Font size
WorksheetsSecurity
Total questions: 165
Worksheet time: 2hrs 36mins
IT security or cybersecurity is
about protecting computers, networks, programs, and data from unintended or malicious access, change, or destruction
is also about ensuring that business functions and personal tasks can still be performed with minimal interference at a reasonable response or throughput rate.
3 Perspektif CIA?
Confidentiality
Integrity
Availability
Confidentiality adalah?
Apakah data pribadi dilindungi untuk mencegah akses yang tidak sah?
Apakah ada langkah-langkah untuk memastikan bahwa data tidak dirusak, dan benar serta otentik?
Apakah pengguna yang berwenang dapat mengakses data saat mereka membutuhkannya?
Integrity adalah?
Apakah data pribadi dilindungi untuk mencegah akses yang tidak sah?
Apakah ada langkah-langkah untuk memastikan bahwa data tidak dirusak, dan benar serta otentik?
Apakah pengguna yang berwenang dapat mengakses data saat mereka membutuhkannya?
Availability adalah?
Apakah data pribadi dilindungi untuk mencegah akses yang tidak sah?
Apakah ada langkah-langkah untuk memastikan bahwa data tidak dirusak, dan benar serta otentik?
Apakah pengguna yang berwenang dapat mengakses data saat mereka membutuhkannya?
Beberapa ancaman security?
Password events
Man-in-the-middle
Drive by
Man-in-the-middle
Social engineering
Apa itu password event?
A process of recovering passwords from data that has been stored or transmitted by a computer system.
Multiple compromised systems are used to compromise a single system.
An outside party secretly relays the communication between two parties, who believe that they are communicating directly with each other.
An event that uses human interaction to manipulate a person to break security procedures to gain access to security details and break through systems
Cybercriminals use unsecure websites to plant malicious codes
Apa itu Distributed denial of service (DDoS)?
A process of recovering passwords from data that has been stored or transmitted by a computer system.
Multiple compromised systems are used to compromise a single system.
An outside party secretly relays the communication between two parties, who believe that they are communicating directly with each other.
An event that uses human interaction to manipulate a person to break security procedures to gain access to security details and break through systems
Cybercriminals use unsecure websites to plant malicious codes
Apa itu Distributed Social engineering?
A process of recovering passwords from data that has been stored or transmitted by a computer system.
Multiple compromised systems are used to compromise a single system.
An outside party secretly relays the communication between two parties, who believe that they are communicating directly with each other.
An event that uses human interaction to manipulate a person to break security procedures to gain access to security details and break through systems
Cybercriminals use unsecure websites to plant malicious codes
Apa itu Distributed Man-in-the-middle ?
A process of recovering passwords from data that has been stored or transmitted by a computer system.
Multiple compromised systems are used to compromise a single system.
An outside party secretly relays the communication between two parties, who believe that they are communicating directly with each other.
An event that uses human interaction to manipulate a person to break security procedures to gain access to security details and break through systems
Cybercriminals use unsecure websites to plant malicious codes
Apa itu Distributed drive by ?
A process of recovering passwords from data that has been stored or transmitted by a computer system.
Multiple compromised systems are used to compromise a single system.
An outside party secretly relays the communication between two parties, who believe that they are communicating directly with each other.
An event that uses human interaction to manipulate a person to break security procedures to gain access to security details and break through systems
Cybercriminals use unsecure websites to plant malicious codes that are automatically downloaded to users’ computers
types of security?
System security
Infrastucture Security
Access management
identity management, physical security
Data security, software security
Kontrol keamanan dibagi menjadi 3 apa saja?
preventive
detective
corrective
security life cycle
prevention
detection
response
analysis
Corrective
Apa itu preventif?
The first line of defense.
Occurs when prevention fails.
Describes what you do upon detection of a security issue
Completes the cycle as you implement new preventative measures to prevent the issue from occurring again in the future.
Apa itu Detection?
The first line of defense.
Occurs when prevention fails.
Describes what you do upon detection of a security issue
Completes the cycle as you implement new preventative measures to prevent the issue from occurring again in the future.
Apa itu Response?
The first line of defense.
Occurs when prevention fails.
Describes what you do upon detection of a security issue
Completes the cycle as you implement new preventative measures to prevent the issue from occurring again in the future.
Apa itu Analysis?
The first line of defense.
Occurs when prevention fails.
Describes what you do upon detection of a security issue
Completes the cycle as you implement new preventative measures to prevent the issue from occurring again in the future.
Which term refers to approaches to information security or strategies for network security that are used to implement several defense layers?
Defense-in-depth
Simplicity in security
Data protection
Layered security
Which tool can automatically detect security weakness in a host?
Firewall
Scanner
Protocol analyzer
Security policy
Which statement describes the function of the traceroute utility?
It determines the journey of a packet of data from its source to its destination.
It watches and stores all traffic that goes through a network.
It discovers network traffic.
It maps networks.
Which utilities are usually associated with Internet Control Message Protocol (ICMP)? (Select TWO.)
tcpdump
nslookup
ping
traceroute
dig
Which organization is responsible for assigning IP addresses worldwide?
Internet Assigned Numbers Authority (IANA)
Common Vulnerabilities and Exposures (CVE)
American Registry for Internet Numbers (ARIN)
Regional internet registry (RIR)
The hardening process berfungsi untuk
melibatkan pengurangan jumlah layanan yang berjalan pada suatu sistem.
a
cara umum untuk harden system
Turning off services that are not needed.
Implementing corporate policies and restrictions
Regularly applying security updates and patches.
panduan pengembangan software securiti
change management, peer review
separation of duties, code escrow
quality assurance
production and development teams
backround check on programmer
which tool can access the interactions between a source and destination by IP address, media access control (MAC) address, port, and protocol?
netstat
wireshark
nexpose
ping
Which tool is a virtual trap that lures malicious actors and gains their information by functioning like a normal computer system?
Switch configuration
Router
Client
Honeypot
Which task helps to harden a system?
Enabling unused services.
Applying patches regularly.
Allowing all permissions for all groups.
Disabling used services.
What is a security baseline?
A starting point for determining what to secure and how to secure it.
A starting point that uses an abnormal condition to determine what to secure.
An ending point for determining how to secure a resource.
A way to provide information that’s related to company documentation and abnormal conditions.
What is the primary goal of systems hardening?
To keep all devices and services running so that they can run processes and scripts in the background.
To reduce isolated security risks by having as many systems as possible be up and running.
To minimize security risks by reducing the set of vulnerabilities that are exposed by a system.
To reduce security risks by setting a schedule of patches, regardless of time, to run once a year.
access control list (ACL) adalah
rules that grant or deny access to the network.
a
A network-based intrusion detection system (NIDS)?
memindai lalu lintas jaringan langsung untuk mengidentifikasi lalu lintas dan anomali protokol dan melaporkannya.
a
ada 2 A network-based intrusion detection system (NIDS) apa saja?
signature-based detection
and behavior-based detection.
Signature-based detection bekerja dengan?
membandingkan lalu lintas jaringan dengan database pola berbahaya yang diketahui dan memberi tahu Anda saat mendeteksi kecocokan.
Jenis deteksi ini menggunakan seperangkat aturan atau baseline yang diketahui untuk mendeteksi anomali atau apa pun yang dianggap di luar norma.
Behavior-based detection bekerja dengan?
membandingkan lalu lintas jaringan dengan database pola berbahaya yang diketahui dan memberi tahu Anda saat mendeteksi kecocokan.
Jenis deteksi ini menggunakan seperangkat aturan atau baseline yang diketahui untuk mendeteksi anomali atau apa pun yang dianggap di luar norma.
Host-based intrusion detection system?
melindungi critical files
mencegah perilaku perubahan yang membuat corrupt
mengidentifikasi aplikasi penipu
melengkapi antivirus software
Backdoor threat adalah
A vulnerability that allows an attacker to bypass normal security checks and access a system.
A vulnerability that allows an attacker to access a system as a privileged (root) user in an undetected fashion.
Rootkit threat adalah
A vulnerability that allows an attacker to bypass normal security checks and access a system.
A vulnerability that allows an attacker to access a system as a privileged (root) user in an undetected fashion.
Firewalls?
firewalls allow you to create rules and exceptions that help control network traffic.
a
Firewalls categories?
packet filters
stateful packet inspection
application level
Tipe konfigurasi untuk perimeter zone
Back-to-back (The perimeter zone is placed between two firewalls)
Three-leg (The perimeter zone is behind the same firewall)
NAT fungsinya adalah?
translates private address ke public address
a
PAT fungsinya adalah?
Associates multiple private address dengan satu public address
a
Network Access Control List (ACL) berfungsi untuk?
inspect system that are connected to protected segment to verify compliance with a security policy
a
Network ACL berfungsi untuk?
Verify antivirus
Make sure that a firewall is enabled
verify anti-spyware
Which statements describe the function of a network layer route? (Select TWO.)
It’s an access control list (ACL) that restricts the traffic allowed in the network.
It can support network segmentation.
It’s a subnet, which shouldn’t be used to isolate part of the network.
It’s a router that should be used for advanced packet-filtering techniques.
It’s used as a tool to create network segmentation.
Which statement describes the function of a network-based intrusion detection system (NIDS)?
It’s designed to respond to network attacks.
It creates virtual large area networks (VLANs).
It monitors network activity by using signature-based detection and rules to detect malicious patterns.
It creates rules and exceptions that help control network traffic.
Which statement describes the purpose of a firewall?
It creates rules and exceptions that help control network traffic.
It’s an assurance that a computer on a network won’t be attacked.
It filters packets that are directed to the client on a network.
It filters packets on only one subnet.
What is Network Address Translation (NAT)?
A protocol that translates public IP addresses to private IP addresses, and private IP addresses to public IP addresses
A protocol that associates multiple private IP addresses with one public IP address
A protocol that’s used when a network is segmented into public subnets and private subnets
A protocol that translates between publicly visible ports and internal ports
Which type of network zone is an intranet?
Uncontrolled zone
Fully controlled zone
Restricted zone
Demilitarized zone
Security group itu adalah?
seperti firewall pada virtual server yang bisa memfilter traffic pada instance.
a
Yang bertindak sebagai firewall untuk associated Amazon Elastic Compute Cloud (Amazon EC2) instances
Security groups
Network access controls lists (network ACLs)
Yang bertindak sebagai firewall untuk subnet terkait
Security groups
Network access controls lists (network ACLs)
Amazon EC2 TIDAK MENGGUNAKAN public key cryptography untuk encrypt and decrypt login information. TRUE or FALSE
TRUE
FALSE
public key digunakan untuk
encrypt a piece of data.
decrypt the data
private key digunakan untuk
encrypt a piece of data.
decrypt the data
Key pair juga berfungsi untuk?
masuk Secure Shell (SSH) di Linux
masuk Remote Desktop Protocol (RDP) di windows
Security groups itu?
Stateful
Stateless
network ACLs itu?
Stateful
Stateless
Maksud dari statefull?
means that the computer tracks the state of interaction.
means that no information is retained by the sender or receiver.
Maksud dari stateless?
means that the computer tracks the state of interaction.
means that no information is retained by the sender or receiver.
apa perbedaan port 80 dengan port 443
proses komunikasi data antara browser dan web. port 80 itu HTTP jadi tidak terenkripsi, sedang 443 HTTPS terenkripsi.
proses komunikasi data antara browser dan web. port 80 itu HTTP jadi tidak terenkripsi, sedang 443 HTTP jadi tidak terenkripsi.
Kita bisa mengatur security group di?
AWS management console
a
What is an Amazon Web Services (AWS) security group?
A group of users that are allowed to access resources
A group of servers that are configured to protect resources
A firewall that protects resources
An application that is installed on resources to protect them
Which type of resource does a security group protect?
Virtual server
Router
Subnet
Switch
What are the basic parts of a security group rule? (Select TWO.)
Media Access Control (MAC) address
IP address
Virtual Private Cloud (VPC) name
Port number
Route table name
Which statement describes the stateful nature of a security group?
Responses to allowed inbound traffic require a separate outbound rule to flow out.
All inbound traffic is allowed by default.
Responses to allowed inbound traffic are automatically allowed to flow out.
All outbound traffic is blocked by default.
Which statement describes security groups?
A security group is configured by using Linux permissions.
A security group controls traffic at the subnet level.
A security group contains only one rule.
A security group controls traffic at the instance level.
menonatifkan perangkat jaringan dapat memengaruhi sebagian besar jaringan. sehingga kita harus menerapkan: authentication, authorization, and accounting (AAA). cara membatasi akses:
Limit who is allowed administrative access.
Limit how the devices are accessed
Limit where the devices are accessed
1. How many firewalls should you have in your network?
As many as make sense. More specifically, the answer will depend on your network topology and security requirements.
a
Where should you place network firewalls?
Position firewalls at the junction points of the network as close to the source as possible to identify bad traffic, stop bad traffic, or do both.
a
Network segmentation berguna untuk
untuk meningkatkan keamanan
a
Menonaktifkan discovery protocol berguna untuk
mencegah pihak luar menggunakan protokol tersebut untuk mendapatkan informasi penting tentang jaringan Anda.
a
Mendirikan akses secure
menonaktifkan protokol yg tidak aman: TELNET, HTTP, SNMP v1
membatasi subnet di mana lalu lintas manajemen dapat berasal
menghapus semua jalan traffic akses ke device secara langsung
AAA
What is a technique that is used for network hardening?
Allowing all users remote administrative access.
Connecting all resources by using a single network.
Implementing authentication, authorization, and accounting (AAA).
Configuring all routers to use the default settings.
What is logging access an example of in authentication, authorization, and accounting (AAA)?
Availability
Authentication
Authorization
Accoutning
What is an example of segmenting a network?
Team A is in subnet A and team B is in subnet B.
Team A and B are in one subnet.
Team A has administrator permissions to access all of Team B's resources.
All members of team B have root permissions in their own subnet.
Which protocol should be disabled if it isn’t used and protected if used?
Secure Sockets Layer (SSL)
Secure HTTP (HTTPS)
Simple Network Management Protocol (SNMP) v1
Transport Layer Security (TLS)
What is a best practice for traffic filtering?
Explicitly allow all traffic and deny restricted sites.
Explicitly deny all traffic, then permit only needed traffic.
Filter traffic through a firewall furthest from the server as possible.
Accept all traffic that is directed to network control devices.
disiplin ilmu yang mewujudkan prinsip dan teknik untuk menyediakan keamanan data, termasuk kerahasiaan dan integritas data.
Cryptography
a
Ada 3 jenis enkripsi
symmetric,
asymmetric,
hybrid.
Symetric encription? (choose 3)
Advanced Encryption Standard (AES)
International Data Encryption Algorithm (IDEA)
Twofish
Rivest–Shamir–Adleman (RSA)
Diffie-Hellman (DH)
Symetric encription? (choose 3)
ElGamal
International Data Encryption Algorithm (IDEA)
Twofish
Rivest–Shamir–Adleman (RSA)
Diffie-Hellman (DH)
Protokol yang menggunakan enkripsi hybrid adalah
Transmission Layer Security (TLS), juga dikenal sebagai Secure Sockets Layer (SSL).
a
Contoh penggunaan data encryption pada data at rest (select 2)
Encrypting a file system
Drive encryption
SSL
Kerberos
Contoh penggunaan data encryption pada data at montion (select 4)
IP Security (IPsec)
Instant messaging or secure email
SSL
Kerberos
Drive encryption
Untuk memastikan integritas data kita menggunakan teknik?
enkripsi
criptography
hash
Macam-macam permission? (Choose 2)
Discretionary
Role-based
Which of the following terms best describes the discipline which embodies the principles and techniques for providing data security?
Data integrity
Encryption
Cryptography
Decryption
Which of the following is an advantages of symmetric encryption?
It can not encrypt and decrypt large amounts of data without compromising speed.
Encryption uses both a private key and a public key (a key pair)
The key is a shared secret between the sender and the receiver.
Symmetric encryption has a complex encryption structure.
Symmetric encryption is considered to be more secure than asymmetric encryption.
What is the goal of encryption?
Confidentiality
Integrity
Accuracy
Authentication
What protocols use the hybrid encryption method as a mode of encryption? (SELECT TWO.)
Transmission Layer Security (TLS)
Transmission Layer Security (TLS)
Transmission Control Protocol (TCP)
Hyper-Text Transfer Protocol (HTTP)
Internet Protocol (IP)
Which of the following is a standard asymmetric encryption algorithm?
Rivest–Shamir–Adleman (RSA)
Advanced Encryption Standard (AES)
International Data Encryption Algorithm (IDEA)
Twofish Encryption
are electronic credentials that are used to represent online identities of individuals, computers, and other entities on a network.
Digital certificates
a
Two types of certificates are available:
Certificates signed by a CA
self-signed certificates
In the AWS Cloud, we can use to obtain certificates from the internal AWS..
AWS Certificate Manager service
a
An expired or revoked certificate cannot be used because
it is added to the certificate revocation list (CRL)
a
What signs and issues certificates to entities, and manages trusts and relationships?
Certificate authorities (CAs)
Certificates
Registration authorities (RAs)
Revocation lists
What is a digital certificate?
An electronic credential that is used to verify and validate an individual or computer
A root certificate that is external, and services other entities
A certificate that is used to represent the online identity or computer
An electronic credential that is used to represent an individual, computer, or other entity's online identity
Which resource is used with Secure Sockets Layer (SSL) and Transport Layer Security (TLS) to establish a secure connection between a client and server?
Public key
Private key and public key
Private key
Certificate authority (CA)
A company's site is giving users an error that the certificate authority (CA) is invalid. What could be the cause of this issue?
The CA certificate is expired.
The user has a connection issue.
The company’s server is down.
The user is using a root CA.
How is trust achieved?
Through public keys and private keys that validate the identities of the parties
By an external certificate authority (CA) that validates the identities of the parties
Through the exchange of public keys that validate the identities of the parties
Through the exchange of private keys that validate the identities of the parties
SSO mengizinkan untuk google login ke akun FB (T/F)
TRUE
FALSE
is an example of an identity provider on the AWS Cloud
Amazon Cognito
A
Which of the features below correctly correspond to the step in Identification and Authentication, Authorization and Accountability (IAAA)?
Accounting --> Tracking
Authorization --> Uniqueness
Authentication --> Validation
Identification --> Verification
Which is an authentication factor for something you are?
Fingerprint reader
Passphrase
Smart card
USB key
What type of table is used to store hashes of possible passwords?
Hash table
Horizon table
Rain table
Rainbow table
Select two features of Brute force attacks.
GPUs are used to accelerate cracking
Password cracking tests 10 % of password possibilities within the range of parameters.
Range of parameters are undefined
The brute force attack relies on all password possibilities
What is a form of single sign-on in which one account is used for multiple services?
Independent identities
Federated Identities
Relationship Identities
Directory Identities
You have decided to include a physical object authentication factor in a security plan you are writing for your department.
Which are possible options you could consider for your plan? Select three responses.
Smart card
Password
Physical key
USB key
You have a password policy as an additional layer in your department's security plan. All parameters provide for a strong, secure password EXCEPT:
Minimum of 3 characters
Password must be changed every 30 days
Password must included a mixture of capital & lower case letters, numbers and special characters
Password has reversible encryption capability
Gunakan IAM untuk
Manage the resources that can be accessed and the actions that can be performed on the resources
Define required credentials based on context,
Kita bisa mengakses AWS service dengan menggunakan beberapa cara
AWS Management Console
AWS Command Line Interface (AWS CLI)
Software development kits (SDKs) and application programming interfaces (APIs) from a variety of supported environments
What is the goal of identity management?
Detect security threats and notify users
Identify all systems that can be accessed by users
Manage the responses to security threats based on user type
Administer users and their access permissions
Which security steps are performed during a typical login? (Select TWO.)
Authentication
Consolidation
Authorization
Prevention
Activation
What is an example of an authentication factor?
Encryption algorithm
Certificate
Authentication server
Firewall policy
Which personal attribute works well as an authentication factor?
Height
Retina
Weight
Age
What is a best practice for identity management?
Implement password policies.
Avoid single sign-on.
Manage passwords manually.
Use group accounts.
What is a database injection attack?
An application that takes over other applications in a database server
An attempt to circumvent security controls by deceiving people to reveal backend data
A program that installs itself and infects the memory of a database server
An attack that introduces malicious data to a backend system through a frontend mechanism
Which action can help prevent software vulnerabilities?
Use firewalls.
Perform code reviews.
Verify the integrity of the file system.
Control user permissions.
What is considered to be a highly effective defense against social engineering attacks?
Hiring top security experts
Hardening systems
Rewarding safe employees
Training and education
What is a countermeasure against malware?
Regularly scan systems.
Monitor routers.
Log user access.
Scale virtual servers.
Which threats are a type of malware? (Select TWO.)
Distributed denial of service (DDoS)
Virus
Ransomware
Phishing
Social engineering
What is AWS CloudTrail?
A web service that uses log files to record Amazon Web Service (AWS) application programming interface (API) calls.
A web service that controls other Amazon Web Services (AWS) services through application programming interface (API) calls.
A web service that manages users and permissions.
A web service that assesses application vulnerabilities.
What are key benefits of AWS CloudTrail? (Select TWO.)
It provides visibility by recording users and resource activities.
It improves application security by filtering inbound and outbound data.
It simplifies compliance audits by recording activities and events into logs files.
It simplifies threat detection by detecting malicious activities.
It enables migration from on-premises applications to the Amazon Web Services (AWS) Cloud.
Which types of information are captured by AWS CloudTrail events when a user performs a service request? (Select TWO.)
The Amazon Web Services (AWS) application programming interface (API) calls that the user request triggers
The cost of the call to the service
The size of the request in kilobytes (KB)
The user who performed the request
The IP address where the request originated
Which statements are best practices for working with AWS CloudTrail? (Select TWO.)
Aggregate log files to a single Amazon Simple Storage Service (Amazon S3) bucket.
Enable file validation for CloudTrail.
Integrate CloudTrail with AWS Elastic Compute Cloud (Amazon EC2).
Integrate CloudTrail with AWS Lambda.
Ensure that CloudTrail is available only in one AWS Region.
Why is integrating AWS CloudTrail with AWS CloudWatch considered to be a good practice?
CloudWatch monitors and reacts to events that involve CloudTrail log files.
CloudWatch transforms CloudTrail log files into a file format that the user defines.
CloudWatch secures access to CloudTrail log files.
Users can use CloudWatch to create a dashboard that is based on CloudTrail log files.
What is AWS Config?
A tool that helps reduce cost.
A tool that logs application programming interface (API) calls to Amazon Web Services (AWS) services in log files.
A tool that tracks changes to resources.
A tool that helps configure secure networks on Amazon Web Services (AWS).
What are features of AWS Config? (Select TWO.)
Retrieve inventory from Amazon Web Services (AWS) resources.
Send notifications when a configuration change has occurred in an Amazon Web Services (AWS) resource.
Send a notification when a threat to Amazon Web Services (AWS) resources is detected.
Check for service usage to see the limits of the service.
Enable users to set up more secure security groups.
Which tool enables customers to define custom rules for AWS Config?
AWS Lambda
AWS CloudFormation
AWS Elastic Beanstalk
Amazon API Gateway
What are actions that AWS Config takes when a configuration change occurs on an Amazon Web Services (AWS) service ? (Select TWO.)
The change is logged, and then stored in an Amazon Simple Storage Service (Amazon S3) bucket.
AWS Config calls AWS Trusted Advisor to assess the security level of applications.
AWS Config sends a notification by using AWS Simple Notification Service (AWS SNS).
AWS Config calls AWS CloudTrail to log the change into log files.
Which tasks can an AWS Config rule help achieve?
Logging Elastic IP addresses that are attached to instances
Verifying that multi-factor authentication (MFA) on the account root user is not activated
Sending a warning if a security group has unrestricted access permissions
Sending a warning if server access logging is enabled on Amazon Simple Storage Service (Amazon S3) buckets.
Which types of plans are used to minimize the impact of unplanned downtime? (Select TWO.)
Test plan
Business continuity plan
Disaster recovery (DR) plan
Software management plan
Quality assurance (QA) plan
Which types of plans are used to minimize the impact of unplanned downtime? (Select TWO.)
Test plan
Business continuity plan
Disaster recovery (DR) plan
Software management plan
Quality assurance (QA) plan
What is the purpose of the business continuity plan?
To define how to run the business in a reduced form
To define how to recover from an outage loss
To define how to investigate any security eventx
To define how to investigate any security event
To define the Recovery Time Objective (RTO) and the Recovery Point Objective (RPO)
What is the purpose of the disaster recovery (DR) plan?
To define how to run the business in a reduced form after a disaster occurs
To define how to restore business functionality quickly after a disaster occurs
To list different disaster scenarios and the actions that the business will take to keep the business running
To define how to minimize the Recovery Time Objective (RTO) and the Recovery Point Objective (RPO)
Which statements describe the purpose of the Recovery Point Objective (RPO)? (Select TWO.)
Its focus is on recovering the entire IT infrastructure.
Its focus is on recovering only data.
It represents how much data loss a business can tolerate.
It establishes the maximum amount of time a resource can be unavailable.
It defines the Work Recovery Time (WRT).
What are best practices for backing up data? (Select TWO.)Fully back up critical data once a year. Use remote storage. Store backups on a portable hard drive. Avoid multiple backup solutions. Encrypt backup files.
Fully back up critical data once a year.
Use remote storage.
Store backups on a portable hard drive.
Avoid multiple backup solutions.
Encrypt backup files.
What does a monitoring policy define? (Select TWO.)
Who performs the monitoring?
Who reviews the policy?
When is the policy approved?
What resources are to be monitored?
Where is the policy stored?
A company has just recovered from a Trojan horse security breach and is performing a security analysis. Which questions should the company ask during the analysis? (Select TWO.)
Can the company file charges against the attacker?
How should the breach be reported to the public?
Who is the manager that allowed the breach to happen?
How did the breach happen?
How could the breach have been prevented?
What is a benefit of monitoring and logging?
It increases application performance.
It prevents security threats.
It provides the data that is used for problem identification.
It corrects security threats.
Which step is performed during root cause analysis (RCA)?
Establish a projection for when business will return to normal.
Establish a timeline, starting with normal operations and ending with the problem’s occurrence.
Describe the actions to perform when a problem occurs.
Implement preventative measures to protect resources.
Which phase of the security life cycle reviews what happened after a security breach?
Analysis
Detection
Prevention
Response
Which are the categories in which Trusted advisor provide best practices? (Select TWO.)
Cost optimization
Events monitoring
Users rights and permissions
Threat detection
Fault tolerance
Which of the following Trusted Advisor checks are available for free? (Select TWO.)
Low utilization of Amazon EC2 instances
Multi-factor authentication (MFA) on the root account
AWS Identity and Access Management (IAM) use
AWS Identity and Access Management (IAM) policy
Amazon S3 bucket logging
What does an AWS Trusted Advisor Red check (Exclamation point (!) ) mean?
Action is recommended
Action is required
Services that raised red flags were deactivated(.)
An Investigation is recommended
What is the service limit threshold that triggers a warning from the service limits check?
80 percent
70 percent
90 percent
95 percent
AWS Trusted Advisor raises a Security Groups - Unrestricted Access Red check (Exclamation point (!) ) status. Which action should be taken?
Add rules that give access to a few known IP addresses to the identified security group
Add a rule that forbids all inbound access to the identified security group
Add a rule that forbids all outbound access to the identified security group
Transform all public subnets into private subnets
What is used to authenticate the Amazon Web Services (AWS ) account root user in the AWS Management Console?
Key pair
Email address
Access key
User name
Which type of permissions does an Amazon Web Services (AWS) account root user have?
Complete access to all AWS services and resources
Administrator access to all AWS services except managed services
Complete access to only AWS security services
Administrator access to AWS Identity and Access Management (IAM), and limited access to all other services
Which logging service should be immediately enabled as a best practice when creating an Amazon Web Services (AWS) account?
Amazon CloudWatch
AWS Config
AWS Control Tower
AWS CloudTrail
What is a best practice when creating a user in an Amazon Web Services (AWS) account?
Include numbers in the user name.
Make the password 10 characters in length.
Require multi-factor authentication (MFA) for access.
Make the password the same as the user name initially.
A systems administrator must provide access to the company’s Amazon Web Services (AWS) account to four new employees who work in the same department. How should the administrator set up the new employees according to best practices for AWS Identity and Access Management (IAM)?
Create one IAM user for the department and assign it to all four employees.
Create an IAM user for each employee.
Create two IAM users and assign them evenly to two employees each.
Give the account root user credentials to all four employees.
Which Amazon Web Services (AWS) resources can customers use to make their application more secure? (Select TWO.)
AWS Free Tier
AWS account teams
AWS Devops and automation toolkit
AWS advisories and bulletins
AWS Developer Tools
Which Amazon Web Services (AWS) resources can customers use to support compliance for their application? (Select TWO.)
AWS auditor learning path
AWS account teams
AWS reference architecture diagrams
AWS technical guides
AWS Cloud Praticioner course
Which offers are part of the AWS Compliance Solutions Guide? (Select TWO.)
Understanding the shared responsibility model
Requesting a compliance report
Scanning AWS resources for security threats
AWS reference architecture diagrams
AWS whitepapers in the Introduction to AWS category
What does Amazon Web Services (AWS) Enterprise Support offer? (Select TWO.)
Support 24/7 through phone, chat, or email
A response time of less than 15 minutes for all issues
A dedicated consultant from AWS Professional Services
A dedicated AWS Technical Account Manager (TAM)
A dedicated consultant from the AWS Partner Network (APN)
Which statement describes the service that Amazon Web Services (AWS) account teams provide?
They guide customers through deployment and implementation.
They provide customer support for deployed applications.
They perform security tests on customer applications, such as penetration testing.
They provide customers with compliance reports of their applications.
What are the roles of Amazon Web Services (AWS), according to the AWS approach to compliance? (Select TWO.)
To provide highly secure and controlled environments
To provide an array of security features
To configure the customer’s IT environments
To scan the customer’s IT infrastructure for security breaches
To scan the customer’s IT infrastructure for security breaches
How does Amazon Web Services (AWS) share security information? (Select THREE.)
By publishing control practices in a newsletter that customers can subscribe to
By obtaining industry certifications and third-party attestations
By publishing information about AWS security in technical papers
By providing documentation to AWS customers directly through nondisclosure agreements (NDAs)
By providing all documentation for AWS security compliance on the AWS website.
Which statements describe the Amazon Web Services (AWS) approach to compliance? (Select TWO.)
AWS assesses compliance certifications and attestations.
Third-party independent auditors deliver attestations of compliance.
Only AWS is responsible for ensuring compliance with laws, regulations, and privacy requirements.
AWS provides security features and documents that customers can use to meet compliance requirements for specific industries.
A significant step for AWS compliance is open source licensing.
Which statements describe the Amazon Web Services (AWS) approach to risk management? (Select TWO.)
AWS regularly scans all endpoint IP addresses for public services.
AWS maintains a security framework and security policies.
AWS offers security training to its customers
AWS offers security certifications to its customers.
AWS regularly scans the customer’s entire IT infrastructure.
Which steps are part of the basic approach to compliance for customers ? (Select TWO.)
Design
Implement
Write acceptance criteria
Review
Develop
