Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Security & Encryption

Total questions: 81

Worksheet time: 41mins

Name
Class
Date
1.

What is the purpose of encryption in flight using TLS/SSL?

a)

To increase the speed of data transmission

b)

To ensure data integrity only

c)

To encrypt data before sending and decrypt it after receiving

d)

To compress data to save bandwidth

2.

What does TLS stand for?

a)

Transport Layer Security

b)

Transfer Link System

c)

Transmission Layering Standard

d)

Trusted Layering SSL

3.

What does encryption in flight help prevent?

a)

Data loss due to system crashes

b)

Unauthorized access to data at rest

c)

Man in the Middle (MITM) attacks

d)

Physical theft of data storage devices

4.

What do TLS certificates help with?

a)

Speeding up the encryption process

b)

Ensuring data is only stored in encrypted form

c)

Helping with encryption for HTTPS

d)

Generating random passwords for users

5.

When is data encrypted in server-side encryption at rest?

a)

Before being received by the server

b)

After being received by the server

c)

During transmission over the network

d)

After being sent to the client

6.

What is necessary for data to be stored in an encrypted form on the server?

a)

A data key

b)

A password

c)

A user ID

d)

A digital certificate

7.

Why must encryption/decryption keys be managed on the server?

a)

Because the client must have access to it

b)

Because the server must have access to it

c)

Because they are not necessary

d)

Because they are managed by the client

8.

What happens to the data before it is sent from the server?

a)

It is encrypted

b)

It is stored

c)

It is decrypted

d)

It is deleted

9.

What is the primary characteristic of client-side encryption regarding data decryption?

a)

Data is decrypted by the server.

b)

Data is decrypted by the client.

c)

Data is decrypted by both the client and the server.

d)

Data is never decrypted.

10.

Who should not be able to decrypt the data in client-side encryption?

a)

The client

b)

The receiving client

c)

The server

d)

The storage service

11.

Which encryption technique could be leveraged in client-side encryption?

a)

Symmetric Encryption

b)

Asymmetric Encryption

c)

Envelope Encryption

d)

Hashing

12.

Where can the encrypted object be stored in client-side encryption?

a)

Only on the client's local storage

b)

Only on the server's database

c)

Any storage service

d)

Only in secure hardware modules

13.

What does AWS KMS stand for?

a)

Key Management Service

b)

Key Maintenance System

c)

Knowledge Management Service

d)

Kernel Management System

14.

Which AWS service is most likely involved when you hear "encryption" in context of AWS?

a)

AWS IAM

b)

AWS EC2

c)

AWS KMS

d)

AWS S3

15.

What is AWS KMS seamlessly integrated into?

a)

Only AWS EBS

b)

AWS services like EBS, S3, RDS, SSM, etc.

c)

Only AWS IAM

d)

Only AWS EC2

16.

How can you audit KMS Key usage?

a)

Using AWS S3

b)

Using AWS IAM

c)

Using CloudTrail

d)

Using AWS EC2

17.

What is the recommended practice for storing secrets in AWS KMS?

a)

Store secrets in plaintext in the code

b)

Store secrets in plaintext in environment variables

c)

Never store your secrets in plaintext, especially in your code

d)

Store secrets in plaintext in AWS S3

18.

What is the new name for KMS Customer Master Key?

a)

KMS Data Key

b)

KMS Encryption Key

c)

KMS Keys

d)

KMS Secret Key

19.

What type of key is used by AWS services that are integrated with KMS for encryption and decryption?

a)

Asymmetric Key

b)

Symmetric Key

c)

Public Key

d)

Private Key

20.

Which of the following is a characteristic of the symmetric key in KMS?

a)

It is a pair of keys used for encryption and decryption.

b)

The key can be downloaded and used outside of AWS.

c)

Users get direct access to the KMS Key unencrypted.

d)

Users never get access to the KMS Key unencrypted.

21.

What are the components of an asymmetric key in KMS?

a)

Public Key and Secret Key

b)

Public Key and Private Key

c)

Encryption Key and Decryption Key

d)

Signature Key and Verification Key

22.

For what operations might an asymmetric key be used?

a)

Encrypt/Decrypt only

b)

Sign/Verify only

c)

Encrypt/Decrypt or Sign/Verify

d)

Hashing and Salting

23.

What is a use case for the public key in KMS asymmetric key pairs?

a)

Encryption inside of AWS by users who can call the KMS API

b)

Decryption inside of AWS by users who can call the KMS API

c)

Encryption outside of AWS by users who can't call the KMS API

d)

Decryption outside of AWS by users who can't call the KMS API

24.

What is the cost of customer managed keys created in AWS KMS per month?

a)

$0.03 per 10,000 calls

b)

$1 per month

c)

Free

d)

Automatic every year

25.

How often does AWS-managed KMS Key rotate automatically?

a)

Every 6 months

b)

Every 2 years

c)

Every year

d)

It does not rotate automatically

26.

Which type of KMS key allows only manual rotation using an alias?

a)

AWS Owned Keys

b)

AWS Managed Key

c)

Customer-managed KMS Key

d)

Imported KMS Key

27.

What is the cost associated with API calls to KMS for customer managed keys?

a)

$0.03 per 10,000 calls

b)

$1 per month

c)

Free

d)

Automatic every year

28.

What is the process called when an EBS snapshot is encrypted with a new KMS key during a copy across regions?

a)

KMS Transfer

b)

KMS ReEncrypt

c)

KMS Copy

d)

KMS Migration

29.

Which AWS regions are depicted in the image for copying snapshots?

a)

Region us-east-1 and Region us-west-1

b)

Region eu-central-1 and Region ap-northeast-1

c)

Region eu-west-2 and Region ap-southeast-2

d)

Region us-west-2 and Region eu-north-1

30.

What is the purpose of KMS Key A and KMS Key B in the context of the diagram?

a)

To serve as identifiers for the EBS volumes

b)

To encrypt the EBS snapshots during the copy process

c)

To act as region identifiers for the EBS volumes

d)

To provide network access to the EBS volumes

31.

What is the purpose of a KMS Key Policy in AWS?

a)

To define the CPU and memory requirements for virtual machines

b)

To control access to KMS keys, similar to S3 bucket policies

c)

To monitor the network traffic in AWS

d)

To set up the virtual private cloud configurations

32.

What happens if you do not provide a specific KMS Key Policy?

a)

A default KMS Key Policy is created with limited access to the key

b)

No KMS Key Policy is created and the key remains inaccessible

c)

A default KMS Key Policy is created giving complete access to the key to the root user

d)

A custom KMS Key Policy is automatically generated based on the user's most common actions

33.

What can be defined in a Custom KMS Key Policy?

a)

The geographical location of the KMS key servers

b)

The encryption and decryption algorithms to be used

c)

Users and roles that can access the KMS key and who can administer the key

d)

The pricing model for the KMS key usage

34.

Why might a Custom KMS Key Policy be useful?

a)

For setting up automatic key rotation every 90 days

b)

For cross-account access of your KMS key

c)

For linking KMS keys to specific EC2 instances

d)

For generating detailed usage reports of the KMS key

35.

What is the first step in copying snapshots across accounts according to the learning material?

a)

Share the encrypted snapshot

b)

Create a volume from the snapshot

c)

Create a Snapshot, encrypted with your own KMS Key

d)

Attach a KMS Key Policy to authorize cross-account access

36.

What is the purpose of attaching a KMS Key Policy in the process of copying snapshots across accounts?

a)

To create a volume from the snapshot

b)

To encrypt the snapshot with a CMK in your account

c)

To authorize cross-account access

d)

To create a copy of the Snapshot

37.

What action is taken in the target account when copying snapshots across accounts?

a)

Attach a KMS Key Policy

b)

Share the encrypted snapshot

c)

Create a volume from the snapshot

d)

Create a copy of the Snapshot, encrypt it with a CMK in your account

38.

What is the final step in the process of copying snapshots across accounts as described in the learning material?

a)

Share the encrypted snapshot

b)

Attach a KMS Key Policy

c)

Create a copy of the Snapshot, encrypt it with a CMK in your account

d)

Create a volume from the snapshot

39.

What is the purpose of the synchronization shown in the diagram between the AWS regions?

a)

To distribute load between regions

b)

To ensure data redundancy across regions

c)

To synchronize multi-Region Replica keys with the multi-Region Primary key

d)

To provide different services in different regions

40.

In which AWS region is the multi-Region Primary key located according to the diagram?

a)

us-west-2

b)

eu-west-1

c)

us-east-1

d)

ap-southeast-2

41.

How many multi-Region Replica keys are shown in the diagram?

a)

1

b)

2

c)

3

d)

4

42.

What is true about KMS Multi-Region keys in AWS?

a)

They cannot be used interchangeably between different AWS Regions.

b)

They have different key IDs in each region.

c)

They require re-encryption or cross-Region API calls for decryption in other Regions.

d)

They have the same key ID, key material, and automatic rotation across different AWS Regions.

43.

Are KMS Multi-Region keys considered global (Primary + Replicas)?

a)

Yes, they are global.

b)

No, they are not global.

c)

Yes, but only within the same AWS account.

d)

No, they are regional but share the same key material.

44.

How is each Multi-Region key managed in AWS KMS?

a)

Collectively with other keys.

b)

In a centralized manner.

c)

Independently.

d)

Through a third-party service.

45.

Which of the following is a use case for KMS Multi-Region keys?

a)

Local client-side encryption only.

b)

Encryption on a single-region DynamoDB instance.

c)

Global client-side encryption and encryption on Global DynamoDB and Global Aurora.

d)

Cross-Region replication of encrypted data without the need for KMS keys.

46.

What can be encrypted client-side in a DynamoDB table using the Amazon DynamoDB Encryption Client?

a)

The entire database

b)

Specific attributes

c)

Only numeric data types

d)

Only the primary key

47.

When combined with Global Tables, where is the client-side encrypted data replicated to?

a)

To the same region only

b)

To a central data warehouse

c)

To other regions

d)

It is not replicated

48.

What advantage does using a multi-region key, replicated in the same region as the DynamoDB Global table, provide to clients?

a)

Higher costs for data storage

b)

Increased data redundancy

c)

Low-latency API calls to KMS in their region to decrypt the data client-side

d)

Automatic data archiving

49.

What is guaranteed by using client-side encryption with specific fields in DynamoDB?

a)

Data is encrypted using the server-side encryption only

b)

Decryption is possible without an API key

c)

Only decryption if the client has access to an API key

d)

Unlimited data transfer between regions

50.

What can be encrypted client-side in an Aurora table using the AWS Encryption SDK?

a)

The entire database

b)

Specific attributes

c)

The Aurora GlobalTables configuration

d)

The KMS keys themselves

51.

When combined with Aurora GlobalTables, where is the client-side encrypted data replicated to?

a)

To a single region

b)

To the primary region only

c)

To other regions

d)

It is not replicated

52.

What is the benefit of using a multi-region key replicated in the same region as the Global Aurora DB?

a)

Clients can use high-latency API calls to KMS in their region to decrypt the data client-side

b)

Clients cannot decrypt the data at all

c)

Clients can use low-latency API calls to KMS in their region to decrypt the data client-side

d)

It increases the encryption strength

53.

What can client-side encryption protect specific fields from, even if the client has access to an API key?

a)

Protection from all users, including database admins

b)

Protection from network attacks only

c)

Protection from the AWS Encryption SDK

d)

Protection from replication issues

54.

Which objects are replicated by default in S3 Replication?

a)

Objects encrypted with SSE-C

b)

Unencrypted objects and objects encrypted with SSE-S3

c)

Objects encrypted with SSE-KMS

d)

Multi-region AWS KMS Keys encrypted objects

55.

What must be done for objects encrypted with SSE-KMS to be replicated?

a)

Specify which KMS Key to encrypt the objects within the target bucket

b)

Disable the KMS Key Policy for the target key

c)

Remove all IAM Roles related to KMS Key

d)

Do nothing, as they are replicated by default

56.

What role is required for the source KMS Key in the context of S3 Replication with SSE-KMS?

a)

An IAM Role with kms:Encrypt for the source KMS Key

b)

An IAM Role with s3:Replicate for the source KMS Key

c)

An IAM Role with kms:Decrypt for the source KMS Key

d)

An IAM Role with s3:Read for the source KMS Key

57.

What might you experience due to KMS throttling when replicating objects encrypted with SSE-KMS?

a)

A decrease in replication speed

b)

An increase in replication speed

c)

Service Quotas increase automatically

d)

You can ask for a Service Quotas increase

58.

How are multi-region AWS KMS Keys treated when used with S3 objects?

a)

They are not allowed to be used with S3 objects

b)

They are treated as independent keys by Amazon S3 and the object will be decrypted and then encrypted

c)

They are treated as the same key across all regions

d)

They are treated as independent keys but the object remains encrypted

59.

What is required to be modified in the source account to share an AMI with a target AWS account?

a)

Modify the image attribute to add a Launch Permission

b)

Share the KMS Key directly with the target account

c)

Change the IAM Role/User permissions

d)

Launch an EC2 instance from the AMI

60.

Which permissions must the IAM Role/User in the target account have to use the shared AMI?

a)

DescribeInstances, StartInstances, StopInstances

b)

DescribeKey, ReEncrypt, CreateGrant, Decrypt

c)

LaunchInstances, TerminateInstances, ModifyInstanceAttribute

d)

Encrypt, Decrypt, RotateKey, DisableKey

61.

What can the target account optionally specify when launching an EC2 instance from the shared AMI?

a)

A new IAM Role/User

b)

A new KMS key to re-encrypt the volumes

c)

A new EC2 instance type

d)

A new Launch Permission for the AMI

62.

What is the SSM Parameter Store primarily used for?

a)

Data analytics and warehousing

b)

Secure storage for configuration and secrets

c)

Web hosting services

d)

Content delivery and distribution

63.

Which AWS service is integrated with the SSM Parameter Store for optional seamless encryption?

a)

AWS Lambda

b)

AWS EC2

c)

AWS KMS

d)

AWS S3

64.

What feature of the SSM Parameter Store allows tracking changes to configurations or secrets?

a)

High availability

b)

Version tracking

c)

Load balancing

d)

Auto-scaling

65.

Which AWS service provides notifications in integration with the SSM Parameter Store?

a)

AWS SNS

b)

AWS SQS

c)

AWS EventBridge

d)

AWS CloudWatch

66.

How does the SSM Parameter Store ensure security?

a)

Through SSL encryption

b)

Through IAM

c)

Through VPC endpoints

d)

Through multi-factor authentication

67.

Which AWS service is used by the SSM Parameter Store for decryption services?

a)

AWS CloudTrail

b)

AWS KMS

c)

AWS Shield

d)

AWS IAM

68.

What type of architecture does the SSM Parameter Store represent?

a)

Monolithic

b)

Server-based

c)

Serverless

d)

Microservices

69.

Which AWS API can be used to retrieve parameters from the SSM Parameter Store as shown in the hierarchy?

a)

GetParametersByValue API

b)

GetParametersByPath API

c)

FetchParameters API

d)

RetrieveParametersByHierarchy API

70.

What are the two types of environments specified under the 'my-app/' application in the SSM Parameter Store hierarchy?

a)

test and prod

b)

dev and prod

c)

stage and live

d)

beta and release

71.

According to the SSM Parameter Store hierarchy, what kind of AWS Lambda functions are associated with the parameters?

a)

Test Lambda Function and Live Lambda Function

b)

Dev Lambda Function and Prod Lambda Function

c)

Stage Lambda Function and Release Lambda Function

d)

Beta Lambda Function and Final Lambda Function

72.

Which of the following is a public parameter available in the SSM Parameter Store hierarchy?

a)

/my-department/my-app/dev/db-url

b)

/other-department/

c)

/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2 (public)

d)

/aws/reference/secretsmanager/secret_ID_in_Secrets_Manager

73.

What is the total number of parameters allowed for the Standard tier per AWS account and Region?

a)

1,000

b)

10,000

c)

100,000

d)

No limit

74.

What is the maximum size of a parameter value for the Advanced tier?

a)

4 KB

b)

8 KB

c)

16 KB

d)

32 KB

75.

Are parameter policies available for the Standard tier?

a)

Yes

b)

No

c)

Only for an additional charge

d)

Only for certain parameters

76.

How much does AWS charge for storage pricing for the Advanced tier?

a)

Free

b)

$0.01 per advanced parameter per month

c)

$0.05 per advanced parameter per month

d)

$0.10 per advanced parameter per month

77.

What is the purpose of assigning a TTL to a parameter according to the Parameters Policies?

a)

To increase the security of the parameter

b)

To force updating or deleting sensitive data such as passwords

c)

To duplicate the parameter for backup purposes

d)

To notify the user about parameter changes

78.

How many policies can be assigned to a parameter at a time?

a)

Only one policy at a time

b)

Up to two policies at a time

c)

Multiple policies at a time

d)

No policies can be assigned

79.

What does the "Expiration" policy do for a parameter?

a)

Notifies when a parameter is unchanged

b)

Sends a notification before a parameter expires

c)

Deletes a parameter

d)

Creates a backup of a parameter

80.

What is the "Unit" specified in the ExpirationNotification policy?

a)

Hours

b)

Days

c)

Minutes

d)

Seconds

81.

According to the NoChangeNotification policy, after how many days will a notification be sent if there are no changes to the parameter?

a)

15 days

b)

20 days

c)

10 days

d)

30 days