WorksheetsAWS Data Protect and Encryption
Total questions: 10
Worksheet time: 5mins
What compliance reports can you access via AWS Artifact?
SOC, PCI DSS, ISO, HIPAA
GDPR, CCPA, SOX, FISMA
NIST, COBIT, ITIL, ISO 27001
FERPA, GLBA, PCI, HIPAA
What happens when an AWS KMS key is scheduled for deletion?
The key is immediately deleted without any notice.
The key enters a pending deletion state (7-30 days) before permanent deletion.
The key can be used for encryption until the end of the month.
The key is archived and can be retrieved at any time.
Where can AWS ACM certificates NOT be deployed directly?
On CloudFront
On ELB
On API Gateway
On EC2 instances
Which service would you use to securely store and retrieve database credentials at runtime?
AWS Secrets Manager
AWS Key Management Service
AWS Identity and Access Management
AWS CloudTrail
What is the purpose of AWS Incident Response?
To provide guides and tools to help customers detect, respond to, and recover from security incidents following best practices like the NIST CSF.
To offer cloud storage solutions for data backup and recovery.
To manage user access and permissions in AWS environments.
To monitor network traffic for performance optimization.
What is the key security feature of AWS Secrets Manager?
Automatically encrypts all secrets at rest
Automatically rotates secrets (e.g., database passwords, API keys) on a schedule
Provides a user-friendly interface for managing secrets
Stores secrets in a publicly accessible database
How does AWS Certificate Manager (ACM) simplify SSL/TLS certificate management?
ACM automates the provisioning, renewal, and deployment of SSL/TLS certificates for AWS services.
ACM requires manual intervention for certificate renewal and deployment.
ACM only provides SSL/TLS certificates for on-premises servers.
ACM does not support integration with AWS services.
What is the primary use of AWS KMS?
To create, store, and manage cryptographic keys for data encryption in AWS services.
To provide a platform for deploying machine learning models.
To manage user access and permissions in AWS.
To monitor and analyze application performance in real-time.
How does AWS Secrets Manager differ from SSM Parameter Store?
Secrets Manager supports automatic rotation and is designed for secrets, while Parameter Store is a general-purpose service for configuration data.
Both services are identical in functionality and purpose.
SSM Parameter Store supports automatic rotation and is designed for secrets, while Secrets Manager is a general-purpose service for configuration data.
AWS Secrets Manager is only for storing passwords, while SSM Parameter Store is for all types of data.
Can AWS KMS keys be exported?
Yes, AWS-managed KMS keys can be exported.
No, AWS-managed KMS keys cannot be exported.
Yes, but only for custom key stores.
No, but you can use AWS Lambda to export them.
