AWS 4: Data Security and Governance: 162 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS 4: Data Security and Governance: 162 practice questions

AWS 162 questions 12 shown free

12 of the 162 4: Data Security and Governance questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for AWS? Take the free 5-min readiness check →

1. Allow TCP 5432 inbound on DbSG from AppSG: Which update should restore access?

Hard
A support integration runs in application security group AppSG and connects to a database in DbSG. Exhibit: DbSG currently allows inbound TCP 5432 from 10.0.4.0/24. App instances moved to another private subnet, and the connection now times out. Network policy prohibits broad CIDR access. Which update should restore access?
  1. Allow TCP 5432 inbound on DbSG from 0.0.0.0/0.
    This permits database access from every IPv4 source and violates the stated restriction against broad access.
  2. Allow TCP 5432 inbound on AppSG from DbSG.
    Inbound rules on the client group do not authorize the database’s inbound connection request.
  3. Attach the database security group to the application instances.
    Sharing a security group does not replace the required inbound rule on the database security group.
  4. Allow TCP 5432 inbound on DbSG from AppSG. ✓
    Referencing the application security group permits database traffic from current application members without broad subnet-based access.
The trap
Confuses connectivity restoration with least-privilege network authorization. Confuses group association with traffic authorization. Reverses the direction of the required security-group rule.

Permit database-port traffic from AppSG on DbSG, preserving dynamic membership and avoiding broad CIDR access.

2. Create a least-privilege IAM role and configure: Select TWO actions.

Easy
A healthcare ETL workload runs in private subnets and must read approved S3 data without embedded credentials. Administrators require temporary, least-privilege authorization and private network access to the service. Select TWO actions.

Select two. More than one option is correct — every correct one is ticked below.

  1. Add the ETL service principal to an IAM group for workload permissions.
    IAM groups contain users and are not execution identities that AWS workloads assume.
  2. Allow inbound security-group traffic from the private subnet to S3.
    Security groups do not provide S3 authorization or replace the required endpoint path.
  3. Store a long-lived access key in the ETL configuration and restrict its source subnet.
    A long-lived embedded key increases exposure and does not provide preferred temporary role-based authorization.
  4. Create a least-privilege IAM role and configure the workload to assume it. ✓
    An IAM role provides temporary credentials and limits access to approved S3 actions and resources.
  5. Configure an Amazon S3 VPC endpoint for private workload traffic. ✓
    An S3 VPC endpoint provides private connectivity from the VPC without public internet routing.
The trap
Confuses network restriction with credential management. Confuses human-user grouping with workload roles. Confuses instance traffic controls with S3 access.

Use an execution role for temporary authorization and an S3 VPC endpoint for private connectivity.

3. Store it in Secrets Manager with rotation enabled: Which solution best satisfies these requirements?

Easy
A media analytics pipeline connects to a database nightly. The database password must rotate automatically, application code cannot contain static credentials, and brief connection retries during rotation are acceptable. Which solution best satisfies these requirements?
  1. Create an IAM user and embed its access keys in the pipeline configuration.
    IAM access keys are static AWS credentials and do not manage the database password.
  2. Place the password in an S3 object and grant the pipeline read access.
    S3 stores the value but does not by itself rotate database credentials or coordinate refreshed connections.
  3. Store it in Secrets Manager with rotation enabled. ✓
    Secrets Manager stores the password centrally, supports configured rotation, and allows runtime retrieval of the current value.
  4. Store the password in an encrypted configuration file deployed with the pipeline.
    Encryption protects the file but does not provide managed rotation or eliminate the need to distribute decryption material.
The trap
Confuses encryption at rest with secret lifecycle management. Assumes protected storage performs credential rotation. Confuses AWS API credentials with database credentials.

Use Secrets Manager with automatic rotation and runtime retrieval.

4. Attach an IAM role to the Lambda function with narrowly: Which approach should an engineer implement?

Easy
A billing reconciliation job runs on AWS Lambda and reads invoices from a specific S3 prefix. The team requires temporary credentials, no long-lived access keys, and permissions limited to that Lambda function and prefix. Which approach should an engineer implement?
  1. Attach an IAM role to the Lambda function with narrowly scoped S3 permissions. ✓
    A Lambda execution role supplies temporary credentials and can restrict actions and resources to the required S3 prefix.
  2. Grant the Lambda function administrator permissions and rely on code to access only invoices.
    Administrator permissions violate least privilege because application behavior cannot reliably enforce authorization boundaries.
  3. Create an IAM user, store its access keys in Lambda environment variables, and restrict the bucket policy.
    Environment variables still contain long-lived access keys, creating avoidable credential exposure and rotation responsibilities.
  4. Use the billing analyst's IAM user credentials because that user already reads invoice files.
    Sharing a human principal with an automated workload weakens accountability and uses long-lived credentials unnecessarily.
The trap
Confuses human access with workload identity. Assumes application code alone should constrain AWS access. Treats restricted permissions as a substitute for temporary credentials.

An execution role gives Lambda temporary credentials while policy scope limits invoice access.

5. Allow the role to use the S3 Access Point ARN and restrict: Which configuration best applies authorization?

Easy
A manufacturing application must read quality files through an S3 Access Point. The application role should access only that Access Point, while the bucket remains inaccessible through general bucket access paths. Which configuration best applies authorization?
  1. Grant the role permission to the S3 service without specifying an Access Point or bucket resource.
    Service-level authorization without appropriate resources does not identify which S3 data the role may access.
  2. Allow the role to access every object in the bucket and depend on the Access Point network settings.
    Network configuration does not replace IAM authorization, and bucket-wide permissions exceed the required resource scope.
  3. Allow the role to use the S3 Access Point ARN and restrict the bucket policy to that access path. ✓
    Policies can authorize the role through the Access Point while the bucket policy denies or limits alternate access paths.
  4. Attach an IAM policy granting the role access to the application server's security group.
    Security groups control network traffic, not S3 object authorization or Access Point permissions.
The trap
Confuses network path controls with identity authorization. Treats a network control as an IAM resource permission. Assumes naming a service alone grants usable resource access.

Authorize the role and bucket through the Access Point resource, while restricting alternate bucket access.

6. Use managed AWS analytics services: Which statement correctly describes the preferred managed-service approach

Easy
An enterprise data platform team wants to reduce operational work for its shared analytics environment. It needs AWS to handle much of the underlying infrastructure maintenance, while retaining responsibility for data permissions and application configuration. Which statement correctly describes the preferred managed-service approach?
  1. Use managed services and assume AWS automatically grants analysts access to every registered dataset.
    Managed infrastructure does not eliminate customer responsibility for authorization, governance, or data access decisions.
  2. Use managed AWS analytics services; AWS operates underlying infrastructure, while the team configures data and access. ✓
    Managed services reduce infrastructure administration, but customers remain responsible for configurations, permissions, and their data.
  3. Build the platform entirely on premises because managed services cannot support customer-defined permissions.
    AWS managed services commonly expose customer configuration and authorization controls, so on-premises hosting is not required.
  4. Run analytics software on self-managed EC2 instances so AWS handles application patching automatically.
    EC2 customers generally manage guest operating systems and installed applications rather than receiving automatic application maintenance.
The trap
Overstates the provider's responsibility for unmanaged software. Confuses service management with data governance. Assumes managed services prevent customer security configuration.

Managed services shift infrastructure operations to AWS but preserve customer responsibility for data, configuration, and permissions.

7. Create a project for the ingestion engineers and manage: Select TWO actions that satisfy these requirements.

Easy
A company receives partner files daily. In SageMaker Unified Studio, the data governance team must organize separate business areas with delegated ownership, while ingestion engineers need a shared workspace to build and operate pipelines. Select TWO actions that satisfy these requirements.

Select two. More than one option is correct — every correct one is ticked below.

  1. Create a project for the ingestion engineers and manage their collaboration through project membership. ✓
    Projects provide collaborative workspaces, and project membership governs who can collaborate and use project-associated resources.
  2. Create domain units for the separate business areas and assign appropriate unit ownership policies. ✓
    Domain units organize delegated areas within a domain and support ownership and authorization policies for those areas.
  3. Use only catalog asset types because catalog registration automatically creates an execution workspace.
    Asset types define catalog representation and validation; they do not create project collaboration or execution environments.
  4. Grant all domain users project ownership so they can discover and operate every ingestion resource.
    Broad ownership is unnecessary and weakens governance; project membership and scoped policies provide controlled collaboration.
  5. Register every partner file as a separate domain to isolate ingestion operations.
    Domains are broader organizational environments; individual files should not be modeled as separate domains.
The trap
Confuses data assets with top-level Unified Studio environments. Confuses catalog metadata structures with projects. Confuses discovery or broad membership with least-privilege project access.

Use domain units for delegated organization and projects for controlled ingestion collaboration.

8. Create a custom policy for the required S3 actions: Which solution provides least-privilege access?

Medium
An inventory synchronization role may list one S3 bucket, read objects under one prefix, and write synchronization results to another prefix. No managed policy provides this exact combination. Which solution provides least-privilege access?
  1. Create a custom policy for the required S3 actions, resources, prefixes, and conditions. ✓
    A customer-managed policy can precisely grant the required actions and resource scope when managed policies are too broad.
  2. Attach AmazonS3FullAccess because synchronization requires several S3 operations.
    Full access includes unrelated buckets and actions, exceeding the stated requirement.
  3. Use a permissions boundary granting the S3 actions without an identity policy.
    A permissions boundary limits maximum permissions but does not independently grant the role access.
  4. Allow the role to assume an administrator role only during synchronization runs.
    Temporary administrator access remains excessive and violates least privilege.
The trap
Treats limited duration as a substitute for limited permissions. Assumes multiple actions require unrestricted access. Confuses a permission limit with a permission grant.

Use a custom identity policy scoped to the required actions, resources, prefixes, and conditions.

9. Use Secrets Manager for the credential and authorize: Which solution is best?

Medium
A marketing attribution service connects to a production database. Its password must not appear in source control or container images, access must be controlled with IAM, and the team wants managed rotation with applications retrieving the current value. Which solution is best?
  1. Store the credential in S3 and grant the container read permission.
    S3 can store the value, but it does not provide the requested managed database credential rotation.
  2. Store the credential in an IAM policy condition for the database to evaluate.
    IAM conditions authorize AWS requests; they do not store or authenticate a database password.
  3. Use Secrets Manager for the credential and authorize retrieval through the service role. ✓
    Secrets Manager centrally stores and supports rotation of the credential, while IAM controls which role may retrieve it.
  4. Store the credential in a container environment variable injected during image construction.
    Build-time injection can embed or distribute the credential in the image and prevents centralized rotation.
The trap
Assumes build-time injection avoids static-secret exposure. Confuses AWS authorization metadata with database credentials. Confuses storage with secret lifecycle management.

Use Secrets Manager with IAM-controlled retrieval and managed rotation.

10. Create database roles: Which database authorization design is appropriate?

Medium
A retail analytics team uses Amazon Redshift. Analysts should query curated sales views, while an automated loader may insert into staging tables but must not query customer-facing views. Administrators need to manage grants without sharing individual passwords. Which database authorization design is appropriate?
  1. Create database roles, grant each role only required object privileges, and assign users or workloads to those roles. ✓
    Database roles group object privileges and support distinct analyst, loader, and administrator authority without sharing credentials.
  2. Use one shared database user for all analysts and loaders, assigning permissions based on job names.
    Shared users prevent individual accountability and cannot cleanly express different database authorities.
  3. Grant IAM permission to query views and assume that Redshift automatically creates equivalent database privileges.
    IAM permissions and database object grants are different authorization layers and are not interchangeable.
  4. Grant every analyst and loader superuser authority, then rely on application conventions to prevent misuse.
    Superuser authority bypasses least privilege and cannot be safely constrained by application conventions.
The trap
Confuses operational trust with database authorization. Confuses organizational labels with database principals and roles. Assumes AWS API authorization controls SQL object access.

Use database roles with narrowly scoped object grants, assigning users and workloads according to required authority.

11. Apply a Lake Formation data filter with a regional row: Which solution should be implemented?

Medium
A telemetry table is registered in the AWS Glue Data Catalog. Regional analysts query it through Athena, but each analyst should see only rows for their region and must not see the device_serial column. The organization wants centralized permissions for the catalog table. Which solution should be implemented?
  1. Encrypt the table with KMS and grant analysts decrypt permission.
    Encryption protects data at rest but does not restrict query rows or hide selected columns.
  2. Apply a Lake Formation data filter with a regional row expression and excluded column. ✓
    A Lake Formation data filter can combine row filtering with column exclusion when filtered SELECT access is granted.
  3. Create separate Athena workgroups and use their names to filter regional rows.
    Workgroups organize query settings but do not enforce row- or column-level authorization.
  4. Grant full-table SELECT and require analysts to add regional predicates and omit the column.
    Query conventions are not enforcement because analysts could request unrestricted rows and columns.
The trap
Confuses query execution organization with data permissions. Confuses encryption with query-result authorization. Confuses user behavior with centralized authorization.

Use a Lake Formation data filter combining regional row security and column exclusion.

12. Grant analysts Lake Formation SELECT through a data filter: | Principal | Attributes | Required access | |---|

Medium
A financial platform stores transactions with attributes below. Compliance requires analysts to query only records tagged with their assigned region, while auditors may query every region but only non-sensitive columns. Access rules must remain centrally enforceable when users change teams. Select TWO authorization approaches that satisfy these requirements.

| Principal | Attributes | Required access |
|---|---|---|
| Analyst | Department=Finance, Region=West | West transactions, approved columns |
| Auditor | Department=Audit | All regions, non-sensitive columns |

Select two. More than one option is correct — every correct one is ticked below.

  1. Grant analysts Lake Formation SELECT through a data filter that includes only rows matching their assigned Region. ✓
    A Lake Formation row filter centrally restricts each analyst’s query results to the governed regional value.
  2. Assign broad finance roles and enforce regional filtering only through dashboard queries.
    Dashboard predicates are not a dependable authorization boundary because users may issue other queries or access underlying data.
  3. Grant auditors Lake Formation SELECT through a data filter that includes all rows but excludes sensitive columns. ✓
    A Lake Formation column filter can expose every region while excluding sensitive fields, without granting administrator access.
  4. Use one shared analyst role regardless of each analyst’s region or team assignment.
    A shared role cannot distinguish regional entitlements when analysts have different assignments.
  5. Give auditors administrator permissions so they can inspect all regions without data filters.
    Administrator access is broader than required and does not enforce exclusion of sensitive columns.
The trap
Confuses presentation filtering with enforceable authorization. Confuses common job function with variable entitlements. Treats unrestricted authority as compatible with least privilege.

Use Lake Formation row filters for analyst regions and column filters for auditor visibility.

150 more 4: Data Security and Governance questions

The remaining 150 questions in this domain are part of the full AWS bank — 900 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your AWS readiness — free

Other AWS domains

Part of the Certsqill AWS question bank · 4: Data Security and Governance · Every answer, right and wrong, comes with its own explanation.