Implementation & Compliance Best Practices Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Implementation & Compliance Best Practices flashcards as text
Which ACL feature should be enabled to support incident response and forensic investigations?
Answer: ACL logging with timestamps and hit counts
Enabling logging with timestamps and hit counts on ACL entries provides the audit trail necessary for incident response and forensic analysis.
A company must comply with GDPR for EU customer data. How should ACLs be configured to support data residency requirements?
Answer: Restrict data flows so EU customer data cannot be routed to non-EU servers without authorization
GDPR data residency controls require restricting unauthorized transfers of EU personal data outside approved jurisdictions, which ACLs can enforce at the network level.
What is the purpose of using reflexive ACLs (also called 'ip inspect' or stateful ACL entries) in a compliance-focused environment?
Answer: To dynamically allow return traffic only for established outbound sessions
Reflexive ACLs dynamically create temporary entries to allow return traffic only for sessions that were initiated from the trusted side, preventing unsolicited inbound connections.
A cloud security engineer needs to implement ACL-equivalent controls in AWS. Which AWS service provides this functionality at the subnet level?
Answer: Network Access Control Lists (NACLs)
AWS Network ACLs (NACLs) are stateless subnet-level controls that function similarly to traditional router ACLs, applied at the VPC subnet boundary.
During a compliance review, auditors require evidence that ACL changes follow a four-eyes principle. Which process satisfies this requirement?
Answer: Requiring peer review and approval in a ticketing system before ACL changes are deployed
A four-eyes (dual-control) principle requires a second person to review and approve changes before implementation, typically enforced through a ticketing and approval workflow.
Which statement correctly describes the difference between standard and extended ACLs in the context of compliance implementations?
Answer: Extended ACLs filter on source IP, destination IP, protocol, and port; standard ACLs filter on source IP only
Extended ACLs match on source IP, destination IP, protocol, and port, providing granular control; standard ACLs only match on source IP.
A security policy requires blocking all ICMP traffic inbound to production servers except for echo-reply. Which ACL entry correctly implements this?
Answer: permit icmp any host 10.1.1.1 echo-reply
The entry 'permit icmp any host 10.1.1.1 echo-reply' allows only ICMP echo-reply messages destined for the server, with the implicit deny blocking all other ICMP.