A web application behind an Application Load Balancer is vulnerable to SQL injection attacks. Which AWS service combination best mitigates this threat?
#2Design Secure Architectures
A security team must enforce multi-factor authentication for all IAM users accessing the AWS Management Console. Which approach achieves this?
#3Design Secure Architectures
Company A needs to give Company B's application temporary read access to an S3 bucket in Company A's AWS account. Which method is most secure?
#4Design Secure Architectures
A healthcare company stores patient records in S3 and must ensure encryption at rest with a full audit trail of key usage. Which encryption option meets these requirements?
#5Design Secure Architectures
A company must encrypt its RDS MySQL database at rest using keys it controls and rotates annually. Which approach meets this requirement?
#6Design Secure Architectures
A development team hardcodes database credentials in application source code. Which AWS service should they use to store and automatically rotate these credentials?
#7Design Secure Architectures
A financial company must log all API calls across all AWS regions for compliance auditing. Which service should be configured?
#8Design Secure Architectures
A company accidentally enabled public access on an S3 bucket containing internal reports. What is the fastest way to block all public access to this bucket?
#9Design Secure Architectures
An architect must control traffic to EC2 instances in a VPC. Inbound HTTP must be allowed; all other inbound traffic must be denied. Which configuration is correct?
#10Design Secure Architectures
A three-tier application runs entirely in private subnets. The application tier must download patches from the internet but must not be directly reachable from the internet. Which architecture satisfies this?
#11Design Secure Architectures
A global e-commerce company needs protection against large-scale DDoS attacks on its ALB endpoints with 24/7 access to the AWS DDoS Response Team. Which solution is needed?
#12Design Secure Architectures
A company wants to serve its web application over HTTPS using an Application Load Balancer. How should they manage the SSL/TLS certificate?
#13Design Secure Architectures
A company stores sensitive documents in Amazon S3. Only specific IAM users should have read access to one bucket. Which approach provides least-privilege access?
#14Design Secure Architectures
An application in a private subnet must access S3 without traversing the public internet or using a NAT gateway. Which solution meets this requirement?
#15Design Secure Architectures
A company wants continuous threat detection for its AWS environment that monitors VPC flow logs, DNS logs, and CloudTrail events. Which service provides this capability?
Want to track your score, take timed mock exams and get AI explanations? Create a free account