What does Amazon GuardDuty analyze to detect threats?
GuardDuty analyzes CloudTrail, VPC flow and DNS logs for threats.
Question 2 of 10 · Incident Response
Why disable rather than delete a suspected compromised IAM user during investigation?
Disabling stops access while preserving the account for investigation.
Question 3 of 10 · Infrastructure Security
How can you reach an AWS service privately without traversing the internet?
VPC endpoints connect to AWS services privately over the AWS network.
Question 4 of 10 · Identity and Access Management
What does IAM Access Analyzer help identify?
Access Analyzer finds unintended external access to resources.
Question 5 of 10 · Data Protection
Which service manages encryption keys for AWS data protection?
KMS creates and controls encryption keys used across AWS services.
Question 6 of 10 · Security Foundations and Governance
What is the shared responsibility model in AWS?
AWS secures the infrastructure; customers secure their configuration and data.
Question 7 of 10 · Detection
Which AWS service records API calls made in an account for detection and audit?
CloudTrail records management and data API activity. CloudWatch handles metrics and logs, Config tracks configuration and Inspector scans for vulnerabilities.
Question 8 of 10 · Incident Response
What should follow containment and eradication?
Recovery restores service and the review captures lessons.
Question 9 of 10 · Infrastructure Security
Which stateful control filters traffic to an EC2 instance?
Security groups are stateful instance-level firewalls; network ACLs are stateless at the subnet.
Question 10 of 10 · Identity and Access Management
Why review IAM permissions regularly?
Regular review catches accumulated and stale permissions.
0 of 10
Detection
Incident Response
Infrastructure Security
Identity and Access Management
Data Protection
Security Foundations and Governance
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.