โ† All Architecting on AWS Certification Flashcard Decks

Quality Control & Inspection Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Quality Control & Inspection flashcards as text
  1. An organization wants to enforce that all new AWS resources are tagged with a 'CostCenter' tag before they can be created. Which mechanism achieves this preventatively?

    Answer: Service Control Policy (SCP) with a tag condition

    An SCP with an aws:RequestTag condition key denies resource creation if the required tag is absent, preventing non-compliant resources from ever existing.

  2. A developer accidentally deletes a CloudTrail trail. Which service can detect this and automatically recreate it?

    Answer: AWS Config with auto-remediation using SSM Automation

    An AWS Config rule can detect that a CloudTrail trail is missing and trigger an SSM Automation document to recreate it automatically.

  3. Which AWS CloudTrail feature ensures that log files have not been tampered with after delivery to S3?

    Answer: Log file integrity validation

    CloudTrail log file integrity validation creates a digitally signed digest file every hour so you can verify logs were not altered or deleted.

  4. AWS Trusted Advisor's 'Security' category flags which of the following issues? (Choose the BEST match)

    Answer: S3 buckets with public read or write access enabled

    Trusted Advisor's Security checks include identifying S3 buckets with public access, exposed access keys, and overly permissive security groups.

  5. A conformance pack in AWS Config is BEST described as:

    Answer: A set of AWS Config rules bundled with remediation actions as a deployable template

    A conformance pack is a YAML template that groups multiple Config rules and optional remediation actions for deployment across an organization.

  6. Which AWS service enables forensic investigation of security incidents by visualizing relationships between resources, IPs, and user accounts over time?

    Answer: Amazon Detective

    Amazon Detective automatically collects log data and uses ML to build an interactive graph model for investigating and visualizing security incidents.

  7. An architect needs patch compliance reporting for 500 EC2 instances across multiple regions. Which service provides a unified patch compliance dashboard?

    Answer: AWS Systems Manager Patch Manager

    AWS Systems Manager Patch Manager scans instances and reports patch compliance status in a centralized compliance dashboard.