Skip to content

AWS Security Engineer - Intermediate Quiz

Back to Quiz Home


This quiz covers operational security, cross-account patterns, and advanced data protection mechanisms.


#

How can you securely share an AMI (Amazon Machine Image) with another AWS account?

#

What is a "Permission Boundary"?

#

How do you monitor for the "Root" user login?

#

What data source does Amazon GuardDuty use to detect compromised EC2 instances (e.g., Bitcoin mining)?

#

What is the "IMDSv2" (Instance Metadata Service Version 2) security improvement?

#

How do you grant a Lambda function access to a DynamoDB table in a different account?

#

What is "S3 Object Lock"?

#

How do you analyze a compromised instance without tipping off the attacker?

#

Which service manages SSL/TLS certificates for your load balancers?

#

What is the difference between "Inspector" and "GuardDuty"?

#

How do you rotate database passwords without downtime?

#

What is "VPC Flow Logs"?

#

How can you ensure that no one deletes the CloudTrail logs?

#

Which component allows you to filter traffic based on the body of an HTTP request (e.g., JSON payload)?

#

What is a "Trust Policy" in IAM?

#

How do you detect if an S3 bucket is publicly accessible?

#

What is "S3 Block Public Access"?

#

How do you secure data in transit between EC2 instances in the same VPC?

#

What is "AWS Detective"?

#

Can Security Groups block traffic?

Quiz Progress

0 / 0 questions answered (0%)

0 correct


📚 Study Guides


📬 Weekly DevOps, Cloud & Gen AI quizzes & guides