views
AmazonのAWS Certified Security - Specialtyガイド急流で試験に合格できない場合は、全額返金されます。 クライアントのみが試験証明書とスキャンコピーまたはAWS-Security-Specialty試験の不合格スコアのスクリーンショットを提供した場合、すぐにクライアントに返金します。 払い戻しの手順は非常に簡単です。 AWS-Security-Specialty試験問題についてJPTestKingクライアントに問題や疑念がある場合は、メールを送信するか、オンラインでお問い合わせください。できるだけ早くクライアントの問題に返信して解決します。
Amazon AWS-Security-Specialty 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
>> AWS-Security-Specialty試験復習赤本 <<
AWS-Security-Specialty試験 & AWS-Security-Specialty受験料
我々のAWS-Security-Specialty問題集はIT認定試験に関連する豊富な経験を持っているIT専門家によって研究された最新バージョンの試験参考書です。この問題集は全面的で的中率が超高いです。我々のAWS-Security-Specialty問題集はAmazonのリーダーです。そのほかに、我々はお客様の立場で商品を開発するという目的を持っていますから、あなたに利便性をもたらすために、我々は大好評を博しているAWS-Security-Specialty問題集を開発しました。
Amazon AWS Certified Security - Specialty 認定 AWS-Security-Specialty 試験問題 (Q258-Q263):
質問 # 258
During a recent security audit, it was discovered that multiple teams in a large organization have placed
restricted data in multiple Amazon S3 buckets, and the data may have been exposed. The auditor has
requested that the organization identify all possible objects that contain personally identifiable information
(PII) and then determine whether this information has been accessed.
What solution will allow the Security team to complete this request?
- A. Using Amazon Athena, query the impacted S3 buckets by using the PII query identifier function. Then,
create a new Amazon CloudWatch metric for Amazon S3 object access to alert when the objects are
accessed. - B. Enable Amazon Macie on the S3 buckets that were impacted, then perform data classification. For
identified objects that contain PII, use the research function for auditing AWS CloudTrail logs and S3
bucket logs for GET operations. - C. Enable Amazon GuardDuty and enable the PII rule set on the S3 buckets that were impacted, then
perform data classification. Using the PII findings report from GuardDuty, query the S3 bucket logs by
using Athena for GET operations. - D. Enable Amazon Inspector on the S3 buckets that were impacted, then perform data classification. For
identified objects that contain PII, query the S3 bucket logs by using Athena for GET operations.
正解:B
質問 # 259
A security engineer must develop an encryption tool for a company. The company requires a cryptographic solution that supports the ability to perform cryptographic erasure on all resources protected by the key material in 15 minutes or less Which AWS Key Management Service (AWS KMS) key solution will allow the security engineer to meet these requirements?
- A. Use Imported key material with CMK
- B. Use an AWS managed CMK.
- C. Use an AWS KMS CMK
- D. Use an AWS KMS customer managed CMK
正解:B
質問 # 260
The CFO of a company wants to allow one of his employees to view only the IAM usage report page. Which of the below mentioned IAM policy statements allows the user to have access to the IAM usage report page?
Please select:
- A. "Effect": "Allow". "Action": ["Describe"], "Resource": "Billing"
- B. "Effect": "Allow", "Action": ["IAM-portal: ViewBilling"], "Resource": "*"
- C. "Effect": "Allow", "Action": ["AccountUsage], "Resource": "*"
- D. "Effect': "Allow", "Action": ["IAM-portal:ViewUsage"," IAM-portal:ViewBilling"], "Resource": "*"
正解:D
解説:
Explanation
the IAM documentation, below is the access required for a user to access the Usage reports page and as per this, Option C is the right answer.
質問 # 261
A company is running workloads in a single IAM account on Amazon EC2 instances and Amazon EMR clusters a recent security audit revealed that multiple Amazon Elastic Block Store (Amazon EBS) volumes and snapshots are not encrypted The company's security engineer is working on a solution that will allow users to deploy EC2 Instances and EMR clusters while ensuring that all new EBS volumes and EBS snapshots are encrypted at rest. The solution must also minimize operational overhead Which steps should the security engineer take to meet these requirements?
- A. Use the IAM Management Console or IAM CLi to enable encryption by default for EBS volumes in each IAM Region where the company operates.
- B. Create an IAM Config rule to evaluate the conguration of each EC2 instance on creation or modication.
Have the IAM Cong rule trigger an IAM Lambdafunction to alert the security team and terminate the instance it the EBS volume is not encrypted. 5 - C. Create an Amazon Event Bridge (Amazon Cloud watch Events) event with an EC2 instance as the source and create volume as the event trigger. When the event is triggered invoke an IAM Lambda function to evaluate and notify the security engineer if the EBS volume that was created is not encrypted.
- D. Use a customer managed IAM policy that will verify that the encryption ag of the Createvolume context is set to true. Apply this rule to all users.
正解:A
質問 # 262
You have a set of 100 EC2 Instances in an AWS account. You need to ensure that all of these instances are patched and kept to date. All of the instances are in a private subnet. How can you achieve this. Choose 2 answers from the options given below Please select:
- A. Use the Systems Manager to patch the instances
- B. Use the AWS inspector to patch the updates
- C. Ensure an internet gateway is present to download the updates
- D. Ensure a NAT gateway is present to download the updates
正解:A、D
解説:
Option C is invalid because the instances need to remain in the private:
Option D is invalid because AWS inspector can only detect the patches
One of the AWS Blogs mentions how patching of Linux servers can be accomplished. Below is the diagram representation of the architecture setup
For more information on patching Linux workloads in AWS, please refer to the Lin.
https://aws.amazon.com/blogs/security/how-to-patch-linux-workloads-on-awsj The correct answers are: Ensure a NAT gateway is present to download the updates. Use the Systems Manager to patch the instances Submit your Feedback/Queries to our Experts
質問 # 263
......
私はあなたがAWS-Security-Specialty試験に合格したいことを知っています。 私たちのAWS-Security-Specialty学習教材は、多くの人が試験に合格するのを助け、あなたを助けようと思います。私たちのAWS-Security-Specialty学習教材の99%の合格率は高いです。また、あなたの自分の努力が必要です。 そして、私たちのAWS-Security-Specialty試験問題を利用すれば、あなたは絶対試験に合格できます。
AWS-Security-Specialty試験: https://www.jptestking.com/AWS-Security-Specialty-exam.html