โ† All AWS Flashcard Decks

Security Automation Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Automation flashcards as text
  1. A company uses AWS CodeArtifact to host internal packages. How can they ensure that only packages without known vulnerabilities are consumed by development teams?

    Answer: Integrate Amazon Inspector with CodeArtifact and block packages with critical CVEs via a Lambda upstream proxy

    Inspector can scan packages in CodeArtifact and a Lambda-backed upstream proxy can block or flag packages with critical vulnerabilities.

  2. Which AWS feature allows you to define and enforce tagging policies across all resources in an AWS Organization to support cost allocation and security auditing?

    Answer: AWS Organizations Tag Policies

    Tag Policies in AWS Organizations define standardized tag keys and allowed values and can enforce compliance across the entire organization.

  3. A security engineer needs to ensure that no EC2 instance in the account uses a security group that allows unrestricted inbound SSH (port 22). Which solution provides continuous automated detection?

    Answer: AWS Firewall Manager with a Security Group policy

    AWS Firewall Manager Security Group policies continuously audit and can automatically remediate non-compliant security groups across accounts.

  4. When using AWS KMS customer-managed keys (CMKs) in a CI/CD pipeline, what is the recommended practice for granting CodeBuild access to decrypt artifacts?

    Answer: Attach an IAM role to the CodeBuild project with kms:Decrypt permission and reference the role in the CMK key policy

    The CodeBuild service role must have kms:Decrypt in its IAM policy and that role must be listed in the CMK key policy for cross-service access.

  5. A DevOps team stores database credentials as environment variables in CodeBuild. The security team flags this as a risk. What is the correct remediation?

    Answer: Reference secrets using the SSM Parameter Store or Secrets Manager integration in the CodeBuild environment variables configuration

    CodeBuild natively supports referencing SSM Parameter Store and Secrets Manager secrets in environment variable definitions, keeping plaintext credentials out of the build configuration.

  6. Which AWS service provides a managed, centralized dashboard that aggregates security findings from GuardDuty, Inspector, Macie, and other services across multiple accounts?

    Answer: AWS Security Hub

    AWS Security Hub aggregates, normalizes, and prioritizes findings from integrated AWS security services and third-party tools.

  7. A pipeline deploys infrastructure using CloudFormation. To enforce least privilege, the CloudFormation service role should have which characteristic?

    Answer: Only the permissions required to create, update, and delete the specific resources defined in the stack template

    The CloudFormation service role should follow least privilege and only include permissions for the exact resource types used in that specific stack.