Editing AWS Certified Security - Specialty: 9 Sample questions
Jump to navigation
Jump to search
Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | ||
− | 1) A corporate cloud security policy states that | + | 1) A corporate cloud security policy states that communication between the company's [[VPC]] and [[KMS]] must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Select TWO.) |
:A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | :A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | ||
:B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | :B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | ||
:C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | :C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | ||
:D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | :D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | ||
− | :E) Add the following condition to the AWS KMS key policy: <code>" | + | :E) Add the following condition to the AWS KMS key policy: <code>"aws:SourceIp": "10.0.0.0/16"</code> |
Line 43: | Line 43: | ||
5) TODO | 5) TODO | ||
− | 6) A company decides to place database hosts in its own VPC, and to set up | + | 6) A company decides to place database hosts in its own VPC, and to set up VPC peering to different VPCs containing the application and web tiers. The application servers are unable to connect to the database. |
Which network troubleshooting steps should be taken to resolve the issue? (Select TWO.) | Which network troubleshooting steps should be taken to resolve the issue? (Select TWO.) | ||
:A) Check to see if the application servers are in a private subnet or public subnet. | :A) Check to see if the application servers are in a private subnet or public subnet. | ||
:B) Check the route tables for the application server subnets for routes to the VPC peering connection. | :B) Check the route tables for the application server subnets for routes to the VPC peering connection. | ||
− | :C) Check the | + | :C) Check the NACLs for the database subnets for rules that allow traffic from the internet. |
:D) Check the database security groups for rules that allow traffic from the application servers. | :D) Check the database security groups for rules that allow traffic from the application servers. | ||
:E) Check to see if the database VPC has an internet gateway | :E) Check to see if the database VPC has an internet gateway | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
== See also == | == See also == |
Advertising: