Security and Compliance

Domain 6: Security and Compliance

36 practice questions for Domain 6 of the AWS Certified DevOps Engineer - Professional (DOP-C02) exam, which makes up 17% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 6: Security and Compliance

17% of scored content · 36 practice questions

210. Application teams must be able to create IAM roles for their own workloads without a central team reviewing each request, and without exceeding their own permissions. Which solution meets these requirements?

Answer and explanation

Answer: C. Requiring a boundary on created roles is what makes safe delegation possible, since no created role can exceed the boundary. A ticket queue is the bottleneck being removed. Full IAM access with monthly audit permits escalation between audits. A fixed central role set forces workloads into ill-fitting permissions.

211. Machine identities must have their credentials rotated automatically without application changes. Which solution meets these requirements?

Answer and explanation

Answer: D. Secrets Manager rotates on a schedule and serves the current value at run time, so applications are unchanged. String parameters are neither encrypted nor rotated. Manual key rotation is operational toil and error-prone. Embedded credentials require a redeployment on every rotation.

212. Access must be granted based on resource tags rather than by enumerating resources in each policy. Which approach meets these requirements?

Answer and explanation

Answer: A. Attribute-based access control compares principal and resource tags in a policy condition, so access follows tags without policy changes as resources are created. A role per resource group multiplies roles. Enumerating ARNs requires updating policies continuously. Broad permissions with tags used only for reporting is not access control.

213. Workforce users must reach many AWS accounts with corporate credentials and centrally assigned permissions. Which solution meets these requirements?

Answer and explanation

Answer: D. IAM Identity Center connects once to the corporate provider and assigns permission sets across organization accounts from one place. Per-account SAML configuration multiplies work by the number of accounts. Synchronized IAM users create the long-term identities federation eliminates. Cognito serves application end users.

214. AWS WAF rules and security group baselines must be applied and continuously enforced across every account from one place. Which solution meets these requirements?

Answer and explanation

Answer: A. Firewall Manager centrally creates and enforces protection policies across an organization and remediates drift automatically. StackSets deploy resources without continuously enforcing them. A service control policy restricts actions rather than requiring resources to exist. A conformance pack reports without applying.

215. Sensitive data held in Amazon S3 across many accounts must be discovered and classified automatically. Which solution meets these requirements?

Answer and explanation

Answer: D. Macie applies managed and custom data identifiers to discover and classify sensitive data across S3, and delegated administration extends it organization-wide. Inspector assesses software vulnerabilities. A crawler infers schema without classifying values. Access logging records requests rather than content.

216. TLS certificates for internal services must be issued and renewed from an authority the organization controls. Which solution meets these requirements?

Answer and explanation

Answer: C. Private CA operates a certificate authority the organization controls and integrates with ACM for issuance and renewal. Public certificates require domain validation and are for internet-facing endpoints. Self-signed certificates need manual trust distribution and have no revocation path. Imported certificates must be renewed and reimported manually.

217. Defence in depth must be applied to a public web application beyond a single control. Which combination of steps meets these requirements? (Select TWO.)

Answer and explanation

Answer: A, C. Layering an application-layer filter with network-layer restriction means a bypass of one control still meets another. A larger instance absorbs load rather than filtering attacks. Detailed monitoring improves observability without adding a control. An architecture diagram informs review rather than defending the application.

218. An automated compliance check must confirm continuously that CloudTrail log file validation remains enabled on every trail in the organization. Which solution meets these requirements?

Answer and explanation

Answer: C. A conformance pack deploys the rule to every account and evaluates it continuously, which is what makes the control ongoing rather than point-in-time. Quarterly manual validation checks the delivered files rather than the setting, and only occasionally. Recording a setting in a runbook does not detect it being changed. An annual console review is far too infrequent.

219. A security team must be alerted when an IAM policy grants access to principals outside the organization. Which solution meets these requirements?

Answer and explanation

Answer: D. Access Analyzer evaluates policies for access outside the defined zone of trust, and the organization zone reports only genuinely external access. Using the account as the zone reports every legitimate internal cross-account grant. A Config rule evaluates configuration without policy reachability analysis. GuardDuty detects threat activity rather than enumerating grants.

220. Unexpected security events must raise an alert rather than waiting for a scheduled review. Which solution meets these requirements?

Answer and explanation

Answer: B. Routing findings through EventBridge as they are produced turns detection into an immediate alert or remediation. A weekly meeting and quarterly analysis both leave the finding unaddressed in the interim. More frequent assessment detects sooner without acting.

221. An auditor must establish which principal made a specific infrastructure change and from where. Which source provides this?

Answer and explanation

Answer: B. CloudTrail records each API call with the calling identity, timestamp, source address, and parameters. Application logs record application behaviour. Config records what the configuration was without attributing the call. Flow Logs capture network traffic metadata.

222. A session issued to a role must be restricted further than the role's own policy for one specific operation. Which approach is appropriate?

Answer and explanation

Answer: A. A session policy narrows a single set of temporary credentials to the intersection of the role and the policy, without changing the role. A permanent attachment affects every session. A second role is workable but heavier when the narrowing is per-session. Session duration limits time rather than scope.

223. Access to a resource must be granted based on a tag matching between the requesting principal and the resource. Which approach is appropriate?

Answer and explanation

Answer: D. Comparing principal and resource tags in a condition means access follows tags with no policy change as resources are created. Enumerating ARNs requires continual policy updates. A role per tag value multiplies roles. Broad access with audit permits misuse between audits.

224. A machine identity's credential must rotate without any application change or restart. Which approach is appropriate?

Answer and explanation

Answer: C. Retrieving at use time means a rotated value is used on the next call with no restart. Environment variables are fixed for the process lifetime. A configuration file requires the process to re-read it. Caching at startup holds the pre-rotation value until restart.

225. An organization must ensure new Amazon S3 buckets cannot be made public in any account. Which approach is appropriate?

Answer and explanation

Answer: B. Account-level Block Public Access prevents public exposure regardless of bucket policy, and a service control policy stops it being disabled locally. A Config rule reports after the bucket exists. Per-bucket policies must be applied to every new bucket. Monthly review leaves exposure in between.

226. Certificates used by internal services must renew without operator action. Which approach is appropriate?

Answer and explanation

Answer: D. Automatic renewal and deployment removes the expiry incident entirely. A calendar reminder depends on a person acting. Long-lived certificates delay the problem and increase the exposure window if a key is compromised. Non-expiring self-signed certificates are both untrusted and a security weakness.

227. Sensitive data discovered in an unexpected location must trigger an automated response. Which approach is appropriate?

Answer and explanation

Answer: D. Routing findings to an automated runbook closes the gap between discovery and containment. A weekly meeting and quarterly analysis both leave the data exposed. More frequent discovery detects sooner without responding.

228. An audit requires evidence that a control has operated continuously rather than at a point in time. Which approach is appropriate?

Answer and explanation

Answer: D. Continuous evidence collection against a framework produces a record covering the period, which is what continuous operation means. A point-in-time screenshot, a deployment-time check, and a quarterly review all leave the intervening period unevidenced.

229. An organization must detect when a resource configuration drifts from its infrastructure as code definition. Which approach is appropriate?

Answer and explanation

Answer: C. Drift detection compares deployed resources against the stack definition and reports differences. A template comparison shows what the definition says rather than what exists. Quarterly manual review is slow. Scheduled redeployment overwrites drift without reporting that it occurred or why.

230. An alert must fire when an unusual pattern of API activity occurs in an account, without a predefined threshold. Which approach is appropriate?

Answer and explanation

Answer: C. CloudTrail Insights baselines normal management API call volume and raises events on deviation, requiring no preset threshold. A fixed threshold cannot adapt to an account's normal pattern. Daily review of event history or configuration changes is neither timely nor baselined.

231. An IAM policy must permit an action only when the requested resource carries a tag matching the principal's tag. Which element is required?

Answer and explanation

Answer: C. A condition comparing resource and principal tags implements attribute-based access control. ARN enumeration requires updates as resources change. A statement per value multiplies policy size. A boundary caps permissions rather than matching tags.

232. Temporary credentials issued to a federated user must be restricted below the role's permissions for one session. Which mechanism is appropriate?

Answer and explanation

Answer: C. A session policy narrows one set of credentials without changing the role. A permanent attachment affects every session. A boundary caps the role generally. Session duration limits time rather than scope.

233. An automated control must prevent an EBS volume from being created without encryption. Which approach is appropriate?

Answer and explanation

Answer: D. Encryption by default encrypts every new volume irrespective of the request. A Config rule reports after creation. An IAM deny binds only the roles it is attached to. Weekly review is retrospective.

234. A pipeline must prevent a secret from being committed to source control. Which approach is appropriate?

Answer and explanation

Answer: B. Automated secret scanning with rejection prevents the commit. Manual review does not scale. Rotation limits exposure after the fact. A separate repository is still source control.

235. An organization must detect when a resource is created without required tags and correct it automatically. Which combination of steps meets these requirements? (Select TWO.)

Answer and explanation

Answer: B, C. A Config rule detects the non-compliant state and an attached remediation acts on it. Monthly review is retrospective. Cost allocation activation makes tags billable. A resource count alarm does not evaluate tags.

236. An audit must confirm that a control operated throughout a period rather than at a point in time. Which evidence is appropriate?

Answer and explanation

Answer: B. Continuous records cover the period. A screenshot, a statement, and a template all describe a point in time or an intent rather than sustained operation.

237. An organization must grant a pipeline temporary access to a production account for the duration of a deployment. Which approach is appropriate?

Answer and explanation

Answer: D. A short-lived assumed role scoped to deployment gives temporary least-privilege access. An IAM user is a standing credential, administrator access is excessive, and shared credentials are long-lived secrets.

238. An organization must ensure that IAM roles created by automation carry required tags for attribution. Which approach is appropriate?

Answer and explanation

Answer: C. A condition on the create action prevents untagged roles existing. A Config rule reports afterwards, weekly tagging is manual, and documentation is advisory.

239. An organization must revoke a departed employee's access across all accounts immediately. Which approach is appropriate?

Answer and explanation

Answer: C. Disabling centrally removes federated access everywhere at once. Per-account deletion and permission set removal are slow and error-prone, and key rotation assumes long-term credentials that federation avoids.

240. An organization must prevent a deployment from disabling encryption on a resource. Which approach is appropriate?

Answer and explanation

Answer: B. A policy condition on the action prevents the unencrypted state. A Config rule reports after creation, template review depends on a reviewer, and service defaults cover only some services.

241. An organization must scan infrastructure code for hardcoded credentials before it is deployed. Which approach is appropriate?

Answer and explanation

Answer: B. A required scanning stage blocks the deployment. Scanning deployed resources is after the fact, manual review misses patterns, and rotation limits exposure without preventing it.

242. An organization must ensure a deployment cannot grant a role broader permissions than policy allows. Which approach is appropriate?

Answer and explanation

Answer: C. A required boundary caps what any created role can do regardless of its policies. Manual review and weekly audit are after the fact, and restricting who runs the deployment does not bound what it creates.

243. An organization must confirm that a security control remains in place across accounts without querying each one. Which approach is appropriate?

Answer and explanation

Answer: D. An aggregator presents compliance across accounts in one view. Per-account querying and owner confirmation do not scale, and an account list shows membership rather than control state.

244. An audit must show that a remediation ran each time a control was found non-compliant. Which source is appropriate?

Answer and explanation

Answer: C. Execution history correlated with compliance events shows each detection and its remediation. Current status and configuration reflect now, and CloudTrail records calls without linking them to the compliance event.

245. An organization must evaluate a new account against its control framework as soon as it is created. Which approach is appropriate?

Answer and explanation

Answer: B. Automatic deployment to the organizational unit evaluates accounts as they join. Manual deployment, quarterly audit, and owner action all leave an unevaluated window.