[{"data":1,"prerenderedAt":523},["ShallowReactive",2],{"practiceExams":3,"practice-exam-questions-\u002Fpractice-exams\u002Faws-certified-security-specialty-scs-c02\u002Fquestions":79},[4,15,23,32,42,51,61,70],{"id":5,"slug":6,"description":7,"questionCount":8,"isActive":9,"datePublicModified":10,"difficulty":11},9,"aws-certified-data-engineer-associate-dea-c01","Prepare for your AWS Certified Data Engineer - Associate exam with our practice exam simulator. Featuring real exam scenarios, detailed explanations, and instant feedback to boost your confidence and success rate.",3312,true,"2024-11-13T00:00:00.000Z",{"title":12,"subtitle":13,"slug":6,"coverImageUrl":14},"AWS Certified Data Engineer - Associate","DEA-C01","",{"id":16,"slug":17,"description":18,"questionCount":19,"isActive":9,"datePublicModified":10,"difficulty":20},10,"aws-certified-advanced-networking-specialty-ans-c01","The AWS Certified Advanced Networking - Specialty practice exam simulates the real test, offering scenario-based questions that assess your ability to design, implement, and troubleshoot complex AWS networking solutions. ",3531,{"title":21,"subtitle":22,"slug":17,"coverImageUrl":14},"AWS Certified Advanced Networking - Specialty","ANS-C01",{"id":24,"slug":25,"description":26,"questionCount":27,"isActive":9,"datePublicModified":28,"difficulty":29},8,"aws-certified-devops-engineer-professional-dop-c02","Boost your readiness for the AWS Certified DevOps Engineer - Professional (DOP-C02) exam with our practice exam simulator. Featuring realistic questions and detailed explanations, it helps you identify knowledge gaps and improve your skills.",2775,"2024-08-08T00:00:00.000Z",{"title":30,"subtitle":31,"slug":25,"coverImageUrl":14},"AWS Certified DevOps Engineer - Professional","DOP-C02",{"id":33,"slug":34,"description":35,"questionCount":36,"isActive":9,"datePublicModified":37,"difficulty":38},1,"aws-certified-solutions-architect-associate-saa-c03","Unlock your potential with the AWS Certified Solutions Architect - Associate Practice Exam Simulator. This comprehensive tool is designed to prepare you thoroughly and assess your readiness for the most sought-after AWS associate certification.",3813,"2024-06-13T00:00:00.000Z",{"title":39,"subtitle":40,"slug":34,"coverImageUrl":41},"AWS Certified Solutions Architect - Associate","SAA-C03","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-associatesaa-c03\u002Fcovers\u002Faws-SAA-C03.png",{"id":43,"slug":44,"description":45,"questionCount":46,"isActive":9,"datePublicModified":37,"difficulty":47},5,"aws-certified-cloud-practitioner-clf-c02","Master your AWS Certified Cloud Practitioner exam with our Practice Exam Simulator. Prepare effectively and assess your readiness with realistic practice exams designed to mirror the most popular official AWS exam.",4227,{"title":48,"subtitle":49,"slug":44,"coverImageUrl":50},"AWS Certified Cloud Practitioner","CLF-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-cloud-practitionerclf-c02\u002Fcovers\u002Faws-CLF-C02.png",{"id":52,"slug":53,"description":54,"questionCount":55,"isActive":9,"datePublicModified":56,"difficulty":57},4,"aws-certified-developer-associate-dva-c02","Unlock your potential as a software developer with the AWS Certified Developer - Associate Exam Simulator! Prepare thoroughly with realistic practice exams designed to mirror the official exam.",3787,"2024-06-06T00:00:00.000Z",{"title":58,"subtitle":59,"slug":53,"coverImageUrl":60},"AWS Certified Developer - Associate","DVA-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-developer-associatedva-c02\u002Fcovers\u002Faws-DVA-C02.png",{"id":62,"slug":63,"description":64,"questionCount":65,"isActive":9,"datePublicModified":56,"difficulty":66},6,"aws-certified-solutions-architect-professional-sap-c02","Elevate your career with the AWS Certified Solutions Architect - Professional Exam Simulator. Get ready to ace the most popular Professional AWS exam with our realistic practice exams. Assess your readiness, boost your confidence, and ensure your success.",8203,{"title":67,"subtitle":68,"slug":63,"coverImageUrl":69},"AWS Certified Solutions Architect - Professional","SAP-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-professionalsap-c02\u002Fcovers\u002Faws-SAP-C02.png",{"id":71,"slug":72,"description":73,"questionCount":74,"isActive":9,"datePublicModified":56,"difficulty":75},7,"aws-certified-security-specialty-scs-c02","Advance your career in cloud cybersecurity with the AWS Certified Security - Specialty Exam Simulator! Tailored for professionals, this tool offers realistic practice exams to mirror the official exam.",5439,{"title":76,"subtitle":77,"slug":72,"coverImageUrl":78},"AWS Certified Security - Specialty","SCS-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-security-specialtyscs-c02\u002Fcovers\u002Faws_SCS_c02.png",{"id":71,"slug":72,"description":73,"content":80,"formalQuestionCount":81,"minQuestionCount":33,"maxQuestionCount":81,"formalTimeLimitCount":82,"minTimeLimitCount":16,"maxTimeLimitCount":83,"passingScore":84,"questionCount":74,"isActive":9,"dateCreated":85,"dateModified":86,"datePublicModified":56,"difficulty":87,"tags":522},"\u003Cp>\u003Cspan class=\"text-big\">Don't be fooled by the relatively short list of exam scope services. You really have to know them all in great detail. Each service is integrated with others and encompasses countless concepts and technologies you must be well familiar with.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The AWS Certified Security - Specialty certification is known for its high level of difficulty, requiring both broad and deep knowledge of security principles and AWS services. This certification tests your ability to secure applications and data on the AWS platform, demanding a thorough understanding of core security services and best practices for securing AWS environments.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The exam emphasizes an understanding of key AWS security services such as IAM, KMS, CloudTrail, Config, Shield, WAF, Security Hub, and GuardDuty. You need to know how these services work, how to configure them, and how to integrate them into a secure architecture.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">You must be able to solve complex, real-world security problems. This includes designing secure infrastructures, implementing robust access controls, managing data protection, and performing incident response. Understanding how to monitor and audit AWS environments for compliance and security issues is also essential, involving tools like CloudWatch, CloudTrail, and AWS Config.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Regulatory compliance is another critical aspect. Candidates must understand various regulatory requirements such as HIPAA, GDPR, and PCI-DSS, and how to implement and maintain compliance within AWS environments. This includes using AWS services to meet these regulatory standards and setting up audit trails and monitoring systems to ensure ongoing compliance.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The certification also requires a solid grasp of AWS's global infrastructure, including regions and availability zones, and how to design applications that ensure high availability, fault tolerance, and disaster recovery.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Furthermore, the exam demands familiarity with advanced security practices, including encryption mechanisms, secure data storage and transfer, and identity and access management. You need to understand how to leverage these practices to protect sensitive data and maintain security across various AWS services.\u003C\u002Fspan>\u003C\u002Fp>",65,170,200,75,"2024-05-12T19:17:22.106Z","2024-08-08T19:29:30.000Z",{"id":43,"title":76,"subtitle":77,"rating":88,"slug":72,"guideUrl":89,"categories":90,"services":366},4.5,"https:\u002F\u002Fd1.awsstatic.com\u002Ftraining-and-certification\u002Fdocs-security-spec\u002FAWS-Certified-Security-Specialty_Exam-Guide.pdf",[91,136,187,235,272,319],{"id":92,"title":93,"subtitle":94,"description":95,"content":96,"coverImageUrl":14,"weight":97,"subcategories":98},17,"Threat Detection and Incident Response","Domain 1","The Threat Detection and Incident Response domain focuses on identifying, mitigating, and managing security threats. It involves detecting suspicious activities, analyzing security incidents, and implementing effective response strategies.",null,14,[99,126,131],{"id":100,"title":101,"subtitle":102,"description":96,"questions":103},69,"Design and implement an incident response plan","Task 1.1",[104],{"id":105,"subcategoryId":100,"content":106,"hint":107,"isPublic":9,"answers":108},11855,"A company with multiple AWS accounts is using AWS Organizations to manage these accounts. The security team wants to enhance threat detection and incident response across the organization. They plan to implement a centralized logging solution using Amazon CloudWatch Logs and to create custom metric filters that match the patterns of known incidents. When a threat is detected, they want to automate the response by triggering AWS Lambda functions to remediate the issue. To ensure that threat detection events are managed centrally and that appropriate responses are automatically initiated, the team decides to use Amazon EventBridge. Which of the following steps should the security team take to configure integration and incident response using Amazon EventBridge, without adding unnecessary complexity or permissions?","Consider the role of AWS Organizations service control policies (SCPs) in managing permissions and how EventBridge can be set up to orchestrate and handle events across multiple accounts.",[109,113,118,122],{"id":110,"questionId":105,"content":111,"hint":112,"isCorrect":9},47419,"Create an EventBridge event bus in the management account, enable EventBridge to receive events across the associated accounts in AWS Organizations, and create rules in the central event bus to trigger Lambda functions in response to specific threat detection patterns.","This approach allows for centralized management of events and automated responses. EventBridge can be set up in a multi-account environment using event buses to pull in events from all the linked accounts in AWS Organizations. This simplifies the operation and ensures that proper actions are taken without direct intervention, streamlining the incident response process.",{"id":114,"questionId":105,"content":115,"hint":116,"isCorrect":117},47420,"Create an individual EventBridge event bus in each account and set up cross-account resource sharing for each event bus to send and receive threat detection events.","This setup increases complexity and management overhead by necessitating individual event buses and cross-account sharing for all accounts, which is not required if a centralized event bus is used in the management account.",false,{"id":119,"questionId":105,"content":120,"hint":121,"isCorrect":117},47421,"Avoid using EventBridge and manually assess and respond to threat detection patterns by assigning dedicated security personnel to monitor CloudWatch Logs in each AWS account.","This strategy would be resource-intensive and slow, as it relies on manual intervention instead of automation, which doesn't align with the goal of designing and implementing an incident response plan that includes automated response to threats.",{"id":123,"questionId":105,"content":124,"hint":125,"isCorrect":117},47422,"Develop a custom third-party service outside AWS to collect CloudWatch Logs from all accounts and trigger AWS Lambda functions in each account upon threat detection.","While a third-party service could theoretically be used, it introduces additional complexity, potential security concerns, and goes against the intent of the question which is to integrate with native AWS services. AWS offers built-in tools specifically designed for this purpose, like EventBridge and AWS Organizations.",{"id":127,"title":128,"subtitle":129,"description":96,"questions":130},70,"Detect security threats and anomalies by using AWS services","Task 1.2",[],{"id":132,"title":133,"subtitle":134,"description":96,"questions":135},71,"Respond to compromised resources and workloads","Task 1.3",[],{"id":137,"title":138,"subtitle":139,"description":140,"content":96,"coverImageUrl":14,"weight":137,"subcategories":141},18,"Security Logging and Monitoring","Domain 2","The Security Logging and Monitoring domain covers the implementation and management of logging and monitoring systems. It focuses on collecting, analyzing, and responding to security-related data to ensure compliance and enhance security posture.",[142,147,152,157,161],{"id":143,"title":144,"subtitle":145,"description":96,"questions":146},72,"Design and implement monitoring and alerting to address security events","Task 2.1",[],{"id":148,"title":149,"subtitle":150,"description":96,"questions":151},73,"Troubleshoot security monitoring and alerting","Task 2.2",[],{"id":153,"title":154,"subtitle":155,"description":96,"questions":156},74,"Design and implement a logging solution","Task 2.3",[],{"id":84,"title":158,"subtitle":159,"description":96,"questions":160},"Troubleshoot logging solutions","Task 2.4",[],{"id":162,"title":163,"subtitle":164,"description":96,"questions":165},76,"Design a log analysis solution","Task 2.5",[166],{"id":167,"subcategoryId":162,"content":168,"hint":169,"isPublic":9,"answers":170},12612,"A company is using AWS for their production environment, where they have multiple EC2 instances, S3 buckets and RDS databases in use. They want to aggregate all logs into a central repository for analysis to improve security through better visibility. To automate the process of normalizing, parsing, and correlating these logs for consistent formatting and simplified analysis, they are planning on leveraging AWS services. Which of the following approaches using AWS Lambda is most appropriate for meeting their need to analyze security logs in a cost-effective and scalable way?","Think about the AWS Lambda's ability to trigger from various AWS service events and its power to run code in response. Also, consider its integration with other AWS services for log analysis.",[171,175,179,183],{"id":172,"questionId":167,"content":173,"hint":174,"isCorrect":9},50447,"Use AWS Lambda functions triggered by S3 event notifications whenever new logs are delivered to the S3 bucket. The Lambda function can parse, normalize, and then push the transformed logs to Amazon Elasticsearch Service for correlation and analysis.","This method is cost-effective as AWS Lambda runs only when triggered, thereby saving on idle resources. It also scales automatically with the number of events, making it a good fit for variable log data. Moreover, Amazon Elasticsearch Service is well-suited for log analysis and correlation.",{"id":176,"questionId":167,"content":177,"hint":178,"isCorrect":117},50448,"Invoke AWS Lambda functions on a fixed schedule using Amazon CloudWatch Events to pull logs from each EC2 instance, S3 bucket, and RDS instance, for manual normalization, parsing, and correlation before storage in an Amazon RDS database.","While it is possible to schedule AWS Lambda functions, pulling logs from each service would be inefficient and manual parsing would not be a scalable solution. Storing processed logs in an RDS database is also not ideal for log analysis.",{"id":180,"questionId":167,"content":181,"hint":182,"isCorrect":117},50449,"Deploy AWS Lambda functions to each EC2 instance to locally normalize and parse logs before directly forwarding them to a third-party SIEM (Security Information and Event Management) solution over the Internet.","AWS Lambda cannot be deployed 'to' EC2 instances like an agent. It exists as a standalone service that can interact with EC2 but not reside on it. Additionally, this approach does not efficiently use AWS integrations for log correlation and it potentially introduces significant data transfer costs.",{"id":184,"questionId":167,"content":185,"hint":186,"isCorrect":117},50450,"Configure AWS Lambda to continuously stream data from Amazon Kinesis Data Firehose to execute in-memory log normalization and parsing, and subsequently discard the logs to prevent overstorage.","While you can use AWS Lambda to process streaming data from Kinesis, discarding the logs after processing would defeat the purpose of log aggregation for analysis. The goal is to store the processed logs for future analysis, not to discard them.",{"id":188,"title":189,"subtitle":190,"description":191,"content":96,"coverImageUrl":14,"weight":192,"subcategories":193},19,"Infrastructure Security","Domain 3","Infrastructure Security domain focuses on securing cloud infrastructure. It covers best practices for network security, host-based security, and securing data in transit and at rest, leveraging AWS services to protect against threats and vulnerabilities.",20,[194,199,204,209],{"id":195,"title":196,"subtitle":197,"description":96,"questions":198},77,"Design and implement security controls for edge services","Task 3.1",[],{"id":200,"title":201,"subtitle":202,"description":96,"questions":203},78,"Design and implement network security controls","Task 3.2",[],{"id":205,"title":206,"subtitle":207,"description":96,"questions":208},79,"Design and implement security controls for compute workloads","Task 3.3",[],{"id":210,"title":211,"subtitle":212,"description":96,"questions":213},80,"Troubleshoot network security","Task 3.4",[214],{"id":215,"subcategoryId":210,"content":216,"hint":217,"isPublic":9,"answers":218},13227,"A company has deployed its critical application across multiple EC2 instances within a VPC. Recently, there have been reports of atypical network behavior and potential security issues affecting the application's performance. As a security specialist tasked with investigating this issue, you decide to use AWS services to capture and analyze the traffic to and from the affected EC2 instances without impacting their performance or network throughput. Which AWS feature would you use to accomplish this task?","Remember that the goal is to analyze network traffic for the instances without affecting their performance.",[219,223,227,231],{"id":220,"questionId":215,"content":221,"hint":222,"isCorrect":9},52907,"Enable VPC Traffic Mirroring on the affected EC2 instances to capture and analyze their network traffic.","VPC Traffic Mirroring allows for the capture of network traffic from EC2 instances and then sends the traffic to a security appliance or monitoring instance for analysis. It is non-intrusive, as it doesn't affect the performance of the instances whose traffic is being mirrored.",{"id":224,"questionId":215,"content":225,"hint":226,"isCorrect":117},52908,"Use AWS Shield Advanced to monitor and protect the network traffic to the EC2 instances.","AWS Shield Advanced provides protection against DDoS attacks but does not offer traffic capturing for analysis of network behavior and security issues.",{"id":228,"questionId":215,"content":229,"hint":230,"isCorrect":117},52909,"Implement an additional Elastic Load Balancer (ELB) to log and analyze the traffic going to the EC2 instances.","While ELB can log traffic, it is primarily for load balancing and does not provide in-depth traffic capturing and analysis features like traffic mirroring, and could also introduce latency.",{"id":232,"questionId":215,"content":233,"hint":234,"isCorrect":117},52910,"Deploy AWS WAF in front of the EC2 instances to inspect and capture incoming traffic.","AWS WAF is a web application firewall that helps protect web applications from common web exploits but does not provide traffic capturing for thorough network traffic analysis.",{"id":192,"title":236,"subtitle":237,"description":238,"content":96,"coverImageUrl":14,"weight":239,"subcategories":240},"Identity and Access Management","Domain 4","Identity and Access Management domain focuses on managing access to AWS resources. It involves implementing and maintaining AWS IAM policies, roles, and permissions to ensure secure access control, user authentication, and compliance with best practices.",16,[241,246],{"id":242,"title":243,"subtitle":244,"description":96,"questions":245},81,"Design, implement, and troubleshoot authentication for AWS resources","Task 4.1",[],{"id":247,"title":248,"subtitle":249,"description":96,"questions":250},85,"Design, implement, and troubleshoot authorization for AWS Resources","Task 4.2",[251],{"id":252,"subcategoryId":247,"content":253,"hint":254,"isPublic":9,"answers":255},13472,"A developer at a company attempted to deploy an application on AWS using an IAM user account. The application needed to write logs to an Amazon S3 bucket; however, the deployment failed with an 'Access Denied' error when trying to write to the bucket. After reviewing the IAM policy attached to the user, the developer discovered that the policy provided the necessary 's3:PutObject' permission for the bucket. Upon further investigation, the developer found no explicit deny in the IAM policy that could have caused the error. Which of the following could be the MOST likely reason for the observed 'Access Denied' error?","Consider all the levels at which permissions in AWS are evaluated, including AWS service-specific policies and resource-based policies.",[256,260,264,268],{"id":257,"questionId":252,"content":258,"hint":259,"isCorrect":9},53888,"The S3 bucket had a bucket policy that explicitly denied write access to the IAM user.","Even though the IAM user had the correct IAM policy with the 's3:PutObject' permission, S3 bucket policies can override these permissions. If the bucket policy explicitly denies access to the IAM user or the user's group, the user would not be able to write to the bucket despite having the required permissions in their IAM policy.",{"id":261,"questionId":252,"content":262,"hint":263,"isCorrect":117},53889,"The IAM user did not have the 's3:ListBucket' permission for the S3 bucket.","Lack of the 's3:ListBucket' permission would prevent the user from listing the contents of the bucket, but it would not prevent the user from writing to the bucket if 's3:PutObject' permission is correctly set.",{"id":265,"questionId":252,"content":266,"hint":267,"isCorrect":117},53890,"The S3 bucket was located in a different AWS region than the IAM user's default region.","S3 buckets are global resources, and the region of the IAM user's default region does not directly affect permissions to access the S3 bucket. The 'Access Denied' error is related to permissions, not the location of resources.",{"id":269,"questionId":252,"content":270,"hint":271,"isCorrect":117},53891,"The 's3:PutObject' permission was mistyped as 'S3:putobject' in the IAM policy.","While capitalization errors in the IAM policy statement can cause issues, the error message would not be 'Access Denied' in this case. Instead, the policy would simply not grant any permissions due to the incorrect action name.",{"id":273,"title":274,"subtitle":275,"description":276,"content":96,"coverImageUrl":14,"weight":137,"subcategories":277},21,"Data Protection","Domain 5","Data Protection domain focuses on safeguarding data within AWS. It includes encryption, key management, data masking, and secure storage solutions to protect data at rest and in transit, ensuring privacy and compliance with regulations.",[278,283,309,314],{"id":279,"title":280,"subtitle":281,"description":96,"questions":282},86,"Design and implement controls that provide confidentiality and integrity for data in transit","Task 5.1",[],{"id":284,"title":285,"subtitle":286,"description":96,"questions":287},87,"Design and implement controls that provide confidentiality and integrity for data at rest","Task 5.2",[288],{"id":289,"subcategoryId":284,"content":290,"hint":291,"isPublic":9,"answers":292},13852,"A financial services company is migrating its relational database workloads to AWS and has chosen Amazon Aurora as their database service because of its high performance and availability. The company's chief information security officer (CISO) has emphasized the importance of securing sensitive customer data at rest to comply with stringent financial industry regulations. The CISO is considering various encryption options to ensure data confidentiality and integrity. Which encryption technique should be used to meet the company's business requirements for encrypting data at rest in Amazon Aurora?","Consider the encryption options provided by Amazon Aurora that are capable of securing data at rest and meet the regulatory compliance requirements for the financial industry.",[293,297,301,305],{"id":294,"questionId":289,"content":295,"hint":296,"isCorrect":9},55409,"Encrypt the Amazon Aurora database using AWS Key Management Service (AWS KMS) customer managed keys.","This is the correct answer because Amazon Aurora integrates with AWS KMS, allowing you to create and control the encryption keys. Using AWS KMS customer managed keys provides a robust encryption and key management solution that helps meet compliance requirements for data protection by offering an additional layer of control and security.",{"id":298,"questionId":289,"content":299,"hint":300,"isCorrect":117},55410,"Encrypt the Amazon Aurora database using SSL\u002FTLS for data in transit.","This answer is incorrect because the question asks about encryption for data at rest, not data in transit. SSL\u002FTLS is used to encrypt data as it travels between the database and the client applications, not while the data is stored.",{"id":302,"questionId":289,"content":303,"hint":304,"isCorrect":117},55411,"Use Amazon Aurora's built-in Transparent Data Encryption with a default master key.","This answer is incorrect because while Amazon Aurora supports Transparent Data Encryption (TDE), the question specifies the need for complying with stringent regulations, which usually requires the use of customer managed keys rather than default master keys.",{"id":306,"questionId":289,"content":307,"hint":308,"isCorrect":117},55412,"Implement database encryption using a tokenization service.","This answer is incorrect because Amazon Aurora does not natively support tokenization as a method for encrypting data at rest. Tokenization is more commonly used for specific use cases like protecting credit card data within a set of controlled environments.",{"id":310,"title":311,"subtitle":312,"description":96,"questions":313},88,"Design and implement controls to manage the lifecycle of data at rest","Task 5.3",[],{"id":315,"title":316,"subtitle":317,"description":96,"questions":318},89,"Design and implement controls to protect credentials, secrets, and cryptographic key materials","Task 5.4",[],{"id":320,"title":321,"subtitle":322,"description":323,"content":96,"coverImageUrl":14,"weight":97,"subcategories":324},22,"Management and Security Governance","Domain 6","Management and Security Governance domain emphasizes establishing and maintaining security policies and procedures. It involves ensuring compliance, risk management, and implementing governance frameworks.",[325,330,356,361],{"id":326,"title":327,"subtitle":328,"description":96,"questions":329},90,"Develop a strategy to centrally deploy and manage AWS accounts","Task 6.1",[],{"id":331,"title":332,"subtitle":333,"description":96,"questions":334},91,"Implement a secure and consistent deployment strategy for cloud resources","Task 6.2",[335],{"id":336,"subcategoryId":331,"content":337,"hint":338,"isPublic":9,"answers":339},14220,"Your company is utilizing AWS for their critical web application and relies heavily on the AWS network infrastructure for protection against DDoS attacks. You, as a security specialist, have been tasked to ensure that all the AWS accounts under organizational units (OUs) comply with the company's strict security policies, which include DDoS protection for all resources. You need to deploy a solution that automates the application of DDoS protection policies and integrates with AWS Shield Advanced for additional protection. Which AWS service should you implement to meet this requirement while adhering to the security governance domain and ensuring a secure and consistent deployment strategy for cloud resources?","Consider a service that enables you to centrally configure and manage firewall rules across your accounts and applications in AWS, and think about how it can integrate with AWS Shield for DDoS protection.",[340,344,348,352],{"id":341,"questionId":336,"content":342,"hint":343,"isCorrect":9},56882,"Deploy AWS Firewall Manager with AWS Shield Advanced integration to automatically apply the necessary DDoS protection policies to the accounts in the OUs.","AWS Firewall Manager simplifies your AWS WAF, AWS Shield Advanced, and Amazon VPC security groups administration and maintenance tasks across multiple accounts and resources. With Firewall Manager, you can deploy and manage security policies to protect against DDoS attacks, which integrates with AWS Shield Advanced for enhanced protection.",{"id":345,"questionId":336,"content":346,"hint":347,"isCorrect":117},56883,"Set up Amazon Inspector to automatically assess applications for exposure to DDoS attacks and enforce the necessary protection policies.","Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS, but it does not enforce DDoS protection policies or specifically integrate with AWS Shield Advanced.",{"id":349,"questionId":336,"content":350,"hint":351,"isCorrect":117},56884,"Use AWS Config rules to assess, audit, and evaluate the configurations of your AWS resources for compliance with DDoS protection policies.","While AWS Config is useful for assessing and auditing resource configurations for compliance, it does not enforce DDoS protection policies or integrate with AWS Shield Advanced for enhanced DDoS protection.",{"id":353,"questionId":336,"content":354,"hint":355,"isCorrect":117},56885,"Implement AWS Direct Connect to link your internal network to AWS and manage DDoS protection policies.","AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS, but it does not provide centralized management of DDoS protection policies or integration with AWS Shield Advanced.",{"id":357,"title":358,"subtitle":359,"description":96,"questions":360},92,"Evaluate the compliance of AWS resource","Task 6.3",[],{"id":362,"title":363,"subtitle":364,"description":96,"questions":365},93,"Identify security gaps through architectural reviews and cost analysis","Task 6.4",[],[367,372,378,384,390,396,402,408,414,420,426,432,438,444,450,456,462,468,474,480,486,492,498,504,510,516],{"id":362,"title":368,"description":369,"slug":370,"coverImageUrl":371},"AWS CloudTrail","AWS CloudTrail is a service that provides a comprehensive log of user activity and API usage across the AWS infrastructure, enabling security monitoring, compliance auditing, and operational troubleshooting.","aws-cloudtrail","\u002Fimages\u002Fprovider-services\u002Faws-cloudtrail\u002Fcovers\u002FArch_AWS-CloudTrail_64.png",{"id":373,"title":374,"description":375,"slug":376,"coverImageUrl":377},95,"Amazon CloudWatch","Amazon CloudWatch is a monitoring and observability service offered by Amazon Web Services (AWS) that provides data and actionable insights to monitor applications, respond to system-wide performance changes, optimize resource utilization, and get a unified view of operational health.","amazon-cloudwatch","\u002Fimages\u002Fprovider-services\u002Famazon-cloudwatch\u002Fcovers\u002FArch_Amazon-CloudWatch_64.png",{"id":379,"title":380,"description":381,"slug":382,"coverImageUrl":383},96,"AWS Command Line Interface (AWS CLI)","The AWS Command Line Interface (AWS CLI) is a unified tool that allows you to manage and automate AWS services directly from the terminal or command prompt.","aws-command-line-interface-(aws-cli)","\u002Fimages\u002Fprovider-services\u002Faws-command-line-interface-(aws-cli)\u002Fcovers\u002FArch_AWS-Command-Line-Interface_64.png",{"id":385,"title":386,"description":387,"slug":388,"coverImageUrl":389},98,"AWS Config","AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources, providing a detailed view of their compliance with the configurations specified by your internal guidelines and regulatory standards.","aws-config","\u002Fimages\u002Fprovider-services\u002Faws-config\u002Fcovers\u002FArch_AWS-Config_64.png",{"id":391,"title":392,"description":393,"slug":394,"coverImageUrl":395},107,"AWS Management Console","The AWS Management Console is a web-based interface that allows users to access and manage Amazon Web Services (AWS) and its resources, offering an intuitive and easy-to-navigate user experience for configuring AWS services, monitoring their performance, and managing billing and security.","aws-management-console","\u002Fimages\u002Fprovider-services\u002Faws-management-console\u002Fcovers\u002FArch_AWS-Management-Console_64.png",{"id":397,"title":398,"description":399,"slug":400,"coverImageUrl":401},108,"AWS Organizations","AWS Organizations is a cloud service from Amazon Web Services that allows you to centrally manage and govern your environment as you scale your AWS resources across multiple accounts.","aws-organizations","\u002Fimages\u002Fprovider-services\u002Faws-organizations\u002Fcovers\u002FArch_AWS-Organizations_64.png",{"id":403,"title":404,"description":405,"slug":406,"coverImageUrl":407},112,"AWS Systems Manager","AWS Systems Manager is a management service that provides visibility and control over your AWS resources, enabling you to automate operational tasks, gather system inventory, apply OS patches, automate the creation of Amazon Machine Images, and configure your operating systems and applications.","aws-systems-manager","\u002Fimages\u002Fprovider-services\u002Faws-systems-manager\u002Fcovers\u002FArch_AWS-Systems-Manager_64.png",{"id":409,"title":410,"description":411,"slug":412,"coverImageUrl":413},113,"AWS Trusted Advisor","AWS Trusted Advisor is an online tool that provides real-time guidance to help users optimize their Amazon Web Services (AWS) infrastructure for cost, performance, security, and fault tolerance by scanning their environment and offering recommendations based on best practices.","aws-trusted-advisor","\u002Fimages\u002Fprovider-services\u002Faws-trusted-advisor\u002Fcovers\u002FArch_AWS-Trusted-Advisor_64.png",{"id":415,"title":416,"description":417,"slug":418,"coverImageUrl":419},136,"Amazon VPC","Amazon VPC (Virtual Private Cloud) is a service that allows users to launch AWS resources in a logically isolated virtual network that they can define and control, including IP address ranges, subnets, route tables, and gateways.","amazon-vpc","\u002Fimages\u002Fprovider-services\u002Famazon-vpc\u002Fcovers\u002FVirtual-private-cloud-VPC_32.png",{"id":421,"title":422,"description":423,"slug":424,"coverImageUrl":425},138,"AWS Audit Manager","AWS Audit Manager is a cloud service provided by Amazon Web Services that helps users automate the process of auditing and compliance by continuously collecting evidence, thus enabling them to assess their AWS environment against industry standards and regulations.","aws-audit-manager","\u002Fimages\u002Fprovider-services\u002Faws-audit-manager\u002Fcovers\u002FArch_AWS-Audit-Manager_64.png",{"id":427,"title":428,"description":429,"slug":430,"coverImageUrl":431},141,"AWS Certificate Manager (ACM)","AWS Certificate Manager (ACM) is a service provided by Amazon Web Services that simplifies the creation, management, and deployment of SSL\u002FTLS certificates for use with AWS services and your internal connected resources.","aws-certificate-manager-(acm)","\u002Fimages\u002Fprovider-services\u002Faws-certificate-manager-(acm)\u002Fcovers\u002FArch_AWS-Certificate-Manager_64.png",{"id":433,"title":434,"description":435,"slug":436,"coverImageUrl":437},142,"AWS CloudHSM","AWS CloudHSM is a cloud-based hardware security module service offered by Amazon Web Services that provides key storage and cryptographic operations within a tamper-resistant hardware appliance.","aws-cloudhsm","\u002Fimages\u002Fprovider-services\u002Faws-cloudhsm\u002Fcovers\u002FArch_AWS-CloudHSM_64.png",{"id":439,"title":440,"description":441,"slug":442,"coverImageUrl":443},144,"Amazon Detective","Amazon Detective is a security service that automatically collects, organizes, and analyzes data from AWS resources to help users easily investigate and quickly identify the root cause of potential security issues or suspicious activities.","amazon-detective","\u002Fimages\u002Fprovider-services\u002Famazon-detective\u002Fcovers\u002FArch_Amazon-Detective_64.png",{"id":445,"title":446,"description":447,"slug":448,"coverImageUrl":449},145,"AWS Directory Service","AWS Directory Service is a managed service provided by Amazon Web Services that allows users to connect AWS resources with an existing on-premises Microsoft Active Directory or to set up and operate a new, fully managed directory in the AWS Cloud.","aws-directory-service","\u002Fimages\u002Fprovider-services\u002Faws-directory-service\u002Fcovers\u002FArch_AWS-Directory-Service_64.png",{"id":451,"title":452,"description":453,"slug":454,"coverImageUrl":455},146,"AWS Firewall Manager","AWS Firewall Manager is a security management service that allows you to centrally configure and manage firewall rules across your Amazon Web Services (AWS) accounts and applications, simplifying your AWS network firewall administration.","aws-firewall-manager","\u002Fimages\u002Fprovider-services\u002Faws-firewall-manager\u002Fcovers\u002FArch_AWS-Firewall-Manager_64.png",{"id":457,"title":458,"description":459,"slug":460,"coverImageUrl":461},147,"Amazon GuardDuty","Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.","amazon-guardduty","\u002Fimages\u002Fprovider-services\u002Famazon-guardduty\u002Fcovers\u002FArch_Amazon-GuardDuty_64.png",{"id":463,"title":464,"description":465,"slug":466,"coverImageUrl":467},148,"AWS IAM Identity Center (AWS Single Sign-On)","AWS IAM Identity Center (formerly AWS Single Sign-On) is a cloud service that enables secure and unified authentication for users to access AWS accounts and business applications with a single set of credentials.","aws-iam-identity-center-(aws-single-sign-on)","\u002Fimages\u002Fprovider-services\u002Faws-iam-identity-center-(aws-single-sign-on)\u002Fcovers\u002FArch_AWS-IAM-Identity-Center_64.png",{"id":469,"title":470,"description":471,"slug":472,"coverImageUrl":473},149,"AWS Identity and Access Management (IAM)","AWS Identity and Access Management (IAM) is a cloud service that helps securely control access to AWS resources by allowing you to create and manage AWS users and groups, and use permissions to allow and deny their access to AWS resources.","aws-identity-and-access-management-(iam)","\u002Fimages\u002Fprovider-services\u002Faws-identity-and-access-management-(iam)\u002Fcovers\u002FArch_AWS-Identity-and-Access-Management_64.png",{"id":475,"title":476,"description":477,"slug":478,"coverImageUrl":479},150,"Amazon Inspector","Amazon Inspector is a security assessment service offered by Amazon Web Services (AWS) that automatically assesses applications for vulnerabilities or deviations from best practices, and produces a detailed list of security findings prioritized by level of severity.","amazon-inspector","\u002Fimages\u002Fprovider-services\u002Famazon-inspector\u002Fcovers\u002FArch_Amazon-Inspector_64.png",{"id":481,"title":482,"description":483,"slug":484,"coverImageUrl":485},151,"AWS Key Management Service (AWS KMS)","AWS Key Management Service (AWS KMS) is a managed service that makes it easy for you to create and control the cryptographic keys used to secure your data across AWS services and in your applications.","aws-key-management-service-(aws-kms)","\u002Fimages\u002Fprovider-services\u002Faws-key-management-service-(aws-kms)\u002Fcovers\u002FArch_AWS-Key-Management-Service_64.png",{"id":487,"title":488,"description":489,"slug":490,"coverImageUrl":491},152,"Amazon Macie","Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS.","amazon-macie","\u002Fimages\u002Fprovider-services\u002Famazon-macie\u002Fcovers\u002FArch_Amazon-Macie_64.png",{"id":493,"title":494,"description":495,"slug":496,"coverImageUrl":497},153,"AWS Network Firewall","AWS Network Firewall is a managed service provided by Amazon Web Services that enables users to deploy essential network protections such as stateful firewall rules, intrusion detection and prevention, and web filtering within their Virtual Private Cloud (VPC) environments.","aws-network-firewall","\u002Fimages\u002Fprovider-services\u002Faws-network-firewall\u002Fcovers\u002FArch_AWS-Firewall-Manager_64.png",{"id":499,"title":500,"description":501,"slug":502,"coverImageUrl":503},156,"AWS Security Hub","AWS Security Hub is a cloud security management service that aggregates, organizes, and prioritizes security alerts or findings from multiple AWS services and AWS Partner Network (APN) security solutions, providing a comprehensive view of security and compliance across an AWS environment.","aws-security-hub","\u002Fimages\u002Fprovider-services\u002Faws-security-hub\u002Fcovers\u002FArch_AWS-Security-Hub_64.png",{"id":505,"title":506,"description":507,"slug":508,"coverImageUrl":509},157,"AWS Shield","AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS against DDoS attacks.","aws-shield","\u002Fimages\u002Fprovider-services\u002Faws-shield\u002Fcovers\u002FArch_AWS-Shield_64.png",{"id":511,"title":512,"description":513,"slug":514,"coverImageUrl":515},158,"AWS WAF","AWS WAF (Web Application Firewall) is a web application firewall service that helps protect web applications and APIs from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.","aws-waf","\u002Fimages\u002Fprovider-services\u002Faws-waf\u002Fcovers\u002FArch_AWS-WAF_64.png",{"id":517,"title":518,"description":519,"slug":520,"coverImageUrl":521},196,"AWS Tools and SDKs","AWS Tools and SDKs are a collection of software and tools provided by Amazon Web Services to facilitate the development, deployment, and management of applications and services on the AWS platform.","aws-tools-and-sdks","\u002Fimages\u002Fprovider-services\u002Faws-tools-and-sdks\u002Fcovers\u002FArch_AWS-Tools-and-SDKs_64.png",[],1790430989764]