New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

SCS-C01 Reviews Questions

Page: 18 / 44
Total 589 questions

AWS Certified Security - Specialty Questions and Answers

Question 69

An application is currently secured using network access control lists and security groups. Web servers are located in public subnets behind an Application Load Balancer (ALB); application servers are located in private subnets.

How can edge security be enhanced to safeguard the Amazon EC2 instances against attack? (Choose two.)

Options:

A.

Configure the application’s EC2 instances to use NAT gateways for all inbound traffic.

B.

Move the web servers to private subnets without public IP addresses.

C.

Configure IAM WAF to provide DDoS attack protection for the ALB.

D.

Require all inbound network traffic to route through a bastion host in the private subnet.

E.

Require all inbound and outbound network traffic to route through an IAM Direct Connect connection.

Question 70

An application developer is using an IAM Lambda function that must use IAM KMS to perform encrypt and decrypt operations for API keys that are less than 2 KB Which key policy would allow the application to do this while granting least privilege?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 71

An organization policy states that all encryption keys must be automatically rotated every 12 months.

Which IAM Key Management Service (KMS) key type should be used to meet this requirement?

Options:

A.

IAM managed Customer Master Key (CMK)

B.

Customer managed CMK with IAM generated key material

C.

Customer managed CMK with imported key material

D.

IAM managed data key

Question 72

A Web Administrator for the website example.com has created an Amazon CloudFront distribution for dev.example.com, with a requirement to configure HTTPS using a custom TLS certificate imported to IAM Certificate Manager.

Which combination of steps is required to ensure availability of the certificate in the CloudFront console? (Choose two.)

Options:

A.

Call UploadServerCertificate with /cloudfront/dev/ in the path parameter.

B.

Import the certificate with a 4,096-bit RSA public key.

C.

Ensure that the certificate, private key, and certificate chain are PKCS #12-encoded.

D.

Import the certificate in the us-east-1 (N. Virginia) Region.

E.

Ensure that the certificate, private key, and certificate chain are PEM-encoded.

Page: 18 / 44
Total 589 questions