โ† All AWS Flashcard Decks

AWS Security and IAM Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 AWS Security and IAM flashcards as text
  1. Which AWS service continuously monitors and records API calls made in your AWS account for auditing purposes?

    Answer: AWS CloudTrail

    AWS CloudTrail records API calls and account activity as events, providing an audit trail for governance and compliance.

  2. What is the function of AWS Secrets Manager compared to AWS Systems Manager Parameter Store?

    Answer: Secrets Manager provides automatic secret rotation while Parameter Store requires manual rotation

    AWS Secrets Manager natively supports automatic rotation of secrets like database passwords, whereas Parameter Store requires custom Lambda functions for rotation.

  3. Which AWS KMS key type allows you to import your own key material and is managed entirely by you?

    Answer: Customer Managed Key (CMK) with imported key material

    Customer Managed Keys with imported key material let you bring your own cryptographic material while AWS KMS handles the infrastructure.

  4. An application running in Account A needs to access an S3 bucket in Account B. What is the most efficient configuration?

    Answer: Add a bucket policy in Account B that allows Account A's IAM role, then grant the role permission to assume cross-account access

    Cross-account S3 access requires a bucket policy in the target account plus an IAM role or user in the source account with appropriate permissions.

  5. Which GuardDuty finding type would indicate that an IAM user's credentials may be compromised?

    Answer: UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B

    The UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B finding indicates a successful console login from a potentially compromised or unusual location.

  6. What is the primary purpose of AWS IAM Access Analyzer?

    Answer: To identify resources shared with external entities outside your zone of trust

    IAM Access Analyzer uses automated reasoning to identify resources like S3 buckets or IAM roles accessible from outside your account or organization.

  7. A security team wants to enforce MFA for all IAM user console logins without modifying each user's individual policies. What is the best approach?

    Answer: Use an SCP to deny all actions if MFA is not present

    An SCP with a Deny effect for actions where aws:MultiFactorAuthPresent is false enforces MFA organization-wide without touching individual user policies.