wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS ACF Módulo 4 - Segurança na nuvem

Total questions: 19

Worksheet time: 5hrs 31mins

Name
Class
Date
1.

A company needs to know which user was responsible for terminating several critical Amazon Elastic Compute Cloud (EC2) instances. Where can the customer find this information?

a)

AWS Trusted Advisor

b)

Amazon EC2 instance usage report

c)

Amazon CloudWatch

d)

AWS CloudTrail Logs

2.

What best describes the "Principle of Least Privilege"? Choose the correct answer from the options given below.

a)

All users should have the same baseline permissions granted to them to use basic AWS services

b)

Users should be granted permission to access only resources they need to do their assigned job.

c)

Users should submit all access request in written form so that there is a paper trail of who needs access to different AWS resources

d)

Users should always have a little more access granted to them than they need, just in case they end up needed in the future.

3.

You plan do deploy an application on AWS. This application needs to be PCI compliant. Which of the below steps are needed to ensure compliance? Choose 2 answers from below.

a)

Choose AWS services which are PCI Compliant

b)

Ensure the right steps are taken during application development for PCI Compliance

c)

Ensure the AWS Services are made PCI Compliante

d)

Do an audit after the deployment of the application for PCI Compliance.

4.

A startup company for social media apps would like to grant freelance developers temporary access to its Lambda functions setup on AWS. These developers should be signing-in via Facebook authentication. Which service is most appropriate to use in securely granting access?

a)

Create user credentials using Identity Access Management, IAM

b)

Use Amazon Cognito for web-identify federation

c)

Create temporary access roles using IAM

d)

Use a third-party Web ID, federated access provider

5.

During an organization's information system audit, the administrator is requested to provide a dossier of security and compliance reports as well as online service agreements that exist between the organization and AWS. Which service can they utilize to acquire this information?

a)

AWS Artifact

b)

AWS Resource Center

c)

AWS Service Catalog

d)

AWS Directory Service

6.

A new department has recently joined the organization and the administrator needs to compose access permissions for the group of users. Given that they have varying roles and access needs, what is the best-practice approach when granting access?

a)

After gathering information on their access needs, the administrator should allow every user to access the most common resources and privileges on the system.

b)

The administrator should grant all users the same permissions and then grant more upon request.

c)

The administrator should grant all users the least privilege and add more privileges to only to those who need it.

d)

Users should have no access and be granted temporary access on the occasions that they need to execute a task.

7.

There is an external audit being carried out on your company. The IT auditor needs to have a log of all access to the AWS resources in the company account. Which of the below services can assist in providing these details?

a)

AWS CloudWatch

b)

AWS CloudTrail

c)

AWS EC2

d)

AWS SNS

8.

A web administrator maintains several public and private web-based resources for an organization. Which service can they use to keep track of the expiry dates of SSL/TLS certificates as well as updating and renewal?

a)

AWS Data Lifecycle Manager

b)

AWS License Manager

c)

AWS Firewall Manager

d)

AWS Certificate Manager

9.

Which of the following services can be used as web application firewall in AWS?

a)

AWS EC2

b)

AWS WAF

c)

AWS Firewall

d)

AWS Protection

10.

Currently your organization has an operational team that takes care of ID management in their on-premise data center. They now also need to manage users and groups created in AWS. Which of the following AWS tools would they need to use performing this management function?

a)

AWS Config

b)

AWS CloudTrail

c)

AWS Key Management Service (AWS KMS)

d)

AWS Identity and Access Management (IAM)

11.

Which of the following is the responsibility of AWS according to the Shared Security Model? Choose 3 answers from the options given below.

a)

Managing AWS Identity and Access Management (IAM)

b)

Securing Edge Locations

c)

Monitoring physical device security

d)

Implementing service organization control (SOC) standards.

12.

By default, who from the below roles has complete administrative control over all resources in the respective AWS account?

a)

AWS Support Team

b)

AWS Account Owner

c)

AWS Security Team

d)

AWS Technical Account Manager (TAM)

13.

Which of the following security requirements are managed by AWS? Select 3 answers from the options given below.

a)

Password Policies

b)

User permissions

c)

Physical security

d)

Disk disposal

e)

Hardware patching

14.

Which of the following can be used as an additional layer of security to using a username and password when logging into the AWS Console?

a)

Multi-Factor Authentication (MFA)

b)

Secondary password

c)

Root access privileges

d)

Secondary username

15.

You have an EC2 instance in development that interacts with the Simple Storage Service. The EC2 Instance is going to be promoted to the production environment. Which of the following features should be used for secure communication between the EC2 Instance and the Simple Storage Service?

a)

IAM Users

b)

IAM Roles

c)

IAM Groups

d)

IAM Policies

16.

In a fully managed service such as Amazon Aurora, what are the implications of the Shared Responsability Model?

a)

Amazon is responsible for only the physical infrastructure on which the users data resides.

b)

Amazon is responsible for the EC2 instances, the operation system updates, patching of software and its maintenance.

c)

The user is responsible for the operating system updates, patching of software and its maintenance

d)

The user is responsible for the security of the EC2 instances on which the relational databases resides.

17.

In AWS, which security aspects are the customer's responsibility? Choose 4 answers from the options given below.

a)

Security Group and ACL (Access Control List) settings

b)

Encryption of EBS (Elastic Block Storage) volumes

c)

Patch management on the EC2 Instance's operation system

d)

Life-cycle management of IAM credentials

e)

Controlling physical access to compute resources

18.

Which of the following can be used to manage identities in AWS?

a)

AWS Config

b)

AWS IAM

c)

AWS Trusted Advisor

d)

AWS WAF

19.

In Identity Access Management (IAM), what is meant by Identity Federation? Select two most suitable statements.

a)

It is possible for users to log into the AWS environment using their Facebook, Twitter or LinkedIn login credentials.

b)

IAM Activity logs can be obtained in AWS CloudTrail then uploaded onto Amazon Athena tables for querying.

c)

A user with multiple AWS accounts and multiple log-in credentials can combine them into one set of login credentials for the multiple AWS accounts

d)

It is the temporary provision of access, using a temporary disposable set of credentials, to an untrusted user.

e)

An adminsitrator can configure identity federation so that users can access the AWS environment using their active directory credentials.