Cloud Security Architecture Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Architecture flashcards as text
What happens when both an AWS Identity-Based Policy and a Resource-Based Policy exist for the same action, and neither has an explicit Deny?
Answer: Access is granted if either policy allows it
When both policy types exist without explicit denies, access is granted if either the identity-based or resource-based policy allows the action.
Which AWS Organization feature allows enforcing ACL guardrails across all member accounts simultaneously?
Answer: Service Control Policies (SCPs)
SCPs applied at the AWS Organization level create guardrails that restrict what actions member accounts can perform, even for their root users.
A cloud ACL rule with a lower rule number is evaluated before a rule with a higher number. What should the last rule in an AWS NACL always be?
Answer: An explicit deny-all rule (*)
AWS NACLs include an implicit deny-all at rule number *, which blocks any traffic not matched by earlier explicit rules.
In cloud security architecture, what does 'micro-segmentation' achieve that traditional perimeter ACLs cannot?
Answer: Granular east-west traffic controls between individual workloads
Micro-segmentation applies ACL controls between individual workloads inside the data center or cloud VPC, limiting lateral movement after a breach.
Which cloud-native control enforces ACLs on API calls to cloud management planes rather than on data-plane network traffic?
Answer: IAM policies
IAM policies control access to cloud provider APIs (management plane), whereas network ACLs and firewalls govern data-plane traffic flows.
What is the recommended practice when an S3 bucket ACL conflicts with a bucket policy in AWS?
Answer: AWS evaluates both, and an explicit deny in either will block access
AWS evaluates all applicable policies together; an explicit Deny in any policy (ACL or bucket policy) overrides all Allows.
In Azure, which resource acts as the cloud equivalent of a network ACL applied at the subnet level?
Answer: Network Security Group (NSG)
Azure NSGs contain inbound and outbound security rules that filter traffic at the subnet or NIC level using priority-ordered rules.