Application Access, Monitoring and Compliance Controls
This topic covers CloudTrail, CloudWatch logs, Config, GuardDuty, Security Hub, Inspector, access auditing, compliance evidence, and secure application entry points.
How to study for AWS Solutions Architect Associate
Treat each question as an architecture tradeoff: identify security boundaries, failure modes, performance needs, data paths, and cost constraints before choosing services.
Core concepts
Concept 1
Application Access, Monitoring and Compliance Controls questions reward architecture tradeoff reasoning rather than picking the most familiar AWS service.
Exam cue: Identify the workload requirement, failure mode, data path, access boundary, and operational constraint.
Concept 2
The best answer maps requirements to security, resilience, performance, and cost constraints before choosing services.
Exam cue: Match the AWS service to the Well-Architected pillar the scenario is testing.
Concept 3
Eliminate answers that ignore shared responsibility, single points of failure, data movement, scaling behavior, or total cost.
Exam cue: Prefer managed, durable, least-privilege, multi-AZ, and right-sized designs when requirements call for them.
Risk pitfalls and guardrails
Choosing the most powerful service when a simpler managed service satisfies the requirement.
Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.
Solving performance while ignoring security, availability, or cost constraints stated in the scenario.
Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.
Assuming one Availability Zone, public access, or manual operations are acceptable without justification.
Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.
Memory anchors
CloudTrail
CloudTrail records AWS API activity and supports governance, audit, and investigation.
CloudWatch Logs
CloudWatch Logs collects and stores log data for monitoring and troubleshooting.
AWS Config
AWS Config records resource configuration history and evaluates compliance rules.
GuardDuty
GuardDuty uses threat intelligence and analytics to detect suspicious activity.
Security Hub
Security Hub aggregates and prioritizes security findings from AWS and partner services.
Inspector
Amazon Inspector assesses workloads for software vulnerabilities and unintended network exposure.
Access Analyzer
IAM Access Analyzer helps identify resources shared with external principals.
ALB Authentication
An Application Load Balancer can authenticate users with supported identity providers.
Compliance Evidence
Compliance evidence comes from logs, configuration history, reports, and controlled access.
Detective Control
A detective control identifies events or drift so teams can respond.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A consumer web application needs sign-up, password reset, MFA, and JWT tokens for its APIs. Which service should provide the user directory?
Authenticated mobile users must upload photos directly to a user-specific S3 prefix without receiving long-term AWS credentials. Which design fits?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
