โ† All Architecting on AWS Certification Flashcard Decks

Safety Practices & PPE Flashcards

7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Safety Practices & PPE flashcards as text
  1. Which principle should guide IAM policy design to minimize the risk of accidental or malicious misuse of AWS resources?

    Answer: Principle of least privilege

    The principle of least privilege means granting only the permissions required to perform a task, reducing the attack surface.

  2. A workload processes highly sensitive PII data. The architect wants to ensure data in transit between services is always encrypted. Which approach satisfies this for an HTTPS API endpoint?

    Answer: Deploy behind an Application Load Balancer with an SSL/TLS certificate

    An ALB with an SSL/TLS certificate terminates HTTPS connections, ensuring all data in transit to the endpoint is encrypted.

  3. Which AWS service provides a centralized view of security alerts and compliance status across multiple AWS accounts and services?

    Answer: AWS Security Hub

    AWS Security Hub aggregates, organizes, and prioritizes security findings from multiple AWS services into a single dashboard.

  4. An organization wants to detect and classify sensitive data (such as PII or financial data) stored across thousands of S3 buckets. Which AWS service automates this?

    Answer: Amazon Macie

    Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data stored in Amazon S3.

  5. A company must ensure that all API calls to AWS services are logged for compliance and forensic analysis. Which service provides this audit trail?

    Answer: AWS CloudTrail

    AWS CloudTrail records all API calls made in an AWS account, providing an audit trail of who did what and when.

  6. Which AWS KMS feature allows you to automatically rotate cryptographic keys on a yearly basis without changing the key ID or ARN used by applications?

    Answer: KMS automatic key rotation

    KMS automatic key rotation rotates the backing key material annually while keeping the same KMS key ID, so no application changes are needed.

  7. A security policy requires that no EC2 instance should be able to communicate directly with the internet. Which VPC component enforces this at the subnet level?

    Answer: Placing instances in a private subnet with no internet gateway route

    Private subnets have no route to an internet gateway, preventing direct internet communication by design.