Solutions Architect Security & Compliance Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Solutions Architect Security & Compliance flashcards as text
Which AWS service uses threat intelligence feeds and anomaly detection to identify malicious activity such as cryptocurrency mining or unauthorized access in an AWS account?
Answer: Amazon GuardDuty
Amazon GuardDuty continuously analyzes CloudTrail, VPC Flow Logs, and DNS logs using threat intelligence and ML to detect malicious activity.
A solutions architect must allow an on-premises application to call AWS APIs securely without storing long-term IAM credentials. What is the recommended approach?
Answer: Use AWS IAM Roles Anywhere with an on-premises PKI certificate
IAM Roles Anywhere lets on-premises workloads assume IAM roles using X.509 certificates from a trusted PKI, eliminating long-term credentials.
An application stores database passwords in AWS Secrets Manager with automatic rotation enabled. What happens to the application during a rotation event if it caches the secret?
Answer: The application may use the old secret briefly until the cache expires; Secrets Manager maintains the old version during rotation
Secrets Manager maintains both AWSPREVIOUS and AWSCURRENT versions during rotation, so cached old secrets remain valid briefly, preventing application downtime.
Which AWS Certificate Manager (ACM) feature automatically renews public SSL/TLS certificates before expiration?
Answer: ACM managed renewal for certificates issued by ACM and used with supported AWS services
ACM automatically renews public certificates it issues when they are associated with supported AWS services like CloudFront, ALB, or API Gateway.
A regulated workload requires that encryption keys never leave a hardware boundary and that the company has sole control. Which KMS key type satisfies this?
Answer: External key store (XKS) backed by an on-premises HSM
KMS External Key Store (XKS) keeps the key material in a customer-controlled external HSM, so keys never reside inside AWS infrastructure.
What is the primary security benefit of enabling VPC Flow Logs for a production environment?
Answer: They capture IP traffic metadata for network monitoring, forensics, and anomaly detection
VPC Flow Logs capture metadata about accepted and rejected traffic (IPs, ports, protocols) enabling network forensics and anomaly detection without impacting traffic.
A company wants to use AWS WAF to protect an API Gateway. Which WAF rule type can block requests containing SQL injection patterns in query strings?
Answer: AWS Managed Rules for SQL database
AWS WAF Managed Rules for SQL Database detect and block common SQL injection attack patterns in request components including query strings.