Editing AWS Certified Security - Specialty: 9 Sample questions
Jump to navigation
Jump to search
Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | https://d1.awsstatic.com/training-and-certification/docs-security-spec/AWS-Certified-Security-Speciality_Sample-Questions.pdf | ||
− | 1) A corporate cloud security policy states that | + | 1) A corporate cloud security policy states that communication between the company's [[VPC]] and [[KMS]] must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Select TWO.) |
:A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | :A) Add the <code>aws:sourceVpce</code> condition to the AWS KMS key policy referencing the company's [[VPC endpoint]] ID. | ||
:B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | :B) Remove the [[VPC internet gateway]] from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. | ||
:C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | :C) Create a [[VPC endpoint]] for [[AWS KMS]] with private DNS enabled. | ||
:D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | :D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | ||
− | :E) Add the following condition to the AWS KMS key policy: <code>" | + | :E) Add the following condition to the AWS KMS key policy: <code>"aws:SourceIp": "10.0.0.0/16"</code> |
Line 33: | Line 33: | ||
− | 4) A security engineer is working with a product team building a web application on AWS. The application uses Amazon S3 to host the static content, | + | 4) A security engineer is working with a product team building a web application on AWS. The application uses Amazon S3 to host the static content, Amazon API Gateway to provide RESTful services, and Amazon DynamoDB as the backend data store. The users already exist in a directory that is exposed through a SAML identity provider. Which combination of the following actions should the engineer take to enable users to be authenticated into the web application and call APIs? (Select THREE). |
:A) Create a custom authorization service using AWS Lambda. | :A) Create a custom authorization service using AWS Lambda. | ||
− | :B) Configure a | + | :B) Configure a SAML identity provider in Amazon Cognito to map attributes to the Amazon Cognito user pool attributes. |
:C) Configure the SAML identity provider to add the Amazon Cognito user pool as a relying party. | :C) Configure the SAML identity provider to add the Amazon Cognito user pool as a relying party. | ||
:D) Configure an Amazon Cognito identity pool to integrate with social login providers. | :D) Configure an Amazon Cognito identity pool to integrate with social login providers. | ||
:E) Update DynamoDB to store the user email addresses and passwords. | :E) Update DynamoDB to store the user email addresses and passwords. | ||
− | :F) Update | + | :F) Update API Gateway to use an Amazon Cognito user pool authorizer. |
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
== See also == | == See also == |
Advertising: