โ† All AWS Flashcard Decks

Security & Compliance Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Compliance flashcards as text
  1. Which AWS service automatically discovers, classifies, and protects sensitive data such as PII in Amazon S3?

    Answer: Amazon Macie

    Amazon Macie uses machine learning to identify and protect sensitive data like PII stored in S3.

  2. What is the AWS shared responsibility model's division for patching the guest operating system on an EC2 instance?

    Answer: The customer is responsible

    Customers are responsible for patching the guest OS and applications on EC2 instances under security 'in' the cloud.

  3. Which feature allows you to grant temporary, limited-privilege credentials to users from an identity provider?

    Answer: IAM roles with STS

    AWS STS issues temporary credentials that are assumed via IAM roles for federated or cross-account access.

  4. What does AWS KMS primarily provide?

    Answer: Creation and control of encryption keys

    AWS Key Management Service (KMS) lets you create and manage cryptographic keys for encryption.

  5. Which service provides continuous monitoring for malicious activity and unauthorized behavior across AWS accounts?

    Answer: Amazon GuardDuty

    Amazon GuardDuty is a threat detection service that monitors for malicious and unauthorized activity.

  6. What is the most secure way to handle the AWS account root user?

    Answer: Enable MFA and avoid daily use

    Best practice is to secure the root user with MFA and use IAM identities for everyday tasks.

  7. Which AWS service offers on-demand access to AWS compliance reports such as SOC and PCI documentation?

    Answer: AWS Artifact

    AWS Artifact provides self-service downloads of AWS compliance reports and agreements.