AWS 6: Security and Compliance: 144 practice questions
12 of the 144 6: Security and Compliance questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for AWS? Take the free 5-min readiness check →
1. Give each ECS task a narrowly scoped task role and block: Which design best enforces least privilege?
- Attach administrator permissions to the task role, then use deployment pipelines and review approvals to control when tasks can exercise them.Approval processes do not enforce runtime least privilege, and administrative task credentials remain available if a container is compromised.
- Give each ECS task a narrowly scoped task role and block access to instance-profile credentials. ✓The task role can limit S3 resources and KMS actions, while instance metadata protections prevent a compromised task from obtaining the broader EC2 profile.
- Attach the S3 and KMS permissions to the ECS task execution role and omit an application task role.The execution role supports ECS operations such as image retrieval and logging; application API calls require a separate task role.
- Use the broad instance profile for all task API calls and block only selected S3 actions.A shared instance profile exposes host-level permissions to every task and does not isolate workload credentials or narrowly scope KMS access.
Use a narrowly scoped ECS task role and prevent tasks from obtaining the EC2 instance-profile credentials.
2. Create a narrowly scoped reconciliation role with only: Which two designs should be implemented?
Select two. More than one option is correct — every correct one is ticked below.
- Use an IAM permissions boundary on workload roles and omit workload identity policies.A permissions boundary limits maximum permissions but does not grant the workload access it needs.
- Create a narrowly scoped reconciliation role with only required billing actions and resources. ✓A dedicated least-privilege role fits operators with a fixed reconciliation responsibility.
- Attach broad workload permissions, then use department tags only for inventory, reporting, and ownership reviews.Inventory tags do not enforce access boundaries, so broad permissions would allow cross-department access.
- Match approved principal and resource department tags in IAM policies, and control principal-tag assignment during provisioning. ✓Controlled principal and resource tags enable scalable ABAC while provisioning controls prevent workloads from selecting unauthorized attributes.
- Allow each workload to choose its department principal tag when it assumes the role.A workload-controlled principal tag could be changed to match another department and bypass ABAC isolation.
Use governed ABAC for workloads and a narrow RBAC role for fixed reconciliation duties.
3. Enable Secrets Manager managed rotation and modify clients: Which design should be implemented?
- Enable Secrets Manager managed rotation and modify clients to retrieve and refresh the secret without embedding credentials. ✓Managed rotation updates supported database credentials, while clients must refresh values so rotation does not strand cached credentials.
- Create a Lambda rotation function even though the database is supported by Secrets Manager managed rotation.A custom Lambda rotation function is unnecessary for a supported managed secret and adds operational code and failure modes.
- Store the credential in an ECS task definition secret and redeploy tasks annually with a manually changed value.Annual manual replacement is not automatic rotation and task-definition updates can leave long-lived credentials and outage risk.
- Use Parameter Store SecureString and rotate its value with a monthly Systems Manager maintenance window.Scheduled parameter replacement does not automatically update the database credential or provide the supported managed rotation workflow.
Managed rotation handles supported database credentials, but clients must refresh secret values instead of caching them indefinitely.
4. Require Identity Center MFA: Which design satisfies these requirements?
- Require Identity Center MFA and workload roles, then attach the deny SCP only to a development OU.The guardrail does not cover the listed production accounts when it is attached only to a development OU.
- Use long-lived access keys for workloads, require MFA on an automation user, and deny trail deletion with IAM.Long-lived credentials fail the temporary-credential requirement, and a shared automation user weakens workload isolation.
- Require Identity Center MFA, use workload roles, and attach a deny SCP to every listed production account. ✓Identity Center provides federated human MFA, workload roles provide temporary credentials, and the SCP deny centrally restricts trail deletion. Account administrators still grant application permissions through IAM policies.
- Assign AdministratorAccess to application roles, rely on an SCP deny, and review effective access afterward.An SCP can restrict but cannot grant permissions, and AdministratorAccess violates the requirement for explicitly granted application permissions.
Use federated MFA for people, workload roles for temporary credentials, and an SCP deny on every production account.
5. Govern workload OUs with Control Tower: Which design best satisfies these requirements?
- Deploy Config conformance packs manually in every account and Region, aggregate compliance results, and open tickets for remediation.This is executable but manual deployment and ticket-based response do not guarantee automatic inheritance or automated remediation for newly created accounts.
- Govern workload OUs with Control Tower, aggregate Security Hub findings, and route EventBridge events to authorized Systems Manager runbooks. ✓Control Tower applies OU governance, Security Hub centralizes findings, and EventBridge can invoke authorized Systems Manager remediation without centralizing workload data.
- Use an Organizations SCP to grant security administrators remediation actions, then invoke those actions from Security Hub.An SCP cannot grant permissions, and Security Hub findings require a separate authorized remediation workflow.
- Create a Security Hub administrator account, manually enable controls in each workload Region, and send findings to email for owner action.This provides aggregation and notification but manual regional setup does not ensure automatic inheritance or remediation for new accounts.
Use Control Tower for OU governance, Security Hub for findings, and EventBridge with Systems Manager for response.
6. Use security groups between ALB: Current topology: internet-facing Application Load Balancer in public subnets
Current topology: internet-facing Application Load Balancer in public subnets; ECS tasks in private subnets; Amazon RDS in isolated subnets; no centralized configuration monitoring.
Select two. More than one option is correct — every correct one is ticked below.
- Use security groups between ALB, ECS, and RDS, and monitor security-group changes with AWS Config rules. ✓Stateful security groups enforce tier-to-tier access, while Config rules detect prohibited security-group configuration changes.
- Use Amazon GuardDuty to terminate every ECS task associated with a finding, preventing attacks automatically.GuardDuty detects threats but does not inherently terminate every associated workload or replace application-layer preventive controls.
- Place the RDS database in public subnets and use network ACLs to block unwanted database clients.Public database placement increases exposure, while stateless network ACLs are unnecessarily coarse for tier-specific stateful access.
- Use CloudTrail management events to inspect request payloads and block malicious API parameters before reaching ECS.CloudTrail records API activity rather than application payloads and cannot block malicious HTTP requests in transit.
- Use AWS Certificate Manager certificates on the ALB and AWS WAF web ACLs to inspect HTTPS requests. ✓ACM provides managed certificate integration, while AWS WAF evaluates HTTP requests for application-layer attack patterns.
ACM and WAF protect HTTPS application traffic, while tiered security groups and Config monitoring provide network isolation and drift detection.
7. Use Amazon Macie delegated administration: Which design is most appropriate?
- Create an AWS Config rule that examines object contents and reports personally identifiable information centrally.AWS Config evaluates supported resource configuration, not arbitrary object contents or sensitive-data classifications.
- Use Amazon Inspector delegated administration to scan S3 objects and forward vulnerability findings to Security Hub.Inspector identifies supported compute and software vulnerabilities, not sensitive information contained in S3 objects.
- Use Amazon Macie delegated administration, configure organization-wide S3 discovery, and aggregate findings into the security account. ✓Macie supports centralized organization administration and sensitive-data discovery directly across eligible S3 buckets without copying objects.
- Enable S3 Inventory in each account and use CloudTrail data events to identify sensitive fields in object bodies.S3 Inventory reports object metadata, while CloudTrail data events record API activity and do not inspect object bodies.
Amazon Macie is designed to discover sensitive data in S3 at organizational scale while centralizing administration and findings.
8. Use regional customer-managed KMS keys: Which design best meets the requirements?
- Use CloudHSM for export encryption, terminate TLS at S3 endpoints, and let each workload account administer certificates.S3 does not provide arbitrary public certificate termination, and decentralized certificate administration conflicts with the stated centralized key administration.
- Use one security-account KMS key for every bucket, then attach its policy to analytics roles.KMS keys are regional, so a single key cannot directly serve S3 buckets across Regions.
- Use SSE-S3 for exports, grant analytics accounts bucket access, and require HTTPS on CloudFront distributions.HTTPS protects transit, but SSE-S3 does not meet the customer-managed-key requirement or provide centralized key policy control.
- Use regional customer-managed KMS keys, cross-account key policies, SSE-KMS, and ACM certificates on CloudFront and ALBs. ✓Regional customer-managed keys support controlled cross-account decryption, while SSE-KMS and ACM provide the required at-rest and in-transit encryption.
Use regional customer-managed KMS keys for SSE-KMS and ACM certificates for CloudFront and ALBs.
9. Use an organization trail with validation and an S3 Object: Which design should the team implement?
- Create separate multi-Region trails, deliver to S3, and restrict bucket deletion with administrator IAM policies.Separate trails increase coverage-management risk, and IAM restrictions alone do not provide immutable retention against privileged changes.
- Use an organization trail with validation and an S3 Object Lock compliance bucket. ✓An organization trail centralizes account coverage, validation provides tamper evidence, and Object Lock compliance retention prevents deletion during the required period.
- Send organization-trail events to CloudWatch Logs and set a seven-year log-group retention period.Retention duration does not by itself provide the required immutable S3 archive or protection against privileged alteration and deletion.
- Enable log validation, periodically verify checksums, and delete older S3 objects after verification.Validation detects modification but deleting verified records violates the seven-year retention requirement.
Combine an organization trail, log validation, and S3 Object Lock compliance retention.
10. Use Security Hub for GuardDuty findings and CloudTrail: Which TWO designs meet all requirements?
Select two. More than one option is correct — every correct one is ticked below.
- Centralize GuardDuty and CloudTrail events in EventBridge, send every matching event to SNS, and require an approval step only after responders begin remediation.Sending approved deployment changes to SNS still pages responders, so the required suppression is missing.
- Send GuardDuty findings and CloudTrail IAM changes to a central bus, suppress all deployment-role events permanently, and route production remediation directly to Lambda.Permanent suppression can hide unauthorized use of the deployment role, and direct Lambda remediation bypasses human approval.
- Use Security Hub for GuardDuty findings and CloudTrail for IAM events; apply the context processor, approved-change suppression, SNS notification and approval gate. ✓Security Hub consolidates GuardDuty findings, while CloudTrail management events record IAM policy changes. EventBridge can filter approved deployments, include context, and route remediation through human approval.
- Route both event sources through the context processor, suppress only manifest-matched approved changes, notify SNS and require production approval. ✓This design alerts on GuardDuty and unauthorized IAM policy changes, filters approved deployment activity, preserves account and tenant context, and gates production remediation on human approval.
- Use AWS Config evaluations for IAM policies and GuardDuty notifications to SNS, then permit an automated production rollback for critical findings.Config evaluation is not the required immediate event-driven alert for every unauthorized policy change, and automated rollback violates the human-approval requirement.
Use event-driven filtering with account and tenant context, then gate production remediation through human approval.
11. Redact logs and retain 30 days: Which design best satisfies the requirements?
- Redact logs and retain 30 days; lock the organization trail with management and data events. ✓Application-side redaction prevents token exposure, CloudWatch Logs provides searchable 30-day operational logs, and the organization trail records API activity and explicitly enabled S3 data events in separately protected longer-retention storage.
- Send redacted application logs to CloudWatch Logs with 30-day retention, and store organization-trail management events in protected S3.Management events alone do not record S3 object-level access.
- Send application logs to CloudWatch Logs and store audit records in S3.This does not specify token redaction, 30-day operational retention, S3 data events, or longer protected audit retention.
- Retain redacted application logs for 30 days and collect only S3 data events in the audit trail.S3 object activity is covered, but the omitted management events leave broader API activity unrecorded.
Redact application output, retain it in CloudWatch Logs for 30 days, and store organization-trail management and S3 data events in protected longer-retention S3 storage.
12. Use Detective for findings: Which approach should be selected?
- Use Detective for findings, API activity, resources, and network evidence; keep metrics in separate CloudWatch dashboards. ✓Detective correlates supported security, API, resource, and network activity. CloudWatch dashboards separately preserve operational metrics during high-volume incidents.
- Query CloudTrail Lake and VPC Flow Logs separately, then compare results manually with application dashboards.These sources provide useful evidence, but separate manual comparison does not provide the requested efficient correlation.
- Review Security Hub findings and CloudTrail events manually for each affected account.Manual review can gather evidence but does not efficiently correlate network activity and affected resources at this scale.
- Create CloudWatch metric filters from CloudTrail logs and use dashboards as the primary correlation mechanism.Metric filters can support alerting and dashboards but do not correlate findings, entities, and network activity as an investigation view.
Use Detective for supported security and activity correlation, while retaining application metrics in CloudWatch dashboards.
132 more 6: Security and Compliance questions
The remaining 132 questions in this domain are part of the full AWS bank — 849 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your AWS readiness — freeOther AWS domains
- 1: SDLC Automation — 187 questions →
- 2: Configuration Management and IaC — 144 questions →
- 3: Resilient Cloud Solutions — 128 questions →
- 4: Monitoring and Logging — 127 questions →
- 5: Incident and Event Response — 119 questions →
- All 849 AWS questions →
- AWS certification: requirements, cost and exam format →