Skip to main content

Practice Questions

9 questions for Domain 2 - Security and Compliance (30%). Download all for Anki.

Which of the following is the customer responsible for updating and patching, according to the AWS shared responsibility model?

  • A. Amazon Cognito
  • B. AWS Directory Service
  • C. AWS IAM Identity Center
  • D. Amazon API Gateway

Which AWS service identifies security groups that allow unrestricted access to a user's AWS resources?

  • A. AWS CloudTrail
  • B. AWS Trusted Advisor
  • C. AWS Identity and Access Management (IAM)
  • D. Amazon CloudWatch

Which credential components are required to gain programmatic access to an AWS account?

2 answers
  • A. An access key ID
  • B. A secret access key
  • C. A user ID
  • D. A primary key
  • E. A secondary key

Which of the following is the customer responsible for updating and patching, according to the AWS shared responsibility model?

  • A. Amazon FSx for Windows File Server
  • B. Amazon WorkSpaces virtual Windows desktop
  • C. AWS Directory Service for Microsoft Active Directory
  • D. Amazon RDS for Microsoft SQL Server

Which AWS service should be used to implement encryption in transit?

  • A. AWS Certificate Manager (ACM)
  • B. AWS Security Hub
  • C. AWS Shield
  • D. AWS Resource Access Manager (AWS RAM)

Which task is the customer's responsibility for AWS Lambda, according to the AWS shared responsibility model?

  • A. Encryption of the application data at rest
  • B. Management of the application platform
  • C. Patching of the guest operating system
  • D. Security of the physical infrastructure

A user needs to automatically discover, classify, and protect sensitive data stored in Amazon S3. Which AWS service can meet these requirements?

  • A. Amazon GuardDuty
  • B. Amazon Macie
  • C. Amazon Inspector
  • D. AWS Secrets Manager

Which security-related services or features does AWS offer? (Select TWO.)

2 answers
  • A. Complete PCI compliance for customer applications that run on AWS
  • B. AWS Trusted Advisor security checks
  • C. Data encryption
  • D. Automated penetration testing
  • E. Amazon S3 copyrighted content detection

Which tasks are the customer's responsibility according to the AWS shared responsibility model?

2 answers
  • A. Configure security groups for Amazon EC2 instances.
  • B. Configure IAM users according to the principle of least privilege.
  • C. Control physical access to the data center that contains a customer's VPC.
  • D. Patch the operating system that AWS Lambda functions use.
  • E. Install patches on Amazon RDS DB instances.