โ† All CLF-C02 Flashcard Decks

Security & Compliance in the Cloud Flashcards

7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Compliance in the Cloud flashcards as text
  1. Which AWS service provides a managed threat detection capability that analyzes CloudTrail, VPC Flow Logs, and DNS logs to identify malicious activity?

    Answer: Amazon GuardDuty

    Amazon GuardDuty is a managed threat detection service that continuously analyzes CloudTrail, VPC Flow Logs, and DNS logs to identify threats.

  2. A company needs to ensure that only approved AWS services can be used across all accounts in their organization. Which AWS service enables this policy enforcement?

    Answer: AWS Organizations with Service Control Policies

    AWS Organizations with Service Control Policies (SCPs) allows you to centrally control the maximum permissions available to all accounts in your organization.

  3. Which AWS service helps customers discover, classify, and protect sensitive data such as PII stored in Amazon S3?

    Answer: Amazon Macie

    Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data like PII in Amazon S3.

  4. Under the AWS Shared Responsibility Model, patching the guest operating system on an Amazon EC2 instance is the responsibility of:

    Answer: The customer

    The customer is responsible for patching the guest OS on EC2 instances; AWS only manages the underlying infrastructure.

  5. Which feature of AWS IAM allows you to grant temporary security credentials to trusted entities without creating long-term IAM users?

    Answer: IAM Roles

    IAM Roles provide temporary security credentials to trusted entities such as EC2 instances, Lambda functions, or federated users.

  6. What does the AWS penetration testing policy require customers to do before conducting penetration tests on their AWS environment?

    Answer: No prior approval is required for tests on permitted services

    AWS no longer requires prior approval for penetration testing on a defined list of permitted services owned by the customer.

  7. Which AWS service provides a central location to manage security alerts and compliance status across multiple AWS accounts and services?

    Answer: AWS Security Hub

    AWS Security Hub aggregates, organizes, and prioritizes security alerts and compliance findings from multiple AWS services and third-party tools.