Safety Practices & PPE Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety Practices & PPE flashcards as text
Which AWS service protects web applications from common exploits like SQL injection and cross-site scripting (XSS) by inspecting HTTP/HTTPS requests?
Answer: AWS WAF
AWS WAF (Web Application Firewall) inspects web requests and blocks those matching rules for threats like SQL injection and XSS.
An architect wants to enforce MFA for all IAM users when they access the AWS Management Console. What is the correct approach?
Answer: Attach an IAM policy requiring MFA as a condition on all actions
An IAM policy with a condition key (aws:MultiFactorAuthPresent) denies actions unless MFA is active, effectively requiring MFA for console access.
A company wants to manage and rotate database credentials automatically without hardcoding them in application code. Which AWS service provides this capability?
Answer: AWS Secrets Manager
AWS Secrets Manager stores, retrieves, and automatically rotates secrets like database credentials on a configurable schedule.
Which defense-in-depth approach should an architect use to protect an application that requires both web-tier and database-tier security?
Answer: Use separate security groups for web and database tiers with the DB group only allowing traffic from the web group
Tiered security groups implement defense in depth by ensuring the database tier only accepts traffic explicitly from the web tier, not from any external source.
AWS Shield Standard is automatically enabled for all AWS customers. What additional protection does AWS Shield Advanced provide?
Answer: DDoS cost protection and access to the AWS DDoS Response Team (DRT)
AWS Shield Advanced adds financial protection against DDoS-related cost spikes and provides access to the specialized AWS DDoS Response Team.
Which IAM entity should applications running on EC2 use to securely access other AWS services without storing long-term credentials?
Answer: IAM role attached to the EC2 instance
IAM roles attached to EC2 instances provide temporary, automatically-rotated credentials, eliminating the need to store long-term access keys.
A company needs to ensure that all resources created in AWS comply with security tagging standards. Which AWS service continuously monitors and alerts on compliance?
Answer: AWS Config with managed rules
AWS Config evaluates resource configurations against rules (including required-tags rules) and flags non-compliant resources in real time.