Skip to content
BytePatterns

SAP-C02 · Domain 3: Continuous Improvement for Existing Solutions · 25% of the exam

Task 3.2: Determine a strategy to improve security.

Hardening what already exists: secrets moved out of code and rotated, least privilege audited with Access Analyzer, Config rules with automatic remediation, patching and backup processes, and a full trail of who did what.

Study it

  • Patch compliance with Systems Manager Patch Manager

    Lesson coming

  • Automation and remediation: EventBridge, Systems Manager Automation and Config remediation

    Lesson coming

  • Secrets, least privilege audits and traceability: Secrets Manager, Access Analyzer, CloudTrail

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A security review found that 200 application servers keep the password of an Amazon RDS for SQL Server database in a configuration file. The password has not changed in two years. The company wants the password out of the files, rotated every 30 days automatically, and applications that keep working during rotation. Which solution meets these requirements?

  1. AStore the password as a SecureString parameter in Parameter Store and have each server read it at startup
  2. BKeep the credentials in AWS Secrets Manager with 30-day automatic rotation and fetch the secret at runtime
  3. CEncrypt the configuration files with an AWS KMS key and replace the files on every server each month
  4. DPut the password in an environment variable of each server through the instance user data
Show the answer and why
  • AStore the password as a SecureString parameter in Parameter Store and have each server read it at startup

    Incorrect

    SecureString parameters are encrypted, but Parameter Store has no built-in rotation, so the 30-day rotation would need custom code.

  • BKeep the credentials in AWS Secrets Manager with 30-day automatic rotation and fetch the secret at runtime

    Correct

    Secrets Manager can rotate Amazon RDS credentials automatically on a schedule, updating both the secret and the database, and applications that fetch the secret when they connect pick up the new value.

  • CEncrypt the configuration files with an AWS KMS key and replace the files on every server each month

    Incorrect

    The password stays in files on 200 servers, and changing it every month depends on a manual or custom process.

  • DPut the password in an environment variable of each server through the instance user data

    Incorrect

    AWS advises against keeping passwords in user data, because anyone with access to the instance can read it, and nothing would rotate the password.

"Out of the code, rotated on a schedule" is Secrets Manager rotation with applications that read the secret at runtime.

Question 2 · choose 1

After five years of growth, a company's 60 accounts contain thousands of IAM roles. The security team suspects that many roles are never used and that most roles hold permissions they never exercise. It wants a continuous, organization-wide list of unused roles, unused access keys and unused permissions to remove. Which solution meets this requirement?

  1. ACreate an IAM Access Analyzer unused access analyzer for the organization
  2. BDownload the IAM credential report from every account each month and compare the results
  3. CDeploy an AWS Config rule that checks for IAM users with unused credentials in every account
  4. DTurn on Amazon GuardDuty in every account and review its IAM findings for unused roles
Show the answer and why
  • ACreate an IAM Access Analyzer unused access analyzer for the organization

    Correct

    An unused access analyzer reports unused roles, unused access keys and passwords, and unused permissions across the accounts of an organization, and keeps the findings up to date.

  • BDownload the IAM credential report from every account each month and compare the results

    Incorrect

    The credential report lists IAM users and the status of their credentials. It does not cover roles or unused permissions.

  • CDeploy an AWS Config rule that checks for IAM users with unused credentials in every account

    Incorrect

    A rule about IAM user credentials says nothing about unused roles or the permissions that roles never use.

  • DTurn on Amazon GuardDuty in every account and review its IAM findings for unused roles

    Incorrect

    GuardDuty detects suspicious activity and threats. It does not report unused roles or unused permissions.

Unused roles, keys and permissions across an organization are exactly the findings of an IAM Access Analyzer unused access analyzer.

Question 3 · choose 1

Engineers keep opening SSH (port 22) to 0.0.0.0/0 in security groups to debug instances, and the security team finds these rules days later. The company wants every such rule detected and removed within minutes of being created, with a record of each finding and fix. Which solution meets these requirements with the LEAST custom code?

  1. AReview the AWS Trusted Advisor security group check every week and delete the rules it lists
  2. BTurn on Amazon Inspector and review its network reachability findings for port 22 every day
  3. CTurn on CloudTrail Insights so that unusual security group changes raise an event for the security team
  4. DUse the restricted SSH AWS Config managed rule with automatic remediation by an Automation runbook
Show the answer and why
  • AReview the AWS Trusted Advisor security group check every week and delete the rules it lists

    Incorrect

    The check can list such rules, but a weekly manual review is neither automatic nor fast enough.

  • BTurn on Amazon Inspector and review its network reachability findings for port 22 every day

    Incorrect

    Inspector reports exposure findings, but a daily manual review does not remove the rule within minutes.

  • CTurn on CloudTrail Insights so that unusual security group changes raise an event for the security team

    Incorrect

    CloudTrail Insights detects unusual API call rates. It does not evaluate a rule's content or remove it.

  • DUse the restricted SSH AWS Config managed rule with automatic remediation by an Automation runbook

    Correct

    AWS Config evaluates security groups when they change, and its automatic remediation can run a Systems Manager Automation document against noncompliant resources, with the evaluation and remediation history kept by Config.

Detect-and-fix of a configuration within minutes is a Config rule with automatic remediation.

Question 4 · choose 2

Employees authenticate with the corporate identity provider and use IAM SAML 2.0 federation (AssumeRoleWithSAML) to assume one shared IAM role that can read sensitive files in an S3 bucket. The identity provider sets the role session name to the employee's department, and other teams' reports depend on those session names, so they must stay as they are. An audit found that the company cannot tell which person read a given object: the account's CloudTrail trail records only management events. Auditors want each object-read record to name the person directly, without joining it to sign-in events. Which changes meet these requirements? (Choose TWO.)

  1. ATurn on VPC Flow Logs for every VPC from which employees reach Amazon S3 and query the records with Athena
  2. BAdd S3 data events for the sensitive bucket to the trail with an advanced event selector on its ARN
  3. CHave the identity provider send the user ID as SAML SourceIdentity and allow sts:SetSourceIdentity in the role trust policy
  4. DTurn on Amazon GuardDuty S3 Protection in the account so that GuardDuty analyzes every object read in the bucket
  5. ERecord the bucket in AWS Config and review its configuration timeline to find each read of an object
Show the answer and why
  • ATurn on VPC Flow Logs for every VPC from which employees reach Amazon S3 and query the records with Athena

    Incorrect

    Flow logs capture information about the IP traffic going to and from network interfaces. They do not show which object was read or which person sent the request.

  • BAdd S3 data events for the sensitive bucket to the trail with an advanced event selector on its ARN

    Correct

    Trails do not log data events by default. Object-level operations such as GetObject are S3 data events, and an advanced event selector can limit them to the objects of one bucket.

  • CHave the identity provider send the user ID as SAML SourceIdentity and allow sts:SetSourceIdentity in the role trust policy

    Correct

    The SourceIdentity attribute in the SAML assertion sets a value that stays with every request of the role session and cannot be changed during it, and CloudTrail shows it in the userIdentity of the events from that session. The role trust policy must allow sts:SetSourceIdentity, or the role assumption fails.

  • DTurn on Amazon GuardDuty S3 Protection in the account so that GuardDuty analyzes every object read in the bucket

    Incorrect

    S3 Protection analyzes S3 data events without needing data event logging on a trail, and it produces findings for potential threats. It does not give the company a record of every read.

  • ERecord the bucket in AWS Config and review its configuration timeline to find each read of an object

    Incorrect

    AWS Config records how resources are configured and how those configurations change over time, not reads of the objects in a bucket.

Two gaps need closing. Object reads are data events, which a trail logs only after they are added to it. And because the session names on the shared role do not identify anyone and must stay as they are, the identity provider passes the person's ID as the source identity in the SAML assertion; CloudTrail then shows that value on each action taken in the session, including each GetObject data event.

Question 5 · choose 1

A customer managed KMS key protects payroll data in S3 and Aurora. Its key policy has no statement that enables IAM policies; one statement gives the security team's KeyAdmin role kms:* and another lets the payroll application role use the key. An audit found that KeyAdmin can therefore decrypt payroll data. Auditors require that KeyAdmin keep managing the key, such as its policy, rotation and deletion schedule, without any cryptographic use, that only the application role can encrypt and decrypt, and that the key ID and existing ciphertext stay unchanged. Which change meets these requirements?

  1. ARewrite the key policy to give KeyAdmin only key administration actions and the application role only cryptographic actions
  2. BRemove the application role from the key policy and give it a grant for Encrypt and Decrypt on the key instead
  3. CRe-encrypt the payroll data with the AWS managed keys for Amazon S3 and Amazon RDS and retire the customer managed key
  4. DKeep the policy, and alarm on CloudTrail records of Decrypt calls made by KeyAdmin so that the security team investigates each one
Show the answer and why
  • ARewrite the key policy to give KeyAdmin only key administration actions and the application role only cryptographic actions

    Correct

    Key policies separate key administrators, who manage the key, from key users, who use it in cryptographic operations, in different statements. Because the policy does not enable IAM policies, the key policy alone decides access, and the key and its ciphertext stay as they are.

  • BRemove the application role from the key policy and give it a grant for Encrypt and Decrypt on the key instead

    Incorrect

    Grants let principals use a KMS key in cryptographic operations, often for temporary access, without editing the key policy. They do not take anything away from KeyAdmin, which keeps kms:* and can still decrypt.

  • CRe-encrypt the payroll data with the AWS managed keys for Amazon S3 and Amazon RDS and retire the customer managed key

    Incorrect

    Nobody can manage the lifecycle or permissions of an AWS managed key, so KeyAdmin could not manage rotation or deletion, and re-encrypting changes the key and the ciphertext.

  • DKeep the policy, and alarm on CloudTrail records of Decrypt calls made by KeyAdmin so that the security team investigates each one

    Incorrect

    CloudTrail records KMS API calls, so an alarm would reveal decryption by KeyAdmin after the fact. It detects rather than prevents, so KeyAdmin would still be able to decrypt payroll data.

The constraints are management without use, use without management, and an unchanged key. Grants add use without removing KeyAdmin's kms:*, an alarm only detects decryption, and AWS managed keys cannot be managed at all and force re-encryption. Splitting the key policy into a key administrators statement and a key users statement meets every constraint.

Question 6 · choose 1

A review found that applications on 120 EC2 instances call S3 and SQS with IAM user access keys kept in a shared credentials file on each instance, and the keys have not been rotated in years. The applications use the AWS SDK's default credential provider chain and must not be changed. Security now requires that no long-term AWS credentials exist on or for these instances, that the credentials the applications use expire and renew automatically, and that nobody has to distribute or rotate anything by hand. Which change meets these requirements?

  1. AStore the access keys in Secrets Manager with automatic rotation, and have the applications fetch the current keys at startup
  2. BRotate the access keys every 90 days with a scheduled script that writes the new keys into each instance's credentials file
  3. CPass the access keys to each instance as environment variables in the launch template's user data instead of the credentials file
  4. DAttach an IAM role through an instance profile, then delete the credentials files and deactivate the IAM user keys
Show the answer and why
  • AStore the access keys in Secrets Manager with automatic rotation, and have the applications fetch the current keys at startup

    Incorrect

    Secrets Manager can rotate secrets with a Lambda function, but the secrets would still be IAM user access keys, which are long-term credentials, and fetching them means changing the applications.

  • BRotate the access keys every 90 days with a scheduled script that writes the new keys into each instance's credentials file

    Incorrect

    Regular rotation shortens the exposure of a leaked key, but access keys remain long-term credentials, and AWS recommends temporary credentials such as IAM roles instead.

  • CPass the access keys to each instance as environment variables in the launch template's user data instead of the credentials file

    Incorrect

    The SDK would still find the keys through its credential provider chain, but they would be the same long-term access keys, only stored in a different place on each instance.

  • DAttach an IAM role through an instance profile, then delete the credentials files and deactivate the IAM user keys

    Correct

    A role supplies temporary credentials through instance metadata that update automatically before they expire, so no long-term keys are distributed. Once the files are gone, the SDK's provider chain reaches the IMDS provider without code changes.

The constraints are no long-term credentials, automatic renewal and no application change. Secrets Manager rotation and scripted rotation still use IAM user keys, and user data only moves the keys. An instance profile role gives temporary, automatically refreshed credentials, and removing the files lets the default provider chain find them.

Question 7 · choose 1

GuardDuty already analyzes CloudTrail, VPC Flow Logs and DNS logs for a company's EKS clusters. The security team now wants threat detection based on what happens inside the containers, such as suspicious processes and file activity. Which feature fits?

  1. AMore detailed VPC Flow Logs fields
  2. BGuardDuty Runtime Monitoring for the clusters
  3. CAWS Config rules for the clusters
  4. DAmazon Inspector container image scanning in the registry
Show the answer and why
  • AMore detailed VPC Flow Logs fields

    Incorrect

    Flow logs describe network traffic, not processes or files.

  • BGuardDuty Runtime Monitoring for the clusters

    Correct

    Runtime Monitoring analyzes operating system-level, networking and file events to detect potential threats in workloads.

  • CAWS Config rules for the clusters

    Incorrect

    Config evaluates resource configuration, not runtime events.

  • DAmazon Inspector container image scanning in the registry

    Incorrect

    Image scanning finds vulnerabilities before run time, not suspicious behavior while containers run.

Threat detection from inside running workloads is GuardDuty Runtime Monitoring.

Question 8 · choose 1

An engineer with broad permissions uploaded a modified .zip package straight to a production Lambda function, bypassing the company's build pipeline. The security team now wants every production function to reject any code package that the approved pipeline did not produce and sign, and to reject a signed package that was altered after signing. Releases from the pipeline must keep deploying without manual steps. Which change meets these requirements?

  1. ATurn on Amazon Inspector Lambda code scanning for the production functions and act on its findings
  2. BAdd a manual approval action to the pipeline before the production deployment stage of each function
  3. CSign packages in the pipeline with an AWS Signer profile and attach an enforcing Lambda code signing configuration
  4. DStore build artifacts in an S3 bucket with Object Lock in governance mode so that they cannot be overwritten
Show the answer and why
  • ATurn on Amazon Inspector Lambda code scanning for the production functions and act on its findings

    Incorrect

    Inspector scans function code and dependencies for vulnerabilities. It reports on code that is already deployed, and it does not stop an unsigned or altered package from being deployed.

  • BAdd a manual approval action to the pipeline before the production deployment stage of each function

    Incorrect

    A manual approval stops the pipeline until someone approves, which adds the manual step the team must avoid, and it does nothing about uploads that bypass the pipeline.

  • CSign packages in the pipeline with an AWS Signer profile and attach an enforcing Lambda code signing configuration

    Correct

    With a code signing configuration that allows only the pipeline's signing profile and is set to Enforce, Lambda blocks packages that fail the signature checks, and its integrity check rejects any package modified since it was signed.

  • DStore build artifacts in an S3 bucket with Object Lock in governance mode so that they cannot be overwritten

    Incorrect

    Object Lock protects stored object versions from being overwritten or deleted. Lambda would still accept a package that someone uploads directly instead of the locked artifact.

The control has to sit at the point where code enters the function, not in the pipeline or the artifact store. Lambda code signing checks every new deployment against the allowed signing profiles and verifies that the package has not changed since it was signed, so direct uploads of unsigned or tampered packages fail while signed releases from the pipeline deploy as before.

Question 9 · choose 2

Forty Lambda functions call a payment vendor's API with an API key kept in a plain-text environment variable that every developer with console access can see. The vendor requires the key to be replaced every 30 days through its own API. The security team wants the key stored once, encrypted, rotated automatically on that schedule and no longer visible in any function's configuration. The functions handle 2,000 requests per second, so getting the key must add almost no latency and must not call the storage service on every invocation, and the developers will not write caching code. Which changes meet these requirements? (Choose TWO.)

  1. AHave each function call GetSecretValue through the AWS SDK at the start of every invocation to read the current key
  2. BStore the key as a SecureString parameter in Parameter Store, encrypted with a customer managed KMS key
  3. CRead the key through the AWS Parameters and Secrets Lambda Extension layer added to each function
  4. DKeep the environment variable but encrypt it with a customer managed KMS key that developers cannot use
  5. EStore the key as a secret in Secrets Manager with a rotation Lambda function that calls the vendor's API every 30 days
Show the answer and why
  • AHave each function call GetSecretValue through the AWS SDK at the start of every invocation to read the current key

    Incorrect

    Reading through the SDK always returns the current value, but it calls the service on every invocation. AWS notes that the caching approaches perform better and cost less than retrieving secrets directly with the SDK.

  • BStore the key as a SecureString parameter in Parameter Store, encrypted with a customer managed KMS key

    Incorrect

    A SecureString parameter is stored once and encrypted, but AWS recommends Secrets Manager for API keys because it provides automatic rotation, which Parameter Store does not.

  • CRead the key through the AWS Parameters and Secrets Lambda Extension layer added to each function

    Correct

    The extension retrieves and caches secrets without an SDK, and its local cache means a function does not call Secrets Manager on every invocation, which gives better performance and lower cost.

  • DKeep the environment variable but encrypt it with a customer managed KMS key that developers cannot use

    Incorrect

    With a customer managed key, only users with access to the key can view the variable, but the key still lives in every function's configuration, in 40 copies, with no rotation.

  • EStore the key as a secret in Secrets Manager with a rotation Lambda function that calls the vendor's API every 30 days

    Correct

    Secrets Manager stores secrets centrally and encrypted, and for secrets that are not managed by an AWS service, rotation uses a Lambda function that updates the secret and the external service on a schedule.

The constraints are one encrypted copy, automatic 30-day rotation, nothing in function configuration, and cached low-latency reads without new code. Secrets Manager with a rotation function covers storage and rotation, and the Lambda extension supplies cached reads. SDK calls on every invocation add latency and cost, SecureString parameters do not rotate, and an encrypted environment variable stays in each function.

Practise domain 3 →Practise all domains →