Courseiva

CCNA Security Governance Questions

18 of 168 questions · Page 3/3 · Security Governance topic · Answers revealed

151
MCQhard

Refer to the exhibit. An IAM policy attached to a user allows s3:GetObject only from a specific IP range and denies all S3 actions if not using HTTPS. What happens when the user makes a GET request from IP 10.0.0.5 using HTTP?

A.Allowed because the IP is in the range
B.Allowed because the condition does not match
C.Denied because the Deny statement matches
D.Denied because the IP is not in the range
AnswerC

IAM decisions are made by evaluating all statements: if any applicable Deny statement matches the request, the result is Deny regardless of any matching Allow. Here, the Deny statement's condition is satisfied by the request, and because explicit Deny statements cannot be overridden by Allows, the effective decision is denied. This is not due to a default deny or missing allow, but an active, matching Deny.

Why this answer

IAM policies evaluate all matching statements, and an explicit Deny always wins over any Allow. The policy denies all S3 actions when the request is not using HTTPS (aws:SecureTransport is false). Since the user made the request over HTTP, the Deny statement matches, so the request is denied regardless of the IP-based Allow.

Exam trap

SCS-C02 often tests the misconception that an Allow for a matching IP will permit the request — candidates forget that an explicit Deny with a matching condition always wins.

How to eliminate wrong answers

Option A is wrong because the IP being in the allowed range is irrelevant when an explicit Deny matches — explicit Deny overrides Allow. Option B is wrong because the condition does match: HTTP means aws:SecureTransport is false, triggering the Deny. Option D is wrong because the IP 10.0.0.5 is within the allowed range, so the IP is not the reason for denial — the HTTP protocol is.

152
Multi-Selectmedium

Which TWO AWS services can be used to centrally manage and audit permissions across multiple AWS accounts? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.AWS Organizations
D.AWS Single Sign-On
E.IAM Access Analyzer
AnswersC, E

AWS Organizations is the correct service for centrally managing multiple accounts and applying service control policies (SCPs) that place guardrails on the maximum permissions available to IAM principals within member accounts. SCPs act as a policy filter, allowing you to forbid or allow specific AWS services and actions at the organizational, organizational unit, or account level without modifying the IAM policies themselves. This makes Organizations a central control plane for permission boundaries across an entire AWS environment.

Why this answer

AWS Organizations provides a central view of all accounts and can apply SCPs. IAM Access Analyzer analyzes resource policies across accounts to identify public or cross-account access. AWS Config evaluates resource configurations but does not centrally manage permissions.

AWS CloudTrail logs API calls but does not manage permissions. AWS SSO manages user access but not resource permissions.

153
MCQhard

A security engineer is designing a solution to monitor and remediate non-compliant resources across multiple AWS accounts. The company uses AWS Organizations and wants to enforce that any S3 bucket with public read access is automatically remediated. The solution must be centralized and scalable. Which approach should the engineer take?

A.Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.
B.Create an AWS Config rule in each account and configure an Amazon CloudWatch Events rule to trigger an AWS Lambda function for remediation.
C.Use AWS Trusted Advisor to identify public buckets and manually remediate them.
D.Deploy an AWS Config conformance pack with a rule that checks for public buckets and reports non-compliance.
AnswerA

AWS Config conformance packs aggregate a pack of rules plus associated remediation actions, deployable across an entire AWS Organization from a single managed template. For a public S3 bucket, the included rule (e.g., s3-bucket-public-read-prohibited) detects noncompliance and automatically invokes an SSM Automation document, such as AWS-DisablePublicReadAccessForS3Bucket, to remove public access. This provides centralized, scalable, and fully automated governance rather than per-account, manual, or report-only controls.

Why this answer

AWS Config conformance packs allow you to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions in AWS Organizations. By including an auto-remediation action using AWS Systems Manager Automation, the solution can automatically remediate S3 buckets with public read access in a centralized and scalable manner, without manual intervention or per-account configuration.

Exam trap

The trap here is that candidates may confuse conformance packs with simple AWS Config rules, forgetting that conformance packs can include automated remediation actions via Systems Manager Automation, while standalone rules only detect and report non-compliance.

How to eliminate wrong answers

Option B is wrong because creating an AWS Config rule in each account is not centralized; it requires manual setup per account and does not scale efficiently across many accounts. Option C is wrong because AWS Trusted Advisor only identifies public buckets and provides recommendations, but it does not support automated remediation; manual remediation is not scalable or centralized. Option D is wrong because while an AWS Config conformance pack with a rule can detect non-compliant public buckets, it only reports non-compliance and does not include an auto-remediation action, failing to meet the requirement for automatic remediation.

154
MCQmedium

A company uses AWS Organizations with multiple accounts and wants to ensure that all newly created S3 buckets have encryption enabled. The Security team needs a solution that automatically remediates non-compliant buckets without manual intervention. What should they do?

A.Apply a service control policy (SCP) that denies the s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions unless the bucket has encryption enabled.
B.Use an S3 bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header.
C.Enable AWS Config with the s3-bucket-server-side-encryption-enabled rule and set up automatic remediation using Systems Manager Automation.
D.Create an IAM role with permissions to enforce encryption and attach it to all accounts in the organization.
AnswerC

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates each bucket and flags any bucket whose default encryption setting is disabled. When non-compliance is detected, the rule can trigger an SSM Automation remediation—typically the AWS-EnableS3BucketEncryption document—which automatically applies the appropriate SSE-S3 or SSE-KMS default encryption to the bucket. This pairing of continuous detection and automated remediation provides an enforceable, organization-wide corrective control that directly satisfies the encryption requirement.

Why this answer

AWS Config can continuously evaluate S3 buckets against the s3-bucket-server-side-encryption-enabled rule and automatically remediate non-compliant buckets using Systems Manager Automation, requiring no manual intervention. Option A is incorrect because a service control policy (SCP) cannot enforce encryption on bucket creation; the described SCP is circular and unenforceable since it denies s3:PutBucketEncryption unless encryption is already enabled, which is impossible to satisfy at creation time.

Exam trap

Candidates often think SCPs can enforce encryption on resource creation, but SCPs only control API permissions, not resource configuration. The correct approach is reactive remediation via AWS Config and automation, not proactive denial through SCPs.

How to eliminate wrong answers

Option B is wrong because an S3 bucket policy that denies PutObject unless the x-amz-server-side-encryption header is present only enforces encryption on objects uploaded to existing buckets, not on the bucket creation itself, and does not prevent creation of unencrypted buckets. Option C is wrong because AWS Config with the s3-bucket-server-side-encryption-enabled rule can detect non-compliant buckets, but automatic remediation using Systems Manager Automation requires manual setup and may not prevent creation in real time; it is reactive rather than proactive. Option D is wrong because creating an IAM role with permissions to enforce encryption and attaching it to all accounts does not automatically enforce encryption on new buckets; it only provides the capability, and users could still create buckets without encryption if they have other permissions.

155
Multi-Selectmedium

A security engineer needs to implement a solution to detect and alert on suspicious API calls in an AWS account. Which TWO AWS services should be integrated to achieve this? (Choose two.)

Select 2 answers
A.AWS Config
B.Amazon Inspector
C.AWS CloudTrail
D.AWS Trusted Advisor
E.Amazon GuardDuty
AnswersC, E

AWS CloudTrail is an audit service that continuously records all API activity in an AWS account, capturing the calling identity, source IP address, timestamp, request parameters, and response elements. CloudTrail itself is not a threat-detection engine—it simply produces the raw audit logs—but it is a required and correct component because it provides the management-event data that GuardDuty consumes to detect suspicious API calls. Enabling CloudTrail is the necessary first step, and when paired with GuardDuty's analysis engine, it becomes part of a complete detection solution.

Why this answer

AWS CloudTrail (C) is correct because it records API activity in the account as management and data events, providing the raw log source needed to detect suspicious API calls. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events (along with VPC Flow Logs and DNS logs) using threat intelligence and machine learning to detect and alert on suspicious API activity. Together, CloudTrail supplies the API call records and GuardDuty generates the findings and alerts.

AWS Config (A) evaluates resource configuration compliance rather than detecting suspicious API behavior, Amazon Inspector (B) scans workloads for software vulnerabilities and network exposure, and AWS Trusted Advisor (D) provides best-practice recommendations, so none of these fulfill the detection-and-alert requirement.

Exam trap

SCS-C02 often tests the pairing of CloudTrail (the data source) with GuardDuty (the analyzer), tempting candidates to pick AWS Config or Inspector, which address compliance and vulnerability scanning rather than threat detection.

156
MCQeasy

A company has a requirement that all S3 buckets must block public access. The security engineer needs to continuously monitor for compliance and automatically remediate any noncompliant buckets. Which combination of AWS services should the engineer use?

A.Amazon GuardDuty and AWS Security Hub
B.AWS Config and AWS Lambda (or SSM Automation)
C.AWS Organizations SCPs and AWS CloudTrail
D.AWS Trusted Advisor and Amazon SNS
AnswerB

AWS Config rules continuously evaluate bucket public access settings and flag noncompliant resources, triggering remediation. Lambda or SSM Automation then applies the block public access configuration automatically, satisfying both continuous monitoring and automatic remediation requirements.

Why this answer

AWS Config continuously evaluates S3 bucket configurations against a managed rule such as 's3-bucket-public-read-prohibited' or 's3-bucket-level-public-access-prohibited', detecting any bucket that becomes noncompliant. Config can then trigger an EventBridge event that invokes a Lambda function or SSM Automation document to re-apply the Block Public Access settings, delivering both continuous monitoring and automatic remediation. This is the canonical AWS pattern for compliance enforcement.

Exam trap

SCS-C02 often tests the distinction between detection-only services (GuardDuty, Security Hub, Trusted Advisor) and the Config + Lambda/SSM Automation pattern that provides both continuous compliance evaluation and automated remediation.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat-detection service that analyzes logs for malicious activity and Security Hub aggregates findings — neither continuously evaluates resource configuration state nor performs remediation. Option C is wrong because SCPs are preventive guardrails applied at the Organizations level and CloudTrail only records API activity; SCPs cannot retroactively detect or remediate an already-misconfigured bucket, and CloudTrail does not evaluate compliance. Option D is wrong because Trusted Advisor provides periodic best-practice checks (not continuous configuration evaluation) and SNS only delivers notifications — it cannot remediate.

157
Multi-Selectmedium

Which TWO actions are valid ways to enforce the principle of least privilege in an AWS environment?

Select 2 answers
A.Use the root user for daily administration
B.Use S3 bucket policies to allow all IAM users
C.Grant only the necessary actions in IAM policies
D.Use SCPs to deny actions that are not required
E.Assign the AdministratorAccess managed policy to all users
AnswersC, D

IAM policies define which actions an identity may perform on which resources; listing only the required actions means any unlisted API call is implicitly denied. This directly enforces least privilege at the identity-policy layer, satisfying the stem's requirement to grant no more than the task needs.

Why this answer

Option C is correct because least privilege means granting identities only the specific IAM actions and resources they actually need, so scoping IAM policy statements to the minimum required actions directly enforces that principle. Option D is correct because AWS Organizations Service Control Policies (SCPs) set a permissions boundary that can explicitly deny actions not required across accounts or OUs, preventing even otherwise-allowed IAM permissions from being used. Option A is wrong because using the root user for daily administration violates least privilege, as root has unrestricted access and should be reserved for a few account-level tasks.

Option B is wrong because an S3 bucket policy allowing all IAM users grants broad access rather than the minimum necessary. Option E is wrong because attaching AdministratorAccess to all users gives full administrative permissions, the opposite of least privilege.

Exam trap

SCS-C02 often tests the difference between IAM policies and SCPs. Candidates may think SCPs alone are sufficient, but they must be combined with IAM policies that grant only necessary actions. Also, candidates may confuse least privilege with other concepts like defense in depth.

158
MCQeasy

A company wants to centralize the management of IAM users and groups for multiple AWS accounts. Which AWS service should be used to allow users to access multiple accounts with a single set of credentials?

A.AWS Organizations
B.IAM users and groups in each account
C.Amazon Cognito
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (successor to AWS SSO) is designed precisely for centralized management of workforce user access to multiple AWS accounts. It connects to external identity providers like Okta, Azure AD, or its own built-in identity store, and assigns users and groups to accounts using permission sets that define granular IAM permissions. With IAM Identity Center, an organization can manage one user directory and control sign-in across all accounts, complete with MFA and auditing, eliminating the need to create IAM users in each account.

Why this answer

AWS IAM Identity Center (successor to AWS SSO) is purpose-built to centralize workforce access across multiple AWS accounts using a single set of credentials. It integrates with AWS Organizations to enumerate accounts and permission sets, and can federate with an external IdP (e.g., Okta, Azure AD) or use its own identity store. Users sign in once and pick from assigned accounts/roles, eliminating per-account IAM users.

Exam trap

SCS-C02 often tests the distinction between AWS Organizations (account governance) and IAM Identity Center (workforce SSO) — candidates pick Organizations because it 'centralizes accounts' and miss that it has no identity store.

How to eliminate wrong answers

Option A is wrong because AWS Organizations is a governance/billing construct for grouping accounts and applying SCPs — it does not provide a user identity store or single-sign-on credentials. Option B is wrong because creating IAM users and groups in each account is exactly the siloed, multi-credential model the company wants to eliminate; it does not centralize identity. Option C is wrong because Amazon Cognito is a customer-facing CIAM service for application sign-up/sign-in (user pools, identity pools), not for workforce SSO into AWS accounts/console.

159
MCQmedium

A company uses AWS Organizations with a single management account and multiple member accounts. The security team needs to ensure that all member accounts automatically deploy AWS Config rules to audit security group configurations. Which solution meets this requirement with minimal operational overhead?

A.Configure an AWS Lambda function in each account that periodically checks security group compliance.
B.Enable AWS Security Hub and rely on its built-in security group checks.
C.Use AWS Config conformance packs deployed via AWS CloudFormation StackSets from the management account.
D.Create an AWS Config rule in each member account manually using AWS CloudFormation templates.
AnswerC

AWS Config conformance packs bundle multiple managed or custom Config rules and remediation actions into a single CloudFormation template, and when deployed from the management account using CloudFormation StackSets, they are automatically applied to every target member account and Region. This leverages native AWS Organizations integration, so rules are provisioned consistently without manual per-account steps, and any updates to the conformance pack template can be rolled out centrally. With organization conformance packs, AWS Config manages the deployment across all accounts, making this a fully managed, scalable solution for enforcing security group compliance.

Why this answer

AWS Config conformance packs, deployed via AWS CloudFormation StackSets from the management account, allow you to centrally deploy a collection of AWS Config rules and remediation actions across all member accounts in an AWS Organization. This approach ensures consistent security group auditing with minimal operational overhead, as StackSets automatically handle deployment, updates, and drift detection across accounts and Regions.

Exam trap

The trap here is that candidates often confuse AWS Security Hub’s ability to aggregate and visualize security findings with the ability to automatically deploy and enforce Config rules, leading them to select Option B, but Security Hub does not deploy or manage Config rules itself.

How to eliminate wrong answers

Option A is wrong because using an AWS Lambda function in each account to periodically check security group compliance introduces significant operational overhead (function maintenance, scheduling, cross-account coordination) and does not leverage AWS Config’s native, event-driven compliance evaluation. Option B is wrong because AWS Security Hub provides security posture visibility and aggregates findings, but it does not automatically deploy AWS Config rules; it relies on existing Config rules or other integrations to generate findings. Option D is wrong because manually creating an AWS Config rule in each member account using AWS CloudFormation templates requires per-account deployment and maintenance, which is not scalable and contradicts the requirement for minimal operational overhead.

160
MCQeasy

A security engineer needs to grant an EC2 instance access to an S3 bucket without storing long-term credentials on the instance. Which approach should the engineer use?

A.Generate an access key and secret key for an IAM user and store them in the EC2 instance.
B.Use an SCP to allow the EC2 instance to access the S3 bucket.
C.Store the credentials in the AMI used to launch the instance.
D.Create an IAM role with the required permissions and attach it to the EC2 instance as an instance profile.
AnswerD

An instance profile is a container for an IAM role that you attach to an EC2 instance, and its trust policy allows the EC2 service to assume the role on behalf of the instance. When the instance calls the instance metadata service (IMDS) at 169.254.169.254, it receives temporary security credentials with the role's permissions, and these credentials are automatically rotated before they expire. This eliminates the need to store any long-term access key on the instance, keeps permissions centrally managed, and is the secure AWS-recommended approach for granting instance-level access to resources like S3.

Why this answer

An IAM role attached to an EC2 instance via an instance profile allows the instance to obtain temporary, automatically rotated credentials from the EC2 Instance Metadata Service (IMDS) at 169.254.169.254. This eliminates the need to embed long-term access keys anywhere on the instance or in the AMI. The instance assumes the role and receives short-lived STS credentials scoped to the role's permissions.

Exam trap

SCS-C02 often tests whether candidates confuse identity-based permission grants (IAM roles/instance profiles) with permission boundaries or guardrails (SCPs), leading them to pick an SCP as if it granted access.

How to eliminate wrong answers

Option A is wrong because generating long-term IAM user access keys and storing them on the instance creates a persistent credential that can be exfiltrated and has no automatic rotation. Option B is wrong because an SCP is an AWS Organizations policy that sets permission guardrails on accounts/OUs — it does not grant permissions to an EC2 instance and cannot by itself authorize S3 access. Option C is wrong because baking credentials into an AMI embeds static secrets in an image that may be shared, copied, or launched by others, and the credentials never rotate.

161
MCQhard

A security engineer is auditing the AWS Organizations structure. The engineer notices that the 'Management' account (111111111111) has a status of 'ACTIVE' and joined method 'CREATED'. The engineer is concerned about potential security risks. Which action should the engineer take to improve security?

A.Remove the management account from the organization.
B.Delete the management account and create a new one.
C.Create a new root user for the management account and delete the old one.
D.Enable multi-factor authentication (MFA) for the root user of the management account.
AnswerD

Enabling multi-factor authentication (MFA) on the management account's root user is a mandatory security best practice because the root user holds unrestricted permissions across the entire organization, including billing and the ability to close accounts. Without MFA, a compromised password or access key for the root user grants an attacker complete control of the organization's structure and member accounts. MFA forces a second authentication factor, mitigating password theft or phishing attacks on that critical identity.

Why this answer

The management account in AWS Organizations is the account that created the organization and has full administrative access. It is critical to secure this account, and enabling multi-factor authentication (MFA) for the root user is a fundamental security best practice. Option A is incorrect because you cannot remove the management account from the organization; it is the foundational account.

Option B is incorrect because you cannot delete the management account; you would need to delete the entire organization. Option C is incorrect because you cannot delete the root user; it is a built-in user that cannot be removed. Therefore, enabling MFA on the root user of the management account is the appropriate action to improve security.

162
MCQeasy

A security engineer needs to generate a report of all AWS Identity and Access Management (IAM) users who have not used their access keys in the last 90 days. Which AWS service can provide this information?

A.AWS IAM Credentials Report
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerA

The AWS IAM Credentials Report is a built-in console or API-generated CSV that inventories every IAM user and the root user, listing each access key's ID, status, creation date, and the exact date and time it was last used. This report is the authoritative source for producing a usage report because it directly provides last-used timestamps without requiring log mining. Generating it is a single action, and it can be refreshed on demand to reflect the most recent activity.

Why this answer

AWS IAM Credentials Report provides a CSV file with details about IAM users, including last activity dates. Option B is wrong because AWS CloudTrail logs API calls but does not provide a summary report. Option C is wrong because Amazon GuardDuty does not track IAM key usage.

Option D is wrong because AWS Config evaluates configurations, not usage.

163
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account for compliance. Which AWS service should be enabled to record the API calls that modify IAM policies?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.VPC Flow Logs
AnswerC

AWS CloudTrail is the native service that records management events in the AWS control plane, including every IAM policy change such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event includes the requesting principal, source IP, timestamp, and request/response details, giving you a complete audit trail. You can configure a trail to deliver these logs to S3 or CloudWatch Logs for long-term storage, analysis, and alerting on unauthorized IAM modifications.

Why this answer

AWS CloudTrail records API activity in an AWS account, including all calls that modify IAM policies such as CreatePolicy, PutRolePolicy, AttachRolePolicy, and DeletePolicy. Enabling CloudTrail (which is on by default for management events) provides the audit trail of who made the change, when, and from where. This is the correct service for auditing IAM policy modifications.

Exam trap

SCS-C02 often tests the difference between CloudTrail (who did what API call) and AWS Config (what the resource configuration was) — candidates confuse 'audit API calls' with 'track configuration changes' and pick AWS Config.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is a log storage and analysis service — it can receive CloudTrail logs, but it does not itself record API calls that modify IAM policies. Option B is wrong because AWS Config records resource configuration changes and evaluates compliance, but it does not provide the API-level audit trail of who made the change; Config shows the before/after state, not the API caller identity. Option D is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, port, protocol) for network interfaces, not AWS API calls.

164
MCQeasy

A security engineer needs to audit all IAM role creations across an AWS account. Which AWS service should be used to log these API calls?

A.Amazon GuardDuty
B.AWS Config
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct choice because it is the native AWS service for recording management events such as the CreateRole API call, capturing the requesting IAM principal, source IP, request parameters, and timestamp. By default, CloudTrail logs management events for all IAM actions, and you can deliver these logs to an S3 bucket or CloudWatch Logs for long-term retention and analysis. This makes CloudTrail the authoritative audit trail for answering 'who created this IAM role and when'.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including IAM role creation events (CreateRole). CloudTrail captures the identity of the caller, the time, source IP, and request parameters, making it the authoritative audit log for API activity. GuardDuty, Config, and CloudWatch Logs do not provide a complete API call history for IAM actions.

Exam trap

SCS-C02 often tests the confusion between CloudTrail (API activity auditing) and AWS Config (resource configuration history), causing candidates to pick Config for 'audit all IAM role creations' when the question asks for API call logging.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat detection service that analyzes logs for malicious activity; it does not log every API call or provide an audit trail of IAM role creations. Option B is wrong because AWS Config records resource configuration changes and compliance, but it does not capture the full API call details (who made the call, from where) for IAM role creation events. Option C is wrong because CloudWatch Logs is a log storage and monitoring service; it does not natively capture AWS API calls unless CloudTrail is configured to send them there.

165
MCQmedium

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which policy should be attached to the IAM users or group to enforce this requirement?

A.Allow access if MFA is present
B.Deny access if MFA is not present
C.Deny access if MFA is present
D.Grant access with a condition requiring MFA
AnswerB

An explicit deny statement using the condition 'aws:MultiFactorAuthPresent' equals 'false' will reject any IAM user request that did not authenticate with MFA. Because AWS IAM evaluation logic gives explicit deny precedence over every allow, this pattern universally blocks non-MFA access while still permitting MFA-authenticated requests. Correctly scoped, this is the standard and reliable way to enforce MFA across all users, including those with other grants.

Why this answer

The correct policy is to explicitly deny access when MFA is not present. In IAM, an explicit Deny overrides any Allow, so attaching a policy with a Deny statement conditioned on 'aws:MultiFactorAuthPresent' being false ensures that users without MFA are blocked from accessing the console. This is the standard pattern to enforce MFA because it cannot be bypassed by other permissive policies.

Exam trap

SCS-C02 often tests the difference between Allow and Deny in IAM policies, and candidates may incorrectly choose an Allow with a condition, not realizing that an explicit Deny is required to enforce MFA.

How to eliminate wrong answers

Option A is wrong because allowing access if MFA is present does not enforce MFA; users without MFA would still be allowed by other policies. Option C is wrong because denying access if MFA is present would block users who have MFA, which is the opposite of the requirement. Option D is wrong because granting access with a condition requiring MFA is an Allow statement, which can be overridden by other Allow statements and does not guarantee enforcement; an explicit Deny is needed.

166
MCQmedium

A company wants to use AWS CloudTrail to log all API activity across multiple accounts in AWS Organizations. Which configuration meets the requirement of centralized logging with minimal operational overhead?

A.Create a CloudTrail trail in each account and aggregate logs to a common S3 bucket
B.Enable CloudTrail in each account and use cross-account roles to centralize logs
C.Use AWS Config to record API calls and send to CloudWatch Logs
D.Create an organization trail in the management account that applies to all accounts
AnswerD

When you create a CloudTrail trail in the management account with the 'Apply trail to my organization' option enabled, CloudTrail automatically creates and configures trails in every member account, delivering all management events to a single S3 bucket. The trail is managed centrally by the organization management account, and any new accounts that join the organization are automatically included without additional manual setup. This provides the lowest operational overhead and ensures comprehensive, centralized logging of API activity across the entire AWS organization, which is exactly what the requirement demands.

Why this answer

Creating an organization trail in the management account automatically applies to all accounts in AWS Organizations, centralizing CloudTrail logs into a single S3 bucket without requiring per-account configuration. This approach minimizes operational overhead by leveraging the Organizations integration, which handles log delivery from member accounts transparently.

Exam trap

The trap here is that candidates often think they need to manually configure trails per account or use cross-account roles, missing the fact that AWS Organizations provides a native, low-overhead solution through organization trails that automatically centralize logging.

How to eliminate wrong answers

Option A is wrong because creating a trail in each account and aggregating logs to a common S3 bucket requires manual setup and maintenance per account, increasing operational overhead and risking inconsistent configurations. Option B is wrong because enabling CloudTrail in each account and using cross-account roles to centralize logs adds complexity with IAM role management and does not provide the automatic, unified logging that an organization trail offers. Option C is wrong because AWS Config records resource configuration changes, not API calls; it cannot replace CloudTrail for logging API activity, and sending to CloudWatch Logs does not centralize logs across accounts.

167
MCQeasy

A company wants to run a security assessment that checks for vulnerabilities in an EC2 instance. Which AWS service should be used?

A.Amazon Inspector
B.AWS WAF
C.Amazon GuardDuty
D.AWS Shield Advanced
AnswerA

Amazon Inspector is a vulnerability management service that automatically scans Amazon EC2 instances, container images in Amazon ECR, and Lambda functions for software vulnerabilities and unintentional network exposure. It assesses the OS and application packages against known CVE databases and CIS benchmarks, producing a risk score. This is precisely the security assessment tool suited for checking compute workloads for weaknesses.

Why this answer

Amazon Inspector automatically assesses EC2 instances for vulnerabilities and network exposure.

168
Multi-Selectmedium

Which TWO actions are effective for detecting and responding to unauthorized access in an AWS environment? (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail and monitor logs for suspicious activity.
B.Deploy Amazon GuardDuty to analyze CloudTrail logs and VPC Flow Logs for threats.
C.Use AWS Security Hub to automatically block suspicious IP addresses.
D.Enable VPC Flow Logs to capture all network traffic.
E.Enable IAM Access Analyzer to detect unauthorized access attempts.
AnswersA, B

CloudTrail records all API activity in your account—who made the call, from which IP, when, and with what outcome—enabling you to audit for suspicious behavior like new keys or unusual regions. But simply enabling CloudTrail is not enough; you must actively monitor the logs via CloudWatch Logs, Athena, or a SIEM. This is a detective control, not a preventive one, so it requires continual human or automated review to catch anomalies.

Why this answer

AWS CloudTrail records all API activity in your AWS environment, including management and data plane events. By enabling CloudTrail and monitoring its logs for suspicious activity (e.g., unusual API calls, failed authentication attempts, or access from unexpected IP addresses), you can detect unauthorized access. This is a foundational detective control that provides the audit trail necessary for incident response.

Exam trap

The trap here is that candidates often confuse detection services (like GuardDuty and CloudTrail) with automated remediation services (like AWS WAF or Lambda-based blocking), leading them to incorrectly select Security Hub as a blocking mechanism or IAM Access Analyzer as a real-time detection tool.

← PreviousPage 3 of 3 · 168 questions total

Ready to test yourself?

Try a timed practice session using only Security Governance questions.