| Exam Code/Number: | AWS-Security-SpecialtyJoin the discussion |
| Exam Name: | AWS Certified Security - Specialty |
| Certification: | Amazon |
| Question Number: | 592 |
| Publish Date: | May 31, 2026 |
|
Rating
100%
|
|
An Amazon S3 bucket is encrypted using an IAM KMS CMK. An IAM user is unable to download objects from the S3 bucket using the IAM Management Console; however, other users can download objects from the S3 bucket.
Which policies should the Security Engineer review and modify to resolve this issue? (Select three.)
A recent security audit found that IAM CloudTrail logs are insufficiently protected from tampering and unauthorized access Which actions must the Security Engineer take to address these audit findings? (Select THREE )
Your organization is preparing for a security assessment of your use of IAM. In preparation for this assessment, which three IAM best practices should you consider implementing?
Please select:
A company has two VPCs in the same AWS Region and in the same AWS account Each VPC uses a CIDR block that does not overlap with the CIDR block of the other VPC One VPC contains AWS Lambda functions that run inside a subnet that accesses the internet through a NAT gateway. The Lambda functions require access to a publicly accessible Amazon Aurora MySQL database that is running in the other VPC A security engineer determines that the Aurora database uses a security group rule that allows connections from the NAT gateway IP address that the Lambda functions use. The company's security policy states that no database should be publicly accessible.
What is the MOST secure way that the security engineer can provide the Lambda functions with access to the Aurora database?
Your company has a set of EC2 Instances defined in IAM. They need to ensure that all traffic packets are monitored and inspected for any security threats. How can this be achieved? Choose 2 answers from the options given below Please select:
Amazon.AWS-Security-Specialty.v2024-01-11.q331
Jan 11, 2024
Amazon.AWS-Security-Specialty.v2023-02-20.q450
Feb 20, 2023
Amazon.AWS-Security-Specialty.v2022-09-02.q399
Sep 02, 2022
Amazon.AWS-Security-Specialty.v2022-07-14.q194
Jul 14, 2022
Enter your email address to download Amazon.AWS-Security-Specialty.premium Dumps