AWS 4: Data Security and Governance: 162 practice questions
12 of the 162 4: Data Security and Governance questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for AWS? Take the free 5-min readiness check →
1. Allow TCP 5432 inbound on DbSG from AppSG: Which update should restore access?
- Allow TCP 5432 inbound on DbSG from 0.0.0.0/0.This permits database access from every IPv4 source and violates the stated restriction against broad access.
- Allow TCP 5432 inbound on AppSG from DbSG.Inbound rules on the client group do not authorize the database’s inbound connection request.
- Attach the database security group to the application instances.Sharing a security group does not replace the required inbound rule on the database security group.
- Allow TCP 5432 inbound on DbSG from AppSG. ✓Referencing the application security group permits database traffic from current application members without broad subnet-based access.
Permit database-port traffic from AppSG on DbSG, preserving dynamic membership and avoiding broad CIDR access.
2. Create a least-privilege IAM role and configure: Select TWO actions.
Select two. More than one option is correct — every correct one is ticked below.
- Add the ETL service principal to an IAM group for workload permissions.IAM groups contain users and are not execution identities that AWS workloads assume.
- Allow inbound security-group traffic from the private subnet to S3.Security groups do not provide S3 authorization or replace the required endpoint path.
- Store a long-lived access key in the ETL configuration and restrict its source subnet.A long-lived embedded key increases exposure and does not provide preferred temporary role-based authorization.
- Create a least-privilege IAM role and configure the workload to assume it. ✓An IAM role provides temporary credentials and limits access to approved S3 actions and resources.
- Configure an Amazon S3 VPC endpoint for private workload traffic. ✓An S3 VPC endpoint provides private connectivity from the VPC without public internet routing.
Use an execution role for temporary authorization and an S3 VPC endpoint for private connectivity.
3. Store it in Secrets Manager with rotation enabled: Which solution best satisfies these requirements?
- Create an IAM user and embed its access keys in the pipeline configuration.IAM access keys are static AWS credentials and do not manage the database password.
- Place the password in an S3 object and grant the pipeline read access.S3 stores the value but does not by itself rotate database credentials or coordinate refreshed connections.
- Store it in Secrets Manager with rotation enabled. ✓Secrets Manager stores the password centrally, supports configured rotation, and allows runtime retrieval of the current value.
- Store the password in an encrypted configuration file deployed with the pipeline.Encryption protects the file but does not provide managed rotation or eliminate the need to distribute decryption material.
Use Secrets Manager with automatic rotation and runtime retrieval.
4. Attach an IAM role to the Lambda function with narrowly: Which approach should an engineer implement?
- Attach an IAM role to the Lambda function with narrowly scoped S3 permissions. ✓A Lambda execution role supplies temporary credentials and can restrict actions and resources to the required S3 prefix.
- Grant the Lambda function administrator permissions and rely on code to access only invoices.Administrator permissions violate least privilege because application behavior cannot reliably enforce authorization boundaries.
- Create an IAM user, store its access keys in Lambda environment variables, and restrict the bucket policy.Environment variables still contain long-lived access keys, creating avoidable credential exposure and rotation responsibilities.
- Use the billing analyst's IAM user credentials because that user already reads invoice files.Sharing a human principal with an automated workload weakens accountability and uses long-lived credentials unnecessarily.
An execution role gives Lambda temporary credentials while policy scope limits invoice access.
5. Allow the role to use the S3 Access Point ARN and restrict: Which configuration best applies authorization?
- Grant the role permission to the S3 service without specifying an Access Point or bucket resource.Service-level authorization without appropriate resources does not identify which S3 data the role may access.
- Allow the role to access every object in the bucket and depend on the Access Point network settings.Network configuration does not replace IAM authorization, and bucket-wide permissions exceed the required resource scope.
- Allow the role to use the S3 Access Point ARN and restrict the bucket policy to that access path. ✓Policies can authorize the role through the Access Point while the bucket policy denies or limits alternate access paths.
- Attach an IAM policy granting the role access to the application server's security group.Security groups control network traffic, not S3 object authorization or Access Point permissions.
Authorize the role and bucket through the Access Point resource, while restricting alternate bucket access.
6. Use managed AWS analytics services: Which statement correctly describes the preferred managed-service approach
- Use managed services and assume AWS automatically grants analysts access to every registered dataset.Managed infrastructure does not eliminate customer responsibility for authorization, governance, or data access decisions.
- Use managed AWS analytics services; AWS operates underlying infrastructure, while the team configures data and access. ✓Managed services reduce infrastructure administration, but customers remain responsible for configurations, permissions, and their data.
- Build the platform entirely on premises because managed services cannot support customer-defined permissions.AWS managed services commonly expose customer configuration and authorization controls, so on-premises hosting is not required.
- Run analytics software on self-managed EC2 instances so AWS handles application patching automatically.EC2 customers generally manage guest operating systems and installed applications rather than receiving automatic application maintenance.
Managed services shift infrastructure operations to AWS but preserve customer responsibility for data, configuration, and permissions.
7. Create a project for the ingestion engineers and manage: Select TWO actions that satisfy these requirements.
Select two. More than one option is correct — every correct one is ticked below.
- Create a project for the ingestion engineers and manage their collaboration through project membership. ✓Projects provide collaborative workspaces, and project membership governs who can collaborate and use project-associated resources.
- Create domain units for the separate business areas and assign appropriate unit ownership policies. ✓Domain units organize delegated areas within a domain and support ownership and authorization policies for those areas.
- Use only catalog asset types because catalog registration automatically creates an execution workspace.Asset types define catalog representation and validation; they do not create project collaboration or execution environments.
- Grant all domain users project ownership so they can discover and operate every ingestion resource.Broad ownership is unnecessary and weakens governance; project membership and scoped policies provide controlled collaboration.
- Register every partner file as a separate domain to isolate ingestion operations.Domains are broader organizational environments; individual files should not be modeled as separate domains.
Use domain units for delegated organization and projects for controlled ingestion collaboration.
8. Create a custom policy for the required S3 actions: Which solution provides least-privilege access?
- Create a custom policy for the required S3 actions, resources, prefixes, and conditions. ✓A customer-managed policy can precisely grant the required actions and resource scope when managed policies are too broad.
- Attach AmazonS3FullAccess because synchronization requires several S3 operations.Full access includes unrelated buckets and actions, exceeding the stated requirement.
- Use a permissions boundary granting the S3 actions without an identity policy.A permissions boundary limits maximum permissions but does not independently grant the role access.
- Allow the role to assume an administrator role only during synchronization runs.Temporary administrator access remains excessive and violates least privilege.
Use a custom identity policy scoped to the required actions, resources, prefixes, and conditions.
9. Use Secrets Manager for the credential and authorize: Which solution is best?
- Store the credential in S3 and grant the container read permission.S3 can store the value, but it does not provide the requested managed database credential rotation.
- Store the credential in an IAM policy condition for the database to evaluate.IAM conditions authorize AWS requests; they do not store or authenticate a database password.
- Use Secrets Manager for the credential and authorize retrieval through the service role. ✓Secrets Manager centrally stores and supports rotation of the credential, while IAM controls which role may retrieve it.
- Store the credential in a container environment variable injected during image construction.Build-time injection can embed or distribute the credential in the image and prevents centralized rotation.
Use Secrets Manager with IAM-controlled retrieval and managed rotation.
10. Create database roles: Which database authorization design is appropriate?
- Create database roles, grant each role only required object privileges, and assign users or workloads to those roles. ✓Database roles group object privileges and support distinct analyst, loader, and administrator authority without sharing credentials.
- Use one shared database user for all analysts and loaders, assigning permissions based on job names.Shared users prevent individual accountability and cannot cleanly express different database authorities.
- Grant IAM permission to query views and assume that Redshift automatically creates equivalent database privileges.IAM permissions and database object grants are different authorization layers and are not interchangeable.
- Grant every analyst and loader superuser authority, then rely on application conventions to prevent misuse.Superuser authority bypasses least privilege and cannot be safely constrained by application conventions.
Use database roles with narrowly scoped object grants, assigning users and workloads according to required authority.
11. Apply a Lake Formation data filter with a regional row: Which solution should be implemented?
- Encrypt the table with KMS and grant analysts decrypt permission.Encryption protects data at rest but does not restrict query rows or hide selected columns.
- Apply a Lake Formation data filter with a regional row expression and excluded column. ✓A Lake Formation data filter can combine row filtering with column exclusion when filtered SELECT access is granted.
- Create separate Athena workgroups and use their names to filter regional rows.Workgroups organize query settings but do not enforce row- or column-level authorization.
- Grant full-table SELECT and require analysts to add regional predicates and omit the column.Query conventions are not enforcement because analysts could request unrestricted rows and columns.
Use a Lake Formation data filter combining regional row security and column exclusion.
12. Grant analysts Lake Formation SELECT through a data filter: | Principal | Attributes | Required access | |---|
| Principal | Attributes | Required access |
|---|---|---|
| Analyst | Department=Finance, Region=West | West transactions, approved columns |
| Auditor | Department=Audit | All regions, non-sensitive columns |
Select two. More than one option is correct — every correct one is ticked below.
- Grant analysts Lake Formation SELECT through a data filter that includes only rows matching their assigned Region. ✓A Lake Formation row filter centrally restricts each analyst’s query results to the governed regional value.
- Assign broad finance roles and enforce regional filtering only through dashboard queries.Dashboard predicates are not a dependable authorization boundary because users may issue other queries or access underlying data.
- Grant auditors Lake Formation SELECT through a data filter that includes all rows but excludes sensitive columns. ✓A Lake Formation column filter can expose every region while excluding sensitive fields, without granting administrator access.
- Use one shared analyst role regardless of each analyst’s region or team assignment.A shared role cannot distinguish regional entitlements when analysts have different assignments.
- Give auditors administrator permissions so they can inspect all regions without data filters.Administrator access is broader than required and does not enforce exclusion of sensitive columns.
Use Lake Formation row filters for analyst regions and column filters for auditor visibility.
150 more 4: Data Security and Governance questions
The remaining 150 questions in this domain are part of the full AWS bank — 900 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your AWS readiness — freeOther AWS domains
- 1: Data Ingestion and Transformation — 306 questions →
- 2: Data Store Management — 234 questions →
- 3: Data Operations and Support — 198 questions →
- All 900 AWS questions →
- AWS certification: requirements, cost and exam format →