WorksheetsAWS Security & Encryption
Total questions: 81
Worksheet time: 41mins
What is the purpose of encryption in flight using TLS/SSL?
To increase the speed of data transmission
To ensure data integrity only
To encrypt data before sending and decrypt it after receiving
To compress data to save bandwidth
What does TLS stand for?
Transport Layer Security
Transfer Link System
Transmission Layering Standard
Trusted Layering SSL
What does encryption in flight help prevent?
Data loss due to system crashes
Unauthorized access to data at rest
Man in the Middle (MITM) attacks
Physical theft of data storage devices
What do TLS certificates help with?
Speeding up the encryption process
Ensuring data is only stored in encrypted form
Helping with encryption for HTTPS
Generating random passwords for users
When is data encrypted in server-side encryption at rest?
Before being received by the server
After being received by the server
During transmission over the network
After being sent to the client
What is necessary for data to be stored in an encrypted form on the server?
A data key
A password
A user ID
A digital certificate
Why must encryption/decryption keys be managed on the server?
Because the client must have access to it
Because the server must have access to it
Because they are not necessary
Because they are managed by the client
What happens to the data before it is sent from the server?
It is encrypted
It is stored
It is decrypted
It is deleted
What is the primary characteristic of client-side encryption regarding data decryption?
Data is decrypted by the server.
Data is decrypted by the client.
Data is decrypted by both the client and the server.
Data is never decrypted.
Who should not be able to decrypt the data in client-side encryption?
The client
The receiving client
The server
The storage service
Which encryption technique could be leveraged in client-side encryption?
Symmetric Encryption
Asymmetric Encryption
Envelope Encryption
Hashing
Where can the encrypted object be stored in client-side encryption?
Only on the client's local storage
Only on the server's database
Any storage service
Only in secure hardware modules
What does AWS KMS stand for?
Key Management Service
Key Maintenance System
Knowledge Management Service
Kernel Management System
Which AWS service is most likely involved when you hear "encryption" in context of AWS?
AWS IAM
AWS EC2
AWS KMS
AWS S3
What is AWS KMS seamlessly integrated into?
Only AWS EBS
AWS services like EBS, S3, RDS, SSM, etc.
Only AWS IAM
Only AWS EC2
How can you audit KMS Key usage?
Using AWS S3
Using AWS IAM
Using CloudTrail
Using AWS EC2
What is the recommended practice for storing secrets in AWS KMS?
Store secrets in plaintext in the code
Store secrets in plaintext in environment variables
Never store your secrets in plaintext, especially in your code
Store secrets in plaintext in AWS S3
What is the new name for KMS Customer Master Key?
KMS Data Key
KMS Encryption Key
KMS Keys
KMS Secret Key
What type of key is used by AWS services that are integrated with KMS for encryption and decryption?
Asymmetric Key
Symmetric Key
Public Key
Private Key
Which of the following is a characteristic of the symmetric key in KMS?
It is a pair of keys used for encryption and decryption.
The key can be downloaded and used outside of AWS.
Users get direct access to the KMS Key unencrypted.
Users never get access to the KMS Key unencrypted.
What are the components of an asymmetric key in KMS?
Public Key and Secret Key
Public Key and Private Key
Encryption Key and Decryption Key
Signature Key and Verification Key
For what operations might an asymmetric key be used?
Encrypt/Decrypt only
Sign/Verify only
Encrypt/Decrypt or Sign/Verify
Hashing and Salting
What is a use case for the public key in KMS asymmetric key pairs?
Encryption inside of AWS by users who can call the KMS API
Decryption inside of AWS by users who can call the KMS API
Encryption outside of AWS by users who can't call the KMS API
Decryption outside of AWS by users who can't call the KMS API
What is the cost of customer managed keys created in AWS KMS per month?
$0.03 per 10,000 calls
$1 per month
Free
Automatic every year
How often does AWS-managed KMS Key rotate automatically?
Every 6 months
Every 2 years
Every year
It does not rotate automatically
Which type of KMS key allows only manual rotation using an alias?
AWS Owned Keys
AWS Managed Key
Customer-managed KMS Key
Imported KMS Key
What is the cost associated with API calls to KMS for customer managed keys?
$0.03 per 10,000 calls
$1 per month
Free
Automatic every year
What is the process called when an EBS snapshot is encrypted with a new KMS key during a copy across regions?
KMS Transfer
KMS ReEncrypt
KMS Copy
KMS Migration
Which AWS regions are depicted in the image for copying snapshots?
Region us-east-1 and Region us-west-1
Region eu-central-1 and Region ap-northeast-1
Region eu-west-2 and Region ap-southeast-2
Region us-west-2 and Region eu-north-1
What is the purpose of KMS Key A and KMS Key B in the context of the diagram?
To serve as identifiers for the EBS volumes
To encrypt the EBS snapshots during the copy process
To act as region identifiers for the EBS volumes
To provide network access to the EBS volumes
What is the purpose of a KMS Key Policy in AWS?
To define the CPU and memory requirements for virtual machines
To control access to KMS keys, similar to S3 bucket policies
To monitor the network traffic in AWS
To set up the virtual private cloud configurations
What happens if you do not provide a specific KMS Key Policy?
A default KMS Key Policy is created with limited access to the key
No KMS Key Policy is created and the key remains inaccessible
A default KMS Key Policy is created giving complete access to the key to the root user
A custom KMS Key Policy is automatically generated based on the user's most common actions
What can be defined in a Custom KMS Key Policy?
The geographical location of the KMS key servers
The encryption and decryption algorithms to be used
Users and roles that can access the KMS key and who can administer the key
The pricing model for the KMS key usage
Why might a Custom KMS Key Policy be useful?
For setting up automatic key rotation every 90 days
For cross-account access of your KMS key
For linking KMS keys to specific EC2 instances
For generating detailed usage reports of the KMS key
What is the first step in copying snapshots across accounts according to the learning material?
Share the encrypted snapshot
Create a volume from the snapshot
Create a Snapshot, encrypted with your own KMS Key
Attach a KMS Key Policy to authorize cross-account access
What is the purpose of attaching a KMS Key Policy in the process of copying snapshots across accounts?
To create a volume from the snapshot
To encrypt the snapshot with a CMK in your account
To authorize cross-account access
To create a copy of the Snapshot
What action is taken in the target account when copying snapshots across accounts?
Attach a KMS Key Policy
Share the encrypted snapshot
Create a volume from the snapshot
Create a copy of the Snapshot, encrypt it with a CMK in your account
What is the final step in the process of copying snapshots across accounts as described in the learning material?
Share the encrypted snapshot
Attach a KMS Key Policy
Create a copy of the Snapshot, encrypt it with a CMK in your account
Create a volume from the snapshot
What is the purpose of the synchronization shown in the diagram between the AWS regions?
To distribute load between regions
To ensure data redundancy across regions
To synchronize multi-Region Replica keys with the multi-Region Primary key
To provide different services in different regions
In which AWS region is the multi-Region Primary key located according to the diagram?
us-west-2
eu-west-1
us-east-1
ap-southeast-2
How many multi-Region Replica keys are shown in the diagram?
1
2
3
4
What is true about KMS Multi-Region keys in AWS?
They cannot be used interchangeably between different AWS Regions.
They have different key IDs in each region.
They require re-encryption or cross-Region API calls for decryption in other Regions.
They have the same key ID, key material, and automatic rotation across different AWS Regions.
Are KMS Multi-Region keys considered global (Primary + Replicas)?
Yes, they are global.
No, they are not global.
Yes, but only within the same AWS account.
No, they are regional but share the same key material.
How is each Multi-Region key managed in AWS KMS?
Collectively with other keys.
In a centralized manner.
Independently.
Through a third-party service.
Which of the following is a use case for KMS Multi-Region keys?
Local client-side encryption only.
Encryption on a single-region DynamoDB instance.
Global client-side encryption and encryption on Global DynamoDB and Global Aurora.
Cross-Region replication of encrypted data without the need for KMS keys.
What can be encrypted client-side in a DynamoDB table using the Amazon DynamoDB Encryption Client?
The entire database
Specific attributes
Only numeric data types
Only the primary key
When combined with Global Tables, where is the client-side encrypted data replicated to?
To the same region only
To a central data warehouse
To other regions
It is not replicated
What advantage does using a multi-region key, replicated in the same region as the DynamoDB Global table, provide to clients?
Higher costs for data storage
Increased data redundancy
Low-latency API calls to KMS in their region to decrypt the data client-side
Automatic data archiving
What is guaranteed by using client-side encryption with specific fields in DynamoDB?
Data is encrypted using the server-side encryption only
Decryption is possible without an API key
Only decryption if the client has access to an API key
Unlimited data transfer between regions
What can be encrypted client-side in an Aurora table using the AWS Encryption SDK?
The entire database
Specific attributes
The Aurora GlobalTables configuration
The KMS keys themselves
When combined with Aurora GlobalTables, where is the client-side encrypted data replicated to?
To a single region
To the primary region only
To other regions
It is not replicated
What is the benefit of using a multi-region key replicated in the same region as the Global Aurora DB?
Clients can use high-latency API calls to KMS in their region to decrypt the data client-side
Clients cannot decrypt the data at all
Clients can use low-latency API calls to KMS in their region to decrypt the data client-side
It increases the encryption strength
What can client-side encryption protect specific fields from, even if the client has access to an API key?
Protection from all users, including database admins
Protection from network attacks only
Protection from the AWS Encryption SDK
Protection from replication issues
Which objects are replicated by default in S3 Replication?
Objects encrypted with SSE-C
Unencrypted objects and objects encrypted with SSE-S3
Objects encrypted with SSE-KMS
Multi-region AWS KMS Keys encrypted objects
What must be done for objects encrypted with SSE-KMS to be replicated?
Specify which KMS Key to encrypt the objects within the target bucket
Disable the KMS Key Policy for the target key
Remove all IAM Roles related to KMS Key
Do nothing, as they are replicated by default
What role is required for the source KMS Key in the context of S3 Replication with SSE-KMS?
An IAM Role with kms:Encrypt for the source KMS Key
An IAM Role with s3:Replicate for the source KMS Key
An IAM Role with kms:Decrypt for the source KMS Key
An IAM Role with s3:Read for the source KMS Key
What might you experience due to KMS throttling when replicating objects encrypted with SSE-KMS?
A decrease in replication speed
An increase in replication speed
Service Quotas increase automatically
You can ask for a Service Quotas increase
How are multi-region AWS KMS Keys treated when used with S3 objects?
They are not allowed to be used with S3 objects
They are treated as independent keys by Amazon S3 and the object will be decrypted and then encrypted
They are treated as the same key across all regions
They are treated as independent keys but the object remains encrypted
What is required to be modified in the source account to share an AMI with a target AWS account?
Modify the image attribute to add a Launch Permission
Share the KMS Key directly with the target account
Change the IAM Role/User permissions
Launch an EC2 instance from the AMI
Which permissions must the IAM Role/User in the target account have to use the shared AMI?
DescribeInstances, StartInstances, StopInstances
DescribeKey, ReEncrypt, CreateGrant, Decrypt
LaunchInstances, TerminateInstances, ModifyInstanceAttribute
Encrypt, Decrypt, RotateKey, DisableKey
What can the target account optionally specify when launching an EC2 instance from the shared AMI?
A new IAM Role/User
A new KMS key to re-encrypt the volumes
A new EC2 instance type
A new Launch Permission for the AMI
What is the SSM Parameter Store primarily used for?
Data analytics and warehousing
Secure storage for configuration and secrets
Web hosting services
Content delivery and distribution
Which AWS service is integrated with the SSM Parameter Store for optional seamless encryption?
AWS Lambda
AWS EC2
AWS KMS
AWS S3
What feature of the SSM Parameter Store allows tracking changes to configurations or secrets?
High availability
Version tracking
Load balancing
Auto-scaling
Which AWS service provides notifications in integration with the SSM Parameter Store?
AWS SNS
AWS SQS
AWS EventBridge
AWS CloudWatch
How does the SSM Parameter Store ensure security?
Through SSL encryption
Through IAM
Through VPC endpoints
Through multi-factor authentication
Which AWS service is used by the SSM Parameter Store for decryption services?
AWS CloudTrail
AWS KMS
AWS Shield
AWS IAM
What type of architecture does the SSM Parameter Store represent?
Monolithic
Server-based
Serverless
Microservices
Which AWS API can be used to retrieve parameters from the SSM Parameter Store as shown in the hierarchy?
GetParametersByValue API
GetParametersByPath API
FetchParameters API
RetrieveParametersByHierarchy API
What are the two types of environments specified under the 'my-app/' application in the SSM Parameter Store hierarchy?
test and prod
dev and prod
stage and live
beta and release
According to the SSM Parameter Store hierarchy, what kind of AWS Lambda functions are associated with the parameters?
Test Lambda Function and Live Lambda Function
Dev Lambda Function and Prod Lambda Function
Stage Lambda Function and Release Lambda Function
Beta Lambda Function and Final Lambda Function
Which of the following is a public parameter available in the SSM Parameter Store hierarchy?
/my-department/my-app/dev/db-url
/other-department/
/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2 (public)
/aws/reference/secretsmanager/secret_ID_in_Secrets_Manager
What is the total number of parameters allowed for the Standard tier per AWS account and Region?
1,000
10,000
100,000
No limit
What is the maximum size of a parameter value for the Advanced tier?
4 KB
8 KB
16 KB
32 KB
Are parameter policies available for the Standard tier?
Yes
No
Only for an additional charge
Only for certain parameters
How much does AWS charge for storage pricing for the Advanced tier?
Free
$0.01 per advanced parameter per month
$0.05 per advanced parameter per month
$0.10 per advanced parameter per month
What is the purpose of assigning a TTL to a parameter according to the Parameters Policies?
To increase the security of the parameter
To force updating or deleting sensitive data such as passwords
To duplicate the parameter for backup purposes
To notify the user about parameter changes
How many policies can be assigned to a parameter at a time?
Only one policy at a time
Up to two policies at a time
Multiple policies at a time
No policies can be assigned
What does the "Expiration" policy do for a parameter?
Notifies when a parameter is unchanged
Sends a notification before a parameter expires
Deletes a parameter
Creates a backup of a parameter
What is the "Unit" specified in the ExpirationNotification policy?
Hours
Days
Minutes
Seconds
According to the NoChangeNotification policy, after how many days will a notification be sent if there are no changes to the parameter?
15 days
20 days
10 days
30 days
