views
We learned that a majority of the candidates for the exam are office workers or students who are occupied with a lot of things, and do not have plenty of time to prepare for the AWS-Security-Specialty exam. Taking this into consideration, we have tried to improve the quality of our AWS-Security-Specialty training materials for all our worth. Now, I am proud to tell you that our AWS-Security-Specialty Exam Questions are definitely the best choice for those who have been yearning for success but without enough time to put into it. Just buy them and you will pass the exam by your first attempt!
In this fast-changing world, the requirements for jobs and talents are higher, and if people want to find a job with high salary they must boost varied skills which not only include the good health but also the working abilities. The AWS-Security-Specialty exam torrent is compiled by the experienced professionals and of great value. You can master them fast and easily. We provide varied versions for you to choose and you can find the most suitable version of AWS-Security-Specialty Exam Materials. So it is convenient for the learners to master the AWS Certified Security questions torrent and pass the exam in a short time.
>> Latest Amazon AWS-Security-Specialty Learning Materials <<
Upgrade Amazon AWS-Security-Specialty Dumps - Official AWS-Security-Specialty Practice Test
The Amazon desktop practice test software and web-based Understanding AWS Certified Security - Specialty AWS-Security-Specialty practice test both simulate the actual exam environment and identify your mistakes. With these two Amazon AWS-Security-Specialty practice exams, you will get the actual AWS-Security-Specialty Exam environment. Whereas the FreeDumps PDF file is ideal for restriction-free test preparation. You can open this PDF file and revise AWS-Security-Specialty real exam questions at any time.
Amazon AWS Certified Security - Specialty Sample Questions (Q138-Q143):
NEW QUESTION # 138
A company has multiple production AWS accounts. Each account has AWS CloudTrail configured to log to a single Amazon S3 bucket in a central account. Two of the production accounts have trails that are not logging anything to the S3 bucket.
Which steps should be taken to troubleshoot the issue? (Choose three.)
- A. Verify that the S3 bucket policy allows access for CloudTrail from the production AWS account IDs.
- B. Confirm in the CloudTrail Console that each trail is active and healthy.
- C. Verify that the log file prefix is set to the name of the S3 bucket where the logs should go.
- D. Open the global CloudTrail configuration in the master account, and verify that the storage location is set to the correct S3 bucket.
- E. Create a new CloudTrail configuration in the account, and configure it to log to the account's S3 bucket.
- F. Confirm in the CloudTrail Console that the S3 bucket name is set correctly.
Answer: A,B,F
NEW QUESTION # 139
A Software Engineer is trying to figure out why network connectivity to an Amazon EC2 instance does not appear to be working correctly. Its security group allows inbound HTTP traffic from 0.0.0.0/0, and the outbound rules have not been modified from the default. A custom network ACL associated with its subnet allows inbound HTTP traffic from 0.0.0.0/0 and has no outbound rules.
What would resolve the connectivity issue?
- A. The outbound rules on the security group do not allow the response to be sent to the client on the HTTP port.
- B. The outbound rules on the security group do not allow the response to be sent to the client on the ephemeral port range.
- C. An outbound rule must be added to the network ACL to allow the response to be sent to the client on the HTTP port.
- D. An outbound rule must be added to the network ACL to allow the response to be sent to the client on the ephemeral port range.
Answer: C
NEW QUESTION # 140
A company has Windows Amazon EC2 instances in a VPC that are joined to on-premises Active Directory servers for domain services. The security team has enabled Amazon GuardDuty on the AWS account to alert on issues with the instances.
During a weekly audit of network traffic, the Security Engineer notices that one of the EC2 instances is attempting to communicate with a known command-and-control server but failing. This alert does not show up in GuardDuty.
Why did GuardDuty fail to alert to this behavior?
- A. GuardDuty only monitors active network traffic flow for command-and-control activity.
- B. GuardDuty does not see these DNS requests.
- C. GuardDuty did not have the appropriate alerts activated.
- D. GuardDuty does not report on command-and-control activity.
Answer: A
NEW QUESTION # 141
You have a set of 100 EC2 Instances in an IAM account. You need to ensure that all of these instances are patched and kept to date. All of the instances are in a private subnet. How can you achieve this. Choose 2 answers from the options given below Please select:
- A. Use the Systems Manager to patch the instances
- B. Ensure an internet gateway is present to download the updates
- C. Ensure a NAT gateway is present to download the updates
- D. Use the IAM inspector to patch the updates
Answer: A,C
Explanation:
Explanation
Option C is invalid because the instances need to remain in the private:
Option D is invalid because IAM inspector can only detect the patches
One of the IAM Blogs mentions how patching of Linux servers can be accomplished. Below is the diagram representation of the architecture setup
For more information on patching Linux workloads in IAM, please refer to the Lin.
https://IAM.amazon.com/blogs/security/how-to-patch-linux-workloads-on-IAMj The correct answers are: Ensure a NAT gateway is present to download the updates. Use the Systems Manager to patch the instances Submit your Feedback/Queries to our Experts
NEW QUESTION # 142
An application running on Amazon EC2 instances generates log files in a folder on a Linux file system. The instances block access to the console and file transfer utilities, such as Secure Copy Protocol (SCP) and Secure File Transfer Protocol (SFTP). The Application Support team wants to automatically monitor the application log files so the team can set up notifications in the future.
A Security Engineer must design a solution that meets the following requirements:
* Make the log files available through an IAM managed service.
* Allow for automatic monitoring of the logs.
* Provide an Interlace for analyzing logs.
* Minimize effort.
Which approach meets these requirements