Skip to content
BytePatterns

SCS-C03 · Domain 6: Security Foundations and Governance · 14% of the exam

Task 6.2: Implement a secure and consistent deployment strategy for cloud resources

Deploying the same safe way everywhere: StackSets and other infrastructure as code checked with CloudFormation Guard and cfn-lint, tags that group resources, Firewall Manager policies from one place, and sharing through Service Catalog and AWS RAM.

Study it

  • Infrastructure as code that stays safe: StackSets, CloudFormation Guard and cfn-lint

    Lesson coming

  • Tags, Firewall Manager, Service Catalog and AWS RAM

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

A platform team's pipeline deploys CloudFormation templates to many accounts. Before deployment, the build must fail when a template has invalid syntax or property values, and also when it breaks company security rules, such as S3 buckets without encryption, written by the security team as policy as code. Which tools should the pipeline run? (Choose TWO.)

  1. Acfn-lint against the CloudFormation resource specification
  2. BCloudFormation drift detection run against the deployed stacks
  3. CAWS CloudFormation Guard rules written in its DSL
  4. DAWS Config rules evaluated in each of the target accounts
  5. ECloudFormation StackSets with automatic deployment to new accounts
Show the answer and why
  • Acfn-lint against the CloudFormation resource specification

    Correct

    cfn-lint inspects template structure, syntax and allowed property values, which Guard does not do.

  • BCloudFormation drift detection run against the deployed stacks

    Incorrect

    Drift detection compares deployed resources with their templates after deployment; it does not test templates before deployment.

  • CAWS CloudFormation Guard rules written in its DSL

    Correct

    Guard is a policy-as-code tool that validates templates and other JSON or YAML data against rules written in its DSL.

  • DAWS Config rules evaluated in each of the target accounts

    Incorrect

    Config rules evaluate resources after they exist, not templates in the build.

  • ECloudFormation StackSets with automatic deployment to new accounts

    Incorrect

    StackSets deploy stacks across accounts. They do not check templates against security rules.

The two checks are complementary: cfn-lint for "is this a valid template?", Guard for "does it follow our rules?".

Question 2 · choose 1

A company requires that every internet-facing Application Load Balancer in its organization is protected by a standard AWS WAF web ACL with AWS managed rule groups. Application teams create new accounts and load balancers every week. What is the most operationally efficient way to meet this requirement?

  1. AAn AWS Firewall Manager AWS WAF policy for Application Load Balancers
  2. BA CloudFormation StackSet that creates the web ACL in every account
  3. CAn AWS Config rule that reports load balancers that have no web ACL
  4. DAn SCP that denies elasticloadbalancing:CreateLoadBalancer unless a web ACL exists
Show the answer and why
  • AAn AWS Firewall Manager AWS WAF policy for Application Load Balancers

    Correct

    Firewall Manager applies protections across accounts and resources and automatically adds them to new resources and accounts in scope.

  • BA CloudFormation StackSet that creates the web ACL in every account

    Incorrect

    A StackSet can create the web ACL, but it does not associate it with load balancers created later.

  • CAn AWS Config rule that reports load balancers that have no web ACL

    Incorrect

    The rule finds unprotected load balancers but does not protect them.

  • DAn SCP that denies elasticloadbalancing:CreateLoadBalancer unless a web ACL exists

    Incorrect

    An SCP only limits which API calls principals can make. It does not associate a web ACL with any load balancer.

"Apply once, keep applying to new accounts and resources" is the purpose of Firewall Manager policies. Individual accounts can still add their own rules in the managed web ACL.

Question 3 · choose 1

Developers in many accounts may launch only a hardened, pre-approved Amazon RDS configuration that the platform team maintains. The developers must not have permissions to create RDS instances or run CloudFormation directly. What should the platform team do?

  1. AA shared Service Catalog portfolio with the RDS product and without any launch constraint
  2. BPublish the approved template in a shared S3 bucket for developers to deploy
  3. CA shared Service Catalog portfolio with the RDS product and a launch constraint role
  4. DDeploy the approved RDS configuration to every account with a StackSet
Show the answer and why
  • AA shared Service Catalog portfolio with the RDS product and without any launch constraint

    Incorrect

    Without a launch constraint, users launch products with their own credentials, so developers would need CloudFormation and RDS permissions.

  • BPublish the approved template in a shared S3 bucket for developers to deploy

    Incorrect

    Developers would deploy with their own credentials, which requires the permissions the company wants to withhold.

  • CA shared Service Catalog portfolio with the RDS product and a launch constraint role

    Correct

    A launch constraint makes Service Catalog assume the named role to provision the product, so end users need only Service Catalog permissions.

  • DDeploy the approved RDS configuration to every account with a StackSet

    Incorrect

    StackSets push stacks centrally; they do not let developers launch the approved configuration on demand.

Service Catalog plus a launch role is how teams offer self-service for approved products without giving users the underlying permissions.

Question 4 · choose 1

A CloudFormation template sets a database password as a literal value. The team wants the template to fetch the password from Secrets Manager at deployment time instead. What should it use?

  1. AA parameter with a default value set to the password
  2. BA dynamic reference to the Secrets Manager secret
  3. CAn Outputs section that exports the password
  4. DA Mappings section with the password per environment
Show the answer and why
  • AA parameter with a default value set to the password

    Incorrect

    The password would still be written in the template.

  • BA dynamic reference to the Secrets Manager secret

    Correct

    Dynamic references let a template get values stored in other services, such as secrets in Secrets Manager.

  • CAn Outputs section that exports the password

    Incorrect

    Outputs publish values; they would expose the password.

  • DA Mappings section with the password per environment

    Incorrect

    Mappings are literal values inside the template.

Do not use dynamic references in properties that form a resource's primary identifier, because the value could appear in plaintext.

Question 5 · choose 1

An EC2 Image Builder pipeline produces the company's hardened AMI. Every account in the organization should be able to launch it, without anyone sharing it by hand after each build. What should the team configure?

  1. AMake the AMI public after each build
  2. BCopy the AMI into each account with a scheduled script
  3. CDistribution settings granting launch to the org
  4. DA launch template in the image account only
Show the answer and why
  • AMake the AMI public after each build

    Incorrect

    A public AMI can be launched by anyone, not only the organization.

  • BCopy the AMI into each account with a scheduled script

    Incorrect

    Scripts add work that distribution settings already handle.

  • CDistribution settings granting launch to the org

    Correct

    Distribution settings can authorize other accounts, organizations and OUs to launch the output AMI.

  • DA launch template in the image account only

    Incorrect

    A launch template does not give other accounts permission to use the AMI.

Pair distribution with Allowed AMIs so accounts can launch only approved images.

Question 6 · choose 1

Before updating a production stack, reviewers want to see exactly which resources CloudFormation would add, modify or replace. What should the team create?

  1. AA change set for the stack
  2. BA drift detection run on the stack
  3. CA stack policy for the stack
  4. DA new stack set for the stack
Show the answer and why
  • AA change set for the stack

    Correct

    Change sets preview how proposed changes would affect resources, including additions, modifications and deletions.

  • BA drift detection run on the stack

    Incorrect

    Drift detection compares current resources with the template, not proposed changes.

  • CA stack policy for the stack

    Incorrect

    Stack policies protect resources during updates; they do not preview them.

  • DA new stack set for the stack

    Incorrect

    StackSets deploy stacks to many accounts; they are not a preview.

Review change sets for replacements, which can delete and re-create resources with new identifiers.

Question 7 · choose 1

Many existing resources in an account lack the required CostCenter tag. An administrator wants to find them and add the tag to many resources at once from the console. What should the administrator use?

  1. AAWS Config advanced query with a SQL update
  2. BA tag policy, which adds missing tags automatically
  3. CAWS Cost Explorer filtered by the CostCenter tag
  4. DTag Editor to find the resources and edit tags
Show the answer and why
  • AAWS Config advanced query with a SQL update

    Incorrect

    Advanced query reads configuration data; it cannot change tags.

  • BA tag policy, which adds missing tags automatically

    Incorrect

    Tag policies standardize tags and report noncompliance; they do not add tags to resources.

  • CAWS Cost Explorer filtered by the CostCenter tag

    Incorrect

    Cost Explorer reports costs; it does not edit tags.

  • DTag Editor to find the resources and edit tags

    Correct

    Tag Editor finds resources and adds, removes or edits tags on up to 500 selected resources at a time.

Fix the backlog with Tag Editor, then prevent new gaps with tag policies and tag-on-create rules.

Question 8 · choose 1

A template takes an API token as a parameter. The team does not want the value shown in the console or in describe calls for the stack. What should it set on the parameter?

  1. ANoEcho true, which masks the value in the console and API
  2. BAllowedPattern, which encrypts the value with KMS
  3. CType set to SecureString, which CloudFormation stores encrypted
  4. DMinLength, which hides values that are long enough
Show the answer and why
  • ANoEcho true, which masks the value in the console and API

    Correct

    NoEcho masks the parameter value in the console, command line tools and API; dynamic references are still the better home for secrets.

  • BAllowedPattern, which encrypts the value with KMS

    Incorrect

    AllowedPattern validates input; it encrypts nothing.

  • CType set to SecureString, which CloudFormation stores encrypted

    Incorrect

    Template parameters do not have a SecureString type that stores the value encrypted.

  • DMinLength, which hides values that are long enough

    Incorrect

    MinLength validates length; it hides nothing.

NoEcho does not mask values that the template itself writes elsewhere, such as in outputs or metadata.

Practise domain 6 →Practise all domains →