Security & Compliance Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
Which service records API calls and account activity for governance, compliance, and auditing?
Answer: AWS CloudTrail
AWS CloudTrail logs API calls and events across your account for audit and compliance.
What does AWS Config primarily help you do?
Answer: Assess and audit resource configurations
AWS Config tracks resource configuration changes and evaluates them against desired rules.
Which AWS service helps protect web applications from common exploits like SQL injection and XSS?
Answer: AWS WAF
AWS WAF lets you define rules to filter malicious web requests such as SQL injection and XSS.
What level of DDoS protection does AWS Shield Standard provide?
Answer: Automatic protection at no extra cost
AWS Shield Standard is automatically enabled for all AWS customers at no additional charge.
Which IAM policy element explicitly overrides any matching Allow statement?
Answer: An explicit Deny
In IAM, an explicit Deny always takes precedence over any Allow.
Which service performs automated security assessments for software vulnerabilities and unintended network exposure on EC2 and container images?
Answer: Amazon Inspector
Amazon Inspector continuously scans workloads for vulnerabilities and network exposure.
What is the recommended approach for granting an application running on EC2 access to S3?
Answer: Attach an IAM role to the instance
Attaching an IAM role provides temporary, automatically rotated credentials without storing keys.