4.0 Security and Compliance SOA-C03 Practice Quiz
80 exam-style questions covering 16% of the SOA-C03 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified CloudOps Engineer Associate practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A company requires console users to use an additional authentication factor before accessing AWS accounts. Which IAM feature should be enforced?
- A. Multi-factor authentication
- B. S3 Versioning
- C. VPC Flow Logs
- D. CloudFront cache policies
Multi-factor authentication. AWS designs this control specifically for IAM features use cases.
An operations team needs workforce users to access multiple AWS accounts through centralized federation. Which service should be considered?
- A. AWS IAM Identity Center
- B. Amazon EBS encryption by default
- C. Amazon CloudFront Origin Shield
- D. AWS Backup Vault Lock
AWS IAM Identity Center. This is the textbook AWS pattern for IAM features.
An EC2 application must access an S3 bucket without storing long-term access keys on the instance. What should be used?
- B. An IAM role attached through an instance profile
- A. An IAM user access key embedded in the application
- C. A Route 53 health check
- D. An EBS snapshot policy
Choose An IAM role attached through an instance profile. This is the AWS-recommended fit for this IAM features need.
A policy should allow access to an S3 prefix only when the request uses a specific resource tag. What IAM capability supports this?
- B. Policy conditions
- A. EC2 placement groups
- C. DynamoDB point-in-time recovery
- D. Route 53 query logging
Policy conditions. This is the AWS-recommended approach for IAM features.
A security team needs to identify whether an S3 bucket policy allows access from outside the organization. Which service can help?
- B. IAM Access Analyzer
- A. Amazon EFS lifecycle management
- C. RDS Performance Insights
- D. Route 53 Resolver inbound endpoints
Choose IAM Access Analyzer. This is the AWS-recommended fit for this Access troubleshooting and auditing need.
A workload in one account needs to read an S3 bucket in another account. Which policy combination is commonly required?
- C. An IAM role or principal policy plus an S3 bucket resource policy that allows the access
- A. A CloudFront invalidation and an S3 lifecycle rule
- B. A NAT gateway and a route table only
- D. An RDS parameter group and subnet group
An IAM role or principal policy plus an S3 bucket resource policy that allows the access is the standard AWS answer. It addresses IAM features cleanly here.
A security team wants to prevent weak account passwords for IAM users. Which setting should be configured?
- C. IAM account password policy
- A. CloudTrail Lake retention
- B. S3 Transfer Acceleration
- D. AWS WAF managed rules
Use IAM account password policy. It directly satisfies the IAM features requirement in this scenario.
A company wants to restrict IAM role assumption to requests that include a specific external ID from a third-party vendor. Which policy element should be used?
- D. A trust policy condition that checks sts:ExternalId
- A. A password policy minimum length
- B. An S3 Object Lock retention rule
- C. An ALB listener rule
AWS recommends A trust policy condition that checks sts:ExternalId for this IAM features scenario.
Key Terms in This Domain
- AWS Trusted Advisor: Best-practice checks for cost, security, fault tolerance, and performance
- AWS Resource Access Manager (RAM): Securely share resources across AWS accounts
- IAM Access Analyzer: Identify unintended public or cross-account resource access
- CloudFormation StackSets: Deploy and manage stacks across multiple accounts and Regions
- AWS Control Tower: Set up and govern a multi-account AWS environment
- CloudWatch composite alarms: Combine multiple alarms into a single state to reduce noise
- CloudWatch dashboards: Customizable, shareable views of metrics and alarms across accounts and Regions
- AWS CloudTrail: Audit log of AWS API activity for governance and security
- S3 multipart upload: Uploads of large objects in parallel parts for speed and resilience
- Security groups: Stateful instance-level firewall for inbound/outbound traffic
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-cloudops-engineer-associate/security-and-compliance/
<a href="https://quizbuffet.com/aws-cloudops-engineer-associate/security-and-compliance/">AWS CloudOps Engineer Associate Security and Compliance practice quiz on QuizBuffet</a>
Other SOA-C03 Domains
- 1.0 Monitoring, Logging, Analysis, Remediation, and Performance Optimization
- 2.0 Reliability and Business Continuity
- 3.0 Deployment, Provisioning, and Automation
- 5.0 Networking and Content Delivery
← Back to SOA-C03 practice test overview
Questions are written against the published SOA-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.