ฝึก AWS Security Specialty

ฝึกข้อสอบ AWS Security Specialty ต้นฉบับ 60 ข้อครอบคลุมการตรวจจับ Logging ความปลอดภัยโครงสร้างพื้นฐาน IAM การปกป้องข้อมูล และการกำกับดูแล

ระดับ: AWS Certified Security - Specialty (SCS-C02) ความยาก: advanced 60 ข้อ 60 นาที
เลือกโหมดฝึก ตอบแต่ละข้อ แล้วทบทวนคำอธิบาย ข้อที่ผิดจะถูกบันทึกไว้ในเครื่อง
จำนวนวันต่อเนื่อง: 0 วัน บันทึกเฉพาะอุปกรณ์นี้
ความคืบหน้า 0 / 60
ข้อ 1

Which AWS service continuously monitors accounts and workloads for threats and generates security findings?

เลือกคำตอบ
ข้อ 2

Which data sources does Amazon GuardDuty analyze?

เลือกคำตอบ
ข้อ 3

Which AWS service provides a central place to aggregate security findings from multiple accounts?

เลือกคำตอบ
ข้อ 4

Which AWS service provides managed incident response and remediation workflows?

เลือกคำตอบ
ข้อ 5

Which AWS service protects applications from distributed denial-of-service attacks?

เลือกคำตอบ
ข้อ 6

Which AWS service provides a managed web application firewall?

เลือกคำตอบ
ข้อ 7

Which AWS service scans EC2 instances and container images for software vulnerabilities?

เลือกคำตอบ
ข้อ 8

What is the first priority during an AWS security incident?

เลือกคำตอบ
ข้อ 9

Which AWS service can detect cryptocurrency mining activity on EC2 instances?

เลือกคำตอบ
ข้อ 10

Match each AWS security service to its main purpose.

ข้อ 11

Which AWS service records API calls in an AWS account for auditing?

เลือกคำตอบ
ข้อ 12

Which AWS feature captures metadata about network traffic in a VPC?

เลือกคำตอบ
ข้อ 13

Which service stores and monitors application and system logs?

เลือกคำตอบ
ข้อ 14

Which CloudTrail feature can help detect whether log files were modified?

เลือกคำตอบ
ข้อ 15

Which agent should you install on EC2 instances to send operating system logs to CloudWatch?

เลือกคำตอบ
ข้อ 16

Which CloudWatch Logs feature extracts numeric values from log events to create metrics?

เลือกคำตอบ
ข้อ 17

Which feature lets you query and analyze logs stored in CloudWatch Logs?

เลือกคำตอบ
ข้อ 18

Which AWS approach centralizes CloudTrail logs from all accounts in an organization?

เลือกคำตอบ
ข้อ 19

Which CloudWatch feature sends a notification when a security metric crosses a threshold?

เลือกคำตอบ
ข้อ 20

Match each AWS logging feature to its purpose.

ข้อ 21

Which VPC component filters traffic at the instance level?

เลือกคำตอบ
ข้อ 22

Which VPC component filters traffic at the subnet level?

เลือกคำตอบ
ข้อ 23

Which AWS service provides private connectivity from a VPC to supported services without traversing the internet?

เลือกคำตอบ
ข้อ 24

Which AWS service connects many VPCs and on-premises networks through a central hub?

เลือกคำตอบ
ข้อ 25

Which AWS service provides a managed network firewall for a VPC?

เลือกคำตอบ
ข้อ 26

Which AWS service lets you manage EC2 instances without opening SSH ports or using public IP addresses?

เลือกคำตอบ
ข้อ 27

What is a bastion host used for?

เลือกคำตอบ
ข้อ 28

Which AWS service lets you apply service control policies across an organization?

เลือกคำตอบ
ข้อ 29

Which AWS service provides secure encrypted tunnels between on-premises networks and AWS?

เลือกคำตอบ
ข้อ 30

Match each VPC security component to its purpose.

ข้อ 31

What is an IAM role?

เลือกคำตอบ
ข้อ 32

What is an IAM policy?

เลือกคำตอบ
ข้อ 33

Which AWS service issues temporary security credentials?

เลือกคำตอบ
ข้อ 34

What does an IAM trust policy define?

เลือกคำตอบ
ข้อ 35

What does least privilege mean?

เลือกคำตอบ
ข้อ 36

Which AWS service provides workforce identity federation across AWS accounts and applications?

เลือกคำตอบ
ข้อ 37

What is an IAM permission boundary?

เลือกคำตอบ
ข้อ 38

Which IAM condition key can require multifactor authentication?

เลือกคำตอบ
ข้อ 39

Which IAM best practice applies to the AWS root user?

เลือกคำตอบ
ข้อ 40

Match each IAM concept to its purpose.

ข้อ 41

Which AWS service creates and manages encryption keys?

เลือกคำตอบ
ข้อ 42

Which AWS service securely stores and automatically rotates database credentials and secrets?

เลือกคำตอบ
ข้อ 43

Which AWS service manages SSL/TLS certificates for AWS services?

เลือกคำตอบ
ข้อ 44

What is envelope encryption?

เลือกคำตอบ
ข้อ 45

Which S3 encryption option uses an AWS-managed key automatically?

เลือกคำตอบ
ข้อ 46

Which mechanism protects data in transit to AWS?

เลือกคำตอบ
ข้อ 47

Which AWS service provides dedicated single-tenant hardware security modules?

เลือกคำตอบ
ข้อ 48

Which S3 feature prevents objects from being deleted or overwritten for a fixed period?

เลือกคำตอบ
ข้อ 49

Which AWS service centralizes encryption keys and integrates with many AWS services?

เลือกคำตอบ
ข้อ 50

Match each data protection service to its purpose.

ข้อ 51

Which AWS service provides compliance reports, certifications, and agreements?

เลือกคำตอบ
ข้อ 52

Which AWS service tracks resource configurations and evaluates them against rules?

เลือกคำตอบ
ข้อ 53

Which AWS service helps you centrally manage accounts, budgets, and service control policies?

เลือกคำตอบ
ข้อ 54

What is a service control policy?

เลือกคำตอบ
ข้อ 55

Which AWS Config feature bundles multiple rules for compliance frameworks?

เลือกคำตอบ
ข้อ 56

Which AWS service provides recommendations for security, cost, performance, and reliability?

เลือกคำตอบ
ข้อ 57

Which AWS service can automatically remediate noncompliant resources?

เลือกคำตอบ
ข้อ 58

Which AWS service provides a single dashboard for security posture and compliance?

เลือกคำตอบ
ข้อ 59

Which AWS Organizations feature restricts the AWS services an account can use?

เลือกคำตอบ
ข้อ 60

Match each governance service to its purpose.