โ† All ACL Flashcard Decks

Cloud Security Architecture Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Security Architecture flashcards as text
  1. What happens when both an AWS Identity-Based Policy and a Resource-Based Policy exist for the same action, and neither has an explicit Deny?

    Answer: Access is granted if either policy allows it

    When both policy types exist without explicit denies, access is granted if either the identity-based or resource-based policy allows the action.

  2. Which AWS Organization feature allows enforcing ACL guardrails across all member accounts simultaneously?

    Answer: Service Control Policies (SCPs)

    SCPs applied at the AWS Organization level create guardrails that restrict what actions member accounts can perform, even for their root users.

  3. A cloud ACL rule with a lower rule number is evaluated before a rule with a higher number. What should the last rule in an AWS NACL always be?

    Answer: An explicit deny-all rule (*)

    AWS NACLs include an implicit deny-all at rule number *, which blocks any traffic not matched by earlier explicit rules.

  4. In cloud security architecture, what does 'micro-segmentation' achieve that traditional perimeter ACLs cannot?

    Answer: Granular east-west traffic controls between individual workloads

    Micro-segmentation applies ACL controls between individual workloads inside the data center or cloud VPC, limiting lateral movement after a breach.

  5. Which cloud-native control enforces ACLs on API calls to cloud management planes rather than on data-plane network traffic?

    Answer: IAM policies

    IAM policies control access to cloud provider APIs (management plane), whereas network ACLs and firewalls govern data-plane traffic flows.

  6. What is the recommended practice when an S3 bucket ACL conflicts with a bucket policy in AWS?

    Answer: AWS evaluates both, and an explicit deny in either will block access

    AWS evaluates all applicable policies together; an explicit Deny in any policy (ACL or bucket policy) overrides all Allows.

  7. In Azure, which resource acts as the cloud equivalent of a network ACL applied at the subnet level?

    Answer: Network Security Group (NSG)

    Azure NSGs contain inbound and outbound security rules that filter traffic at the subnet or NIC level using priority-ordered rules.