AWS Cloud Security and Compliance Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AWS Cloud Security and Compliance flashcards as text
Which AWS encryption option allows you to manage your own encryption keys using dedicated hardware security modules?
Answer: AWS CloudHSM
AWS CloudHSM provides dedicated Hardware Security Modules so you have full control over your encryption keys.
What does the principle of least privilege mean in AWS IAM?
Answer: Grant only the permissions needed to perform a specific task
Least privilege means granting only the minimum permissions required for a user or service to complete its intended task.
Which AWS service helps you centrally manage and enforce policies across multiple AWS accounts in an organization?
Answer: AWS Organizations
AWS Organizations lets you consolidate multiple accounts and apply Service Control Policies (SCPs) to govern access across your entire organization.
What is an IAM role primarily used for?
Answer: Granting temporary permissions to AWS services or external identities
IAM roles provide temporary credentials to AWS services (like EC2 or Lambda) or federated users so they can access resources securely.
Which AWS service stores and rotates database credentials, API keys, and other secrets securely?
Answer: AWS Secrets Manager
AWS Secrets Manager stores secrets like database passwords and API keys, and can automatically rotate them on a schedule.
Which compliance framework is most relevant for organizations that handle payment card data on AWS?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) applies to organizations that process, store, or transmit cardholder payment information.