Courseiva

CCNA Security and Compliance Questions

75 of 198 questions · Page 2/3 · Security and Compliance · Answers revealed

76
MCQmedium

A company's security team requires that all Amazon EC2 instances in a specific AWS account must have the tag 'Environment' set to either 'Production' or 'Test'. Any instance that is launched without this tag or with an invalid value must be automatically terminated within five minutes. Which combination of AWS services can enforce this requirement with minimal manual intervention?

A.AWS Config with a custom rule and AWS Lambda
B.AWS CloudTrail and Amazon CloudWatch Events
C.AWS Service Catalog and AWS Organizations
D.Amazon Inspector and AWS Systems Manager
AnswerA

A custom AWS Config rule can evaluate EC2 instances when they are created (configuration change trigger) and invoke an AWS Lambda function to terminate instances lacking the required tag or having an invalid value. This provides continuous compliance enforcement.

Why this answer

AWS Config with a custom rule can evaluate EC2 instances for the required 'Environment' tag with valid values. When a non-compliant instance is detected, AWS Config triggers an AWS Lambda function that terminates the instance within the required five-minute window. This combination provides automated, event-driven enforcement with minimal manual intervention.

Exam trap

The trap here is that candidates may think CloudTrail and CloudWatch Events alone can enforce tag compliance, but they lack the evaluation logic and automated remediation that AWS Config with a custom Lambda rule provides.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls and CloudWatch Events can trigger on those events, but they lack native tag validation logic; you would still need a Lambda function to evaluate tag values and terminate instances, making this an incomplete solution. Option C is wrong because AWS Service Catalog enforces compliance at provisioning time through predefined products, but it cannot retroactively terminate instances launched outside the catalog or enforce tag compliance on existing instances. Option D is wrong because Amazon Inspector is a vulnerability assessment service and AWS Systems Manager is for operational management; neither service has the capability to evaluate tags or terminate instances based on tag compliance.

77
MCQhard

A SysOps administrator is troubleshooting an issue where an EC2 instance cannot access an S3 bucket using an instance profile. The instance profile has an IAM role with a policy that allows s3:GetObject on the bucket. The S3 bucket policy has a Deny for all principals except a specific service role. What is the most likely reason for the access failure?

A.The IAM role trust policy does not allow EC2 to assume the role.
B.The instance profile is not correctly attached to the EC2 instance.
C.The S3 bucket requires a VPC endpoint.
D.The S3 bucket policy Deny overrides the IAM role permissions.
AnswerD

When both an IAM role policy and a bucket policy apply to the same S3 request, AWS evaluates all identity-based and resource-based policies, and an explicit Deny in any applicable policy takes precedence over any Allow. In this scenario, the IAM role grants the s3:GetObject permission, but the S3 bucket policy contains a separate statement that explicitly denies the same action; the explicit Deny overrides the allow and causes the final authorization decision to be Deny AWS documentation confirms that explicit deny statements in resource policies are authoritative and cannot be overridden by any other allow. Therefore, the bucket policy Deny is the reason the EC2 instance cannot access the object.

Why this answer

An explicit Deny in an S3 bucket policy overrides any Allow permissions granted by IAM policies, including those from an instance profile role. In this scenario, the bucket policy denies access to all principals except a specific service role, so even though the IAM role attached to the EC2 instance allows s3:GetObject, the Deny takes precedence, causing access failure. Option A is incorrect because the issue is not about the trust policy; if the instance profile is attached, EC2 can assume the role.

Option B is incorrect because the instance profile attachment is not the likely cause; the Deny in the bucket policy would block access regardless. Option C is incorrect because a VPC endpoint is not required for S3 access and would not override the bucket policy Deny.

78
MCQhard

Refer to the exhibit. The security team wants to ensure that all objects uploaded to the S3 bucket 'my-secure-bucket' are encrypted at rest. Based on the CloudTrail log entry, what can be concluded about the object 'confidential.pdf'?

A.The object is encrypted with AWS KMS
B.The object is not encrypted
C.The object is encrypted with SSE-S3
D.The object was uploaded without an encryption header
AnswerC

The header value AES256 is the standard indicator for SSE-S3, where Amazon S3 manages the encryption keys entirely on your behalf. SSE-S3 uses the AES-256-GCM block cipher to encrypt objects at rest and provides automatic, transparent encryption with no additional cost or key management burden. The logged value matches this mode exactly, confirming that the object is encrypted with SSE-S3.

Why this answer

The CloudTrail log entry shows that the object 'confidential.pdf' was uploaded with the 'x-amz-server-side-encryption' header set to 'AES256'. This header indicates that server-side encryption with Amazon S3-managed keys (SSE-S3) was requested. The response also confirms that encryption was applied.

Therefore, the object is encrypted with SSE-S3, making option C correct. Option A is incorrect because the log does not mention KMS key details. Option B is incorrect because the object is encrypted.

Option D is incorrect because the encryption header was provided.

79
MCQhard

A company has an AWS account with multiple VPCs connected via a transit gateway. The security team wants to centrally manage VPC security group rules and ensure compliance. Which approach is most effective?

A.Use AWS Firewall Manager to centrally define and enforce security group rules across all VPCs.
B.Create a single security group and attach it to all VPCs.
C.Define security group rules in AWS CloudFormation templates and deploy them to each VPC.
D.Use network ACLs instead of security groups for centralized management.
AnswerA

AWS Firewall Manager is the correct choice because it provides centrally managed security policies that automatically apply and enforce security group rules across all VPCs and accounts in an AWS Organization. It continuously audits compliance, automatically repairs non-compliant resources, and allows you to define common security group rules in one place, eliminating per-VPC manual updates while offering a single pane of glass for ongoing enforcement.

Why this answer

AWS Firewall Manager is the correct choice because it provides centralized administration of security group rules across multiple VPCs and accounts, enabling the security team to define a common set of rules and automatically enforce compliance. It integrates with AWS Organizations to apply policies to all VPCs in the organization, ensuring consistent security posture without manual intervention.

Exam trap

The trap here is that candidates may think CloudFormation or a single security group can achieve centralized management, but they overlook the cross-VPC scope limitation of security groups and the lack of automated enforcement and compliance monitoring in those approaches.

How to eliminate wrong answers

Option B is wrong because a single security group cannot be attached to resources in different VPCs; security groups are scoped to a single VPC and cannot span VPCs, even when connected via a transit gateway. Option C is wrong because while CloudFormation can deploy security group rules, it does not provide ongoing centralized enforcement or compliance monitoring; it requires manual updates and does not automatically detect or remediate drift. Option D is wrong because network ACLs are stateless and operate at the subnet level, not at the resource level like security groups, and AWS Firewall Manager does not support centralized management of network ACLs for security group rules.

80
MCQmedium

A company's security team notices that an IAM user has access keys that have not been rotated in over a year. Which action should the SysOps administrator take to enforce key rotation automatically?

A.Set up an AWS Config rule to detect old keys and trigger an AWS Lambda function to rotate them.
B.Apply a service control policy (SCP) that requires key rotation.
C.Configure an IAM policy that automatically rotates keys every 90 days.
D.Use AWS Trusted Advisor to automatically rotate the keys.
AnswerA

This is the correct automated approach: AWS Config evaluates IAM access keys against a managed rule such as iam-user-access-key-age, and when a key exceeds the defined maximum age, Config triggers an AWS Lambda function as a remediation action. The Lambda function programmatically rotates the key—creating a new access key, updating or notifying the user, and retiring/deleting the old one—using IAM APIs without manual intervention.

Why this answer

AWS Config can evaluate IAM user access keys against a custom or managed rule (e.g., 'access-keys-rotated') to detect keys older than a specified threshold. When a non-compliant key is found, you can configure an AWS Config rule to invoke an AWS Lambda function that programmatically deactivates the old key and creates a new one, enforcing automatic rotation. This is the only native, automated approach that combines detection and remediation without manual intervention.

Exam trap

The trap here is that candidates confuse AWS Config's evaluation and remediation capabilities with IAM policies or Trusted Advisor, assuming those services can perform automated actions when they only provide static controls or recommendations.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) are used to define permission boundaries for AWS Organizations accounts and cannot enforce or trigger key rotation actions—they only allow or deny API calls. Option C is wrong because IAM policies are static permission documents that cannot perform automated actions like rotating keys; they only define what actions are allowed or denied. Option D is wrong because AWS Trusted Advisor provides security checks and recommendations but does not have the capability to automatically rotate keys—it only alerts you to non-rotated keys.

81
MCQmedium

A SysOps administrator is configuring a new AWS account and wants to set up a secure password policy for IAM users. The policy must require at least 12 characters, one uppercase letter, one number, and must prevent password reuse. Where should this policy be configured?

A.Apply a service control policy (SCP) that enforces password complexity.
B.In the IAM console under Account settings, set the password policy.
C.Set a password policy on the AWS account root user.
D.Create an IAM role with a password policy attached.
AnswerB

The IAM password policy is configured at the AWS account level under IAM > Account settings, and it applies uniformly to all IAM users in that account. This policy can enforce requirements like minimum length, uppercase/lowercase letters, numbers, symbols, password expiration, and reuse prevention. It is the standard mechanism for implementing password complexity rules across all IAM users, and it must be set independently for each AWS account.

Why this answer

The IAM account password policy is configured in the IAM console under Account settings, where you can enforce minimum length, character complexity, password reuse prevention, and expiration. This policy applies to all IAM users in the account and is the correct location for the stated requirements. It is a single account-level setting, not something attached to individual users or roles.

Exam trap

SOA-C02 often tests whether candidates confuse SCPs (permission guardrails) with the IAM account password policy, leading them to pick SCPs for password complexity requirements.

How to eliminate wrong answers

Option A is wrong because SCPs govern permissions for AWS Organizations accounts and do not enforce IAM password complexity rules. Option C is wrong because the root user does not have a separate password policy — the account password policy applies to IAM users, and the root user's password is managed separately without these complexity controls. Option D is wrong because IAM roles do not have passwords; roles are assumed via temporary credentials, so attaching a password policy to a role is meaningless.

82
MCQmedium

An application running on an Amazon EC2 instance needs to access an Amazon S3 bucket. The company security policy requires that credentials are not stored on the instance. What is the most secure way to grant access?

A.Create an IAM role with S3 access permissions and attach it to the EC2 instance profile.
B.Generate an access key and secret key for an IAM user, then store them in a configuration file on the instance.
C.Create an S3 bucket policy that allows access from the instance's public IP address.
D.Define the access keys as environment variables in the user data script when launching the instance.
AnswerA

Attaching an IAM role to the EC2 instance profile is the recommended pattern because the instance retrieves temporary, automatically rotating credentials from the instance metadata service (IMDSv2). These credentials are scoped by the role's trust policy and S3 permissions, so no long-lived access keys are ever written to disk, code, or configuration files. The AWS SDKs and CLI automatically assume the role, enabling secure access to S3 without manual credential management.

Why this answer

Attaching an IAM role to an EC2 instance via an instance profile allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS). These credentials are automatically rotated and never stored on the instance, satisfying the security policy requirement. The EC2 instance retrieves the credentials through the instance metadata service (IMDS), eliminating the need for long-term access keys.

Exam trap

The trap here is that candidates may think storing keys in environment variables or configuration files is acceptable because they are 'hidden' or 'temporary,' but the exam emphasizes that any form of long-term credential storage on the instance violates the principle of least privilege and the security policy.

How to eliminate wrong answers

Option B is wrong because storing an access key and secret key in a configuration file on the instance violates the security policy that credentials must not be stored on the instance, and long-term keys increase the risk of exposure. Option C is wrong because an S3 bucket policy that allows access based on the instance's public IP address is insecure; public IPs can change (e.g., after stop/start) and do not authenticate the instance, leaving the bucket open to any traffic from that IP. Option D is wrong because defining access keys as environment variables in user data still stores the keys in the instance's memory and can be retrieved from the instance, violating the no-storage policy and exposing credentials to processes or logs.

83
Multi-Selecteasy

Which TWO measures help protect an AWS account root user? (Choose two.)

Select 2 answers
A.Use the root user regularly for administrative tasks.
B.Create an access key for the root user for programmatic access.
C.Grant other IAM users full administrator access.
D.Use a strong, complex password for the root user.
E.Enable multi-factor authentication (MFA) for the root user.
AnswersD, E

A strong, complex password for the root user is a core, direct defensive control because the root account bypasses all IAM policies, so the console password is the only baseline barrier against unauthorized sign-ins. A long mix of characters, coupled with the absence of the password being reused elsewhere, materially reduces the risk of credential-stuffing and forced-entry attacks. AWS recommends a minimum of 14 characters for the root password.

Why this answer

Options D and E are correct. Using a strong, complex password and enabling MFA for the root user are essential security measures to protect the account. Option A is incorrect because using the root user regularly increases the risk of compromise; it should be used only for tasks that require root privileges.

Option B is incorrect because creating an access key for the root user exposes long-term credentials that can be misused; root user access keys should be avoided. Option C is incorrect because granting other IAM users full administrator access does not directly protect the root user; it reduces dependency on the root user but is not a security measure for the root user itself.

84
MCQhard

A SysOps administrator deploys the CloudFormation template shown in the exhibit. The stack creation fails with a security group error. What is the most likely cause?

A.The AMI ID is incorrect.
B.The security group ingress rule uses an invalid CIDR.
C.The template uses 'SecurityGroups' instead of 'SecurityGroupIds' for a VPC instance.
D.The security group ingress rule allows SSH from all IPs.
AnswerC

In CloudFormation's AWS::EC2::Instance resource, the SecurityGroups property accepts security group names and is only supported for EC2-Classic or a default VPC, but when launching an instance into a VPC subnet you must use SecurityGroupIds. Supplying SecurityGroups together with a SubnetId causes the EC2 RunInstances API to receive a group name in a context that requires a group ID, generating a parameter-combination or subnet-not-found error. Changing the template to reference the VPC security group's ID via SecurityGroupIds resolves the deployment failure.

Why this answer

When launching an EC2 instance into a VPC subnet, CloudFormation's AWS::EC2::Instance resource requires the SecurityGroupIds property (a list of security group IDs), not SecurityGroups (which is only valid for EC2-Classic). Using SecurityGroups with a VPC subnet causes the stack to fail with a security group error.

Exam trap

SOA-C02 often tests the EC2-Classic vs VPC property distinction — candidates see 'SecurityGroups' and assume it is valid because it sounds correct, missing that VPC instances require SecurityGroupIds.

How to eliminate wrong answers

Option A is wrong because an incorrect AMI ID produces an 'InvalidAMIID.NotFound' error, not a security group error. Option B is wrong because an invalid CIDR in an ingress rule would fail with an 'InvalidParameterValue' error referencing the CIDR, not a generic security group error. Option D is wrong because allowing SSH from 0.0.0.0/0 is a security best-practice violation but does not cause stack creation to fail — CloudFormation will happily create the rule.

85
MCQeasy

Developers are allowed to create IAM roles for their Lambda functions. However, the security team is concerned that developers could create roles with Administrator access, granting Lambda functions more permissions than the developers themselves have. What IAM feature prevents privilege escalation in this scenario?

A.Attach a permission boundary to each developer IAM user that limits them to creating roles with only the permissions they are allowed to grant
B.Enable IAM Access Analyzer to detect when developers create overly permissive roles
C.Require MFA for all IAM API calls so developers must re-authenticate before creating roles
D.Enable CloudTrail logging for all IAM API calls and set up a CloudWatch alarm for iam:CreateRole events
AnswerA

The permission boundary on the developer prevents them from passing permissions they do not have (iam:PassRole with a role whose boundary exceeds their own). When combined with an IAM policy that requires any role they create to have the same boundary attached, privilege escalation is prevented systematically.

Why this answer

Permission boundaries are an IAM feature that allow you to set the maximum permissions that an identity-based policy can grant to a principal. By attaching a permission boundary to each developer IAM user that restricts them to creating roles with only the permissions they are allowed to grant, you prevent the developer from creating a Lambda execution role with AdministratorAccess or any other policy that exceeds the boundary. This directly addresses the privilege escalation concern because the boundary acts as a ceiling on the permissions the developer can delegate to the role.

Exam trap

The trap here is that candidates often confuse detective controls (like Access Analyzer, CloudTrail, or alarms) with preventive controls, thinking that monitoring or alerting can stop the action, when only a preventive mechanism like a permission boundary can block the creation of an overly permissive role at the time of the API call.

How to eliminate wrong answers

Option B is wrong because IAM Access Analyzer is a post-creation analysis tool that identifies resources shared with external principals; it does not prevent a developer from creating an overly permissive role in the first place. Option C is wrong because requiring MFA for IAM API calls adds an authentication step but does not restrict the permissions that can be assigned to a role; a developer with valid MFA could still create an AdministratorAccess role. Option D is wrong because CloudTrail logging and CloudWatch alarms are detective controls that only alert after the role has been created; they do not prevent the privilege escalation from occurring.

86
MCQeasy

A company wants to centrally manage access to AWS accounts for its employees. Which AWS service should be used to create and manage users and groups across multiple accounts?

A.AWS IAM
B.AWS Directory Service
C.AWS IAM Identity Center
D.AWS Organizations
AnswerC

AWS IAM Identity Center is the AWS-native service designed specifically to centralize user and group management across multiple AWS accounts and applications. It integrates with AWS Organizations so you can assign users or groups to accounts and apply permission sets that map to IAM roles, enabling single sign-on and consistent permission enforcement. With support for built-in identity stores or external identity providers, IAM Identity Center provides the exact capability needed to centrally manage access to AWS accounts.

Why this answer

AWS IAM Identity Center (successor to AWS SSO) allows you to centrally create and manage users and groups and assign them single sign-on access to multiple AWS accounts. Option C is correct. Option A (AWS IAM) is wrong because IAM is per-account and not designed for cross-account user management.

Option B (AWS Directory Service) is wrong because it provides managed Microsoft Active Directory, not multi-account user management. Option D (AWS Organizations) is wrong because it manages accounts and policies, not users and groups.

87
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users in any member account can create access keys for themselves. What is the MOST efficient way to enforce this policy across all accounts?

A.Create an SCP that denies the iam:CreateAccessKey action and attach it to the root organizational unit.
B.Apply an IAM policy to the master account's root user that denies access key creation.
C.Enable AWS Trusted Advisor security checks and follow the recommendations.
D.Use AWS Config to detect access key creation and automatically delete the keys using a Lambda function.
AnswerA

An SCP is an organization-level policy that applies to all accounts (including the management account, though it can be excluded) when attached to the root OU. Denying iam:CreateAccessKey at the root OU is a preventive control that blocks the action organization-wide before it can be executed. This is the correct approach because it enforces the restriction in a centralized, scalable way that cannot be overridden by individual account IAM policies.

Why this answer

A service control policy (SCP) can be applied at the root or to specific OUs to deny IAM actions across all member accounts. Option A is correct because it centrally restricts the action. Option B is wrong because it only works for the master account.

Option C is wrong because it requires individual account configuration. Option D is wrong because while AWS Config and Lambda can detect and remediate access key creation, this is a reactive approach and not the most efficient preventive control. SCPs proactively deny the action before it occurs, making them more efficient for enforcing this policy across all accounts.

88
MCQeasy

A SysOps administrator needs to audit all API calls made in the AWS account, including actions performed by the root user. Which service should be enabled?

A.AWS Config
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the definitive service for auditing API activity because it records a detailed history of every public AWS API call made on the account, including the identity of the caller, the API operation, parameters, source IP, and event time. It captures management events from all regions and by default retains the last 90 days in the event history, while a trail can deliver logs to S3 for long-term storage, enabling governance, security analysis, and tracking of root user actions. It is the correct service when you need to answer 'who did what, when, and how' across the entire AWS control plane.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including those made by the root user, IAM users, roles, and AWS services. It provides a detailed audit trail of actions taken, which is essential for security and compliance auditing. Enabling CloudTrail in all regions ensures comprehensive coverage.

Exam trap

SOA-C02 often tests the difference between CloudTrail (API auditing) and AWS Config (resource configuration history); candidates may confuse the two, especially when the question mentions 'audit' and 'API calls'.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations against desired policies but does not record API calls or user actions. Option B is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option D is wrong because Amazon CloudWatch Logs is a log storage and analysis service; it does not natively capture API activity unless CloudTrail logs are specifically sent to it.

89
MCQmedium

A SysOps administrator is asked to ensure that all objects in an S3 bucket are encrypted at rest using a customer-managed KMS key. The bucket currently has default encryption set to SSE-S3. What must be done to meet the requirement?

A.Update the bucket's default encryption to SSE-KMS using the customer-managed key, and re-upload existing objects.
B.Add a bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header.
C.Apply a service control policy to enforce SSE-KMS across the organization.
D.Enable S3 Versioning and set the bucket's default encryption to SSE-KMS.
AnswerA

Default encryption is applied only when an object is first written to Amazon S3; changing the bucket's default from SSE-S3 or none to SSE-KMS with a customer-managed key does not retroactively alter objects that are already stored. To satisfy the requirement, the administrator must update the default encryption configuration and then copy each existing object back over itself (or re-upload it) using an operation that explicitly applies SSE-KMS, because the bucket's default will not touch the old objects. Only this combination ensures both current and future objects meet the SSE-KMS policy.

Why this answer

Default encryption on an S3 bucket only applies to newly uploaded objects; existing objects remain encrypted with the previous method (SSE-S3). To ensure all objects are encrypted at rest with a customer-managed KMS key, you must update the bucket's default encryption to SSE-KMS with the desired key and then re-upload (or copy) existing objects so they inherit the new encryption setting. Simply changing the default encryption does not retroactively re-encrypt objects already stored.

Exam trap

The trap here is that candidates assume changing the bucket's default encryption automatically re-encrypts all existing objects, but AWS S3 default encryption only applies to new uploads, not to objects already in the bucket.

How to eliminate wrong answers

Option B is wrong because adding a bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header only enforces encryption on new uploads but does not address existing objects already encrypted with SSE-S3, nor does it require the use of a customer-managed KMS key. Option C is wrong because a service control policy (SCP) is an AWS Organizations feature that applies to all accounts in an organization, but it cannot retroactively re-encrypt existing objects in a specific bucket; it only governs future API calls. Option D is wrong because enabling S3 Versioning does not change the encryption of existing objects; it only creates new versions of objects on subsequent writes, and setting default encryption to SSE-KMS still only applies to new uploads, leaving the original versions encrypted with SSE-S3.

90
MCQeasy

A company uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances. The security team wants to ensure that all traffic between the ALB and the instances is encrypted. Which configuration step is required?

A.Configure the ALB listener to use HTTPS with a security policy.
B.Configure the target group to use HTTPS protocol and install SSL/TLS certificates on the instances.
C.Place the instances in a private subnet and use a NAT gateway for outbound traffic.
D.Create a security group rule that allows only HTTPS traffic from the ALB to the instances.
AnswerB

The ALB-to-instance hop is encrypted only when the target group's protocol is HTTPS and the instances present valid certificates. Setting the target group to HTTPS satisfies the requirement, since the listener's own TLS termination covers only the client-to-ALB leg.

Why this answer

Configuring the target group to use the HTTPS protocol ensures that the ALB encrypts traffic to the instances using SSL/TLS. The instances must have valid certificates installed to terminate the HTTPS connection. Option A is incorrect because the ALB listener handles encryption between clients and the ALB, not between the ALB and instances.

Option C is incorrect because placing instances in a private subnet and using a NAT gateway affects outbound internet access, not encryption between the ALB and instances. Option D is incorrect because a security group rule can allow only HTTPS traffic, but it does not enforce encryption; the traffic protocol must also be HTTPS.

91
MCQhard

A SysOps administrator is investigating a security incident where an unauthorized key pair was created. The CloudTrail lookup command output is shown. The administrator wants to find the source IP address of the 'admin' user who created the key pair. Which field in the 'CloudTrailEvent' JSON should the administrator examine?

A.requestParameters
B.userIdentity
C.sourceIPAddress
D.eventTime
AnswerC

The sourceIPAddress field in an AWS CloudTrail event is the authoritative record of the IP address from which the request was made, whether over the internet or from within a VPC via a VPC endpoint. This field is the primary evidence for tracing the original network source of suspicious API calls, and it is the correct answer for the security incident in question. It may contain a public IPv4/IPv6 address or, in some scenarios, the private IP of a proxy, so it must be interpreted carefully.

Why this answer

The source IP address of the API call is recorded in the 'sourceIPAddress' field within the CloudTrail event JSON. Therefore, option C is correct. Option A (requestParameters) contains the parameters of the request, not the IP.

Option B (userIdentity) contains information about the user identity, not the IP. Option D (eventTime) is the timestamp.

92
MCQeasy

A SysOps administrator needs to ensure that data in an S3 bucket is encrypted at rest. The bucket already has server-side encryption with S3 managed keys (SSE-S3) enabled. Which additional step is required to enforce encryption for all objects?

A.Add a bucket policy that denies PutObject without encryption.
B.Enable CloudTrail to log unencrypted uploads.
C.Enable default encryption on the bucket.
D.Enable versioning on the bucket.
AnswerA

This enforces encryption at upload time by explicitly rejecting any PutObject request that does not include server-side encryption headers (e.g., x-amz-server-side-encryption: AES256 or aws:kms). This is a preventive control that blocks unencrypted writes outright, unlike default encryption which merely applies encryption if the request lacks headers but can be overridden by explicit headers. The policy should include a condition like "Null": {"s3:x-amz-server-side-encryption": "true"} to deny requests without the encryption header.

Why this answer

A bucket policy can deny PutObject requests that do not include the x-amz-server-side-encryption header, thereby enforcing encryption for all uploads. Option B is incorrect because CloudTrail logs API calls but does not enforce encryption. Option C is incorrect because enabling default encryption on the bucket only encrypts objects that are uploaded without specifying encryption, but it does not prevent unencrypted uploads; a bucket policy is needed to enforce encryption.

Option D is incorrect because versioning allows multiple versions of objects but does not enforce encryption.

93
Multi-Selecthard

A SysOps administrator is designing a solution to manage secrets (e.g., database credentials) for a multi-tier application running on EC2 instances. The solution must rotate secrets automatically and provide fine-grained access control. Which TWO services should be used together? (Choose TWO.)

Select 2 answers
A.AWS KMS
B.AWS CloudHSM
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
E.IAM roles for EC2
AnswersC, E

AWS Secrets Manager is purpose-built for securely storing and automatically rotating database credentials, API keys, and other secrets. It supports built-in rotation for Amazon RDS and Redshift, and custom rotation via AWS Lambda for other services. Secrets can be retrieved on demand through the AWS SDK or CLI, with IAM policies controlling access, and versioning ensures application rollback and staged rotation.

Why this answer

AWS Secrets Manager (C) is correct because it is the service purpose-built for storing and automatically rotating secrets such as database credentials, using built-in rotation via Lambda functions and native integration with services like RDS, Redshift, and DocumentDB. IAM roles for EC2 (E) is correct because attaching an IAM role to the EC2 instances provides temporary credentials through the instance metadata service (IMDS), enabling fine-grained, least-privilege access control via IAM policies that scope which secrets each instance can retrieve, eliminating hard-coded credentials. AWS KMS (A) is not selected because it is an encryption key management service used to encrypt data and secrets, but it does not itself store or rotate secrets.

AWS CloudHSM (B) is not selected because it provides dedicated hardware security modules for key operations and compliance use cases, not secret lifecycle management or rotation. AWS Systems Manager Parameter Store (D) is not selected because, although it can store parameters and SecureString values, it lacks native automatic secret rotation, which the scenario explicitly requires.

Exam trap

SOA-C02 often tests the misconception that Parameter Store and Secrets Manager are interchangeable, when only Secrets Manager provides native automatic rotation for RDS-style credentials.

94
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all IAM users in member accounts must use MFA. They create an SCP that denies all actions if the IAM user does not have MFA. However, the SCP does not apply to the root user. The SysOps administrator finds that some IAM users in member accounts are still able to access the console without MFA. What is the most likely reason?

A.The SCP is applied to an OU that does not contain the affected accounts.
B.The IAM user has a resource-based policy that allows access.
C.The SCP only applies to the root user, not IAM users.
D.The SCP is not inherited by child OUs.
AnswerA

Service control policies take effect only on accounts that are directly in the OU or in child OUs underneath it. If the affected accounts are in a different OU—or in the organization root with no explicit SCP attachment—the deny statement won't apply. The fix is to attach the denying SCP to the exact branch of the organization hierarchy that contains those accounts, which requires verifying the OU structure in AWS Organizations.

Why this answer

SCPs are inherited down the OU tree, but they only apply to accounts within the OU they are attached to. If the SCP is attached to an OU that does not contain the affected member accounts, those accounts are unaffected and their IAM users can still sign in without MFA.

Exam trap

The trap is assuming SCPs are global once created, when in fact they only affect accounts within the OU they are attached to — attachment scope is the most common reason an SCP appears not to work.

How to eliminate wrong answers

Option B is wrong because resource-based policies cannot override an SCP — SCPs act as a permissions boundary at the account/OU level and take precedence in the authorization evaluation. Option C is wrong because SCPs apply to all principals in the account, including IAM users and roles, not just the root user; the question's note about root is a red herring. Option D is wrong because SCPs are inherited by child OUs by default — inheritance is a core feature, not a limitation.

95
Drag & Dropmedium

Drag and drop the steps to configure an Amazon Route 53 failover routing policy into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Create health checks first, then create primary and secondary records with failover types, then test.

96
Multi-Selecthard

A company uses AWS Organizations and wants to restrict the use of specific AWS services across all member accounts. Which TWO methods can be used to enforce these restrictions? (Choose TWO.)

Select 2 answers
A.Create IAM policies in each account that deny the service actions and attach them to all IAM users and roles.
B.Use AWS Config rules to automatically disable non-compliant services.
C.Use AWS Service Catalog to block the use of disallowed services.
D.Attach a service control policy to the root organizational unit that denies the service actions.
E.Configure VPC endpoints to block traffic to the disallowed services.
AnswersA, D

IAM policies can explicitly deny AWS service actions and, when attached to every IAM user and role in an account, prevent those principals from invoking the disallowed APIs. However, this approach is operationally heavy because you must attach the policy to all existing and future principals individually, and it does not restrict the account root user unless combined with an SCP or resource-based policy. It is a valid account-level enforcement method, but it requires diligent maintenance across all accounts.

Why this answer

IAM policies in each account can deny actions for specific services, and when attached to all IAM users and roles, they effectively restrict usage across the account, though this requires consistent application. Option D is correct because SCPs attached to the root organizational unit can deny access to specified services across all member accounts in the organization. Option B is incorrect because AWS Config rules can detect non-compliance but cannot enforce restrictions or disable services.

Option C is incorrect because AWS Service Catalog is used to create and manage a catalog of approved services, not to block disallowed services. Option E is incorrect because VPC endpoints control network traffic to services, not service-level restrictions.

97
MCQhard

A company uses AWS CloudTrail to log API activity. The security team needs to be alerted when an IAM user creates a new access key. Which combination of services should the SysOps administrator use to meet this requirement?

A.CloudWatch Logs Insights query on CloudTrail logs with an alarm
B.An AWS Config rule that checks for new access keys and sends an SNS notification
C.A CloudWatch Events rule that matches the CreateAccessKey API call and sends an SNS notification
D.S3 event notifications to an SNS topic
AnswerC

Amazon EventBridge (formerly CloudWatch Events) can consume CloudTrail events as a built-in event source, so a rule with an event pattern tailored to `AWS API Call via CloudTrail` and `eventName` `CreateAccessKey` fires whenever that API is invoked. The rule can target an SNS topic as the action, delivering a near-real-time notification that includes the full event detail such as the IAM user, source IP, and user agent. This is the direct, native mechanism for alerting on specific API calls.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can match AWS API calls recorded by CloudTrail, such as CreateAccessKey, and route them to targets like SNS for alerting. The rule pattern matches the event source (iam.amazonaws.com) and event name (CreateAccessKey), then triggers an SNS notification to the security team. This is the standard serverless approach for real-time alerting on specific API activity.

Exam trap

The trap is confusing AWS Config rules with EventBridge rules; Config evaluates resource compliance, while EventBridge matches API events for real-time alerting.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is a query tool for analyzing logs on demand; it does not natively trigger alarms based on specific API calls without additional metric filters and alarms, and it is not the most direct combination. Option B is wrong because AWS Config rules evaluate resource compliance periodically or on configuration changes, but they are not designed for immediate alerting on API calls like CreateAccessKey. Option D is wrong because S3 event notifications trigger on object-level events in S3 buckets, not on CloudTrail API activity.

98
MCQmedium

A SysOps administrator notices that an Amazon CloudWatch Logs log group is growing rapidly and suspects that an EC2 instance is sending sensitive data to the logs. What is the most effective way to detect and redact sensitive data in real-time?

A.Use CloudWatch Logs Insights to query and mask sensitive data.
B.Enable S3 event notifications to trigger a Lambda function for redaction.
C.Create a CloudWatch Logs subscription filter that invokes a Lambda function for redaction.
D.Send logs to Amazon Kinesis Data Firehose and use Lambda for redaction.
AnswerC

A CloudWatch Logs subscription filter with a Lambda destination is the native near-real-time mechanism for processing incoming log events. When new log events arrive, the subscription filter immediately invokes the Lambda function, which can decode the gzip-compressed payload, redact sensitive fields, and forward the sanitized data to its final storage destination. This direct integration avoids intermediate storage or additional pipeline services, making it the most efficient and purpose-built solution for real-time log redaction.

Why this answer

CloudWatch Logs subscription filters can invoke a Lambda function in real-time as log events are ingested. This allows the Lambda function to inspect, detect, and redact sensitive data (e.g., credit card numbers or passwords) before the logs are stored in the log group, meeting the requirement for real-time detection and redaction.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with a real-time processing capability, or they over-engineer the solution by involving S3 or Kinesis when a direct subscription filter is the simplest and most effective real-time redaction method.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is a query tool for analyzing historical log data, not a real-time processing or redaction mechanism; it cannot modify or redact data in transit. Option B is wrong because S3 event notifications trigger on object-level events in an S3 bucket, but the logs are not yet in S3; this would require an additional export step and cannot provide real-time redaction at the point of ingestion. Option D is wrong because sending logs to Kinesis Data Firehose adds unnecessary latency and complexity; while Lambda can be used for redaction in that pipeline, the most direct and effective real-time method is a CloudWatch Logs subscription filter targeting Lambda, which operates at the log ingestion stage without requiring an intermediate streaming service.

99
MCQhard

A company uses AWS Organizations with SCPs to restrict member accounts. The security team wants to prevent all users in the 'Developers' OU from deleting S3 buckets, except for the root user of the management account. How should this be implemented?

A.Create an IAM policy that denies s3:DeleteBucket and attach it to all IAM users. The root user is not affected by IAM policies.
B.Attach an SCP that denies s3:DeleteBucket to the Developers OU. The management account root is not affected by SCPs.
C.Attach an SCP that denies s3:DeleteBucket except when called by root user.
D.Attach an SCP that denies s3:DeleteBucket to the Developers OU. The root user in member accounts is not affected.
AnswerB

Attaching an SCP that denies s3:DeleteBucket to the Developers OU effectively blocks all principals in every member account under that OU, including each member account's root user, because SCPs act as an upper permission boundary. The management account root is explicitly exempt from SCP restrictions, so this control does not affect the management account root. This is the correct way to implement a cross-account deletion guardrail.

Why this answer

SCPs applied to an OU restrict what member accounts can do, but they do not affect the management account. The management account root user is not constrained by SCPs, so attaching a deny s3:DeleteBucket SCP to the Developers OU prevents users in that OU from deleting buckets while leaving the management account root unaffected. This matches the requirement exactly.

Exam trap

The trap is thinking SCPs can be conditioned to exempt the root user or that member-account root users are exempt — SCPs do not apply to the management account at all, and they do apply to member account roots.

How to eliminate wrong answers

Option A is wrong because an IAM policy attached to users does not cover all principals (roles, federated users) and the root user of the management account is not affected by IAM policies, but the requirement is to exempt only the management account root — the IAM approach is incomplete and does not use the Organizations control plane. Option C is wrong because SCPs do not support 'except when called by root user' conditions in that form; SCP conditions cannot reliably identify the management account root in the way described, and SCPs do not apply to the management account anyway. Option D is wrong because the root user in member accounts IS affected by SCPs, so the statement is factually incorrect.

100
MCQeasy

A company wants to provide temporary security credentials to a mobile application so it can access an S3 bucket. Which AWS service should be used to issue these credentials?

A.Amazon Cognito
B.AWS Key Management Service (KMS)
C.AWS Security Token Service (STS)
D.AWS Identity and Access Management (IAM)
AnswerC

AWS Security Token Service (STS) is the authoritative AWS service that vends temporary security credentials, returning an access key, a secret key, a session token, and an expiration timestamp. It provides APIs such as AssumeRole, GetFederationToken, AssumeRoleWithSAML, and AssumeRoleWithWebIdentity to support cross-account access, role delegation, and identity federation. These credentials automatically expire and carry the permissions of the assumed role, which is exactly what the company needs for short-lived, limited-privilege access.

Why this answer

AWS Security Token Service (STS) is specifically designed to generate temporary security credentials for users and applications. Option A is incorrect: Amazon Cognito can issue temporary credentials via identity pools, but STS is the direct service for temporary credentials. Option B is incorrect: AWS KMS manages encryption keys, not credentials.

Option D is incorrect: IAM manages long-term user credentials, not temporary ones.

101
MCQmedium

A SysOps administrator needs to audit all IAM user activity in the AWS account for the last 90 days. Which AWS service should be used?

A.AWS Config
B.AWS Trusted Advisor
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the correct service for auditing IAM user activity because it records every AWS API call as a CloudTrail event, including who made the request (IAM user or role), when it was made, from which source IP, and what action was performed. By enabling a trail that delivers events to an S3 bucket (and optionally CloudWatch Logs), you capture a complete, tamper-evident history of all IAM user activity for security analysis and operational troubleshooting. CloudTrail also supports logging both management events, such as CreateUser or AttachUserPolicy, and data events, giving you the audit coverage necessary to answer 'who did what' in your account.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made by IAM users, including console sign-in events, CLI commands, and SDK actions, and retains these logs for up to 90 days by default in the event history. This allows the SysOps administrator to audit all IAM user activity over the last 90 days without additional configuration.

Exam trap

The trap here is that candidates confuse AWS Config's configuration tracking with CloudTrail's API activity logging, or assume GuardDuty's threat detection includes a built-in audit trail for all user actions.

How to eliminate wrong answers

Option A is wrong because AWS Config is used for evaluating resource configurations against desired policies and tracking configuration changes, not for recording API-level user activity. Option B is wrong because AWS Trusted Advisor provides best-practice recommendations for cost, performance, security, and fault tolerance, but does not log or audit IAM user actions. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not provide a direct audit trail of all IAM user activity.

102
MCQhard

A company operates a web application behind an Application Load Balancer (ALB). The SysOps administrator needs to block incoming requests from specific geographic locations (countries X and Y) and also enforce a rate limit of 100 requests per IP address per 5-minute window to mitigate DDoS attacks. The solution must be centrally configured and apply to all requests handled by the ALB. Which AWS service should be used to implement these requirements?

A.AWS WAF
B.Amazon CloudFront geo restriction
C.AWS Shield Advanced
D.Security Groups
AnswerA

AWS WAF offers both geo-match conditions to block requests from specific countries and rate-based rules to limit request rates from an IP address. It integrates directly with ALB and provides a single, centrally managed solution.

Why this answer

AWS WAF is the correct service because it provides both geographic (geo-match) blocking and rate-based rules that can be associated directly with an Application Load Balancer. Geo-match conditions allow you to block requests from specific countries (X and Y), while rate-based rules can limit requests to 100 per 5-minute window per source IP. This solution is centrally configured at the ALB level, applying to all incoming requests without requiring additional infrastructure.

Exam trap

The trap here is that candidates often confuse AWS WAF with CloudFront geo restriction or AWS Shield Advanced, not realizing that only WAF provides both geo-blocking and rate-based rules that can be directly associated with an ALB without requiring CloudFront.

How to eliminate wrong answers

Option B (Amazon CloudFront geo restriction) is wrong because CloudFront geo restriction only works when CloudFront is the front-end service, not directly with an ALB; it cannot be applied to an ALB alone and does not support rate limiting. Option C (AWS Shield Advanced) is wrong because while it provides enhanced DDoS protection and cost protection, it does not offer granular geo-blocking or configurable rate-based rules; it is a managed threat protection service, not a web application firewall. Option D (Security Groups) is wrong because security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer attributes like geographic origin or enforce rate limits based on HTTP request counts.

103
MCQmedium

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest using server-side encryption. Which combination of actions should be taken to enforce this policy?

A.Enable default encryption on each S3 bucket and create a CloudWatch alarm to notify if unencrypted objects are uploaded.
B.Use an S3 bucket policy with a Deny statement for s3:PutObject without encryption applied to all buckets via a single policy.
C.Use AWS CloudTrail to monitor PutObject calls and trigger an AWS Lambda function to delete unencrypted objects.
D.Use an S3 bucket policy on each bucket that denies s3:PutObject if the x-amz-server-side-encryption header is not present.
AnswerD

A bucket policy with a Deny for s3:PutObject when the x-amz-server-side-encryption header is absent enforces encryption at upload time by rejecting the request before any object is written. The condition evaluates the presence of the encryption header (e.g., using StringNotEquals if s3:x-amz-server-side-encryption is not AES256 or aws:kms), and this applies to every PutObject on that bucket. Because each bucket needs its own policy, the administrator must attach the policy to every bucket individually, but this fully satisfies the enforcement requirement.

Why this answer

An S3 bucket policy with a Deny statement for s3:PutObject that requires the x-amz-server-side-encryption header ensures that any PUT request without encryption headers is rejected. This enforces server-side encryption at the point of upload, preventing unencrypted objects from being stored in the bucket. Default encryption (Option A) only applies encryption to objects that are uploaded without encryption headers, but it does not prevent unencrypted uploads; a bucket policy denial is the only way to block them outright.

Exam trap

The trap here is that candidates confuse default encryption (which is applied server-side after upload) with a bucket policy that denies unencrypted uploads, thinking that default encryption alone enforces encryption, when in fact it does not prevent the upload of unencrypted objects.

How to eliminate wrong answers

Option A is wrong because enabling default encryption on each S3 bucket does not prevent unencrypted objects from being uploaded; it only applies encryption after the object is stored, and a CloudWatch alarm is reactive, not preventive. Option B is wrong because a single S3 bucket policy cannot be applied to all buckets; bucket policies are per-bucket resources, and a single policy cannot span multiple buckets. Option C is wrong because using CloudTrail and Lambda to delete unencrypted objects is a reactive, non-compliant approach that allows unencrypted data to exist temporarily, violating the 'enforce' requirement, and it introduces unnecessary complexity and potential data loss.

104
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account. Which AWS service should be used to track these changes?

A.AWS Config
B.AWS CloudTrail
C.Amazon CloudWatch
D.AWS Trusted Advisor
AnswerB

AWS CloudTrail is the correct service because it records all IAM API calls as events, including actions like PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each CloudTrail event contains the principal who made the call, the source IP, the user agent, the request parameters, and the response—creating a complete, immutable audit log. This evidence trail enables you to answer exactly who changed which IAM policy and when, satisfying the requirement to audit all policy modifications.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including all IAM policy changes such as CreatePolicy, PutUserPolicy, AttachRolePolicy, and DeletePolicy. CloudTrail logs these events with details like the user, source IP, and timestamp, providing a complete audit trail for security and compliance. AWS Config, while capable of tracking configuration changes, does not capture the API-level detail required for auditing who made the change and how.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration state) with CloudTrail (which tracks API activity), leading them to choose Config for change auditing when only CloudTrail provides the necessary who, what, and when details for IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and evaluates compliance rules, but it does not record the API calls that initiated those changes, so it cannot provide the detailed audit trail of who made the IAM policy change and when. Option C is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, not designed to track API-level changes to IAM policies; it can ingest CloudTrail logs but does not natively capture them. Option D is wrong because AWS Trusted Advisor is an advisory service that inspects your environment for best practices and cost optimization, not a logging or auditing service for tracking changes.

105
MCQmedium

A company requires that all Amazon S3 buckets in its AWS account must be encrypted using AWS KMS (SSE-KMS). The SysOps administrator needs to detect any bucket that does not have KMS encryption enabled and automatically remediate it by enabling encryption. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Trusted Advisor
AnswerA

AWS Config can continuously monitor and evaluate S3 bucket configurations. With a managed rule for server-side encryption, it can detect non-compliant buckets. Combined with automatic remediation actions, AWS Config can enable encryption on non-compliant buckets without manual intervention.

Why this answer

AWS Config is the correct service because it can continuously monitor S3 bucket configurations against a desired encryption state using managed rules like 's3-bucket-server-side-encryption-enabled' or custom Lambda rules. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation to enable SSE-KMS encryption, enforcing compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's detective and remediation capabilities with CloudTrail's logging or Trusted Advisor's advisory-only checks, assuming any 'security' service can enforce compliance, but only AWS Config provides automated remediation via rules and Systems Manager.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail is a service for auditing API calls and logging activity, not for detecting or remediating configuration drift in real time. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail events for malicious activity, not for enforcing encryption policies on S3 buckets. Option D is wrong because AWS Trusted Advisor provides best-practice recommendations and checks for cost optimization, security, and performance, but it cannot automatically remediate non-compliant resources; it only reports findings.

106
MCQmedium

A SysOps administrator needs to ensure that all traffic to an Application Load Balancer (ALB) uses encryption. How can this be enforced?

A.Configure the security group to allow only HTTPS traffic (port 443).
B.Create a listener that redirects HTTP requests (port 80) to HTTPS (port 443).
C.Use AWS WAF to block HTTP requests.
D.Configure the ALB to use a custom SSL certificate.
AnswerB

An Application Load Balancer listener rule can define a redirect action that responds to every HTTP (port 80) request with a 301 or 302 status and the corresponding HTTPS URL, preserving the path and query parameters. This is the native, supported pattern to force HTTPS because it transparently upgrades the client before the request reaches any target. The redirect action is evaluated before routing to target groups, so no compute resources are needed to enforce the policy.

Why this answer

An Application Load Balancer can be configured with a listener rule that redirects incoming HTTP (port 80) requests to HTTPS (port 443). This ensures that all traffic to the ALB is encrypted in transit, as any unencrypted HTTP request is automatically redirected to the secure HTTPS protocol. The redirect action is a native ALB feature and does not require additional services or complex configurations.

Exam trap

The trap here is that candidates often confuse security group rules with application-layer behavior, mistakenly believing that restricting the security group to port 443 alone will enforce encryption, when in fact it only controls network access and does not prevent unencrypted traffic on that port.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer and can only allow or deny traffic based on IP addresses, ports, and protocols; they cannot enforce encryption or redirect traffic. Even if the security group allows only port 443, a client could still send unencrypted HTTP traffic to that port, and the ALB would accept it if a listener exists for HTTP on port 443. Option C is wrong because AWS WAF is a web application firewall that inspects HTTP/HTTPS requests for malicious patterns, but it cannot enforce encryption or redirect HTTP to HTTPS; it operates after the listener has accepted the connection.

Option D is wrong because configuring a custom SSL certificate on the ALB enables HTTPS but does not automatically redirect HTTP traffic to HTTPS; without a redirect rule, clients can still send unencrypted HTTP requests to the ALB.

107
Matchingmedium

Match each AWS cost management tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Visualize and analyze costs

Set custom cost and usage alerts

Detailed billing data

Discount in exchange for commitment

Flexible pricing model

Why these pairings

The correct matches: AWS Cost Explorer visualizes costs, AWS Budgets sets alerts, AWS Cost and Usage Report provides detailed data, and AWS Trusted Advisor offers cost optimization recommendations. Common confusions include swapping the purposes of Cost Explorer and Budgets, or Budgets with the Cost and Usage Report.

108
Matchingmedium

Match each AWS compute service to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Virtual machines in the cloud

Serverless function execution

Container orchestration with Docker

Managed Kubernetes clusters

Serverless compute for containers

Why these pairings

Amazon EC2 gives full server control; AWS Lambda runs serverless code; Amazon ECS manages containers. Distractors swap definitions with Lambda or Elastic Beanstalk.

109
MCQeasy

Refer to the exhibit. A SysOps administrator runs the command to list running EC2 instances. What is the purpose of the '--query' parameter?

A.It filters the results on the server side.
B.It limits the API call to only running instances.
C.It filters the output to show only specified fields.
D.It saves the output to a file.
AnswerC

The --query parameter in this command takes a JMESPath expression that processes the JSON response and extracts only the fields the user wants to display, such as instance IDs and their state. It filters the output client-side after the API returns the data, thereby customizing the visible result without changing the underlying API request. This is the correct interpretation of what the command accomplishes.

Why this answer

The AWS CLI '--query' parameter uses JMESPath to filter and shape the JSON response returned by the API call, so it controls which fields appear in the output. It does not change what the API returns from the server; it only transforms the client-side presentation. This is why it is described as filtering the output to show only specified fields.

Exam trap

SOA-C02 often tests the distinction between server-side filtering ('--filters') and client-side output shaping ('--query') — candidates frequently assume '--query' reduces the API payload, when it only reshapes what the CLI prints.

How to eliminate wrong answers

Option A is wrong because '--query' is a client-side JMESPath expression evaluated by the CLI after the response is received; server-side filtering is done with parameters like '--filters' or '--instance-ids'. Option B is wrong because limiting results to running instances requires a server-side filter such as '--filters Name=instance-state-name,Values=running', not '--query'. Option D is wrong because saving output to a file is done with shell redirection or '--output' combined with redirection, not '--query'.

110
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to restrict all accounts from using specific AWS services unless explicitly allowed. Which feature should be used?

A.Service control policies (SCPs)
B.Resource-based policies
C.IAM permissions boundaries
D.AWS Config rules
AnswerA

SCPs are the correct answer because they let you centrally govern the maximum permitted actions for every principal (including the root user) across all accounts in your AWS Organizations. By attaching an SCP to an organizational unit or account, you can explicitly deny or allow services (e.g., disabling Amazon S3 or EC2) regardless of the IAM policies attached to individual users or roles. This makes SCPs the only option here that can restrict service usage at the account or organization-wide level.

Why this answer

Service control policies (SCPs) in AWS Organizations define the maximum permissions for member accounts, allowing the security team to restrict which AWS services and actions are available across all accounts unless explicitly allowed. SCPs are applied at the organization, OU, or account level and act as a permissions guardrail that even account administrators cannot override.

Exam trap

The trap is confusing SCPs with IAM permissions boundaries or AWS Config — SCPs are the only mechanism that centrally restricts service usage across all accounts in an AWS Organization, while the others operate within a single account or only detect violations.

How to eliminate wrong answers

Option B is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, KMS keys) and grant cross-account access — they do not centrally restrict service usage across an organization. Option C is wrong because IAM permissions boundaries apply to individual IAM users or roles within a single account and do not provide organization-wide service restrictions. Option D is wrong because AWS Config rules evaluate resource compliance and trigger remediation; they detect and report violations but do not prevent service usage in real time.

111
MCQhard

A company has an EC2 instance that needs to access an S3 bucket. The instance is launched in a private subnet with no internet gateway. What is the most secure way to provide access to S3 without traversing the internet?

A.Use a NAT gateway in a public subnet
B.Create an S3 VPC gateway endpoint
C.Set up an AWS Direct Connect connection
D.Attach an internet gateway to the VPC and a public IP to the instance
AnswerB

An S3 VPC gateway endpoint is a component you add to the VPC's route table that directs S3-bound traffic to the AWS network via a prefix list, completely bypassing the internet. Because it works via the AWS internal backbone, instances in private subnets can reach S3 without a NAT gateway, internet gateway, public IP, or VPN, and there is no charge for the gateway endpoint itself. The route is confined to the customer VPC and AWS's shared network, making it a private and secure method for S3 access.

Why this answer

An S3 VPC gateway endpoint allows EC2 instances in a private subnet to access S3 privately using AWS’s internal network, without requiring an internet gateway, NAT gateway, or public IP. Traffic stays within the AWS backbone, never traversing the internet, which provides the most secure and cost-effective solution for this scenario.

Exam trap

The trap here is that candidates often confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for private subnet outbound traffic, forgetting that S3 can be accessed directly via a gateway endpoint without internet routing.

How to eliminate wrong answers

Option A is wrong because a NAT gateway in a public subnet would route traffic to the internet, which violates the requirement of not traversing the internet and introduces additional cost and complexity. Option C is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not designed for VPC-to-S3 access within the same region, and it would be overkill and more expensive. Option D is wrong because attaching an internet gateway and a public IP would expose the instance to the internet, breaking the private subnet requirement and reducing security.

112
MCQmedium

Refer to the exhibit. A SysOps administrator creates this stack. Which of the following is true about the bucket?

A.The bucket has versioning enabled
B.The bucket is publicly accessible
C.The bucket does not have versioning enabled
D.The bucket allows public read access
AnswerA

The exhibit displays the S3 bucket's versioning configuration with the Status field set to 'Enabled'. This confirms that the bucket has versioning enabled, which means every object upload creates a new version rather than overwriting the existing object, preserving history and enabling recovery from accidental deletions or overwrites. Therefore, the statement is correct based on the provided configuration.

Why this answer

The exhibit shows a CloudFormation template where the S3 bucket resource includes the VersioningConfiguration property with Status set to Enabled. When this stack is deployed, AWS applies that configuration to the bucket, so versioning is active. This means every object overwrite or delete creates a new version rather than destroying the prior object.

Exam trap

SOA-C02 often tests whether candidates can read a CloudFormation snippet and infer the resulting resource state — the trap is assuming a bucket is public or unversioned by default without checking the explicit properties in the template.

How to eliminate wrong answers

Option B is wrong because nothing in the template sets a public bucket policy or ACL — versioning has no bearing on public accessibility. Option C is wrong because the template explicitly sets VersioningConfiguration Status to Enabled, which is the opposite of disabled. Option D is wrong because public read access requires a bucket policy or ACL granting s3:GetObject to a principal like *, which the template does not define.

113
MCQmedium

A company requires that all S3 buckets be tagged with a 'CostCenter' tag. A SysOps administrator needs to enforce this and prevent creation of untagged buckets. Which approach should be used?

A.Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag
B.Create an IAM policy that allows s3:CreateBucket only if the bucket has the tag, and attach it to all users
C.Enable AWS CloudTrail to log bucket creation and review logs daily
D.Use an AWS Config rule to automatically delete untagged buckets
AnswerA

An SCP applied at the organizational unit (OU) or root level can explicitly deny s3:CreateBucket when the request lacks a specific tag key (e.g., cost-center). Because SCPs act as a guardrail for all accounts under the OU, they cannot be overridden by individual account IAM policies, making them the most reliable preventive control. The SCP would use a Condition block with the StringNotEquals or StringLike operator on aws:RequestTag, ensuring that only properly tagged bucket creation requests succeed.

Why this answer

AWS Organizations SCPs can be used to deny actions that do not meet certain conditions, such as requiring specific tags. An SCP with a condition for 'aws:RequestTag' can enforce tagging at bucket creation. IAM policies can also enforce tagging for specific users, but SCPs apply to all accounts in the organization.

AWS Config rules can detect non-compliant resources but cannot prevent creation. CloudTrail is for logging, not enforcement.

114
MCQeasy

A company wants to ensure that all Amazon S3 buckets have versioning enabled to protect against accidental deletion of objects. A SysOps administrator needs to automatically detect any buckets that do not have versioning enabled and receive notifications. Which AWS service should the administrator use?

A.AWS CloudTrail
B.AWS Config
C.Amazon Inspector
D.AWS Trusted Advisor
AnswerB

AWS Config continuously records resource configuration changes and evaluates them against desired policies using managed or custom rules. The managed rule 's3-bucket-versioning-enabled' specifically checks whether an S3 bucket has versioning turned on, and AWS Config will flag the bucket as noncompliant if it is disabled. It also integrates with Amazon SNS for real-time notifications and AWS Systems Manager Automation for automatic remediation, making it the appropriate service for proactive compliance enforcement.

Why this answer

AWS Config is the correct service because it provides managed rules, such as 's3-bucket-versioning-enabled', that continuously evaluate your S3 buckets against desired configuration states. When a bucket is non-compliant (versioning disabled), AWS Config can trigger an Amazon SNS notification to alert the administrator, enabling automated detection and remediation.

Exam trap

The trap here is that candidates confuse AWS Config (continuous configuration auditing) with AWS CloudTrail (API activity logging), thinking that CloudTrail can detect non-compliant states when it only records actions that change the state.

How to eliminate wrong answers

Option A (AWS CloudTrail) is wrong because it records API activity (e.g., PutBucketVersioning calls) but does not continuously evaluate the current configuration state of resources; it cannot proactively detect buckets with versioning disabled unless an API call is made. Option C (Amazon Inspector) is wrong because it is designed for vulnerability assessment of EC2 instances and container workloads, not for auditing S3 bucket configurations. Option D (AWS Trusted Advisor) is wrong because while it can check S3 bucket versioning as part of its cost optimization and security checks, it does not provide automated, real-time notifications for configuration drift; it is a manual, periodic review tool.

115
MCQmedium

A SysOps administrator manages IAM roles for Amazon EC2 instances. The administrator needs to identify permissions that have never been used in the last 90 days to right-size the policies. Which AWS feature should be used to achieve this?

A.AWS CloudTrail Insights
B.IAM Access Analyzer unused access analysis
C.IAM policy simulator
D.AWS Config managed rules
AnswerB

IAM Access Analyzer unused access analysis examines the service last accessed data for IAM roles and users to identify which actions, services, and resources have not been used within a specified timeframe (e.g., 90 or 180 days). This feature produces findings that directly highlight unused permissions, allowing SysOps administrators to update policies and enforce least privilege. It is the only option listed that provides the historical usage data needed to detect and remove unnecessary access.

Why this answer

IAM Access Analyzer unused access analysis is the correct AWS feature because it specifically analyzes IAM roles and policies to identify permissions that have not been used within a specified time frame (e.g., 90 days). It provides a report of unused actions, allowing the administrator to right-size policies by removing unnecessary permissions. This directly addresses the requirement to identify unused permissions for EC2 instance roles.

Exam trap

The trap here is that candidates may confuse IAM Access Analyzer unused access analysis with AWS CloudTrail Insights, but CloudTrail Insights focuses on anomalous activity patterns rather than a straightforward unused permissions report for policy right-sizing.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Insights analyzes management and data events to detect unusual activity patterns, not to identify unused permissions over a specific period. Option C is wrong because the IAM policy simulator tests whether a given policy allows or denies specific actions for a user, role, or resource, but it does not analyze historical usage or identify unused permissions. Option D is wrong because AWS Config managed rules evaluate resource configurations against compliance rules, not historical permission usage.

116
MCQeasy

A company wants to allow a developer to deploy applications using AWS CloudFormation but restrict the developer from creating or modifying IAM resources. Which IAM policy should be used?

A.Allow iam:*
B.Deny cloudformation:*
C.Allow cloudformation:* and deny iam:*
D.Allow cloudformation:* only
AnswerC

This combination correctly grants the developer the full CloudFormation API to create, update, and delete stacks needed for application deployment, while an explicit deny on iam:* overrides any other policy that might inadvertently allow IAM actions. Because an explicit deny always takes precedence over an allow, this ensures the developer cannot alter users, roles, or policies, even if they have attached policies from other sources. This strikes the right balance between enabling deployment workflows and enforcing least privilege.

Why this answer

The developer needs CloudFormation permissions to deploy stacks, but must be blocked from creating or modifying IAM roles, users, or policies. An explicit Deny on iam:* overrides any Allow, so combining Allow cloudformation:* with Deny iam:* enforces least privilege while still permitting stack operations. This is the standard pattern for preventing privilege escalation via CloudFormation, since stacks can otherwise create IAM roles with broad permissions.

Exam trap

SOA-C02 often tests the misconception that allowing cloudformation:* is safe — candidates forget that CloudFormation can create IAM resources, so an explicit Deny on iam:* is required to truly restrict IAM changes.

How to eliminate wrong answers

Option A is wrong because Allow iam:* grants the developer full IAM control, which is exactly what the requirement forbids and enables privilege escalation. Option B is wrong because Deny cloudformation:* blocks the very deployment capability the developer needs, defeating the purpose. Option D is wrong because Allow cloudformation:* alone still permits CloudFormation to create IAM resources (e.g., via AWS::IAM::Role in a template), so the restriction is not enforced.

117
Multi-Selecteasy

A SysOps administrator needs to ensure that an Amazon S3 bucket is not publicly accessible. Which THREE actions should be taken to prevent public access?

Select 3 answers
A.Enable versioning on the bucket.
B.Delete the bucket policy if it exists.
C.Configure the bucket to block new public ACLs using S3 Object Ownership.
D.Review and remove any public ACLs on the bucket and objects.
E.Use the S3 Block Public Access feature at the bucket level.
AnswersC, D, E

Setting S3 Object Ownership to Bucket Owner Enforced disables Access Control Lists for the bucket, which prevents new ACLs—including those that would grant public access—from being created. With ACLs disabled, S3 ignores any ACL-based permissions, and all access is controlled exclusively by bucket policies and IAM policies. This is a preventive, proactive measure that stops future public ACL misconfigurations at the source.

Why this answer

Enabling S3 Object Ownership allows you to disable ACLs on the bucket, which prevents new public ACLs from being applied. This is a key step in ensuring that no objects can be made publicly accessible via ACLs, as ACLs are an older access control mechanism that can grant public read/write access.

Exam trap

The trap here is that candidates might think deleting the bucket policy (option B) is sufficient to prevent public access, but they overlook that public ACLs on objects can still grant public access, and that S3 Block Public Access provides a more comprehensive and enforceable control.

118
Multi-Selectmedium

Which TWO IAM policy conditions can be used to enforce multi-factor authentication (MFA) for API calls? (Choose two.)

Select 2 answers
A.aws:PrincipalType
B.aws:MultiFactorAuthPresent
C.aws:MultiFactorAuthAge
D.aws:TokenIssueTime
E.aws:SourceIp
AnswersB, C

aws:MultiFactorAuthPresent is a boolean condition key that returns true if the principal authenticated with multi-factor authentication, and false otherwise. It can be used with the Bool condition operator to require that MFA was used, for example, "Bool": {"aws:MultiFactorAuthPresent": "true"}. This is a straightforward way to enforce MFA but it only checks the presence, not the age, of the MFA authentication. One caveat is that this key is only meaningful for temporary credentials, so you must ensure callers use temporary sessions (e.g., via GetSessionToken) when applying this restriction.

Why this answer

Option B, aws:MultiFactorAuthPresent, is correct because this boolean condition key evaluates to true when the request is made with temporary credentials that were obtained through MFA, allowing a policy to explicitly deny or allow API calls based on whether MFA was used. Option C, aws:MultiFactorAuthAge, is correct because it checks the elapsed time (in seconds) since the MFA-authenticated session was established, enabling policies to require MFA to have occurred within a maximum age for API calls. Together these two conditions are the standard AWS mechanisms for enforcing MFA on API requests.

Option A, aws:PrincipalType, only distinguishes between account, user, role, or federated principal types and does not indicate MFA usage. Option D, aws:TokenIssueTime, reflects when temporary credentials were issued but does not by itself prove MFA was performed. Option E, aws:SourceIp, restricts requests by source IP address and is unrelated to MFA enforcement.

Exam trap

The trap is assuming that any condition key containing 'Auth' or 'Token' enforces MFA; only aws:MultiFactorAuthPresent and aws:MultiFactorAuthAge are directly tied to MFA status.

119
Multi-Selectmedium

Match each AWS service with its primary security compliance function. (Drag each service to its correct function.) (Choose 4.)

Select 4 answers
A.AWS CloudTrail -> Detect unauthorized API calls
B.AWS Config -> Monitor resource configuration changes
C.Amazon GuardDuty -> Identify malicious activity
D.Amazon Macie -> Discover sensitive data in S3
AnswersA, B, C, D

AWS CloudTrail is the compliance service that records every API action made in an AWS account, capturing the identity, time, source IP, and request parameters for each call. This complete audit trail enables security teams to detect unauthorized or anomalous API activity, such as a user attempting to access resources without permission or a compromised credential generating unusual calls. It is the first place to investigate security incidents and prove compliance for regulatory audits, making it correctly matched to 'Detect unauthorized API calls'.

Why this answer

AWS CloudTrail is the service that records API activity in your AWS account, including both management and data events. By enabling CloudTrail, you can detect unauthorized API calls by analyzing the recorded events for actions that were not initiated by authorized users or services, such as an IAM user making a call from an unexpected IP address or using an unknown user agent.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail with AWS Config, thinking both are for monitoring configuration changes, but CloudTrail focuses on API activity logging while Config tracks resource configuration state changes.

How to eliminate wrong answers

Option A is correct because AWS CloudTrail specifically logs API calls and is used to detect unauthorized activity. Option B is correct because AWS Config continuously monitors and records changes to AWS resource configurations, enabling compliance auditing. Option C is correct because Amazon GuardDuty uses machine learning and threat intelligence to identify malicious activity such as unusual API calls or compromised instances.

Option D is correct because Amazon Macie uses machine learning and pattern matching to discover and protect sensitive data, such as personally identifiable information (PII), stored in Amazon S3 buckets.

120
MCQeasy

A company requires that all access to the AWS Management Console be protected by multi-factor authentication (MFA). The SysOps administrator has enabled an IAM policy that denies all actions if the user does not authenticate with MFA. However, some users report they cannot list their own MFA devices. What is the MOST likely cause?

A.The policy denies the iam:ListMFADevices action without an MFA-authenticated session
B.The policy is applied to the root user only
C.Users are not using MFA-enabled access keys
D.The policy is not applied in the us-east-1 region
AnswerA

The Deny clause for iam:ListMFADevices when the session lacks an MFA-authenticated condition blocks the AWS Management Console from displaying a user's existing MFA devices and prevents the self-service MFA enrollment flow from working. Because iam:ListMFADevices is one of the first API calls the console makes when a user attempts to manage or set up MFA, this Deny effectively locks out any user who has not yet enrolled MFA, making it impossible to satisfy the MFA requirement. A correctly designed MFA enforcement policy must explicitly allow iam:ListMFADevices (along with iam:CreateVirtualMFADevice and iam:EnableMFADevice) without requiring MFA, allowing users to bootstrap their first device.

Why this answer

The IAM policy that denies all actions unless the user is authenticated with MFA will also block the iam:ListMFADevices action because that API call is made without an MFA-authenticated session. When a user tries to list their own MFA devices, they have not yet passed the MFA challenge, so the session is not MFA-authenticated, and the deny policy applies. This creates a catch-22: the user cannot list their devices to manage MFA because listing requires MFA, but they need to list devices to set up MFA.

Exam trap

The trap here is that candidates assume the deny policy only applies to sensitive actions like modifying resources, but they overlook that even benign read actions like listing MFA devices are blocked because the policy uses a blanket Deny for all actions when MFA is not present, creating a circular dependency.

How to eliminate wrong answers

Option B is wrong because the root user is not the only user affected; the policy is applied to all IAM users via a deny-all policy, and the issue is about IAM users, not the root user. Option C is wrong because access keys are not used for console access; the issue is about the AWS Management Console, which uses a session, not access keys, and MFA enforcement for console access is separate from access key MFA. Option D is wrong because IAM policies are global and not region-specific; they apply across all regions, including us-east-1, and there is no regional restriction for IAM actions.

121
MCQhard

A company has an S3 bucket that stores sensitive customer data. The security team requires that all objects in the bucket be encrypted at rest using AWS KMS. An administrator notices that some objects are not encrypted. What is the MOST efficient way to enforce encryption for future uploads?

A.Use an SCP to require KMS encryption for all S3 actions.
B.Use AWS Config to detect unencrypted objects and automatically encrypt them.
C.Add a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms.
D.Enable S3 default encryption on the bucket with KMS.
AnswerC

An S3 bucket policy can deny s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms, using a condition block with StringNotEqualsIfExists (or an equivalent combination of conditions). Because the bucket policy is evaluated synchronously before the write is committed, any upload that lacks the header or specifies a different encryption type is immediately rejected with an Access Denied error. This makes it a true preventive control: it enforces server-side encryption with KMS on every PUT, regardless of what IAM permissions the caller holds. This is the correct solution when sensitive data must never be stored unencrypted or with non-KMS encryption.

Why this answer

Adding a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms is the most efficient way to enforce encryption for future uploads. This policy prevents any upload without proper encryption. Option A is incorrect because SCPs (Service Control Policies) limit IAM permissions but do not directly enforce encryption on S3 objects.

Option B is incorrect because AWS Config can detect unencrypted objects but does not automatically encrypt them; it is a reactive measure. Option D is incorrect because S3 default encryption can be overridden by the client specifying a different encryption header in the upload request.

122
MCQeasy

A company's security policy requires that all IAM user passwords must be at least 12 characters long. The SysOps administrator needs to enforce this requirement across the AWS account. Which action should the administrator take?

A.Create an AWS Config rule to check password length and auto-remediate.
B.Update the IAM account password policy to require a minimum length of 12 characters.
C.Enable AWS CloudTrail to monitor for password changes and alert the administrator.
D.Attach a service control policy (SCP) that denies IAM user creation if the password is less than 12 characters.
AnswerB

The IAM account password policy is the native, preventative control that enforces password requirements at the account level for all IAM users. When you set a minimum length of 12 characters, IAM rejects any password creation or change that does not meet this threshold, ensuring compliance before the password is ever stored. This is the intended mechanism that directly satisfies the security policy requirement.

Why this answer

The IAM account password policy is the native AWS mechanism for enforcing password requirements across all IAM users in an account. By updating this policy to require a minimum length of 12 characters, the administrator ensures that any new or changed password must comply, and existing passwords are not affected until the next change. This is a direct, account-wide setting that requires no additional services or custom logic.

Exam trap

The trap here is that candidates confuse AWS Config (which can detect but not enforce password length at creation time) with the IAM password policy (which is the correct, built-in enforcement mechanism), or they mistakenly think SCPs can inspect password content when they only control API actions at a high level.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect noncompliant passwords but cannot directly enforce password length at the point of creation or change; auto-remediation would require a custom Lambda function to modify the password policy, which is unnecessary when the native IAM password policy already exists. Option C is wrong because CloudTrail logs API calls but does not enforce password requirements; it only provides auditing after the fact, which does not prevent users from setting short passwords. Option D is wrong because service control policies (SCPs) apply to AWS Organizations and can restrict IAM user creation actions, but they cannot evaluate or enforce password length at the time of password creation or change; SCPs operate at the API level and lack the granularity to inspect password content.

123
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team requires that all logs be encrypted at rest and stored in an S3 bucket that blocks public access. The SysOps administrator configures the bucket with default encryption (SSE-S3) and a bucket policy that denies all actions unless the request includes the x-amz-server-side-encryption header with value AES256. However, CloudTrail delivery fails. What is the MOST likely cause?

A.The bucket policy requires the x-amz-server-side-encryption header, but CloudTrail does not include this header
B.CloudTrail does not support SSE-S3 encryption
C.The bucket policy does not grant CloudTrail the s3:PutObject permission
D.The bucket has default encryption enabled, which conflicts with CloudTrail's encryption
AnswerA

CloudTrail delivers log files to S3 with SSE-S3 encryption applied automatically, but its PutObject requests do not include an x-amz-server-side-encryption header. The bucket policy in this scenario uses a condition that requires that exact header on all writes (e.g., s3:x-amz-server-side-encryption equals AES256). Because CloudTrail omits the header, the condition evaluates to false and the bucket policy denies the request, so log delivery fails even though the object would have been encrypted server-side.

Why this answer

CloudTrail does not include the x-amz-server-side-encryption header when delivering log files to S3. The bucket policy requires this header for all PutObject requests, so CloudTrail's PUT requests are denied, causing delivery to fail. SSE-S3 encryption is applied automatically by S3 when default encryption is enabled, but the policy condition overrides that by requiring the header explicitly.

Exam trap

The trap here is that candidates assume default encryption automatically satisfies encryption requirements, but bucket policy conditions are evaluated before S3 applies default encryption, so the missing header still causes a denial.

How to eliminate wrong answers

Option B is wrong because CloudTrail fully supports SSE-S3 encryption; it can deliver logs to buckets with default SSE-S3 encryption as long as the bucket policy does not block it. Option C is wrong because the bucket policy does not explicitly deny s3:PutObject permission; it denies actions unless the required header is present, which is a condition-based denial, not a missing permission. Option D is wrong because default encryption does not conflict with CloudTrail's encryption; CloudTrail does not set its own encryption headers, so S3 applies default encryption automatically, but the policy condition still blocks the request due to the missing header.

124
MCQmedium

A company uses AWS Organizations to manage multiple AWS accounts. The security team requires that all Amazon S3 buckets in every account be encrypted at rest using AWS KMS customer managed keys. The SysOps administrator needs to enforce this requirement centrally without requiring changes in each account individually. Which approach should the administrator use?

A.Create an IAM policy in each account that denies creation of unencrypted S3 buckets
B.Configure an S3 bucket policy on each bucket to require encryption
C.Create a service control policy (SCP) in the management account that denies creation of S3 buckets without KMS encryption
D.Enable AWS Config rules in each account to detect and remediate non-compliant buckets
AnswerC

An SCP in the management account is the correct preventive control because AWS Organizations applies SCPs to all member accounts, OUs, and their principals, including the root user. The SCP can deny s3:CreateBucket unless the request includes the condition key s3:x-amz-server-side-encryption-aws-kms, forcing all new buckets to use SSE-KMS. Because SCPs are evaluated before the API call is allowed, they stop the bucket from being created at all, giving central management of encryption policy across the entire organization.

Why this answer

A service control policy (SCP) applied at the AWS Organizations management account can centrally deny the creation of S3 buckets that do not have AWS KMS encryption enabled, affecting all member accounts without requiring individual account changes. SCPs act as a permission guardrail that restricts what actions accounts can perform, even for account administrators, making them ideal for enforcing organization-wide security policies like mandatory KMS encryption on S3 bucket creation.

Exam trap

The trap here is that candidates often confuse detective controls like AWS Config rules (which alert or remediate after the fact) with preventive controls like SCPs (which block the action at the API level), leading them to choose a reactive solution instead of the correct proactive, centrally enforced SCP.

How to eliminate wrong answers

Option A is wrong because IAM policies are account-specific and must be applied in each account individually, failing the requirement for a central, no-change-per-account approach; additionally, IAM policies cannot enforce encryption settings on S3 bucket creation because the encryption requirement is a resource-level condition, not an identity-based permission. Option B is wrong because S3 bucket policies are configured per bucket and require manual changes on each existing and new bucket, which does not meet the central enforcement requirement and does not prevent creation of unencrypted buckets. Option D is wrong because AWS Config rules operate within each account and require individual setup and remediation actions per account, which violates the central enforcement without per-account changes; Config rules are detective and reactive, not preventive at the point of bucket creation.

125
MCQmedium

A company wants to encrypt data at rest in an Amazon RDS for MySQL DB instance. Which solution meets this requirement with minimal administrative overhead?

A.Create a new encrypted DB instance and migrate the data.
B.Use application-level encryption to encrypt data before storing it in the DB.
C.Enable encryption on the existing DB instance by modifying the DB instance.
D.Store the data in an S3 bucket with encryption enabled and use RDS to access it.
AnswerA

RDS encryption at rest is a one-time immutable setting that must be enabled during DB instance creation. To encrypt an existing unencrypted database, you must create a new encrypted DB instance—either by restoring from a snapshot of the original or by exporting/importing data—and then migrate traffic, since there is no in-place conversion. The new instance will use an AWS KMS customer master key to encrypt the storage, automated backups, snapshots, and read replicas. This approach is the only supported path to satisfy the encryption requirement without losing data.

Why this answer

To encrypt data at rest in Amazon RDS for MySQL, encryption must be enabled at launch time; it cannot be added later. Therefore, the correct approach is to create a new encrypted DB instance and migrate the existing data (Option A). Option B (application-level encryption) adds administrative overhead and is not native to RDS.

Option C is incorrect because encryption cannot be enabled on an existing instance; you must create a new one. Option D is incorrect because RDS does not use S3 for its primary storage; it uses Amazon EBS volumes.

126
MCQeasy

A SysOps administrator needs to generate a report of all IAM users and their last activity. Which AWS service can provide this information?

A.AWS Config
B.IAM Credential Report
C.AWS Trusted Advisor
D.AWS CloudTrail
AnswerB

The IAM Credential Report is a downloadable CSV that lists every IAM user in the account with detailed fields including password last used, password last changed, access key IDs, key last used, and key rotation dates. This report is generated on demand or on a schedule using the AWS API, CLI, or console and directly satisfies the requirement to report on IAM users. It is the correct answer because it is purpose-built for summarizing user credential activity.

Why this answer

IAM Credential Report provides a consolidated report of all IAM users and their last activity, including password last used and access key last rotated. Option A is incorrect because AWS Config tracks resource configuration changes, not user activity. Option C is incorrect because AWS Trusted Advisor provides cost optimization and security recommendations, not detailed user activity reports.

Option D is incorrect because AWS CloudTrail logs API calls but does not generate a summarized report of user credentials.

127
MCQmedium

A company stores sensitive data in an Amazon S3 bucket. A security audit reveals that some objects were uploaded without server-side encryption. The SysOps administrator must ensure that all future PUT requests to the bucket are denied unless they include the x-amz-server-side-encryption header with the value AES256. Which action should the administrator take?

A.Configure default encryption on the bucket using SSE-S3 and enable the bucket key feature.
B.Attach an IAM policy to all users that allows s3:PutObject only when the s3:x-amz-server-side-encryption condition key equals AES256.
C.Enable S3 Block Public Access on the bucket and require encryption in the bucket policy.
D.Create an S3 bucket policy that denies s3:PutObject when the s3:x-amz-server-side-encryption condition key is not present or does not equal AES256.
AnswerD

An S3 bucket policy can use the s3:x-amz-server-side-encryption condition key to require that PUT requests include the x-amz-server-side-encryption header with a specific value. By denying s3:PutObject when the condition is not met, the policy blocks any upload that lacks the required encryption header. This directly enforces the requirement at the bucket level for all principals.

Why this answer

A bucket policy with a Deny effect on s3:PutObject when the s3:x-amz-server-side-encryption condition is absent or not AES256 enforces the requirement for all requests to the bucket. This is the most direct and centralized method, as it applies to any principal attempting to upload without the required header, regardless of their IAM permissions.

Exam trap

The trap here is thinking that enabling default encryption prevents unencrypted uploads; default encryption only encrypts objects after they are uploaded and does not reject requests missing the encryption header.

128
MCQeasy

A company wants to securely store database credentials used by an application running on Amazon EC2. Which AWS service should be used to rotate and manage access to these secrets?

A.AWS Identity and Access Management (IAM)
B.AWS Key Management Service (KMS)
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
AnswerC

AWS Secrets Manager is a purpose-built service for storing and managing secrets, including database credentials, with native support for automatic rotation. It uses AWS Lambda functions to rotate credentials for supported services such as Amazon RDS, Redshift, and DocumentDB, without requiring custom code. Secrets Manager also integrates with IAM for fine-grained access control and with KMS for encryption of the secret payload at rest. This makes it the correct choice because it directly satisfies both requirements: secure storage and automated rotation.

Why this answer

AWS Secrets Manager is designed specifically for storing, rotating, and managing access to secrets such as database credentials. It provides built-in rotation for supported databases (e.g., Amazon RDS, Redshift) and integrates with IAM for fine-grained access control. This makes it the ideal service for securely managing database credentials used by an application on EC2.

Exam trap

The trap is selecting Parameter Store because it can store secrets, but candidates must remember that Secrets Manager provides automatic rotation and is purpose-built for secret management, which is a key requirement in the question.

How to eliminate wrong answers

Option A is wrong because IAM is for managing access to AWS resources, not for storing secrets; it does not provide secret rotation or storage. Option B is wrong because KMS is for creating and managing encryption keys, not for storing secrets; it can encrypt secrets but does not manage them. Option D is wrong because Systems Manager Parameter Store can store secrets (as SecureString), but it does not provide automatic rotation or the same level of secret management features as Secrets Manager.

129
MCQeasy

A company wants to provide temporary credentials to an application running on an on-premises server so it can access AWS resources. The credentials must be rotated automatically. Which IAM feature should be used?

A.Use an EC2 instance profile and attach it to the on-premises server.
B.Configure a SAML 2.0 identity provider and federate the application.
C.Create an IAM user with programmatic access and share the access key.
D.Use IAM Roles Anywhere with a certificate authority to issue temporary credentials.
AnswerD

IAM Roles Anywhere enables on-premises applications to safely obtain temporary AWS credentials by presenting an X.509 certificate issued by a trusted certificate authority (CA). The service uses the certificate's subject and issuer information to match the workload to an IAM role, then calls AWS STS to return temporary credentials that automatically expire after a configurable duration. This approach eliminates the need for long-term access keys and is the recommended pattern for non-AWS servers or hybrid workloads. It is the only option listed that directly satisfies the company's need for temporary credentials for an on-premises application.

Why this answer

IAM Roles Anywhere allows workloads running outside of AWS, such as on-premises servers, to assume IAM roles and obtain temporary credentials using X.509 certificates. The credentials are automatically rotated by the service. Option A is wrong because an EC2 instance profile can only be used for EC2 instances, not on-premises servers.

Option B is wrong: SAML 2.0 federation is typically used for federating user identities (e.g., SSO), not for application or machine identities. Option C is wrong because IAM users with programmatic access have long-term access keys that do not rotate automatically.

130
Multi-Selecthard

A company is using AWS Organizations and wants to delegate administration of a specific member account to a user in the management account. Which TWO steps are required?

Select 2 answers
A.Create an IAM user in the member account with the same name as the management account user.
B.Grant the user in the management account permissions to assume the role in the member account.
C.Enable AWS Single Sign-On (SSO) for the member account.
D.Create a service control policy (SCP) that allows the member account to be administered.
E.Create an IAM role in the member account with a trust policy that allows the management account to assume it.
AnswersB, E

To delegate access, an IAM policy must be attached to the management account user that explicitly allows the sts:AssumeRole action against the member account role's Amazon Resource Name (ARN). When the user assumes the role, AWS STS returns temporary security credentials that are automatically scoped to the role's permissions policy. This permission is the identity-based side of the trust relationship, and it is necessary because a trust policy alone cannot grant the user the right to call the role.

Why this answer

To delegate administration of a member account to a user in the management account, you must create an IAM role in the member account with a trust policy that allows the management account (or a specific user/role in it) to assume that role. Then, the user in the management account must be granted permissions (e.g., via an IAM policy) to call sts:AssumeRole on that role. This cross-account access pattern is the standard AWS mechanism for delegating administrative access without sharing long-term credentials.

Exam trap

The trap here is that candidates often confuse service control policies (SCPs) with IAM policies, thinking SCPs can grant permissions to delegate administration, when in fact SCPs only filter permissions and cannot grant access; the correct mechanism is always an IAM role with a trust policy.

131
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive user data in an S3 bucket. The security team requires that traffic between the ALB and the EC2 instances be encrypted, and that the EC2 instances only accept traffic from the ALB. Currently, the ALB terminates HTTPS and forwards HTTP to the instances. The SysOps administrator needs to implement the required security controls. Which solution should the administrator implement?

A.Use an AWS Global Accelerator to route traffic to the instances and enable encryption.
B.Create a network ACL that allows inbound HTTPS traffic from the ALB subnet and outbound HTTPS responses. Use AWS Certificate Manager to install a certificate on the instances.
C.Enable S3 VPC endpoint and configure the ALB to forward traffic to the instance via the endpoint.
D.Configure the target group to use HTTPS protocol, install a TLS certificate on the EC2 instances, and update the security group on the instances to allow inbound traffic only from the ALB's security group.
AnswerD

Setting the target group protocol to HTTPS forces the ALB to use TLS when forwarding requests to the instances, which requires each instance to present a valid TLS certificate for the domain, typically installed on the web server. Updating the instances' security group to allow inbound traffic only from the ALB's security group (as a source reference, not a CIDR block) ensures that only the ALB can reach the instances on the HTTPS port, providing both encryption and access control. This configuration also avoids relying on static IP addresses, as security group references automatically accommodate ALB scaling.

Why this answer

Configuring the target group to use HTTPS protocol ensures encryption between the ALB and EC2 instances. Installing a TLS certificate on the instances enables the ALB to establish a secure connection. Restricting the instances' security group to allow inbound traffic only from the ALB's security group ensures that only the ALB can reach the instances, meeting the requirement.

Exam trap

The trap is focusing on encryption alone and forgetting the access restriction; candidates might choose an option that encrypts traffic but does not limit instance access to the ALB, or vice versa.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves performance and availability but does not encrypt traffic between ALB and instances, nor does it restrict instance access to the ALB. Option B is wrong because network ACLs are stateless and subnet-level; they cannot enforce that traffic comes only from the ALB, and installing a certificate on instances without configuring the target group for HTTPS does not encrypt ALB-to-instance traffic. Option C is wrong because an S3 VPC endpoint is for private access to S3, not for routing ALB traffic to instances, and it does not provide encryption between ALB and instances.

132
Multi-Selecthard

A SysOps administrator needs to ensure that an Amazon RDS for MySQL database is compliant with PCI DSS requirements. Which THREE configurations should be implemented?

Select 3 answers
A.Enable Multi-AZ deployment for high availability.
B.Require SSL/TLS connections to the database.
C.Configure automated backups with a retention period of 30 days.
D.Enable RDS audit logging to capture database activities.
E.Enable encryption at rest using AWS KMS.
AnswersB, D, E

Requiring SSL/TLS for all client connections to the RDS instance encrypts data during transmission, directly fulfilling PCI DSS Requirement 4.2.1, which mandates protecting cardholder data over open networks. By enforcing SSL/TLS at the database parameter group level, you prevent eavesdropping or man-in-the-middle attacks on queries and result sets. This is a foundational security control for any database that stores cardholder data.

Why this answer

Option B is correct because PCI DSS requires strong cryptography for data in transit, and enforcing SSL/TLS on RDS for MySQL (via the require_secure_transport parameter or rds.force_ssl) ensures all client connections are encrypted. Option D is correct because PCI DSS mandates audit trails and monitoring of access to cardholder data; RDS audit logging (e.g., MySQL audit or general/slow query logs exported to CloudWatch Logs) captures database activity for review and forensics. Option E is correct because PCI DSS requires protection of stored cardholder data, and enabling encryption at rest with AWS KMS encrypts the underlying storage, snapshots, and read replicas.

Option A is not a PCI DSS requirement—Multi-AZ provides high availability, not compliance controls. Option C is not required by PCI DSS; while backups support availability and retention, the specific 30-day automated backup retention is not a PCI DSS mandate.

Exam trap

The trap here is that candidates often confuse Multi-AZ deployment (high availability) with a security or compliance control, but PCI DSS does not require high availability; it requires encryption, logging, and access controls.

133
MCQhard

A company manages multiple AWS accounts under AWS Organizations. The security team requires that all Amazon S3 buckets in the organization must be encrypted using AWS KMS (SSE-KMS). The SysOps administrator needs to automatically detect any bucket that is not compliant and remediate it by enabling SSE-KMS. Which AWS feature or service should be used to implement this automated compliance enforcement?

A.AWS Config with the s3-bucket-server-side-encryption-enabled managed rule and automatic remediation using an AWS Systems Manager Automation document.
B.AWS CloudTrail to log bucket creation events and trigger an AWS Lambda function that applies SSE-KMS.
C.Amazon Inspector to scan S3 buckets for encryption compliance and automatically apply SSE-KMS.
D.AWS Trusted Advisor to check S3 bucket encryption and send notifications but not auto-remediate.
AnswerA

The managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates every S3 bucket in an AWS Region against the requirement that default encryption is enabled. When a bucket is noncompliant, automatic remediation triggers an AWS Systems Manager Automation document, typically `AWS-EnableS3BucketEncryption`, to directly apply SSE-KMS to that bucket. Because Config re-evaluates the rule periodically and whenever bucket configuration changes, this approach corrects existing noncompliant buckets on deployment and continuously handles any future drift without manual intervention.

Why this answer

AWS Config's `s3-bucket-server-side-encryption-enabled` managed rule can evaluate S3 buckets for encryption compliance. When a non-compliant bucket is detected, AWS Config can trigger automatic remediation via an AWS Systems Manager Automation document that applies SSE-KMS encryption to the bucket. This provides a fully automated, policy-driven enforcement mechanism without manual intervention.

Exam trap

The trap here is that candidates may confuse AWS Config's evaluation and remediation capabilities with CloudTrail's logging or Trusted Advisor's advisory-only checks, failing to recognize that only AWS Config provides native automated remediation through Systems Manager Automation documents.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail logs API calls but does not evaluate compliance or trigger remediation directly; while you could build a custom solution using Lambda, it is not a native automated compliance enforcement feature. Option C is wrong because Amazon Inspector is designed for vulnerability management and network assessments of EC2 instances and containers, not for S3 bucket encryption compliance. Option D is wrong because AWS Trusted Advisor can check encryption settings and send notifications, but it cannot automatically remediate non-compliant resources.

134
Multi-Selecthard

A company uses AWS KMS to encrypt EBS volumes. Which TWO statements about using KMS with EBS are correct? (Choose two.)

Select 2 answers
A.You can import key material for EBS encryption
B.AWS managed KMS keys are automatically rotated each year
C.EBS can use either customer managed or AWS managed KMS keys
D.EBS supports asymmetric KMS keys
E.You must specify a KMS key when creating a snapshot
AnswersB, C

AWS managed keys are rotated annually.

Why this answer

Option B is correct because AWS managed KMS keys (aws/ebs) are automatically rotated every year (approximately 365 days) with no manual action required. Option C is correct because EBS encryption can use either an AWS managed key (aws/ebs) or a customer managed KMS key that you create and control. Option A is incorrect because EBS encryption requires a symmetric KMS key, and imported key material is not supported for EBS volume encryption.

Option D is incorrect because EBS encryption requires symmetric KMS keys; asymmetric KMS keys are not supported for EBS volume encryption. Option E is incorrect because when you create a snapshot, the encryption key is inherited from the source volume (or from the default EBS KMS key if the volume is unencrypted), so you are not required to specify a KMS key at snapshot creation time.

Exam trap

The trap here is that candidates often assume you must specify a KMS key when creating a snapshot, but in reality, the snapshot inherits the encryption from the source volume, and you only need to specify a different key during a copy operation.

135
MCQeasy

A company's security policy requires that all IAM users must change their passwords every 90 days. The SysOps administrator needs to enforce this requirement. Which IAM setting should the administrator configure?

A.IAM password policy
B.IAM user permissions boundary
C.IAM role trust policy
D.IAM group policy
AnswerA

The IAM account password policy is the account-level security setting that governs the lifecycle of IAM user passwords. It can enforce a maximum password age, such as 90 days, which forces users to rotate their passwords at a set interval. This is the only mechanism in IAM that controls password expiration for all users in the account, directly satisfying the security policy's rotation requirement.

Why this answer

The IAM password policy is the correct setting because it allows the SysOps administrator to define password rotation requirements, such as a mandatory password change every 90 days. This policy is applied at the account level and enforces the security requirement for all IAM users, ensuring compliance without needing to modify individual user permissions.

Exam trap

The trap here is that candidates may confuse IAM password policy with IAM user permissions or group policies, thinking that password rotation can be enforced through permission boundaries or role trust policies, which are unrelated to authentication settings.

How to eliminate wrong answers

Option B is wrong because an IAM user permissions boundary defines the maximum permissions a user can have, but it does not control password rotation or expiration settings. Option C is wrong because an IAM role trust policy defines which entities (users or services) can assume the role, not password policies for IAM users. Option D is wrong because an IAM group policy grants permissions to a group of users but does not enforce password expiration or rotation requirements.

136
MCQmedium

A company has an AWS account that contains multiple Amazon S3 buckets with sensitive data. A SysOps administrator needs to ensure that all S3 buckets in the account have versioning enabled to protect against accidental deletions. The administrator wants to automatically remediate any bucket that is created without versioning enabled. Which solution should be used?

A.Use AWS Config with a managed rule (s3-bucket-versioning-enabled) and an automatic remediation action that uses an AWS Systems Manager Automation document to enable versioning
B.Use Amazon CloudWatch Events to detect CreateBucket API calls and trigger an AWS Lambda function to enable versioning
C.Use AWS CloudTrail to monitor CreateBucket events and send an alert to the SysOps administrator for manual action
D.Use AWS Service Catalog to enforce versioning on all buckets provisioned through it
AnswerA

AWS Config's s3-bucket-versioning-enabled managed rule continuously evaluates every bucket in the account, including both existing resources and newly created ones. When a bucket is found noncompliant—whether it never had versioning or had it disabled—an automatic remediation action invokes an AWS Systems Manager Automation document (such as AWS-EnableS3BucketVersioning) to enable versioning immediately. This closed-loop approach ensures ongoing compliance without manual effort, and it covers all buckets regardless of how they were created or modified. AWS Config evaluates configuration changes in near real time, making this a truly detective and corrective control.

Why this answer

AWS Config with the managed rule `s3-bucket-versioning-enabled` continuously evaluates S3 buckets against the desired configuration. When a noncompliant bucket is detected, an automatic remediation action can be configured to invoke an AWS Systems Manager Automation document that enables versioning on the bucket. This provides a fully automated, event-driven remediation without manual intervention, ensuring all buckets—including those created outside of AWS Config's initial evaluation—are brought into compliance.

Exam trap

The trap here is that candidates often choose CloudWatch Events + Lambda (Option B) thinking it provides real-time remediation, but they overlook that it only catches new buckets and fails to remediate existing noncompliant buckets or buckets that have versioning disabled after creation, whereas AWS Config provides continuous compliance monitoring and automatic remediation for both new and existing resources.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Events (now Amazon EventBridge) can detect `CreateBucket` API calls, but triggering a Lambda function to enable versioning only remediates buckets at creation time; it does not detect or fix buckets that were created before the rule was enabled or buckets that have versioning disabled after creation. Option C is wrong because AWS CloudTrail monitoring and sending an alert requires manual action by the SysOps administrator, which is not an automatic remediation and does not meet the requirement to automatically remediate. Option D is wrong because AWS Service Catalog only enforces versioning on buckets provisioned through it; buckets created directly via the S3 console, CLI, or SDK bypass Service Catalog and remain noncompliant.

137
MCQeasy

A company requires that all data stored in Amazon S3 be encrypted at rest. Which S3 feature should be enabled to meet this requirement without changing the application code?

A.Use an S3 bucket policy to deny unencrypted uploads.
B.Enable default encryption on the S3 bucket.
C.Enable S3 Object Lock.
D.Use client-side encryption.
AnswerB

Enabling default encryption on the S3 bucket configures it to apply server-side encryption with Amazon S3-managed keys (SSE-S3) automatically to any new object uploaded without an explicit encryption header. Existing objects are not encrypted automatically by this setting alone, but after enabling default encryption, you can copy those objects onto themselves to encrypt them, thereby satisfying the requirement for all data at rest.

Why this answer

Enabling default encryption on the S3 bucket automatically encrypts all new objects at rest without requiring any application code changes. Option A (using a bucket policy to deny unencrypted uploads) can enforce encryption but does not encrypt the objects; it requires the application to include encryption headers, which would require code changes. Option C (S3 Object Lock) is a feature for preventing object deletion or overwrites, not for encryption.

Option D (client-side encryption) requires modifying the application to encrypt data before upload, which does not meet the requirement of no code changes.

138
MCQmedium

The CISO asks for a centralized dashboard showing security findings from GuardDuty, Macie, Inspector, and Firewall Manager across 30 AWS accounts. Findings must be normalized into a single format so they can be prioritized by severity without switching between services. Which AWS service provides this capability?

A.Enable AWS Security Hub with an administrator account in the organization; integrate GuardDuty, Macie, Inspector, and Firewall Manager as finding providers
B.Deploy a custom Lambda function that polls each service's API and writes findings to a DynamoDB table for a custom dashboard
C.Enable Amazon Detective to investigate and correlate security findings across all accounts
D.Configure AWS Config conformance packs to evaluate security compliance checks across all accounts and report to an aggregator account
AnswerA

Security Hub's organization integration automatically enables member accounts and routes their findings to the designated administrator account. All findings — regardless of source service — are normalized to ASFF with a consistent severity schema. The security team sees one consolidated dashboard instead of five separate consoles.

Why this answer

AWS Security Hub is designed to aggregate, normalize, and prioritize security findings from multiple AWS services (GuardDuty, Macie, Inspector, Firewall Manager) and third-party tools across accounts. By designating an administrator account in AWS Organizations, you can centrally view all findings in a single dashboard, with a standardized findings format (AWS Security Finding Format, ASFF) that includes severity, resource, and remediation fields. This directly meets the CISO's requirement for a centralized, normalized, severity-prioritized view without switching between services.

Exam trap

The trap here is that candidates often confuse Amazon Detective (a visualization/investigation tool) with Security Hub (a centralized finding aggregation and prioritization service), or they assume a custom Lambda solution is acceptable despite the exam's emphasis on managed, scalable services that reduce operational burden.

How to eliminate wrong answers

Option B is wrong because deploying a custom Lambda function to poll APIs and write to DynamoDB is a manual, brittle approach that does not provide the native normalization, cross-account aggregation, or built-in severity prioritization that Security Hub offers out of the box; it also introduces operational overhead and potential latency. Option C is wrong because Amazon Detective is a service for investigating and visualizing security data (e.g., VPC Flow Logs, GuardDuty findings) but it does not aggregate findings from multiple services into a single normalized dashboard for prioritization; it focuses on root-cause analysis after an alert. Option D is wrong because AWS Config conformance packs evaluate resource compliance against rules (e.g., PCI DSS, CIS benchmarks) and report compliance status, but they do not ingest or normalize security findings from GuardDuty, Macie, Inspector, or Firewall Manager; they are for configuration compliance, not security finding aggregation.

139
MCQmedium

Refer to the exhibit. A SysOps administrator runs the AWS CLI command to check the event selectors for a CloudTrail trail. What does the output indicate?

A.The trail logs all management events.
B.The trail logs both management and data events.
C.The trail logs all data events.
D.The trail logs only write management events.
AnswerA

The trail logs all management events because the IncludeManagementEvents field is set to true and ReadWriteType is set to All, which captures both read and write operations on AWS resources. The JSON configuration confirms this is the default and intended behavior for a management-event-only trail, so any claim that it logs only a subset or additional data events would be incorrect.

Why this answer

The exhibit shows the output of the AWS CLI command to describe event selectors for a CloudTrail trail. The output indicates that the trail is configured to log all management events, as specified by the 'IncludeManagementEvents' field set to true and no data event selectors defined. Therefore, the trail logs all management events.

Exam trap

SOA-C02 often tests the interpretation of CloudTrail event selector output; candidates may assume data events are included by default, but they are not unless explicitly configured.

How to eliminate wrong answers

Option B is wrong because the output does not show any data event selectors (e.g., 'DataResources' field), so data events are not logged. Option C is wrong because the trail is not configured to log data events; only management events are enabled. Option D is wrong because the output does not restrict logging to only write management events; it includes all management events (read and write) unless specified otherwise.

140
Multi-Selecteasy

Which TWO services can be used to centrally manage cryptographic keys for AWS services? (Choose two.)

Select 2 answers
A.AWS CloudHSM
B.AWS Certificate Manager (ACM)
C.AWS Identity and Access Management (IAM)
D.AWS Key Management Service (KMS)
E.AWS Secrets Manager
AnswersA, D

AWS CloudHSM is a hardware security module (HSM) service that provides dedicated, FIPS 140-2 Level 3 validated cryptographic appliances under your exclusive control. It enables centralized, secure key generation, storage, and cryptographic operations using industry-standard APIs (PKCS#11, JCE, Microsoft CNG) while keeping keys isolated in tamper-resistant hardware, making it one of the two services that directly manage cryptographic keys.

Why this answer

AWS CloudHSM (A) is correct because it provides dedicated, single-tenant hardware security modules in the AWS cloud where you can generate, store, and manage cryptographic keys, giving you full control over the key material for AWS services and custom applications. AWS Key Management Service (D) is correct because it is a managed service specifically designed to create, store, and centrally control cryptographic keys used to encrypt data across AWS services and applications, integrating natively with many AWS offerings. AWS Certificate Manager (B) is not a key management service; it provisions, manages, and deploys SSL/TLS certificates, though it can integrate with KMS for private CA keys.

AWS Identity and Access Management (C) manages identities, permissions, and access policies, not cryptographic key material. AWS Secrets Manager (E) stores and rotates secrets such as database credentials and API keys, but it is not intended for centrally managing cryptographic keys for AWS services.

Exam trap

SOA-C02 often tests the distinction between services that manage keys (KMS, CloudHSM) versus services that manage certificates (ACM) or secrets (Secrets Manager), catching candidates who conflate 'cryptographic material' with 'key management'.

141
MCQeasy

A company wants to monitor for unauthorized API calls in their AWS account. Which AWS service should they use?

A.Amazon CloudWatch
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the correct service because it records every API call made on an account, including the identity of the caller, the source IP address, the request parameters, and the response elements, creating a complete event log for governance and auditing. It captures calls made through the AWS Management Console, SDKs, CLI, and other services, and these logs can be delivered to an S3 bucket and integrated with CloudWatch Logs for alerting. With CloudTrail, you can specifically track unauthorized API calls by analyzing the log for failed or suspicious actions, which is exactly what the company needs.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity, source IP, and timestamp of each call. This enables monitoring for unauthorized API activity by analyzing the logs for suspicious patterns or unexpected actions. CloudTrail is specifically designed for auditing API usage, unlike other services that focus on resource configuration or threat detection.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), leading them to select Config when the question specifically asks about monitoring API calls rather than resource state.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, but it does not natively capture or record API calls; it can only consume CloudTrail logs if configured. Option B is wrong because AWS Config evaluates and records resource configuration changes and compliance, not API calls; it focuses on resource state, not the actions that changed them. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not directly provide the raw API call history needed for monitoring unauthorized calls; it relies on CloudTrail as a data source.

142
MCQeasy

A company uses AWS Config to track resource changes. The security team wants to receive notifications whenever an IAM policy is changed. Which AWS service should be used with AWS Config to send notifications?

A.Amazon CloudWatch Logs
B.Amazon Simple Queue Service (SQS)
C.AWS CloudTrail
D.Amazon Simple Notification Service (SNS)
AnswerD

Amazon Simple Notification Service (SNS) is the correct answer because AWS Config natively publishes configuration item change notifications, rule compliance change notifications, and other alerts to an SNS topic. This pub/sub model allows real-time fan-out to email, SMS, Lambda, or SQS consumers. You configure an SNS topic as the delivery channel for your Config recorder, and Config sends JSON messages to that topic whenever a resource changes or a rule evaluation changes.

Why this answer

Amazon Simple Notification Service (SNS) is the correct service to pair with AWS Config to send notifications when an IAM policy changes. AWS Config can publish configuration change events to an SNS topic, which then delivers notifications via email, SMS, or other protocols to the security team. This integration allows real-time alerting on resource changes without additional polling or custom logic.

Exam trap

The trap here is that candidates often confuse AWS Config's notification mechanism with CloudTrail's logging, assuming CloudTrail can send alerts directly, when in fact CloudTrail only records events and requires integration with other services like CloudWatch Alarms or SNS for notifications.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is used for storing, monitoring, and accessing log data, not for sending notifications; it would require additional services like CloudWatch Alarms or Lambda to trigger notifications. Option B is wrong because Amazon Simple Queue Service (SQS) is a message queuing service for decoupling application components, not a push notification service; it would require a consumer to poll and process messages to send alerts. Option C is wrong because AWS CloudTrail records API activity for auditing, but it does not natively send notifications; it can deliver logs to S3 or CloudWatch Logs, but not directly notify users of changes.

143
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. Which statement about the user's access is correct?

A.The user can get objects over HTTP.
B.The user can list objects in the bucket over HTTP.
C.The user can list objects only over HTTPS.
D.The user can get objects only over HTTPS.
AnswerD

The policy's Condition element restricts access to HTTPS, so GetObject requests succeed only when the aws:SecureTransport condition key evaluates true. Plain HTTP calls are denied, satisfying the stem's HTTPS-only constraint while leaving the action and resource permissions otherwise intact.

Why this answer

The IAM policy includes a condition that restricts access to HTTPS (aws:SecureTransport true) and allows s3:GetObject. Therefore, the user can only perform GetObject over HTTPS. The policy does not grant s3:ListBucket, so listing is not allowed at all.

Thus, the correct statement is that the user can get objects only over HTTPS.

Exam trap

SOA-C02 often tests the misunderstanding that a condition applies only to certain actions; candidates may think GetObject over HTTP is allowed because the action is permitted, but the condition blocks it.

How to eliminate wrong answers

Option A is wrong because the policy condition requires secure transport (HTTPS), so HTTP requests are denied. Option B is wrong because the policy does not include the s3:ListBucket action, so listing objects is not permitted regardless of protocol. Option C is wrong because listing is not allowed at all, and even if it were, the condition would require HTTPS, but the action is missing.

144
MCQmedium

A company's security policy requires that all Amazon S3 buckets must have server-side encryption with AWS Key Management Service (SSE-KMS) enabled. The SysOps administrator needs to automatically detect any existing or new S3 bucket that does not have SSE-KMS enabled and automatically apply the encryption configuration. The solution must use managed AWS services with minimal custom code. Which combination of AWS services should be used?

A.Use AWS Config with a custom rule backed by an AWS Lambda function that checks if the S3 bucket has default SSE-KMS encryption enabled, and auto-remediates by enabling SSE-KMS default encryption (e.g., calling the PutBucketEncryption API).
B.Enable default encryption on the AWS account's S3 buckets using an S3 account-level setting in the S3 console, which automatically applies SSE-KMS to all new buckets.
C.Create an AWS CloudTrail event that triggers an AWS Lambda function when a bucket is created, and the Lambda applies SSE-KMS encryption. Use AWS Config to periodically scan existing buckets and apply encryption.
D.Use AWS Identity and Access Management (IAM) with a Service Control Policy (SCP) that denies any S3 bucket creation without SSE-KMS enabled, and use AWS Config to detect and notify on non-compliance.
AnswerA

This uses AWS Config for detection and Lambda for remediation, which is a standard pattern. Bucket policy approach prevents future unencrypted uploads but does not encrypt existing objects; however, the requirement is to apply encryption configuration, which can be done via put-bucket-encryption API. The Lambda can call that API. This is a valid solution with managed services and minimal custom code (only the Lambda).

Why this answer

It uses AWS Config with a custom Lambda-backed rule to detect non-compliant S3 buckets (those missing SSE-KMS) and auto-remediate by calling the PutBucketEncryption API to enable default SSE-KMS encryption on the bucket. This satisfies the requirement for minimal custom code (only the Lambda function) and uses managed AWS services (AWS Config, Lambda, S3) to automatically detect and fix both existing and new buckets, ensuring that all S3 buckets have SSE-KMS enabled as per the security policy.

Exam trap

The trap here is that candidates often confuse S3 default encryption settings (which apply to objects, not buckets) with bucket policies or AWS Config rules, leading them to choose Option B or D, which cannot automatically remediate existing non-compliant buckets.

How to eliminate wrong answers

Option B is wrong because S3 account-level default encryption settings apply only to new objects uploaded to existing buckets, not to new buckets themselves, and cannot retroactively enforce encryption on existing buckets or detect non-compliant buckets. Option C is wrong because it requires creating a CloudTrail event trigger and a separate AWS Config periodic scan, which introduces more custom code and complexity than necessary, and the CloudTrail approach only catches bucket creation events, not modifications to existing buckets. Option D is wrong because IAM Service Control Policies (SCPs) can only deny bucket creation based on tags or conditions at creation time, but they cannot detect or remediate existing buckets that lack SSE-KMS, and AWS Config alone without a remediation action cannot automatically apply encryption.

145
MCQhard

A company's security policy requires that all Amazon S3 buckets must be non-publicly accessible. The SysOps administrator needs to automatically detect any bucket that becomes publicly accessible and automatically remediate it by applying a bucket policy that blocks public access. The solution should use AWS managed services with minimal custom code. Which combination of services should be used?

A.AWS IAM Access Analyzer with Amazon EventBridge
B.AWS Config with managed rule and automatic remediation via SSM Automation
C.AWS CloudTrail and AWS Lambda
D.AWS Trusted Advisor and Amazon SNS
AnswerB

AWS Config continuously evaluates S3 bucket configurations against a managed rule such as s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited. When a bucket becomes noncompliant, AWS Config can invoke an automatic remediation using a prebuilt Systems Manager Automation document, for example AWS-DisableS3BucketPublicReadWrite, which applies the necessary bucket policy or public access block settings. Because this is a fully managed integration between Config and SSM Automation, it satisfies the security policy without custom code.

Why this answer

AWS Config with a managed rule (e.g., s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited) can continuously evaluate S3 bucket configurations against the security policy. When a bucket becomes publicly accessible, AWS Config triggers an automatic remediation action using an SSM Automation document that applies a bucket policy to block public access, all without custom code.

Exam trap

The trap here is that candidates often choose AWS IAM Access Analyzer (Option A) because it detects public access, but they overlook that it lacks built-in automatic remediation, requiring additional services and custom code to achieve the full requirement.

How to eliminate wrong answers

Option A is wrong because AWS IAM Access Analyzer analyzes resource-based policies to identify external access, but it does not provide automatic remediation; it only generates findings and requires separate automation via EventBridge and custom logic. Option C is wrong because AWS CloudTrail records API calls but does not evaluate bucket configurations or trigger remediation; using Lambda would require custom code, violating the 'minimal custom code' requirement. Option D is wrong because AWS Trusted Advisor checks for publicly accessible S3 buckets but only provides recommendations and alerts via SNS; it cannot automatically remediate the issue.

146
MCQmedium

A SysOps administrator notices that an IAM user can access the AWS Management Console but cannot use the AWS CLI. The user has a password and an access key. What is the most likely cause?

A.The secret access key was not saved during creation
B.The user's access key is inactive
C.The user is using the wrong password for the CLI
D.The IAM policy denies CLI access unless MFA is present
AnswerD

An IAM policy can include a condition key such as aws:MultiFactorAuthPresent with a value of 'false' to deny API actions when the user's session was not authenticated with MFA. The user may have properly authenticated with MFA for the console session, but if the CLI request was made without providing an MFA token, the condition evaluates to false and the policy denies the action. This explains why the console works while CLI commands return an AccessDenied error, and it is the only option that addresses the precise distinction between authenticated console access and unauthenticated programmatic access.

Why this answer

The most likely cause is that the user's IAM policy includes a condition that denies CLI access unless MFA is present. The AWS CLI uses access keys for authentication, and if a policy explicitly requires MFA for API calls (e.g., via `aws:MultiFactorAuthPresent` condition key), CLI requests will be denied even though console access (which can enforce MFA separately via a sign-in policy) remains functional. This scenario is common when an administrator has attached a policy like `DenyAllExceptWithMFA` to the user or a group.

Exam trap

The trap here is that candidates often assume CLI access is always tied to the access key's active status or password, rather than understanding that IAM policies with MFA conditions can selectively block API calls while allowing console access.

How to eliminate wrong answers

Option A is wrong because if the secret access key was not saved during creation, the user would not have a valid access key at all, but the question states the user has an access key. Option B is wrong because an inactive access key would prevent both CLI and SDK access, but the user can still access the console (which uses password authentication), so the key being inactive would not explain the discrepancy. Option C is wrong because the AWS CLI does not use the console password for authentication; it uses the access key ID and secret access key, so using the wrong password is irrelevant to CLI access.

147
MCQmedium

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all S3 buckets across all accounts have encryption enabled. What is the most efficient way to enforce this policy?

A.Apply a service control policy (SCP) to the root organizational unit that denies S3 actions without encryption.
B.Configure an IAM role in the master account to enforce encryption via cross-account access.
C.Create an IAM policy in each account that denies s3:PutObject without encryption.
D.Use AWS CloudFormation StackSets to deploy a bucket policy to each account.
AnswerA

Applying an SCP at the root organizational unit is the correct centralized method because SCPs act as guardrails that restrict the maximum permissions available to all IAM principals in every account under that OU, including the account root user. An SCP can, for example, use a condition like `s3:x-amz-server-side-encryption` or `aws:SecureTransport` to deny `s3:PutObject` calls that do not include encryption parameters, and because SCPs cannot be overridden by individual account administrators, this enforces encryption uniformly across the entire organization.

Why this answer

A service control policy (SCP) applied to the root organizational unit in AWS Organizations can centrally enforce encryption requirements for all S3 buckets across every member account. By denying S3 actions (such as s3:PutObject) unless the request includes encryption parameters (e.g., x-amz-server-side-encryption), the SCP acts as a guardrail that cannot be overridden by account-level IAM policies, ensuring compliance without per-account configuration.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, assuming that IAM policies in each account are sufficient, but SCPs provide centralized, unoverridable enforcement across all accounts in an organization.

How to eliminate wrong answers

Option B is wrong because an IAM role in the master account cannot enforce encryption on S3 actions performed by principals in other accounts; cross-account access via roles requires explicit trust and does not prevent unencrypted operations initiated by users in member accounts. Option C is wrong because creating an IAM policy in each account is not the most efficient approach—it requires manual deployment and maintenance across potentially hundreds of accounts, and IAM policies can be overridden by account administrators. Option D is wrong because CloudFormation StackSets deploy resources (like bucket policies) but cannot enforce encryption on existing buckets or future actions across all accounts without additional mechanisms; bucket policies also apply only to specific buckets, not globally.

148
MCQmedium

A company has a single AWS account with multiple IAM users. The security team wants to ensure that no IAM user can create or modify VPC resources. The SysOps administrator creates a managed policy that denies ec2:CreateVpc, ec2:DeleteVpc, ec2:ModifyVpcAttribute, and similar actions. The policy is attached to all IAM users via a group. However, after a week, a user reports that they were able to create a VPC. The administrator checks CloudTrail and confirms that the user created the VPC. What is the most likely cause?

A.The user used the AWS Management Console, which does not enforce IAM policies.
B.The user had an inline policy that allowed ec2:CreateVpc, overriding the group policy.
C.The policy was attached to the user's group, but the user was not a member of that group.
D.The user created the VPC using AWS CloudFormation with a service role that had full EC2 access.
AnswerD

With AWS CloudFormation, you can specify an IAM service role (or just a role) that CloudFormation assumes to create stack resources. If the user launched the stack with a role that includes ec2:CreateVpc, the role's permissions authorize the VPC creation, not the user's own policies, provided the user had iam:PassRole for that role. This is a legitimate way for a user without direct EC2 create permission to create a VPC.

Why this answer

The most likely cause is that the user created the VPC using AWS CloudFormation with a service role that had full EC2 access (including ec2:CreateVpc). IAM policies applied to a user do not affect actions taken by AWS services like CloudFormation when a service role is used, because the service role itself grants permissions. Even though the user's group policy denies VPC creation, the CloudFormation service role bypasses the user's IAM policies.

This is a known pitfall: service roles can allow users to perform actions that their own IAM policies deny, if they have permission to pass the role.

149
MCQmedium

A company wants to enforce that all Amazon S3 buckets in their AWS account are encrypted at rest. They have enabled AWS CloudTrail and want to automatically remediate any non-compliant bucket created by users. Which AWS service should they use to achieve this?

A.AWS Trusted Advisor
B.Amazon Inspector
C.AWS Config
D.AWS Service Catalog
AnswerC

AWS Config is a configuration governance service that continuously records, evaluates, and audits AWS resource configurations. Its managed rule s3-bucket-server-side-encryption-enabled checks whether S3 buckets have default encryption enabled, and you can attach auto-remediation actions using Systems Manager Automation documents (e.g., AWS-ConfigureS3BucketEncryption) to automatically apply encryption to noncompliant buckets. This combination of detection and corrective action makes AWS Config the correct service for enforcing S3 encryption.

Why this answer

AWS Config is the correct service because it continuously evaluates AWS resource configurations against desired rules and can trigger automatic remediation. For S3 encryption, you can use the managed rule 's3-bucket-server-side-encryption-enabled' to detect non-compliant buckets. When a bucket is created without encryption, AWS Config can invoke an AWS Lambda function or SSM Automation document to enable default encryption, achieving automatic remediation.

This directly meets the requirement to enforce encryption at rest across all S3 buckets.

Exam trap

SOA-C02 often tests the difference between monitoring/recommendation services (Trusted Advisor, Inspector) and compliance enforcement services (AWS Config), so candidates may mistakenly choose Trusted Advisor for its security checks, but it lacks automatic remediation.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer automatic remediation or continuous compliance enforcement; it only reports issues. Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not for S3 bucket encryption configuration. Option D is wrong because AWS Service Catalog allows you to create and manage catalogs of approved IT services, but it does not monitor or remediate existing resources for compliance; it is used for provisioning standardized products, not for enforcing encryption on existing S3 buckets.

150
MCQhard

A company uses an IAM policy that allows s3:GetObject for a specific bucket. However, an IAM user is getting an Access Denied error when trying to download an object. The bucket policy also allows s3:GetObject for the user's account. What is the most likely cause?

A.The IAM policy does not include the s3:GetObjectVersion action.
B.The bucket policy has a Deny statement that applies to the user.
C.The object is encrypted with a customer-managed KMS key, and the user does not have kms:Decrypt permissions.
D.The user's account is part of an AWS Organization with an SCP that denies s3:GetObject.
AnswerB

An explicit Deny statement in a bucket policy always overrides any Allow that exists in an IAM identity-based policy, because AWS IAM evaluates all policies and the explicit deny takes precedence. If the bucket policy contains a Deny that applies to this specific user, the user will receive AccessDenied even if their IAM policy grants s3:GetObject for the same bucket and object. This is the classic cause described in the scenario, and it correctly explains why the user is blocked.

Why this answer

The most likely cause because if the bucket policy has a Deny statement that applies to the user, that explicit denial overrides any allow from the IAM policy or the bucket policy. Option A is incorrect because s3:GetObjectVersion is not required to download the current version; s3:GetObject is sufficient. Option C is incorrect because there is no indication that the object is encrypted with KMS, and even if it were, the error would be different (e.g., 'AccessDenied' due to missing KMS permissions, but the scenario explicitly says Access Denied from S3).

Option D is incorrect because SCPs apply to the entire account, but the question states that both IAM and bucket policies allow access, so an SCP denial would be possible, but it is not the most likely cause given the explicit allow statements and the fact that a bucket-level Deny is more direct.

← PreviousPage 2 of 3 · 198 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.