Security & Compliance in the Cloud Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Compliance in the Cloud flashcards as text
Which AWS service allows you to centrally manage AWS WAF rules, Security Groups, and Shield Advanced protections across multiple accounts in an organization?
Answer: AWS Firewall Manager
AWS Firewall Manager lets you centrally configure and manage firewall rules, WAF policies, and Shield Advanced protections across all accounts in AWS Organizations.
A company wants to verify that their AWS infrastructure changes never violate compliance rules in real time. Which service continuously monitors and records resource configurations?
Answer: AWS Config
AWS Config continuously monitors and records AWS resource configurations and evaluates them against desired compliance rules.
Which AWS service enables federated identity, allowing users to sign in with corporate credentials (e.g., Active Directory) to access AWS resources?
Answer: AWS Single Sign-On (IAM Identity Center)
AWS IAM Identity Center (formerly AWS SSO) enables federated access, allowing users to sign in with their corporate identity provider credentials to access AWS accounts.
What does 'encryption at rest' mean in the context of AWS security?
Answer: Data stored on disk or in a database is encrypted when not actively being used
Encryption at rest means that data stored on physical media (disks, databases, backups) is encrypted to protect it from unauthorized physical access.
Which AWS service provides hardware security modules (HSMs) in the cloud to generate and manage your own encryption keys with exclusive single-tenant access?
Answer: AWS CloudHSM
AWS CloudHSM provides dedicated, single-tenant HSM appliances in the cloud, giving customers exclusive control over their cryptographic keys.
A security team wants to analyze historical API activity across their AWS account to investigate a potential security incident. Which service provides this audit trail?
Answer: AWS CloudTrail
AWS CloudTrail records all API calls made in an AWS account, providing a complete audit trail for security investigations and compliance auditing.
Which of the following is a customer responsibility under the AWS Shared Responsibility Model when using Amazon RDS?
Answer: Configuring database user access controls and permissions
Customers are responsible for configuring database user access controls in RDS, while AWS manages the underlying infrastructure and database engine patching.