Security & Compliance Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
Which encryption option lets AWS manage the keys for S3 server-side encryption with minimal customer effort?
Answer: SSE-S3
SSE-S3 uses keys that AWS fully manages for server-side encryption of S3 objects.
What does enabling MFA on an IAM user require for sign-in?
Answer: A password plus a one-time code
MFA requires a second factor, such as a time-based one-time code, in addition to the password.
Which service centrally manages and enforces policies across multiple AWS accounts?
Answer: AWS Organizations with SCPs
AWS Organizations uses Service Control Policies (SCPs) to set permission guardrails across accounts.
What is the purpose of a VPC security group?
Answer: Act as a stateful virtual firewall for instances
Security groups are stateful firewalls that control inbound and outbound traffic at the instance level.
How do network ACLs differ from security groups?
Answer: Network ACLs are stateless and operate at the subnet level
Network ACLs are stateless subnet-level filters, requiring explicit inbound and outbound rules.
Which service stores and rotates database credentials and other secrets securely?
Answer: AWS Secrets Manager
AWS Secrets Manager securely stores secrets and can automatically rotate them.
What compliance benefit does encryption in transit using TLS provide?
Answer: Protects data from interception during transfer
TLS encrypts data while moving between endpoints, protecting it from interception.