QuestionQ1
Infrastructure SecurityA company must comply with a requirement to encrypt all data in transit. The company recently identified an Amazon Aurora cluster that fails to meet this requirement.
How can the company require encryption for every connection to the Aurora cluster?
QuestionQ2
DetectionA company operates several applications on Amazon Elastic Kubernetes Service (Amazon EKS). The company requires a solution to identify Kubernetes security risks by monitoring Amazon EKS audit logs, as well as operating system, networking, and file events. The solution must send email alerts for any detected risks to a mailing list associated with a security team.
Which solution meets these requirements?
Community Discussion
QuestionQ3
Identity and Access ManagementA company hosts an application on an Amazon EC2 instance. The application creates invoices and saves them in an Amazon S3 bucket. The instance profile attached to the instance has the required access to the S3 bucket.
The company must share every invoice with multiple clients who do not have AWS credentials. Each client must be able to download only that client’s own invoices. Clients must download invoices within 1 hour after invoice creation. Clients must use only temporary credentials to access the company’s AWS resources.
A security engineer creates a script that runs on the EC2 instance. The script uses the instance profile to create an S3 presigned URL for the clients. Each presigned URL expires after 1 hour.
Which additional step will satisfy these requirements?
Community Discussion
QuestionQ4
Incident ResponseA company operates critical workloads in an on-premises data center. The company wants to implement an AWS-based disaster recovery (DR) solution that achieves an RTO of less than 1 hour. The company must continuously replicate physical and virtual servers. It must optimize costs for data storage and bandwidth use. The DR solution must be automated.
Which solution meets these requirements?
Community Discussion
QuestionQ5
Identity and Access ManagementA company uses AWS IAM Identity Center to control access to its AWS accounts. The accounts belong to an organization in AWS Organizations.
A security engineer must establish delegated administration of IAM Identity Center in the organization’s management account.
Which combination of steps should the security engineer complete in IAM Identity Center before setting up delegated administration?
Community Discussion