Security & Compliance Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
Which AWS principle minimizes risk by granting only the permissions required to perform a task?
Answer: Least privilege
Least privilege grants only the minimum permissions needed, reducing the attack surface.
What does AWS Trusted Advisor provide regarding security?
Answer: Best-practice checks and recommendations
Trusted Advisor inspects your environment and recommends improvements including security best practices.
Which feature lets you keep your own keys with AWS managing the hardware security module for KMS?
Answer: Customer managed keys in KMS
Customer managed keys give you control over key policies and rotation within KMS.
What is the safest practice for IAM access keys that are no longer needed?
Answer: Delete or deactivate them
Unused access keys should be deactivated or deleted to reduce credential risk.
Which service aggregates and prioritizes security findings from multiple AWS security services?
Answer: AWS Security Hub
AWS Security Hub provides a centralized view of security alerts and compliance status across services.
What does enabling default encryption on an S3 bucket ensure?
Answer: All new objects are automatically encrypted
Default encryption ensures every new object uploaded to the bucket is encrypted automatically.
Which control helps prevent accidental public exposure of S3 buckets account-wide?
Answer: S3 Block Public Access
S3 Block Public Access settings override permissive policies to prevent unintended public access.