Quality Control & Inspection Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Quality Control & Inspection flashcards as text
Which AWS Config aggregator feature allows a security team to view compliance data from all accounts in an AWS Organization from a single account?
Answer: Organization-level Config aggregator
An AWS Config aggregator collects configuration and compliance data from multiple accounts and regions into a single delegated administrator account.
A company must prove to auditors that no IAM root account API calls occurred in the past 90 days. Which approach provides this evidence MOST efficiently?
Answer: Query CloudTrail Lake with SQL for root user events
CloudTrail Lake allows SQL-based queries over event history, making it straightforward to filter for `userIdentity.type = Root` within a date range.
AWS Config's `restricted-ssh` managed rule evaluates which resource type?
Answer: EC2 security groups permitting unrestricted inbound SSH
The `restricted-ssh` rule flags EC2 security groups that allow inbound traffic from 0.0.0.0/0 or ::/0 on port 22.
A company runs containers on Amazon ECS and needs vulnerability scanning for container images at the time of push. Which service integration provides this?
Answer: Amazon Inspector integrated with Amazon ECR
Amazon Inspector integrates with Amazon ECR to automatically scan container images for software vulnerabilities when they are pushed to a repository.
Which metric does the AWS Well-Architected Tool produce after completing a workload review?
Answer: A count of high-risk issues (HRIs) per pillar
The Well-Architected Tool surfaces High Risk Issues (HRIs) and Medium Risk Issues (MRIs) per pillar, guiding remediation priority.
An architect must ensure CloudTrail is enabled in every region for every new account added to an AWS Organization. What is the MOST scalable solution?
Answer: Create an organization-level CloudTrail trail in the management account
An organization-level CloudTrail trail automatically applies to all existing and future member accounts and all regions with a single configuration.
GuardDuty finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS' indicates what threat?
Answer: EC2 instance credentials are being used from outside AWS, suggesting exfiltration
This GuardDuty finding means credentials issued to an EC2 instance (via instance metadata) are being used from an IP address outside of AWS, a strong indicator of credential theft.