DOP-C02 · Domain 6: Security and Compliance · 17% of the exam
Task 6.2: Apply automation for security controls and data protection.
Defense in depth, applied by automation: security groups, network ACLs, Network Firewall, AWS WAF and Shield, certificates, encryption with KMS and CloudHSM, Macie for sensitive data, and controls rolled out to every account and Region.
Study it
Network defense in depth: security groups, network ACLs, Network Firewall, AWS WAF and Shield
Data protection: KMS, CloudHSM, ACM certificates and Macie
Lesson coming
Security controls across accounts: Security Hub, Control Tower and Systems Manager
Lesson coming
Sample questions
Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.
Question 1 · choose 3
A public web application runs behind an Application Load Balancer in a VPC, with Amazon CloudFront in front of it. Recent incidents showed three problems: a few clients at a time, from addresses that change every day, send thousands of requests per minute to the /login path and overload the authentication service; attackers send requests straight to the ALB's DNS name to bypass CloudFront; and some clients still use plain HTTP. Customers often browse the catalog at high request rates from shared corporate addresses and must not be throttled there, and real customers must still be able to sign in during an attack. Which controls should the DevOps engineer add? (Choose THREE.)
AAdd a rate-based rule to the distribution's web ACL that uses the Count all aggregation with a scope-down statement for the /login path
BAdd a rate-based rule to the distribution's web ACL that aggregates on the source IP address, with a scope-down statement for the /login path
CAdd a rate-based rule to the distribution's web ACL that aggregates on the source IP address, with no scope-down statement
DAllow inbound traffic to the ALB's security group only from the CloudFront managed prefix list for origin-facing servers
ESet the viewer protocol policy to Redirect HTTP to HTTPS, with an ACM certificate in us-east-1 for the distribution's domain
Show the answer and why
AAdd a rate-based rule to the distribution's web ACL that uses the Count all aggregation with a scope-down statement for the /login path
Incorrect
Count all puts every matching request into one aggregation instance, so once the total passes the limit, sign-in requests from real customers are rate limited along with the attackers' requests.
BAdd a rate-based rule to the distribution's web ACL that aggregates on the source IP address, with a scope-down statement for the /login path
Correct
Each client address is counted on its own, and the scope-down statement limits counting to /login, so only addresses that send too many sign-in requests are rate limited and catalog traffic is not counted.
CAdd a rate-based rule to the distribution's web ACL that aggregates on the source IP address, with no scope-down statement
Incorrect
Without a scope-down statement the rule counts every request from an address, so customers browsing the catalog from shared corporate addresses would be throttled too.
DAllow inbound traffic to the ALB's security group only from the CloudFront managed prefix list for origin-facing servers
Correct
The prefix list holds the IP ranges of CloudFront's origin-facing servers, so only CloudFront can reach the origin and direct requests to the ALB are refused.
ESet the viewer protocol policy to Redirect HTTP to HTTPS, with an ACM certificate in us-east-1 for the distribution's domain
Correct
The viewer protocol policy can require HTTPS between viewers and CloudFront, and an ACM certificate for CloudFront must be in the US East (N. Virginia) Region.
A rate-based rule is the right tool when a small number of addresses send too many requests, and its aggregation key and scope-down statement decide who is counted and which requests count. Per-address counting on /login stops the abusive clients without touching catalog browsing or other customers' sign-ins. The security group with the CloudFront prefix list removes the bypass path, and the viewer protocol policy with an ACM certificate enforces HTTPS.
A company with 200 accounts in AWS Organizations must find out which of its thousands of S3 buckets hold personal data, keep that view current as new data arrives, and keep the cost lower than scanning every object. The results must be visible to a central security account. What should the DevOps engineer do?
ARun a one-time Amazon Macie sensitive data discovery job in each account that analyzes every object in every bucket
BMake the security account the Macie administrator for the organization and turn on automated sensitive data discovery
CTurn on GuardDuty S3 Protection in all accounts so that GuardDuty reports the buckets that contain personal data to the security account
DDeploy an AWS Config rule to every account that checks whether each bucket has default encryption and versioning turned on
Show the answer and why
ARun a one-time Amazon Macie sensitive data discovery job in each account that analyzes every object in every bucket
Incorrect
A one-time job in each account scans everything once and is not kept current or visible in one place.
BMake the security account the Macie administrator for the organization and turn on automated sensitive data discovery
Correct
Automated discovery continually evaluates the bucket inventory, samples representative objects, and covers member accounts' buckets for the Macie administrator.
CTurn on GuardDuty S3 Protection in all accounts so that GuardDuty reports the buckets that contain personal data to the security account
Incorrect
GuardDuty looks for threats in activity data. Classifying the content of objects as sensitive data is what Macie does.
DDeploy an AWS Config rule to every account that checks whether each bucket has default encryption and versioning turned on
Incorrect
Bucket settings say nothing about what the objects contain, so this does not find personal data.
Macie's automated sensitive data discovery uses sampling to give a broad, continually updated picture of where sensitive data lives, and a Macie administrator for the organization sees it for member accounts too.
An application encrypts sensitive fields client-side with AWS KMS in us-east-1 before writing them to an Amazon DynamoDB global table that is replicated to us-west-2. In a Regional outage of us-east-1, the copy of the application in us-west-2 must decrypt these fields without calling KMS in us-east-1 and without re-encrypting the data. What should the DevOps engineer do?
AGrant the us-west-2 application role kms:Decrypt on the us-east-1 key in that key's key policy, and call it from us-west-2
BCreate a new single-Region key in us-west-2 and give it the same alias as the key in us-east-1
CEncrypt with a multi-Region primary key in us-east-1 and create its replica key in us-west-2 for the application there
DExport the key material of the us-east-1 key and store it in a Secrets Manager secret that is replicated to us-west-2
Show the answer and why
AGrant the us-west-2 application role kms:Decrypt on the us-east-1 key in that key's key policy, and call it from us-west-2
Incorrect
The application would still call KMS in us-east-1 to decrypt, which fails in an outage of that Region.
BCreate a new single-Region key in us-west-2 and give it the same alias as the key in us-east-1
Incorrect
An alias is only a name. A different key has different key material and cannot decrypt data encrypted under the us-east-1 key.
CEncrypt with a multi-Region primary key in us-east-1 and create its replica key in us-west-2 for the application there
Correct
Related multi-Region keys share key material and key ID, so data encrypted in one Region can be decrypted in the other without a cross-Region call or re-encryption.
DExport the key material of the us-east-1 key and store it in a Secrets Manager secret that is replicated to us-west-2
Incorrect
KMS keys never leave AWS KMS unencrypted, so their key material cannot be exported for use elsewhere.
KMS keys are Regional. For data that moves between Regions and must stay readable during a Regional outage, multi-Region keys provide interchangeable keys in each Region; existing data encrypted under a single-Region key would need to be re-encrypted once.
A security team uses AWS Security Hub CSPM with a delegated administrator account. Today each account and Region is configured on its own, and some existing accounts have standards turned off. The team wants Security Hub CSPM enabled with the same standards and controls in every existing and future account and in four Regions, managed from one place, and member accounts must not be able to change these settings. What should the DevOps engineer do?
AKeep local configuration and turn on auto-enable for new accounts from the delegated administrator in each of the four Regions
BUse central configuration with three linked Regions and a configuration policy for centrally managed accounts
CDeploy a StackSet that enables Security Hub CSPM and the standards in every account and Region, with automatic deployment to new accounts
DDeploy an organization conformance pack with the same AWS Config rules as the standards to every account in the four Regions
Show the answer and why
AKeep local configuration and turn on auto-enable for new accounts from the delegated administrator in each of the four Regions
Incorrect
Local configuration applies only to new accounts in the current Region and not to existing accounts, and it supports only a limited set of standards.
BUse central configuration with three linked Regions and a configuration policy for centrally managed accounts
Correct
Configuration policies take effect in the home Region and linked Regions, and only the delegated administrator can configure centrally managed accounts.
CDeploy a StackSet that enables Security Hub CSPM and the standards in every account and Region, with automatic deployment to new accounts
Incorrect
This enables the service but leaves each account self-managed, so member accounts can still change the settings.
DDeploy an organization conformance pack with the same AWS Config rules as the standards to every account in the four Regions
Incorrect
Conformance packs deploy AWS Config rules; they do not enable Security Hub CSPM or manage its standards and controls.
Central configuration lets the delegated administrator define configuration policies once, from the home Region, for accounts and OUs across linked Regions. Centrally managed accounts cannot override them.
Public ACM certificates for 40 domains are attached to load balancers. Renewals sometimes fail because an email approval is missed, and sites then show expired certificates. The domains are hosted in Route 53. What should the DevOps engineer do so that renewals happen without people?
AReissue the certificates with DNS validation and keep the CNAME records
BBuy the certificates from a third-party CA and import them into ACM for the load balancers
CRequest private certificates through ACM from an AWS Private CA
DDeploy the AWS Config rule acm-certificate-expiration-check and notify the team before each expiry
Show the answer and why
AReissue the certificates with DNS validation and keep the CNAME records
Correct
With DNS validation, ACM renews a certificate automatically while it is in use and its CNAME record remains.
BBuy the certificates from a third-party CA and import them into ACM for the load balancers
Incorrect
Imported certificates are not eligible for ACM managed renewal, so someone must import a new certificate before each expiry.
CRequest private certificates through ACM from an AWS Private CA
Incorrect
Browsers trust only certificates that chain to public root CAs, so public visitors would see certificate errors.
DDeploy the AWS Config rule acm-certificate-expiration-check and notify the team before each expiry
Incorrect
The rule only reports certificates close to expiry; someone still has to approve the email renewal in time.
DNS validation proves domain control with a CNAME record that needs to be added only once. ACM then renews the certificate automatically as long as it is in use and the record stays.
A data lake bucket uses SSE-KMS with a customer managed key that compliance requires. Analytics jobs read millions of small objects written each day, KMS request costs are high, and some jobs hit KMS request throttling. The objects must stay server-side encrypted under the same key, and the analytics jobs must not be changed. What should the DevOps engineer do?
ASwitch the bucket's default encryption to SSE-S3 so that S3 no longer calls KMS for each object
BTurn on S3 Bucket Keys for SSE-KMS on the bucket
CRequest a higher KMS cryptographic request quota and keep the current settings
DHave the jobs encrypt and decrypt with the AWS Encryption SDK and its data key caching
Show the answer and why
ASwitch the bucket's default encryption to SSE-S3 so that S3 no longer calls KMS for each object
Incorrect
SSE-S3 removes the KMS calls, but it drops the customer managed key that compliance requires.
BTurn on S3 Bucket Keys for SSE-KMS on the bucket
Correct
Bucket Keys reduce the requests that S3 makes to KMS by up to 99 percent, without client changes, while objects stay encrypted with the customer managed key.
CRequest a higher KMS cryptographic request quota and keep the current settings
Incorrect
KMS request quotas are adjustable, so throttling can be eased, but the number of requests and their cost stay the same.
DHave the jobs encrypt and decrypt with the AWS Encryption SDK and its data key caching
Incorrect
Data key caching reduces KMS calls for client-side encryption, but the jobs would have to change and the objects would no longer use SSE-KMS.
With S3 Bucket Keys, S3 uses a short-lived bucket-level key from KMS instead of calling KMS for every object, which reduces request traffic, throttling and cost while keeping SSE-KMS. Bucket Keys apply to new objects; existing objects can be copied to use them.
A public web application behind CloudFront needs protection against common web exploits such as those described in the OWASP Top 10. The rules must be written and kept up to date by AWS, not by the team or a third-party vendor, and the budget allows no charges beyond basic AWS WAF pricing. What should the DevOps engineer add to the web ACL?
AA rate-based rule that blocks any IP address above 100 requests per five minutes
BAn AWS Marketplace managed rule group for the OWASP Top 10 from a security vendor
CThe AWS WAF Bot Control managed rule group at the targeted protection level
DThe AWS managed core rule set (AWSManagedRulesCommonRuleSet) rule group
Show the answer and why
AA rate-based rule that blocks any IP address above 100 requests per five minutes
Incorrect
Rate limits address request floods from single addresses, not exploit payloads, and the team would write and tune the rule itself.
BAn AWS Marketplace managed rule group for the OWASP Top 10 from a security vendor
Incorrect
Marketplace rule groups give broad exploit protection, but they are owned and maintained by the seller and need a paid subscription.
CThe AWS WAF Bot Control managed rule group at the targeted protection level
Incorrect
Bot Control is maintained by AWS, but it manages bot traffic rather than exploit payloads and carries fees beyond basic AWS WAF pricing.
DThe AWS managed core rule set (AWSManagedRulesCommonRuleSet) rule group
Correct
The core rule set is maintained by AWS, protects against a wide range of vulnerabilities including those in OWASP publications, and has no additional fee.
AWS Managed Rules are written and updated by AWS. Apart from Bot Control, account takeover prevention and account creation fraud prevention, they cost nothing beyond basic AWS WAF pricing, and the core rule set is the common baseline for web exploits.
Amazon Macie runs on the company's buckets, but its managed data identifiers do not recognize the company's internal employee IDs, which look like EMP- followed by seven digits and usually appear near the word employee. Security wants Macie to report objects that contain them. What should the DevOps engineer do?
ACreate a custom data identifier with a regex for the ID and the keyword employee
BAdd the IDs to a Macie allow list so that they are reported
CTurn on GuardDuty S3 Protection for all of the company's buckets
DWrite an S3 Object Lambda function that scans each object as it is read
Show the answer and why
ACreate a custom data identifier with a regex for the ID and the keyword employee
Correct
Custom data identifiers use a regex and optional keywords to detect company-specific sensitive data.
BAdd the IDs to a Macie allow list so that they are reported
Incorrect
Allow lists define text that Macie should ignore, not report.
CTurn on GuardDuty S3 Protection for all of the company's buckets
Incorrect
GuardDuty looks for threats, not sensitive data patterns.
DWrite an S3 Object Lambda function that scans each object as it is read
Incorrect
This builds custom scanning instead of extending Macie.
Custom data identifiers combine a regex with keywords, ignore words and a proximity rule, so Macie can find sensitive data that managed identifiers do not cover.
A batch job running under its own role must decrypt data with a customer managed KMS key for a few hours each night. Security does not want to widen the key policy or the role's IAM policy, and wants the access removed as soon as the job is done. What should the DevOps engineer use?
AAdd the job role to the key policy before each run and remove it after
BShare the key's material with the job so that it can decrypt locally
CCreate a KMS grant for the job role to Decrypt, and retire it after the job
DAttach an IAM policy that allows kms:* on all keys to the job role
Show the answer and why
AAdd the job role to the key policy before each run and remove it after
Incorrect
This changes the key policy, which security does not want to widen.
BShare the key's material with the job so that it can decrypt locally
Incorrect
KMS keys never leave AWS KMS unencrypted, so there is no key material to share.
CCreate a KMS grant for the job role to Decrypt, and retire it after the job
Correct
Grants are often used for temporary permissions and can be retired as soon as the task is complete.
DAttach an IAM policy that allows kms:* on all keys to the job role
Incorrect
This widens the role's permissions far beyond the job's needs.
A grant gives a principal permission to use a KMS key without changing the key policy or IAM policies. It can be retired or revoked when it is no longer needed.