← All ACL Flashcard Decks

Cloud Security Architecture Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cloud Security Architecture flashcards as text
  1. Which cloud ACL model evaluates permissions at the resource level rather than at the identity level?

    Answer: Resource-Based Policy

    Resource-based policies are attached directly to cloud resources (e.g., S3 buckets) and define who can access that specific resource.

  2. In AWS, which service acts as the central ACL enforcement point for cross-account resource access?

    Answer: AWS IAM with resource-based policies

    IAM resource-based policies with Principal elements allow cross-account access by explicitly naming trusted accounts or roles.

  3. A Security Group in AWS is best described as which type of access control?

    Answer: Stateful virtual firewall ACL

    Security Groups are stateful, meaning return traffic is automatically allowed without explicit outbound rules for established connections.

  4. What is the primary difference between AWS Network ACLs and Security Groups in cloud architecture?

    Answer: NACLs operate at the subnet level and are stateless; Security Groups operate at the instance level and are stateful

    NACLs process rules in numbered order at the subnet boundary and are stateless, while Security Groups are stateful and apply per-instance.

  5. In a Zero Trust cloud architecture, which principle governs how ACLs should be applied to internal network segments?

    Answer: Never trust, always verify — apply least-privilege ACLs everywhere

    Zero Trust mandates that no traffic is implicitly trusted regardless of network location, requiring explicit ACL verification for every connection.

  6. Which cloud ACL feature allows administrators to define maximum permission boundaries for IAM entities without granting those permissions directly?

    Answer: Permission Boundaries

    Permission Boundaries set the maximum permissions an IAM entity can have, but the entity still needs identity-based policies to actually use those permissions.

  7. In GCP, which construct is equivalent to AWS Security Groups for controlling VM-level network traffic?

    Answer: VPC firewall rules with target tags or service accounts

    GCP VPC firewall rules applied via network tags or service accounts control ingress/egress traffic at the VM instance level.