Skip to content

Data Protection Questions

Practice questions for Data Protection topic in AWS Certified Security - Specialty. 36 questions covering this domain.

36 questions8 easy19 medium9 hard
Q1
medium

A security architect wants full control over KMS key lifecycle and usage permissions for an encryption key used by applications and AWS services. Whic...

Q2
hard

An object version in Amazon S3 is protected by Object Lock in compliance mode until a future date. An administrator wants to shorten the retention per...

Q3
hard

A company uses S3 Cross-Region Replication for objects encrypted with a multi-Region KMS key and expects replication to avoid any re-encryption becaus...

Q4
medium

A compliance officer needs a retention mode in S3 Object Lock that prevents any user, including the AWS account root user, from deleting or shortening...

Q5
medium

A company wants to enforce backup plans across accounts in AWS Organizations, copy backups across accounts and Regions, and generate daily compliance ...

Q6
easy

A company wants write-once-read-many protection for objects in Amazon S3 so the objects cannot be deleted or overwritten for a retention period. Which...

Q7
easy

A team stores database credentials in AWS Secrets Manager and wants to avoid extra KMS key charges unless custom key control is required. Which encryp...

Q8
medium

A company needs single-tenant hardware security modules with full control over algorithms and keys, and it accepts more operational responsibility tha...

Q9
hard

A company needs to encrypt data in one AWS Region and decrypt it in another Region without re-encrypting the data or making a cross-Region call to AWS...

Q10
medium

Which Systems Manager Parameter Store parameter type encrypts the value with AWS KMS at rest and is the recommended choice for storing application sec...

Q11
hard

A regulated workload requires single-tenant FIPS 140-3 Level 3 hardware security modules with full administrative control over the HSM and cluster, in...

Q12
hard

An auditor requires that S3 objects in the EU only be decrypted by KMS keys that are themselves located in the EU, even though the bucket replicates o...

Q13
medium

An application requires double encryption of objects in Amazon S3 such that every object is encrypted twice with two different keys at the object leve...

Q14
easy

Which AWS KMS feature, when enabled on a customer-managed symmetric key, automatically rotates the key material every year while keeping the same key ...

Q15
medium

A developer needs to allow another AWS account to use a customer-managed KMS key for a limited time without modifying the key policy permanently. Whic...

Q16
easy

Which Amazon S3 feature reduces AWS KMS request volume and costs when many objects in the same bucket are encrypted with the same SSE-KMS key?

Q17
medium

A team wants AWS Secrets Manager to automatically rotate Amazon RDS database credentials on a schedule using a Lambda rotation function provided by AW...

Q18
medium

An ALB needs a public TLS certificate for a custom domain that is automatically renewed at no charge. Which AWS service provides this?

Q19
medium

A team needs to distribute an application secret (database password) to multiple Lambda functions across multiple AWS accounts in an organization with...

Q20
medium

A security team needs to prevent any IAM principal in the account from disabling S3 Object Lock or shortening the retention period on any object in a ...

Sign in to see all 36 questions

Create a free account to browse all questions — completely free during our launch phase.