โ† All AWS Flashcard Decks

Security & Compliance Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Compliance flashcards as text
  1. Which encryption option lets AWS manage the keys for S3 server-side encryption with minimal customer effort?

    Answer: SSE-S3

    SSE-S3 uses keys that AWS fully manages for server-side encryption of S3 objects.

  2. What does enabling MFA on an IAM user require for sign-in?

    Answer: A password plus a one-time code

    MFA requires a second factor, such as a time-based one-time code, in addition to the password.

  3. Which service centrally manages and enforces policies across multiple AWS accounts?

    Answer: AWS Organizations with SCPs

    AWS Organizations uses Service Control Policies (SCPs) to set permission guardrails across accounts.

  4. What is the purpose of a VPC security group?

    Answer: Act as a stateful virtual firewall for instances

    Security groups are stateful firewalls that control inbound and outbound traffic at the instance level.

  5. How do network ACLs differ from security groups?

    Answer: Network ACLs are stateless and operate at the subnet level

    Network ACLs are stateless subnet-level filters, requiring explicit inbound and outbound rules.

  6. Which service stores and rotates database credentials and other secrets securely?

    Answer: AWS Secrets Manager

    AWS Secrets Manager securely stores secrets and can automatically rotate them.

  7. What compliance benefit does encryption in transit using TLS provide?

    Answer: Protects data from interception during transfer

    TLS encrypts data while moving between endpoints, protecting it from interception.