WAF in front of the ALB and create a rule that validates the SAML assertion signature before forwarding traffic.
AnswerC

ALB supports authenticate-cognito and authenticate-oidc actions on listener rules. A Cognito user pool can federate a SAML 2.0 IdP, so the ALB can offload the SAML exchange and issue its own session cookie. This meets the requirement without custom sign-in code on the EC2 instances.

Why this answer

The ALB can perform user authentication as a listener rule action using Amazon Cognito or an OIDC-compliant IdP. Because the corporate IdP speaks SAML 2.0, federating it with a Cognito user pool lets the ALB handle the SAML exchange and issue a session cookie, so the application receives only authenticated requests and no custom sign-in code is required.

Exam trap

The trap here is assuming that IAM SAML identity providers authenticate application users, when they actually federate identities for AWS API access.

149
MCQeasy

A CI/CD pipeline needs to deploy to your production environment. Security requires that the pipeline uses temporary credentials (not long-lived access keys) and only has permissions to read a specific set of parameters from AWS Systems Manager Parameter Store and write application logs to CloudWatch Logs. What is the best AWS approach?

A.Create an IAM user for the pipeline and store access keys in the CI system.
B.Create an IAM role in the production account, grant least-privilege policies, and let the CI assume it using STS AssumeRole.
C.Attach the required permissions to an IAM group and add the pipeline’s principal to that group directly.
D.Use AWS KMS to encrypt the pipeline’s access keys and store the ciphertext in the CI system.
AnswerB

STS AssumeRole issues short-lived credentials, eliminating long-lived access keys. Attaching least-privilege IAM policies scoped to the specific Parameter Store parameters and CloudWatch Logs write actions confines the pipeline to exactly the permissions required, satisfying both security constraints.

Why this answer

It uses an IAM role with least-privilege policies that the CI/CD pipeline can assume via AWS STS AssumeRole, providing temporary credentials that automatically expire. This avoids long-lived access keys and meets the security requirement of using temporary credentials. The role can be scoped to allow only reading specific parameters from Systems Manager Parameter Store and writing logs to CloudWatch Logs, adhering to the principle of least privilege.

Exam trap

The trap here is that candidates may think IAM users with access keys are acceptable for automation, but the question explicitly requires temporary credentials, making the IAM role with STS AssumeRole the only correct approach.

Why the other options are wrong

A

Option A uses long-lived access keys, violating the requirement for temporary credentials. IAM users with access keys are not temporary and increase security risk.

D

Using KMS to encrypt long-lived access keys does not eliminate the security risk of having permanent credentials; the pipeline still uses static keys, violating the requirement for temporary credentials.

150
MCQhard

A healthcare company stores protected health information in an Amazon S3 bucket. Compliance requires that all data be encrypted at rest with keys that the company controls and can rotate on demand. The security team also needs to audit every use of the encryption keys and immediately revoke access for a compromised IAM role without affecting other roles. Which solution meets these requirements?

A.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.
B.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS), and manage access through the KMS key policy.
C.Use S3 server-side encryption with AWS KMS AWS managed keys (SSE-KMS) and enable S3 server access logging.
D.Use client-side encryption with an AWS KMS customer managed key and store the encrypted data key in S3 object metadata.
AnswerB

Customer managed KMS keys give the company full control over rotation, and every use is recorded in AWS CloudTrail for auditing. The KMS key policy can grant or deny permissions per principal, so revoking the compromised IAM role is immediate and does not affect other roles that retain access.

Why this answer

Customer managed KMS keys provide the needed control: the company can rotate them, audit every cryptographic operation through CloudTrail, and enforce or revoke access using the key policy. AWS managed keys and S3 managed keys lack customer-controlled rotation and granular, auditable access control, so they cannot meet the compliance and revocation requirements.

Exam trap

The trap here is treating AWS managed KMS keys as equivalent to customer managed keys, when only customer managed keys allow on-demand rotation and key policy changes for immediate revocation.

← PreviousPage 2 of 4 · 293 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design Secure questions.