Skip to content

Security Foundations and Governance Questions

Practice questions for Security Foundations and Governance topic in AWS Certified Security - Specialty. 28 questions covering this domain.

28 questions8 easy14 medium6 hard
Q1
medium

A platform team wants a configurable account template that standardizes the provisioning of new AWS accounts with pre-approved configurations inside a...

Q2
medium

A team wants a single CloudFormation template to deploy baseline security resources consistently across multiple AWS accounts and Regions from a centr...

Q3
medium

A compliance team wants a service that uses prebuilt frameworks, automatically collects evidence for in-scope AWS accounts on an ongoing basis, and he...

Q4
easy

An auditor asks for AWS compliance reports and agreements that can be downloaded at no additional cost and submitted as audit artifacts. Which AWS ser...

Q5
easy

A company is scaling its AWS environment and wants the recommended boundary for permission, security, costs, and workloads, while centrally creating a...

Q6
medium

A management account administrator attaches a restrictive service control policy at the organization root and expects it to limit permissions in the m...

Q7
medium

A team writes an SCP and assumes that it will grant the permissions users need as long as the SCP allows those actions. Why is this assumption incorre...

Q8
medium

A team wants AWS Trusted Advisor to surface security checks beyond the seven core checks available at the basic support level. Which prerequisite is r...

Q9
medium

A compliance team needs to deploy a baseline set of resources (CloudTrail trail, Config recorder, IAM password policy) consistently to every account i...

Q10
medium

A platform team wants developers to self-service launch only pre-approved, security-vetted infrastructure templates (with parameter constraints and IA...

Q11
easy

Which AWS Control Tower feature applies preventive and detective rules across all accounts in a Control Tower organization, mapped to controls like CI...

Q12
hard

An organization deploys workloads across multiple Regions and accounts, and wants AWS to provide an opinionated multi-account environment with org set...

Q13
hard

Auditors require evidence that an organization's AWS environment meets a specific compliance framework, with controls automatically mapped to AWS data...

Q14
easy

Which AWS service consolidates AWS Config configuration and compliance data from many accounts and Regions into a single account view?

Q15
medium

A company creates a new AWS account through AWS Control Tower Account Factory. The account is automatically enrolled in the organization and the landi...

Q16
medium

A compliance officer requests evidence that a specific Amazon EC2 instance maintained its approved configuration (no open ports other than 443) over t...

Q17
easy

Which AWS service provides a centralized catalog of prebuilt and custom security and operational controls mapped to frameworks such as NIST CSF, CIS, ...

Q18
hard

A company uses AWS Organizations. An SCP at the root OU allows all services, but an SCP on a child OU denies EC2 actions. A developer in an account wi...

Q19
medium

A team uses AWS Organizations and wants to prevent any member account from leaving the organization without management account approval. Which SCP act...

Q20
hard

A large enterprise wants a managed solution that automatically provisions a secure multi-account AWS environment, enrolls new accounts with a pre-appr...

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.