Free AWS-CERTIFIED-SYSOPS-ADMINISTRATOR-ASSOCIATE Amazon AWS-CERTIFIED-SYSOPS-ADMINISTRATOR-ASSOCIATE Practice Test Question

Loading demo links...

Showing 7–9 of 48 questions

Question 7 (Topic 1)

A SysOps administrator must manage the security of an AWS account. Recently, an IAM user's access key was mistakenly uploaded to a public code repository. The SysOps administrator must identify anything that was changed by using this access key. How should the SysOps administrator meet these requirements?

Select an option, then click Submit answer.

  • Create an Amazon EventBridge (Amazon CloudWatch Events) rule to send all IAM events to an AWS Lambda function for analysis.
  • Query Amazon EC2 logs by using Amazon CloudWatch Logs Insights for all events initiated with the compromised access key within the suspected timeframe.
  • Search AWS CloudTrail event history for all events initiated with the compromised access key within the suspected timeframe.
  • Search VPC Flow Logs for all events initiated with the compromised access key within the suspected timeframe.
Question 8 (Topic 1)

A company runs an application that hosts critical data for several clients. The company uses AWS CloudTrail to track user activities on various AWS resources. To meet new security requirements, the company needs to protect the CloudTrail log files from being modified, deleted, or forged. Which solution will meet these requirement?

Select an option, then click Submit answer.

  • Enable CloudTrail log file integrity validation.
  • Use Amazon S3 MFA Delete on the S3 bucket where the CloudTrail log files are stored.
  • Use Amazon S3 Versioning to keep all versions of the CloudTrail log files.
  • Use AWS Key Management Service (AWS KMS) security keys to secure the CloudTrail log files.
Question 9 (Topic 1)

A company wants to prohibit its developers from using a particular family of Amazon EC2 instances. The company uses AWS Organizations and wants to apply the restriction across multiple accounts. What is the MOST operationally efficient way for the company to apply service control policies (SCPs) to meet these requirements?

Select an option, then click Submit answer.

  • Add the accounts to an organizational unit (OU). Apply the SCPs to the OU.
  • Add the accounts to resource groups in AWS Resource Groups. Apply the SCPs to the resource groups.
  • Apply the SCPs to each developer account
  • Enroll the accounts with AWS Control Tower. Apply the SCPs to the AWS Control Tower management account.