Security Automation Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Automation flashcards as text
A security team wants to automatically remediate S3 buckets that become publicly accessible. Which combination of AWS services achieves this with the least operational overhead?
Answer: AWS Config rule with an SSM Automation remediation document
AWS Config rules can be paired with SSM Automation documents to automatically remediate non-compliant resources without custom Lambda code.
During a pipeline run, you need to scan container images for known CVEs before pushing to ECR. Which service is purpose-built for this task within an AWS-native pipeline?
Answer: Amazon Inspector with ECR integration
Amazon Inspector integrates natively with ECR to scan container images for CVEs on push and continuously thereafter.
Your CodePipeline must ensure that all CloudFormation stacks pass a security review before deployment. Which approach enforces preventive controls at the IaC layer?
Answer: AWS CloudFormation Guard (cfn-guard) rules in a CodeBuild stage
CloudFormation Guard evaluates IaC templates against policy rules as a pipeline gate before any resources are provisioned.
A DevSecOps team needs secrets stored in AWS Secrets Manager to be automatically rotated every 30 days for an RDS database. What must be configured for this to work?
Answer: A Lambda rotation function associated with the secret and a rotation schedule
Secrets Manager requires a Lambda rotation function (AWS provides templates) and a rotation schedule configured on the secret.
Which AWS service can be used to detect when an IAM principal is making API calls from an unusual geographic location and automatically alert the security team?
Answer: Amazon GuardDuty
GuardDuty uses ML to detect anomalous API activity including calls from unusual locations and generates findings for alerting.
A team wants to enforce that all new IAM roles created in their AWS account have a permission boundary attached. Which service and feature enforces this as a preventive control?
Answer: AWS Organizations Service Control Policy (SCP) denying CreateRole without a PermissionsBoundary condition
An SCP with a Deny on iam:CreateRole unless a PermissionsBoundary condition key is present enforces this preventively across the organization.
In a CI/CD pipeline, static application security testing (SAST) should be placed at which stage to provide the earliest feedback to developers?
Answer: In the build stage, immediately after source code checkout
SAST tools analyze source code without execution and should run at build time to give developers the fastest feedback loop.