AWS Security and Compliance Flashcards
6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 AWS Security and Compliance flashcards as text
Which AWS service allows you to audit user activity and API calls across your AWS infrastructure?
Answer: AWS CloudTrail
AWS CloudTrail records API calls and user activity in your AWS account, providing a complete audit trail for compliance and security analysis.
What AWS tool helps you identify S3 buckets that contain sensitive data such as PII?
Answer: Amazon Macie
Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data in Amazon S3.
Which AWS service lets you set fine-grained permissions for AWS services and resources using JSON-based policies?
Answer: AWS IAM
AWS Identity and Access Management (IAM) lets you manage access to AWS services and resources securely using policies.
What is an IAM role used for in AWS?
Answer: Granting temporary permissions to entities that need access to AWS resources
IAM roles are used to delegate access to AWS resources with temporary security credentials, without sharing long-term keys.
Which AWS service scans EC2 instances and container images for software vulnerabilities and unintended network exposure?
Answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for vulnerabilities and deviations from best practices.
What does AWS WAF protect against?
Answer: Common web exploits such as SQL injection and cross-site scripting
AWS WAF (Web Application Firewall) protects web applications from common exploits like SQL injection and XSS that could affect availability or compromise security.