exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 539 discussion

Exam question from Amazon's AWS-SysOps
Question #: 539
Topic #: 1
[All AWS-SysOps Questions]

The InfoSec team has asked the SysOps Administrator to perform some hardening on the company Amazon RDS database instances.
Based on this requirement, what actions should be recommended for the start of the security review? (Choose two.)

  • A. Use Amazon Inspector to present a detailed report of security vulnerabilities across the RDS database fleet
  • B. Review the security group's inbound access rules for least privilege
  • C. Export AWS CloudTrail entries detailing all SSH activity on the RDS instances
  • D. Use the cat command to enumerate the allowed SSH keys in ~/.ssh on each RDS instance
  • E. Report on the Parameter Group settings and ensure that encrypted connections are enforced
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 6 months ago
A should not be correct as Amazon Inspector checks the vulnerabilities for EC2 instances only. Not for RDS
upvoted 9 times
...
mukeshs
Highly Voted 2 years, 6 months ago
Answer should be B and E
upvoted 8 times
...
albert_kuo
Most Recent 10 months ago
Selected Answer: BE
B. Review the security group's inbound access rules for least privilege: It is important to review and ensure that the security group associated with the RDS instances has appropriate inbound access rules configured. This involves following the principle of least privilege, where only necessary and authorized sources are allowed to access the RDS instances. E. Report on the Parameter Group settings and ensure that encrypted connections are enforced: Parameter Groups in Amazon RDS are used to configure database engine settings. It is important to review the Parameter Group settings and ensure that encrypted connections (SSL/TLS) are enforced to secure the data in transit between the client and the RDS instances.
upvoted 1 times
...
kenkct
2 years, 6 months ago
A: Inspector only work for EC2 B. restrict SG inbound with least privilege is correct C. Cloudtrail is for monitoring D. Cat command not relevent E. Connection encryption is correct Answer: B & E
upvoted 5 times
...
holydrac
2 years, 6 months ago
https://www.mssqltips.com/sqlservertip/5967/enforce-ssl-for-connecting-to-aws-rds-instance-of-sql-server/
upvoted 3 times
...
sen12
2 years, 6 months ago
A is not possible since we need to install an agent on the EC2 instance, which we cant do it on RDS. So I will go with B and E as well.
upvoted 1 times
...
Pyt
2 years, 6 months ago
BE - RDS are managed by AWS only security group and parameters like ssl can by adjusted
upvoted 2 times
...
saumenP
2 years, 6 months ago
BE are correct
upvoted 4 times
...
omar_bahrain
2 years, 6 months ago
A is most probably correct . As per AWS doc. " Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.". I would say this among very early step to harden
upvoted 2 times
exbash
2 years, 6 months ago
That only applies to EC2 instances and not RDS. When you see Amazon Inspector, think EC2
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago