WorksheetsAWS ACF Módulo 4 - Segurança na nuvem
Total questions: 19
Worksheet time: 5hrs 31mins
A company needs to know which user was responsible for terminating several critical Amazon Elastic Compute Cloud (EC2) instances. Where can the customer find this information?
AWS Trusted Advisor
Amazon EC2 instance usage report
Amazon CloudWatch
AWS CloudTrail Logs
What best describes the "Principle of Least Privilege"? Choose the correct answer from the options given below.
All users should have the same baseline permissions granted to them to use basic AWS services
Users should be granted permission to access only resources they need to do their assigned job.
Users should submit all access request in written form so that there is a paper trail of who needs access to different AWS resources
Users should always have a little more access granted to them than they need, just in case they end up needed in the future.
You plan do deploy an application on AWS. This application needs to be PCI compliant. Which of the below steps are needed to ensure compliance? Choose 2 answers from below.
Choose AWS services which are PCI Compliant
Ensure the right steps are taken during application development for PCI Compliance
Ensure the AWS Services are made PCI Compliante
Do an audit after the deployment of the application for PCI Compliance.
A startup company for social media apps would like to grant freelance developers temporary access to its Lambda functions setup on AWS. These developers should be signing-in via Facebook authentication. Which service is most appropriate to use in securely granting access?
Create user credentials using Identity Access Management, IAM
Use Amazon Cognito for web-identify federation
Create temporary access roles using IAM
Use a third-party Web ID, federated access provider
During an organization's information system audit, the administrator is requested to provide a dossier of security and compliance reports as well as online service agreements that exist between the organization and AWS. Which service can they utilize to acquire this information?
AWS Artifact
AWS Resource Center
AWS Service Catalog
AWS Directory Service
A new department has recently joined the organization and the administrator needs to compose access permissions for the group of users. Given that they have varying roles and access needs, what is the best-practice approach when granting access?
After gathering information on their access needs, the administrator should allow every user to access the most common resources and privileges on the system.
The administrator should grant all users the same permissions and then grant more upon request.
The administrator should grant all users the least privilege and add more privileges to only to those who need it.
Users should have no access and be granted temporary access on the occasions that they need to execute a task.
There is an external audit being carried out on your company. The IT auditor needs to have a log of all access to the AWS resources in the company account. Which of the below services can assist in providing these details?
AWS CloudWatch
AWS CloudTrail
AWS EC2
AWS SNS
A web administrator maintains several public and private web-based resources for an organization. Which service can they use to keep track of the expiry dates of SSL/TLS certificates as well as updating and renewal?
AWS Data Lifecycle Manager
AWS License Manager
AWS Firewall Manager
AWS Certificate Manager
Which of the following services can be used as web application firewall in AWS?
AWS EC2
AWS WAF
AWS Firewall
AWS Protection
Currently your organization has an operational team that takes care of ID management in their on-premise data center. They now also need to manage users and groups created in AWS. Which of the following AWS tools would they need to use performing this management function?
AWS Config
AWS CloudTrail
AWS Key Management Service (AWS KMS)
AWS Identity and Access Management (IAM)
Which of the following is the responsibility of AWS according to the Shared Security Model? Choose 3 answers from the options given below.
Managing AWS Identity and Access Management (IAM)
Securing Edge Locations
Monitoring physical device security
Implementing service organization control (SOC) standards.
By default, who from the below roles has complete administrative control over all resources in the respective AWS account?
AWS Support Team
AWS Account Owner
AWS Security Team
AWS Technical Account Manager (TAM)
Which of the following security requirements are managed by AWS? Select 3 answers from the options given below.
Password Policies
User permissions
Physical security
Disk disposal
Hardware patching
Which of the following can be used as an additional layer of security to using a username and password when logging into the AWS Console?
Multi-Factor Authentication (MFA)
Secondary password
Root access privileges
Secondary username
You have an EC2 instance in development that interacts with the Simple Storage Service. The EC2 Instance is going to be promoted to the production environment. Which of the following features should be used for secure communication between the EC2 Instance and the Simple Storage Service?
IAM Users
IAM Roles
IAM Groups
IAM Policies
In a fully managed service such as Amazon Aurora, what are the implications of the Shared Responsability Model?
Amazon is responsible for only the physical infrastructure on which the users data resides.
Amazon is responsible for the EC2 instances, the operation system updates, patching of software and its maintenance.
The user is responsible for the operating system updates, patching of software and its maintenance
The user is responsible for the security of the EC2 instances on which the relational databases resides.
In AWS, which security aspects are the customer's responsibility? Choose 4 answers from the options given below.
Security Group and ACL (Access Control List) settings
Encryption of EBS (Elastic Block Storage) volumes
Patch management on the EC2 Instance's operation system
Life-cycle management of IAM credentials
Controlling physical access to compute resources
Which of the following can be used to manage identities in AWS?
AWS Config
AWS IAM
AWS Trusted Advisor
AWS WAF
In Identity Access Management (IAM), what is meant by Identity Federation? Select two most suitable statements.
It is possible for users to log into the AWS environment using their Facebook, Twitter or LinkedIn login credentials.
IAM Activity logs can be obtained in AWS CloudTrail then uploaded onto Amazon Athena tables for querying.
A user with multiple AWS accounts and multiple log-in credentials can combine them into one set of login credentials for the multiple AWS accounts
It is the temporary provision of access, using a temporary disposable set of credentials, to an untrusted user.
An adminsitrator can configure identity federation so that users can access the AWS environment using their active directory credentials.
