โ† All CCP Flashcard Decks

AWS Cloud Security and Compliance Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 AWS Cloud Security and Compliance flashcards as text
  1. Which AWS service provides a managed firewall to filter malicious web traffic before it reaches your application?

    Answer: AWS WAF

    AWS WAF (Web Application Firewall) filters HTTP/HTTPS traffic based on rules you define to block common exploits like SQL injection and XSS.

  2. Which service continuously monitors AWS accounts and workloads for malicious activity using machine learning and threat intelligence?

    Answer: Amazon GuardDuty

    Amazon GuardDuty is a threat detection service that continuously analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify suspicious activity.

  3. Under the AWS Shared Responsibility Model, who is responsible for patching the guest operating system on an Amazon EC2 instance?

    Answer: The customer

    In the Shared Responsibility Model, customers manage the guest OS, including updates and patches, on EC2 instances.

  4. Which AWS service helps you discover and protect sensitive data, such as PII, stored in Amazon S3?

    Answer: Amazon Macie

    Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data stored in S3.

  5. Which AWS feature allows you to define fine-grained permissions for AWS users and roles using JSON policy documents?

    Answer: AWS IAM Policies

    IAM (Identity and Access Management) policies are JSON documents that define what actions are allowed or denied on which AWS resources.

  6. Which service provides on-demand access to AWS compliance reports such as SOC and PCI DSS documentation?

    Answer: AWS Artifact

    AWS Artifact is a self-service portal that gives you on-demand access to AWS compliance reports and agreements.