Security and Compliance Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
A company wants to prevent users in their AWS account from disabling AWS CloudTrail. Which is the MOST effective way to enforce this?
Answer: Apply a Service Control Policy (SCP) that denies cloudtrail:DeleteTrail
An SCP applied at the organizational level can explicitly deny the cloudtrail:DeleteTrail and cloudtrail:StopLogging actions, preventing even privileged users from disabling CloudTrail.
Which of the following BEST describes the principle of least privilege in AWS IAM?
Answer: Granting users only the minimum permissions required to perform their tasks
The principle of least privilege means users, roles, and services receive only the exact permissions necessary to perform their intended function, reducing the blast radius of compromised credentials.
Which AWS service performs automated security assessments of EC2 instances and container workloads to identify software vulnerabilities and unintended network exposure?
Answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for software vulnerabilities (CVEs) and unintended network accessibility.
Which of the following is a customer responsibility under the AWS Shared Responsibility Model when using Amazon RDS?
Answer: Configuring database security groups and network access controls
For managed services like RDS, customers are responsible for network access controls (security groups, NACLs) and database-level security configurations, while AWS handles OS and engine patching.
Which AWS service provides DDoS protection automatically for all AWS customers at no additional cost?
Answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no extra charge and provides protection against common network and transport layer DDoS attacks.
What is the purpose of an IAM permission boundary?
Answer: It sets the maximum permissions an IAM entity can have, regardless of their attached policies
A permission boundary is an advanced IAM feature that sets the maximum permissions an IAM entity (user or role) can have, even if their identity-based policies grant more access.
A security team needs to ensure all API calls made in their AWS account are logged for auditing. Which service provides this capability?
Answer: AWS CloudTrail
AWS CloudTrail records all API calls made in an AWS account, including the identity of the caller, the time, source IP, request parameters, and response elements.