Codes & Standards Compliance Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Codes & Standards Compliance flashcards as text
A financial services company must ensure all data at rest in S3 is encrypted to meet PCI DSS requirements. Which S3 feature enforces this at the bucket level without modifying application code?
Answer: S3 Default Encryption with SSE-S3 or SSE-KMS
S3 Default Encryption automatically encrypts all objects stored in a bucket, satisfying PCI DSS encryption-at-rest requirements without application changes.
Which AWS service provides a managed way to store, rotate, and audit database credentials to help meet SOC 2 access-control requirements?
Answer: AWS Secrets Manager
AWS Secrets Manager provides automatic rotation, fine-grained access policies, and CloudTrail audit logging for secrets, directly supporting SOC 2 access-control criteria.
An architect needs to demonstrate that all API calls to AWS services are logged for a HIPAA audit. Which service should be enabled?
Answer: AWS CloudTrail
AWS CloudTrail records all API calls made within an account and delivers log files to S3, providing the audit trail required by HIPAA's audit-control safeguard.
A company subject to FedRAMP must use FIPS 140-2 validated encryption endpoints. How should architects configure AWS SDK clients to meet this requirement?
Answer: Use AWS FIPS endpoints for the relevant services
AWS publishes FIPS 140-2 validated service endpoints (e.g., s3-fips.us-east-1.amazonaws.com) that SDK clients must explicitly target to meet FedRAMP cryptographic requirements.
Under the AWS Shared Responsibility Model, who is responsible for patching the guest operating system on Amazon EC2 instances?
Answer: The customer
The customer is responsible for patching the OS and software running on EC2 instances; AWS only manages the underlying hypervisor and physical infrastructure.
Which AWS service continuously evaluates resource configurations against desired compliance rules and can automatically remediate non-compliant resources?
Answer: AWS Config with Config Rules and Remediation Actions
AWS Config Rules evaluate resource configurations on change or schedule, and Remediation Actions can invoke SSM Automation to auto-fix non-compliant resources.
A healthcare company needs to sign a Business Associate Agreement (BAA) with AWS before storing PHI. Where is this BAA executed?
Answer: Through AWS Artifact by accepting the AWS BAA agreement
AWS Artifact provides on-demand access to AWS compliance reports and agreements, including the HIPAA BAA, which customers accept to cover their use of HIPAA-eligible services.