Skip to content

Detection Questions

Practice questions for Detection topic in AWS Certified Security - Specialty. 32 questions covering this domain.

32 questions8 easy17 medium7 hard
Q1
medium

A team wants broad, continuous visibility into where sensitive data might exist across its Amazon S3 estate before deciding which buckets need deeper ...

Q2
easy

A company needs a searchable, downloadable, and immutable record of the last 90 days of management events in a single AWS Region without first creatin...

Q3
easy

A security team enables Amazon GuardDuty in an AWS account for the first time. Which data sources does GuardDuty start analyzing automatically as foun...

Q4
hard

A security engineer wants to detect multi-stage attacks across multiple data sources in an AWS account without paying extra for that specific GuardDut...

Q5
hard

A responder integrates Amazon Detective with Amazon Security Lake. Which raw log sources does Detective begin pulling from Security Lake for querying ...

Q6
medium

A security operations team wants a centralized security data lake that normalizes AWS and third-party security events into a common schema and storage...

Q7
medium

A company enables AWS Security Hub CSPM today in one Region. GuardDuty produced findings in that Region last week. What should the team expect after e...

Q8
medium

A compliance team wants a service that continuously evaluates AWS resources as they are created, changed, or deleted and flags resources as noncomplia...

Q9
hard

A delegated administrator account in AWS Organizations enables Amazon GuardDuty across all member accounts and Regions. According to AWS guidance, wha...

Q10
medium

A team wants AWS Config to package a curated set of rules and remediation actions as a single deployable unit that can be applied across accounts in A...

Q11
medium

A security team wants Amazon Macie to perform a one-time deep scan of a specific Amazon S3 bucket for sensitive data using both managed and custom dat...

Q12
easy

Which AWS service provides a managed dashboard of standardized security best-practice checks (such as CIS, AWS Foundational Security Best Practices, a...

Q13
medium

Which AWS CloudTrail capability detects unusual write management API activity in an account by automatically modeling normal call volumes and surfacin...

Q14
easy

Which Amazon GuardDuty protection plan scans Amazon EBS volumes attached to EC2 instances and ECS workloads for malware when GuardDuty produces a susp...

Q15
medium

A team wants Amazon GuardDuty to continuously analyze container-level processes and network activity inside Amazon EKS, ECS on Fargate, and self-manag...

Q16
medium

A team wants AWS Config to evaluate noncompliant resources and automatically take a remediation action without requiring an external runbook. Which fe...

Q17
medium

A security engineer wants to detect when Amazon S3 GetObject API calls spike to an unusual volume, which may indicate data exfiltration. S3 data event...

Q18
hard

A SIEM team wants to normalize all AWS security events (GuardDuty findings, VPC Flow Logs, CloudTrail logs, Route 53 Resolver logs) into the Open Cybe...

Q19
easy

A security team wants to create custom patterns to detect specific proprietary data formats (such as employee ID or account codes) in Amazon S3 object...

Q20
medium

Which CloudWatch feature lets a team automatically create CloudWatch alarms based on the normal statistical patterns of a metric, rather than requirin...

Sign in to see all 32 questions

Create a free account to browse all questions — completely free during our launch phase.