AWS CCP Exam Questions with Correct Answers
Question 1:
AWS Artifact
Answer:
Download AWS security and compliance documents, provide them to regulators, and inform
your cloud architecture.
Question 2:
Audit manager
Answer:
Automate assessments against frameworks designed to meet common
Question 3:
Provides pre-build auditing frameworks to meet industry standards:
-HIPAA
-NIST Cybersecurity
-AWS Operational Best Practices
Answer:
Find root causes of noncompliance and generate reports.
-Many more
Question 4:
Security Token Service
Answer:
AWS STS enables you to request temporary credentials for users such as auditors
Question 5:
FIPS 140-2 level 3
Answer:
KMS is not compliant you will have to use CloudHSM
,Question 6:
HIPAA
Answer:
Cannot transfer data over public web, must use Snowball Edge
Question 7:
AWS Control Tower
Answer:
Automate account creation and the application of best-practice Config rules and SCPs(service
control policies)
Question 8:
AWS Trusted Advisor
Answer:
Gives you advice or best practice suggestions for all kinds of things.
Performance, Cost Optimization, Service Limits, Security, Operational Excellence, Fault
Tolerance
Question 9:
Amazon GuardDuty
Answer:
Collects activity logs from around AWS and uses machine learning to intelligently detect
threats; detects active threats
Question 10:
Amazon Detective
Answer:
Used to investigate security events that have already happened
Question 11:
Amazon Inspector
Answer:
contunuously scans your workloads for software vulnerabilities and network exposure
,Question 12:
Security Hub
Answer:
Aggregate findings across your AWS ecosystem. Prioritize security events and determine the
best way to take action.
Question 13:
review shared responsibility model
Answer:
The customer is responsible for security IN the cloud, AWS is responsible for security OF the
cloud
Question 14:
The Well-Architected Framework:Security
Answer:
Identity and Access Management, Data Stewardshipand Encryption, Network Security,
Application Security, Compliance, Security Management
Question 15:
The Well-Architected Framework:Security
Answer:
Identity and Access Management, Data Stewardship
Question 16:
Amazon Macie
Answer:
Amazon Macie searches your S3 buckets for PII(Personally identifiable information) uses
machine learning
Question 17:
EBS volume + RDS encryption
Answer:
EBS volumes are encrypted using Key Management
, Question 18:
Service(KMS), To encrypt an existing RDS instance, you must create a copy and encrypt the
copy. Parameter Store
Answer:
Systems Manager Parameter Store can keep encrypted secrets like login credentials or
environment variables
Question 19:
Secrets Manager
Answer:
adds another layer of security by allowing automatic rotation of your secrets
Question 20:
AWS WAF(Web Appliation Firewall)
Answer:
protects your web applications
Question 21:
Network Firewall
Answer:
Protects your AWS network
Question 22:
AWS Shield
Answer:
protects against DDoS attacts
Question 23:
AWS Firewall Manager
Answer:
manages AWS Shield, Network Firewall, and AWS WAF(Web Application Firewall)
Question 1:
AWS Artifact
Answer:
Download AWS security and compliance documents, provide them to regulators, and inform
your cloud architecture.
Question 2:
Audit manager
Answer:
Automate assessments against frameworks designed to meet common
Question 3:
Provides pre-build auditing frameworks to meet industry standards:
-HIPAA
-NIST Cybersecurity
-AWS Operational Best Practices
Answer:
Find root causes of noncompliance and generate reports.
-Many more
Question 4:
Security Token Service
Answer:
AWS STS enables you to request temporary credentials for users such as auditors
Question 5:
FIPS 140-2 level 3
Answer:
KMS is not compliant you will have to use CloudHSM
,Question 6:
HIPAA
Answer:
Cannot transfer data over public web, must use Snowball Edge
Question 7:
AWS Control Tower
Answer:
Automate account creation and the application of best-practice Config rules and SCPs(service
control policies)
Question 8:
AWS Trusted Advisor
Answer:
Gives you advice or best practice suggestions for all kinds of things.
Performance, Cost Optimization, Service Limits, Security, Operational Excellence, Fault
Tolerance
Question 9:
Amazon GuardDuty
Answer:
Collects activity logs from around AWS and uses machine learning to intelligently detect
threats; detects active threats
Question 10:
Amazon Detective
Answer:
Used to investigate security events that have already happened
Question 11:
Amazon Inspector
Answer:
contunuously scans your workloads for software vulnerabilities and network exposure
,Question 12:
Security Hub
Answer:
Aggregate findings across your AWS ecosystem. Prioritize security events and determine the
best way to take action.
Question 13:
review shared responsibility model
Answer:
The customer is responsible for security IN the cloud, AWS is responsible for security OF the
cloud
Question 14:
The Well-Architected Framework:Security
Answer:
Identity and Access Management, Data Stewardshipand Encryption, Network Security,
Application Security, Compliance, Security Management
Question 15:
The Well-Architected Framework:Security
Answer:
Identity and Access Management, Data Stewardship
Question 16:
Amazon Macie
Answer:
Amazon Macie searches your S3 buckets for PII(Personally identifiable information) uses
machine learning
Question 17:
EBS volume + RDS encryption
Answer:
EBS volumes are encrypted using Key Management
, Question 18:
Service(KMS), To encrypt an existing RDS instance, you must create a copy and encrypt the
copy. Parameter Store
Answer:
Systems Manager Parameter Store can keep encrypted secrets like login credentials or
environment variables
Question 19:
Secrets Manager
Answer:
adds another layer of security by allowing automatic rotation of your secrets
Question 20:
AWS WAF(Web Appliation Firewall)
Answer:
protects your web applications
Question 21:
Network Firewall
Answer:
Protects your AWS network
Question 22:
AWS Shield
Answer:
protects against DDoS attacts
Question 23:
AWS Firewall Manager
Answer:
manages AWS Shield, Network Firewall, and AWS WAF(Web Application Firewall)