Search Header Logo

Security Engineering on AWS (Final test)

Authored by Su Trinh

Professional Development

Professional Development

Used 1+ times

Security Engineering on AWS (Final test)
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Can an Service Control Policy (SCP) effects to permission of an individual account in its AWS Organizations?

Yes, it can

No, it can't

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which AWS service can rotate, manage, and retrieve database credentials throughout their lifecycle?

KMS

Secrets Manager

API Gateway

AWS Config

3.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What AWS services/features help you to troubleshoot network security? (Select TWO.)

Cloudwatch

VPC traffic mirorring

VPC flow log

S3 access logging

4.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

A secure web application runs in an Amazon VPC that has a public subnet and a private subnet. An Application Load Balancer is deployed into the public subnet. Each subnet has a separate Network ACL.

The public subnet CIDR range is 10.1.0.0/24 and the private subnet CIDR range is 10.1.1.0/24.

The web application is deployed on Amazon EC2 instances in the private subnet. Which combination of rules should be defined on the private subnet’s Network ACL to allow access from internet-based clients?

(Select TWO.)

An inbound rule for port 443 from source 10.1.0.0/24

An outbound rule for port 443 to destination 10.1.0.0/24

An outbound rule for ports 1024 through 65535 to destination 10.1.0.0/24." is also a correct answer

An inbound rule for port 443 from source 0.0.0.0/0

An outbound rule for port 443 to destination 0.0.0.0/0

5.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which of the following AWS services can help you implement DDoS mitigation? (Choose THREE.)

Amazon Route 53

VPC Flow Logs

Amazon RDS

Amazon CloudFront

AWS Shield

6.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Alice has currently permission to access all actions of S3, EC2 services. When she assume a role which allows all actions of EC2 and Lambda, then what services Alice can access to?

S3, EC2

EC2, Lambda

S3, EC2, Lambda

Nothing

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Amazon Detective is a service used in what following stage of Layered Security Services?

Identify

Protect

Detect

Investigate

Respond

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Microsoft

Continue with Microsoft

or continue with

Facebook

Facebook

Apple

Apple

Others

Others

Already have an account?

Discover more resources for Professional Development