1. Right Answer: D
Explanation: Trusted Advisor checks for compliance with the following security recommendations: Limited access to common administrative ports to only a small subset of addresses. This includes ports 22 (SSH), 23 (Telnet) 3389 (RDP), and 5500 (VNC). Limited access to common database ports. This includes ports 1433 (MSSQL Server), 1434 (MSSQL Monitor), 3306 (MySQL), Oracle (1521) and 5432 (PostgreSQL). Option A is partially correct but then you would need to write custom rules for this. The AWS(Amazon Web Service) trusted advisor can give you all of these checks on its dashboard Options C and D are invalid because these services don't provide these details For more information on the Trusted Advisor, please visit the following URL: https://aws.amazon.com/premiumsupport/trustedadvisor/
2. Right Answer: A,B
Explanation: The CMK keys themselves can only be used for encrypting data that is maximum 4KB in size. Hence it can be used for encrypting information such as passwords and RSA keys. Option A and B are invalid because the actual CMK key can only be used to encrypt small amounts of data and not large amount of data. You have to generate the data key from the CMK key in order to encrypt high amounts of data For more information on the concepts for KMS, please visit the following URL: https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html
3. Right Answer: C
Explanation:
4. Right Answer: B
Explanation:
5. Right Answer: C,D
Explanation: