Courseiva

CCNA Security and Compliance Questions

48 of 198 questions · Page 3/3 · Security and Compliance · Answers revealed

151
MCQhard

A company has a legacy application that requires access to an S3 bucket using an IAM user's access keys. The security team wants to rotate the access keys every 90 days automatically. What is the MOST efficient way to achieve this?

A.Use AWS Lambda with a scheduled CloudWatch Events rule to rotate the keys.
B.Create a script that runs on an EC2 instance using cron to rotate the keys.
C.Store the access keys in AWS Secrets Manager and use automatic rotation.
D.Enable IAM access key rotation in the IAM console.
AnswerC

AWS Secrets Manager natively supports automatic rotation for IAM user access keys: you configure a rotation schedule (e.g., every 30 or 90 days), and the service creates a new access key, updates the secret with the new credentials, and deletes the old key after a safe handoff—all with versioning so you can stage the new secret separately from the current one. It does not require you to write any custom scheduling code because Secrets Manager uses an AWS-provided Lambda rotation function template for IAM user keys, and it can alternate between two active keys to avoid downtime for downstream systems. This directly meets the need to 'require access to the service' without manual intervention, and it also gives you fine-grained IAM permissions to control who can access or rotate the secret, plus CloudTrail audit logs of rotation events.

Why this answer

AWS Secrets Manager provides built-in automatic rotation for IAM user access keys, allowing you to set a 90-day rotation schedule without custom code. Option A is incorrect because while AWS Lambda with a scheduled CloudWatch Events rule could rotate keys, it requires custom code and is less efficient than the managed rotation in Secrets Manager. Option B is incorrect because a script on an EC2 instance using cron would require additional infrastructure and maintenance.

Option D is incorrect because there is no built-in IAM access key rotation in the IAM console; you must manually rotate keys each time.

152
Multi-Selecteasy

A company uses AWS Shield Advanced to protect against DDoS attacks. Which of the following are benefits of AWS Shield Advanced? (Choose TWO.)

Select 2 answers
A.24/7 access to the DDoS Response Team (DRT)
B.Free for all AWS accounts
C.Integration with AWS WAF to create custom rules
D.Automatic scaling of resources during an attack
E.Enhanced DDoS protection for resources like EC2, ELB, CloudFront, and Route 53
AnswersA, E

Shield Advanced provides 24/7 access to the AWS DDoS Response Team (DRT), a specialized crew that can assist during an ongoing attack, perform proactive architectural reviews, and create tailored mitigations. This human-level support is a unique, paid benefit that distinguishes Shield Advanced from the free Shield Standard, making it crucial for high-risk, mission-critical applications.

Why this answer

AWS Shield Advanced provides enhanced DDoS protection for resources like EC2, ELB, CloudFront, and Route 53 (option E), and includes 24/7 access to the DDoS Response Team (DRT) (option A). Option B is incorrect because Shield Advanced is not free; it has a monthly cost. Option C is incorrect because integration with AWS WAF is not a direct benefit of Shield Advanced; WAF is a separate service that can be used alongside Shield but is not a benefit of Shield Advanced itself.

Option D is incorrect because automatic scaling is not a direct benefit of Shield Advanced; it is handled by other AWS services like Auto Scaling.

153
MCQhard

Refer to the exhibit. A SysOps administrator reviews the account password policy. Which of the following is true based on this output?

A.Passwords do not expire
B.Users cannot reuse their last 5 passwords
C.The maximum password age is 120 days
D.Users cannot change expired passwords
AnswerB

This statement is correct. The IAM password policy includes PasswordReusePrevention configured to 5, which prevents a user from reusing any of their previous 5 passwords when changing or resetting a password. This means the specified number of previous passwords is stored and cannot be reused, directly matching the statement.

Why this answer

The output shows MaxPasswordAge: 90 and ExpirePasswords: true, meaning passwords expire after 90 days. PasswordReusePrevention: 5 means users cannot reuse the last 5 passwords. Option B is correct.

Option A is wrong because password expiration is enabled (ExpirePasswords: true). Option C is wrong because MaximumPasswordAge is 90 days. Option D is wrong because HardExpiry is false, meaning users can change expired passwords.

154
MCQhard

A company has an S3 bucket that stores sensitive customer data. The security team requires that all objects uploaded to the bucket must be encrypted at rest using AWS KMS with a specific customer managed key. Which bucket policy condition should be used to enforce this?

A."Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}
B."Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms", "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
C."Condition": {"StringEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
D."Condition": {"Null": {"s3:x-amz-server-side-encryption": "false"}}
AnswerB

Combines both conditions to enforce KMS encryption and the specific customer managed key, meeting the requirement.

Why this answer

It uses both conditions: 's3:x-amz-server-side-encryption' set to 'aws:kms' ensures that objects are encrypted with SSE-KMS, and 's3:x-amz-server-side-encryption-aws-kms-key-id' set to the specific key ARN ensures that only the designated customer managed key is used. Option A enforces KMS encryption but does not restrict which KMS key, allowing any managed key. Option C enforces a specific key ARN but does not require the encryption header to be present, which could allow objects without encryption if the key ID header is omitted (though in practice, the key ID is only valid with SSE-KMS, the condition alone is not sufficient to guarantee encryption).

Option D uses a 'Null' condition incorrectly and would not properly enforce encryption.

155
MCQmedium

A company wants to ensure that only specific IAM roles within the same AWS account can encrypt and decrypt data using an AWS KMS customer managed key. Which type of policy must be configured to achieve this restriction?

A.IAM policy attached to the roles
B.KMS key policy
C.Service control policy (SCP)
D.Resource policy attached to the KMS key
AnswerB

A KMS key policy is the resource-based policy attached directly to the customer master key (CMK) that defines which principals can use the key. For roles within the same AWS account, you can either specify the role ARNs directly in the key policy or allow the account root to delegate permissions via IAM policies. This is the authoritative mechanism to restrict key usage to only the designated IAM roles.

Why this answer

A KMS key policy is the primary mechanism to control access to a customer managed key. By default, a KMS key policy must explicitly grant the necessary permissions (kms:Encrypt, kms:Decrypt) to IAM roles, and it can restrict those permissions to specific roles within the same account using the `aws:PrincipalArn` condition key. This ensures that only the designated IAM roles can encrypt and decrypt data with that key.

Exam trap

The trap here is that candidates often think an IAM policy alone is sufficient to grant KMS key access, but they forget that KMS key policies act as a resource-based policy that must explicitly allow the IAM principal, otherwise the IAM policy is ignored.

How to eliminate wrong answers

Option A is wrong because an IAM policy attached to the roles alone is insufficient; KMS requires a key policy that explicitly allows the IAM roles to use the key, and without such a key policy, the IAM policy has no effect (the key policy acts as a resource-based policy that must grant access). Option C is wrong because a Service Control Policy (SCP) is used in AWS Organizations to set permission boundaries across accounts, not to grant or deny specific IAM roles access to a KMS key within a single account. Option D is wrong because while a KMS key policy is technically a resource policy, the term 'resource policy attached to the KMS key' is redundant and misleading; the correct and specific term is 'KMS key policy', and the question asks for the type of policy, not a generic description.

156
MCQeasy

A SysOps administrator needs to grant an application running on an Amazon EC2 instance access to an Amazon S3 bucket without embedding long-term AWS credentials in the application code. The EC2 instance is in a private subnet and must not use an IAM user access key. Which solution should the administrator use?

A.Store the AWS credentials in an encrypted Amazon S3 bucket and have the application download them at startup.
B.Create an IAM user with programmatic access, generate an access key, and store it in AWS Systems Manager Parameter Store as a SecureString parameter.
C.Configure the S3 bucket policy to allow access from the EC2 instance's private IP address using the aws:SourceIp condition.
D.Attach an IAM role to the EC2 instance with a policy that allows the required S3 actions, and let the application use the instance metadata service to obtain temporary credentials.
AnswerD

Attaching an IAM role to an EC2 instance provides temporary credentials through the instance metadata service (IMDS). The application can retrieve these credentials automatically without embedding long-term keys. This is the recommended best practice for granting AWS permissions to EC2 instances. The role's policy can be scoped to only the necessary S3 actions, following least privilege.

Why this answer

Attaching an IAM role to the EC2 instance allows the application to obtain temporary credentials from the instance metadata service. This eliminates the need for long-term access keys and follows AWS best practices for least privilege and credential management. The role can be scoped to only the required S3 actions.

Exam trap

The trap here is assuming that storing credentials in Parameter Store or an encrypted S3 bucket solves the problem, but those still involve long-term credentials and additional bootstrap challenges.

157
MCQeasy

A company requires that all AWS account activity be recorded and the logs be stored in a centralized S3 bucket for analysis. Which two AWS services should be used together to meet this requirement?

A.Amazon GuardDuty and Amazon S3
B.AWS CloudTrail and Amazon S3
C.AWS Config and Amazon S3
D.Amazon Inspector and Amazon S3
E.VPC Flow Logs and Amazon S3
AnswerB

AWS CloudTrail is the correct service for recording all AWS account activity. It captures every API call made in the account, including the identity of the caller, the time of the call, the source IP address, and the requested action, delivering these events as log files. These logs can be delivered to an Amazon S3 bucket for long-term, tamper-evident storage, which directly satisfies the compliance and auditing requirement.

Why this answer

The correct answer is B: AWS CloudTrail and Amazon S3. CloudTrail records all AWS account activity as API call events, and it can be configured with a trail that delivers those event logs to a centralized S3 bucket for storage and later analysis. The other options do not fit: GuardDuty is a threat-detection service that generates findings rather than recording all account activity, AWS Config tracks resource configuration changes and compliance rather than full API activity, Amazon Inspector assesses vulnerabilities on workloads, and VPC Flow Logs capture IP traffic metadata for network interfaces, not AWS account API activity.

158
Multi-Selectmedium

Which TWO actions can a SysOps administrator take to secure an Amazon S3 bucket that contains sensitive data? (Choose TWO.)

Select 2 answers
A.Configure a cross-origin resource sharing (CORS) policy.
B.Enable default encryption using AWS KMS (SSE-KMS) on the bucket.
C.Enable cross-region replication for the bucket.
D.Block all public access to the bucket using the S3 Block Public Access feature.
E.Enable MFA Delete on the bucket to require multi-factor authentication for delete operations.
AnswersB, D

Enabling default encryption with SSE-KMS ensures that every object uploaded without an explicit encryption header is automatically encrypted at rest using a KMS-managed customer key. This provides envelope encryption and allows you to control key access through IAM policies, while CloudTrail records key usage for auditing. It directly addresses data-at-rest confidentiality, making it a necessary and effective security action.

Why this answer

Enabling default encryption with SSE-KMS ensures that all objects uploaded to the S3 bucket are automatically encrypted at rest using AWS KMS-managed keys. This protects sensitive data even if the uploader forgets to specify encryption, meeting security and compliance requirements for data-at-rest protection.

Exam trap

The trap here is that candidates often confuse operational features like replication or MFA Delete with security controls that prevent unauthorized access or ensure encryption, leading them to select options that do not directly secure sensitive data.

159
MCQhard

A company's security team notices that an IAM user has been generating multiple access keys and deleting them within a short period. The SysOps administrator needs to detect and alert on this behavior. Which solution is the MOST effective?

A.Enable AWS Trusted Advisor security checks and review the report weekly.
B.Enable IAM Access Analyzer to analyze user activity and send alerts.
C.Enable AWS CloudTrail and create a CloudWatch Events rule that triggers on iam:CreateAccessKey events and sends a notification to an SNS topic.
D.Use AWS Config to track IAM user configuration changes and trigger an alert when an access key is created.
AnswerC

AWS CloudTrail is the correct foundation because it records management events, including the iam:CreateAccessKey API call, as a JSON audit log. A CloudWatch Events rule (or Amazon EventBridge rule) can use an event pattern to match the eventSource, eventName, and other fields, then invoke an SNS topic to send an email or SMS notification. This combination provides near-real-time detection of the exact API action—something a periodic report or static policy scanner cannot deliver.

Why this answer

The behavior described—creating and deleting access keys rapidly—is an API-level event that must be captured in real time. AWS CloudTrail logs all IAM API calls, including CreateAccessKey and DeleteAccessKey. By creating a CloudWatch Events (now Amazon EventBridge) rule that matches the iam:CreateAccessKey event, you can trigger an SNS notification immediately, enabling the security team to detect and respond to the suspicious activity.

This solution is the most effective because it provides near-real-time detection and alerting based on the specific API call.

Exam trap

SOA-C02 often tests the difference between services that monitor configuration changes (AWS Config) and those that capture API activity (CloudTrail), and candidates may incorrectly choose AWS Config because it can track IAM changes, but it lacks real-time event-driven alerting on specific API calls.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor security checks focus on best practices and configuration weaknesses (e.g., MFA on root, public S3 buckets), not on real-time API activity like access key creation; weekly reviews are too slow. Option B is wrong because IAM Access Analyzer analyzes resource policies to identify external access, not user API activity; it does not monitor or alert on CreateAccessKey events. Option D is wrong because AWS Config tracks resource configuration changes and can alert on access key creation, but it is not real-time and does not capture the API call details or the rapid deletion pattern as effectively as CloudTrail/CloudWatch Events.

160
MCQeasy

A company wants to ensure that all data in Amazon S3 is encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). Which bucket policy statement should be used to deny any PUT request that does not include the 'x-amz-server-side-encryption' header with value 'aws:kms'?

A.Condition: { StringNotEquals: { 's3:x-amz-server-side-encryption': 'aws:kms' } }
B.Condition: { StringNotEquals: { 's3:x-amz-server-side-encryption-aws-kms-key-id': 'alias/aws/s3' } }
C.Condition: { StringNotEquals: { 's3:ServerSideEncryption': 'KMS' } }
D.Condition: { StringEquals: { 's3:x-amz-server-side-encryption': 'aws:kms' } }
AnswerA

This Deny policy uses StringNotEquals on the s3:x-amz-server-side-encryption request header to block any PUT that does not explicitly specify aws:kms. Because it's an explicit deny, it overrides all allows, so objects uploaded with AES256, no encryption header, or any other value are rejected. That directly enforces the requirement that all S3 data be encrypted with SSE-KMS.

Why this answer

It uses the condition key 's3:x-amz-server-side-encryption' and denies the request when the header value is not 'aws:kms', enforcing SSE-KMS. Option B is incorrect because it checks the specific KMS key ID via 's3:x-amz-server-side-encryption-aws-kms-key-id', not the encryption type. Option C is incorrect because 's3:ServerSideEncryption' is not a valid condition key for S3; the correct key is 's3:x-amz-server-side-encryption'.

Option D is incorrect because using StringEquals with this condition key would only match requests that include the header with value 'aws:kms', but a deny policy with this condition would not block requests that omit the header entirely; additionally, the question requires denying requests that do not include the specified encryption header.

161
MCQeasy

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are configured with server-side encryption using AWS KMS (SSE-KMS). The administrator wants to automatically detect any S3 buckets that are not compliant and remediate them by enabling SSE-KMS. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.AWS Trusted Advisor
C.AWS Service Catalog
D.AWS CloudFormation
AnswerA

AWS Config continuously evaluates S3 bucket configurations against managed rules such as s3-bucket-server-side-encryption-enabled, which specifically verifies that default encryption is set to SSE-KMS. When a bucket is non-compliant, AWS Config can automatically invoke an SSM automation document (e.g., AWS-EnableS3BucketEncryption) to remediate the violation, enforcing SSE-KMS without manual intervention. This real-time monitoring and automated remediation capability is exactly what the SysOps administrator needs to ensure all S3 buckets meet the encryption requirement.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 buckets for compliance with SSE-KMS. When a non-compliant bucket is detected, AWS Config can trigger an AWS Systems Manager Automation document or a custom remediation action (via AWS Config Rules remediation) to automatically enable SSE-KMS on the bucket, ensuring automated enforcement without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's reactive compliance monitoring with Trusted Advisor's advisory checks, or assume CloudFormation can handle post-deployment compliance, but only AWS Config provides the continuous evaluation and automated remediation required for this use case.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor only provides reactive recommendations and best-practice checks (e.g., S3 bucket permissions) but does not support automated remediation or custom compliance rules; it cannot automatically enable SSE-KMS on non-compliant buckets. Option C is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured S3 bucket templates) but does not perform ongoing compliance monitoring or remediation of existing resources. Option D is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources via templates; it can enforce SSE-KMS at deployment time but cannot automatically detect or remediate non-compliant buckets that already exist or are created outside of CloudFormation stacks.

162
Multi-Selectmedium

Which TWO actions can be used to protect data in transit between an EC2 instance and an S3 bucket? (Choose two.)

Select 2 answers
A.Configure security group rules on the EC2 instance to allow only S3 traffic.
B.Apply an S3 bucket policy that denies access unless the request includes the x-amz-server-side-encryption header.
C.Use HTTPS instead of HTTP when accessing S3 from the EC2 instance.
D.Enable S3 default encryption (SSE-S3) on the bucket.
E.Use S3 VPC endpoints to ensure traffic between the VPC and S3 does not traverse the internet.
AnswersC, E

HTTPS uses TLS to encrypt the entire HTTP request and response payload between the EC2 instance and S3, including object data, providing confidentiality and integrity against eavesdropping and tampering. This is a client-side action: the application must explicitly use the https:// prefix in the S3 endpoint URL, and AWS recommends this as the primary measure for protecting data in transit.

Why this answer

Option C is correct because using HTTPS (TLS) when accessing S3 from the EC2 instance encrypts the data in transit between the instance and S3, protecting it from interception or tampering on the network. Option E is correct because an S3 VPC endpoint (gateway endpoint for S3) keeps traffic between the VPC and S3 on the AWS private network, so it does not traverse the public internet, reducing exposure to interception. Option A is incorrect because security groups control which traffic is allowed to and from the instance but do not encrypt or otherwise protect the data in transit.

Option B is incorrect because the x-amz-server-side-encryption header relates to server-side encryption of data at rest, not protection of data in transit. Option D is incorrect because S3 default encryption (SSE-S3) encrypts objects at rest in the bucket, not data moving between the EC2 instance and S3.

Exam trap

The trap here is confusing encryption in transit (HTTPS) with encryption at rest (SSE-S3 or bucket policies requiring encryption headers), leading candidates to select options that protect data only after it reaches S3 rather than during network transmission.

163
MCQmedium

A SysOps administrator needs to ensure that all API calls made to AWS are logged for auditing purposes. Which AWS service should be enabled to capture management events?

A.AWS CloudTrail
B.S3 server access logs
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the correct service because it records API activity across all AWS services, capturing the identity of the caller, the time of the call, the source IP address, and the user agent. Management events are logged and can be delivered to an S3 bucket or CloudWatch Logs for governance, compliance, and operational auditing. CloudTrail is specifically designed to answer 'who did what and when' at the API level, making it the authoritative audit trail for API calls in an AWS account.

Why this answer

AWS CloudTrail is the service specifically designed to record API activity in an AWS account, including management events (control plane operations) such as creating, modifying, or deleting resources. It captures the identity of the caller, the time of the call, the source IP address, and other details, making it the correct choice for auditing API calls. CloudTrail logs can be delivered to an S3 bucket and optionally to CloudWatch Logs for further analysis.

Exam trap

SOA-C02 often tests the distinction between services that log API activity (CloudTrail) and those that log network traffic (VPC Flow Logs) or resource access (S3 server access logs). Candidates may incorrectly choose CloudWatch Logs because it sounds like a logging service, but it does not capture API calls natively.

How to eliminate wrong answers

Option B is wrong because S3 server access logs record requests made to an S3 bucket (data plane operations) and do not capture API calls across all AWS services. Option C is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option D is wrong because Amazon CloudWatch Logs is a log storage and analysis service, not a service that itself captures API calls; it can receive CloudTrail logs but is not the source.

164
Multi-Selecteasy

A SysOps administrator is configuring a new VPC and wants to ensure that only traffic from a specific IP address range can access an EC2 instance via SSH. Which TWO components should be configured? (Choose two.)

Select 2 answers
A.VPC endpoint
B.Network ACL (NACL)
C.Security group
D.Internet gateway
E.Route table
AnswersB, C

A network ACL is a stateless virtual firewall at the subnet boundary. It evaluates ingress and egress rules independently, so to allow SSH from a specific CIDR you must add an inbound allow rule and a corresponding outbound rule for ephemeral ports. NACLs can explicitly deny traffic (e.g., block a hostile IP) and are applied to all instances in the subnet, making them an effective subnet-level control for SSH.

Why this answer

To restrict SSH access to a specific IP range, you configure a network ACL at the subnet level and a security group at the instance level. NACLs are stateless and evaluate rules in order; security groups are stateful. Both can allow inbound SSH from the specific IP range.

Internet gateway enables internet access but does not filter by IP. Route tables direct traffic but do not filter. VPC endpoint is for private connectivity to AWS services.

165
MCQeasy

Refer to the exhibit. An IAM policy is attached to a user. What is the effective permission regarding the s3:DeleteObject action on the example-bucket?

A.Denied because of the explicit Deny statement
B.Denied because the action is not allowed explicitly
C.Allowed because the Allow statement is listed first
D.Allowed because the Deny statement has a typo
AnswerA

The presence of an explicit Deny statement for the s3:DeleteObject action creates an unresolvable conflict with the Allow statement in the same policy. AWS IAM evaluates all policies and any explicit Deny always overrides every Allow, regardless of how broad or specific the Allow may be. Even though the first statement grants all S3 actions, the Deny takes precedence and the request is ultimately denied.

Why this answer

The effective permission is Denied because of the explicit Deny statement. In AWS IAM policy evaluation, an explicit Deny always overrides any Allow, regardless of the order in which statements appear or whether the action is otherwise permitted. Since the policy contains an explicit Deny for s3:DeleteObject on example-bucket, the request is denied.

Exam trap

SOA-C02 often tests whether candidates know that explicit Deny always wins over Allow and that statement order in an IAM policy is irrelevant to evaluation.

How to eliminate wrong answers

Option B is wrong because the action is explicitly denied, not merely absent from an Allow statement; the presence of an explicit Deny makes the distinction between implicit and explicit denial irrelevant here. Option C is wrong because statement order in an IAM policy has no effect on evaluation; AWS evaluates all statements and applies the explicit Deny rule regardless of ordering. Option D is wrong because a typo in the Deny statement would only matter if it prevented the Deny from matching the action or resource; the question states the Deny applies, and typos do not convert a Deny into an Allow.

166
MCQmedium

An organization requires that all Amazon S3 buckets be encrypted with AES-256 server-side encryption. A SysOps administrator needs to enforce this policy across the entire AWS account. Which action should be taken?

A.Enable default encryption on all existing and future S3 buckets.
B.Use AWS CloudTrail to monitor uploads without encryption and alert the administrator.
C.Use S3 Inventory to list unencrypted objects and remediate them manually.
D.Apply an S3 bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to AES256.
AnswerD

This bucket policy is the correct preventive control. By using a Deny statement with the s3:x-amz-server-side-encryption condition key and the StringNotEquals operator, S3 evaluates the policy before accepting any PUT and rejects the request unless the header is exactly AES256. This forces every upload—from CLI, SDKs, or other IAM principals—to explicitly request SSE-S3 encryption, and it overrides any default bucket encryption behavior because the policy blocks requests that do not meet the condition.

Why this answer

A bucket policy that denies PutObject without the x-amz-server-side-encryption header set to AES256 will enforce encryption. Option A is wrong because default encryption does not prevent objects from being uploaded without encryption header. Option B is wrong because CloudTrail logs but does not enforce.

Option C is wrong because S3 Inventory does not enforce.

167
Multi-Selecthard

A company is using AWS CloudTrail to log all API calls. The security team wants to ensure that logs are tamper-proof and stored securely. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Write logs to a different AWS account.
B.Encrypt the CloudTrail log files with SSE-KMS.
C.Enable MFA Delete on the S3 bucket.
D.Enable S3 server access logs.
E.Enable CloudTrail log file validation.
AnswersB, E

SSE-KMS encrypts the CloudTrail log files at rest using a customer managed AWS KMS key, so an unauthorized user who gains access to the S3 bucket cannot read the logs without also having kms:Decrypt permissions. This protects the confidentiality of the log data, though it must be paired with log file validation to prove the logs have not been altered.

Why this answer

Option B is correct because enabling SSE-KMS encryption on the S3 bucket that receives CloudTrail logs protects the log files at rest with AWS KMS keys, ensuring confidentiality and helping meet the requirement that logs are stored securely. Option E is correct because CloudTrail log file validation creates a digitally signed digest file for each log, allowing you to verify that logs have not been altered or deleted after delivery, which directly addresses tamper-proofing. Option A is not required for tamper-proofing or secure storage; while a separate account can improve isolation, it is not one of the two actions that specifically ensure integrity and encryption.

Option C (MFA Delete) adds protection against accidental or unauthorized deletion but does not itself make log contents tamper-proof or encrypted. Option D (S3 server access logs) only records access requests to the bucket and does not provide integrity validation or encryption of CloudTrail logs.

Exam trap

SOA-C02 often tests the distinction between access control (who can read/delete) and integrity verification (detecting tampering) — candidates pick MFA Delete or cross-account logging as tamper-proofing, but the exam expects SSE-KMS for confidentiality and log file validation for integrity.

168
MCQmedium

An organization requires that all Amazon S3 buckets block public access entirely. A SysOps administrator needs to ensure that no bucket can be made public, even accidentally. Which approach enforces this control at the organizational level?

A.Apply an S3 Bucket Policy on each bucket that denies public access.
B.Use an AWS Config managed rule 's3-bucket-public-read-prohibited' to detect and remediate public buckets.
C.Enable S3 Block Public Access at the account level and attach an SCP to deny changes to it.
D.Create an IAM policy that denies s3:PutBucketPolicy for all users.
AnswerC

This is the only correct answer because it provides a centralized, preventive, and tamper-proof control. Enabling S3 Block Public Access at the account level immediately denies all public read/write access to every current and future bucket in that account. Attaching an SCP that denies s3:PutAccountPublicAccessBlock and s3:PutBucketPublicAccessBlock prevents users—even those with full S3 permissions—from modifying those settings, because SCPs cannot be overridden by IAM policies within the member account.

Why this answer

S3 Block Public Access at the account level provides a centralized, immutable control that prevents any bucket in the account from being made public, regardless of bucket policies or ACLs. Attaching an SCP (Service Control Policy) to deny changes to these settings ensures that even administrators with full IAM permissions cannot disable the block, enforcing the control at the organizational level across all accounts in the organization.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config rules) with preventive controls (like SCPs and account-level Block Public Access), assuming that detecting and auto-remediating public buckets is equivalent to preventing them from ever becoming public.

How to eliminate wrong answers

Option A is wrong because applying an S3 Bucket Policy on each bucket is not an organizational-level control; it is per-bucket and can be overridden or omitted by users with sufficient permissions, failing to enforce the requirement across all buckets. Option B is wrong because AWS Config managed rules are detective and reactive, not preventive; they can detect and auto-remediate public buckets, but there is a window of exposure before remediation occurs, and the rule can be disabled or modified by authorized users, so it does not enforce a hard block at the organizational level. Option D is wrong because an IAM policy that denies s3:PutBucketPolicy for all users does not prevent public access via bucket ACLs (e.g., granting public read/write via ACLs), and it can be bypassed by users with full administrative privileges who can modify or detach the IAM policy.

169
MCQmedium

A company's security policy requires that all Amazon RDS for PostgreSQL instances be encrypted at rest using AWS Key Management Service (KMS) customer managed keys and have automated backups enabled with a retention period of at least 30 days. A SysOps administrator needs to use AWS Config to automatically detect any RDS instance that is non-compliant with either requirement and automatically remediate it. Which combination of AWS Config managed rules and remediation actions should be used?

A.Use two AWS Config managed rules: 'rds-instance-encrypted' and 'rds-backup-enabled'. Configure each rule with an automatic remediation action that triggers an Amazon CloudWatch alarm, which then invokes an AWS Lambda function to enable encryption and backups.
B.Create custom AWS Config rules as AWS Lambda functions that evaluate the RDS instance configuration. In the Lambda function, if a resource is non-compliant, call the RDS API to enable encryption and modify backup settings.
C.Use the AWS Config managed rules 'rds-instance-encrypted' and 'rds-backup-enabled'. Configure automatic remediation for each rule using the corresponding AWS Systems Manager Automation runbook: 'AWSConfigRemediation-EnableRDSInstanceEncryption' and 'AWSConfigRemediation-EnableRDSInstanceBackup'.
D.Use a single custom AWS Config rule that checks both encryption and backup settings. If non-compliant, trigger an AWS Lambda function that uses the RDS API to configure both settings.
AnswerC

This is the correct approach. Managed rules evaluate compliance, and automatic remediation using Systems Manager Automation runbooks applies the fix without custom code. The runbooks perform the necessary API calls to enable encryption and backups, meeting the policy requirements.

Why this answer

AWS Config managed rules 'rds-instance-encrypted' and 'rds-backup-enabled' natively evaluate encryption and backup compliance. The corresponding AWS Systems Manager Automation runbooks ('AWSConfigRemediation-EnableRDSInstanceEncryption' and 'AWSConfigRemediation-EnableRDSInstanceBackup') provide built-in, automatic remediation without custom code, aligning with the requirement to use managed rules and automatic remediation.

Exam trap

The trap here is that candidates may assume custom Lambda functions are required for complex remediation, but AWS provides pre-built Systems Manager Automation runbooks that integrate directly with AWS Config managed rules for common RDS compliance issues, making custom code unnecessary.

How to eliminate wrong answers

Option A is wrong because triggering a CloudWatch alarm to invoke a Lambda function is an indirect, custom remediation path; AWS Config supports direct automatic remediation via Systems Manager Automation runbooks, making this approach unnecessarily complex and not leveraging native capabilities. Option B is wrong because creating custom AWS Config rules as Lambda functions violates the requirement to use AWS Config managed rules; the question explicitly asks for managed rules, not custom ones. Option D is wrong because using a single custom rule that checks both encryption and backups is not a managed rule, and it requires custom Lambda code for remediation, which contradicts the directive to use managed rules and automatic remediation actions.

170
MCQmedium

A company requires that all API calls to AWS services be logged for compliance. The logs must be stored in a centralized S3 bucket with server-side encryption enabled. Which AWS service should be used to capture the API calls?

A.AWS Config
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the native AWS service designed to log all API activity in an account, including actions taken through the AWS Management Console, SDKs, CLI, and other services. Each event records the identity of the caller, the time of the call, the source IP address, and the request parameters. By enabling a trail, these logs can be delivered to Amazon S3 for long-term storage and integrated with CloudWatch Logs or third-party tools for monitoring and alerting.

Why this answer

AWS CloudTrail records API activity across AWS services, capturing who made what call, from where, and when, and can deliver logs to a centralized S3 bucket with SSE enabled. It is the designated service for auditing API calls for compliance.

Exam trap

SOA-C02 often tests the confusion between CloudTrail (API activity auditing) and AWS Config (resource configuration/compliance) or VPC Flow Logs (network traffic), especially when the question emphasizes 'API calls' and 'compliance.'

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance against rules — it does not log API calls themselves. Option C is wrong because VPC Flow Logs capture IP traffic metadata (source/dest IP, ports, bytes) for network interfaces, not AWS API calls. Option D is wrong because CloudWatch Logs is a log aggregation and monitoring service; while CloudTrail can deliver to CloudWatch Logs, CloudWatch Logs itself does not capture API calls.

171
MCQmedium

A company wants to enforce that all Amazon EC2 instances launched in the AWS account must have a specific termination protection setting enabled. The SysOps administrator needs to automatically remediate any instances that are launched without termination protection. Which AWS service should be used to achieve this?

A.AWS Config with a managed rule ec2-instance-no-public-ip and an SSM Automation remediation.
B.AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.
C.Amazon Inspector to scan instances and trigger a remediation action.
D.AWS Systems Manager Patch Manager to apply a policy for termination protection.
AnswerB

A custom AWS Config rule can use a Lambda function to check if an EC2 instance has termination protection enabled. If not, the function can call the EC2 API to enable it. This provides automatic remediation for non-compliant resources.

Why this answer

AWS Config can evaluate resources against desired configurations using managed or custom rules. A custom AWS Config rule can invoke a Lambda function to check if termination protection is enabled on EC2 instances and automatically enable it if missing, providing the required remediation. This approach directly addresses the requirement to enforce termination protection on all launched instances.

Exam trap

The trap here is that candidates may confuse AWS Config's managed rules (which cover common compliance checks) with the need for a custom rule and Lambda function to enforce a specific setting like termination protection, or mistakenly think services like Inspector or Patch Manager can handle configuration enforcement.

How to eliminate wrong answers

Option A is wrong because the ec2-instance-no-public-ip rule checks for public IPs, not termination protection, and SSM Automation remediation is not designed to enable termination protection on EC2 instances. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposures, not for enforcing instance configuration settings like termination protection. Option D is wrong because AWS Systems Manager Patch Manager is used to automate patching of operating systems and applications, not to apply termination protection policies to EC2 instances.

172
MCQeasy

A company requires that all Amazon EC2 instances launched in its AWS account must have termination protection enabled. The SysOps administrator needs to automatically remediate any instance launched without termination protection. The solution should use AWS managed services without custom scripts. Which AWS service should be used?

A.Configure AWS Config with a managed rule 'ec2-termination-protection-check' and set an auto-remediation action using an AWS Systems Manager Automation document that enables termination protection on the instance.
B.Use Amazon EC2 Auto Scaling to automatically apply termination protection to all launched instances.
C.Enable AWS Trusted Advisor to send notifications when instances lack termination protection, and have administrators manually fix them.
D.Create an IAM policy that denies the RunInstances action unless termination protection is enabled.
AnswerA

AWS Config's managed rule ec2-termination-protection-check continuously evaluates each EC2 instance against the required configuration, flagging any instance without termination protection as non-compliant. When non-compliance is detected, the associated auto-remediation action invokes an AWS Systems Manager Automation document, such as AWS-EnableEC2TerminationProtection, which calls the ModifyInstanceAttribute API to enable DisableApiTermination on the instance. This serverless, event-driven workflow automatically corrects drift without custom scripts or manual intervention, fully satisfying the company's requirement for automatic remediation.

Why this answer

AWS Config's managed rule 'ec2-termination-protection-check' can detect instances without termination protection, and you can attach an auto-remediation action using an AWS Systems Manager Automation document (e.g., AWS-EnableTerminationProtection) to automatically enable termination protection on noncompliant instances. This solution uses only AWS managed services and requires no custom scripts, meeting the company's requirements.

Exam trap

The trap here is that candidates may confuse AWS Config's detection-only capability with its auto-remediation feature, or assume that IAM policies can enforce instance-level attributes at launch time, when in fact IAM conditions like 'ec2:DisableApiTermination' are not supported for the RunInstances action.

How to eliminate wrong answers

Option B is wrong because Amazon EC2 Auto Scaling does not have a native feature to automatically apply termination protection to all launched instances; it manages scaling policies and health checks, not instance attribute remediation. Option C is wrong because AWS Trusted Advisor only provides notifications and recommendations, not automated remediation; it requires manual intervention by administrators, which violates the requirement for automatic remediation. Option D is wrong because an IAM policy that denies RunInstances unless termination protection is enabled would prevent launching instances without termination protection, but it does not remediate instances already launched without it; additionally, IAM policies cannot enforce instance-level attributes like termination protection at launch time in a granular way, and the requirement is to remediate after launch, not prevent.

173
MCQmedium

A SysOps administrator needs to provide temporary, limited-privilege credentials to an application running on an EC2 instance. The application needs to access an S3 bucket. What is the most secure way to grant these credentials?

A.Use a Lambda function to generate temporary credentials from an IAM user.
B.Store the AWS access keys in an S3 bucket and have the application download them at startup.
C.Attach an IAM role with the necessary permissions to the EC2 instance.
D.Create an IAM user with programmatic access and store the access keys in the application's environment variables.
AnswerC

Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended way to grant AWS API access to applications running on that instance. The AWS SDK and CLI automatically retrieve short-lived credentials from the instance metadata service (IMDSv2) and refresh them before they expire, so no secrets are stored in code, configuration, or environment variables. These credentials carry only the permissions defined in the role, and the role can be updated without changing the instance.

Why this answer

Attaching an IAM role to an EC2 instance is the most secure method because it leverages the AWS Security Token Service (STS) to automatically rotate temporary credentials. The instance retrieves these credentials via the instance metadata service (IMDS), eliminating the need to hardcode, store, or manually manage long-term access keys. This approach follows the principle of least privilege and ensures credentials are automatically rotated and revoked when the role is detached.

Exam trap

The trap here is that candidates may think storing keys in environment variables or S3 is acceptable because it 'works', but the SOA-C02 exam specifically tests the understanding that IAM roles with EC2 instance profiles are the only secure, AWS-recommended method for providing temporary credentials to applications running on EC2, avoiding the pitfalls of long-term static keys.

How to eliminate wrong answers

Option A is wrong because using a Lambda function to generate temporary credentials from an IAM user still requires the IAM user's long-term access keys to be stored somewhere (e.g., in Lambda environment variables), which introduces a static credential risk and adds unnecessary complexity. Option B is wrong because storing AWS access keys in an S3 bucket and having the application download them at startup exposes the keys to potential interception, requires managing bucket policies and encryption, and still relies on long-term credentials that do not rotate automatically. Option D is wrong because creating an IAM user with programmatic access and storing the access keys in environment variables embeds long-term static credentials that are not automatically rotated, increasing the risk of exposure and violating the security best practice of using temporary credentials for EC2 workloads.

174
MCQhard

A company has an AWS account with multiple VPCs connected via a transit gateway. The SysOps administrator needs to ensure that all traffic between VPCs is encrypted in transit. Which solution should the administrator implement?

A.Use VPC peering connections between the VPCs.
B.Use VPC endpoints to route traffic through AWS PrivateLink.
C.Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.
D.Configure network ACLs to deny unencrypted traffic.
AnswerC

AWS Site-to-Site VPN connections establish IPsec tunnels that encrypt all traffic between the connected sites. By attaching these VPN connections to a transit gateway, you can interconnect multiple VPCs and route private traffic through those encrypted tunnels, achieving confidentiality for inter-VPC communication. This is the correct approach because the VPN terminates IPsec encryption at the transit gateway, and the transit gateway handles routing between all attached VPCs and VPN connections.

Why this answer

AWS Site-to-Site VPN connections between VPCs via a transit gateway can enforce IPsec encryption for all inter-VPC traffic. The transit gateway acts as a central hub, and each VPN connection encrypts traffic using IPsec tunnels, ensuring data confidentiality and integrity in transit. This meets the requirement for encrypted transit between VPCs without relying on third-party appliances.

Exam trap

The trap here is that candidates often assume VPC peering provides encryption by default, but AWS does not encrypt traffic over peering connections; encryption must be explicitly added via VPN or other mechanisms.

How to eliminate wrong answers

Option A is wrong because VPC peering connections do not provide encryption in transit by default; traffic between peered VPCs traverses the AWS network without IPsec or TLS encryption. Option B is wrong because VPC endpoints with AWS PrivateLink are used to privately access specific AWS services or your own services, not to route general inter-VPC traffic, and they do not inherently encrypt all traffic between VPCs. Option D is wrong because network ACLs are stateless firewalls that filter traffic based on IP addresses and ports but do not encrypt traffic; they cannot enforce encryption of the data payload.

175
MCQmedium

A SysOps administrator is troubleshooting an issue where an IAM user can launch EC2 instances but cannot terminate them. The user's permissions are based on an IAM group policy. Which action should the administrator take to resolve this?

A.Attach a managed policy that includes ec2:TerminateInstances directly to the user
B.Add the user to a different IAM group that has the required permissions
C.Check the user's permissions boundary for any restrictions
D.Review and modify the IAM group policy to include ec2:TerminateInstances action
AnswerD

The most likely root cause is that the IAM group policy attached to the user's group does not include an ec2:TerminateInstances action, so modifying that policy to allow the API call resolves the issue for every member of the group. Use a statement with "Effect": "Allow" for ec2:TerminateInstances on the appropriate resource, then test with the IAM policy simulator to verify effective access.

Why this answer

Since the user's permissions come from an IAM group policy, the missing ec2:TerminateInstances action must be added to that group policy — that's the source of the user's effective permissions. Modifying the group policy grants the permission to all members consistently and follows AWS best practice of managing permissions at the group level.

Exam trap

SOA-C02 often tests whether candidates jump to user-level policy attachments instead of fixing the group policy that is explicitly identified as the permission source — the exam rewards least-disruption, best-practice fixes.

How to eliminate wrong answers

Option A is wrong because attaching a managed policy directly to the user bypasses the group-based model and creates permission sprawl; while it would technically work, it's not the correct administrative action when the group policy is the identified source. Option B is wrong because moving the user to a different group is disruptive and unnecessary when the existing group policy can simply be corrected. Option C is wrong because a permissions boundary would restrict permissions, but the scenario states permissions are based on a group policy — there's no indication of a boundary, and checking it doesn't resolve the missing action.

176
MCQhard

A company is using AWS CodePipeline to deploy a web application. The security team requires that all code changes be reviewed and approved before deployment to production. Which action should be taken to enforce this requirement?

A.Add a manual approval action in the CodePipeline pipeline before the production deployment stage.
B.Create an IAM policy that denies the codecommit:PutFile action unless the user is in a specific group.
C.Enable AWS CloudTrail and create a CloudWatch Events rule to notify the security team of any deployments.
D.Configure a CodeCommit repository to require pull requests for all changes.
AnswerA

A manual approval action is the only option that inserts a human decision gate directly into the CodePipeline execution. You configure an approval action by adding a stage of type 'Approval' with an SNS topic; the pipeline pauses once that stage is reached and sends a notification to the approver(s). The approver must have IAM permissions for codepipeline:PutApprovalResult to approve or reject, and the pipeline does not proceed to the production deployment stage until that explicit approval is granted. This enforces separation of duties and prevents unverified code from reaching production.

Why this answer

Adding a manual approval action in the CodePipeline pipeline before the production deployment stage enforces a required review and approval gate. This action pauses the pipeline at that point, waiting for an authorized user to manually approve the change before it proceeds to the production stage, directly meeting the security team's requirement.

Exam trap

The trap here is that candidates often confuse source-level controls (like pull request requirements or IAM policies) with pipeline-level approval gates, mistakenly thinking that preventing direct pushes or requiring pull requests alone satisfies the deployment approval requirement.

How to eliminate wrong answers

Option B is wrong because denying the codecommit:PutFile action prevents users from pushing code directly to the repository, but it does not enforce a review and approval process within the deployment pipeline; it only restricts write access. Option C is wrong because enabling CloudTrail and creating a CloudWatch Events rule only provides notification of deployments after they occur, not a pre-deployment approval gate. Option D is wrong because configuring a CodeCommit repository to require pull requests for all changes enforces code review at the source code level, but it does not add an approval step within the CodePipeline deployment pipeline itself.

177
MCQeasy

A SysOps administrator needs to grant a developer access to view only the logs of a specific Amazon RDS instance. Which IAM action should be allowed?

A.rds:DownloadDBLogFilePortion
B.rds:DescribeDBInstances
C.rds:DescribeDBLogFiles
D.rds:DescribeEvents
AnswerA

rds:DownloadDBLogFilePortion permits retrieving individual log file contents for the specified RDS instance, giving read-only visibility without granting modify or delete permissions. This satisfies the least-privilege requirement of viewing only logs, unlike broader rds actions that expose instance configuration or management.

Why this answer

`rds:DownloadDBLogFilePortion` grants permission to download and view the contents of a log file for a specific RDS instance. The question asks for the action to 'view only the logs', which requires retrieving the log file content. `rds:DescribeDBLogFiles` only lists available log files, not the actual log data. Therefore, to view logs, the developer needs the `DownloadDBLogFilePortion` permission.

Exam trap

The trap here is that candidates often think `rds:DescribeDBLogFiles` (Option C) is sufficient to view logs, but it only lists log files. To actually view the log content, you need `rds:DownloadDBLogFilePortion`. The question specifies 'view only the logs', which implies viewing the content, not just listing files.

How to eliminate wrong answers

Option A is wrong because `rds:DownloadDBLogFilePortion` allows downloading the actual content of a log file, which is more than just viewing — it permits retrieval of log data, and the question specifies 'view only', so this action would grant excessive permissions. Option B is wrong because `rds:DescribeDBInstances` provides metadata about the DB instance (e.g., endpoint, engine, storage) but does not include log file information, so it cannot be used to view logs. Option D is wrong because `rds:DescribeEvents` returns events related to the DB instance (e.g., maintenance, backups) and has no relation to log files or log viewing.

178
Multi-Selecteasy

A company needs to comply with PCI DSS requirements for its AWS environment. Which TWO services should the SysOps administrator use to automate compliance checks and generate reports? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch
B.AWS Config
C.AWS CloudTrail
D.AWS Trusted Advisor
E.AWS Audit Manager
AnswersB, E

AWS Config continuously records the configuration state of supported AWS resources and evaluates those configurations against AWS-managed or custom rules. For PCI DSS, you can use the managed rule pack to check for requirements like encrypted storage, restricted security group rules, and MFA on root accounts, then view the overall compliance snapshot over time. It generates a compliance timeline and aligned findings, making it the core service for automated configuration compliance.

Why this answer

AWS Config (B) is correct because it continuously records resource configuration changes and evaluates them against managed or custom rules, such as the PCI DSS conformance pack, which automates compliance checks against AWS resources. AWS Audit Manager (E) is correct because it automates evidence collection and produces audit-ready reports mapped to frameworks like PCI DSS, which is exactly what the company needs for generating compliance reports. Amazon CloudWatch (A) is for metrics, logs, and alarms, not compliance evaluation or audit reporting.

AWS CloudTrail (C) records API activity for auditing but does not itself perform automated compliance checks or generate compliance reports. AWS Trusted Advisor (D) provides best-practice recommendations across cost, security, and limits, but it is not a PCI DSS compliance automation or reporting service.

Exam trap

SOA-C02 often tests the distinction between services that detect (Config, CloudTrail, GuardDuty) and services that report/assess (Audit Manager) — candidates who pick CloudTrail for 'compliance checks' miss that CloudTrail only logs API calls and does not evaluate compliance.

179
MCQeasy

An organization wants to centrally manage access to multiple AWS accounts in an AWS Organizations setup. Which AWS service should the SysOps administrator use to define and enforce fine-grained permissions across accounts?

A.AWS Config rules
B.Service control policies (SCPs)
C.IAM roles with cross-account trust policies
D.AWS Single Sign-On (SSO)
AnswerC

IAM roles are the correct mechanism because a role in a target account can attach a permissions policy that precisely defines allowable actions and resources, and a trust policy in the same role lists which principals in a central account may assume it. When a user in the central account calls sts:AssumeRole, AWS returns temporary, scoped credentials that carry exactly the role's permissions, no more and no less. This gives fine-grained control while centralizing the decision about who gets to assume which role.

Why this answer

IAM roles with cross-account trust policies allow a SysOps administrator to define fine-grained permissions centrally in a single AWS account (the management or security account) and then grant access to users or services in other accounts by assuming the role. This approach uses AWS Security Token Service (STS) to issue temporary credentials, enabling precise control over actions and resources across accounts without duplicating IAM users or policies.

Exam trap

The trap here is that candidates often confuse Service Control Policies (SCPs) with fine-grained permission enforcement, but SCPs only set guardrails and cannot grant cross-account access or define granular user-level permissions, which is the core requirement of this question.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configurations for compliance against desired policies (e.g., checking if S3 buckets are public) but do not define or enforce permissions for user or role actions across accounts; they are auditing tools, not access control mechanisms. Option B is wrong because Service Control Policies (SCPs) set maximum permission boundaries for all IAM entities in an AWS Organizations member account, but they cannot grant or deny specific actions at the user or role level—they only filter what is allowed by IAM policies, and they do not provide cross-account access delegation. Option D is wrong because AWS Single Sign-On (SSO) centralizes user authentication and assigns permissions via IAM roles or permission sets, but it does not directly define fine-grained permissions across accounts; it relies on IAM roles with trust policies to enable access, making it a management layer rather than the core service for enforcing permissions.

180
Multi-Selectmedium

A company has an S3 bucket that stores sensitive data. The security team requires that all access to the bucket be encrypted in transit. Which TWO actions should be taken to enforce this requirement? (Choose two.)

Select 2 answers
A.Enable default encryption (SSE-S3) on the bucket
B.Enable S3 Transfer Acceleration
C.Enable AWS CloudTrail to log all S3 API calls and set up a CloudWatch alarm for any HTTP access
D.Create an S3 bucket policy that denies s3:GetObject and s3:PutObject if the aws:SecureTransport condition is false
E.Use S3 VPC endpoints
AnswersC, D

CloudTrail logs every S3 API call, and the event record includes the aws:SecureTransport flag, which distinguishes HTTPS from HTTP. A CloudWatch alarm on that flag lets the company immediately detect and respond to any plaintext request. As a detective control, it does not block the request at the time, but it satisfies the requirement by enabling continuous monitoring for HTTPS-only access.

Why this answer

Enabling AWS CloudTrail to log all S3 API calls and setting up a CloudWatch alarm for any HTTP access allows the security team to detect and alert on any access that is not encrypted in transit (i.e., HTTP instead of HTTPS). This provides monitoring and incident response capability to enforce the encryption-in-transit requirement.

Exam trap

The trap here is confusing encryption at rest (SSE-S3) with encryption in transit (HTTPS/SSL), leading candidates to select default encryption instead of the bucket policy condition or monitoring approach.

181
MCQhard

A company uses AWS Organizations and has multiple accounts. The security team requires that all Amazon S3 buckets across all accounts must be encrypted at rest with AWS KMS (SSE-KMS). The SysOps administrator needs to automatically detect non-compliant buckets and remediate them by enabling SSE-KMS. The solution must work across all existing and future accounts. Which AWS service should be used?

A.AWS Config with a managed rule and an automatic remediation action using AWS Systems Manager Automation.
B.AWS CloudTrail with a metric filter and Amazon CloudWatch alarm to trigger a Lambda function.
C.AWS Trusted Advisor to check S3 bucket encryption and send notifications.
D.Amazon Macie to discover sensitive data and then manually encrypt buckets.
AnswerA

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates whether every S3 bucket has default encryption configured. When a bucket is found non-compliant, Config's automatic remediation feature can invoke an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) to apply SSE-KMS to that bucket. Because Config is state-based, it detects both pre-existing non-compliant buckets and buckets that drift after creation. With AWS Organizations, you can deploy the rule and remediation across all accounts using CloudFormation StackSets, and aggregators centralize compliance visibility.

Why this answer

AWS Config with the managed rule 's3-bucket-server-side-encryption-enabled' can evaluate all S3 buckets across accounts in an AWS Organization. When a non-compliant bucket is detected, an automatic remediation action using an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') can enable SSE-KMS without manual intervention. This solution scales to existing and future accounts because AWS Config can be set up as an aggregator across the organization, and remediation actions apply automatically as new accounts are added.

Exam trap

The trap here is that candidates often confuse detection-only services (like Trusted Advisor or CloudTrail) with services that can both detect and automatically remediate, or they mistakenly think Macie handles encryption compliance when it actually focuses on data classification.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail with a metric filter and CloudWatch alarm only detects API calls (e.g., PutBucketEncryption) after they occur; it cannot proactively detect non-compliant buckets or automatically remediate them without a custom Lambda function, and it does not provide continuous compliance evaluation across all accounts. Option C is wrong because AWS Trusted Advisor checks S3 bucket encryption only for the root account or linked accounts in a support plan, but it does not support automatic remediation—it only sends notifications, and it cannot enforce encryption across all accounts in an organization. Option D is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII) in S3 buckets, not to check or enforce encryption settings; it requires manual intervention to encrypt buckets and does not provide automated detection or remediation of non-compliant encryption.

182
MCQhard

A company manages multiple AWS accounts using AWS Organizations. The security team wants to restrict the use of Amazon EC2 instance types to only those that are approved for production workloads (e.g., m5.large, m5.xlarge). The policy should be applied to all member accounts in the organization, and it should prevent any non-approved instance type from being launched. The SysOps administrator should implement this with minimal operational overhead. Which solution should be used?

A.Create an IAM policy in each member account that denies ec2:RunInstances unless the instance type is in the approved list.
B.Create an AWS Organizations Service Control Policy (SCP) that denies ec2:RunInstances if the instance type is not in the approved list.
C.Use AWS Config with the managed rule 'ec2-instance-type-check' and an automatic remediation action that terminates non-compliant instances.
D.Use Amazon EventBridge to detect RunInstances API calls and invoke a Lambda function that terminates unapproved instances.
AnswerB

An SCP attached to the organization root, OUs, or individual accounts acts as a preventive guardrail: the deny effect applies to every principal, including the root user. Using a condition such as StringNotEquals on ec2:InstanceType with the approved list, the policy rejects any RunInstances call that uses a non-approved type before the API call can succeed. Because SCPs are inherited and cannot be bypassed by IAM permissions, this gives consistent, low-overhead enforcement across all current and future accounts.

Why this answer

AWS Organizations Service Control Policies (SCPs) can centrally enforce restrictions across all member accounts without requiring per-account configuration. By creating an SCP that denies ec2:RunInstances when the instance type is not in the approved list, the security team can prevent non-approved EC2 instance types from being launched with minimal operational overhead, as SCPs are applied at the organization, OU, or account level and do not require managing IAM policies in each account.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking that SCPs grant permissions, but SCPs only act as a guardrail to restrict permissions, and they must be combined with appropriate IAM policies to allow actions; additionally, candidates may choose reactive solutions like AWS Config or EventBridge because they are familiar, but the question explicitly asks for a preventive control with minimal overhead.

How to eliminate wrong answers

Option A is wrong because creating an IAM policy in each member account introduces significant operational overhead, as it requires manual or automated deployment to every account, and IAM policies can be overridden by account administrators with full permissions, whereas SCPs provide a guardrail that cannot be bypassed by account-level IAM. Option C is wrong because AWS Config with the 'ec2-instance-type-check' rule is a detective control that only identifies non-compliant instances after launch, and automatic remediation via termination is reactive, not preventive, and can lead to resource churn and potential data loss; it also requires additional setup for remediation actions. Option D is wrong because using EventBridge to detect RunInstances API calls and invoking a Lambda function to terminate unapproved instances is a reactive, event-driven approach that still allows the instance to be launched momentarily, incurs additional cost and complexity, and does not prevent the API call from succeeding in the first place.

183
MCQhard

A company uses AWS Organizations to manage multiple AWS accounts. The security team wants to restrict access to a specific AWS service (Amazon EC2) in all accounts except for the 'production' account. The SysOps administrator needs to implement this restriction centrally. Which approach should the administrator use?

A.Create an IAM policy that denies Amazon EC2 actions and attach it to all users and roles in non-production accounts.
B.Attach a service control policy (SCP) to the organization root or to the OUs of non-production accounts that denies access to Amazon EC2.
C.Use AWS Config to create a rule that detects EC2 usage in non-production accounts and automatically terminates instances.
D.Create a resource-based policy on each EC2 instance that denies access from non-production accounts.
AnswerB

SCPs are a centralized way to set permission boundaries for all accounts in the organization. By denying EC2 actions via SCP on non-production OUs, the restriction is enforced even for the root user of those accounts, and it applies to all IAM principals.

Why this answer

Service control policies (SCPs) are the correct mechanism for centrally restricting permissions across accounts in AWS Organizations. By attaching an SCP that denies EC2 actions to the organization root or to the OUs containing non-production accounts, the security team can enforce this restriction at the account level, overriding any IAM policies within those accounts. This approach ensures that even if a user or role in a non-production account has an IAM policy granting EC2 access, the SCP will block it.

Exam trap

The trap here is that candidates often confuse IAM policies (which are identity-based and account-specific) with SCPs (which are account-wide and centrally managed), leading them to choose Option A because they think attaching a deny policy to users is sufficient, but they overlook that SCPs provide the only centralized, preventive control across multiple accounts in AWS Organizations.

How to eliminate wrong answers

Option A is wrong because IAM policies attached to users and roles are not centrally managed across multiple accounts; they must be applied individually in each account, which is not a centralized solution and can be bypassed by local administrators. Option C is wrong because AWS Config is a detective service that can detect and react to EC2 usage (e.g., via auto-remediation), but it does not prevent the initial creation or use of EC2 resources; it only responds after the fact, which is not a preventive restriction. Option D is wrong because resource-based policies on EC2 instances control access to the instance itself (e.g., who can start/stop it), not the ability to launch or manage EC2 services in an account; they are also not centrally managed across accounts.

184
MCQeasy

A company's security policy requires that only traffic from the corporate office IP range (203.0.113.0/24) can access an Amazon S3 bucket that stores internal reports. The SysOps administrator must enforce this restriction. Which policy type should be modified to implement this requirement?

A.IAM identity-based policy
B.VPC endpoint policy
C.S3 bucket policy
D.AWS Organizations SCP
AnswerC

An S3 bucket policy is a resource-based policy that can be directly associated with the target bucket. By setting the Principal to '*' and adding a condition key of aws:SourceIp with the allowed CIDR ranges, the bucket denies any request that does not originate from those addresses, regardless of whether the requester is an IAM user, an anonymous caller, or a service. This is the most precise and comprehensive way to enforce an IP-based allowlist at the bucket level.

Why this answer

An S3 bucket policy is the correct choice because it allows you to explicitly deny or allow access to the S3 bucket based on the source IP address using the `aws:SourceIp` condition key. This policy is attached directly to the bucket and can restrict access to only the corporate office IP range (203.0.113.0/24), regardless of the IAM user or role making the request. It enforces the security requirement at the resource level, which is the most direct and effective method for controlling network-based access to an S3 bucket.

Exam trap

The trap here is that candidates often confuse IAM identity-based policies with resource-based policies, mistakenly thinking they can use IAM policies to restrict by source IP, when in fact only S3 bucket policies (or similar resource-based policies) support the `aws:SourceIp` condition for network-level access control.

How to eliminate wrong answers

Option A is wrong because IAM identity-based policies are attached to users, groups, or roles and control what actions those identities can perform, but they cannot restrict access based on the source IP address of the requestor; they lack the `aws:SourceIp` condition key for network-level control. Option B is wrong because a VPC endpoint policy controls access to S3 from a specific VPC endpoint, but it does not allow you to specify a source IP range like 203.0.113.0/24; it only restricts access based on the VPC or endpoint ID, not the client's IP address. Option D is wrong because AWS Organizations SCPs are used to set permission boundaries across accounts in an organization, but they cannot enforce IP-based restrictions on a specific S3 bucket; they operate at the account or organizational unit level, not at the resource level.

185
Multi-Selectmedium

A company is using AWS KMS to encrypt data at rest. Which TWO actions can be taken to audit the usage of a customer managed key?

Select 2 answers
A.Enable AWS CloudTrail to log KMS API calls.
B.Enable Amazon S3 server access logs to track KMS operations.
C.Use IAM Access Analyzer to review KMS key policies.
D.Stream CloudTrail logs to Amazon CloudWatch Logs and create metric filters for KMS events.
E.Use AWS Config rules to monitor KMS key usage.
AnswersA, D

AWS CloudTrail is the authoritative audit service for KMS because every KMS API operation—including Encrypt, Decrypt, GenerateDataKey, and CreateKey—is captured as an event containing the principal, source IP, request parameters, and response. These events are delivered to an S3 bucket as JSON files, providing a durable, tamper-evident record that supports compliance and security investigations. Enabling a trail that records management events is sufficient for KMS, as KMS data-plane calls are automatically logged as management events.

Why this answer

AWS CloudTrail captures all KMS API calls (e.g., Encrypt, Decrypt, GenerateDataKey) as events, providing a complete audit trail of who used the key, when, and from which source. By enabling CloudTrail, you can review these logs to audit customer managed key usage. This is the primary method for auditing KMS key operations.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which check configuration compliance) with actual usage auditing, or they think S3 server access logs can capture KMS operations when they only log S3-level requests, not the underlying KMS API calls.

186
Multi-Selecthard

A company wants to use AWS WAF to protect a web application behind an Application Load Balancer. Which of the following can AWS WAF inspect? (Choose all that apply.)

Select 4 answers
A.HTTP headers
B.Query string parameters
C.SSL certificate of the client
D.Request body of HTTPS requests
E.URI path
AnswersA, B, D, E

HTTP headers are one of the key web request components that AWS WAF natively inspects. You can create rules that match on header names and values, such as checking the User-Agent header for known bot signatures or the Authorization header for invalid tokens. WAF supports string matching, regex pattern sets, and size constraints on header values, providing flexible control over header-based threats.

Why this answer

AWS WAF inspects the HTTP request components that reach the Application Load Balancer, and HTTP headers (Option A) are one of the core inspectable request parts used in rules such as header-match statements. Query string parameters (Option B) are also inspectable, allowing rules to match on keys/values in the URL query, which is essential for blocking injection or abuse patterns. The request body of HTTPS requests (Option D) can be inspected because AWS WAF supports body inspection (with size limits and sampling behavior) even though the traffic is TLS-encrypted at the ALB, since WAF evaluates the decrypted HTTP request.

The URI path (Option E) is inspectable via URI-path match conditions, enabling rules that target specific endpoints or path patterns. Option C is not correct because AWS WAF does not inspect the client's SSL/TLS certificate; client certificate handling/validation is a function of the load balancer's mutual TLS configuration, not a WAF match condition.

Exam trap

Candidates may mistakenly think that the request body of HTTPS requests cannot be inspected, but AWS WAF can inspect it when used with an Application Load Balancer because the ALB decrypts the traffic before forwarding to WAF.

187
MCQhard

An application stores its RDS PostgreSQL credentials in AWS Secrets Manager. The security policy requires credentials to be rotated every 30 days automatically. During rotation, the application must continue to serve traffic with zero downtime. The application retrieves credentials by calling GetSecretValue at the start of each database connection. What must be configured to satisfy all requirements?

A.Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials
B.Rotate credentials manually every 30 days by updating the secret value in the console and restarting the application
C.Create an EventBridge scheduled rule every 30 days that triggers a Lambda to generate a new RDS password and update both the database and the secret
D.Store credentials in an environment variable on the application's EC2 instance and rotate by updating the environment variable and reloading the application
AnswerA

The AWS-provided rotation Lambda handles the full four-step lifecycle. The 30-day rotation schedule triggers the Lambda automatically. Because the application fetches credentials fresh per connection, it starts using the new credentials immediately after AWSCURRENT switches, with no restart needed. Secrets Manager's rotation is designed for zero downtime — the new password is validated on the database before the old version is retired.

Why this answer

AWS Secrets Manager's automatic rotation, combined with the AWS-provided Lambda rotation function for RDS PostgreSQL, ensures credentials are rotated every 30 days without manual intervention. The application's practice of calling GetSecretValue at the start of each database connection guarantees it always retrieves the current secret, avoiding stale credentials and achieving zero downtime during rotation.

Exam trap

The trap here is that candidates may think any automated rotation (like EventBridge + Lambda) suffices, but the question specifically tests the integration of Secrets Manager's native rotation with its versioning and staging labels to achieve zero downtime.

How to eliminate wrong answers

Option B is wrong because manual rotation every 30 days with a console update and application restart violates the zero-downtime requirement; restarting the application causes service interruption. Option C is wrong because while it implements rotation via EventBridge and Lambda, it does not use Secrets Manager's built-in rotation mechanism, missing the automatic version management and staging labels (AWSCURRENT, AWSPREVIOUS) that ensure seamless credential transition. Option D is wrong because storing credentials in an environment variable on EC2 and rotating by updating the variable and reloading the application introduces downtime and bypasses Secrets Manager's secure storage, auditing, and rotation capabilities.

188
Multi-Selectmedium

A SysOps administrator is configuring CloudTrail to log all management events and data events for S3 buckets. Which of the following are true about CloudTrail logging? (Choose THREE.)

Select 3 answers
A.Data events for S3 are logged by default for all buckets
B.CloudTrail logs include the identity of the user who made the API call
C.Management events are logged by default
D.CloudTrail can log events for all AWS services automatically
E.CloudTrail can deliver log files to CloudWatch Logs for real-time analysis
AnswersB, C, E

CloudTrail logs capture the full userIdentity element for every API call, including the IAM user or role, root user, federated user, or assumed role. It also records the access key ID, source IP address, user agent, and session context, enabling you to determine exactly who performed an action. This makes CloudTrail essential for security auditing and governance.

Why this answer

CloudTrail logs include the identity of the user or role that made the API call, captured as the `userIdentity` element in the log record. This element contains details such as the ARN, access key ID, and whether the call was made by an IAM user, federated user, or assumed role, enabling full auditability of who performed each action.

Exam trap

The trap here is that candidates often assume data events are logged by default because S3 is a core service, but CloudTrail requires explicit opt-in for data events, and management events are the only ones enabled by default.

189
MCQeasy

A SysOps administrator is troubleshooting an issue where an IAM user cannot launch an EC2 instance. The user has a policy that allows ec2:RunInstances. What is the most likely cause of the failure?

A.The user does not have permissions for supporting actions like CreateNetworkInterface.
B.The user is not using multi-factor authentication (MFA).
C.The user does not have permission to use the KMS key for encryption.
D.The policy is attached to a group instead of the user.
AnswerA

Launching an instance via RunInstances is a complex API call that implicitly requires permission for several supporting EC2 actions, including CreateNetworkInterface, DescribeSubnets, DescribeVpcs, and CreateTags. If the IAM policy grants only "ec2:RunInstances" without including these supporting actions, the call will fail with an UnauthorizedOperation or dependency error. Thus a user with the RunInstances permission can still be blocked because the instance launch cannot complete without the ability to create and attach the necessary network interfaces.

Why this answer

Launching an EC2 instance requires more than just ec2:RunInstances — the principal also needs permissions for dependent actions such as ec2:CreateNetworkInterface, ec2:DescribeImages, ec2:DescribeSubnets, and ec2:DescribeSecurityGroups, depending on the launch configuration. If the policy only grants ec2:RunInstances, the launch fails with an UnauthorizedOperation error on the supporting action. This is the most likely cause given the scenario.

Exam trap

SOA-C02 often tests the misconception that a single allow action (ec2:RunInstances) is sufficient for a composite operation — candidates overlook the dependent actions that EC2 requires under the hood, so they pick MFA or KMS as the cause instead of the missing supporting permissions.

How to eliminate wrong answers

Option B is wrong because MFA is not required by default to launch EC2 instances; while a policy could enforce MFA via aws:MultiFactorAuthPresent, the question states the user has a policy allowing ec2:RunInstances, and MFA absence would produce a different, explicit error only if such a condition existed. Option C is wrong because KMS permissions are only needed if the instance uses an encrypted EBS volume with a customer-managed key; the scenario does not mention encryption, and the default EBS encryption uses the AWS-managed key which does not require explicit KMS grants. Option D is wrong because IAM policies attached to a group are inherited by group members — attaching a policy to a group rather than directly to the user is a valid and common configuration and would not cause a permission failure.

190
MCQhard

An S3 bucket policy is shown in the exhibit. The AdminRole attempts to upload an object to my-bucket without specifying any server-side encryption header. What will happen?

A.The upload fails because the Allow statement requires encryption, but the Deny statement is evaluated first.
B.The upload succeeds because the Allow statement grants permission to the AdminRole.
C.The upload succeeds because the Deny statement does not apply to the AdminRole.
D.The upload fails because the Deny statement denies PutObject without encryption.
AnswerD

Option 4 is correct because the Deny statement explicitly denies the s3:PutObject action when the request is not protected with server-side encryption using AWS KMS (aws:kms). Since the upload in the scenario is performed without that encryption header, the Deny statement's condition matches the request, and an explicit Deny overrides any Allow from the same bucket policy or from the role's own IAM policies. Therefore, the upload fails with an AccessDenied error.

Why this answer

The Deny statement denies PutObject when encryption is not aws:kms. Since the request has no encryption header, it does not equal aws:kms, so the Deny applies and the upload fails. The Allow statement allows the action only when encryption is aws:kms, so without encryption, it does not apply.

Because the Deny overrides Allow, the upload is denied. Option A is wrong because the Allow does not apply. Option B is wrong because the Deny applies.

Option C is wrong because the Deny does apply to the AdminRole.

191
Multi-Selecthard

A company wants to audit all AWS account activity for compliance. Which THREE AWS services should be used together to achieve this? (Choose three.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.AWS Trusted Advisor
D.Amazon GuardDuty
E.AWS CloudTrail
AnswersA, B, E

CloudWatch Logs stores, monitors, and queries log data from applications and AWS services, including CloudTrail events, VPC flow logs, and custom logs. You can create metric filters to detect patterns and set alarms for compliance-related events. While it does not natively generate API activity records, it is essential for centralizing and retaining audit logs for operational analysis and alerting. In this scenario, CloudWatch Logs can be used to ingest trail logs for monitoring, but the actual account activity is captured by CloudTrail.

Why this answer

AWS CloudTrail (E) is the foundational service for auditing AWS account activity because it records API calls and management events across the account, delivering the raw audit trail needed for compliance. Amazon CloudWatch Logs (A) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where they can be retained, searched with metric filters, and alerted on for compliance monitoring. AWS Config (B) is correct because it continuously records resource configuration changes and evaluates them against compliance rules, complementing CloudTrail's activity records with configuration history and drift detection.

AWS Trusted Advisor (C) is not part of an activity-auditing pipeline; it only provides best-practice checks and recommendations. Amazon GuardDuty (D) is a threat-detection service that analyzes logs for malicious behavior, not a primary audit or compliance-recording service.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's advisory recommendations with actual audit logging, or they think GuardDuty's threat detection logs are sufficient for compliance auditing, when in fact only CloudTrail, Config, and CloudWatch Logs together provide the necessary historical record of all account activity and configuration changes.

192
MCQmedium

Refer to the exhibit. An IAM user has this policy attached. The user tries to start an EC2 instance that has no tags. What will happen?

A.The user will be allowed because the condition only applies if the tag exists
B.The user will be allowed because the resource ARN includes a wildcard
C.The user will be allowed because the policy does not explicitly deny the action
D.The user will be denied because the instance does not have the required tag
AnswerD

The policy includes a condition that requires the instance to have a tag key Environment with value 'Production'. Since the instance in question does not have that tag, the condition is not met, so the allow statement cannot be applied. IAM's default is to deny any request not explicitly allowed, so the user is denied permission to start the instance. The condition must be satisfied even if the resource ARN matches.

Why this answer

The IAM policy includes a condition that requires the EC2 instance to have a tag with key 'Environment' and value 'Production'. When the instance has no tags, the condition evaluates to false, and the default behavior for IAM policies is to deny access when a condition is not met. Since the policy does not explicitly allow the action without the tag, the request is implicitly denied.

Exam trap

The trap here is that candidates often assume a missing tag causes the condition to be ignored or treated as 'not applicable', but in IAM, a missing tag causes the condition to evaluate to false, leading to an implicit deny.

How to eliminate wrong answers

Option A is wrong because the condition does not 'only apply if the tag exists'; the condition key 'aws:ResourceTag' evaluates to false when the tag is absent, resulting in denial. Option B is wrong because the resource ARN wildcard does not override the condition; conditions are evaluated independently and must be satisfied for the allow to take effect. Option C is wrong because IAM policies are deny-by-default; an allow statement with an unsatisfied condition does not grant permission, so the action is implicitly denied.

193
MCQeasy

A company is using Amazon RDS for MySQL and needs to encrypt data at rest. Which action should be taken to enable encryption?

A.Use the RDS console to enable encryption on the existing DB instance.
B.Use AWS KMS to create a customer master key and assign it to the existing DB instance.
C.Modify the existing RDS DB instance and enable encryption.
D.Create a new RDS DB instance with encryption enabled.
AnswerD

The only supported way to get encrypted-at-rest storage for data that currently lives in an unencrypted RDS instance is to create a new DB instance with encryption enabled. This is done either by taking a snapshot of the original instance and restoring it with encryption toggled on, or by launching a new encrypted instance and migrating the data with a tool such as AWS DMS. During creation, you choose an AWS KMS key, and once the instance is created, encryption cannot be removed or changed.

Why this answer

Amazon RDS for MySQL does not support enabling encryption on an existing DB instance. Encryption at rest must be enabled at the time of instance creation. Therefore, the correct action is to create a new RDS DB instance with encryption enabled, and then migrate the data from the unencrypted instance to the new encrypted one.

Exam trap

The trap here is that candidates assume encryption can be toggled on an existing RDS instance via a modification, similar to enabling encryption on an EBS volume, but RDS requires encryption to be set at launch and cannot be added later.

How to eliminate wrong answers

Option A is wrong because the RDS console does not allow enabling encryption on an existing DB instance; encryption can only be enabled during creation. Option B is wrong because while AWS KMS customer master keys are used for RDS encryption, you cannot assign a KMS key to an existing unencrypted DB instance; encryption must be enabled at launch. Option C is wrong because modifying an existing RDS DB instance does not support enabling encryption; the 'Modify' action does not include an encryption toggle for existing instances.

194
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive data in an S3 bucket. The security team has mandated that all data in transit to the S3 bucket must be encrypted using TLS. The SysOps administrator configured the application to use HTTPS endpoints for S3. However, a security audit reveals that some requests to S3 are still being sent over HTTP. The administrator checks the VPC Flow Logs and sees that the EC2 instances are communicating with the S3 bucket via a VPC endpoint. The company also uses an S3 bucket policy that allows access only from the VPC endpoint. What is the most likely reason that some requests are sent over HTTP?

A.The VPC endpoint is not encrypting traffic between the instances and the endpoint.
B.The VPC endpoint is configured for HTTP instead of HTTPS.
C.The S3 bucket policy does not require HTTPS for requests.
D.The application is not configured to use HTTPS for all S3 requests.
AnswerD

This is the correct root cause. The application must use HTTPS endpoints when calling S3 (e.g., https://bucket.s3.amazonaws.com) to encrypt data in transit between the EC2 instances and S3. Even when using a VPC endpoint, the application's SDK or code explicitly determines whether requests are signed and sent over TLS. If the code uses HTTP URLs or does not enforce TLS, traffic is sent in plaintext, exposing data on the network.

Why this answer

The VPC endpoint for S3 does not automatically encrypt traffic; encryption is handled at the application level. The application must be configured to use HTTPS for all S3 requests. Even though the administrator configured the application to use HTTPS endpoints, some requests may still be sent over HTTP if the application has fallback logic or uses an SDK that defaults to HTTP in certain cases.

Option A is incorrect because the VPC endpoint itself does not encrypt traffic; encryption is an application-layer function. Option B is incorrect because VPC endpoints are not configured for HTTP or HTTPS; they use AWS API calls which can be made over either protocol depending on the client. Option C is incorrect because the S3 bucket policy does not require HTTPS; it only restricts access to the VPC endpoint, not the protocol.

195
MCQeasy

A company's security team requires that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The SysOps administrator needs to create an IAM policy that denies all console actions if the user has not authenticated with MFA. Which IAM condition key should the administrator use?

A.aws:MultiFactorAuthPresent
B.aws:SourceIp
C.iam:PassedToService
D.aws:RequestedRegion
AnswerA

aws:MultiFactorAuthPresent is a boolean condition key that returns true when the caller authenticated with MFA. To enforce MFA for all IAM user console access, you attach an identity policy with a condition like "Bool": {"aws:MultiFactorAuthPresent": "true"}. This works with temporary credentials obtained via the console or sts:GetSessionToken, but it does not automatically apply to long-lived access keys unless the session is explicitly created with MFA.

Why this answer

The `aws:MultiFactorAuthPresent` condition key evaluates to `true` when the user has authenticated using MFA. By using this key in a `Deny` statement, the policy can block all console actions unless MFA is present, enforcing the security team's requirement.

Exam trap

The trap here is that candidates confuse `aws:MultiFactorAuthPresent` with `aws:MultiFactorAuthAge` (which checks how long ago MFA was used) or assume `SourceIp` can enforce MFA, but only the `MultiFactorAuthPresent` key directly evaluates MFA status for console access.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` is used to restrict access based on the user's IP address, not MFA status. Option C is wrong because `iam:PassedToService` is used to control which roles can be passed to AWS services, not for MFA enforcement. Option D is wrong because `aws:RequestedRegion` restricts actions to specific AWS regions, not MFA authentication.

196
MCQhard

A company has a VPC with public and private subnets. The private subnets contain RDS databases that should not be accessible from the internet. Which configuration ensures that the databases are only accessible from the application servers in the public subnets?

A.Attach an internet gateway to the VPC and route the private subnet's traffic to it.
B.Attach a NAT gateway to the private subnet and route traffic through it.
C.Configure a network ACL on the private subnet to allow inbound traffic from the public subnet CIDR.
D.Create a security group for the RDS instances that allows inbound traffic from the security group attached to the application servers.
AnswerD

Create a security group for the RDS instances and add an inbound rule that allows the database port from the security group attached to the application servers. Because security groups can reference other security groups as sources, this rule automatically restricts access to only those instances that carry the application security group, regardless of their IP addresses or whether the application tier scales up or down. This stateful, least-privilege approach is the AWS best practice for tiered access within a VPC and directly resolves the connectivity failure without affecting other subnets or relying on broad CIDR ranges.

Why this answer

Security groups act as a virtual firewall at the instance level, and you can reference another security group as a source. By creating a security group for the RDS instances that allows inbound traffic from the security group attached to the application servers, you ensure that only those application servers (regardless of their IP addresses) can reach the databases. This approach is more dynamic and secure than using CIDR-based rules, as it automatically accommodates changes in the application servers' IP addresses or scaling events.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs, assuming that a network ACL rule allowing inbound traffic from the public subnet CIDR is sufficient, but they overlook that network ACLs are stateless and do not provide the same granular, instance-level control as security groups, nor do they automatically adapt to changes in application server IPs.

How to eliminate wrong answers

Option A is wrong because attaching an internet gateway to the VPC and routing private subnet traffic to it would expose the RDS databases to the internet, violating the requirement that they should not be accessible from the internet. Option B is wrong because a NAT gateway is used to allow outbound internet traffic from private subnets, not to control inbound access; it would not restrict inbound traffic to only the application servers. Option C is wrong because a network ACL is stateless and requires explicit allow rules for both inbound and outbound traffic; while it could allow inbound traffic from the public subnet CIDR, it would not restrict access to only the application servers (any instance in that CIDR range could connect), and it would not automatically adapt to changes in application server IPs.

197
MCQeasy

An organization wants to ensure that no Amazon S3 bucket in the entire AWS Organization can be made public. The security team requires a preventive control that cannot be overridden by individual account administrators. Which AWS service or feature should be used?

A.Create a Service Control Policy (SCP) in AWS Organizations that denies permissions to modify S3 bucket public access settings.
B.Enable AWS Config rules in each account to detect public S3 buckets and automatically remediate them using AWS Lambda.
C.Use an IAM policy attached to all IAM users in each account that denies s3:PutBucketPolicy.
D.Apply Amazon S3 Block Public Access at the account level in each individual AWS account.
AnswerA

A Service Control Policy (SCP) attached at the organization root or an organizational unit (OU) is inherited by every AWS account underneath, and it operates as an allow-list or denial of AWS API actions at the account level. Because SCPs are evaluated by AWS Organizations before IAM policies, even an account root user with full administrative rights cannot override an explicit deny of s3:PutBucketPolicy, s3:PutBucketAcl, or s3:PutBucketPublicAccessBlock, making it a true preventative guardrail across the entire organization. This is why the correct answer is to use SCPs rather than account-local controls.

Why this answer

A Service Control Policy (SCP) in AWS Organizations is a preventive guard that applies to all accounts within the organization. It can explicitly deny actions like s3:PutBucketPublicAccessBlock, s3:PutBucketPolicy, and s3:PutObjectAcl, preventing any principal (including root users) from making S3 buckets public. Unlike detective or account-level controls, SCPs cannot be overridden by individual account administrators, meeting the requirement for a non-overridable preventive control.

Exam trap

The trap here is that candidates often choose account-level S3 Block Public Access (Option D) because it seems like a direct preventive control, but they overlook that it can be overridden by account administrators, whereas an SCP is a centralized, non-overridable guardrail that applies across the entire AWS Organization.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are detective and reactive, not preventive; they detect public buckets after the fact and can auto-remediate, but they do not block the initial action and can be overridden by account administrators. Option C is wrong because IAM policies attached to users do not apply to the root user or to services running with assumed roles, and they can be modified by account administrators, so they are not a non-overridable preventive control across the entire organization. Option D is wrong because S3 Block Public Access at the account level can be disabled or modified by any user with the necessary permissions (including account administrators), so it does not provide a centrally enforced, non-overridable control.

198
Multi-Selectmedium

A company has an S3 bucket that stores sensitive data. The security team requires that all data be encrypted at rest and that all access be logged. Which TWO actions should the SysOps administrator take to meet these requirements? (Choose TWO.)

Select 2 answers
A.Enable S3 Transfer Acceleration.
B.Enable S3 Replication to replicate objects to another bucket.
C.Enable default encryption on the S3 bucket.
D.Enable S3 Object Lock.
E.Enable S3 server access logs.
AnswersC, E

Enabling default encryption on the bucket ensures that every new object stored is automatically encrypted at rest using SSE-S3 (AES-256) or an SSE-KMS key, even when the upload request does not specify an encryption header. This protects sensitive data from physical media theft or unauthorized access to underlying storage infrastructure. It is a fundamental confidentiality control that should be paired with access logging and IAM policies to fully secure the data.

Why this answer

Option C is correct because enabling default encryption on the S3 bucket (using SSE-S3 or SSE-KMS) ensures that every object is automatically encrypted at rest when written, satisfying the requirement that all stored data be encrypted. Option E is correct because enabling S3 server access logs delivers detailed records of every request made to the bucket to a target logging bucket, which fulfills the requirement that all access be logged. Option A is incorrect because S3 Transfer Acceleration only speeds up uploads/downloads over long distances using edge locations; it does not provide encryption or logging.

Option B is incorrect because S3 Replication copies objects to another bucket for durability, latency, or compliance purposes but does not itself encrypt data at rest or log access. Option D is incorrect because S3 Object Lock enforces WORM protection to prevent deletion or modification of objects, which is unrelated to encryption at rest or access logging.

Exam trap

SOA-C02 often tests whether candidates confuse adjacent S3 features (Transfer Acceleration, Replication, Object Lock) with the specific controls for encryption at rest and access logging, causing them to pick a feature that addresses a different requirement.

← PreviousPage 3 of 3 · 198 questions total

Ready to test yourself?

Try a timed practice session using only Security and Compliance questions.