Cloud Security Architecture Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Architecture flashcards as text
Which ACL-related cloud security concept ensures that service accounts and roles have only the permissions needed for their specific task?
Answer: Principle of least privilege
The principle of least privilege limits ACL grants to the minimum permissions required, reducing the blast radius of a compromised credential.
A cloud engineer needs to allow an EC2 instance to read from S3 without embedding credentials. Which ACL mechanism achieves this securely?
Answer: IAM role with an attached S3 read policy assigned to the instance
IAM roles provide temporary credentials automatically rotated by AWS, avoiding the need to store long-term access keys on the instance.
What is the purpose of a VPC Endpoint Policy in AWS cloud architecture?
Answer: To restrict which S3 buckets or actions are accessible through a VPC endpoint
VPC Endpoint Policies are resource-based ACLs that limit which principals and actions are allowed through the endpoint, preventing data exfiltration.
In a multi-cloud ACL strategy, which approach best ensures consistent access control enforcement across AWS, Azure, and GCP?
Answer: Implement a Cloud Security Posture Management (CSPM) tool with unified policy engine
CSPM tools provide a centralized policy engine that translates and enforces consistent ACL rules across multiple cloud providers.
Which cloud ACL misconfiguration most commonly leads to unauthorized data exposure in S3-like object storage services?
Answer: Public access settings disabled combined with overly permissive ACLs
When Block Public Access settings are disabled and bucket or object ACLs grant public-read, sensitive data becomes accessible to anyone on the internet.
What is the role of a Cloud Access Security Broker (CASB) in relation to cloud ACLs?
Answer: It enforces ACL policies between users and cloud services, providing visibility and control
A CASB sits between users and cloud services to enforce ACL-style policies, detect violations, and provide audit logging for cloud access.
In cloud security architecture, which control plane ACL feature prevents even a privileged administrator from deleting critical audit logs?
Answer: S3 Object Lock with Compliance mode
S3 Object Lock in Compliance mode enforces a retention period during which no user, including root, can delete or modify the protected objects.