Module 8 Quiz
1. An issue is labeled as an incident until it is proven to be a security
failing
False
2. Incident response plans are something that were created for cloud
environments and do not apply to on-premise only or hybrid
environments.
False
3. Which of the following are stages of an incident response plan?
Select all that apply. All correct answers must be selected for credit.
Preparation
identification
containment
investigation
eradication
recovery
follow-up
4. Which stage of an incident response plan is focused on returning to
normal business operations and restoring your services?
Recovery
5. The follow up stage of the incident response process is used to
improve which of the following?
Your internal organizational assets
Your defenses to block your adversary’s tools
The IRP
6. Which of the following AWS services helps protect your environment
against attacks but has a one ear minimum commitment and a
monthly fee of $3,000?
AWS Shield Advanced
7. Which of the following AWS services protects web servers against
layer 3 and layer 4 network based attacks?
AWS Shield Standard
AWS WAF
AWS Shield
8. Which of the following does AWS Firewall Manager simplify
administration and maintenance for?
, AWS WAF or WAF Classic
AWS Shield Advanced
Amazon VPC Security Groups
9. Which of the following AWS services tracks and records changes
made over time to AWS resources and uses rules to compare desired
configuration to current modications?
AWS Config
10. Amazon Detective is one of the few AWS services that can
read and report on your data contents to protect you and your
organization.
False
11. Which of the following methods of identifying events involves
an external party reaching out to you to report a security issue?
Logs and Monitors
AWS Outreach
One-time contact
12. It is your responsibility as the cloud customer to investigate
and remediate cases of unintentional abuse.
True
13. AWS will delete CloudWatch logs that aggregate for over 2
years as a default. It is customer responsibility to change this setting
if they need to keep logs longer for regulatory or compliance
requirements.
False
14. Which of the following logging tools provided by AWS records
API calls only?
Amazon CloudTrail
15. An agent is required to gather information directly from an
instance if you are using AWS inspector.
True
1. An issue is labeled as an incident until it is proven to be a security
failing
False
2. Incident response plans are something that were created for cloud
environments and do not apply to on-premise only or hybrid
environments.
False
3. Which of the following are stages of an incident response plan?
Select all that apply. All correct answers must be selected for credit.
Preparation
identification
containment
investigation
eradication
recovery
follow-up
4. Which stage of an incident response plan is focused on returning to
normal business operations and restoring your services?
Recovery
5. The follow up stage of the incident response process is used to
improve which of the following?
Your internal organizational assets
Your defenses to block your adversary’s tools
The IRP
6. Which of the following AWS services helps protect your environment
against attacks but has a one ear minimum commitment and a
monthly fee of $3,000?
AWS Shield Advanced
7. Which of the following AWS services protects web servers against
layer 3 and layer 4 network based attacks?
AWS Shield Standard
AWS WAF
AWS Shield
8. Which of the following does AWS Firewall Manager simplify
administration and maintenance for?
, AWS WAF or WAF Classic
AWS Shield Advanced
Amazon VPC Security Groups
9. Which of the following AWS services tracks and records changes
made over time to AWS resources and uses rules to compare desired
configuration to current modications?
AWS Config
10. Amazon Detective is one of the few AWS services that can
read and report on your data contents to protect you and your
organization.
False
11. Which of the following methods of identifying events involves
an external party reaching out to you to report a security issue?
Logs and Monitors
AWS Outreach
One-time contact
12. It is your responsibility as the cloud customer to investigate
and remediate cases of unintentional abuse.
True
13. AWS will delete CloudWatch logs that aggregate for over 2
years as a default. It is customer responsibility to change this setting
if they need to keep logs longer for regulatory or compliance
requirements.
False
14. Which of the following logging tools provided by AWS records
API calls only?
Amazon CloudTrail
15. An agent is required to gather information directly from an
instance if you are using AWS inspector.
True