Safety Systems & Standards Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety Systems & Standards flashcards as text
Which AWS service provides automated security assessments that check for deviations from security best practices in EC2 instances and container workloads?
Answer: Amazon Inspector
Amazon Inspector performs automated vulnerability assessments on EC2 instances and container images, checking for software vulnerabilities and unintended network exposure.
A DevOps team needs to enforce that all S3 buckets must have server-side encryption enabled. Which AWS tool automatically remediates non-compliant resources?
Answer: AWS Config with auto-remediation
AWS Config rules can trigger automatic remediation actions via AWS Systems Manager Automation documents when resources are found non-compliant.
In a CI/CD pipeline, which practice ensures that infrastructure code meets security standards before deployment?
Answer: Static code analysis with tools like Checkov or cfn-nag
Static analysis tools like Checkov and cfn-nag scan IaC templates (CloudFormation, Terraform) for security misconfigurations before deployment.
Which AWS CodePipeline feature can pause a pipeline execution and require a human to review and approve changes before proceeding to production?
Answer: Manual approval action
CodePipeline's manual approval action halts the pipeline and sends an SNS notification, requiring an authorized reviewer to approve or reject before continuing.
A team wants to detect when IAM policies are modified in their AWS account. Which service should they configure to alert on these changes?
Answer: AWS CloudTrail with Amazon EventBridge rules
CloudTrail logs all IAM API calls, and EventBridge rules can trigger alerts or automated responses when specific IAM modification events are detected.
Which AWS feature allows you to define guardrails that prevent AWS accounts in an Organization from performing specific high-risk actions regardless of IAM permissions?
Answer: Service Control Policies (SCPs)
SCPs in AWS Organizations act as maximum permission boundaries, blocking actions even if an IAM policy explicitly grants them.
During a rolling deployment, an application's error rate spikes above the defined threshold. Which AWS service automatically triggers a rollback based on CloudWatch alarms?
Answer: AWS CodeDeploy with automatic rollback
AWS CodeDeploy can be configured to automatically roll back a deployment when a CloudWatch alarm threshold is breached during or after deployment.