Security and Compliance Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
Which of the following is a security best practice for the AWS root account?
Answer: Enable MFA and avoid using the root account for routine tasks
AWS best practice is to enable MFA on the root account and use it only for tasks that absolutely require root access, performing all other work with IAM users or roles.
A company wants to protect sensitive database passwords and API keys used by their applications, with automatic rotation. Which AWS service is BEST suited for this?
Answer: AWS Secrets Manager
AWS Secrets Manager is designed to store, manage, and automatically rotate secrets like database credentials and API keys, with built-in integration for RDS and other services.
In the AWS Shared Responsibility Model, which of the following is a responsibility shared between AWS and the customer?
Answer: Encryption of data at rest and in transit
Encryption is a shared responsibility — AWS provides encryption tools and services, but the customer is responsible for deciding to enable encryption and managing their own keys.
Which feature of AWS Organizations helps centrally manage and enforce consistent security policies such as restricting specific AWS regions across all member accounts?
Answer: Service Control Policies (SCPs)
SCPs in AWS Organizations act as organizational-level guardrails that can restrict which AWS services and regions are accessible across all member accounts.
What type of encryption protects data while it is being sent between a client and an AWS service over the network?
Answer: Encryption in transit
Encryption in transit (typically TLS/SSL) protects data as it travels across networks between a client and server, preventing interception of data in motion.
Which AWS service provides security recommendations across categories like cost optimization, performance, and security, including checks for open S3 buckets and MFA on the root account?
Answer: AWS Trusted Advisor
AWS Trusted Advisor inspects your AWS environment and provides recommendations across five categories including security, such as flagging publicly accessible S3 buckets and missing MFA.
A customer needs to run penetration tests against their own AWS infrastructure. What must they do first?
Answer: Penetration testing on your own AWS resources is permitted for allowed services without prior approval
AWS allows customers to perform penetration testing on their own resources for a set of permitted services (like EC2, RDS, and CloudFront) without prior approval, per the AWS Penetration Testing Policy.