AWS 6: Security and Compliance: 144 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS 6: Security and Compliance: 144 practice questions

AWS 144 questions 12 shown free

12 of the 144 6: Security and Compliance questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for AWS? Take the free 5-min readiness check →

1. Give each ECS task a narrowly scoped task role and block: Which design best enforces least privilege?

Medium
A production container fleet runs on Amazon ECS. Tasks need read-only access to one S3 prefix and decrypt access to one KMS key. Developers deploy frequently, but task roles must not gain administrative permissions. Security also requires that a compromised task cannot reuse the EC2 container instance profile to access unrelated resources. Which design best enforces least privilege?
  1. Attach administrator permissions to the task role, then use deployment pipelines and review approvals to control when tasks can exercise them.
    Approval processes do not enforce runtime least privilege, and administrative task credentials remain available if a container is compromised.
  2. Give each ECS task a narrowly scoped task role and block access to instance-profile credentials. ✓
    The task role can limit S3 resources and KMS actions, while instance metadata protections prevent a compromised task from obtaining the broader EC2 profile.
  3. Attach the S3 and KMS permissions to the ECS task execution role and omit an application task role.
    The execution role supports ECS operations such as image retrieval and logging; application API calls require a separate task role.
  4. Use the broad instance profile for all task API calls and block only selected S3 actions.
    A shared instance profile exposes host-level permissions to every task and does not isolate workload credentials or narrowly scope KMS access.
The trap
Uses host credentials instead of workload-specific authorization. Confuses ECS control-plane permissions with application workload permissions. Replaces authorization boundaries with procedural deployment controls.

Use a narrowly scoped ECS task role and prevent tasks from obtaining the EC2 instance-profile credentials.

2. Create a narrowly scoped reconciliation role with only: Which two designs should be implemented?

Medium
Select TWO. An event-driven billing system processes records for multiple departments. Each workload should access only resources tagged with its department, while a small operations group needs a fixed role for billing reconciliation. New workloads are created automatically, and security requires that tag values cannot be self-assigned to obtain another department’s access. Which two designs should be implemented?

Select two. More than one option is correct — every correct one is ticked below.

  1. Use an IAM permissions boundary on workload roles and omit workload identity policies.
    A permissions boundary limits maximum permissions but does not grant the workload access it needs.
  2. Create a narrowly scoped reconciliation role with only required billing actions and resources. ✓
    A dedicated least-privilege role fits operators with a fixed reconciliation responsibility.
  3. Attach broad workload permissions, then use department tags only for inventory, reporting, and ownership reviews.
    Inventory tags do not enforce access boundaries, so broad permissions would allow cross-department access.
  4. Match approved principal and resource department tags in IAM policies, and control principal-tag assignment during provisioning. ✓
    Controlled principal and resource tags enable scalable ABAC while provisioning controls prevent workloads from selecting unauthorized attributes.
  5. Allow each workload to choose its department principal tag when it assumes the role.
    A workload-controlled principal tag could be changed to match another department and bypass ABAC isolation.
The trap
Assumes an untrusted principal attribute is suitable for authorization. Confuses a limiting policy with a permission grant. Confuses governance metadata with authorization conditions.

Use governed ABAC for workloads and a narrow RBAC role for fixed reconciliation duties.

3. Enable Secrets Manager managed rotation and modify clients: Which design should be implemented?

Medium
A healthcare application uses a database credential stored in AWS Secrets Manager. The database supports the standard Secrets Manager rotation workflow, and several ECS tasks currently cache credentials for hours. Compliance requires automatic rotation without outages, while the application team wants no long-lived credentials in task definitions. Which design should be implemented?
  1. Enable Secrets Manager managed rotation and modify clients to retrieve and refresh the secret without embedding credentials. ✓
    Managed rotation updates supported database credentials, while clients must refresh values so rotation does not strand cached credentials.
  2. Create a Lambda rotation function even though the database is supported by Secrets Manager managed rotation.
    A custom Lambda rotation function is unnecessary for a supported managed secret and adds operational code and failure modes.
  3. Store the credential in an ECS task definition secret and redeploy tasks annually with a manually changed value.
    Annual manual replacement is not automatic rotation and task-definition updates can leave long-lived credentials and outage risk.
  4. Use Parameter Store SecureString and rotate its value with a monthly Systems Manager maintenance window.
    Scheduled parameter replacement does not automatically update the database credential or provide the supported managed rotation workflow.
The trap
Treats changing stored text as rotating the credential at its authoritative database. Confuses secret injection with rotation and ignores cached-client refresh requirements. Assumes every Secrets Manager rotation requires custom Lambda implementation.

Managed rotation handles supported database credentials, but clients must refresh secret values instead of caching them indefinitely.

4. Require Identity Center MFA: Which design satisfies these requirements?

Medium
A multi-Region customer portal uses AWS IAM Identity Center for employees and IAM roles for workloads. Security requires MFA for human access, temporary credentials for automation, and a central restriction preventing production roles from deleting CloudTrail trails. Application teams must still receive only permissions explicitly granted by account administrators. Production accounts are explicitly listed for guardrail coverage. Which design satisfies these requirements?
  1. Require Identity Center MFA and workload roles, then attach the deny SCP only to a development OU.
    The guardrail does not cover the listed production accounts when it is attached only to a development OU.
  2. Use long-lived access keys for workloads, require MFA on an automation user, and deny trail deletion with IAM.
    Long-lived credentials fail the temporary-credential requirement, and a shared automation user weakens workload isolation.
  3. Require Identity Center MFA, use workload roles, and attach a deny SCP to every listed production account. ✓
    Identity Center provides federated human MFA, workload roles provide temporary credentials, and the SCP deny centrally restricts trail deletion. Account administrators still grant application permissions through IAM policies.
  4. Assign AdministratorAccess to application roles, rely on an SCP deny, and review effective access afterward.
    An SCP can restrict but cannot grant permissions, and AdministratorAccess violates the requirement for explicitly granted application permissions.
The trap
It uses the correct identity mechanisms but applies the central restriction to the wrong scope. It substitutes shared credentials and MFA for workload roles. It misunderstands SCPs and ignores least privilege.

Use federated MFA for people, workload roles for temporary credentials, and an SCP deny on every production account.

5. Govern workload OUs with Control Tower: Which design best satisfies these requirements?

Medium
An internal operations team manages 40 workload accounts across three AWS Regions. Security requirements must be applied consistently, new accounts must inherit controls automatically, and application teams must retain deployment autonomy. The team wants centralized findings and automated remediation without granting the security account access to workload data. Which design best satisfies these requirements?
  1. Deploy Config conformance packs manually in every account and Region, aggregate compliance results, and open tickets for remediation.
    This is executable but manual deployment and ticket-based response do not guarantee automatic inheritance or automated remediation for newly created accounts.
  2. Govern workload OUs with Control Tower, aggregate Security Hub findings, and route EventBridge events to authorized Systems Manager runbooks. ✓
    Control Tower applies OU governance, Security Hub centralizes findings, and EventBridge can invoke authorized Systems Manager remediation without centralizing workload data.
  3. Use an Organizations SCP to grant security administrators remediation actions, then invoke those actions from Security Hub.
    An SCP cannot grant permissions, and Security Hub findings require a separate authorized remediation workflow.
  4. Create a Security Hub administrator account, manually enable controls in each workload Region, and send findings to email for owner action.
    This provides aggregation and notification but manual regional setup does not ensure automatic inheritance or remediation for new accounts.
The trap
Confuses centralized visibility with consistent automated enforcement. Confuses organizational guardrails with identity permissions and orchestration. Relies on repeated operational work instead of account lifecycle governance.

Use Control Tower for OU governance, Security Hub for findings, and EventBridge with Systems Manager for response.

6. Use security groups between ALB: Current topology: internet-facing Application Load Balancer in public subnets

Medium
A partner-facing API runs behind an Application Load Balancer in two Availability Zones. Partners require TLS, the security team requires protection against common web exploits, and operations must detect unauthorized security-group changes. The API also needs private database access, while public API availability must remain unaffected by internal subnet routing changes. The exhibit shows the current design: internet-facing ALB in public subnets, ECS tasks in private subnets, RDS in isolated subnets, and no centralized configuration monitoring. Select TWO.

Current topology: internet-facing Application Load Balancer in public subnets; ECS tasks in private subnets; Amazon RDS in isolated subnets; no centralized configuration monitoring.

Select two. More than one option is correct — every correct one is ticked below.

  1. Use security groups between ALB, ECS, and RDS, and monitor security-group changes with AWS Config rules. ✓
    Stateful security groups enforce tier-to-tier access, while Config rules detect prohibited security-group configuration changes.
  2. Use Amazon GuardDuty to terminate every ECS task associated with a finding, preventing attacks automatically.
    GuardDuty detects threats but does not inherently terminate every associated workload or replace application-layer preventive controls.
  3. Place the RDS database in public subnets and use network ACLs to block unwanted database clients.
    Public database placement increases exposure, while stateless network ACLs are unnecessarily coarse for tier-specific stateful access.
  4. Use CloudTrail management events to inspect request payloads and block malicious API parameters before reaching ECS.
    CloudTrail records API activity rather than application payloads and cannot block malicious HTTP requests in transit.
  5. Use AWS Certificate Manager certificates on the ALB and AWS WAF web ACLs to inspect HTTPS requests. ✓
    ACM provides managed certificate integration, while AWS WAF evaluates HTTP requests for application-layer attack patterns.
The trap
This assumes network ACL filtering makes an unnecessarily public database equivalent to an isolated database. This confuses AWS API auditing with application request inspection and prevention. This assumes findings automatically prove compromise and provide universal remediation actions.

ACM and WAF protect HTTPS application traffic, while tiered security groups and Config monitoring provide network isolation and drift detection.

7. Use Amazon Macie delegated administration: Which design is most appropriate?

Hard
A large organization has 18 workload accounts, each containing multiple S3 buckets. The security team must discover personally identifiable information in existing and newly created objects, minimize duplicated administration, and keep workload administrators from changing discovery settings. Findings must be visible centrally, but the organization cannot require applications to copy objects into a security account. Which design is most appropriate?
  1. Create an AWS Config rule that examines object contents and reports personally identifiable information centrally.
    AWS Config evaluates supported resource configuration, not arbitrary object contents or sensitive-data classifications.
  2. Use Amazon Inspector delegated administration to scan S3 objects and forward vulnerability findings to Security Hub.
    Inspector identifies supported compute and software vulnerabilities, not sensitive information contained in S3 objects.
  3. Use Amazon Macie delegated administration, configure organization-wide S3 discovery, and aggregate findings into the security account. ✓
    Macie supports centralized organization administration and sensitive-data discovery directly across eligible S3 buckets without copying objects.
  4. Enable S3 Inventory in each account and use CloudTrail data events to identify sensitive fields in object bodies.
    S3 Inventory reports object metadata, while CloudTrail data events record API activity and do not inspect object bodies.
The trap
This assumes configuration compliance services inspect and classify stored data. This treats metadata and access auditing as content discovery mechanisms. This confuses vulnerability assessment with sensitive-data discovery.

Amazon Macie is designed to discover sensitive data in S3 at organizational scale while centralizing administration and findings.

8. Use regional customer-managed KMS keys: Which design best meets the requirements?

Hard
A multi-account retail platform stores customer exports in S3 and shares selected objects with analytics accounts. Compliance requires customer-managed encryption keys, cross-account decryption, and TLS for public API access. Key administration must remain centralized, while each workload account retains application deployment autonomy. The platform uses CloudFront and Application Load Balancers, and all buckets are in their workload Regions. Which design best meets the requirements?
  1. Use CloudHSM for export encryption, terminate TLS at S3 endpoints, and let each workload account administer certificates.
    S3 does not provide arbitrary public certificate termination, and decentralized certificate administration conflicts with the stated centralized key administration.
  2. Use one security-account KMS key for every bucket, then attach its policy to analytics roles.
    KMS keys are regional, so a single key cannot directly serve S3 buckets across Regions.
  3. Use SSE-S3 for exports, grant analytics accounts bucket access, and require HTTPS on CloudFront distributions.
    HTTPS protects transit, but SSE-S3 does not meet the customer-managed-key requirement or provide centralized key policy control.
  4. Use regional customer-managed KMS keys, cross-account key policies, SSE-KMS, and ACM certificates on CloudFront and ALBs. ✓
    Regional customer-managed keys support controlled cross-account decryption, while SSE-KMS and ACM provide the required at-rest and in-transit encryption.
The trap
Treats default encryption and transport security as substitutes for CMK governance. Assumes KMS keys are globally usable. Places TLS termination at an unsupported endpoint and weakens central governance.

Use regional customer-managed KMS keys for SSE-KMS and ACM certificates for CloudFront and ALBs.

9. Use an organization trail with validation and an S3 Object: Which design should the team implement?

Hard
A regulated financial service must retain all AWS API activity for seven years. Auditors require centralized multi-account coverage, evidence that delivered logs were not altered, and storage that prevents deletion during the retention period. The service uses S3 for the audit repository, and security administrators must not modify historical records. Which design should the team implement?
  1. Create separate multi-Region trails, deliver to S3, and restrict bucket deletion with administrator IAM policies.
    Separate trails increase coverage-management risk, and IAM restrictions alone do not provide immutable retention against privileged changes.
  2. Use an organization trail with validation and an S3 Object Lock compliance bucket. ✓
    An organization trail centralizes account coverage, validation provides tamper evidence, and Object Lock compliance retention prevents deletion during the required period.
  3. Send organization-trail events to CloudWatch Logs and set a seven-year log-group retention period.
    Retention duration does not by itself provide the required immutable S3 archive or protection against privileged alteration and deletion.
  4. Enable log validation, periodically verify checksums, and delete older S3 objects after verification.
    Validation detects modification but deleting verified records violates the seven-year retention requirement.
The trap
Treats administrative policy restrictions as write-once protection. Equates a retention setting with tamper-resistant storage. Confuses integrity detection with durable preservation.

Combine an organization trail, log validation, and S3 Object Lock compliance retention.

10. Use Security Hub for GuardDuty findings and CloudTrail: Which TWO designs meet all requirements?

Hard
A SaaS application serves enterprise tenants from multiple AWS accounts. The security team needs immediate alerts for GuardDuty findings and unauthorized IAM policy changes, but routine deployments generate approved changes that must not page responders. Alerts must include account and tenant context, and remediation must require human approval for production resources. Which TWO designs meet all requirements? Select TWO. A trusted event processor can resolve tenant ownership and compare each IAM change with the approved change manifest and time window.

Select two. More than one option is correct — every correct one is ticked below.

  1. Centralize GuardDuty and CloudTrail events in EventBridge, send every matching event to SNS, and require an approval step only after responders begin remediation.
    Sending approved deployment changes to SNS still pages responders, so the required suppression is missing.
  2. Send GuardDuty findings and CloudTrail IAM changes to a central bus, suppress all deployment-role events permanently, and route production remediation directly to Lambda.
    Permanent suppression can hide unauthorized use of the deployment role, and direct Lambda remediation bypasses human approval.
  3. Use Security Hub for GuardDuty findings and CloudTrail for IAM events; apply the context processor, approved-change suppression, SNS notification and approval gate. ✓
    Security Hub consolidates GuardDuty findings, while CloudTrail management events record IAM policy changes. EventBridge can filter approved deployments, include context, and route remediation through human approval.
  4. Route both event sources through the context processor, suppress only manifest-matched approved changes, notify SNS and require production approval. ✓
    This design alerts on GuardDuty and unauthorized IAM policy changes, filters approved deployment activity, preserves account and tenant context, and gates production remediation on human approval.
  5. Use AWS Config evaluations for IAM policies and GuardDuty notifications to SNS, then permit an automated production rollback for critical findings.
    Config evaluation is not the required immediate event-driven alert for every unauthorized policy change, and automated rollback violates the human-approval requirement.
The trap
It adds approval but does not suppress routine approved changes. It combines delayed configuration assessment with unapproved remediation. It over-suppresses events and removes the required approval gate.

Use event-driven filtering with account and tenant context, then gate production remediation through human approval.

11. Redact logs and retain 30 days: Which design best satisfies the requirements?

Hard
A global media service operates applications in five AWS Regions. Engineers need centralized operational logs, security auditors need API activity and S3 object-access records, and application teams must retain searchable logs for 30 days while audit records remain protected longer. The service also requires application logs to avoid exposing authorization tokens. Which design best satisfies the requirements?
  1. Redact logs and retain 30 days; lock the organization trail with management and data events. ✓
    Application-side redaction prevents token exposure, CloudWatch Logs provides searchable 30-day operational logs, and the organization trail records API activity and explicitly enabled S3 data events in separately protected longer-retention storage.
  2. Send redacted application logs to CloudWatch Logs with 30-day retention, and store organization-trail management events in protected S3.
    Management events alone do not record S3 object-level access.
  3. Send application logs to CloudWatch Logs and store audit records in S3.
    This does not specify token redaction, 30-day operational retention, S3 data events, or longer protected audit retention.
  4. Retain redacted application logs for 30 days and collect only S3 data events in the audit trail.
    S3 object activity is covered, but the omitted management events leave broader API activity unrecorded.
The trap
It names suitable destinations but omits required controls. It confuses management events with data events. Data events supplement rather than replace management-event auditing.

Redact application output, retain it in CloudWatch Logs for 30 days, and store organization-trail management and S3 data events in protected longer-retention S3 storage.

12. Use Detective for findings: Which approach should be selected?

Hard
A shared developer platform receives Security Hub findings, CloudTrail events, and application metrics from dozens of accounts. Investigators report that a critical finding alone does not show whether exploitation occurred. They need correlated evidence showing suspicious API activity, affected resources, and network communication, while dashboards must remain useful during high-volume incidents. Which approach should be selected?
  1. Use Detective for findings, API activity, resources, and network evidence; keep metrics in separate CloudWatch dashboards. ✓
    Detective correlates supported security, API, resource, and network activity. CloudWatch dashboards separately preserve operational metrics during high-volume incidents.
  2. Query CloudTrail Lake and VPC Flow Logs separately, then compare results manually with application dashboards.
    These sources provide useful evidence, but separate manual comparison does not provide the requested efficient correlation.
  3. Review Security Hub findings and CloudTrail events manually for each affected account.
    Manual review can gather evidence but does not efficiently correlate network activity and affected resources at this scale.
  4. Create CloudWatch metric filters from CloudTrail logs and use dashboards as the primary correlation mechanism.
    Metric filters can support alerting and dashboards but do not correlate findings, entities, and network activity as an investigation view.
The trap
It relies on a workable but poorly scalable process. It gathers evidence without an investigation correlation layer. It treats dashboard metrics as a substitute for security investigation correlation.

Use Detective for supported security and activity correlation, while retaining application metrics in CloudWatch dashboards.

132 more 6: Security and Compliance questions

The remaining 132 questions in this domain are part of the full AWS bank — 849 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your AWS readiness — free

Other AWS domains

Part of the Certsqill AWS question bank · 6: Security and Compliance · Every answer, right and wrong, comes with its own explanation.