Latihan AWS Security Specialty

Latih 60 soalan AWS Security Specialty asli merangkumi pengesanan, log, keselamatan infrastruktur, IAM, perlindungan data dan tadbir urus.

Tahap: AWS Certified Security - Specialty (SCS-C02) Kesukaran: advanced 60 soalan 60 min
Pilih mod latihan, jawab setiap soalan, kemudian semak penerangan. Jawapan salah disimpan setempat.
Hari berturut-turut: 0 hari Disimpan hanya pada peranti ini
Kemajuan 0 / 60
Soalan 1

Which AWS service continuously monitors accounts and workloads for threats and generates security findings?

Pilih jawapan
Soalan 2

Which data sources does Amazon GuardDuty analyze?

Pilih jawapan
Soalan 3

Which AWS service provides a central place to aggregate security findings from multiple accounts?

Pilih jawapan
Soalan 4

Which AWS service provides managed incident response and remediation workflows?

Pilih jawapan
Soalan 5

Which AWS service protects applications from distributed denial-of-service attacks?

Pilih jawapan
Soalan 6

Which AWS service provides a managed web application firewall?

Pilih jawapan
Soalan 7

Which AWS service scans EC2 instances and container images for software vulnerabilities?

Pilih jawapan
Soalan 8

What is the first priority during an AWS security incident?

Pilih jawapan
Soalan 9

Which AWS service can detect cryptocurrency mining activity on EC2 instances?

Pilih jawapan
Soalan 10

Match each AWS security service to its main purpose.

Soalan 11

Which AWS service records API calls in an AWS account for auditing?

Pilih jawapan
Soalan 12

Which AWS feature captures metadata about network traffic in a VPC?

Pilih jawapan
Soalan 13

Which service stores and monitors application and system logs?

Pilih jawapan
Soalan 14

Which CloudTrail feature can help detect whether log files were modified?

Pilih jawapan
Soalan 15

Which agent should you install on EC2 instances to send operating system logs to CloudWatch?

Pilih jawapan
Soalan 16

Which CloudWatch Logs feature extracts numeric values from log events to create metrics?

Pilih jawapan
Soalan 17

Which feature lets you query and analyze logs stored in CloudWatch Logs?

Pilih jawapan
Soalan 18

Which AWS approach centralizes CloudTrail logs from all accounts in an organization?

Pilih jawapan
Soalan 19

Which CloudWatch feature sends a notification when a security metric crosses a threshold?

Pilih jawapan
Soalan 20

Match each AWS logging feature to its purpose.

Soalan 21

Which VPC component filters traffic at the instance level?

Pilih jawapan
Soalan 22

Which VPC component filters traffic at the subnet level?

Pilih jawapan
Soalan 23

Which AWS service provides private connectivity from a VPC to supported services without traversing the internet?

Pilih jawapan
Soalan 24

Which AWS service connects many VPCs and on-premises networks through a central hub?

Pilih jawapan
Soalan 25

Which AWS service provides a managed network firewall for a VPC?

Pilih jawapan
Soalan 26

Which AWS service lets you manage EC2 instances without opening SSH ports or using public IP addresses?

Pilih jawapan
Soalan 27

What is a bastion host used for?

Pilih jawapan
Soalan 28

Which AWS service lets you apply service control policies across an organization?

Pilih jawapan
Soalan 29

Which AWS service provides secure encrypted tunnels between on-premises networks and AWS?

Pilih jawapan
Soalan 30

Match each VPC security component to its purpose.

Soalan 31

What is an IAM role?

Pilih jawapan
Soalan 32

What is an IAM policy?

Pilih jawapan
Soalan 33

Which AWS service issues temporary security credentials?

Pilih jawapan
Soalan 34

What does an IAM trust policy define?

Pilih jawapan
Soalan 35

What does least privilege mean?

Pilih jawapan
Soalan 36

Which AWS service provides workforce identity federation across AWS accounts and applications?

Pilih jawapan
Soalan 37

What is an IAM permission boundary?

Pilih jawapan
Soalan 38

Which IAM condition key can require multifactor authentication?

Pilih jawapan
Soalan 39

Which IAM best practice applies to the AWS root user?

Pilih jawapan
Soalan 40

Match each IAM concept to its purpose.

Soalan 41

Which AWS service creates and manages encryption keys?

Pilih jawapan
Soalan 42

Which AWS service securely stores and automatically rotates database credentials and secrets?

Pilih jawapan
Soalan 43

Which AWS service manages SSL/TLS certificates for AWS services?

Pilih jawapan
Soalan 44

What is envelope encryption?

Pilih jawapan
Soalan 45

Which S3 encryption option uses an AWS-managed key automatically?

Pilih jawapan
Soalan 46

Which mechanism protects data in transit to AWS?

Pilih jawapan
Soalan 47

Which AWS service provides dedicated single-tenant hardware security modules?

Pilih jawapan
Soalan 48

Which S3 feature prevents objects from being deleted or overwritten for a fixed period?

Pilih jawapan
Soalan 49

Which AWS service centralizes encryption keys and integrates with many AWS services?

Pilih jawapan
Soalan 50

Match each data protection service to its purpose.

Soalan 51

Which AWS service provides compliance reports, certifications, and agreements?

Pilih jawapan
Soalan 52

Which AWS service tracks resource configurations and evaluates them against rules?

Pilih jawapan
Soalan 53

Which AWS service helps you centrally manage accounts, budgets, and service control policies?

Pilih jawapan
Soalan 54

What is a service control policy?

Pilih jawapan
Soalan 55

Which AWS Config feature bundles multiple rules for compliance frameworks?

Pilih jawapan
Soalan 56

Which AWS service provides recommendations for security, cost, performance, and reliability?

Pilih jawapan
Soalan 57

Which AWS service can automatically remediate noncompliant resources?

Pilih jawapan
Soalan 58

Which AWS service provides a single dashboard for security posture and compliance?

Pilih jawapan
Soalan 59

Which AWS Organizations feature restricts the AWS services an account can use?

Pilih jawapan
Soalan 60

Match each governance service to its purpose.