Skip to content
BytePatterns

SOA-C03 · Domain 4: Security and Compliance · 16% of the exam

Task 4.2: Implement strategies to protect data and infrastructure.

Protecting the data itself: classifying it, encryption at rest with KMS keys and in transit with ACM certificates, secrets kept out of code, and acting on findings from Security Hub, GuardDuty, Inspector and Config.

Study it

  • Encryption at rest with KMS keys

    Partly covered by: KMS, Envelope Encryption & Private CA

  • Encryption in transit with ACM certificates

    Lesson coming

  • Secrets: Secrets Manager and Parameter Store

    Lesson coming

  • Findings and classification: Security Hub, GuardDuty, Inspector and Macie

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Many teams launch Amazon EC2 instances in eu-west-1 from their own launch templates and scripts. A new policy requires that every new Amazon EBS volume created in the Region from now on is encrypted at rest, without asking the teams to change their templates or scripts. What should the operations team do?

  1. ATurn on default encryption for the account's Amazon S3 buckets
  2. BTurn on EBS encryption by default in eu-west-1
  3. CTurn on automatic key rotation for the AWS managed key that EBS uses
  4. DUse Elastic Volumes to change every new unencrypted volume to encrypted
Show the answer and why
  • ATurn on default encryption for the account's Amazon S3 buckets

    Incorrect

    Default bucket encryption applies to objects in S3. It does not affect EBS volumes or snapshots.

  • BTurn on EBS encryption by default in eu-west-1

    Correct

    Encryption by default is a Region-specific setting that makes new EBS volumes and snapshot copies in that Region encrypted, with no change to how they are launched.

  • CTurn on automatic key rotation for the AWS managed key that EBS uses

    Incorrect

    AWS KMS already rotates AWS managed keys every year, and rotation cannot be turned on or off for them. Rotation does not encrypt unencrypted volumes either.

  • DUse Elastic Volumes to change every new unencrypted volume to encrypted

    Incorrect

    An existing unencrypted volume cannot be encrypted directly; it takes a snapshot and a new encrypted volume, one at a time.

One Region setting covers every launch path. It has no effect on existing volumes, which still need the snapshot-and-copy route.

Question 2 · choose 1

A website is served through an Amazon CloudFront distribution whose origin is an Application Load Balancer in eu-west-1. An engineer requested and validated a public AWS Certificate Manager (ACM) certificate for www.example.com in eu-west-1. When the engineer adds www.example.com as an alternate domain name on the distribution, the certificate does not appear in the list. What should the engineer do?

  1. AValidate the certificate again by email instead of by DNS
  2. BAttach the certificate to the load balancer's HTTPS listener first
  3. CRequest or import the certificate in us-east-1 and select it
  4. DChange the distribution's security policy to a newer minimum TLS version
Show the answer and why
  • AValidate the certificate again by email instead of by DNS

    Incorrect

    DNS, email and HTTP validation are all ways to prove domain ownership. The method does not decide where CloudFront can use the certificate.

  • BAttach the certificate to the load balancer's HTTPS listener first

    Incorrect

    A certificate for the load balancer may be in any Region, but that covers only the connection from CloudFront to the origin, not viewers.

  • CRequest or import the certificate in us-east-1 and select it

    Correct

    To use an ACM certificate for HTTPS between viewers and CloudFront, the certificate must be requested or imported in US East (N. Virginia).

  • DChange the distribution's security policy to a newer minimum TLS version

    Incorrect

    The security policy sets the minimum protocol and the ciphers used with viewers. It does not change which certificates can be chosen.

Viewer certificates for CloudFront come from us-east-1; origin certificates on a load balancer can live in the load balancer's own Region.

Question 3 · choose 1

An application on AWS Lambda connects to an Amazon RDS for MySQL database with a user name and password that are stored in the function's environment variables. An audit requires that the password be stored encrypted outside the code and configuration, and that it be changed automatically every 30 days in both the store and the database. Which approach meets these requirements?

  1. AKeep the password in the environment variables and encrypt them with a customer managed KMS key
  2. BStore the password as a Parameter Store SecureString and turn on rotation for its KMS key
  3. CStore the password in an encrypted S3 object that a scheduled script updates every month
  4. DStore the credentials in AWS Secrets Manager and turn on automatic rotation every 30 days
Show the answer and why
  • AKeep the password in the environment variables and encrypt them with a customer managed KMS key

    Incorrect

    Lambda already encrypts environment variables at rest, and AWS recommends Secrets Manager instead for database credentials. Nothing here changes the password.

  • BStore the password as a Parameter Store SecureString and turn on rotation for its KMS key

    Incorrect

    KMS key rotation generates new key material for the key. The password encrypted with it stays the same, in the store and in the database.

  • CStore the password in an encrypted S3 object that a scheduled script updates every month

    Incorrect

    This is home-grown rotation that the team must build and keep in step with the database, which Secrets Manager already provides.

  • DStore the credentials in AWS Secrets Manager and turn on automatic rotation every 30 days

    Correct

    Secrets Manager rotation updates the credentials in both the secret and the database on a schedule, and the function reads the secret at run time.

Rotating a database password means changing it in two places at once. Secrets Manager rotation is built for exactly that; key rotation and encrypted storage are not.

Question 4 · choose 1

As the first step of a data classification program, a company must learn which of its 300 Amazon S3 buckets hold personal data such as names, addresses and credit card numbers, and it must keep that picture current as new data arrives. The operations team wants a managed service rather than custom scanning code. Which service should the team turn on?

  1. AAmazon Macie with automated sensitive data discovery
  2. BAmazon GuardDuty protection for the account and its S3 buckets
  3. CAmazon Inspector for the account
  4. DAWS Config with rules for the S3 buckets
Show the answer and why
  • AAmazon Macie with automated sensitive data discovery

    Correct

    Macie discovers sensitive data in S3 with machine learning and pattern matching, and automated discovery continually samples objects across the bucket inventory and reports findings.

  • BAmazon GuardDuty protection for the account and its S3 buckets

    Incorrect

    GuardDuty is a threat detection service that looks for suspicious and malicious activity, not for the kind of data stored in objects.

  • CAmazon Inspector for the account

    Incorrect

    Inspector scans EC2 instances, ECR images and Lambda functions for software vulnerabilities and network exposure.

  • DAWS Config with rules for the S3 buckets

    Incorrect

    Config records and evaluates resource configurations, such as bucket settings. It does not look inside objects.

Classification starts with knowing where sensitive data is. For S3, that discovery is Macie's job.

Question 5 · choose 2

Amazon GuardDuty is enabled in an account. Today the security team looks at the GuardDuty console once a day. A new requirement says the on-call engineer must receive an email within minutes whenever GuardDuty creates a high-severity finding. Which actions should the operations team take? (Choose TWO.)

  1. ACreate an EventBridge rule that matches GuardDuty Finding events with a severity filter
  2. BExport findings to an Amazon S3 bucket that the on-call engineer reviews each morning
  3. CSet an Amazon SNS topic with the on-call email subscription as the rule's target
  4. DTurn on CloudTrail Insights events for the account
  5. ECreate a GuardDuty suppression rule that matches high-severity findings
Show the answer and why
  • ACreate an EventBridge rule that matches GuardDuty Finding events with a severity filter

    Correct

    GuardDuty sends finding events to EventBridge, and a rule's event pattern can match on the detail.severity field.

  • BExport findings to an Amazon S3 bucket that the on-call engineer reviews each morning

    Incorrect

    Export to S3 is for keeping findings longer and tracking history. A daily review does not meet "within minutes".

  • CSet an Amazon SNS topic with the on-call email subscription as the rule's target

    Correct

    EventBridge delivers matched events to targets such as SNS topics, and the topic delivers the message to its email subscriber.

  • DTurn on CloudTrail Insights events for the account

    Incorrect

    CloudTrail Insights detects unusual API call or error rates. It does not deliver GuardDuty findings to anyone.

  • ECreate a GuardDuty suppression rule that matches high-severity findings

    Incorrect

    A suppression rule automatically archives matching new findings, which hides exactly the findings the team wants to see.

Findings become notifications through EventBridge: a rule that selects the findings, and an SNS topic that reaches people.

Practise domain 4 →Practise all domains →