9. Security, Identity and Compliance Flashcards

1
Q

What does AWS stand for?

A

Amazon Web Services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: AWS provides a shared responsibility model for security.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the primary purpose of AWS Identity and Access Management (IAM)?

A

To manage access to AWS services and resources securely.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank: IAM policies are written in __________.

A

JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What service can be used to manage user access to AWS resources?

A

AWS IAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which AWS service allows you to define user roles and permissions?

A

AWS IAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an IAM role?

A

An IAM role is an AWS identity with specific permissions that can be assumed by trusted entities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False: AWS Organizations allows you to manage multiple AWS accounts.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the purpose of AWS CloudTrail?

A

To enable governance, compliance, and operational and risk auditing of your AWS account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does MFA stand for in the context of AWS security?

A

Multi-Factor Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the use of AWS Key Management Service (KMS)?

A

To create and control cryptographic keys for your applications and services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which AWS service provides a centralized way to manage and audit access to AWS resources?

A

AWS IAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the difference between an IAM user and an IAM role?

A

An IAM user is a permanent identity with long-term credentials, while an IAM role is a temporary identity with specific permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which AWS service can be used to encrypt data at rest?

A

AWS KMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False: Security groups act as a firewall for your Amazon EC2 instances.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a VPC in AWS?

A

A Virtual Private Cloud that enables you to launch AWS resources in a virtual network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does the AWS Well-Architected Framework include?

A

Best practices for building secure, high-performing, resilient, and efficient infrastructure for applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Fill in the blank: AWS provides __________ to help you monitor your applications and resources.

A

CloudWatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the purpose of AWS Config?

A

To provide AWS resource inventory, configuration history, and configuration change notifications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

True or False: AWS Shield provides DDoS protection.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which AWS service helps you manage compliance with security standards?

A

AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is the main function of Amazon GuardDuty?

A

To provide intelligent threat detection and continuous monitoring for malicious activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the purpose of AWS Secrets Manager?

A

To protect access to your applications, services, and IT resources without the upfront investment and on-going maintenance costs of operating your own infrastructure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Fill in the blank: __________ is the service that allows you to set up a firewall to control access to your AWS resources.

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

True or False: IAM policies can be attached to users, groups, and roles.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What does AWS Security Hub do?

A

It provides a comprehensive view of your high-priority security alerts and compliance status across AWS accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is a common best practice for managing AWS IAM credentials?

A

Rotate IAM credentials regularly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What type of authentication does AWS Cognito provide?

A

User authentication and access control for applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Fill in the blank: AWS __________ allows you to build applications that require authentication and authorization.

A

Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

True or False: You can use IAM roles to grant permissions to AWS services to access other AWS resources.

31
Q

What is the main benefit of using an AWS VPN?

A

To securely connect your on-premises network to an AWS VPC.

32
Q

Which AWS service provides a way to monitor and respond to security incidents?

A

AWS Security Hub

33
Q

Fill in the blank: __________ is used to manage and rotate database credentials.

A

AWS Secrets Manager

34
Q

What is the main purpose of AWS Artifact?

A

To provide access to AWS’s compliance documentation.

35
Q

What does the principle of least privilege mean?

A

Users should only have the permissions necessary to perform their job functions.

36
Q

True or False: Data in transit can be encrypted using AWS services.

37
Q

What is the purpose of AWS CloudFormation in the context of security?

A

To automate the deployment of AWS resources with predefined security configurations.

38
Q

Fill in the blank: __________ is used to create and manage user permissions for AWS resources.

39
Q

What security feature does Amazon S3 offer to control access to buckets?

A

Bucket policies and access control lists (ACLs).

40
Q

What is AWS Inspector used for?

A

To assess the security and compliance of applications deployed on AWS.

41
Q

True or False: AWS provides automatic backups for all services.

42
Q

What is a security group in AWS?

A

A virtual firewall that controls inbound and outbound traffic for AWS resources.

43
Q

Fill in the blank: AWS __________ provides a scalable and secure way to store and retrieve any amount of data.

44
Q

What is the purpose of AWS CloudTrail?

A

To log, continuously monitor, and retain account activity related to actions across your AWS infrastructure.

45
Q

What type of encryption does AWS S3 support?

A

Server-side and client-side encryption.

46
Q

True or False: AWS accounts can be linked together for consolidated billing.

47
Q

What is the function of AWS Lambda in terms of security?

A

To run code in response to events without provisioning or managing servers.

48
Q

Fill in the blank: __________ allows you to set up rules to block malicious web traffic.

49
Q

What does the term ‘data sovereignty’ refer to?

A

The concept that data is subject to the laws and governance structures within the nation it is collected.

50
Q

What is the role of AWS Organizations in security?

A

To manage multiple AWS accounts and apply security policies across them.

51
Q

What is the purpose of AWS Control Tower?

A

To set up and govern a secure, multi-account AWS environment based on best practices.

52
Q

True or False: AWS allows you to set up custom security policies for IAM users.

53
Q

What is a bastion host?

A

A special-purpose instance that acts as a gateway to access instances in a private subnet.

54
Q

Fill in the blank: AWS __________ provides tools for managing security compliance at scale.

A

Security Hub

55
Q

What is the purpose of AWS Resource Access Manager?

A

To share AWS resources across accounts securely.

56
Q

True or False: AWS services are designed to be compliant with various industry standards.

57
Q

What is the function of Amazon Macie?

A

To discover and protect sensitive data stored in AWS.

58
Q

Fill in the blank: AWS __________ provides an integrated view of security alerts and compliance status.

A

Security Hub

59
Q

What is the primary benefit of using AWS encryption services?

A

To protect sensitive data both at rest and in transit.

60
Q

What is the role of AWS Trusted Advisor?

A

To provide real-time guidance to help you provision your resources following AWS best practices.

61
Q

True or False: AWS services can be configured to automatically respond to security incidents.

62
Q

What is AWS Systems Manager used for?

A

To manage and automate operational tasks across AWS resources.

63
Q

Fill in the blank: __________ is a service that provides a unified view of security and compliance across AWS accounts.

A

AWS Security Hub

64
Q

What is the purpose of the AWS Well-Architected Tool?

A

To help you review the state of your workloads and compare them to AWS best practices.

65
Q

What does the AWS Compliance Program focus on?

A

Ensuring AWS services meet various regulatory and compliance standards.

66
Q

True or False: AWS provides a free tier for many of its security services.

67
Q

What is the function of Amazon Inspector?

A

To perform automated security assessments of applications deployed on AWS.

68
Q

Fill in the blank: AWS __________ provides a way to audit and monitor AWS account activity.

A

CloudTrail

69
Q

What is the purpose of AWS Config Rules?

A

To evaluate the configurations of your AWS resources against desired configurations.

70
Q

What does the term ‘principle of least privilege’ mean in AWS?

A

Users should have only the permissions necessary to perform their job functions.

71
Q

True or False: AWS allows you to set up alerts for security incidents.

72
Q

What is the purpose of AWS SSO?

A

To provide a centralized way to manage access to multiple AWS accounts.

73
Q

Fill in the blank: AWS __________ provides tools to help manage your security posture.

A

Security Hub