wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS IAM and S3

Total questions: 31

Worksheet time: 16mins

Name
Class
Date
1.

Which of the following is the most secure way of giving access to AWS services to applications running on Ec2 instances?

a)

Creating Service users

b)

Creating service groups

c)

Roles

d)

Attaching policies to applications

2.

Users is?

a)

Permission to make AWS service requests

b)

Perfrom any action in any other account

c)

Entity that you create in AWS to represent the person or application

d)

Permissions associated with

3.

TRUE or FALSE : By default a new user in IAM has permisiions to log in to the AWS Console.

a)

TRUE

b)

FLASE

4.

Which of the following is not an IAM best practice?

a)

Delete user accounts not in use

b)

Attach policies to individual users

c)

Manage permissions by adding users to groups

d)

Enable MFA on user accounts

5.

Wch of the following set of credentials are used to log in to AWS programmatically? (Choose two)

a)

Username

b)

Access Key

c)

Password

d)

Secret Key

6.

True or False : An explicit Deny in IAM precedes over an explicit allow

a)

TRUE

b)

FALSE

7.

In order to grant access to users from another AWS account you should

a)

Share your AWS console credentials with remote user

b)

Share you Access/Secret keys with remote user

c)

Create IAM role and provide assume role permissions for remote account

d)

Create a new user into your AWS account and share credentials with remote user

8.

Which user has no permission by default

a)

EC2 user

b)

IAM user

c)

Root user

d)

Service user

9.

IAM policy documents are written in which format

a)

XML

b)

HTML

c)

JSON

d)

YAML

10.

How can you audit the activities happening into your AWS account such as which users logged in to console, who terminated EC2 instance, who created S3 bucket etc

a)

Check the CloudWatch logs

b)

Check the IAM logs

c)

Check the IAM policies

d)

Check AWS CloudTrail

11.

Programmatic Access enables?

a)

Can access the console

b)

Perform task as per given rights

c)

Password that allows user to sign in

d)

Access key id and secret access key for using AWS service Via AWS API

12.

What is AWS IAM?

a)

Access to console

b)

Full access to all resources

c)

Securely

control access

d)

Optionally access

13.

Select the plan TAM can assist ?

a)

Basic

b)

Enterprise

c)

Business

d)

Developer

14.

IAM Users are defined on a per-region basis

a)

True

b)

False

15.

Which of the following is the best practice for adding an additional layer of security when logging into the AWS Management Console?

a)

Secondary user name

b)

Root access permissions

c)

Multi-factor authentication (MFA)

d)

Secondary passowrd

16.

To connect (login) to the ec2 machine , aws given the security file ?

a)

username and password

b)

pem file

c)

MFA

d)

root user

17.

It is a global service that is used to manage users and their permissions.

a)

IAM Policy Simulator

b)

Virtual Private Cloud

c)

Security Group

d)

Identity Access Management

18.

A principle which states that we should only grant what is needed.

a)

Least-Privilege Principle

b)

Less-Access Principle

c)

Less-Privilege Principle

d)

Least-Access Principle

19.

IAM Resources are

a)

IAM User

b)

IAM Group

c)

IAM Team

d)

IAM Policy

20.

How to delete instance permanently?

a)

Stop

b)

Terminate

c)

Hibernate

d)

Run

21.

Who is responsible for Physical security of the data center?

a)

Customer

b)

AWS

c)

College

22.

The document that defines which resources can be accessed and the level of access to each resource

a)

IAM User

b)

IAM Group

c)

IAM Role

d)

IAM Policy

23.

The document that defines which resources can be accessed and the level of access to each resource

a)

IAM User

b)

IAM Group

c)

IAM Role

d)

IAM Policy

24.

What is the abbreviation of KMS?

(a)  

25.

Which service will protect from DDos attacks?

a)

AWS IAM

b)

AWS Cognito

c)

AWS Shield

d)

AWS EC2

26.

Which service helps to create,manage and secure keys?

a)

AWS S3

b)

AWS EC2

c)

AWS KMS

d)

AWS BMS

27.

Abbreviation of S3

(a)  

28.

Which service provides unlimited storage?

a)

Amazon S3

b)

Amazon bucket service

c)

Amazon Tumbler service

d)

AWS IAM

29.

Default bucket is always

a)

Static bucket

b)

Private bucket

c)

Public bucket

d)

General bucket

30.

Which one is completely free service ?

a)

Amazon S3

b)

Amazon EC2

c)

IAM

d)

Amazon Cloud trail

31.

KMS will support ..

a)

Only Encryption data at rest

b)

Only Encryption data in transit

c)

Either Encryption data at rest or in transit

d)

Both Encryption data at rest and in transit