← All CLF-C02 Flashcard Decks

Security & Compliance in the Cloud Flashcards

7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Compliance in the Cloud flashcards as text
  1. Which encryption option allows Amazon S3 to manage the encryption keys on behalf of the customer?

    Answer: SSE-S3

    SSE-S3 (Server-Side Encryption with S3-managed keys) lets S3 handle key management entirely on the customer's behalf.

  2. A developer accidentally committed AWS access keys to a public GitHub repository. What is the FIRST action they should take?

    Answer: Rotate or deactivate the compromised access keys immediately

    Immediately rotating or deactivating the exposed access keys prevents unauthorized use before any damage can be done.

  3. Which AWS service enables you to evaluate the security and compliance of your EC2 instances against predefined rules and best practices?

    Answer: Amazon Inspector

    Amazon Inspector automatically assesses EC2 instances and container images for software vulnerabilities and unintended network exposure.

  4. What is the primary purpose of AWS Artifact?

    Answer: To provide on-demand access to AWS compliance reports and agreements

    AWS Artifact is a self-service portal for on-demand access to AWS security and compliance reports such as SOC, PCI, and ISO certifications.

  5. Which principle states that users and systems should be granted only the minimum permissions necessary to perform their required tasks?

    Answer: Least privilege

    The principle of least privilege means granting only the permissions needed to perform a specific task, reducing the attack surface.

  6. Which AWS service can automatically remediate non-compliant AWS resource configurations based on defined rules?

    Answer: AWS Config

    AWS Config can evaluate resource configurations against rules and trigger automated remediation actions for non-compliant resources.

  7. A company wants to protect their web application from common exploits like SQL injection and cross-site scripting. Which AWS service should they use?

    Answer: AWS WAF

    AWS WAF (Web Application Firewall) filters HTTP/HTTPS traffic and protects against common web exploits like SQL injection and XSS.