โ† All AWS Flashcard Decks

Security & Compliance Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Compliance flashcards as text
  1. Which service records API calls and account activity for governance, compliance, and auditing?

    Answer: AWS CloudTrail

    AWS CloudTrail logs API calls and events across your account for audit and compliance.

  2. What does AWS Config primarily help you do?

    Answer: Assess and audit resource configurations

    AWS Config tracks resource configuration changes and evaluates them against desired rules.

  3. Which AWS service helps protect web applications from common exploits like SQL injection and XSS?

    Answer: AWS WAF

    AWS WAF lets you define rules to filter malicious web requests such as SQL injection and XSS.

  4. What level of DDoS protection does AWS Shield Standard provide?

    Answer: Automatic protection at no extra cost

    AWS Shield Standard is automatically enabled for all AWS customers at no additional charge.

  5. Which IAM policy element explicitly overrides any matching Allow statement?

    Answer: An explicit Deny

    In IAM, an explicit Deny always takes precedence over any Allow.

  6. Which service performs automated security assessments for software vulnerabilities and unintended network exposure on EC2 and container images?

    Answer: Amazon Inspector

    Amazon Inspector continuously scans workloads for vulnerabilities and network exposure.

  7. What is the recommended approach for granting an application running on EC2 access to S3?

    Answer: Attach an IAM role to the instance

    Attaching an IAM role provides temporary, automatically rotated credentials without storing keys.