Quality Control & Inspection Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Quality Control & Inspection flashcards as text
A security team wants to automatically assess EC2 instances for known software vulnerabilities and unintended network exposure. Which AWS service is purpose-built for this?
Answer: Amazon Inspector
Amazon Inspector automatically scans EC2 instances and container images for software vulnerabilities and unintended network exposure.
Which AWS service aggregates security findings from multiple AWS security services and partner tools into a single dashboard?
Answer: AWS Security Hub
AWS Security Hub aggregates, organizes, and prioritizes security findings from services like GuardDuty, Inspector, and Macie.
An architect must ensure S3 buckets never become publicly accessible across all accounts in an AWS Organization. Which control enforces this preventatively?
Answer: S3 Block Public Access at the organization level
Enabling S3 Block Public Access settings at the AWS Organizations level preventatively stops any account from making buckets public.
AWS Audit Manager is BEST suited for which use case?
Answer: Continuously collecting evidence to simplify compliance audits
AWS Audit Manager continuously collects audit-ready evidence mapped to compliance frameworks like PCI DSS and HIPAA.
A company needs to detect when an IAM policy is attached to a user directly (violating least-privilege policy). Which tool detects this configuration drift?
Answer: AWS Config with a managed rule
The AWS Config managed rule `iam-user-no-policies-check` flags any IAM user with policies attached directly rather than via groups.
Which AWS Well-Architected Tool feature allows teams to compare their workload against AWS best practices across five pillars?
Answer: Well-Architected Review milestones
The Well-Architected Tool guides teams through a questionnaire and records milestone snapshots showing improvement over time across all five pillars.
Amazon Macie is PRIMARILY used to inspect which type of resource for sensitive data?
Answer: Amazon S3 buckets
Amazon Macie uses machine learning to automatically discover and classify sensitive data stored in Amazon S3.