WorksheetsAWS IAM and S3
Total questions: 31
Worksheet time: 16mins
Which of the following is the most secure way of giving access to AWS services to applications running on Ec2 instances?
Creating Service users
Creating service groups
Roles
Attaching policies to applications
Users is?
Permission to make AWS service requests
Perfrom any action in any other account
Entity that you create in AWS to represent the person or application
Permissions associated with
TRUE or FALSE : By default a new user in IAM has permisiions to log in to the AWS Console.
TRUE
FLASE
Which of the following is not an IAM best practice?
Delete user accounts not in use
Attach policies to individual users
Manage permissions by adding users to groups
Enable MFA on user accounts
Wch of the following set of credentials are used to log in to AWS programmatically? (Choose two)
Username
Access Key
Password
Secret Key
True or False : An explicit Deny in IAM precedes over an explicit allow
TRUE
FALSE
In order to grant access to users from another AWS account you should
Share your AWS console credentials with remote user
Share you Access/Secret keys with remote user
Create IAM role and provide assume role permissions for remote account
Create a new user into your AWS account and share credentials with remote user
Which user has no permission by default
EC2 user
IAM user
Root user
Service user
IAM policy documents are written in which format
XML
HTML
JSON
YAML
How can you audit the activities happening into your AWS account such as which users logged in to console, who terminated EC2 instance, who created S3 bucket etc
Check the CloudWatch logs
Check the IAM logs
Check the IAM policies
Check AWS CloudTrail
Programmatic Access enables?
Can access the console
Perform task as per given rights
Password that allows user to sign in
Access key id and secret access key for using AWS service Via AWS API
What is AWS IAM?
Access to console
Full access to all resources
Securely
control access
Optionally access
Select the plan TAM can assist ?
Basic
Enterprise
Business
Developer
IAM Users are defined on a per-region basis
True
False
Which of the following is the best practice for adding an additional layer of security when logging into the AWS Management Console?
Secondary user name
Root access permissions
Multi-factor authentication (MFA)
Secondary passowrd
To connect (login) to the ec2 machine , aws given the security file ?
username and password
pem file
MFA
root user
It is a global service that is used to manage users and their permissions.
IAM Policy Simulator
Virtual Private Cloud
Security Group
Identity Access Management
A principle which states that we should only grant what is needed.
Least-Privilege Principle
Less-Access Principle
Less-Privilege Principle
Least-Access Principle
IAM Resources are
IAM User
IAM Group
IAM Team
IAM Policy
How to delete instance permanently?
Stop
Terminate
Hibernate
Run
Who is responsible for Physical security of the data center?
Customer
AWS
College
The document that defines which resources can be accessed and the level of access to each resource
IAM User
IAM Group
IAM Role
IAM Policy
The document that defines which resources can be accessed and the level of access to each resource
IAM User
IAM Group
IAM Role
IAM Policy
What is the abbreviation of KMS?
(a)
Which service will protect from DDos attacks?
AWS IAM
AWS Cognito
AWS Shield
AWS EC2
Which service helps to create,manage and secure keys?
AWS S3
AWS EC2
AWS KMS
AWS BMS
Abbreviation of S3
(a)
Which service provides unlimited storage?
Amazon S3
Amazon bucket service
Amazon Tumbler service
AWS IAM
Default bucket is always
Static bucket
Private bucket
Public bucket
General bucket
Which one is completely free service ?
Amazon S3
Amazon EC2
IAM
Amazon Cloud trail
KMS will support ..
Only Encryption data at rest
Only Encryption data in transit
Either Encryption data at rest or in transit
Both Encryption data at rest and in transit
