20 timed questions (~32 min, ~96 sec each). Underline force words before picking. Pair with the night guide.
1.Block SQLi on ALBs across many accounts.
2.Large DDoS on ELB/CloudFront apps.
3.Discover PII privacy issues in S3.
4.Customer keys; purge material from KMS; audit ≠ CloudTrail.
5.Encrypt EKS secrets in etcd.
6.IPv6 outbound only + traffic inspection.
7.SSH only from 110.238.98.71.
8.Auditor needs AWS compliance reports.
9.Master key + plaintext never sent to AWS for S3.
10.Private path to S3/DynamoDB; no NAT.
11.Detection vs prevention — GuardDuty is?
12.Multi-account reuse of WAF rules — add?
13.Encryption at rest fixing private routing?
14.Network Firewall primary association model?
15.Redis AUTH long-lived password needs?
16.Corporate AD groups already assign roles; console access via federation.
17.First question on a security stem?
18.Macie vs WAF for SQLi on ALB?
19.Shield Advanced vs WAF — volumetric DDoS keyword favors?
20.EBS encryption alone encrypts EKS etcd secrets?