Skip to content

AWS Security Engineer - Advanced Quiz

Back to Quiz Home


This quiz tests your mastery of advanced IAM policies, forensics, compliance automation, and threat remediation.


#

How can you conditionally grant access to a resource only if the request comes from a specific VPC Endpoint?

#

What is a "Token Vending Machine" pattern?

#

How do you remediate a non-compliant resource detected by AWS Config automatically?

#

What is the "NotAction" element in an IAM Policy used for?

#

How do you perform memory analysis on a compromised EC2 instance without rebooting it?

#

What is "AWS Network Firewall"?

#

How do you create a "Data Perimeter" around your organization?

#

What is "Attribute-Based Access Control" (ABAC) in IAM?

#

How to prevent a specific IAM Role from being modified or deleted by anyone, including Administrators?

#

What is "AWS Signer"?

#

How do you investigate a "Root Account Usage" alert?

#

What is the difference between kms:Decrypt and kms:GenerateDataKey?

#

How do you securely manage secrets for a container running in Fargate?

#

What is "AWS Firewall Manager"?

#

How do you implement "Separation of Duties" for KMS keys?

#

What does "passed" mean in iam:PassRole?

#

How do you audit cross-account S3 access?

#

What is a "Forensic Workstation"?

#

How do you ensure logs in CloudWatch Logs are valid and haven't been tampered with?

#

What is the "PrincipalOrgID" condition key?

Quiz Progress

0 / 0 questions answered (0%)

0 correct


📚 Study Guides


📬 Weekly DevOps, Cloud & Gen AI quizzes & guides