Your architecture consists of an Application Load Balancer front, an Auto Scaling Group of EC2 instances, backed by an RDS database. Your security team has notified you of cross-site scripting attacks and also SQL injection attacks on the application. You have been asked to take steps to quickly mitigate these attacks. What steps should you take?
aws test quiz

Quiz
•
Computers
•
9th - 12th Grade
•
Hard
John Francis Olivo
Used 3+ times
FREE Resource
20 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Using the AWS WAF service, set up rules which block SQL injection, and cross-site scripting attacks. Associate the rules to the ALB.
Use Amazon Inspector to detect these attacks and manually block the IP addresses from which these attacks come.
Immediately block the offending IP addresses on the NACL.
Configure Amazon GuardDuty to prevent these attacks.
2.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
You work for a doctor's surgery in New York City that has thousands of patients. The patients data is stored on-premises, but the backups need to be stored on S3 in the most secure way possible. Which of the following is the most secure way of achieving this?
Encrypt the data locally using your own encryption keys. Upload the data to AWS S3 using HTTP. Use AES 256 server side encryption on the S3 bucket to encrypt the bucket.
Store the data on AWS Fargate and use server-side encryption to encrypt the backups.
Upload the backups directly to a public S3 bucket.
Encrypt the data locally using your own encryption keys. Upload the data to AWS S3 using HTTPS. Use AES 256 server-side encryption on the S3 bucket to encrypt the bucket.
3.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
You have a web application running on an Amazon EC2 instance in a Virtual Private Cloud (VPC). You want to allow external users to access your web server over HTTP (port 80) while keeping your server secure. Which of the following actions should you take regarding the associated security group?
Create an inbound rule in the security group that allows incoming traffic on port 80 from your office IP address.
Create an inbound rule in the security group that allows incoming traffic on port 80 from 0.0.0.0/0 (any IP address).
Create an outbound rule in the security group that allows outgoing traffic on port 80 to 0.0.0.0/0 (any IP address) and configure an inbound rule for responses.
You do not need to add rules, by default security groups allow all inbound traffic.
4.
MULTIPLE CHOICE QUESTION
2 mins • 1 pt
You are developing an application that will run on EC2 and requires secure access to a backend RDS (Relational Database Service) running on MySQL. The application needs to utilize credentials to access the RDS database while ensuring communication between the application and RDS is encrypted. What is the most secure method of doing this?
Create a Lambda function which creates an IAM user for the EC2 instances running the application to use, hard code the credentials into the application. Have the Lambda function reset the password for the IAM user every 6 hours and update the code in the application. Download the certificate bundle for the AWS Region where the RDS database resides and import this into the EC2 instance used for the application. Modify the parameter group for the MySQL RDS instance to set the require_secure_transport parameter to ON.
Create an IAM user with the necessary permissions to access the RDS database. Configure a credentials file on the EC2 instance running the application so the application can read the credentials from this file when needing to authenticate to the RDS database. Download the certificate bundle for the AWS Region where the RDS database resides and import this to the EC2 instance used for the application. Modify the parameter group for the Microsoft SQL Server RDS instance to set the force ssl flag to on.
Enable IAM Database Authentication on the MySQL RDS instance, create an IAM Role for RDS access, and then associate the IAM role with a database user in RDS. Download the certificate bundle for the AWS Region where the RDS database resides and import this into the EC2 instance used for the application. Modify the parameter group for the MySQL RDS instance to set the require_secure_transport parameter to ON.
Create an IAM User with the necessary permissions to access the RDS database. Configure a credentials file on the EC2 instance running the application, so the application can read the credentials from this file when needing to authenticate to the RDS database. Download the certificate bundle for the AWS Region where the RDS database resides and import this to the EC2 instance used for the application. Modify the parameter group for the MySQL RDS instance to set the require_secure_transport parameter to ON.
5.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
A news media company is using an S3 bucket as a website to serve photos of television personalities within the company. The photos are intended to be served nationwide to local affiliates across the company, but you have found that these photos are being accessed and pirated for other websites not affiliated with the company. What can you do to stop this?
Use CloudFront on the front end to serve the photos.
Remove public read access from your bucket, then provide your users with presigned URLs to access the photos.
Set up an RDS database to store the photos. Make users register and log in to the site.
Use a Network Access Control List (NACL) to block the IP address of unauthorized users.
6.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
You work for a real estate company that hosts some production services on AWS. Unfortunately, a junior system administrator leaves a CSV file containing Personally Identifiable Information (PII) about the businesses customers on a public S3 bucket. You need to prevent this from happening in the future. What AWS service uses machine learning (ML) and pattern matching to discover and protect PII?
Amazon GuardDuty
Amazon Macie
AWS Shield
AWS CloudTrail
7.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Jessica is a Database Administrator who has been given the task to migrate all the team Oracle databases running on on-premises virtual machines to the AWS cloud. During the migration efforts, it was requested that she find an automated way to convert to using an Amazon Aurora PostgreSQL database instead of Oracle as well as replicating any ongoing transactions during the migration itself.
Which AWS service configurations would Jessica use in this scenario?
Manually convert the Oracle database to PostgreSQL on-premises. Use AWS MGN to migrate the server to the AWS cloud. Then, create an AWS DMS task to replicate data changes only and configure the source as the on-premises PostgreSQL database VM and the target as the Amazon EC2 instance running PostgreSQL.
Use the Amazon Aurora Serverless migration conversion tool to easily convert to a PostgreSQL database during the migration.
Create a new AWS DMS task using the Migrate existing data and replicate ongoing changes (CDC) option to migrate to AWS while capturing changed data.
Use the AWS DMS SCT to enable CDC on the migration task so that changed data is captured during the migration efforts.
Create a free account and access millions of resources
Similar Resources on Quizizz
19 questions
Quiz on Virtualization and Cloud Computing

Quiz
•
12th Grade
21 questions
CLOUD COMPUTING CHAPTER 1

Quiz
•
9th - 12th Grade
17 questions
TCP/IP

Quiz
•
11th Grade
15 questions
J277 Networks and Protocols

Quiz
•
8th - 10th Grade
18 questions
Technology Uses

Quiz
•
12th Grade
16 questions
Troubleshooting

Quiz
•
7th - 9th Grade
16 questions
IT Jobs and Careers

Quiz
•
9th - 12th Grade
20 questions
Software Applications

Quiz
•
9th - 10th Grade
Popular Resources on Quizizz
15 questions
Character Analysis

Quiz
•
4th Grade
17 questions
Chapter 12 - Doing the Right Thing

Quiz
•
9th - 12th Grade
10 questions
American Flag

Quiz
•
1st - 2nd Grade
20 questions
Reading Comprehension

Quiz
•
5th Grade
30 questions
Linear Inequalities

Quiz
•
9th - 12th Grade
20 questions
Types of Credit

Quiz
•
9th - 12th Grade
18 questions
Full S.T.E.A.M. Ahead Summer Academy Pre-Test 24-25

Quiz
•
5th Grade
14 questions
Misplaced and Dangling Modifiers

Quiz
•
6th - 8th Grade
Discover more resources for Computers
17 questions
Chapter 12 - Doing the Right Thing

Quiz
•
9th - 12th Grade
30 questions
Linear Inequalities

Quiz
•
9th - 12th Grade
20 questions
Types of Credit

Quiz
•
9th - 12th Grade
20 questions
Taxes

Quiz
•
9th - 12th Grade
17 questions
Parts of Speech

Quiz
•
7th - 12th Grade
20 questions
Chapter 3 - Making a Good Impression

Quiz
•
9th - 12th Grade
20 questions
Inequalities Graphing

Quiz
•
9th - 12th Grade
10 questions
Identifying equations

Quiz
•
KG - University