,1. Multiple Choice: Which AWS service provides centralized
control over the cryptographic keys used to protect your data?
- A) AWS Identity and Access Management (IAM)
- B) AWS Key Management Service (KMS)
- C) AWS CloudTrail
- D) AWS Shield
Answer: B) AWS Key Management Service (KMS)
Rationale: AWS KMS is a managed service that makes it easy for
you to create and control the encryption keys used to encrypt your
data.
2. Fill-in-the-Blank: The __________ feature of Amazon VPC
allows you to privately connect your VPC to supported AWS
services and VPC endpoint services powered by AWS PrivateLink
without requiring an internet gateway, NAT device, VPN
connection, or AWS Direct Connect connection.
Answer: VPC Endpoint
Rationale: VPC endpoints enable private connections between
your VPC and AWS services.
, Rationale: AWS CloudTrail is a service that enables governance,
compliance, operational auditing, and risk auditing of your AWS
account.
4. Multiple Response: Which of the following are key components
of AWS's shared responsibility model? (Select TWO)
- A) Physical security of data center facilities
- B) Configuration management of the customer's operating
systems
- C) Encryption of data in transit
- D) Life-cycle management of AWS infrastructure
Answer: A) Physical security of data center facilities, B)
Configuration management of the customer's operating systems
Rationale: In AWS's shared responsibility model, AWS is
responsible for the physical security of data center facilities, while
customers are responsible for configuration management of their
operating systems.
5. Multiple Choice: What is the purpose of AWS Shield?
- A) Managing cryptographic keys
- B) Providing DDoS protection
- C) Tracking user activity and API usage
- D) Controlling user access
, Answer: B) Providing DDoS protection
Rationale: AWS Shield is a managed Distributed Denial of
Service (DDoS) protection service that safeguards applications
running on AWS.
6. Fill-in-the-Blank: Amazon __________ is a web service that
records AWS API calls for your account and delivers log files to
you.
Answer: CloudTrail
Rationale: Amazon CloudTrail is a service that provides event
history of your AWS account activity, including actions taken
through the AWS Management Console, AWS SDKs, command
line tools, and other AWS services.
7. True/False: AWS IAM roles can be used to grant necessary
permissions to AWS services to interact with other AWS
resources.
Answer: True
Rationale: IAM roles allow you to delegate access with defined
permissions to AWS services or entities without having to share
access keys.
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Bankart. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $14.49. You're not tied to anything after your purchase.