Security and Compliance Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
Which AWS service provides automated security findings by analyzing CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity?
Answer: AWS GuardDuty
AWS GuardDuty is a threat detection service that continuously monitors CloudTrail, VPC Flow Logs, and DNS logs to identify malicious or unauthorized behavior.
Under the AWS Shared Responsibility Model, who is responsible for patching the underlying hypervisor in an EC2 environment?
Answer: AWS
AWS is responsible for patching the hypervisor and underlying infrastructure (security 'of' the cloud), while customers patch the guest OS and applications.
A company wants to receive compliance reports and security documentation about AWS services such as SOC 2 and ISO 27001. Which service should they use?
Answer: AWS Artifact
AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports and security agreements such as SOC, PCI, and ISO certifications.
Which AWS feature allows administrators to set permission guardrails across all accounts in an AWS Organization, preventing certain actions even by account root users?
Answer: Service Control Policies (SCPs)
Service Control Policies (SCPs) in AWS Organizations set maximum permission boundaries for all accounts, restricting actions organization-wide regardless of individual IAM policies.
Which type of AWS IAM credential should be used by an application running on an EC2 instance to securely access other AWS services?
Answer: An IAM role attached to the EC2 instance
IAM roles attached to EC2 instances provide temporary, automatically rotated credentials that are the most secure way for applications to access AWS services.
Which AWS service uses machine learning to automatically discover, classify, and protect sensitive data such as PII stored in Amazon S3?
Answer: Amazon Macie
Amazon Macie uses machine learning to automatically discover and classify sensitive data (like PII and financial data) stored in S3 buckets.
Which AWS service can be used to centrally view and manage security alerts and compliance status across multiple AWS accounts?
Answer: AWS Security Hub
AWS Security Hub provides a centralized view of security alerts and compliance status aggregated from multiple AWS accounts and supported third-party services.