Preparing your workspace...
Loading latest data

You are an AWS Certified Solutions Architect Associate with security expertise, working for an e-commerce company. A security alert is triggered due to unusual outbound traffic from an EC2 instance.
Investigation:
CloudTrail & GuardDuty detect unauthorized API calls from an IAM user.
IAM logs show multiple failed login attempts.
AWS Config reveals an open SSH port (22) to the public internet.
Mitigation & Response:
Disable compromised IAM user and rotate credentials.
Isolate the EC2 instance using VPC Security Groups.
Take snapshots for forensic analysis.
Implement MFA for all IAM users and enforce strict access control.
Use AWS Systems Manager Session Manager instead of SSH.
Update AWS WAF rules to block suspicious IPs.
Post-Incident Security Enhancements:
Enable AWS Security Hub for centralized security management.
Automate security responses using AWS Lambda (e.g., disabling compromised accounts).
Monitor continuously with Amazon GuardDuty and CloudWatch.
Question 1.
What type of storage does Amazon S3 provide?
Question 2.
What AWS service allows you to run serverless code?
Question 3.
Which AWS service provides a fully managed relational database?
Question 4.
What is the primary use of Amazon CloudFront?
Question 5.
Which service enables private connections between VPCs and AWS services?
Question 6.
What AWS service is used for DNS and domain name management?
Question 7.
Which storage service is ideal for structured NoSQL databases?
Question 8.
What AWS service is used for monitoring resources and logs?
Question 9.
Which AWS storage class is best for long-term archival storage?
Question 10.
What AWS service is used to automate application deployments?
Question 11.
Which database service is best for petabyte-scale analytics?
Question 12.
What service helps protect against DDoS attacks?
Question 13.
What AWS service offers a managed Kubernetes solution?
Question 14.
Which AWS service is used for Infrastructure as Code (IaC)?
Question 15.
Which storage service is designed for file-based workloads?
Question 16.
What AWS service is used to create a virtual private cloud?
Question 17.
What AWS service can be used to manage encryption keys?
Question 18.
Which AWS service is used for server migration?
Question 19.
What AWS service provides virtual desktops?
Question 20.
Which AWS service is used to stream real-time data?