WorksheetsAWS Chapter 5 IAM
Total questions: 20
Worksheet time: 11mins
What is the primary function of the AWS IAM service?
Identity & access management
Access key management
SSH key pair management
Federated access management
Which of the following are requirements you can include in an IAM password policy?(select THREE)
Require at least one uppercase letter
Require at least one number
Require at least one space or null character
Require at least one nonalphanumeric character
Which of the following should you do to secure your AWS root user? (Select TWO)
Assign the root user to the "admins" IAM group
Use the root user for day-to-day administration tasks
Enable MFA
Create a strong password
How does multi-factor authentication work?
Instead of an access password, users authenticate via a physical MFA device
In addition to an access password, users also authenticate via a physical MFA device
Users authenticate using tokens sent to at least two MFA devices
Users authenticate using password & also either a physical or virtual MFA device
Which of the following SSH commands will successfully connect to an EC2 Amazon Linux instance with an IP address of 54.7.35.103 using a key names mykey.pem?
echo "mykey.pem ubuntu@54.7.35.103" ssh -i
ssh -i mykey.pem ec2-user@54.7.35.103
ssh -i mykey.pem@54.7.35.103
ssh ec2-user@mykey.pem:54.7.35.103 -i
What's the most efficient method for managing permissions for multiple IAM users?
Assign users requiring similar permission to IAM roles
Assign users requiring similar permissions to IAM groups
Assign IAM users permissions common to others with similar administration responsibilities
Create roles based on IAM policies, and assign them to IAM users
What is IAM role?
A set of permissions allowing access to specified AWS resources
A set of IAM users given permissions to access specified AWS resources
Permissions granted a trusted entity over specified AWS resources
Permissions granted an IAM user over specified AWS resources
How can federated identities be incorporated into AWS workflows?(Select Two)
You can provide users authenticated through a third party identity provider access to backend resources user by your mobile app
You can use identities to guide your infrastructure design decisions
You can use authenticated identities to import external data(like email records from gmail) into AWS databases
You can provide admins authenticated through AWS Microsoft AD with access to a Microsoft Sharepoint farm running on AWS
Which of the following are valid third-party federated identity standards? (Select TWO)
Secure Shell
SSO
SAML2.0
Active Directory
What information does the IAM credential report provide?
A record of API requests against your account resources
A record of failed password account login attempts
The current state of your account security settings
The current state of security of your IAM users' access credentials
What text format does the credential report use?
JSON
CSV
ASCII
XML
Which of the following IAM policies is the best choice for the admin user you create in order to replace the root user for day-to-day administration tasks?
AdministratorAccess
AmazonS3FullAccess
AmazonEC2FullAccess
AdminAccess
What will IAM users with AWS Management console access need to successfully log in?
Their username, account_number, and a password
Their username & password
Their account number & secret access key
Their username,password, and secret access key
Which of the following will encrypt your data while in transit between your office & Amazon S3?
DynamoDB
SSE-S3
A client-side master key
SSE-KMS
What will you need to provide for a new IAM user you're creating who will use "programmatic access" to AWS resources?
A password
A password and MFA
An access keyID
An access key ID & secret access key
Which of the following AWS resources cannot be encrypted using KMS?
Existing AWS Elastic Block Store volumes
RDS databases
S3 buckets
DynamoDB databases
What does KMS use to encrypt objects stored on your AWS account?
SSH master key
KMS master key
Client side master key
Customer master key
Which of the following standards governs AWS-based applications processing credit card transactions?
SSE-KMS
FedRAMP
PCI DSS
ARPA
What is the purpose of the Service Organization Controls(SOC) reports found on AWS Artifact?
They can be used to help you design secure & reliable credit card transaction application
They attest to AWS infrastructure compliance with data accountability standards like Sarbanes-Oxley
They guarantee that all AWS-based applications are, by default, compliant with Sabanes-Oxley standars
They're an official, ongoing risk-assessment profiler for AWS-based deployments
What role can the documents provided by AWS Artifact play in your application planning? (Select Two)
They can help you confirm that your deployment infrastructure is compliant with regulatory standards.
They can provide insight into various regulatory and industry standards that represent best practices
They can provide insight into the networking and storage design patterns your AWS applications use
They represent AWS infrastructure design policy
