โ† All CLF-C02 Flashcard Decks

Security and Compliance Flashcards

7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Compliance flashcards as text
  1. Which AWS service allows you to create and manage encryption keys used to protect your data, with options for both AWS-managed and customer-managed keys?

    Answer: AWS Key Management Service (KMS)

    AWS KMS is a managed service for creating and controlling cryptographic keys used to encrypt data across AWS services and custom applications.

  2. What is the key difference between AWS KMS and AWS CloudHSM?

    Answer: CloudHSM provides dedicated hardware security modules giving the customer full key control, while KMS is a shared multi-tenant service

    CloudHSM provides single-tenant, dedicated hardware security modules where the customer has exclusive control of the keys, unlike KMS which operates on shared AWS-managed infrastructure.

  3. Which of the following statements about AWS IAM roles is correct?

    Answer: IAM roles provide temporary security credentials and can be assumed by users, services, or applications

    IAM roles provide temporary, automatically rotated credentials and can be assumed by AWS services, applications, users, or even external identity providers.

  4. A company is using AWS and wants to ensure their usage meets HIPAA compliance requirements. What is the FIRST step they should take?

    Answer: Sign a Business Associate Agreement (BAA) with AWS

    To operate HIPAA-eligible workloads on AWS, customers must first sign a Business Associate Agreement (BAA) with AWS, which can be done through AWS Artifact.

  5. Which AWS service enables you to filter and monitor HTTP/HTTPS traffic to your web applications to protect against common exploits like SQL injection and cross-site scripting?

    Answer: AWS WAF (Web Application Firewall)

    AWS WAF is a web application firewall that lets you create rules to allow, block, or monitor web requests based on conditions you define, protecting against OWASP top-10 threats.

  6. What does enabling MFA (Multi-Factor Authentication) on an AWS root account protect against?

    Answer: Account takeover if the root account password is compromised

    MFA on the root account adds a second authentication factor so that even if the password is stolen, an attacker cannot access the account without the physical MFA device or app.

  7. Which AWS service continuously monitors and records AWS resource configurations, enabling compliance auditing and change tracking?

    Answer: AWS Config

    AWS Config continuously records resource configuration changes and evaluates them against desired configurations, providing a configuration history and compliance timeline.