30 practice questions for Domain 4 of the AWS Certified CloudOps Engineer - Associate (SOA-C03) exam, which makes up 16% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 4: Security and Compliance
108. An organization must be alerted when a security group is modified to allow unrestricted inbound access, and the change must be reverted automatically. Which solution meets these requirements?
Answer and explanation
Answer: C. Config continuously evaluates security group configuration and an attached Automation remediation revokes the offending rule without human action. A traffic alarm reacts to consequences rather than the configuration change. Weekly GuardDuty review is neither immediate nor configuration-focused. A monthly scan leaves a month-long exposure.
109. A security team must prove which IAM principal terminated an EC2 instance last week and from which source address. Which solution meets these requirements?
Answer and explanation
Answer: C. CloudTrail records each API call with the calling identity, timestamp, source IP address, and parameters. CloudWatch Logs holds application and system logs rather than the API audit trail. Config records what the configuration was without attributing the call. Flow Logs capture network traffic metadata.
110. An organization must ensure that a mandatory set of AWS Config rules is deployed in every member account and cannot be deleted locally. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, E. An organization conformance pack deploys and maintains the rules centrally including in new accounts, and a service control policy prevents local deletion. Manual onboarding is inconsistent and misses new accounts. A recreating function restores rules after deletion rather than preventing it. Trusted Advisor provides unrelated best-practice checks.
111. An operations engineer must be able to start and stop specific EC2 instances but must never be able to terminate any instance. Which solution meets these requirements?
Answer and explanation
Answer: A. Granting only the required actions on the intended resources is least privilege and cannot be circumvented. Granting ec2:* with a conditional deny is broader than needed and error-prone. Termination protection can be disabled by anyone holding the permission. A Config rule reports a termination after it has happened.
112. A company must identify IAM roles and resource policies in an account that grant access to principals outside its AWS Organization. Which solution meets these requirements?
Answer and explanation
Answer: A. Access Analyzer evaluates resource and trust policies for access outside the defined zone of trust, and the organization zone reports only genuinely external access. Using the account as the zone would report every legitimate internal cross-account grant. A Config rule evaluates configuration without policy reachability analysis. GuardDuty detects threat activity rather than enumerating grants.
113. An organization must apply a consistent security baseline and account provisioning process as it scales from 20 to 300 accounts. Which solution meets these requirements with the LEAST custom engineering?
Answer and explanation
Answer: D. Control Tower automates landing zone setup, account provisioning, and consistent controls, which is purpose-built for this scale. Custom scripts recreate that function at high maintenance cost. A checklist depends on human consistency across hundreds of accounts. Reducing account count weakens isolation and does not address baselines.
114. An operations team must verify that the account has addressed the security findings raised by AWS Trusted Advisor. Which solution meets these requirements?
Answer and explanation
Answer: D. The requirement names Trusted Advisor specifically, and its checks report a status that changes once the flagged condition is corrected. GuardDuty, Config, and Inspector each report a different finding set and would not confirm that the Trusted Advisor checks are satisfied.
115. An organization must restrict which AWS Regions member accounts may use, and the restriction must survive local administrator action. Which solution meets these requirements?
Answer and explanation
Answer: B. A service control policy caps permissions for every principal in a member account and cannot be overridden locally, and a NotAction exception keeps global services usable. IAM policies can be edited by account administrators. A Config rule reports after the fact. Region opt-out is available for some Regions but is not a general control across all of them.
116. Workforce users must access many AWS accounts using existing corporate credentials, with permissions assigned centrally. Which solution meets these requirements?
Answer and explanation
Answer: C. IAM Identity Center connects once to the corporate provider and assigns permission sets across organization accounts from one place. Per-account SAML configuration multiplies the work by the number of accounts. Synchronised IAM users create long-term identities federation is meant to eliminate. Cognito is for application end users rather than workforce account access.
117. A compliance requirement states that every new Amazon EBS volume and snapshot in an account must be encrypted, without depending on the requester. Which solution meets these requirements?
Answer and explanation
Answer: B. Encryption by default causes every new volume and snapshot to be encrypted regardless of the request, which prevents the non-compliant state. A Config rule detects the volume after it exists and cannot encrypt it in place. An IAM deny applies only to principals it is attached to. A tag asserts intent without encrypting.
118. A customer managed AWS KMS key must have its cryptographic material changed annually without re-encrypting existing data. Which solution meets these requirements?
Answer and explanation
Answer: C. Automatic rotation generates new key material annually while retaining previous material, so existing ciphertext remains decryptable without re-encryption. Creating a new key each year requires re-encryption. Deleting the key destroys access to data encrypted under it. An alias is a friendly name and does not rotate material.
119. Database credentials stored in an EC2 user data script must be moved to a managed store with automatic rotation. Which solution meets these requirements?
Answer and explanation
Answer: B. Secrets Manager stores the value encrypted, rotates it on a schedule, and serves it through an instance role. A String parameter is neither encrypted nor rotated. An encrypted volume still places the plaintext on the host once mounted. Launch template environment variables are visible to anyone with describe permissions.
120. An auditor requires proof that delivered AWS CloudTrail log files have not been altered since delivery. Which solution meets these requirements?
Answer and explanation
Answer: D. Log file validation writes digest files containing hashes of the delivered logs, so modification or deletion can be detected cryptographically. Access logging records who read the bucket without attesting to integrity. Encryption protects confidentiality. A delete-denying policy reduces risk without providing proof.
121. An organization must aggregate and prioritize findings from Amazon GuardDuty, Amazon Inspector, and Amazon Macie across many accounts. Which solution meets these requirements?
Answer and explanation
Answer: D. Security Hub ingests findings from AWS security services, normalises them, and evaluates them against security standards under a delegated administrator. Detective investigates a specific finding rather than aggregating across services. A Config aggregator collects configuration compliance rather than security findings. Exporting to S3 requires building the normalisation and standards logic.
122. An Amazon S3 bucket must never permit public access regardless of any bucket policy or ACL applied later. Which solution meets these requirements?
Answer and explanation
Answer: D. Account-level Block Public Access overrides any bucket policy or ACL granting public access and covers buckets created later. Enabling it per bucket leaves future buckets uncovered. A restrictive bucket policy can be replaced by an administrator. A Config rule remediates after exposure has begun.
123. An instance in a private subnet cannot reach the internet through a NAT gateway. Which cause should be investigated first?
Answer and explanation
Answer: B. A missing default route to the NAT gateway is the usual cause. A private instance should not have a public address. A NAT gateway must be in a public subnet, so finding it in the private subnet would also be a fault but the route is checked first. Inbound rules do not govern outbound connections.
124. Two VPCs are peered but instances cannot communicate. Which cause should be investigated first?
Answer and explanation
Answer: D. Peering requires routes in both directions. Availability Zones are not a peering constraint. Peering traffic stays on the AWS network and is not configured for encryption by the customer. Internet gateways are unrelated to peering.
125. A VPC endpoint for Amazon S3 is configured but instances still reach S3 through the NAT gateway. Which cause should be investigated first?
Answer and explanation
Answer: A. A gateway endpoint adds a prefix list route that must be present in the subnet's route table. Gateway endpoints have no public address. A different Region would prevent the endpoint working at all. Client software is not the issue.
126. A private hosted zone's records are not resolving from instances in the VPC. Which cause should be investigated first?
Answer and explanation
Answer: B. A private hosted zone must be associated with the VPC and the VPC must have DNS attributes enabled. Time to live affects caching. Public and private zones are separate. Public addresses do not affect private resolution.
127. A CloudFront distribution is serving stale content after the origin was updated. Which action is appropriate?
Answer and explanation
Answer: D. Invalidation clears cached objects and versioned names avoid the problem entirely. Price class governs edge locations used. Disabling causes an outage. Origin size does not affect the cache.
128. A Route 53 alias record must point at an Application Load Balancer. Which advantage does an alias record provide over a CNAME?
Answer and explanation
Answer: A. Alias records work at the zone apex where CNAMEs cannot, and alias queries to AWS targets are not charged. Resolution speed and time to live are not the distinction, and alias records point at supported AWS resources rather than arbitrary domains.
129. A CloudFront distribution must serve different cache behaviour for a specific URL path. Which configuration is appropriate?
Answer and explanation
Answer: D. Path-pattern cache behaviours apply distinct settings per path within one distribution. A second distribution requires separate DNS. Changing the default affects everything. An additional origin routes requests but does not by itself set cache behaviour.
130. An operator must confirm that IAM policies across an account grant no more access than intended. Which tool is appropriate?
Answer and explanation
Answer: A. Access Analyzer evaluates policy reachability and reports both external and unused access. Inspector assesses software. Trusted Advisor runs general checks. CloudWatch collects metrics.
131. An AWS Config rule reports a resource as non-compliant, and the operator must correct it without manual intervention. Which configuration is appropriate?
Answer and explanation
Answer: A. An attached remediation action corrects the resource automatically. An alarm and a dashboard both require someone to act. More frequent evaluation detects sooner without correcting.
132. An S3 bucket must block public access regardless of any bucket policy or access control list applied to it. Which configuration is appropriate?
Answer and explanation
Answer: D. Block Public Access overrides permissive settings. Removing policies does not prevent one being added later. Versioning and encryption address different risks.
133. An operator must rotate a customer managed KMS key's material automatically each year. Which configuration is appropriate?
Answer and explanation
Answer: A. Automatic rotation generates new material while retaining old material so existing ciphertext remains decryptable. Creating a new key requires re-encryption. Deleting destroys access to existing data. Disabling and re-enabling does not rotate material.
134. An EBS volume must be encrypted, and the volume already exists unencrypted with data on it. Which sequence is required?
Answer and explanation
Answer: C. An existing unencrypted volume is encrypted by copying its snapshot with encryption. Encryption cannot be toggled in place, attaching does not encrypt, and encryption by default applies only to newly created volumes.
135. Secrets used by an application must be retrieved at run time rather than stored on the instance. Which approach is appropriate?
Answer and explanation
Answer: D. Retrieval at run time from Secrets Manager leaves no secret on the instance and picks up rotation. User data, files, and environment variables all place the value on the host.
136. An operator must ensure that an S3 bucket's objects cannot be deleted for a defined retention period, including by an administrator. Which configuration is appropriate?
Answer and explanation
Answer: C. Compliance mode binds every principal including root. Governance mode can be bypassed by a principal holding the bypass permission. A bucket policy can be modified. MFA Delete adds an authentication step.
137. An operator must confirm that data in transit to an RDS database is encrypted. Which configuration is appropriate?
Answer and explanation
Answer: B. Requiring SSL in the parameter group refuses unencrypted connections. Storage encryption protects data at rest. Subnet placement controls reachability. Backups protect against loss.