Platform Assessment
Threat Detection
Auditing & Compliance
Key Management
Resilience & DNS
100

This AWS service automatically scans workloads for vulnerabilities and best practice deviations.

What is Amazon Inspector?

100

This AWS service uses ML and threat intel to detect anomalies and misconfigurations.

What is Amazon GuardDuty?

100

This AWS service logs all API calls and console activity for auditing.

What is AWS CloudTrail?

100

This Azure service stores keys, secrets, and certificates.

What is Azure Key Vault?

100

This AWS service provides DNS with health checks and failover.

What is Amazon Route 53?

200

Amazon Inspector integrates findings directly into this AWS service for centralized visibility.

What is AWS Security Hub?

200

A common misconfiguration GuardDuty can detect is overly permissive use of this IAM feature.

What are IAM roles or policies?

200

This AWS service tracks resource configurations and compliance status over time.

What is AWS Config?

200

Key Vault supports these two major types of key operations.

What are encryption and decryption (or key generation and key management)?

200

Route 53 health checks can monitor these three parameters.

What are HTTP/HTTPS responses, TCP connections, and CloudWatch alarms?

300

Inspector primarily evaluates these two resource types.

What are EC2 instances and container workloads (ECR images)?

300

This AWS service provides always-on protection from common network DDoS attacks.

What is AWS Shield Standard?

300

AWS Config evaluates resource states against these.

What are compliance rules (internal or managed rules)?

300

Key Vault integrates with this identity service for access control.

What is Azure Active Directory (Azure AD)?

300

Route 53 failover routing points users to this when the primary fails.

What is a secondary site (backup endpoint)?

400

True or False: Amazon Inspector requires agents to be manually installed on every instance.

What is False? (It uses the SSM agent automatically on supported instances.)

400

Shield Standard is free for these AWS services.

What are CloudFront and Elastic Load Balancing (and Route 53)?

400

Config findings can be sent here for centralized security management.

What is AWS Security Hub?

400

This feature of Key Vault helps organizations meet compliance by recording all access to keys.

What are audit logs?

400

Route 53 also supports latency-based and this type of routing for load distribution.

What is weighted routing?

500

Inspector complements GuardDuty because Inspector finds vulnerabilities, while GuardDuty identifies these.

What are threats/anomalous activity?

500

To get advanced DDoS protection and SLAs, customers must upgrade to this.

What is AWS Shield Advanced?

500

Trail shows who did what, while Config shows this.

What is how the resource is configured (and its history)?

500

True or False: Keys in Azure Key Vault can only be software-protected.

What is False? (They can also be HSM-protected.)

500

The combined use of health checks and DNS failover helps achieve this organizational goal.

What is high availability and resilience?