AWS Security and IAM Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 AWS Security and IAM flashcards as text
Which AWS service continuously monitors and records API calls made in your AWS account for auditing purposes?
Answer: AWS CloudTrail
AWS CloudTrail records API calls and account activity as events, providing an audit trail for governance and compliance.
What is the function of AWS Secrets Manager compared to AWS Systems Manager Parameter Store?
Answer: Secrets Manager provides automatic secret rotation while Parameter Store requires manual rotation
AWS Secrets Manager natively supports automatic rotation of secrets like database passwords, whereas Parameter Store requires custom Lambda functions for rotation.
Which AWS KMS key type allows you to import your own key material and is managed entirely by you?
Answer: Customer Managed Key (CMK) with imported key material
Customer Managed Keys with imported key material let you bring your own cryptographic material while AWS KMS handles the infrastructure.
An application running in Account A needs to access an S3 bucket in Account B. What is the most efficient configuration?
Answer: Add a bucket policy in Account B that allows Account A's IAM role, then grant the role permission to assume cross-account access
Cross-account S3 access requires a bucket policy in the target account plus an IAM role or user in the source account with appropriate permissions.
Which GuardDuty finding type would indicate that an IAM user's credentials may be compromised?
Answer: UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B
The UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B finding indicates a successful console login from a potentially compromised or unusual location.
What is the primary purpose of AWS IAM Access Analyzer?
Answer: To identify resources shared with external entities outside your zone of trust
IAM Access Analyzer uses automated reasoning to identify resources like S3 buckets or IAM roles accessible from outside your account or organization.
A security team wants to enforce MFA for all IAM user console logins without modifying each user's individual policies. What is the best approach?
Answer: Use an SCP to deny all actions if MFA is not present
An SCP with a Deny effect for actions where aws:MultiFactorAuthPresent is false enforces MFA organization-wide without touching individual user policies.