Skip to content
BytePatterns

SAP-C02 · Domain 2: Design for New Solutions · 29% of the exam

Task 2.3: Determine security controls based on requirements

Turning requirements into controls: least-privilege roles, security group and network ACL flows, private service endpoints, encryption at rest and in transit, protection of large web applications against attack, and patch compliance.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A retailer is launching a global storefront on Amazon CloudFront with an Application Load Balancer origin. It expects large HTTP request floods during sales events. The company wants help from AWS experts during an attack and protection from the extra AWS charges that an attack could cause by scaling the application. Which solution meets these requirements?

  1. ARely on AWS Shield Standard and add Amazon GuardDuty to detect attacks against the load balancer and the distribution
  2. BSubscribe to AWS Shield Advanced for the distribution and load balancer, and add AWS WAF rate-based rules
  3. CPut AWS Network Firewall in the origin VPC and drop traffic from source IP addresses that send too many requests per second
  4. DMove the origin to a larger instance type and raise the Auto Scaling group's maximum size for sales events
Show the answer and why
  • ARely on AWS Shield Standard and add Amazon GuardDuty to detect attacks against the load balancer and the distribution

    Incorrect

    Shield Standard is automatic and free but gives no access to the Shield Response Team or cost protection. GuardDuty detects threats; it does not block request floods.

  • BSubscribe to AWS Shield Advanced for the distribution and load balancer, and add AWS WAF rate-based rules

    Correct

    Shield Advanced adds access to the Shield Response Team and cost protection for scaling charges caused by a DDoS attack, and AWS WAF rate-based rules limit floods of web requests.

  • CPut AWS Network Firewall in the origin VPC and drop traffic from source IP addresses that send too many requests per second

    Incorrect

    Network Firewall inspects traffic in a VPC, behind the edge. It offers neither the Shield Response Team nor cost protection.

  • DMove the origin to a larger instance type and raise the Auto Scaling group's maximum size for sales events

    Incorrect

    More capacity absorbs some load but increases exactly the attack-driven charges the company wants protection from.

Expert help during an attack and protection from attack-driven charges are Shield Advanced features; WAF rate-based rules handle the request floods.

Question 2 · choose 1

A research platform will host hundreds of projects. Each researcher signs in through the company's identity provider, which passes a project attribute. Researchers may only touch S3 objects, DynamoDB items and EC2 instances that belong to their own project, and new projects start every week. The security team wants least privilege without writing a new policy for each project. Which approach meets these requirements?

  1. ACreate one IAM role per project with policies that name that project's resources, and add a role whenever a project starts
  2. BAttach a permissions boundary to every researcher role that lists the ARNs of the resources of all current projects
  3. CPass the project as a session tag and use one role whose policy requires the principal and resource project tags to match
  4. DAdd a resource-based policy to every project resource that lists the researchers of that project by their user names
Show the answer and why
  • ACreate one IAM role per project with policies that name that project's resources, and add a role whenever a project starts

    Incorrect

    Role-based access works but needs a new role and policy for every project, which is exactly the per-project work the team wants to avoid.

  • BAttach a permissions boundary to every researcher role that lists the ARNs of the resources of all current projects

    Incorrect

    A boundary sets maximum permissions for a role. A shared boundary that lists every project's resources would allow access across projects and still need editing for each new project.

  • CPass the project as a session tag and use one role whose policy requires the principal and resource project tags to match

    Correct

    Attribute-based access control compares principal tags, which an identity provider can pass as session tags, with resource tags, so one policy covers new projects without changes.

  • DAdd a resource-based policy to every project resource that lists the researchers of that project by their user names

    Incorrect

    Many of these resources, such as EC2 instances, do not support resource-based policies, and maintaining lists of users on every resource does not scale.

Many projects, frequent change and one policy point to ABAC: tag the principal and the resource, and compare the two in the policy.

Question 3 · choose 2

In a new VPC, clients on the internet reach web servers in subnet W on port 443. The web servers call application servers in subnet P on port 8443. After the network team replaced the default network ACLs with custom ACLs that allow only the inbound ports above, connections time out. Security groups allow the same ports. Which ACL rules must be added? (Choose TWO.)

  1. AAn outbound rule in the security group of the application servers that allows ephemeral ports back to subnet W
  2. BAn outbound rule in the network ACL of subnet W that allows TCP ports 1024-65535 to the internet
  3. CAn inbound rule in the network ACL of subnet P that allows TCP port 443 from the internet
  4. DAn outbound rule in the network ACL of subnet P that allows TCP ports 1024-65535 to the CIDR range of subnet W
  5. EAn inbound rule in the network ACL of subnet W that allows TCP port 8443 from subnet P
Show the answer and why
  • AAn outbound rule in the security group of the application servers that allows ephemeral ports back to subnet W

    Incorrect

    Security groups are stateful: responses to allowed inbound traffic are allowed out automatically, so no extra security group rule is needed.

  • BAn outbound rule in the network ACL of subnet W that allows TCP ports 1024-65535 to the internet

    Correct

    Network ACLs are stateless, so the responses from the web servers to the clients' ephemeral ports must be allowed outbound explicitly.

  • CAn inbound rule in the network ACL of subnet P that allows TCP port 443 from the internet

    Incorrect

    The application servers are not reached from the internet, and opening port 443 to them would widen access without fixing the timeouts.

  • DAn outbound rule in the network ACL of subnet P that allows TCP ports 1024-65535 to the CIDR range of subnet W

    Correct

    The application servers answer the web servers on ephemeral ports, and a stateless ACL blocks those responses unless an outbound rule allows them.

  • EAn inbound rule in the network ACL of subnet W that allows TCP port 8443 from subnet P

    Incorrect

    Port 8443 is the destination port on the application servers. Responses come back to the web servers on ephemeral ports, and subnet W would also need its own outbound rule toward port 8443 for the requests.

Security groups remember connections; network ACLs do not. Every flow through a custom ACL needs a rule for the return traffic on ephemeral ports.

Question 4 · choose 1

A company will run 2,000 Amazon EC2 instances across 25 accounts in its organization. Its compliance standard requires critical operating system patches to be installed within seven days of release, during approved maintenance windows, with a central compliance report. Which solution meets these requirements with the LEAST effort?

  1. AUse a Systems Manager Patch Manager patch policy from Quick Setup for the organization, with baselines and a schedule
  2. BTurn on Amazon Inspector for the organization and open a ticket for each instance with an operating system vulnerability
  3. CAdd a cron job to the AMI of each instance that installs all available updates every night
  4. DDeploy an AWS Config managed rule that marks instances without the latest patches as noncompliant
Show the answer and why
  • AUse a Systems Manager Patch Manager patch policy from Quick Setup for the organization, with baselines and a schedule

    Correct

    A patch policy configured through Quick Setup applies patch baselines and schedules across accounts and Regions in an organization, and Patch Manager reports patch compliance for the managed nodes.

  • BTurn on Amazon Inspector for the organization and open a ticket for each instance with an operating system vulnerability

    Incorrect

    Inspector finds software vulnerabilities and reports them. It does not install patches, so people would still patch every instance.

  • CAdd a cron job to the AMI of each instance that installs all available updates every night

    Incorrect

    Unmanaged nightly updates ignore the approved windows and baselines and give no central compliance report.

  • DDeploy an AWS Config managed rule that marks instances without the latest patches as noncompliant

    Incorrect

    AWS Config evaluates and reports compliance, but a rule alone does not install patches on a schedule.

Patching on a schedule with baselines and an organization-wide compliance view is Patch Manager with patch policies.

Question 5 · choose 1

A new public website will be served by an internet-facing Application Load Balancer in eu-west-1, and its domain is hosted in Route 53 in the same account. Visitors' browsers must trust the certificate without any client setup. Last year a certificate on another site expired because its renewal request went to a mailbox nobody read, so renewals must now complete with no human action at all, and no employee may ever handle private key material. Which approach meets these requirements?

  1. ARequest a public ACM certificate validated by email to the domain's administrative addresses and associate it with the load balancer
  2. BRequest a public ACM certificate with DNS validation, create its CNAME record in Route 53, and associate it with the load balancer
  3. CBuy a certificate from a public CA, import it into ACM, and alarm on the days remaining before it expires
  4. DUpload a certificate from a public CA to IAM as a server certificate and select it on the load balancer's HTTPS listener
Show the answer and why
  • ARequest a public ACM certificate validated by email to the domain's administrative addresses and associate it with the load balancer

    Incorrect

    A public ACM certificate is trusted by browsers and needs no key handling. With email validation, though, ACM sends validation emails again when renewal is due, and someone must follow the link, which is exactly the step that failed last year.

  • BRequest a public ACM certificate with DNS validation, create its CNAME record in Route 53, and associate it with the load balancer

    Correct

    ACM renews Amazon-issued certificates automatically when they use DNS validation, the private key stays in ACM, and a public certificate is trusted by browsers. Keeping the validation CNAME in Route 53 lets each renewal complete without anyone acting.

  • CBuy a certificate from a public CA, import it into ACM, and alarm on the days remaining before it expires

    Incorrect

    Imported certificates work with integrated services, but ACM does not renew them. Someone must obtain a new certificate and reimport it, which means handling the private key.

  • DUpload a certificate from a public CA to IAM as a server certificate and select it on the load balancer's HTTPS listener

    Incorrect

    AWS advises using IAM as a certificate manager only in Regions that ACM does not support. The certificate comes from an external provider, so renewal and key handling stay manual.

Browser trust, renewal with no human step and no key handling decide it. Imported and IAM certificates leave renewal and keys with staff. A public ACM certificate meets the trust and key constraints either way, but only DNS validation lets ACM renew it automatically; email validation needs someone to approve each renewal.

Question 6 · choose 1

A new video training site streams each lesson as HLS through CloudFront from a private S3 bucket. A lesson is a playlist plus hundreds of segment files that the player requests by the relative URLs written in the playlist. Only paying subscribers may play a course, access must lapse 12 hours after sign-in, and one credential per viewer session must cover every file of the courses the viewer bought. The team will not rewrite playlists or file URLs and does not want to write or run code at the edge. Which approach meets these requirements?

  1. AIssue a CloudFront signed URL that expires in 12 hours for every playlist and segment file the subscriber requests
  2. BUse origin access control so that only CloudFront can read the bucket, and keep the course paths hard to guess
  3. CSet CloudFront signed cookies with a custom policy for the purchased course paths after sign-in, valid for 12 hours
  4. DAttach a Lambda@Edge function that validates a session token cookie against the subscriber database on each viewer request
Show the answer and why
  • AIssue a CloudFront signed URL that expires in 12 hours for every playlist and segment file the subscriber requests

    Incorrect

    Signed URLs restrict access with an expiration time, which suits single files or clients without cookie support. Here every segment URL inside the playlists would have to change to carry a signature.

  • BUse origin access control so that only CloudFront can read the bucket, and keep the course paths hard to guess

    Incorrect

    Origin access control keeps viewers from reaching the bucket directly, but it does nothing to decide which viewers CloudFront serves, so anyone with a path could play a course.

  • CSet CloudFront signed cookies with a custom policy for the purchased course paths after sign-in, valid for 12 hours

    Correct

    Signed cookies suit access to many restricted files, such as all the files of an HLS video, when you do not want to change your current URLs. A custom policy can use wildcards in the resource path to cover a whole course and sets how long the cookie is valid.

  • DAttach a Lambda@Edge function that validates a session token cookie against the subscriber database on each viewer request

    Incorrect

    Lambda@Edge runs your functions to customize what CloudFront delivers, so it could check a session token without changing URLs. It is code at the edge that the team would write and run, which it refuses.

The constraints are many files per credential, unchanged URLs, a 12-hour limit and no edge code. Signed URLs need a signature in every file URL, origin access control protects only the origin, and Lambda@Edge is custom code. Signed cookies with a wildcard custom policy cover a course's files for the session without touching the playlists.

Question 7 · choose 1

In a new design, an application tier runs in an Auto Scaling group in an application VPC whose subnets also host batch jobs owned by another team. The application's Amazon RDS for PostgreSQL database runs in a data VPC that is peered with the application VPC in the same Region and account. The application instances scale in and out many times a day, so their IP addresses keep changing. Only the application instances may reach the database port, the batch jobs must not, and the team does not want any automation that rewrites rules after scaling events. Which rule design meets these requirements?

  1. AAdd network ACL rules to the database subnets that allow the database port only from the application subnets
  2. BReference a customer managed prefix list that a Lambda function updates with the application instances' IP addresses after each scaling event
  3. CAllow the database port from the application tier's security group in the peered VPC by referencing that group's ID
  4. DAllow the database port from the application VPC's CIDR range so that any new application instance is covered automatically
Show the answer and why
  • AAdd network ACL rules to the database subnets that allow the database port only from the application subnets

    Incorrect

    A network ACL allows or denies traffic at the subnet level. It cannot tell application instances from batch jobs that run in the same subnets.

  • BReference a customer managed prefix list that a Lambda function updates with the application instances' IP addresses after each scaling event

    Incorrect

    A prefix list is a set of CIDR blocks that rules can reference, so it can hold just the application instances' addresses. Keeping it current needs the update automation that the team has ruled out.

  • CAllow the database port from the application tier's security group in the peered VPC by referencing that group's ID

    Correct

    A rule that references a security group applies to every instance associated with that group, whatever its IP address. Rules can reference security groups in a peered VPC while the peering connection is active.

  • DAllow the database port from the application VPC's CIDR range so that any new application instance is covered automatically

    Incorrect

    The VPC CIDR range never needs updating, but it also covers the batch jobs in the same VPC, which must not reach the database.

The constraints are changing addresses, exclusion of the batch jobs, a peered VPC and no rule automation. The VPC range and subnet ACLs are too coarse to exclude the batch jobs, and a prefix list needs automation. A rule that references the application tier's security group across the active peering connection follows the instances wherever they scale.

Question 8 · choose 1

A new ticketing site will run behind CloudFront with an AWS WAF web ACL. At the last on-sale event of the old site, scalper bots bought tickets in bulk: they spread their requests across thousands of residential IP addresses in the company's home country, sent normal browser user agents, and never identified themselves as bots. The new design must detect and challenge or block such bots on the search and checkout pages, keep letting verified search engine crawlers in, and rely on AWS-maintained detection instead of rules the team writes and tunes. Which solution meets these requirements?

  1. AAdd a rate-based rule that aggregates requests by IP address on the checkout path and blocks addresses above a set limit
  2. BTurn on CloudFront geographic restrictions so that only viewers in the company's home country can reach the distribution
  3. CAdd the AWS WAF account creation fraud prevention managed rule group on the site's account sign-up endpoint
  4. DAdd the AWS WAF Bot Control managed rule group at the targeted inspection level to the web ACL for the search and checkout paths
Show the answer and why
  • AAdd a rate-based rule that aggregates requests by IP address on the checkout path and blocks addresses above a set limit

    Incorrect

    A rate-based rule counts and limits requests per aggregation key, which stops floods from a few sources. Bots spread across thousands of addresses stay under any per-address limit, and the team would set and tune the limits itself.

  • BTurn on CloudFront geographic restrictions so that only viewers in the company's home country can reach the distribution

    Incorrect

    Geographic restrictions work at the country level. These bots use residential addresses in the home country, so they would pass.

  • CAdd the AWS WAF account creation fraud prevention managed rule group on the site's account sign-up endpoint

    Incorrect

    ACFP inspects requests to an account sign-up endpoint and blocks suspicious account creation. It does not inspect the search and checkout pages where the bots buy tickets.

  • DAdd the AWS WAF Bot Control managed rule group at the targeted inspection level to the web ACL for the search and checkout paths

    Correct

    The common level labels self-identifying bots and verifies generally desirable ones such as search engines. The targeted level adds detection of sophisticated bots that do not identify themselves, using browser interrogation, fingerprinting and behavior heuristics.

The constraints are distributed bots that look like browsers, protection on search and checkout, verified crawlers allowed, and AWS-maintained detection. Per-IP rate limits and country restrictions miss bots on many local addresses, and ACFP protects only sign-up. Bot Control's targeted inspection level detects bots that do not self-identify while verified bots stay allowed.

Question 9 · choose 1

A new payments service must process card data on EC2 in an environment that even administrators of the parent instance cannot access, with no persistent storage and no interactive access. Which feature fits?

  1. AA separate VPC for the payments service
  2. BAWS Nitro Enclaves created from the EC2 instance
  3. CA dedicated EC2 instance with SSH disabled and no key pairs
  4. DAn encrypted EBS volume on the instance
Show the answer and why
  • AA separate VPC for the payments service

    Incorrect

    Network isolation does not stop administrators of the instance.

  • BAWS Nitro Enclaves created from the EC2 instance

    Correct

    Nitro Enclaves are isolated, hardened and highly constrained virtual machines created from EC2 instances.

  • CA dedicated EC2 instance with SSH disabled and no key pairs

    Incorrect

    Administrators of the instance could still change its configuration and access its memory.

  • DAn encrypted EBS volume on the instance

    Incorrect

    Encryption at rest does not isolate processing from administrators.

Isolated processing on EC2 is done in Nitro Enclaves.

Practise domain 2 →Practise all domains →