Skip to content

2.2

Question 1

A healthcare company is preparing to use AWS for workloads that are subject to regulatory requirements. The compliance team needs access to AWS security and compliance reports, certifications, and agreements that can be downloaded for audit purposes. Which AWS service should the company use?

A. AWS Artifact
B. AWS Config
C. Amazon CloudWatch
D. AWS Control Tower

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Artifact provides on-demand access to AWS security and compliance documents, such as certifications, reports, and agreements. * **Why distractors are incorrect:** * **B (AWS Config):** Records and evaluates the configurations of AWS resources. * **C (Amazon CloudWatch):** Monitors metrics, logs, and events for AWS resources and applications. * **D (AWS Control Tower):** Helps set up and govern a multi-account AWS environment; it is not the primary service for downloading compliance reports.

Question 2

A financial services company is designing an application on AWS. The company must protect customer data both while it is stored in Amazon S3 and while it travels between users and the application. Which actions meet these requirements? (Select TWO)

A. Use AWS KMS to manage encryption keys for data at rest.
B. Use TLS for data transmitted between users and the application.
C. Use AWS CloudTrail to encrypt data transmitted over the network.
D. Use Amazon CloudWatch to encrypt database storage automatically.

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** AWS Key Management Service (AWS KMS) can create and manage encryption keys used to encrypt data at rest. * **Why B is correct:** TLS encrypts data in transit between clients and applications, helping protect data as it moves across networks. * **Why distractors are incorrect:** * **C (AWS CloudTrail):** Records API activity and account actions; it does not provide encryption for network traffic. * **D (Amazon CloudWatch):** Provides monitoring and logging capabilities; it does not automatically encrypt database storage.

Question 3

A company must retain a record of API calls made in its AWS accounts for security investigations and compliance audits. The company also wants to send these records to a centralized location for long-term retention. Which service should the company use?

A. AWS CloudTrail
B. Amazon Inspector
C. AWS Shield
D. Amazon GuardDuty

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS CloudTrail records AWS API calls and account activity. CloudTrail logs can be delivered to Amazon S3 for centralized and long-term retention and can also be integrated with Amazon CloudWatch Logs. * **Why distractors are incorrect:** * **B (Amazon Inspector):** Assesses workloads for software vulnerabilities and unintended network exposure. * **C (AWS Shield):** Helps protect applications against distributed denial-of-service (DDoS) attacks. * **D (Amazon GuardDuty):** Detects potential threats and suspicious activity; it is not the primary service for recording all API activity.

Question 4

An organization wants to continuously evaluate whether its AWS resources comply with internal rules, such as requiring encryption for storage resources and restricting certain security group configurations. Which AWS service should the organization use?

A. AWS Config
B. AWS CloudTrail
C. AWS Artifact
D. Amazon CloudWatch

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Config records resource configurations and can evaluate them against compliance rules. It also provides configuration history and compliance status. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records API activity and user actions but does not primarily evaluate resource configurations against rules. * **C (AWS Artifact):** Provides AWS compliance documents and agreements. * **D (Amazon CloudWatch):** Monitors operational metrics, logs, and events rather than serving as the primary configuration compliance service.

Question 5

A company operates workloads across multiple AWS accounts. The security team wants to detect suspicious activity, such as unusual API behavior or potential compromised instances, and view security findings in a central location. Which actions should the company take? (Select TWO)

A. Enable Amazon GuardDuty in the required AWS accounts and Regions.
B. Use AWS Security Hub to aggregate and prioritize security findings.
C. Use AWS Artifact to detect suspicious API activity.
D. Use AWS KMS to identify compromised instances.

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** Amazon GuardDuty continuously analyzes relevant AWS data sources to identify potential threats, such as suspicious account activity and compromised resources. * **Why B is correct:** AWS Security Hub provides a centralized view of security findings and can aggregate findings from services such as Amazon GuardDuty and Amazon Inspector. * **Why distractors are incorrect:** * **C (AWS Artifact):** Provides compliance reports and agreements, not threat detection. * **D (AWS KMS):** Manages encryption keys and cryptographic operations; it does not detect compromised instances.

Question 6

An online retailer expects its public web application to be a target for distributed denial-of-service (DDoS) attacks. The company wants an AWS service specifically designed to help protect its applications from these attacks. Which service should the company use?

A. AWS Shield
B. Amazon Inspector
C. AWS Config
D. AWS Organizations

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Shield is a managed DDoS protection service that helps protect AWS applications from network and transport layer attacks. AWS Shield Standard is included automatically, while AWS Shield Advanced provides additional protections and features. * **Why distractors are incorrect:** * **B (Amazon Inspector):** Identifies software vulnerabilities and unintended network exposure in workloads. * **C (AWS Config):** Evaluates resource configurations and compliance. * **D (AWS Organizations):** Centrally manages multiple AWS accounts and policies.

Question 7

A large organization wants to centrally manage multiple AWS accounts. The organization needs to group accounts, apply policies across accounts, and help prevent accounts from taking actions that violate company requirements. Which AWS service is most appropriate?

A. AWS Organizations
B. AWS CloudTrail
C. AWS Security Hub
D. AWS Artifact

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Organizations provides centralized account management, organizational units, consolidated billing, and service control policies (SCPs) that can establish permission guardrails across accounts. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records AWS API activity and account events. * **C (AWS Security Hub):** Aggregates and prioritizes security findings. * **D (AWS Artifact):** Provides access to AWS compliance documentation.

Question 8

A company is creating a new multi-account AWS environment. The company wants an automated way to establish a baseline landing zone with account structure, governance controls, and recommended security configurations. Which service should the company use?

A. AWS Control Tower
B. Amazon CloudWatch
C. AWS Shield
D. AWS KMS

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Control Tower helps establish and govern a multi-account AWS environment by providing a landing zone, account provisioning, and preventive and detective controls. * **Why distractors are incorrect:** * **B (Amazon CloudWatch):** Provides monitoring for AWS resources and applications. * **C (AWS Shield):** Provides DDoS protection. * **D (AWS KMS):** Manages encryption keys and cryptographic operations.

Question 9

A company plans to deploy an application in several AWS Regions. Its legal team warns that data residency, privacy, and industry requirements may differ depending on the location and type of workload. What should the company do before selecting the AWS services and deployment Regions?

A. Review AWS compliance information and verify the requirements that apply to each Region and industry.
B. Assume that compliance in one AWS Region automatically applies to every other Region.
C. Use Amazon CloudWatch to determine which regulations apply to the application.
D. Use AWS Shield to make the application compliant with regional privacy laws.

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Compliance requirements can vary by geography, industry, workload, and AWS service. The company should review AWS compliance documentation, such as information available through AWS Artifact, and confirm its own regulatory obligations. * **Why distractors are incorrect:** * **B:** Compliance coverage and service availability can vary by Region and service; compliance in one Region does not automatically satisfy all requirements elsewhere. * **C (Amazon CloudWatch):** Monitors resources and applications but does not determine applicable laws or regulations. * **D (AWS Shield):** Helps protect against DDoS attacks but does not make an application compliant with privacy regulations.

Question 10

A security team wants to monitor application performance and infrastructure behavior in near real time. The team needs dashboards and alarms for metrics such as CPU utilization, latency, and error counts, while also retaining application and system logs for troubleshooting. Which AWS service should the team use?

A. Amazon CloudWatch
B. AWS CloudTrail
C. AWS Config
D. Amazon Inspector

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Amazon CloudWatch collects and monitors metrics, logs, and events. It can provide dashboards, alarms, and log storage for operational monitoring and troubleshooting. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records AWS API calls and account activity for auditing rather than general application performance monitoring. * **C (AWS Config):** Tracks resource configurations and evaluates compliance. * **D (Amazon Inspector):** Assesses workloads for vulnerabilities and unintended network exposure.

Question 11

A healthcare company is evaluating whether AWS can support its regulatory requirements. The compliance team needs access to AWS compliance reports and agreements. Which AWS service should the company use?

A. AWS Artifact
B. AWS CloudTrail
C. AWS Config
D. Amazon CloudWatch

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Artifact provides on-demand access to AWS security and compliance reports, certifications, and agreements. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records AWS API activity and account actions; it does not provide AWS compliance reports. * **C (AWS Config):** Records and evaluates resource configurations. * **D (Amazon CloudWatch):** Monitors metrics, logs, and alarms for AWS resources and applications.

Question 12

A financial services company must encrypt sensitive data stored in Amazon S3 and Amazon EBS volumes. The company also wants centralized control over encryption keys and permissions. Which AWS service should it use?

A. AWS Key Management Service (AWS KMS)
B. AWS Shield
C. Amazon GuardDuty
D. AWS CloudTrail

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS KMS creates and manages cryptographic keys that can be used to encrypt data at rest in supported AWS services. It also supports access control through AWS Identity and Access Management permissions. * **Why distractors are incorrect:** * **B (AWS Shield):** Helps protect applications from distributed denial-of-service attacks. * **C (Amazon GuardDuty):** Detects suspicious activity and potential threats in AWS accounts. * **D (AWS CloudTrail):** Logs API calls and account activity; it does not centrally manage encryption keys.

Question 13

A company wants to continuously monitor its AWS accounts for suspicious activity, such as unusual API calls, compromised credentials, and communication with known malicious IP addresses. Which service should the company use?

A. Amazon GuardDuty
B. Amazon Inspector
C. AWS Config
D. AWS Shield

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Amazon GuardDuty is a threat detection service that continuously analyzes relevant AWS data sources to identify suspicious activity and potential security threats. * **Why distractors are incorrect:** * **B (Amazon Inspector):** Helps identify software vulnerabilities and unintended network exposure in supported workloads. * **C (AWS Config):** Evaluates resource configurations against desired rules or policies. * **D (AWS Shield):** Provides protection against distributed denial-of-service attacks.

Question 14

A development team is deploying applications to AWS. The security team wants to identify software vulnerabilities and unintended network exposure in the workloads before they become security issues. Which AWS service best meets this requirement?

A. Amazon Inspector
B. Amazon GuardDuty
C. AWS CloudTrail
D. AWS Organizations

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Amazon Inspector automatically assesses supported AWS workloads for software vulnerabilities and unintended network exposure. * **Why distractors are incorrect:** * **B (Amazon GuardDuty):** Detects suspicious activity and potential threats rather than primarily scanning workloads for vulnerabilities. * **C (AWS CloudTrail):** Records API activity and account actions. * **D (AWS Organizations):** Helps centrally manage multiple AWS accounts and apply governance policies.

Question 15

A security operations team uses several AWS security services and wants a centralized view of security findings. The team also wants to prioritize and manage findings across multiple AWS accounts. Which service should it use?

A. AWS Security Hub
B. Amazon CloudWatch
C. AWS Artifact
D. AWS KMS

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Security Hub provides a centralized view of security findings from supported AWS services and helps organizations manage security posture across accounts. * **Why distractors are incorrect:** * **B (Amazon CloudWatch):** Monitors metrics, logs, and alarms but is not the central security findings management service. * **C (AWS Artifact):** Provides access to AWS compliance reports and agreements. * **D (AWS KMS):** Manages encryption keys and cryptographic operations.

Question 16

An online retailer is concerned that a sudden distributed denial-of-service attack could make its public web application unavailable. Which AWS service is designed to help protect the application from DDoS attacks?

A. AWS Shield
B. Amazon GuardDuty
C. AWS Config
D. Amazon Inspector

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Shield provides managed protection against distributed denial-of-service attacks for AWS resources. * **Why distractors are incorrect:** * **B (Amazon GuardDuty):** Detects suspicious activity and threats but is not the primary DDoS protection service. * **C (AWS Config):** Evaluates the configuration of AWS resources. * **D (Amazon Inspector):** Identifies software vulnerabilities and network exposure in supported workloads.

Question 17

A company must determine which user or role terminated an important Amazon EC2 instance and the time the action occurred. Which AWS service should the company use?

A. AWS CloudTrail
B. Amazon CloudWatch
C. AWS Config
D. AWS Artifact

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS CloudTrail records AWS API calls and account activity, including the identity, time, source, and action associated with resource changes. * **Why distractors are incorrect:** * **B (Amazon CloudWatch):** Monitors operational metrics and logs but is not the primary service for recording AWS API activity. * **C (AWS Config):** Tracks resource configuration changes and compliance status but does not provide the same API activity audit trail as CloudTrail. * **D (AWS Artifact):** Provides AWS compliance reports and agreements.

Question 18

A compliance team needs to track changes to resource configurations and determine whether resources comply with company policies. Which AWS service should it use?

A. AWS Config
B. AWS CloudTrail
C. Amazon GuardDuty
D. AWS Shield

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Config records resource configurations, maintains configuration history, and evaluates resources against compliance rules. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records API activity and account actions rather than continuously evaluating configuration compliance. * **C (Amazon GuardDuty):** Detects potential security threats. * **D (AWS Shield):** Protects against distributed denial-of-service attacks.

Question 19

A company wants to create alarms when application performance metrics exceed defined thresholds and collect application and infrastructure logs for operational analysis. Which AWS service should it use?

A. Amazon CloudWatch
B. AWS CloudTrail
C. AWS Artifact
D. AWS Organizations

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Amazon CloudWatch monitors metrics, collects logs, and creates alarms based on defined thresholds. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Records AWS API activity, not general application performance monitoring. * **C (AWS Artifact):** Provides compliance reports and agreements. * **D (AWS Organizations):** Manages multiple AWS accounts and governance policies.

Question 20

A security auditor needs a durable record of AWS API activity that can be reviewed later as part of an investigation. Where should the company configure AWS CloudTrail to deliver its logs?

A. An Amazon S3 bucket
B. AWS Artifact
C. AWS KMS
D. AWS Control Tower

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS CloudTrail can deliver log files to an Amazon S3 bucket for durable storage and later analysis. The logs can also be protected using appropriate access controls and encryption. * **Why distractors are incorrect:** * **B (AWS Artifact):** Provides access to AWS compliance documentation and agreements. * **C (AWS KMS):** Manages encryption keys; it is not a log storage destination. * **D (AWS Control Tower):** Helps set up and govern a multi-account AWS environment.

Question 21

A company has 40 AWS accounts and wants to centrally apply policies that restrict certain actions across accounts. Which AWS service should the company use?

A. AWS Organizations
B. AWS CloudTrail
C. Amazon Inspector
D. Amazon CloudWatch

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Organizations centrally manages multiple AWS accounts and supports governance features such as service control policies. * **Why distractors are incorrect:** * **B (AWS CloudTrail):** Provides an audit history of API activity. * **C (Amazon Inspector):** Assesses supported workloads for vulnerabilities and network exposure. * **D (Amazon CloudWatch):** Monitors metrics, logs, and alarms.

Question 22

A global company is creating a new AWS multi-account environment. It wants an automated starting point with a preconfigured landing zone, account structure, and governance controls. Which AWS service best meets this requirement?

A. AWS Control Tower
B. AWS Artifact
C. Amazon GuardDuty
D. AWS KMS

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Control Tower helps establish and govern a multi-account AWS environment using a landing zone, account provisioning, and preventive and detective controls. * **Why distractors are incorrect:** * **B (AWS Artifact):** Provides compliance reports and agreements. * **C (Amazon GuardDuty):** Detects security threats. * **D (AWS KMS):** Manages encryption keys.

Question 23

A company is designing a secure application that transmits customer information between users and AWS resources and stores the information in an Amazon S3 bucket. Which two actions support encryption requirements? (Select TWO)

A. Use TLS to encrypt data in transit.
B. Use server-side encryption for data stored in Amazon S3.
C. Use AWS CloudTrail to encrypt all application network traffic.
D. Use Amazon GuardDuty to encrypt objects in the S3 bucket.

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** TLS helps protect data in transit while it moves between clients and AWS resources. * **Why B is correct:** Server-side encryption protects data at rest in Amazon S3. * **Why C is incorrect:** AWS CloudTrail records API activity; it does not encrypt application network traffic. * **Why D is incorrect:** Amazon GuardDuty detects threats; it does not encrypt S3 objects.

Question 24

A compliance manager needs official AWS documentation to determine whether AWS services meet requirements for a specific industry and geographic location. Which two resources or actions are most appropriate? (Select TWO)

A. Review applicable reports and certifications in AWS Artifact.
B. Verify the compliance scope and service availability for the required AWS Region.
C. Use Amazon CloudWatch alarms as evidence that every AWS service is compliant.
D. Use AWS Shield to determine whether an industry regulation applies to a service.

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** AWS Artifact provides AWS compliance reports, certifications, and agreements that can help organizations evaluate AWS compliance information. * **Why B is correct:** Compliance requirements and the services covered can vary by geographic location, industry, AWS Region, and service. The company must verify the applicable scope. * **Why C is incorrect:** CloudWatch monitors operations; its alarms do not prove that every AWS service satisfies a regulation. * **Why D is incorrect:** AWS Shield provides DDoS protection and does not determine regulatory applicability.

Question 25

A company operates in two countries. Its legal team says that customer data must remain in a specific country and that some regulatory requirements differ between the countries. What should the company consider when designing its AWS environment?

A. AWS Regions and the compliance requirements that apply to each location
B. Only the number of CloudWatch alarms configured
C. Whether Amazon GuardDuty is enabled, because it determines data residency
D. Whether AWS Shield is enabled, because it determines regulatory scope

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS Regions are separate geographic locations, and compliance, data residency, and service requirements can vary by geography. The company must select appropriate Regions and verify applicable requirements. * **Why distractors are incorrect:** * **B:** CloudWatch alarms support monitoring but do not determine data residency or regulatory scope. * **C:** GuardDuty provides threat detection and does not determine where data is stored. * **D:** Shield provides DDoS protection and does not determine data residency or regulatory requirements.

Question 26

An auditor asks for evidence of who accessed AWS resources and what actions were performed. Which service provides the primary record of this account activity?

A. AWS CloudTrail
B. AWS Config
C. Amazon Inspector
D. AWS Control Tower

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS CloudTrail provides an event history and audit logs for AWS API activity, including the identity that made a request and the requested action. * **Why distractors are incorrect:** * **B (AWS Config):** Provides resource configuration history and compliance evaluation. * **C (Amazon Inspector):** Finds vulnerabilities and network exposure in supported workloads. * **D (AWS Control Tower):** Provides multi-account governance and landing zone capabilities.

Question 27

A company is establishing security and governance controls for its AWS accounts. Which two services can help the company identify security issues or configuration compliance issues? (Select TWO)

A. AWS Security Hub
B. AWS Config
C. AWS Artifact
D. AWS Organizations billing reports

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** AWS Security Hub centralizes and prioritizes security findings from supported AWS services. * **Why B is correct:** AWS Config evaluates resource configurations against compliance rules and provides configuration history. * **Why C is incorrect:** AWS Artifact provides compliance documentation, not continuous identification of the company's resource security issues. * **Why D is incorrect:** Billing reports provide cost information and are not security or configuration compliance controls.

Question 28

A company enables encryption for data stored by two different AWS services. The security team notices that the available encryption settings and key-management options are not identical for both services. What is the most accurate explanation?

A. Encryption capabilities and compliance requirements can vary among AWS services.
B. AWS KMS can encrypt every type of data automatically without service-specific configuration.
C. AWS CloudTrail determines the encryption options for all AWS services.
D. AWS Organizations makes all AWS services use identical encryption settings.

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** AWS services can have different encryption capabilities, supported key options, configuration requirements, and compliance considerations. Customers must review the requirements for each service. * **Why distractors are incorrect:** * **B:** AWS KMS manages keys and cryptographic operations for supported integrations, but it does not automatically configure encryption for every type of data or service. * **C:** CloudTrail records API activity and does not define service encryption capabilities. * **D:** Organizations provides account governance but does not make all services use identical encryption settings.

Question 29

A company wants protection from network-layer DDoS attacks and also wants to detect suspicious activity such as compromised credentials. Which two AWS services should it use? (Select TWO)

A. AWS Shield
B. Amazon GuardDuty
C. AWS Artifact
D. AWS Config

Click to view Answer & Explanation **Correct Answers:** A and B **Explanation:** * **Why A is correct:** AWS Shield helps protect AWS resources from distributed denial-of-service attacks. * **Why B is correct:** Amazon GuardDuty detects suspicious activity and potential threats, including indicators of compromised credentials. * **Why C is incorrect:** AWS Artifact provides compliance reports and agreements. * **Why D is incorrect:** AWS Config evaluates resource configuration and compliance; it is not the primary service for DDoS protection or threat detection.

Question 30

A company wants to improve its compliance audit process. It needs to monitor operational events, record user activity, and verify that resource configurations follow company policies. Which combination of services should it use?

A. Amazon CloudWatch, AWS CloudTrail, and AWS Config
B. AWS Shield, AWS KMS, and AWS Artifact
C. Amazon Inspector, AWS Organizations, and AWS Shield
D. Amazon GuardDuty, AWS KMS, and AWS Control Tower

Click to view Answer & Explanation **Correct Answer:** A **Explanation:** * **Why A is correct:** Amazon CloudWatch monitors metrics, logs, and alarms; AWS CloudTrail records AWS API activity; and AWS Config tracks resource configurations and evaluates compliance. * **Why distractors are incorrect:** * **B:** Shield provides DDoS protection, KMS manages encryption keys, and Artifact provides compliance documentation, but this combination does not directly provide the required monitoring, API auditing, and configuration evaluation. * **C:** Inspector assesses vulnerabilities, Organizations manages accounts, and Shield provides DDoS protection; these services do not provide the complete audit process described. * **D:** GuardDuty detects threats, KMS manages encryption keys, and Control Tower provides multi-account governance; they do not collectively provide the required operational monitoring, API logging, and configuration auditing.