Courseiva

CCNA Security and Compliance Questions

75 of 198 questions · Page 1/3 · Security and Compliance · Answers revealed

1
MCQmedium

A company has the following S3 bucket policy attached to a bucket named 'example-bucket'. A user is unable to download an object from the bucket using an HTTP URL (not HTTPS). What is the cause?

A.The bucket policy does not allow GetObject for anonymous users.
B.The Deny statement blocks all S3 actions when the request is not using HTTPS.
C.The bucket policy requires server-side encryption for all requests.
D.The Deny statement only applies to PutObject, not GetObject.
AnswerB

The Deny statement uses Action 's3:*' with a condition checked via aws:SecureTransport set to false, so any S3 API request sent over HTTP instead of HTTPS is denied. In IAM policy evaluation, an explicit Deny always overrides any Allow, meaning the earlier Allow for GetObject does not help when the request is not encrypted. This is exactly why non-HTTPS access is blocked for all S3 operations.

Why this answer

The bucket policy contains a Deny statement that applies to all s3:* actions when the request does not use HTTPS (SecureTransport is false). Even though there is an Allow statement for GetObject to everyone, the explicit Deny overrides the Allow. Option A is incorrect because the issue is not about anonymous users; the Deny affects all requests.

Option C is incorrect because the policy does not mention server-side encryption. Option D is incorrect because the Deny statement applies to all S3 actions, not just PutObject.

2
Multi-Selecteasy

A company wants to audit all API calls made in their AWS account for security analysis. They need to record both management events and data events. Which THREE steps should be taken to set up comprehensive logging? (Choose THREE.)

Select 3 answers
A.Enable AWS CloudTrail to record data events for S3 and Lambda.
B.Enable AWS CloudTrail to record management events.
C.Enable VPC Flow Logs to capture API call metadata.
D.Send the log files to Amazon CloudWatch Logs for real-time analysis.
E.Configure the trail to deliver log files to an S3 bucket.
AnswersA, B, E

Data events capture object-level API operations for S3, such as GetObject, PutObject, and DeleteObject, as well as Lambda function invocations. Unlike management events, data events are not enabled by default; you must explicitly configure the trail to include them, which is essential for auditing access to sensitive content and detecting suspicious data read/write patterns. Without this explicit enablement, the audit will miss critical resource-level activity that management events do not cover.

Why this answer

Option A is correct because CloudTrail data events are not logged by default; you must explicitly enable them for resources like S3 objects and Lambda invocations to capture those API-level operations. Option B is correct because management events (control-plane operations such as CreateBucket or RunInstances) are the core of CloudTrail auditing and must be enabled on the trail to record API activity across the account. Option E is correct because a CloudTrail trail must deliver its log files to an Amazon S3 bucket, which is the required destination for storing and later analyzing the audit logs.

Option C is not correct because VPC Flow Logs capture IP traffic metadata for network interfaces, not API call details, so they do not satisfy the API auditing requirement. Option D is not correct because sending logs to CloudWatch Logs is an optional enhancement for monitoring and alerting, not a required step for setting up comprehensive CloudTrail logging of management and data events.

Exam trap

SOA-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick Flow Logs thinking 'all activity' includes API calls, but Flow Logs cannot see IAM identities or API actions.

3
MCQmedium

A company's security team requires that all Amazon S3 buckets are encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). A SysOps administrator needs to automatically detect any S3 bucket that does not have encryption enabled and automatically apply SSE-S3 encryption. The solution should leverage AWS managed services and minimize custom code. Which combination of AWS services should be used?

A.Use AWS Trusted Advisor to identify unencrypted buckets and then manually enable encryption.
B.Use AWS Config managed rule 's3-bucket-server-side-encryption-enabled' with an automatic remediation action using AWS Systems Manager Automation.
C.Use AWS CloudTrail to detect PutBucket operations and trigger a Lambda function that enables encryption.
D.Create an IAM bucket policy that denies any PutObject request that does not include x-amz-server-side-encryption header.
AnswerB

The AWS Config managed rule 's3-bucket-server-side-encryption-enabled' continuously evaluates whether S3 buckets have default encryption such as SSE-S3, SSE-KMS, or DSSE-KMS configured. When a bucket is marked NON_COMPLIANT during either a configuration change or a periodic evaluation, AWS Config can invoke an AWS Systems Manager Automation document, specifically the AWS-EnableS3BucketEncryption runbook, to automatically update the bucket's encryption setting and immediately reevaluate it. This approach provides a closed-loop, automated remediation workflow that satisfies the security team's requirement without custom code or manual intervention.

Why this answer

AWS Config's managed rule 's3-bucket-server-side-encryption-enabled' continuously evaluates S3 buckets for encryption compliance, and its automatic remediation action can invoke an AWS Systems Manager Automation document to enable SSE-S3 encryption on noncompliant buckets without custom code. This fully meets the requirement to automatically detect and remediate unencrypted buckets using AWS managed services.

Exam trap

The trap here is that candidates often confuse enforcing encryption on object uploads (via bucket policies or CloudTrail/Lambda) with ensuring the bucket's default encryption setting is enabled, which is what AWS Config's managed rule and remediation specifically address.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only provides a manual check and recommendation; it cannot automatically apply encryption, and the requirement specifies automatic detection and remediation. Option C is wrong because AWS CloudTrail logs PutBucket operations but does not detect existing unencrypted buckets, and using a Lambda function introduces custom code, which the solution should minimize. Option D is wrong because an IAM bucket policy that denies PutObject requests without the encryption header only enforces encryption on new object uploads, not on the bucket's default encryption setting, and does not detect or remediate existing unencrypted buckets.

4
MCQeasy

A company has a fleet of EC2 instances in an Auto Scaling group behind an Application Load Balancer. The security team requires that all traffic to the instances be encrypted in transit. Currently, the ALB terminates HTTPS and forwards HTTP to the instances. The security team wants to ensure that the traffic between the ALB and the instances is also encrypted. What should the SysOps administrator do to meet this requirement with minimal changes?

A.Replace the ALB with a Network Load Balancer and use TLS termination on the instances.
B.Place a CloudFront distribution in front of the ALB and use HTTPS for all origins.
C.Set up a VPN connection between the ALB and the instances.
D.Change the ALB listener to use HTTPS and configure the target group to use HTTPS with a self-signed certificate on the instances.
AnswerD

This option correctly addresses the requirement by enabling TLS at both ends of the connection: the listener uses HTTPS to encrypt traffic from clients to the ALB, and the target group is configured with the HTTPS protocol so the ALB re-encrypts traffic to the instances. The instances use a self-signed certificate because the ALB does not need to validate it against a public CA; it simply establishes an encrypted channel, and you can optionally configure the ALB to verify the certificate if desired.

Why this answer

It encrypts traffic between the ALB and EC2 instances with minimal changes: you change the ALB listener to HTTPS and configure the target group to use HTTPS, using a self-signed certificate on the instances for encryption. Option A is incorrect because replacing the ALB with a Network Load Balancer is not minimal and adds complexity. Option B is incorrect because adding a CloudFront distribution introduces additional cost and overhead, not minimal.

Option C is incorrect because setting up a VPN connection is overly complex and not necessary for this requirement.

5
MCQeasy

A company stores sensitive data in an RDS database. Which AWS service should be used to encrypt the database at rest?

A.AWS Certificate Manager (ACM)
B.AWS Identity and Access Management (IAM)
C.AWS Key Management Service (KMS)
D.AWS CloudHSM
AnswerC

AWS Key Management Service (KMS) is a managed service for creating and controlling customer master keys (CMKs) that encrypt data at rest across AWS services, including Amazon RDS. When you enable encryption on an RDS instance, RDS uses a KMS CMK to encrypt the underlying EBS storage, automated backups, snapshots, and read replicas, with encryption handled transparently by the service. KMS is the only service among these options that natively integrates with RDS for at-rest encryption, making it the correct choice.

Why this answer

AWS Key Management Service (KMS) is the AWS service that manages the customer master keys (CMKs) used to encrypt RDS databases at rest. When you enable encryption on an RDS instance, you select a KMS key, and RDS uses that key to encrypt the underlying storage, snapshots, and read replicas. KMS integrates natively with RDS, EBS, S3, and most other AWS services for at-rest encryption.

Exam trap

SOA-C02 often tests the confusion between encryption in transit (ACM/TLS) and encryption at rest (KMS), so candidates who see 'certificate' or 'key' and pick ACM or CloudHSM instead of KMS lose the point.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager (ACM) issues and manages TLS/SSL certificates for encryption in transit, not at-rest data encryption. Option B is wrong because IAM handles authentication and authorization (who can do what), not cryptographic key management or data encryption. Option D is wrong because AWS CloudHSM is a dedicated hardware security module for customers with strict key custody requirements; while it can be used as a custom key store behind KMS, it is not the service you directly select to encrypt an RDS database.

6
MCQmedium

A company requires that all users in an AWS account must authenticate with multi-factor authentication (MFA) before they can perform any actions on Amazon EC2 instances. The SysOps administrator needs to implement this requirement using IAM policies. Which IAM policy condition key should be used to enforce MFA?

A.aws:SourceIp
B.aws:MultiFactorAuthPresent
C.aws:RequestedRegion
D.iam:PassedToService
AnswerB

The aws:MultiFactorAuthPresent condition key evaluates whether the principal authenticated with MFA during the current session. Attaching it with a Deny or Allow condition in IAM policies blocks non-MFA sessions from performing EC2 actions, enforcing the stated requirement.

Why this answer

The `aws:MultiFactorAuthPresent` condition key checks whether the user authenticated using a valid MFA device before making the API request. By setting this condition to `true` in an IAM policy, you can enforce that all actions on EC2 instances require MFA authentication, meeting the company's requirement.

Exam trap

The trap here is that candidates often confuse `aws:MultiFactorAuthPresent` with `aws:SourceIp` or `iam:PassedToService`, thinking IP-based or role-passing conditions can enforce MFA, but only the MFA-specific condition key directly checks authentication strength.

How to eliminate wrong answers

Option A is wrong because `aws:SourceIp` restricts access based on the source IP address, not MFA status. Option C is wrong because `aws:RequestedRegion` limits actions to specific AWS regions, not MFA enforcement. Option D is wrong because `iam:PassedToService` controls which roles can be passed to AWS services, not MFA authentication.

7
MCQmedium

A company uses Amazon S3 to store sensitive customer data. A SysOps administrator needs to ensure that any S3 bucket that is incorrectly configured to allow public read access is automatically remediated within five minutes. The administrator wants to use native AWS services with minimal custom code. Which solution should be used?

A.Use AWS Config with the 's3-bucket-public-read-prohibited' managed rule and configure automatic remediation to block public access.
B.Create an Amazon EventBridge (CloudWatch Events) rule that triggers an AWS Lambda function to check and fix public read access.
C.Apply an S3 bucket policy to each bucket that denies public read access.
D.Use AWS Trusted Advisor to check for public read access and manually remediate when notified.
AnswerA

AWS Config's 's3-bucket-public-read-prohibited' managed rule evaluates every S3 bucket against the defined parameter (blocking public read access) on a continuous basis. Because it is a managed rule, there is no custom code to write or maintain, and when coupled with automatic remediation (using an AWS Systems Manager Automation document that applies the 'block all public access' setting or removes bucket policies), noncompliant buckets are corrected within minutes. This is the only option that provides both automated detection and automated remediation using a pre-built, low-maintenance AWS service, meeting the five-minute requirement without manual intervention.

Why this answer

AWS Config with the 's3-bucket-public-read-prohibited' managed rule can automatically evaluate S3 bucket configurations against the desired state. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action (e.g., applying an S3 bucket policy or blocking public access) using AWS Systems Manager Automation documents, all within the required five-minute window and with minimal custom code.

Exam trap

The trap here is that candidates often choose EventBridge + Lambda (Option B) because it seems more flexible, but they overlook the 'minimal custom code' constraint and the fact that AWS Config's managed rule with automatic remediation is a fully native, code-free solution.

How to eliminate wrong answers

Option B is wrong because while EventBridge and Lambda can achieve the goal, they require custom code (Lambda function) and manual setup, which contradicts the 'minimal custom code' requirement. Option C is wrong because applying a bucket policy to each bucket is a manual, one-time action that does not provide automatic detection and remediation of newly created or misconfigured buckets. Option D is wrong because Trusted Advisor provides only manual checks and notifications; it cannot automatically remediate misconfigurations, and relying on manual remediation violates the 'automatically remediated within five minutes' requirement.

8
Multi-Selectmedium

An organization needs to encrypt data in transit between an Amazon EC2 instance and an Application Load Balancer (ALB). Which THREE actions should be taken?

Select 3 answers
A.Enable encryption at rest on the EC2 instance's EBS volumes.
B.Ensure the EC2 instance has a valid SSL/TLS certificate installed.
C.Configure the security group to allow only encrypted traffic.
D.Configure the ALB listener to use HTTPS protocol.
E.Install an SSL/TLS certificate on the Application Load Balancer.
AnswersB, D, E

If the Application Load Balancer is configured to forward traffic to the target group using HTTPS, the EC2 instance must have a valid SSL/TLS certificate installed to complete the TLS handshake. The instance presents this certificate to the ALB so that the session between them is encrypted, ensuring end-to-end protection from the client to the backend. Without a trusted, valid certificate matching the target's hostname, the ALB cannot establish the encrypted connection.

Why this answer

Encrypting data in transit between an EC2 instance and an Application Load Balancer requires the EC2 instance to present a valid SSL/TLS certificate. This allows the ALB to establish a secure HTTPS connection with the instance over the backend (target group) port, ensuring that traffic between the ALB and the instance is encrypted using TLS.

Exam trap

The trap here is that candidates often confuse encryption at rest (EBS encryption) with encryption in transit, or mistakenly believe security groups can filter based on encryption status, when in reality they only filter at the network layer.

9
MCQmedium

A company requires all S3 uploads to use server-side encryption with a specific customer managed KMS key. What is the most direct enforcement mechanism?

A.Add a bucket policy that denies PutObject unless the required SSE-KMS headers and key ID are present.
B.Enable S3 versioning only.
C.Enable S3 Transfer Acceleration.
D.Create an IAM user for every uploader with console access.
AnswerA

A bucket policy with an explicit Deny on s3:PutObject can inspect the s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id condition keys. If the request lacks the required SSE-KMS header or uses a different KMS key ID, S3 returns 403 AccessDenied before accepting the upload. This enforces encryption at write time, making it the only option that guarantees every upload is encrypted with your designated KMS key.

Why this answer

A bucket policy with a condition that denies `s3:PutObject` unless the required `x-amz-server-side-encryption` header is set to `aws:kms` and the `x-amz-server-side-encryption-aws-kms-key-id` header matches the specific customer managed KMS key ARN is the most direct enforcement mechanism. This policy-based approach ensures that any upload attempt lacking the required SSE-KMS headers and key ID is rejected at the S3 API level, regardless of the IAM permissions of the uploader.

Exam trap

The trap here is that candidates often confuse IAM permissions with bucket policy conditions, assuming that IAM policies alone can enforce encryption headers, when in fact only a bucket policy with the appropriate condition keys can directly deny uploads that lack the required encryption headers.

How to eliminate wrong answers

Option B is wrong because enabling S3 versioning only preserves object versions but does not enforce any encryption requirements on uploads. Option C is wrong because S3 Transfer Acceleration speeds up uploads over long distances but has no effect on encryption enforcement. Option D is wrong because creating an IAM user for every uploader with console access does not enforce server-side encryption; it only provides authentication and does not mandate the use of a specific KMS key or encryption headers.

10
MCQeasy

A company wants to allow an external auditor to assume an IAM role in their AWS account to review resources. What is the minimum information the auditor needs from the company to do this?

A.The Amazon Resource Name (ARN) of the IAM role to assume.
B.The IAM user name and password of the company's admin user.
C.The IAM policy document that grants the auditor access.
D.The AWS account ID and the region where resources are hosted.
AnswerA

The AssumeRole API in AWS Security Token Service (STS) requires a RoleArn parameter, and the role ARN is the globally unique identifier that the external auditor's account must pass to request temporary credentials. The ARN encodes both the AWS account ID that owns the role and the role name, which allows STS to locate the role and apply its trust policy. Without this ARN, the auditor cannot invoke the role-assumption flow at all.

Why this answer

To assume an IAM role, the auditor must know the role's ARN, which uniquely identifies the role (including the account ID and role name). The auditor then calls sts:AssumeRole with that ARN. The role's trust policy must also allow the auditor's AWS account or principal to assume it, but the ARN is the minimum information the auditor needs to initiate the call.

Exam trap

SOA-C02 often tests the misconception that the auditor needs the IAM policy document or account ID to assume a role, but the key requirement is the role's ARN, which uniquely identifies the role and is used in the AssumeRole API call.

How to eliminate wrong answers

Option B is wrong because sharing an admin user's credentials violates least privilege and is unnecessary; the auditor should use their own credentials to assume a role, not the company's admin user. Option C is wrong because the policy document alone does not identify the role; the auditor needs the role's ARN to assume it, and the policy is attached to the role, not used directly by the auditor. Option D is wrong because the account ID and region are insufficient; the auditor needs the specific role ARN, and the region is not required for global IAM role assumption (STS endpoints are global, though regional endpoints exist).

11
MCQmedium

An organization requires that all Amazon S3 buckets be encrypted at rest by default. A SysOps administrator needs to enforce this using AWS Config. Which AWS Config managed rule should be used?

A.s3-bucket-encryption-enabled
B.s3-bucket-ssl-requests-only
C.s3-bucket-public-read-prohibited
D.s3-bucket-logging-enabled
AnswerA

The AWS Config managed rule s3-bucket-encryption-enabled evaluates whether an S3 bucket has default encryption enabled, which is satisfied by configuring either SSE-S3 or SSE-KMS. This ensures new objects written to the bucket are automatically encrypted at rest, directly meeting the organization's encryption requirement. Without this rule, a bucket could store plaintext objects, making it the correct choice.

Why this answer

The AWS Config managed rule `s3-bucket-encryption-enabled` checks whether S3 buckets have default encryption enabled (SSE-S3, SSE-KMS, or SSE-C). This directly enforces the requirement that all buckets are encrypted at rest by default, as it evaluates each bucket's encryption configuration and flags non-compliant resources.

Exam trap

The trap here is that candidates often confuse encryption in transit (SSL/TLS) with encryption at rest, leading them to select `s3-bucket-ssl-requests-only` instead of the correct rule for default encryption.

How to eliminate wrong answers

Option B is wrong because `s3-bucket-ssl-requests-only` enforces that bucket policies deny HTTP requests, not encryption at rest. Option C is wrong because `s3-bucket-public-read-prohibited` checks for public read access, not encryption. Option D is wrong because `s3-bucket-logging-enabled` verifies that server access logging is enabled, which is unrelated to encryption at rest.

12
MCQmedium

A company's security policy requires that all Amazon EC2 instances must have a specific tag 'Environment' with a value of either 'Production' or 'Development'. The SysOps administrator needs to detect any instance that is missing this tag or has an invalid value, and automatically email the operations team. Which AWS service should be used to achieve this with the least operational overhead?

A.AWS Config with the 'required-tags' managed rule and Amazon SNS
B.Amazon CloudWatch Events with an EC2 instance state change rule and AWS Lambda
C.AWS Trusted Advisor with a custom check
D.Amazon Inspector with a network assessment
AnswerA

AWS Config continuously evaluates EC2 instances against the required-tags managed rule, which verifies that the mandated tag keys (and optionally values) are attached to each instance. On launch or any configuration change, noncompliant resources are recorded, and an Amazon SNS notification is delivered instantly to the security team. This approach is fully managed, requires no custom code, and maintains an audit trail of tag compliance over time.

Why this answer

AWS Config's 'required-tags' managed rule continuously evaluates EC2 instances against the specified tag key and allowed values, triggering an SNS notification when non-compliant resources are detected. This provides automated detection and alerting with minimal operational overhead, as it requires no custom code or infrastructure management.

Exam trap

The trap here is that candidates may confuse AWS Config's continuous compliance evaluation with event-driven services like CloudWatch Events, assuming that a state change rule can also check tags, but Config is purpose-built for resource configuration auditing without custom code.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events with an EC2 instance state change rule only triggers on state transitions (e.g., running, stopped), not on tag compliance; it would require a custom Lambda function to check tags, adding operational overhead. Option C is wrong because AWS Trusted Advisor does not support custom checks; it only provides predefined best-practice checks. Option D is wrong because Amazon Inspector performs network assessments for vulnerabilities and unintended network access, not tag compliance.

13
MCQmedium

A company's security policy requires that IAM users rotate their access keys every 90 days. The SysOps administrator must automatically identify users whose access keys are older than 90 days and notify the security team. Which combination of AWS services should be used to meet this requirement with the least operational overhead?

A.AWS Config with the 'access-keys-rotated' managed rule and Amazon SNS
B.AWS CloudTrail and Amazon CloudWatch Logs with metric filters and alarms
C.IAM Access Analyzer and AWS Lambda
D.Amazon GuardDuty and Amazon EventBridge
AnswerA

AWS Config's managed rule 'access-keys-rotated' continuously evaluates each IAM user's active access keys against the configured maximum age (default 90 days). When the rule detects a key that exceeds the threshold, it marks the user as noncompliant and emits a compliance change notification through the Config delivery channel, which publishes to an Amazon SNS topic. Subscribing security personnel to that topic via email or SMS gives them a near-real-time alert, making this a purpose-built, scalable solution for enforcing rotation policy.

Why this answer

AWS Config's 'access-keys-rotated' managed rule checks whether IAM user access keys have been rotated within the specified number of days (default 90). When a non-compliant resource is detected, AWS Config can trigger an Amazon SNS notification directly, without any custom code or additional infrastructure. This combination provides a fully managed, serverless solution with the least operational overhead.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing custom Lambda or CloudTrail-based approaches, missing that AWS Config provides a fully managed, built-in rule specifically designed for this exact compliance check with zero custom code.

How to eliminate wrong answers

Option B is wrong because CloudTrail logs API calls but does not evaluate the age of access keys; metric filters and alarms would require custom log parsing and lack the built-in compliance check. Option C is wrong because IAM Access Analyzer focuses on analyzing resource-based policies for external access, not on key rotation age; using Lambda would add custom code and maintenance overhead. Option D is wrong because GuardDuty is a threat detection service for malicious activity, not for tracking key rotation compliance; EventBridge alone cannot perform the age evaluation.

14
MCQeasy

A company wants to securely store secrets such as database credentials and API keys used by applications running on Amazon EC2. Which AWS service should be used to manage and rotate these secrets automatically?

A.AWS Identity and Access Management (IAM)
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is a purpose-built service for securely storing and managing database credentials, API keys, and other secrets throughout their lifecycle. It natively supports automatic rotation, either through built-in integration with AWS services like RDS, Redshift, and DocumentDB, or via custom AWS Lambda rotations. Unlike generic parameter storage, Secrets Manager enforces fine-grained IAM access policies and provides audit trails via AWS CloudTrail, making it the recommended choice for production secrets that require rotation and regulated access.

Why this answer

AWS Secrets Manager is designed to securely store, manage, and automatically rotate secrets such as database credentials and API keys. It integrates with AWS services like RDS, Redshift, and DocumentDB to provide built-in rotation. This makes it the correct choice for managing and rotating secrets automatically.

Exam trap

SOA-C02 often tests the confusion between Secrets Manager and Parameter Store, leading candidates to choose Parameter Store for automatic rotation when it does not natively support it.

How to eliminate wrong answers

Option A is wrong because AWS Identity and Access Management (IAM) is for managing access to AWS resources, not for storing and rotating secrets. Option C is wrong because AWS Key Management Service (KMS) is for creating and managing encryption keys, not for storing application secrets; it can be used to encrypt secrets but does not provide secret management or rotation. Option D is wrong because AWS Systems Manager Parameter Store can store secrets, but it does not provide automatic rotation natively; you would need to implement custom rotation logic.

15
MCQeasy

Refer to the exhibit. An IAM policy allows a user to run instances only of type t2.micro. What happens when the user tries to run a t2.small instance?

A.The request is allowed because the policy allows ec2:RunInstances.
B.The request is denied because there is an explicit deny on ec2:RunInstances.
C.The request is allowed because the condition only applies to the resource ARN, not the instance type.
D.The request is denied because t2.small does not match the condition.
AnswerD

The correct outcome is an implicit deny: the request for a t2.small instance fails the policy statement's condition that instanceType equals t2.micro. In IAM, for a request to be allowed, an allow statement must match the action, resource, and any specified conditions; here the action matches, but the condition does not. Since no other statement provides a different allow, the default deny takes effect.

Why this answer

The IAM policy includes a condition that restricts ec2:RunInstances to the t2.micro instance type. When the user attempts to launch a t2.small instance, the condition evaluates to false, so the statement does not apply and the request is implicitly denied. IAM policies are deny-by-default, so the absence of an allow results in denial.

Exam trap

SOA-C02 often tests the misconception that a policy allowing an action (ec2:RunInstances) automatically permits all variations of that action, ignoring the effect of condition keys that narrow the scope.

How to eliminate wrong answers

Option A is wrong because the policy does not grant unconditional ec2:RunInstances — the condition narrows the allowed instance type. Option B is wrong because there is no explicit deny in the policy; the denial is implicit due to the condition not matching. Option C is wrong because the condition applies to the instance type via a condition key (e.g., ec2:InstanceType), not just the resource ARN, so it does restrict the instance type.

16
MCQeasy

A SysOps administrator needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used to record these changes?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon S3
AnswerC

AWS CloudTrail is the authoritative service for auditing API activity in an AWS account, capturing every IAM API call such as PutRolePolicy, AttachUserPolicy, and CreatePolicy. Each CloudTrail event includes the IAM user or role, assumed role, session context, source IP, request parameters, response elements, and a timestamp. By default, CloudTrail provides a 90-day viewable event history, and creating a trail delivers immutable log files to an S3 bucket for long-term storage and optional CloudWatch Logs delivery. This makes CloudTrail the correct choice for auditing all IAM policy changes.

Why this answer

AWS CloudTrail is the correct service because it records API activity in an AWS account, including all IAM policy changes such as creating, updating, or deleting policies. CloudTrail captures these events as JSON logs, which can be stored in an S3 bucket for auditing and analysis. This makes it the appropriate tool for auditing changes to IAM policies.

Exam trap

The trap here is that candidates often confuse AWS Config with CloudTrail, thinking Config records API changes, but Config only tracks resource configuration states and compliance, not the API calls that caused those changes.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from AWS resources like EC2 instances or Lambda functions, but it does not natively record API calls or IAM policy changes; it requires CloudTrail to deliver logs to it. Option B is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes over time, but it does not record API-level events; it focuses on resource state rather than who made the change. Option D is wrong because Amazon S3 is an object storage service and cannot record or audit changes itself; it can only store logs delivered by other services like CloudTrail.

17
MCQmedium

A SysOps administrator is tasked with encrypting data at rest for an Amazon S3 bucket that stores sensitive customer information. The company requires that the encryption keys be managed by AWS and rotated automatically. Which encryption solution meets these requirements?

A.Use client-side encryption with AWS KMS.
B.Use server-side encryption with customer-provided keys (SSE-C).
C.Use server-side encryption with Amazon S3-managed keys (SSE-S3).
D.Use server-side encryption with AWS KMS (SSE-KMS).
AnswerC

Server-side encryption with Amazon S3-managed keys (SSE-S3) is the simplest way to encrypt data at rest in S3: S3 automatically encrypts each object with a unique key that is itself wrapped by a root key, all managed by AWS. These keys are automatically rotated on a regular basis, so you have no key material to manage or rotate, and there is no additional cost. This directly meets the requirement of encrypting data at rest with AWS managing the keys, making it the correct answer.

Why this answer

SSE-S3 uses Amazon S3-managed keys that are automatically rotated by AWS, meeting the requirement for AWS-managed and automatic rotation. Option A is wrong because client-side encryption is not managed by AWS and does not use server-side encryption. Option B is wrong because SSE-C requires the customer to provide their own encryption keys, which are not automatically rotated.

Option D is wrong because SSE-KMS uses AWS KMS keys that are customer-managed unless automatic rotation is specifically enabled, and the question requires automatic rotation without additional configuration.

18
Multi-Selectmedium

A company needs to restrict access to an S3 bucket so that only users from a specific VPC can read objects. Which THREE configurations are required?

Select 3 answers
A.Create a bucket policy that denies access unless the request comes from a specific VPC endpoint.
B.Update the route table in the VPC to route S3 traffic through the VPC endpoint.
C.Create IAM users and assign them permissions to access the bucket.
D.Create a VPC endpoint for S3 in the specified VPC.
E.Attach a security group to the S3 bucket.
AnswersA, B, D

This bucket policy explicitly denies all S3 access unless the vpc:SourceVpce condition matches the specified VPC endpoint (e.g., vpce-12345678). You must include both an Allow statement for the principal (such as the account root) and a Deny statement with StringNotEquals to prevent all other network paths. Requests from the VPC endpoint will carry the vpcSourceVpce value automatically, so only traffic routed through that endpoint is permitted.

Why this answer

Option D is correct because an S3 gateway VPC endpoint must first exist in the specified VPC to give that VPC private connectivity to S3 and to provide the vpce ID that the bucket policy will reference. Option A is correct because the bucket policy must explicitly deny (or restrict) access unless requests arrive via that VPC endpoint, typically using the aws:sourceVpce condition key with the endpoint ID. Option B is correct because the VPC route table must have a route for the S3 prefix list (pl-xxxxxxxx) pointing to the gateway endpoint so that traffic from the VPC actually traverses the endpoint and satisfies the policy condition.

Option C is not required because the scenario restricts access by network origin (VPC endpoint), not by individual IAM identities, and IAM users alone would not enforce the VPC restriction. Option E is not valid because security groups cannot be attached to S3 buckets; S3 access control uses bucket policies, IAM policies, ACLs, and endpoint policies instead.

Exam trap

SOA-C02 often tests the misconception that a VPC endpoint alone restricts access — candidates forget the bucket policy condition and route table entry, or wrongly assume security groups can be attached to S3.

19
MCQeasy

A company uses AWS Key Management Service (KMS) to encrypt data in S3. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which of the following is the MOST effective way to achieve this?

A.Create a separate KMS key for each bucket and assign the IAM role as a key user
B.Configure an S3 bucket policy that allows only the IAM role to perform s3:GetObject
C.Use a KMS key policy with a condition that requires the encryption context to match the bucket ARN, and grant the IAM role decrypt permissions
D.Use an S3 bucket policy that denies s3:GetObject unless the request includes the x-amz-server-side-encryption-aws-kms-key-id header
AnswerC

This is the correct approach because it uses a KMS key policy to enforce that decryption is allowed only when the encryption context matches the specific bucket ARN. When S3 encrypts an object with SSE-KMS, it automatically populates the encryption context with a key-value pair such as `aws:s3:arn` containing the bucket ARN; the key policy can then include a condition like `kms:EncryptionContext:aws:s3:arn` to limit `kms:Decrypt` to requests for that exact bucket. Additionally, granting `kms:Decrypt` to the IAM role in the key policy (or a combination of key and IAM policies) ensures that the role is the only principal allowed to decrypt, while the encryption-context condition prevents the same key from being used to decrypt objects in other buckets. This provides a robust, fine-grained access control that aligns with AWS best practices for SSE-KMS and satisfies the requirement to restrict decryption to the IAM role for the specific bucket.

Why this answer

It uses a KMS key policy with a condition that restricts decryption to requests where the encryption context matches the S3 bucket ARN. This ensures that only the specified IAM role, when making decrypt calls with the correct encryption context, can decrypt objects in that bucket. It directly ties the KMS key's decrypt permission to the bucket, providing a granular and secure access control mechanism.

Exam trap

The trap here is that candidates often confuse S3 bucket policies (which control access to the object) with KMS key policies (which control who can decrypt the underlying data), leading them to pick Option B or D, which address object access but not the decryption permission itself.

How to eliminate wrong answers

Option A is wrong because creating a separate KMS key per bucket and assigning the IAM role as a key user does not restrict decryption to only that bucket; the role could decrypt any object encrypted with that key, even from other locations, and does not enforce the bucket-specific context. Option B is wrong because an S3 bucket policy that allows only the IAM role to perform s3:GetObject controls read access to the object but does not prevent the role from decrypting the object using KMS if it has separate KMS decrypt permissions; the decryption is governed by KMS policies, not S3 bucket policies. Option D is wrong because an S3 bucket policy that denies s3:GetObject unless the request includes the x-amz-server-side-encryption-aws-kms-key-id header only enforces that the object be encrypted with a specific KMS key during upload, but does not control who can decrypt it; the IAM role could still decrypt if it has KMS decrypt permissions on that key.

20
MCQmedium

A company is using AWS Organizations with SCPs to restrict access to services. The security team wants to ensure that no IAM user can create access keys, but the SCP is not working as expected. What is the most likely cause?

A.The SCP is applied to the root OU but not inherited by the account.
B.The SCP is applied to a member account, but the IAM user is in the management account.
C.The SCP has a Deny effect, but it takes 24 hours to apply.
D.The SCP only applies to root users, not IAM users.
AnswerB

SCPs act as a permission boundary for member accounts, but they have no effect on the management account (also known as the payer account) in AWS Organizations. IAM users and roles in the management account retain their full permissions even if an SCP is attached to a member account. Therefore, if the IAM user resides in the management account, the SCP applied to the member account cannot possibly restrict that user's access, making this the correct explanation.

Why this answer

SCPs apply only to member accounts, not the management account. If the IAM user is in the management account, the SCP cannot restrict their actions. Option A is incorrect because SCPs are inherited from the root OU to all member accounts, so the SCP would be applied if the account were a member account; the issue is that the user is in the management account.

Option C is wrong because SCPs take effect almost immediately, not 24 hours. Option D is wrong because SCPs apply to all principals (including IAM users) in member accounts, not just root users.

21
MCQmedium

Refer to the exhibit. A company has a CloudTrail trail in us-east-1 that logs events for that region only. The company operates in multiple regions and wants to ensure all API calls from all regions are logged. What is the most efficient way to achieve this?

A.Use Amazon CloudWatch Events to capture API calls from all regions.
B.Use S3 event notifications to trigger a Lambda function that logs API calls.
C.Create a new CloudTrail trail in each region.
D.Update the existing trail to be a multi-region trail.
AnswerD

Updating the existing trail to be a multi-region trail is the correct action because CloudTrail's multi-region trail design automatically collects API events from every region and delivers them to a single S3 bucket. This ensures comprehensive visibility into account activity without the need to create separate trails. By modifying the existing trail, you preserve its current configuration while expanding its scope, which is both efficient and administratively simple.

Why this answer

Updating the existing trail to be a multi-region trail is the most efficient way to log events from all regions. A multi-region trail logs API calls from all AWS regions into a single trail, aggregating them in the same S3 bucket. Option A is incorrect because CloudWatch Events can capture API calls, but it is less efficient and more complex than using a multi-region trail.

Option B is incorrect because S3 event notifications are triggered by S3 events, not API calls, and cannot capture all API calls. Option C is incorrect because creating a new trail in each region results in multiple trails and log files, which is less efficient to manage than a single multi-region trail.

22
MCQhard

An application running on Amazon EC2 needs to access an S3 bucket. The SysOps administrator wants to ensure that only that specific EC2 instance can access the bucket, without storing any long-term credentials on the instance. What is the most secure way to achieve this?

A.Attach an IAM role to the EC2 instance using an instance profile and grant the role S3 access
B.Configure a resource-based policy on the EC2 instance to allow S3 access
C.Create an IAM user with S3 access and store the access keys in the instance's user data
D.Generate pre-signed URLs for each S3 object the application needs to access
AnswerA

Attaching an IAM role to the EC2 instance through an instance profile is the AWS best practice because the instance retrieves temporary security credentials from the instance metadata service. These credentials are automatically rotated by AWS, eliminating the need to store or manage long-term access keys on the instance. The role's identity-based policy grants the instance exactly the S3 permissions required, following the principle of least privilege.

Why this answer

Attaching an IAM role to the EC2 instance via an instance profile allows the instance to obtain temporary credentials from the EC2 Instance Metadata Service (IMDS), which are automatically rotated. This eliminates the need to store long-term access keys on the instance and scopes permissions to the specific role. It is the AWS-recommended best practice for granting EC2 access to S3.

Exam trap

SOA-C02 often tests the misconception that storing credentials in user data or using pre-signed URLs is 'secure enough' — the exam expects recognition that IAM roles with instance profiles and IMDSv2 are the only best-practice answer for EC2-to-S3 access without long-term credentials.

How to eliminate wrong answers

Option B is wrong because EC2 instances do not support resource-based policies — resource-based policies apply to resources like S3 buckets, SQS queues, and KMS keys, not to EC2 instances. Option C is wrong because storing access keys in user data is insecure: user data is visible via the metadata service and console, and long-term keys can be leaked or committed to logs. Option D is wrong because pre-signed URLs grant temporary access to specific objects but require the application to generate them using credentials anyway, and they are not a scalable identity mechanism for an application needing broad S3 access.

23
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to prevent any IAM user from creating access keys for themselves across all accounts. What is the most effective way to enforce this policy?

A.Attach an IAM policy to the root user that denies iam:CreateAccessKey.
B.Configure an IAM password policy that requires strong passwords.
C.Apply a service control policy (SCP) that denies iam:CreateAccessKey to all accounts in the organization.
D.Use AWS CloudTrail to monitor and alert on CreateAccessKey events.
AnswerC

A service control policy (SCP) is the correct mechanism because it centrally governs the maximum available permissions for all IAM users, roles, and even the root user within every member account of an AWS Organization. An SCP that denies iam:CreateAccessKey ensures that no principal in any account can create new access keys, regardless of their IAM policies, making it a preventive, organization-wide control.

Why this answer

Service control policies (SCPs) are the most effective way to enforce a guardrail across all accounts in an AWS Organization because they allow you to centrally deny or restrict permissions at the root, OU, or account level, overriding any IAM policies attached to users or roles. By applying an SCP that denies iam:CreateAccessKey, the security team ensures that no IAM user in any account within the organization can create access keys, regardless of their individual IAM policies. This approach is scalable and cannot be bypassed by account administrators, making it the correct choice for organization-wide enforcement.

Exam trap

The trap here is that candidates often confuse IAM password policies or CloudTrail monitoring with preventive controls, but only SCPs provide a centralized, enforceable denial across all accounts in an AWS Organization.

How to eliminate wrong answers

Option A is wrong because the root user is not an IAM user; it is a special account with full administrative access that cannot be restricted by IAM policies, and attaching a policy to the root user is not supported. Option B is wrong because an IAM password policy controls password complexity and rotation for IAM users, but it does not prevent users from creating access keys; it only affects password-based authentication. Option D is wrong because AWS CloudTrail is a logging and monitoring service that can alert on CreateAccessKey events, but it does not prevent the action from occurring; it only provides visibility after the fact.

24
MCQeasy

An administrator needs to grant an IAM user the ability to stop and start EC2 instances, but only for instances tagged with 'Environment:Production'. Which IAM policy element should be used to enforce this condition?

A.Effect
B.Resource
C.Action
D.Condition
AnswerD

The Condition element is the correct place to enforce tag-based restrictions through condition operators and keys such as StringEquals with ec2:ResourceTag/environment. A policy could combine Action: ec2:StartInstances with Condition: StringEquals: {'ec2:ResourceTag/environment': 'dev'} so the action is allowed only when the instance's tag matches. This works because Condition evaluates context keys against the request and resource attributes at runtime, which is exactly what is needed for tag-based authorization.

Why this answer

The Condition element in an IAM policy allows specifying conditions, such as restricting actions to instances with a specific tag (e.g., 'Environment:Production'). Option A is incorrect because Effect determines whether the policy allows or denies access. Option B is incorrect because Resource specifies the ARN of the resources the policy applies to.

Option C is incorrect because Action specifies the specific operations (e.g., ec2:StopInstances) that are allowed or denied.

25
MCQmedium

A company's compliance team requires that all changes to IAM policies be logged and immediately alerted. Which AWS solution should be used?

A.Use AWS Config rules to monitor IAM policy changes and send notifications.
B.Use Amazon CloudWatch Logs to capture IAM policy changes and create metric filters.
C.Use Amazon GuardDuty to detect unauthorized IAM policy changes.
D.Use AWS CloudTrail to log API calls and Amazon CloudWatch Events to send alerts.
AnswerD

AWS CloudTrail records every IAM management API call (for example, PutUserPolicy, AttachRolePolicy, or DeleteRole) as an event. When CloudTrail delivers those events to Amazon CloudWatch Events (now Amazon EventBridge), you can create a rule that matches the specific event names and triggers an SNS topic or Lambda function. This event-driven pattern provides near-real-time alerts for each individual policy change, making it the correct choice.

Why this answer

AWS CloudTrail records every IAM API call (CreatePolicy, AttachRolePolicy, PutRolePolicy, etc.) as a management event, and CloudWatch Events (now EventBridge) can match those events with a rule and trigger an SNS notification or Lambda for immediate alerting. This combination satisfies both the logging and the real-time alerting requirements.

Exam trap

The trap is picking AWS Config or GuardDuty because they sound compliance- and security-oriented, but the question demands immediate alerting on every API call, which only CloudTrail + EventBridge delivers deterministically.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configuration compliance on a periodic or change-triggered basis and are designed for drift detection, not immediate alerting on every API call; there is inherent latency and Config is not an event-streaming service. Option B is wrong because CloudWatch Logs metric filters operate on log data but IAM policy changes are not natively written to CloudWatch Logs unless CloudTrail is configured to deliver them there — and even then, metric filters are for aggregation, not immediate per-event alerting. Option C is wrong because GuardDuty is a threat-detection service that uses ML and threat intelligence to find anomalous behaviour; it does not provide a deterministic, immediate alert on every IAM policy change.

26
MCQeasy

A company has an S3 bucket that contains sensitive customer data. The security team requires that all data in transit to and from the bucket must be encrypted. Which bucket policy condition should be used?

A.aws:SecureTransport
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.s3:x-amz-server-side-encryption
D.aws:TLSSupport
AnswerA

aws:SecureTransport is the legitimate boolean condition key used in S3 bucket policies to verify whether the request was made over HTTPS/TLS. When you set "Bool": {"aws:SecureTransport": "true"} in a Deny statement, you explicitly block any request that uses plain HTTP, ensuring all data transmitted to and from the bucket is encrypted in transit. This directly satisfies the requirement to enforce secure transport.

Why this answer

The aws:SecureTransport condition key in an S3 bucket policy checks whether the request was sent using SSL/TLS. Setting it to 'true' denies any requests that are not encrypted in transit, enforcing HTTPS for all access to the bucket. This directly meets the requirement that all data in transit must be encrypted.

Exam trap

The trap is confusing encryption at rest condition keys (s3:x-amz-server-side-encryption) with encryption in transit (aws:SecureTransport), causing candidates to pick a key that enforces SSE instead of HTTPS.

How to eliminate wrong answers

Option B is wrong because s3:x-amz-server-side-encryption-aws-kms-key-id is used to enforce a specific KMS key for server-side encryption at rest, not for transit encryption. Option C is wrong because s3:x-amz-server-side-encryption enforces server-side encryption at rest (e.g., AES256 or aws:kms), not transit encryption. Option D is wrong because aws:TLSSupport is not a valid condition key in AWS; the correct key is aws:SecureTransport.

27
MCQmedium

A company wants to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the SysOps administrator do?

A.Create an IAM role with permissions to the S3 bucket and attach it to the EC2 instance profile.
B.Attach an S3 bucket policy that grants access to the EC2 instance's public IP address.
C.Generate access keys for an IAM user and store them on the instance.
D.Use AWS STS to generate temporary credentials and store them in the instance's user data.
AnswerA

Attaching an IAM role to an EC2 instance through an instance profile is the secure, AWS-recommended approach. The instance profile is passed to the instance at launch, and the Amazon EC2 service uses the role's trust policy to call the AWS Security Token Service (STS) to issue short-term credentials that are delivered via the instance metadata service. These credentials are automatically rotated by the EC2 service before they expire, so the application can access the S3 bucket without ever storing or handling secrets.

Why this answer

An IAM role can be attached to an EC2 instance via an instance profile, granting temporary security credentials that allow the instance to access the S3 bucket without storing long-term credentials on the instance. Option B is incorrect because an S3 bucket policy cannot be attached to an instance; it is attached to the S3 bucket itself, and using the instance's public IP is not a secure or recommended method. Option C is incorrect because storing access keys on the instance violates the requirement of not storing credentials.

Option D is incorrect because while AWS STS can generate temporary credentials, storing them in instance user data is not secure and does not eliminate credential storage on the instance.

28
MCQhard

A SysOps administrator is managing a multi-account AWS environment using AWS Organizations. The security team has mandated that all Amazon S3 buckets across all accounts must be encrypted with SSE-KMS using a centrally managed KMS key. The administrator has created a KMS key in the master account and enabled key rotation. The key policy allows the root user of each member account to use the key. However, users in member accounts report that they cannot upload objects to their S3 buckets with SSE-KMS using the central key, even though they have s3:PutObject permissions. The administrator verifies that the KMS key policy includes the necessary permissions for the member accounts. What should the administrator do to resolve the issue?

A.Create a new KMS key in each member account and configure S3 bucket default encryption accordingly.
B.Ensure that the KMS key policy allows the master account to administer the key.
C.Attach an IAM policy to the users/roles in the member accounts that allows kms:GenerateDataKey using the central KMS key.
D.Update the S3 bucket policy to allow the s3:PutObject action only when encryption is set to SSE-KMS.
AnswerC

For S3 objects encrypted with SSE-KMS, the IAM principal performing the PutObject call must have kms:GenerateDataKey permission on the key that encrypts the object. In a cross-account scenario using a central KMS key in the master account, the member-account users/roles must be explicitly allowed, via an IAM policy, to use that key. The key policy in the master account should grant access to the member account principals, and this IAM policy in the member account completes the authorization chain, enabling the S3 encryption to succeed with the centrally managed key.

Why this answer

Cross-account KMS usage requires permissions on both sides: the key policy must allow the external account, and the IAM principal in that account must also be granted kms:GenerateDataKey (and kms:Decrypt) via an IAM policy. The key policy alone is insufficient.

Exam trap

The trap is assuming that a permissive KMS key policy is sufficient for cross-account access — candidates forget that IAM policies in the member account must also grant the KMS actions.

How to eliminate wrong answers

Option A is wrong because creating per-account keys defeats the requirement for a centrally managed key and adds operational overhead. Option B is wrong because the master account already administers the key — that does not grant member-account users permission to use it. Option D is wrong because the S3 bucket policy controls S3 actions, not KMS permissions; the failure is at the KMS layer, not S3.

29
MCQmedium

A company uses AWS KMS to encrypt data stored in S3. The security team wants to rotate the KMS key automatically every year. The SysOps administrator enabled automatic key rotation for the KMS key. However, after a year, the security team finds that the key has not been rotated. What is the most likely cause?

A.The KMS key is disabled.
B.The KMS key policy does not allow rotation.
C.The KMS key has not been used in the last year.
D.The KMS key was created by importing key material.
AnswerD

Keys with imported key material have an origin of EXTERNAL, meaning the plaintext key material resides only with the customer and AWS KMS cannot access or replace it. Since automatic rotation requires AWS to generate a new backing key, it is unsupported for imported keys. To rotate, you must create a new KMS key, import fresh material, and update any aliases or applications that reference the old key.

Why this answer

AWS KMS does not support automatic key rotation for customer-managed keys that were created by importing key material. This is a key limitation to remember. Options A and B are incorrect because automatic rotation is independent of the key's enabled state or the key policy; rotation occurs automatically for supported keys.

Option C is incorrect because key usage is not a requirement for automatic rotation; the rotation schedule is based on time, not usage.

30
MCQhard

An IAM user has the policy shown in the exhibit. The user is trying to download an object from example-bucket from an IP address of 192.0.2.50. However, the request is denied. What is the most likely reason?

A.The condition key aws:SourceIp should be aws:SourceIpAddress.
B.The bucket has a bucket policy that denies access from the user's IP address.
C.The resource ARN does not include the bucket itself.
D.The condition syntax is incorrect because it should use StringEquals.
AnswerB

A bucket policy is a resource-based policy, and when a user accesses S3, AWS evaluates both the user's IAM policy and the bucket policy together. Even if the IAM policy explicitly allows s3:GetObject, an explicit deny statement in the bucket policy overrides all permits. Therefore, a bucket policy denying access from the user's IP address would correctly block the user regardless of the IAM allow seen in the exhibit.

Why this answer

The bucket policy explicitly denies the request from IP 192.0.2.50, overriding any IAM policy that allows the action. Option A is incorrect because aws:SourceIp is a valid condition key. Option C is incorrect because the resource ARN 'arn:aws:s3:::example-bucket/*' is appropriate for GetObject on objects.

Option D is incorrect because the condition key aws:SourceIp requires the IpAddress operator, not StringEquals.

31
MCQhard

A SysOps administrator needs to detect when an IAM user attempts to modify an Amazon S3 bucket policy in the production AWS account. The administrator wants to receive an email notification within 5 minutes of such an event. The solution must use AWS managed services with no custom code. Which combination of services should the administrator use?

A.AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS
B.AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS
C.Amazon S3 event notifications and Amazon SNS
D.AWS CloudTrail, AWS Lambda, and Amazon SNS
AnswerA

CloudTrail captures the IAM user's API attempt as a management event, and an Amazon EventBridge rule can match the exact API call (for example, PutBucketPolicy) using event patterns. The rule then sends the event to an SNS topic, which delivers an email notification. This pipeline is fully managed, near-real-time, and requires no custom code.

Why this answer

AWS CloudTrail captures the S3 bucket policy modification as a management event, which can be sent to Amazon EventBridge (formerly CloudWatch Events) as a real-time event. EventBridge can then trigger an SNS topic to send an email notification within minutes, all using fully managed services with no custom code required.

Exam trap

The trap here is that candidates often confuse S3 event notifications (object-level) with CloudTrail (management-level), or they assume CloudWatch Logs metric filters are the only way to trigger alarms from logs, overlooking EventBridge's direct event-driven capability for real-time notification without custom code.

How to eliminate wrong answers

Option B is wrong because CloudWatch Logs metric filters operate on log data with a latency of up to 5 minutes for the metric to be created, and then an alarm must be evaluated, which can add additional delay; this does not guarantee notification within 5 minutes and is more complex. Option C is wrong because S3 event notifications are designed for object-level events (e.g., PUT, DELETE) and cannot detect IAM user attempts to modify bucket policies, which are management-level events. Option D is wrong because it requires AWS Lambda custom code to process the CloudTrail event and send the notification, violating the requirement to use only managed services with no custom code.

32
MCQmedium

A company's security policy requires that all new Amazon S3 buckets must have server-side encryption with AWS Key Management Service (SSE-KMS) enabled by default. A SysOps administrator wants to enforce this requirement for all current and future S3 buckets in the account. Which AWS service or feature should be used to automatically apply this configuration?

A.Enable S3 default encryption at the account level in the S3 console.
B.Create an AWS CloudTrail trail that captures S3 API calls and triggers a Lambda function to enable encryption on any bucket that is created without it.
C.Use an AWS Organizations Service Control Policy (SCP) to deny the s3:PutBucketPublicAccessBlock action, forcing users to enable encryption.
D.Use AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule and configure automatic remediation to apply SSE-KMS when a non-compliant bucket is detected.
AnswerD

AWS Config can evaluate all buckets (current and future) against the rule. Automatic remediation can invoke an SSM Automation document or a Lambda function to enable SSE-KMS on the bucket, meeting the requirement with a managed service.

Why this answer

AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule can evaluate S3 buckets for compliance with server-side encryption requirements. When a non-compliant bucket is detected, automatic remediation can be configured to apply SSE-KMS using an AWS Systems Manager Automation document, ensuring all current and future buckets meet the security policy without manual intervention.

Exam trap

The trap here is that candidates confuse S3 default encryption (which is bucket-level only) with account-level enforcement, or they mistakenly think SCPs can directly enable encryption rather than just deny actions, leading them to pick options that are reactive or misaligned with the requirement.

How to eliminate wrong answers

Option A is wrong because S3 default encryption can only be set at the bucket level, not at the account level; there is no account-level setting in the S3 console to enforce encryption on all buckets. Option B is wrong because while CloudTrail and Lambda can reactively fix buckets after creation, this approach is event-driven and not a proactive enforcement mechanism; it also relies on custom code and may introduce latency or gaps. Option C is wrong because the s3:PutBucketPublicAccessBlock action controls public access block settings, not server-side encryption; denying this action does nothing to enforce SSE-KMS, and SCPs cannot directly enable encryption on resources.

33
MCQmedium

A SysOps administrator needs to grant cross-account access to an S3 bucket in Account A for an IAM user in Account B. The bucket policy in Account A allows the IAM user's account root principal. What additional configuration is required?

A.Modify the AWS KMS key policy to allow the user in Account B
B.Add a bucket ACL granting access to the user in Account B
C.Add an AWS Organizations service control policy to allow access
D.Attach an IAM policy to the user in Account B that allows the required S3 actions
AnswerD

Attaching an IAM policy to the user in Account B is required because the user must have explicit permission to perform the S3 actions against the bucket in Account A. Even if Account A's bucket policy grants cross-account access to that user, the user's own IAM policy must also allow the actions, as permissions in AWS are effectively the intersection of the identity-based and resource-based policies. Without this IAM policy, the user will be denied access regardless of the bucket policy. Therefore, this is the correct necessary step.

Why this answer

D is correct because cross-account access to an S3 bucket requires both a bucket policy that grants access to the root principal of the target account (Account B) and an IAM policy attached to the user in Account B that explicitly allows the desired S3 actions. Without the IAM policy, the user in Account B has no permissions to perform any S3 operations, even though the bucket policy in Account A permits the account root. The IAM policy acts as the identity-based permission that authorizes the specific user to invoke the S3 API calls.

Exam trap

The trap here is that candidates assume the bucket policy alone is sufficient for cross-account access, forgetting that the IAM user in the target account must also have an explicit IAM policy allowing the S3 actions, as AWS requires both resource-based and identity-based permissions to be evaluated and both must allow the operation.

How to eliminate wrong answers

Option A is wrong because AWS KMS key policies are only relevant if the S3 bucket uses SSE-KMS encryption; the question does not mention encryption, and modifying the KMS key policy is not a general requirement for cross-account S3 access. Option B is wrong because bucket ACLs are legacy and cannot grant access to an IAM user in another account; they only support granting access to AWS accounts or predefined groups, not individual IAM users. Option C is wrong because AWS Organizations service control policies (SCPs) apply to all principals within an organization and are used to set permission boundaries, not to grant cross-account access; they cannot be used to allow a specific IAM user in another account.

34
MCQmedium

A company's security policy requires that all IAM users must authenticate with multi-factor authentication (MFA) before they can perform any actions on Amazon EC2 instances. The SysOps administrator needs to enforce this requirement using IAM policies. Which IAM policy condition key should the administrator use in the policy?

A.aws:MultiFactorAuthPresent
B.aws:SourceIp
C.iam:PassedToService
D.ec2:SourceInstanceARN
AnswerA

The aws:MultiFactorAuthPresent condition key is a global IAM condition that evaluates to true when the principal authenticated with a valid MFA device. In a policy, adding "aws:MultiFactorAuthPresent": "true" to a condition ensures the action is permitted only if MFA was used, regardless of whether the request originates from the console, an API call, or temporary credentials. If MFA was not used, the key evaluates to false (or is absent), causing the condition to fail, which directly enforces the security policy that all IAM users must use MFA.

Why this answer

The `aws:MultiFactorAuthPresent` condition key allows the administrator to enforce MFA authentication by checking whether the user authenticated with a valid MFA device before allowing the action. When set to `true`, the policy denies access to EC2 actions unless the user has completed MFA. This directly satisfies the security policy requirement.

Exam trap

The trap here is that candidates confuse `aws:MultiFactorAuthPresent` with `aws:SourceIp` or `iam:PassedToService`, mistakenly thinking IP-based or role-passing conditions can enforce MFA, when only the MFA-specific condition key works.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` is used to restrict access based on the originating IP address, not to enforce MFA authentication. Option C is wrong because `iam:PassedToService` is used to control which roles can be passed to AWS services (e.g., EC2), not to enforce MFA for user actions. Option D is wrong because `ec2:SourceInstanceARN` is a condition key for EC2-to-EC2 traffic or resource-based policies, not for IAM user authentication requirements.

35
MCQeasy

A company's security policy requires that the AWS account root user must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to continuously verify compliance and automatically notify the security team if the root user is not configured with MFA. Which AWS service can be used to create a compliance rule for this requirement?

A.AWS Trusted Advisor
B.AWS Config with the managed rule 'root-account-mfa-enabled'
C.AWS Identity and Access Management (IAM) Access Analyzer
D.Amazon Inspector
AnswerB

AWS Config with the managed rule 'root-account-mfa-enabled' continuously evaluates the root user's MFA configuration against the rule's desired state. When the root account becomes non-compliant, AWS Config can publish configuration change notifications to Amazon SNS via EventBridge, allowing automated alerting and remediation. This rule is available as a managed rule and works across all supported regions and accounts with minimal setup, making it the correct choice for verifying and monitoring root MFA compliance.

Why this answer

AWS Config provides a managed rule called 'root-account-mfa-enabled' that continuously evaluates whether the root user has an MFA device configured. When the rule detects non-compliance, it can trigger an Amazon SNS notification to alert the security team, meeting the requirement for automated compliance verification and alerting.

Exam trap

The trap here is that candidates confuse AWS Trusted Advisor's security checks (which include a root MFA check but lack continuous evaluation and automated notification) with AWS Config's managed rules that provide ongoing compliance monitoring and event-driven alerts.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer continuous compliance rules with automated notifications for root user MFA status. Option C is wrong because IAM Access Analyzer analyzes resource policies for external access, not root user MFA configuration compliance. Option D is wrong because Amazon Inspector assesses vulnerabilities in EC2 instances and container workloads, not IAM user configurations.

36
Drag & Dropmedium

Drag and drop the steps to create an Amazon CloudWatch alarm that sends an email notification when CPU utilization exceeds 90% into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First set up the SNS topic, then create the alarm selecting the metric, define the condition, and finally add the notification action.

37
MCQhard

A SysOps administrator discovers that an EC2 instance was compromised because the SSH key pair was leaked. The administrator wants to ensure that future access to EC2 instances is secured using a method that does not rely on static keys. Which solution should the administrator implement?

A.Use a bastion host with a security group that allows SSH from a limited IP range.
B.Create a new key pair and distribute it securely to authorized users.
C.Use AWS Systems Manager Session Manager to connect to instances.
D.Use EC2 Instance Connect to connect to instances.
AnswerD

EC2 Instance Connect uses IAM policies to authorize individual users and temporarily publishes a one-time SSH public key to the instance's metadata service. The user then SSHes with a private key that is valid for only 60 seconds, eliminating long-lived key pairs and enabling per-user audit trails. This integrates with AWS CloudTrail to record access requests and empowers administrators to revoke access instantly by changing IAM permissions. It supports both console and CLI access, making it a secure, keyless-compatible solution while preserving native SSH functionality.

Why this answer

EC2 Instance Connect allows you to connect to EC2 instances using IAM policies and does not require managing or distributing static SSH key pairs. This eliminates the risk of key leakage. Option A (bastion host with limited IP range) still relies on SSH key pairs for authentication.

Option B (create new key pair) continues to use static keys and does not address the root cause. Option C (Systems Manager Session Manager) provides secure access without keys, but it requires the SSM Agent and an IAM instance role, and is not as directly focused on SSH key replacement as EC2 Instance Connect. Therefore, Option D is the best solution.

38
MCQeasy

A company wants to enforce that all IAM users in an AWS account must use multi-factor authentication (MFA) to access the AWS Management Console. Which IAM policy effect should be used to deny access if MFA is not present?

A.Allow with a condition that aws:MultiFactorAuthPresent is false
B.Allow with a condition that aws:MultiFactorAuthPresent is true
C.Deny with a condition that aws:MultiFactorAuthPresent is false
D.Deny with a condition that aws:MultiFactorAuthPresent is true
AnswerC

A Deny policy with the condition aws:MultiFactorAuthPresent is false explicitly blocks any request where the MFA condition does not evaluate to true, meaning the user did not authenticate with a valid MFA token. Because explicit Deny statements take precedence over any Allow, this effectively enforces MFA for all IAM users, as any attempt without MFA is rejected even if a broad Allow policy would otherwise grant access. This is the correct pattern for mandatory MFA enforcement, typically combined with an Allow that grants the needed permissions when MFA is present.

Why this answer

The IAM policy must explicitly deny access when MFA is not present. By using a Deny effect with the condition aws:MultiFactorAuthPresent set to false, any request that does not include MFA authentication is blocked. This is the standard approach to enforce MFA usage, as IAM policies default to an implicit deny, but an explicit Deny overrides any Allow that might otherwise grant access.

Exam trap

The trap here is that candidates often choose an Allow with a condition (option B) thinking it will restrict access, but they forget that an Allow statement only grants access when the condition is met and does not prevent access from other Allow policies; only an explicit Deny can reliably block access when the condition is false.

How to eliminate wrong answers

Option A is wrong because using Allow with a condition that aws:MultiFactorAuthPresent is false would grant access when MFA is not present, which is the opposite of the desired enforcement. Option B is wrong because Allow with a condition that aws:MultiFactorAuthPresent is true would only permit access when MFA is present, but it does not explicitly deny access when MFA is absent; an Allow statement alone cannot block access because other policies might still grant access, and the implicit deny only applies if no Allow matches. Option D is wrong because Deny with a condition that aws:MultiFactorAuthPresent is true would deny access when MFA is present, which contradicts the requirement to enforce MFA usage.

39
Multi-Selecthard

Which TWO actions should a SysOps administrator take to secure an S3 bucket that stores sensitive data? (Choose two.)

Select 2 answers
A.Enable S3 Block Public Access settings on the bucket.
B.Enable cross-origin resource sharing (CORS) on the bucket.
C.Enable S3 Versioning.
D.Enable S3 server access logging.
E.Enable S3 Transfer Acceleration.
AnswersA, D

This is a bucket-level and account-level security control that, when applied, overrides any bucket policies or object ACLs that would grant public read/write access, effectively preventing the bucket and its objects from being accessible to the anonymous internet. For a scenario requiring data to be kept private, blocking public access is the direct and definitive remedy, and it also prevents future accidental public exposure through misconfigured policies or ACLs.

Why this answer

Option A is correct because enabling S3 Block Public Access on the bucket applies the four block-public-access settings (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets) that prevent sensitive objects from ever being exposed through public ACLs or bucket policies. Option D is correct because S3 server access logging records detailed, request-level records (requester, bucket, key, operation, response status, source IP) to a target bucket, giving the audit trail needed to detect and investigate unauthorized access to sensitive data. Option B is not appropriate because CORS only controls which web origins may make cross-origin browser requests to the bucket; it is a browser-enforcement mechanism, not an access-control or data-protection control.

Option C is not appropriate because S3 Versioning only preserves multiple object versions to aid recovery from overwrites or deletes; it does not restrict who can read the data. Option E is not appropriate because S3 Transfer Acceleration merely speeds up uploads/downloads via AWS edge locations and provides no security benefit.

Exam trap

SOA-C02 often tests the misconception that features like Versioning or Transfer Acceleration improve security, when in fact Block Public Access and access logging are the correct security-focused controls.

40
MCQhard

A company hosts a critical web application on EC2 instances behind an Application Load Balancer. The security team enabled AWS WAF on the ALB to block SQL injection and XSS attacks. They also use AWS Shield Advanced for DDoS protection. Recently, the application experienced intermittent performance degradation during normal traffic patterns. The security team reviewed the WAF logs and found that legitimate user requests with query strings containing the word "select" (e.g., ?category=select+option) were being blocked. The team wants to ensure that only actual SQL injection attempts are blocked, not legitimate requests with similar patterns. What course of action should the SysOps administrator take to resolve this issue while maintaining security?

A.Disable the SQL injection rule in AWS WAF and rely solely on AWS Shield Advanced for protection.
B.Enable AWS Shield Advanced's automatic mitigation feature to handle all layer 7 attacks.
C.Create a custom WAF rule that inspects specific query string parameters with a more precise regex pattern to reduce false positives.
D.Replace the WAF SQL injection rule with a rate-based rule to limit request rates from specific IPs.
AnswerC

Creating a custom AWS WAF rule that inspects only the specific query string parameters with a more precise regex pattern is the correct solution because it narrows the detection scope while maintaining SQL injection protections. For example, instead of using a managed rule that flags any occurrence of 'select' across the entire request, a custom rule can apply a SQL injection match condition to a parameter like 'id' and use a regex pattern that requires SQL keywords to appear in a syntactically suspicious sequence, such as after a quote or with UNION operators. This reduces false positives by ignoring benign uses of words like 'select' in other fields, while still detecting actual SQLi attempts that target the parameter the application expects to be numeric or constrained.

Why this answer

The issue is that the AWS WAF SQL injection rule is triggering false positives on legitimate query strings containing the word 'select' (e.g., '?category=select+option'). The best course of action is to create a custom WAF rule that inspects specific query string parameters with a more precise regex pattern, allowing legitimate patterns while still blocking actual SQL injection attempts. This maintains security by targeting the actual attack vectors rather than disabling protection entirely.

Exam trap

SOA-C02 often tests the balance between security and availability — candidates may choose to disable the rule to stop false positives, but the exam expects a solution that maintains security while reducing false positives, such as a custom rule with precise regex.

How to eliminate wrong answers

Option A is wrong because disabling the SQL injection rule entirely removes protection against SQL injection attacks, leaving the application vulnerable — this sacrifices security for availability. Option B is wrong because AWS Shield Advanced's automatic mitigation is designed for DDoS attacks (Layer 3/4 and some Layer 7 volumetric attacks), not for refining SQL injection detection or reducing false positives from WAF rules. Option D is wrong because replacing the SQL injection rule with a rate-based rule only limits request rates from IPs; it does not inspect query strings for SQL injection patterns, so actual SQL injection attacks would not be blocked.

41
Multi-Selecthard

Which THREE are valid methods to control access to an S3 bucket? (Choose three.)

Select 3 answers
A.VPC Flow Logs
B.Access control lists (ACLs)
C.Bucket policies
D.IAM user policies
E.CloudWatch Logs
AnswersB, C, D

Access control lists are legacy sub-resources that can be attached to an S3 bucket or individual object to grant basic read/write permissions to grantees, typically AWS accounts or predefined groups like Authenticated Users. ACLs do not support conditions, complex principals, or fine-grained actions, and AWS now recommends using bucket policies or IAM policies instead. When S3 Object Ownership is set to Bucket owner enforced, ACLs are automatically disabled for the bucket.

Why this answer

Option B (Access control lists, ACLs) is correct because S3 ACLs are a legacy but still supported access-control mechanism that grants read/write permissions on a bucket or object to AWS accounts or predefined groups such as AllUsers or AuthenticatedUsers. Option C (Bucket policies) is correct because an S3 bucket policy is a resource-based JSON policy attached directly to the bucket that can allow or deny principals (IAM users, roles, accounts, or anonymous users) access to the bucket and its objects. Option D (IAM user policies) is correct because identity-based IAM policies attached to users, groups, or roles define what S3 actions (for example s3:GetObject, s3:PutObject) those identities may perform on specified bucket ARNs.

Option A (VPC Flow Logs) is not an access-control method; it captures IP traffic metadata for network interfaces for monitoring and troubleshooting. Option E (CloudWatch Logs) is a logging and monitoring service, not an authorization mechanism, so it cannot grant or deny access to an S3 bucket.

Exam trap

SOA-C02 often tests whether candidates confuse monitoring/logging services (VPC Flow Logs, CloudWatch Logs) with access control mechanisms; the trap is picking a service that observes traffic rather than one that authorizes it.

42
MCQmedium

A company has a production AWS account with multiple IAM users. The security team wants to implement a policy that prevents users from launching EC2 instances without an IAM role that grants access to an S3 bucket containing sensitive data. The policy should also allow users to launch instances with other roles. A SysOps administrator creates an IAM policy that denies ec2:RunInstances if the instance does not have a specific IAM instance profile. However, users are still able to launch instances without any role. What is the most likely reason, and what should be done to fix it?

A.The condition key 'ec2:InstanceProfileArn' is misspelled; it should be 'ec2:IamInstanceProfile'.
B.The policy should be attached to the user's group instead of the user.
C.The policy needs to be applied as a service control policy (SCP) to be effective.
D.The condition key is incorrect; the policy should use 'ec2:InstanceProfile' condition key with a specific ARN.
AnswerD

The condition key should be 'ec2:InstanceProfile', not 'ec2:InstanceProfileArn'. The 'ec2:InstanceProfileArn' condition key does not exist for EC2, so the policy never matches, and the deny effect does not apply, allowing users to launch instances without any role.

Why this answer

The correct condition key for checking an instance's IAM role at launch is 'ec2:InstanceProfile', not 'ec2:InstanceProfileArn'. The 'ec2:InstanceProfile' condition key evaluates the ARN of the instance profile associated with the instance. Using 'ec2:InstanceProfileArn' is not a valid condition key for EC2, so the policy never matches, and the deny effect never applies, allowing users to launch instances without any role.

Exam trap

The trap here is that candidates assume all AWS condition keys follow a consistent 'ResourceArn' naming pattern, but EC2 uses 'ec2:InstanceProfile' without the 'Arn' suffix, leading to a policy that silently fails to deny the action.

How to eliminate wrong answers

Option A is wrong because 'ec2:IamInstanceProfile' is not a valid condition key; the correct key is 'ec2:InstanceProfile'. Option B is wrong because attaching the policy to a user group versus a user does not change the policy's logic or effectiveness; the issue is the condition key itself, not the attachment point. Option C is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organization, not to fix a malformed condition key in an IAM policy; the policy would still fail to deny the action even as an SCP.

43
MCQmedium

A SysOps administrator notices that an EC2 instance running a web server is receiving unexpected traffic from an IP address that is known to be malicious. The administrator wants to block this IP address at the instance level. Which solution should be used?

A.Modify the network ACL to deny traffic from that IP.
B.Use AWS WAF to block the IP address.
C.Install a third-party firewall on the instance.
D.Update the security group to deny traffic from that IP.
AnswerC

A third-party firewall installed on the instance, such as iptables or a host-based security agent, can filter inbound traffic based on source IP at the operating system level before the application processes it. This is the only option that fulfills the 'instance level' requirement, as it controls traffic directly on that specific EC2 instance regardless of the surrounding subnet or VPC configuration. Security groups cannot explicitly deny, making a host-based firewall the correct solution.

Why this answer

A host-based firewall (such as a third-party firewall installed on the instance) can block traffic from a specific IP address at the instance level. Option A is incorrect because network ACLs operate at the subnet level, not the instance level. Option B is incorrect because AWS WAF is designed to filter web requests at the application layer and is typically associated with load balancers or CloudFront, not directly with an individual EC2 instance.

Option D is incorrect because security groups do not support deny rules; they only allow traffic, so they cannot be used to block specific IPs.

Exam trap

The question specifies 'at the instance level,' which disqualifies subnet-level solutions like network ACLs. Candidates often overlook this detail and choose NACLs because they support explicit deny.

44
Multi-Selectmedium

A company needs to audit all changes to AWS resources. Which THREE AWS services should be used together to achieve this? (Choose three.)

Select 3 answers
A.Amazon Inspector
B.AWS CloudTrail
C.Amazon CloudWatch Events
D.AWS Trusted Advisor
E.AWS Config
AnswersB, C, E

AWS CloudTrail is the primary service for auditing by recording all API activity across AWS accounts. It captures every management event, including the identity making the call, the source IP, the time, and the request parameters, delivering a complete and verifiable history of who changed what. This immutable log provides the evidence required to audit changes and maintain compliance.

Why this answer

AWS CloudTrail (B) is correct because it records API activity and management events across the account, providing the audit trail of who made which changes to AWS resources. AWS Config (E) is correct because it continuously records resource configuration changes and evaluates them against desired rules, giving configuration history and compliance auditing. Amazon CloudWatch Events (C) is correct because it can detect and route CloudTrail/Config-related events in near real time to targets such as Lambda, SNS, or SQS for alerting and automated response.

Amazon Inspector (A) is not correct because it is a vulnerability management service that scans EC2 instances and container images, not a change-auditing service. AWS Trusted Advisor (D) is not correct because it provides best-practice checks and recommendations, not a record of resource changes.

Exam trap

SOA-C02 often tests the confusion between auditing (CloudTrail/Config) and security assessment (Inspector) or advisory (Trusted Advisor) services — candidates must map each service to its actual function.

45
MCQmedium

A SysOps administrator needs to grant an IAM user the ability to rotate their own access keys. What is the minimum set of permissions required?

A.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, iam:PutUserPolicy
B.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, kms:*
C.iam:GetUser, iam:CreateAccessKey, iam:DeleteAccessKey, iam:UpdateAccessKey
D.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, iam:UpdateAccessKey
AnswerD

This set of four IAM actions is correct because it represents the minimum required permissions for a self-service access key rotation workflow. First, iam:ListAccessKeys lets the user enumerate their existing keys to identify which one is active or old. iam:CreateAccessKey allows them to generate a new active key, iam:UpdateAccessKey lets them mark the old key as Inactive to avoid downtime, and iam:DeleteAccessKey removes the old key after the new one is confirmed working. Together these actions support a safe, zero-downtime rotation while denying access to unrelated management functions such as policy editing or KMS administration.

Why this answer

The minimum permissions to allow an IAM user to rotate their own access keys are: iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, and iam:UpdateAccessKey. Option D is correct. Option A is wrong because it includes iam:PutUserPolicy, which is unnecessary for key rotation and grants additional permissions to modify user policies.

Option B is wrong because it includes kms:*, which is unrelated to access key rotation and grants excessive permissions. Option C is wrong because it includes iam:GetUser, which is not required for rotating own keys; the user already knows their username or can be resolved via the policy variable.

46
Multi-Selectmedium

Which TWO actions should a SysOps administrator take to secure an AWS account root user? (Choose two.)

Select 2 answers
A.Delete the root user after creating an admin IAM user.
B.Apply a service control policy (SCP) to restrict the root user.
C.Enable multi-factor authentication (MFA) for the root user.
D.Enable CloudTrail to monitor root user activity.
E.Do not create access keys for the root user.
AnswersC, E

Enabling MFA on the root user adds a second authentication factor, requiring both the password and a temporary code from a hardware or virtual MFA device. The root user has unrestricted access to all AWS services and cannot be limited by IAM policies, so MFA is a critical preventive control. AWS recommends always setting up MFA for the root account immediately after creation.

Why this answer

Option C is correct because enabling MFA on the root user adds a second authentication factor, so a stolen root password alone cannot be used to sign in to the account. Option E is correct because the root user's access keys grant unrestricted programmatic access that cannot be scoped down by IAM policies, so AWS best practice is to never create them and instead use IAM roles or IAM users. Option A is wrong because the root user cannot be deleted; it is permanently tied to the account and can only have its credentials rotated or removed.

Option B is wrong because SCPs apply to member accounts in AWS Organizations and do not restrict the root user of the management account, nor can they meaningfully limit root credentials. Option D is wrong because CloudTrail provides monitoring and audit logging of root activity, not a preventive control that secures the root user.

Exam trap

SOA-C02 often tests the misconception that the root user can be deleted or restricted by SCPs, when in fact it is permanent and SCPs do not apply to it — candidates must distinguish preventive controls (MFA, no keys) from detective controls (CloudTrail).

47
MCQhard

A SysOps administrator needs to restrict access to an Amazon S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy statement should be added to the bucket policy?

A.Condition: { StringEquals: { 'aws:SourceVpc': 'vpc-12345' } }
B.Condition: { StringEquals: { 'ec2:Vpc': 'vpc-12345' } }
C.Condition: { IpAddress: { 'aws:VpcSourceIp': '10.0.0.0/16' } }
D.Condition: { StringEquals: { 'aws:SourceVpce': 'vpce-12345' } }
AnswerD

The condition key 'aws:SourceVpce' is the standard and correct way to restrict an S3 bucket policy to a specific VPC endpoint. When a request is made through an AWS PrivateLink VPC endpoint, this global condition contains the endpoint ID (e.g., 'vpce-12345'), allowing you to write a policy that only grants access to that exact endpoint. This ensures that traffic from the VPC must route through the named endpoint, and direct traffic from instances or other endpoints is denied.

Why this answer

The condition key 'aws:SourceVpce' is used to restrict access to requests originating from a specific VPC endpoint (identified by its endpoint ID). Option A uses 'aws:SourceVpc', which restricts to an entire VPC, not a specific endpoint. Option B uses 'ec2:Vpc', which is not a valid condition key for S3 bucket policies.

Option C uses 'aws:VpcSourceIp', which is not a valid condition key; the correct key for IP-based restrictions is 'aws:SourceIp'.

Exam trap

A common trap is confusing 'aws:SourceVpc' with 'aws:SourceVpce'. The former restricts to traffic from any resource in the specified VPC, while the latter restricts to traffic specifically from the VPC endpoint.

48
MCQhard

A company uses AWS KMS to encrypt EBS volumes attached to EC2 instances. The security team wants to ensure that only specific IAM roles can decrypt the volumes. Which configuration meets this requirement?

A.Use a service control policy to deny kms:Decrypt for all users.
B.Apply a bucket policy on the EBS snapshot bucket.
C.Modify the KMS key policy to allow only specific IAM roles to use kms:Decrypt.
D.Attach an instance profile with a policy that denies ec2:DetachVolume.
AnswerC

Modifying the KMS key policy is correct because KMS uses a key policy to specify which principals can use the key for cryptographic operations like kms:Decrypt. By allowing only specific IAM roles in the key policy, you ensure that only those roles (and any other explicitly authorized principals) can decrypt the EBS volumes and snapshots encrypted with that key. This works in conjunction with IAM policies; the key policy explicitly grants the roles decrypt access, while all other IAM principals are implicitly denied. You can further refine this with conditions such as kms:ViaService to limit decrypt calls to EC2.

Why this answer

KMS key policies allow you to specify which IAM roles are allowed to use the key for decryption. Option A is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an organization, but they are not the most direct way to restrict decryption for specific IAM roles; KMS key policies are more appropriate. Option B is wrong because EBS volumes do not have bucket policies; bucket policies apply to S3 buckets.

Option D is wrong because instance profiles and policies denying ec2:DetachVolume do not affect decryption permissions.

49
MCQmedium

A company's security policy requires that all Amazon S3 buckets must have server-side encryption (SSE-S3 or SSE-KMS) enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and remediate it by enabling SSE-S3. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.Amazon Inspector
C.AWS Trusted Advisor
D.Amazon Macie
AnswerA

AWS Config is the correct choice because it continuously evaluates S3 bucket configurations against managed rules such as s3-bucket-default-encryption or s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation by invoking an AWS Systems Manager Automation document or a custom Lambda function. This gives you both detection and enforcement, which matches the security policy's requirement for automatic remediation of unencrypted buckets.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 bucket configurations against the security policy. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation to enable SSE-S3, enforcing compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation and remediation capabilities with Trusted Advisor's advisory checks, leading them to choose Trusted Advisor despite its lack of automated enforcement.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for evaluating S3 bucket encryption settings. Option C is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer automated remediation or continuous compliance enforcement; it is a reactive advisory tool. Option D is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data in S3, not to enforce encryption policies or remediate non-compliant buckets.

50
MCQeasy

A SysOps administrator needs to ensure that an Amazon EC2 instance can access an Amazon S3 bucket without storing long-term credentials on the instance. Which approach should be used?

A.Configure a security group rule that allows outbound traffic to S3.
B.Assign a bucket policy that grants access to the EC2 instance's public IP address.
C.Create an IAM role with S3 permissions and attach it to the EC2 instance profile.
D.Create an IAM user with programmatic access and store the credentials in a file on the instance.
AnswerC

Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended approach because it provides the instance with temporary, rotated credentials automatically. The instance retrieves these credentials from the instance metadata service (IMDSv2) after assuming the role, and the AWS SDK on the instance automatically uses them to sign S3 API requests without any hard-coded keys. This follows least privilege and eliminates the operational burden of key management on the instance.

Why this answer

Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the instance metadata service, eliminating the need to store long-term credentials on the instance. Option A is incorrect because security groups control network traffic, not API-level access to S3. Option B is incorrect because a bucket policy granting access based on a public IP address is insecure and does not provide AWS credentials.

Option D is incorrect because storing IAM user credentials on the instance is insecure and not a best practice.

51
MCQeasy

A SysOps administrator needs to share an encrypted AMI with a different AWS account. The AMI uses an AWS KMS key (customer managed key) for EBS encryption. What must be done to allow the target account to launch EC2 instances from the AMI?

A.Share the underlying EBS snapshot with the target account.
B.Re-encrypt the AMI using a new KMS key that is shared with the target account.
C.Modify the AMI launch permissions and add the target account as a principal in the KMS key policy with kms:Decrypt permission.
D.Modify the AMI launch permissions to include the target account.
AnswerC

This is the correct procedure for sharing an encrypted AMI across accounts. First, you must grant launch permissions on the AMI to the target account, which allows that account to see and launch instances from the AMI. Second, because the EBS snapshots backing the AMI are encrypted with a customer-managed KMS key, you must add the target account (or the IAM role/principal that will launch the instance) as a principal in the KMS key policy with kms:Decrypt permission. Both actions are required; without the KMS permission, instance launch will fail with an error.

Why this answer

When an AMI is encrypted with a customer managed KMS key, sharing the AMI launch permissions alone is insufficient because the target account cannot decrypt the underlying EBS snapshots without KMS permissions. The key policy must explicitly grant the target account (or its principals) kms:Decrypt (and typically kms:DescribeKey, kms:CreateGrant, kms:ReEncrypt*) so EC2 can use the key on the target account's behalf. Combining the AMI launch permission modification with the KMS key policy grant is what actually enables cross-account launches.

Exam trap

SOA-C02 often tests the misconception that sharing an encrypted AMI is a single-step operation — candidates forget that KMS key policies are a separate authorization layer from AMI launch permissions.

How to eliminate wrong answers

Option A is wrong because sharing the EBS snapshot does not grant KMS decrypt rights — the target account still cannot read the encrypted blocks without a key policy grant, and snapshot sharing alone does not enable AMI launch. Option B is wrong because re-encrypting with a new KMS key is unnecessary and does not by itself solve the problem unless that new key is also shared via its key policy; the original key can be used if its policy is updated. Option D is wrong because modifying AMI launch permissions alone is insufficient — the target account will fail to launch with a KMS AccessDenied error because the key policy does not authorize decryption.

52
Multi-Selecthard

A company uses AWS CloudTrail to log API calls. The SysOps team needs to ensure that any attempt to disable CloudTrail logging is immediately detected and triggers an automated response. Which combination of services should be used? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS Lambda
C.Amazon Inspector
D.Amazon Simple Queue Service (SQS)
E.Amazon EventBridge (CloudWatch Events)
AnswersB, E

AWS Lambda is the correct service because it can run custom remediation code in response to an EventBridge rule that detects a CloudTrail StopLogging API call. The Lambda function uses the AWS SDK to call StartLogging or UpdateTrail, automatically re-enabling the trail without manual intervention and requiring no servers to manage.

Why this answer

Amazon EventBridge (CloudWatch Events) can monitor CloudTrail API calls in real time and trigger an AWS Lambda function when a `StopLogging` or `UpdateTrail` API call is detected. Lambda then executes the automated response, such as re-enabling logging or sending an alert. This combination provides event-driven detection and remediation without manual intervention.

Exam trap

The trap here is that candidates often choose AWS Config because it is associated with compliance and monitoring, but they miss that Config is reactive and not designed for real-time event-driven automation, whereas EventBridge and Lambda provide the immediate detection and response required.

53
Multi-Selecteasy

Which THREE security best practices should be followed when managing IAM users? (Choose three.)

Select 3 answers
A.Attach policies directly to users
B.Rotate access keys regularly
C.Use the root user for daily administration
D.Grant least privilege permissions
E.Enable MFA for all users
AnswersB, D, E

Rotating access keys regularly limits the exposure window of compromised credentials. If a key or secret is leaked through a repository, log, or third-party integration, rotation invalidates the stolen key and forces the attacker to re-authenticate. AWS recommends rotation every 90 days or less, and you can create up to two access keys per user to enable seamless rotation without downtime.

Why this answer

Rotating access keys regularly limits the window of exposure if a key is compromised. AWS recommends rotating IAM user access keys every 90 days as a security best practice, and this can be enforced using an IAM policy that checks the key's creation date via the `aws:CurrentTime` condition key.

Exam trap

The trap here is that candidates may think attaching policies directly to users is acceptable for simplicity, but AWS explicitly recommends using groups for scalable permission management, and the exam tests this distinction.

54
MCQmedium

A company's security policy requires that all IAM users must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to automatically detect IAM users without MFA and generate a compliance report. Which AWS service should be used to meet this requirement with minimal operational overhead?

A.AWS Config
B.AWS CloudTrail
C.IAM Access Analyzer
D.AWS Trusted Advisor
AnswerA

AWS Config is the correct service because it includes the managed rule iam-user-mfa-enabled, which continuously evaluates whether each IAM user has an MFA device registered. The rule is part of the CIS AWS Foundations Benchmark and can be configured to run periodically or on configuration changes, returning a noncompliant result for any user missing MFA. This makes AWS Config the appropriate service for automated compliance monitoring and reporting, not just logging or ad-hoc checks.

Why this answer

AWS Config provides managed rules such as `iam-user-mfa-enabled` that can continuously evaluate IAM users against the requirement for MFA. When a user is found without MFA, AWS Config can trigger an automatic remediation action or generate a compliance report via its dashboard or Amazon SNS notifications, meeting the detection and reporting need with minimal operational overhead.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation with CloudTrail's auditing or Trusted Advisor's checks, not realizing that only AWS Config offers a managed rule specifically for IAM user MFA enforcement with automated reporting.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API activity and does not perform ongoing resource configuration compliance checks; it cannot detect the absence of MFA on IAM users. Option C is wrong because IAM Access Analyzer analyzes resource policies for external access, not user-level MFA status. Option D is wrong because AWS Trusted Advisor provides best-practice checks but does not have a specific check for IAM user MFA enforcement; it focuses on root account MFA and other high-level recommendations.

55
MCQhard

A company's security policy requires that all IAM users must authenticate using multi-factor authentication (MFA) before accessing the Amazon S3 bucket containing confidential finance data. The SysOps administrator needs to create an IAM policy that denies access to the S3 bucket if the user has not authenticated using MFA. Which IAM condition key should the administrator include in the policy?

A.aws:MultiFactorAuthPresent
B.aws:UserAgent
C.aws:SourceIp
D.aws:RequestedRegion
AnswerA

aws:MultiFactorAuthPresent is a Boolean global condition key that is populated in the request context after authentication. It evaluates to true only when the principal authenticated with a valid MFA device, such as a hardware token or virtual MFA application. In an IAM policy, you can write a Deny statement using this key with a BoolIfExists condition to explicitly block requests that did not use MFA, which directly satisfies the security requirement. Because it reflects the MFA authentication state itself, it is the correct condition key to enforce this policy.

Why this answer

The `aws:MultiFactorAuthPresent` condition key evaluates to `true` when the requesting IAM user has authenticated using a valid MFA device. By including this key in a `Deny` statement with a condition that it is `false`, the policy effectively blocks any S3 access unless MFA was used. This directly enforces the security policy requirement.

Exam trap

The trap here is that candidates may confuse `aws:MultiFactorAuthPresent` with `aws:MultiFactorAuthAge` or assume that simply having MFA enabled on the user account automatically sets the key, when in fact the key is only present if MFA was used during the current session authentication.

How to eliminate wrong answers

Option B is wrong because `aws:UserAgent` checks the user agent string of the request, which is irrelevant to authentication method. Option C is wrong because `aws:SourceIp` restricts access based on the requester's IP address, not MFA status. Option D is wrong because `aws:RequestedRegion` limits access to specific AWS regions, which does not enforce MFA authentication.

56
MCQeasy

A company's security policy requires that all Amazon S3 buckets must have server-side encryption enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and notify the security team. Which AWS service should be used to detect non-compliant buckets?

A.Amazon Inspector
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerB

AWS Config is the correct service because it provides managed rules such as s3-bucket-default-encryption-enabled and s3-bucket-encryption-enabled that continuously evaluate S3 bucket configurations. When a bucket is created or altered without default encryption, AWS Config records it as non-compliant and can trigger SNS notifications or Amazon EventBridge rules to alert security teams. It also maintains a complete configuration history and compliance timeline, making it ideal for automatically detecting and auditing encryption settings across all S3 buckets.

Why this answer

AWS Config is the correct service because it continuously monitors and evaluates the configuration of AWS resources against desired policies. By using an AWS Config managed rule such as `s3-bucket-server-side-encryption-enabled`, you can automatically detect any S3 bucket that lacks server-side encryption and trigger an SNS notification to the security team.

Exam trap

The trap here is confusing AWS Config's configuration compliance monitoring with AWS CloudTrail's API logging or GuardDuty's threat detection, leading candidates to choose a service that records actions rather than one that evaluates resource states.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for S3 bucket encryption compliance. Option C is wrong because AWS CloudTrail records API activity and provides audit logs, but it does not evaluate resource configurations against compliance rules or detect non-compliant buckets. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, not for checking S3 bucket encryption settings.

57
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user's IP address is 10.0.1.5. What is the result when the user tries to download an object from the folder 'confidential' in 'example-bucket'?

A.The request is denied because of the explicit Deny statement.
B.The request is allowed because the Deny statement only applies if the IP is outside the range.
C.The request is allowed because the user's IP matches the allowed range.
D.The request is denied because the Deny statement applies only when the IP is outside the range.
AnswerA

The request is denied because of the explicit Deny statement. IAM policy evaluation gives Deny statements absolute priority: if any applicable Deny exists, the request is automatically denied, even if an Allow statement also matches. In this exhibit, the Deny statement is unconditional and explicitly targets the S3 path, so it vetoes the request regardless of any IP-based Allow condition.

Why this answer

The policy contains an explicit Deny for the 'confidential' folder. In IAM, an explicit Deny overrides any Allow. Therefore, even if the user's IP is within the allowed range, the Deny blocks the download.

Options B, C, and D are incorrect because the Deny is unconditional and does not depend on IP address.

58
MCQmedium

An administrator notices that an EC2 instance has been compromised. The instance is part of an Auto Scaling group. What should the administrator do FIRST to contain the incident?

A.Update the Auto Scaling group's launch configuration to use a different AMI.
B.Terminate the instance immediately.
C.Detach the instance from the Auto Scaling group and apply a security group that denies all traffic.
D.Delete the Auto Scaling group.
AnswerC

Detaching the instance from the Auto Scaling group prevents the ASG from automatically replacing or terminating it due to health checks, while applying a security group that denies all traffic cuts off network communications to and from the instance. This stops command-and-control channels, data exfiltration, and lateral movement, and preserves the instance's disk and memory for forensics. This is the correct first step in EC2 incident response.

Why this answer

The correct first step is to detach the instance from the Auto Scaling group and apply a security group that denies all traffic. This isolates the compromised instance, preventing further damage while preserving evidence for forensic analysis. Option A is incorrect because changing the launch configuration does not affect running instances.

Option B is incorrect because immediate termination may destroy evidence. Option D is incorrect because deleting the Auto Scaling group is an extreme measure and not the immediate containment step.

59
MCQmedium

Account A owns an S3 bucket containing shared artifacts. Account B needs to read objects from the bucket. The Account A team wants to grant access without creating IAM users, sharing access keys, or creating a role in Account A that Account B assumes. How should the bucket be configured to allow Account B's IAM roles to read objects?

A.Add an S3 bucket policy on Account A's bucket with Principal set to Account B's account ID and s3:GetObject permission; ensure Account B's roles have s3:GetObject in their identity policies
B.Create an IAM role in Account A with s3:GetObject permission and a trust policy allowing Account B's roles to assume it
C.Generate a presigned URL for each object in Account A and share the URLs with Account B's services
D.Enable S3 Access Points on the bucket and create an access point that allows Account B's VPC to connect via PrivateLink
AnswerA

Cross-account S3 access requires both a resource-based policy (bucket policy) that grants Account B access, and identity-based policies in Account B that allow the action. The bucket policy's Principal field specifies Account B's account root ARN or specific role ARNs. When both sides allow, the call succeeds without any role chaining or credential sharing.

Why this answer

It uses an S3 bucket policy with a Principal set to Account B's account ID, which grants cross-account access to all IAM principals (users and roles) in Account B. Account B's IAM roles must also have an identity policy that allows s3:GetObject, ensuring that the effective permissions require both the bucket policy and the role's policy to allow the action. This approach avoids creating IAM users, sharing access keys, or setting up a role in Account A for Account B to assume.

Exam trap

The SOA-C02 exam often tests the misconception that a bucket policy with a cross-account Principal automatically grants access to all IAM roles in that account, but candidates forget that the roles must also have an explicit allow in their identity policies for the action to succeed.

How to eliminate wrong answers

Option B is wrong because it requires creating a role in Account A that Account B assumes, which violates the requirement to avoid such a setup. Option C is wrong because presigned URLs grant temporary access but require generating and sharing a URL for each object, which is not a scalable or secure method for ongoing access by IAM roles, and it does not leverage IAM policies for authorization. Option D is wrong because S3 Access Points with VPC PrivateLink restrict access to a specific VPC, but they do not inherently grant cross-account access to IAM roles in Account B without additional bucket policies or resource policies, and the question does not specify VPC-based access.

60
Multi-Selecthard

A SysOps administrator needs to audit all changes to IAM resources in their AWS account. Which THREE AWS services can be used together to achieve this? (Choose THREE.)

Select 3 answers
A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Config
D.AWS Trusted Advisor
E.Amazon CloudWatch Logs
AnswersA, C, E

AWS CloudTrail records every IAM API call as a management event, capturing who changed which resource, when, and from where. It supplies the authoritative change history that audit tooling and log analysis consume to reconstruct all IAM modifications across the account.

Why this answer

AWS CloudTrail (A) is correct because it records every API call that modifies IAM resources (CreateUser, AttachRolePolicy, PutRolePolicy, etc.) as management events, providing the raw audit trail of who did what and when. AWS Config (C) is correct because it continuously records IAM resource configurations and their change history, letting you see the before/after state of users, roles, and policies and evaluate them against rules. Amazon CloudWatch Logs (E) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where you can retain, search, and set metric filters/alarms on IAM change events.

Amazon GuardDuty (B) is a threat-detection service that analyzes logs for malicious behavior, not a change-auditing mechanism, and AWS Trusted Advisor (D) provides best-practice checks and recommendations rather than a record of IAM changes.

61
MCQhard

A company uses AWS Organizations and wants to restrict access to S3 buckets based on project tags. The security policy requires that users in the 'DataScientists' group can only access S3 buckets that have the tag 'Project: DataEngineering'. Which IAM policy condition key should the SysOps administrator use in a customer managed policy to enforce this restriction?

A.aws:ResourceTag
B.s3:ExistingObjectTag
C.s3:ResourceTag
D.iam:ResourceTag
AnswerA

The aws:ResourceTag condition key allows you to control access based on tags attached to the resource being accessed (e.g., S3 bucket tag). You can use it in the 'Condition' element of an IAM policy to enforce the tag requirement.

Why this answer

The `aws:ResourceTag` condition key is used in IAM policies to control access based on the tags attached to the AWS resource (in this case, an S3 bucket). By specifying `aws:ResourceTag/Project` with a value of `DataEngineering`, the policy ensures that only S3 buckets with that exact tag are accessible to the 'DataScientists' group. This key is evaluated against the resource's tags at the time of the request, making it the appropriate choice for tag-based resource restrictions.

Exam trap

The trap here is that candidates often confuse `aws:ResourceTag` with service-specific keys like `s3:ExistingObjectTag`, mistakenly applying object-level conditions to bucket-level restrictions, or they assume `s3:ResourceTag` exists as a valid key when it does not.

How to eliminate wrong answers

Option B is wrong because `s3:ExistingObjectTag` is used to condition access based on tags on individual objects within an S3 bucket, not on the bucket itself, and thus cannot restrict access to buckets based on bucket-level tags. Option C is wrong because `s3:ResourceTag` is not a valid IAM condition key; AWS uses `aws:ResourceTag` for resource-level tags across services, and S3-specific condition keys like `s3:ExistingObjectTag` or `s3:RequestObjectTag` are for object-level operations. Option D is wrong because `iam:ResourceTag` is specific to IAM resources (such as users, roles, or policies) and cannot be used to restrict access to S3 buckets based on bucket tags.

62
Multi-Selectmedium

A company wants to audit all API calls made in their AWS account for compliance. Which THREE AWS services can be used together to capture and store these logs? (Choose three.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.Amazon S3
E.Amazon GuardDuty
AnswersA, B, D

Amazon CloudWatch Logs is correct because it can be the destination for a CloudTrail trail: you can configure CloudTrail to deliver all API call events to a CloudWatch Logs log group. From there, you can store the logs, apply metric filters for real-time monitoring, and retain them for analysis or alerting. This integration makes CloudWatch Logs a valid place to audit and act on API activity, even though CloudTrail itself is the original recorder.

Why this answer

AWS CloudTrail (B) is the service that records API activity in an AWS account, capturing management and data events as audit trails, which is exactly what is needed to audit all API calls. Amazon CloudWatch Logs (A) is used to receive and store those CloudTrail event logs via a trail's CloudWatch Logs integration, enabling centralized monitoring and retention of the API call records. Amazon S3 (D) is the destination where CloudTrail delivers the log files for durable, long-term storage and later compliance analysis.

AWS Config (C) evaluates resource configurations and compliance against rules rather than capturing API call logs, and Amazon GuardDuty (E) is a threat-detection service that analyzes findings from sources like CloudTrail but does not itself capture and store the raw API call logs.

Exam trap

SOA-C02 often tests the confusion between CloudTrail (captures API activity) and AWS Config (records resource configuration state) — candidates pick Config thinking it logs API calls, but Config tracks configuration drift, not API events.

63
MCQeasy

A SysOps administrator needs to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the administrator do?

A.Create a bucket policy that allows access from the instance's public IP.
B.Create an IAM role with S3 access and attach it to the instance profile.
C.Store the access key and secret key in a file on the instance.
D.Configure the security group to allow outbound traffic to S3.
AnswerB

Attaching an IAM role to the EC2 instance via an instance profile is the secure, recommended way to grant S3 permissions. The instance automatically retrieves temporary security credentials from the instance metadata service (IMDS), which are rotated automatically, eliminating the need to embed long-lived access keys. The role's permissions policy (e.g., AmazonS3ReadOnlyAccess) defines exactly what S3 actions the instance can perform, and the instance profile is the container that delivers the role to the instance.

Why this answer

The correct approach is to create an IAM role with the required S3 permissions and attach it to the EC2 instance profile, so the instance's SDK/CLI can retrieve temporary credentials from the instance metadata service (IMDS). This eliminates the need to store long-term AWS credentials on the instance and follows AWS best practices for least privilege and credential hygiene.

Exam trap

SOA-C02 often tests whether candidates know that IAM roles attached via instance profiles are the only secure way to grant EC2 access to AWS services, so options involving stored keys or IP-based policies are classic distractors.

How to eliminate wrong answers

Option A is wrong because bucket policies based on public IP are fragile (IPs change), do not authenticate the instance, and expose the bucket to anyone from that IP range. Option C is wrong because storing access keys in a file on the instance is exactly the insecure practice the question asks to avoid — keys can be exfiltrated if the instance is compromised. Option D is wrong because security groups control network reachability, not identity or authorization; allowing outbound traffic to S3 does not grant the instance permission to access the bucket.

64
MCQeasy

Refer to the exhibit. An IAM role has the trust policy shown. Which entity can assume this role?

A.Only the IAM user with the ARN arn:aws:iam::123456789012:user/Admin
B.Any IAM user in any AWS account
C.Any IAM user in the AWS account 123456789012
D.Only users who have MFA enabled
AnswerC

Because the Principal value is arn:aws:iam::123456789012:root, AWS treats it as the account root principal, which in a trust policy effectively acts as a wildcard for all IAM users (and roles) within that account. The trust policy does not restrict the source identity to a hyper-specific user ARN or to a particular MFA state. Each IAM user still needs an identity-based policy permitting the sts:AssumeRole action, but the trust relationship is open to every user in the account.

Why this answer

The trust policy specifies `"AWS": "arn:aws:iam::123456789012:root"` as the principal, which allows any IAM user or role within the AWS account 123456789012 to assume the role, provided they have the necessary permissions in their own identity-based policies. This is because the root ARN of an account acts as a wildcard for all identities in that account. Option C correctly identifies that any IAM user in that account can assume the role.

Exam trap

The trap here is that candidates often confuse the account root ARN with a specific user ARN, thinking it only allows the root user, when in fact it allows any identity in the account to assume the role.

How to eliminate wrong answers

Option A is wrong because the trust policy does not restrict the principal to a specific IAM user ARN; it uses the account root ARN, which allows all identities in the account, not just the Admin user. Option B is wrong because the trust policy explicitly limits the principal to account 123456789012, so users from other AWS accounts cannot assume the role unless a cross-account trust is configured. Option D is wrong because the trust policy does not include a condition for MFA (e.g., `"aws:MultiFactorAuthPresent": "true"`), so MFA is not required to assume the role.

65
MCQeasy

A SysOps administrator needs to ensure that an Amazon RDS instance is encrypted at rest. The instance is already provisioned unencrypted. What is the correct approach to enable encryption?

A.Create a snapshot of the instance and restore it with encryption enabled
B.Use AWS KMS to encrypt the underlying EBS volumes of the RDS instance
C.Enable encryption using the AWS CLI command modify-db-instance
D.Modify the RDS instance and enable encryption in the configuration
AnswerA

The only supported way to add encryption to an existing Amazon RDS instance is to create a manual snapshot, copy that snapshot with a KMS customer master key (encryption enabled), and then restore a new DB instance from the encrypted copy. Encryption is a creation-time attribute, so this snapshot-and-restore workflow effectively rebuilds the database with at-rest encryption while preserving your data and configuration.

Why this answer

RDS does not allow enabling encryption in place on an existing unencrypted instance. The supported path is to snapshot the instance, then restore that snapshot with encryption enabled, which produces a new encrypted instance. You then repoint applications to the new endpoint.

Exam trap

SOA-C02 often tests the misconception that modify-db-instance can enable encryption — candidates must remember RDS encryption is immutable after creation and requires snapshot-restore.

How to eliminate wrong answers

Option B is wrong because you cannot directly encrypt the underlying EBS volumes of an RDS instance — RDS manages storage and does not expose EBS volume encryption toggles. Option C is wrong because modify-db-instance has no parameter to enable encryption on an existing instance; encryption can only be set at creation or restore. Option D is wrong because the RDS modify operation does not offer an encryption toggle for existing instances.

66
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all new S3 buckets created in any account have encryption enabled. Which approach should be used to enforce this policy?

A.Create a service control policy (SCP) that denies the s3:CreateBucket action unless the request includes the x-amz-server-side-encryption header with a valid encryption algorithm.
B.Create an IAM role in each member account with a policy that denies s3:CreateBucket without encryption, and require all users to assume that role.
C.Use AWS Config managed rule 's3-bucket-server-side-encryption-enabled' to detect non-compliant buckets and automatically remediate.
D.Enable AWS CloudTrail and create a CloudWatch Events rule that triggers a Lambda function to delete any bucket created without encryption.
AnswerA

A service control policy (SCP) attached at the organization or organizational unit level can deny the s3:CreateBucket action unless the request includes an x-amz-server-side-encryption header, using the s3:x-amz-server-side-encryption condition key. Because SCPs apply to every IAM principal in the account—including the root user—they provide a central, preventive guardrail that blocks the API call entirely, rather than merely auditing or remediating after the fact.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow central governance to deny actions across all accounts. An SCP can deny the s3:CreateBucket action unless the request includes the server-side-encryption header, thus enforcing encryption on new buckets. Option B is incorrect because IAM roles per account lack centralized enforcement and cannot prevent users with their own permissions from creating buckets without encryption.

Option C is incorrect because AWS Config rules are detective, not preventive; they can only detect and optionally remediate after the bucket is created, not block the creation. Option D is incorrect because using CloudTrail and CloudWatch Events with a Lambda function is a reactive approach—it can delete a non-compliant bucket after creation, but does not enforce encryption at the time of creation. The requirement is to enforce the policy, making a preventive SCP the correct solution.

67
MCQmedium

A company stores database credentials in AWS Secrets Manager. The security policy requires that the credentials be rotated automatically every 30 days. Which action should the SysOps administrator take to enforce this requirement?

A.Configure an AWS Lambda function to rotate the secret and set a CloudWatch Events rule to trigger it every 30 days.
B.Enable automatic rotation in the Secrets Manager console and specify a rotation interval of 30 days using a Lambda rotation function.
C.Use AWS Systems Manager Parameter Store to store the credentials and configure a State Manager association for rotation.
D.Create an IAM policy that forces users to rotate the secret manually every 30 days.
AnswerB

Enabling automatic rotation in Secrets Manager is the native solution: you configure the secret's rotation configuration to invoke a dedicated Lambda function (the 'rotation function') that creates new secret versions and updates the resource or database password. Secrets Manager then runs that Lambda on a schedule, and specifying a rotation interval of 30 days gives you exactly the required cadence without building your own scheduler. This approach also integrates with IAM and CloudTrail for permission enforcement and auditability, so the rotation cycle is fully managed rather than custom-coded.

Why this answer

AWS Secrets Manager natively supports automatic rotation using a Lambda function. By enabling automatic rotation in the console and specifying a 30-day interval, the administrator meets the security policy without manual intervention. Secrets Manager handles the rotation schedule and invokes the Lambda function automatically.

Exam trap

The trap here is that candidates may think any automated scheduling (like CloudWatch Events) is sufficient, but AWS Secrets Manager's native rotation feature is the correct and simplest way to enforce automatic rotation without custom infrastructure.

How to eliminate wrong answers

Option A is wrong because while a Lambda function and CloudWatch Events rule could rotate the secret, this approach bypasses Secrets Manager's built-in rotation mechanism and requires custom scheduling logic, making it less reliable and harder to maintain. Option C is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it is designed for configuration management, not secret rotation. Option D is wrong because creating an IAM policy that forces manual rotation does not enforce automated rotation and relies on user compliance, which violates the requirement for automatic rotation every 30 days.

68
MCQmedium

Refer to the exhibit. A SysOps administrator runs the commands shown. Which key(s) have automatic key rotation enabled?

A.Only the first key
B.Only the second key
C.Neither key
D.Both keys
AnswerA

The first key is the only one that meets the rotation requirement because its KeyRotationEnabled value is true. AWS KMS automatic rotation is enabled on this customer-managed key, meaning AWS replaces the backing key every year. The second key's status is false, so only the first key qualifies.

Why this answer

The first key has automatic key rotation enabled because the `EnableKeyRotation` API call was made specifically for that key (key ID `1234abcd-12ab-34cd-56ef-1234567890ab`). AWS KMS automatic key rotation is a per-key setting that must be explicitly enabled; it is not enabled by default. The second key (key ID `0987dcba-09fe-87dc-65ba-0987654321fe`) was not subjected to any rotation-enabling command, so it retains the default disabled state.

Exam trap

The trap here is that candidates assume automatic key rotation is enabled by default for all KMS keys, but in reality it must be explicitly enabled per key, and the CLI output shows only the first key received the enabling command.

How to eliminate wrong answers

Option B is wrong because the second key never had `EnableKeyRotation` called on it; automatic key rotation remains disabled for that key. Option C is wrong because the first key clearly has rotation enabled via the API call. Option D is wrong because only the first key has rotation enabled, not both.

69
MCQeasy

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest. The administrator wants to automatically remediate any bucket that is created without default encryption. Which AWS service should be used to achieve this with the least operational overhead?

A.AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation
B.AWS CloudTrail with Amazon CloudWatch Events and AWS Lambda
C.AWS Trusted Advisor with Amazon Simple Notification Service (SNS)
D.Amazon Inspector with AWS Systems Manager Patch Manager
AnswerA

AWS Config's managed rule `s3-bucket-default-encryption-enabled` continuously evaluates each bucket's configuration against the required encryption state. On detecting a noncompliant bucket, Config invokes an SSM Automation runbook (e.g., `AWS-ConfigureS3BucketEncryption`) that calls `PutBucketEncryption` to enable default AES-256 or AWS KMS encryption automatically. Because this combines policy evaluation with an enforcement action, it satisfies the SysOps administrator's requirement directly without requiring custom code.

Why this answer

AWS Config with the managed rule 's3-bucket-default-encryption-enabled' can detect S3 buckets that lack default encryption. By attaching an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') as an auto-remediation action, the administrator can automatically apply AES-256 or AWS-KMS encryption to noncompliant buckets without manual intervention, minimizing operational overhead.

Exam trap

The trap here is that candidates may assume AWS Config only provides detection and not remediation, overlooking the auto-remediation integration with Systems Manager Automation, or they may confuse AWS Config's managed rules with Trusted Advisor's advisory checks.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail with CloudWatch Events and Lambda requires custom code and event-driven architecture, which introduces more operational overhead than AWS Config's built-in auto-remediation. Option C is wrong because AWS Trusted Advisor only provides recommendations and alerts via SNS, not automated remediation. Option D is wrong because Amazon Inspector is designed for vulnerability assessment of EC2 instances and container workloads, not for S3 bucket encryption compliance.

70
Multi-Selectmedium

A company wants to ensure that its AWS resources are compliant with the CIS AWS Foundations Benchmark. Which TWO AWS services can be used to automate compliance checks and remediation?

Select 2 answers
A.AWS CloudTrail
B.Amazon Inspector
C.AWS Config
D.AWS Security Hub
E.Amazon GuardDuty
AnswersC, D

AWS Config is the native service for tracking resource configuration changes and enforcing compliance through Config rules. You can deploy managed rules aligned with CIS benchmarks and, when a resource is found noncompliant, integrate remediation actions using SSM Automation documents or Lambda functions to automatically correct the drift. Config maintains a configuration item history for every resource, giving auditors the evidence needed to prove compliance over time, which makes it the core service for this use case.

Why this answer

AWS Config (option C) is correct because it continuously records resource configuration changes and evaluates them against managed or custom rules, including CIS AWS Foundations Benchmark conformance packs, and it supports automatic remediation through SSM Automation documents. AWS Security Hub (option D) is correct because it aggregates security findings and runs the CIS AWS Foundations Benchmark as a supported security standard, giving a compliance score and control-level findings that can drive automated response via EventBridge. AWS CloudTrail (option A) only logs API activity for auditing and does not perform compliance evaluation or remediation.

Amazon Inspector (option B) is a vulnerability management service for EC2, ECR images, and Lambda, not a CIS benchmark compliance engine. Amazon GuardDuty (option E) is a threat detection service that identifies malicious or anomalous activity, not configuration compliance against the CIS benchmark.

Exam trap

SOA-C02 often tests the confusion between detection services (GuardDuty, Inspector) and compliance services (Config, Security Hub) — candidates must match the service to the compliance use case.

71
MCQmedium

A company's security policy requires that all Amazon S3 buckets must be encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). A SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and automatically apply SSE-S3 encryption. The solution should leverage AWS managed services and minimize custom code. Which combination of AWS services should be used?

A.AWS Config and AWS Lambda
B.Amazon GuardDuty and AWS Lambda
C.AWS CloudTrail and Amazon EventBridge
D.Amazon Macie and AWS Step Functions
AnswerA

AWS Config continuously evaluates S3 buckets against the managed rule for encryption. Non-compliant buckets can trigger a remediation action via an AWS Lambda function that applies SSE-S3 configuration. This minimizes custom code and uses managed services.

Why this answer

AWS Config can evaluate S3 bucket configurations against a managed rule (s3-bucket-server-side-encryption-enabled) to detect non-compliant buckets. When a non-compliant bucket is detected, AWS Config can trigger an AWS Lambda function via an Amazon EventBridge rule or a custom remediation action to automatically enable SSE-S3 encryption on the bucket. This combination uses managed services and minimizes custom code, meeting the security policy requirement.

Exam trap

The trap here is that candidates may confuse AWS Config's compliance evaluation with GuardDuty's threat detection or Macie's data classification, leading them to choose a service that cannot detect or remediate encryption settings.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for checking or enforcing S3 bucket encryption configurations. Option C is wrong because AWS CloudTrail records API activity but does not evaluate resource compliance or trigger automated remediation; Amazon EventBridge can route events but requires a separate service like AWS Config to detect non-compliance. Option D is wrong because Amazon Macie is a data discovery and protection service that uses machine learning to identify sensitive data, not to detect or enforce encryption settings; AWS Step Functions is an orchestration service that would require custom code to implement the detection logic.

72
MCQmedium

An organization has a policy requiring that all Amazon EC2 instances launched in the production account must have detailed monitoring enabled for Amazon CloudWatch. A SysOps administrator needs to enforce this rule automatically. Which solution will ensure that any EC2 instance launched without detailed monitoring is automatically remediated?

A.Use AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' and configure an automatic remediation action using AWS Systems Manager Automation to enable detailed monitoring on non-compliant instances.
B.Use AWS Trusted Advisor to check for instances without detailed monitoring and send a notification to the administrator via email.
C.Use an Amazon CloudWatch Events rule to detect RunInstances API calls and trigger a Lambda function that enables detailed monitoring on newly launched instances.
D.Use an IAM policy that denies the ec2:RunInstances action unless the user specifies the parameter to enable detailed monitoring.
AnswerA

AWS Config's managed rule 'ec2-instance-detailed-monitoring-enabled' runs continuous evaluations against all recorded EC2 instances, marking any without detailed monitoring as non-compliant. Pairing this with an automatic remediation action leverages an AWS Systems Manager Automation document to run the 'ec2-monitor-instances' command or equivalent, enabling detailed monitoring without manual intervention. Because AWS Config already discovers and tracks instances, this solution covers both newly launched and pre-existing instances, requiring no custom code and providing a fully managed, auditable compliance enforcement loop.

Why this answer

AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' continuously evaluates EC2 instances against the policy. When an instance is non-compliant (i.e., launched without detailed monitoring), the automatic remediation action uses an AWS Systems Manager Automation document to enable detailed monitoring on that instance, ensuring enforcement without manual intervention.

Exam trap

The trap here is that candidates often choose Option C (CloudWatch Events + Lambda) because it seems reactive and automatic, but they overlook that CloudWatch Events may not reliably capture all RunInstances API calls (e.g., when instances are launched by Auto Scaling or other services) and that the Lambda function would need to handle race conditions and permissions, whereas AWS Config remediation is purpose-built for continuous compliance enforcement.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor only provides recommendations and notifications; it cannot automatically remediate non-compliant resources. Option C is wrong because a CloudWatch Events rule triggered by RunInstances API calls cannot reliably catch instances launched without detailed monitoring if the monitoring parameter is not explicitly set in the API call (e.g., instances launched via Auto Scaling or other services may not trigger the rule as expected). Option D is wrong because an IAM policy that denies ec2:RunInstances unless the user specifies the detailed monitoring parameter can be bypassed by users who have permissions to modify the instance after launch, and it does not automatically remediate instances that are already running without detailed monitoring.

73
Multi-Selecthard

A SysOps administrator is designing a VPC for a web application that must be secure. Which THREE security measures should the administrator implement? (Choose THREE.)

Select 3 answers
A.Configure network ACLs to filter traffic at the subnet level.
B.Enable VPC Flow Logs to capture traffic information.
C.Place all resources in public subnets to simplify access.
D.Use security groups to control inbound and outbound traffic at the instance level.
E.Use the default VPC for simplicity.
AnswersA, B, D

Network ACLs are a stateless, subnet-level firewall that filters traffic based on numbered rules evaluated in ascending order. Because they are stateless, you must explicitly define both inbound and outbound rules, and responses to allowed inbound traffic require a corresponding outbound rule. NACLs apply uniformly to every instance in the subnet, providing a coarse boundary that can block traffic before it reaches security groups, though they cannot inspect individual instance traffic.

Why this answer

Network ACLs (NACLs) are stateless firewalls that operate at the subnet level, providing an additional layer of security by filtering traffic entering and exiting each subnet. By default, NACLs allow all traffic, but you can configure custom rules to explicitly allow or deny traffic based on IP addresses, protocols, and port ranges, which is essential for securing a web application VPC.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, subnet-level) with security groups (stateful, instance-level), or assume that using the default VPC is acceptable for simplicity, when in fact it lacks the granular control needed for a secure architecture.

74
MCQhard

A company's security policy requires that all Amazon S3 buckets must be encrypted at rest with AWS Key Management Service (AWS KMS) customer managed keys. A SysOps administrator discovers that some buckets are not encrypted. Which combination of AWS services should be used to automatically detect and remediate non-compliant buckets using infrastructure as code?

A.AWS Config with a managed rule and AWS Lambda for automatic remediation.
B.AWS CloudTrail and Amazon GuardDuty.
C.Amazon Inspector and AWS Systems Manager.
D.Amazon Macie and AWS CloudFormation.
AnswerA

AWS Config is the correct service because it performs continuous, resource-level compliance evaluation. The managed rule 's3-bucket-server-side-encryption-enabled' can be configured with a parameter to require SSE-KMS (aws:kms) rather than just SSE-S3, and when a bucket is non-compliant, AWS Config triggers an automatic remediation action that invokes a Lambda function to apply the required default encryption settings. This creates an end-to-end detect-and-fix pipeline, which CloudTrail, GuardDuty, Inspector, or Macie cannot provide.

Why this answer

AWS Config with a managed rule (e.g., s3-bucket-server-side-encryption-enabled) can continuously evaluate S3 buckets for compliance with the encryption policy. When a non-compliant bucket is detected, AWS Config can automatically invoke an AWS Lambda function to remediate the issue, such as enabling encryption with a customer managed KMS key. This combination provides automated detection and remediation using infrastructure as code, as the Config rule and Lambda function can be defined in AWS CloudFormation or similar IaC tools.

Exam trap

The trap here is that candidates may confuse detection services (like GuardDuty or Macie) with compliance evaluation services (AWS Config), or assume that CloudFormation alone can detect non-compliance without a continuous evaluation mechanism like AWS Config rules.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail and Amazon GuardDuty are used for auditing API activity and threat detection, not for automated compliance detection and remediation of S3 bucket encryption. Option C is wrong because Amazon Inspector is a vulnerability management service for EC2 instances and container workloads, not for S3 bucket encryption compliance, and AWS Systems Manager is for operational management, not automated encryption remediation. Option D is wrong because Amazon Macie is a data discovery and classification service for sensitive data, not for encryption compliance, and AWS CloudFormation alone cannot automatically detect non-compliant buckets without a trigger like AWS Config.

75
MCQmedium

A SysOps administrator is troubleshooting an IAM policy that is not granting the expected permissions. The policy has a Deny effect on a specific action, but the user is still able to perform that action. What is the most likely reason?

A.The Deny statement is listed after an Allow statement in the policy
B.IAM policies do not support deny statements with conditions
C.The Deny statement includes a condition that is not met by the request
D.The user has an attached AWS managed policy that allows the action
AnswerC

This is the correct option. IAM evaluates the Condition element of a Deny statement before treating that statement as an effective deny; if the request's context does not satisfy the condition, the Deny statement is skipped entirely. Once that Deny is out of the way, the default-implicit-deny behavior is replaced by any applicable Allow policies, which then permit the action.

Why this answer

An explicit Deny in IAM only takes effect when the condition attached to that Deny statement evaluates to true for the request. If the Deny statement includes a condition (such as a specific IP range, MFA requirement, or time window) that the current request does not satisfy, the Deny does not apply, and an Allow from another policy can grant access. This is the most likely reason a user can still perform the action despite a Deny statement existing.

Exam trap

SOA-C02 often tests the misconception that any Deny statement automatically blocks access — candidates forget that a Deny with an unmet condition is effectively inert, and they overlook the condition evaluation step in the IAM policy evaluation flow.

How to eliminate wrong answers

Option A is wrong because IAM policy evaluation does not depend on the order of statements within a policy — explicit Deny always overrides Allow regardless of statement order. Option B is wrong because IAM policies absolutely do support deny statements with conditions; condition keys like aws:SourceIp, aws:MultiFactorAuthPresent, and aws:CurrentTime are commonly used with Deny. Option D is wrong because an attached AWS managed policy that allows the action would be overridden by an explicit Deny in another policy — explicit Deny always wins in IAM evaluation logic, so this cannot be the reason the user still has access.

Page 1 of 3 · 198 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.