Security & Compliance in the Cloud Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Compliance in the Cloud flashcards as text
Which encryption option allows Amazon S3 to manage the encryption keys on behalf of the customer?
Answer: SSE-S3
SSE-S3 (Server-Side Encryption with S3-managed keys) lets S3 handle key management entirely on the customer's behalf.
A developer accidentally committed AWS access keys to a public GitHub repository. What is the FIRST action they should take?
Answer: Rotate or deactivate the compromised access keys immediately
Immediately rotating or deactivating the exposed access keys prevents unauthorized use before any damage can be done.
Which AWS service enables you to evaluate the security and compliance of your EC2 instances against predefined rules and best practices?
Answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and container images for software vulnerabilities and unintended network exposure.
What is the primary purpose of AWS Artifact?
Answer: To provide on-demand access to AWS compliance reports and agreements
AWS Artifact is a self-service portal for on-demand access to AWS security and compliance reports such as SOC, PCI, and ISO certifications.
Which principle states that users and systems should be granted only the minimum permissions necessary to perform their required tasks?
Answer: Least privilege
The principle of least privilege means granting only the permissions needed to perform a specific task, reducing the attack surface.
Which AWS service can automatically remediate non-compliant AWS resource configurations based on defined rules?
Answer: AWS Config
AWS Config can evaluate resource configurations against rules and trigger automated remediation actions for non-compliant resources.
A company wants to protect their web application from common exploits like SQL injection and cross-site scripting. Which AWS service should they use?
Answer: AWS WAF
AWS WAF (Web Application Firewall) filters HTTP/HTTPS traffic and protects against common web exploits like SQL injection and XSS.