AWS Cloud Security and Compliance Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 AWS Cloud Security and Compliance flashcards as text
Which AWS service enables multi-factor authentication (MFA) enforcement for IAM users?
Answer: AWS IAM
AWS IAM allows administrators to require MFA for individual users or enforce it via IAM policies across the account.
What is the primary purpose of AWS CloudTrail?
Answer: Record API calls and account activity for auditing
AWS CloudTrail records API calls made in your AWS account, providing an audit trail of who did what, when, and from where.
Which AWS service performs automated security assessments of EC2 instances and container workloads to find vulnerabilities?
Answer: Amazon Inspector
Amazon Inspector automatically assesses applications for software vulnerabilities and unintended network exposures on EC2 and container workloads.
Which AWS offering provides automatic protection against DDoS attacks for all AWS customers at no additional cost?
Answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no extra cost and protects against common network and transport-layer DDoS attacks.
Which IAM best practice recommends avoiding the use of root account credentials for everyday tasks?
Answer: Root Account Protection
AWS recommends locking away root account credentials and creating individual IAM users for day-to-day operations to minimize risk.
Which service centralizes security findings from multiple AWS security services into a single dashboard?
Answer: AWS Security Hub
AWS Security Hub aggregates, organizes, and prioritizes security findings from services like GuardDuty, Inspector, and Macie in one place.