Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Chapter 5 IAM

Total questions: 20

Worksheet time: 11mins

Name
Class
Date
1.

What is the primary function of the AWS IAM service?

a)

Identity & access management

b)

Access key management

c)

SSH key pair management

d)

Federated access management

2.

Which of the following are requirements you can include in an IAM password policy?(select THREE)

a)

Require at least one uppercase letter

b)

Require at least one number

c)

Require at least one space or null character

d)

Require at least one nonalphanumeric character

3.

Which of the following should you do to secure your AWS root user? (Select TWO)

a)

Assign the root user to the "admins" IAM group

b)

Use the root user for day-to-day administration tasks

c)

Enable MFA

d)

Create a strong password

4.

How does multi-factor authentication work?

a)

Instead of an access password, users authenticate via a physical MFA device

b)

In addition to an access password, users also authenticate via a physical MFA device

c)

Users authenticate using tokens sent to at least two MFA devices

d)

Users authenticate using password & also either a physical or virtual MFA device

5.

Which of the following SSH commands will successfully connect to an EC2 Amazon Linux instance with an IP address of 54.7.35.103 using a key names mykey.pem?

a)

echo "mykey.pem ubuntu@54.7.35.103" ssh -i

b)

ssh -i mykey.pem ec2-user@54.7.35.103

c)

ssh -i mykey.pem@54.7.35.103

d)

ssh ec2-user@mykey.pem:54.7.35.103 -i

6.

What's the most efficient method for managing permissions for multiple IAM users?

a)

Assign users requiring similar permission to IAM roles

b)

Assign users requiring similar permissions to IAM groups

c)

Assign IAM users permissions common to others with similar administration responsibilities

d)

Create roles based on IAM policies, and assign them to IAM users

7.

What is IAM role?

a)

A set of permissions allowing access to specified AWS resources

b)

A set of IAM users given permissions to access specified AWS resources

c)

Permissions granted a trusted entity over specified AWS resources

d)

Permissions granted an IAM user over specified AWS resources

8.

How can federated identities be incorporated into AWS workflows?(Select Two)

a)

You can provide users authenticated through a third party identity provider access to backend resources user by your mobile app

b)

You can use identities to guide your infrastructure design decisions

c)

You can use authenticated identities to import external data(like email records from gmail) into AWS databases

d)

You can provide admins authenticated through AWS Microsoft AD with access to a Microsoft Sharepoint farm running on AWS

9.

Which of the following are valid third-party federated identity standards? (Select TWO)

a)

Secure Shell

b)

SSO

c)

SAML2.0

d)

Active Directory

10.

What information does the IAM credential report provide?

a)

A record of API requests against your account resources

b)

A record of failed password account login attempts

c)

The current state of your account security settings

d)

The current state of security of your IAM users' access credentials

11.

What text format does the credential report use?

a)

JSON

b)

CSV

c)

ASCII

d)

XML

12.

Which of the following IAM policies is the best choice for the admin user you create in order to replace the root user for day-to-day administration tasks?

a)

AdministratorAccess

b)

AmazonS3FullAccess

c)

AmazonEC2FullAccess

d)

AdminAccess

13.

What will IAM users with AWS Management console access need to successfully log in?

a)

Their username, account_number, and a password

b)

Their username & password

c)

Their account number & secret access key

d)

Their username,password, and secret access key

14.

Which of the following will encrypt your data while in transit between your office & Amazon S3?

a)

DynamoDB

b)

SSE-S3

c)

A client-side master key

d)

SSE-KMS

15.

What will you need to provide for a new IAM user you're creating who will use "programmatic access" to AWS resources?

a)

A password

b)

A password and MFA

c)

An access keyID

d)

An access key ID & secret access key

16.

Which of the following AWS resources cannot be encrypted using KMS?

a)

Existing AWS Elastic Block Store volumes

b)

RDS databases

c)

S3 buckets

d)

DynamoDB databases

17.

What does KMS use to encrypt objects stored on your AWS account?

a)

SSH master key

b)

KMS master key

c)

Client side master key

d)

Customer master key

18.

Which of the following standards governs AWS-based applications processing credit card transactions?

a)

SSE-KMS

b)

FedRAMP

c)

PCI DSS

d)

ARPA

19.

What is the purpose of the Service Organization Controls(SOC) reports found on AWS Artifact?

a)

They can be used to help you design secure & reliable credit card transaction application

b)

They attest to AWS infrastructure compliance with data accountability standards like Sarbanes-Oxley

c)

They guarantee that all AWS-based applications are, by default, compliant with Sabanes-Oxley standars

d)

They're an official, ongoing risk-assessment profiler for AWS-based deployments

20.

What role can the documents provided by AWS Artifact play in your application planning? (Select Two)

a)

They can help you confirm that your deployment infrastructure is compliant with regulatory standards.

b)

They can provide insight into various regulatory and industry standards that represent best practices

c)

They can provide insight into the networking and storage design patterns your AWS applications use

d)

They represent AWS infrastructure design policy