The official exam guide breaks this domain into 3 objectives:
A drill pulls every published question in this domain and grades each one as you go. Flashcards skip the grading entirely — read the stem, flip when you're ready, move on.
A compliance rule requires that log data stored in Amazon CloudWatch Logs be encrypted with a key the company manages. What should the team do?
CloudWatch Logs can encrypt a log group at rest with a customer managed KMS key, meeting the requirement. Moving to an unencrypted bucket removes encryption, TLS covers transit not rest, and disabling retention destroys the logs rather than protecting them.
A team needs to capture metadata about accepted and rejected IP traffic to and from network interfaces in a VPC for troubleshooting and forensics. What should they enable?
VPC Flow Logs capture metadata about accepted and rejected traffic on network interfaces and can be sent to CloudWatch Logs or S3. CloudTrail records API calls, Config records configuration, and GuardDuty DNS logging covers only DNS queries.
Unofficial study aid. Not affiliated with, endorsed by, or sponsored by Amazon Web Services.