Solutions Architect Security & Compliance Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Solutions Architect Security & Compliance flashcards as text
A company needs to enforce that all S3 objects are encrypted at rest using customer-managed keys. Which S3 bucket policy condition key enforces SSE-KMS encryption on uploads?
Answer: s3:x-amz-server-side-encryption
The condition key `s3:x-amz-server-side-encryption` with value `aws:kms` enforces that objects must be uploaded using SSE-KMS encryption.
Which AWS service provides a managed, hardware-based key storage that meets FIPS 140-2 Level 3 compliance requirements?
Answer: AWS CloudHSM
AWS CloudHSM provides dedicated hardware security modules that meet FIPS 140-2 Level 3 compliance, unlike KMS which is Level 2.
A solutions architect needs to ensure EC2 instances in a private subnet can retrieve secrets without traversing the internet. What is the most secure approach?
Answer: Create a VPC endpoint for Secrets Manager
A VPC interface endpoint for Secrets Manager allows private subnet instances to access secrets without internet exposure via NAT.
Which IAM policy element explicitly overrides all Allow statements and denies access regardless of other policies?
Answer: Explicit Deny
An explicit Deny in any policy always overrides any Allow, following the IAM evaluation logic of default deny → explicit allow → explicit deny.
An organization wants to detect when AWS root account credentials are used. Which combination of services provides near-real-time alerting?
Answer: CloudTrail + CloudWatch Alarms + SNS
CloudTrail logs root account usage, CloudWatch Alarms filter for root login events, and SNS delivers the alert in near-real time.
What is the purpose of an AWS Organizations Service Control Policy (SCP)?
Answer: Define maximum available permissions for accounts in an OU
SCPs set guardrails by defining the maximum permissions that accounts in an OU or organization can have, without granting permissions themselves.
A web application on EC2 must restrict traffic to only HTTPS. Which resource controls inbound traffic at the instance level and supports stateful filtering?
Answer: Security Group
Security groups are stateful firewalls attached at the instance level and can restrict inbound traffic to port 443 (HTTPS) only.