Compliance and Governance Flashcards

1
Q

Q: What is the AWS Shared Responsibility Model?

A

A: AWS is responsible for the security of the cloud (infrastructure), and customers are responsible for security in the cloud (data, configurations, etc.).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Q: What is AWS Artifact?

A

A: A service that provides access to AWS compliance reports, certifications, and agreements (e.g., SOC 1/2/3, ISO 27001, PCI DSS).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Q: What compliance programs does AWS support?

A

A: Examples include GDPR, HIPAA, PCI DSS, ISO 27001, SOC 1/2/3, and FedRAMP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Q: What is AWS Organizations?

A

A: A service that centrally manages multiple AWS accounts, consolidates billing, and enforces governance using Service Control Policies (SCPs).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Q: What are SCPs in AWS Organizations?

A

A: Policies that define permissions and govern access across accounts within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Q: What is AWS Config?

A

A: A service that tracks and evaluates configurations of AWS resources for compliance and governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Q: What are AWS Config rules?

A

A: Custom or AWS-managed rules to evaluate resource configurations for compliance with organizational policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Q: What is AWS CloudTrail?

A

A: A service that records API calls, CLI commands, and actions taken in the AWS Management Console for auditing and compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Q: Name some AWS compliance certifications.

A

A: ISO 27001, SOC 1/2/3, PCI DSS, HIPAA, GDPR, and FedRAMP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Q: What is AWS Security Hub?

A

A: A service that aggregates and monitors security findings from various AWS services to ensure compliance with best practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Q: How does AWS address data residency requirements?

A

A: By allowing customers to store data in specific regions and use services like S3 and DynamoDB with strict regional control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Q: What does the Governance Pillar of the AWS Well-Architected Framework emphasize?

A

A: Best practices for identity management, access control, compliance monitoring, and risk mitigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Q: What is AWS Control Tower?

A

A: A service that automates the setup of a secure, multi-account AWS environment using best practices and governance controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Q: What are some governance best practices in AWS?

A

A: Use IAM roles, enforce SCPs, enable CloudTrail, define tagging standards, and monitor resources with AWS Config.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Q: How does AWS support GDPR compliance?

A

A: AWS provides data residency controls, encryption options, and tools for access logging and auditing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Q: What is AWS Trusted Advisor?

A

A: A tool that provides recommendations for improving security, performance, cost efficiency, and fault tolerance in AWS.

17
Q

Q: How does AWS ensure data encryption compliance?

A

A: By offering encryption at rest (e.g., S3, RDS, DynamoDB) and in transit (e.g., SSL/TLS), managed via AWS KMS.

18
Q

Q: What AWS services support audit logging for compliance?

A

A: AWS CloudTrail, VPC Flow Logs, and S3 Access Logs.

19
Q

Q: What is AWS IAM Access Analyzer?

A

A: A tool that identifies resources accessible from outside your AWS account and provides recommendations to tighten access.

20
Q

Q: What is the AWS Compliance Center?

A

A: An online resource hub for learning about AWS compliance programs, best practices, and customer responsibilities.

21
Q

Q: What is the AWS Policy Generator?

A

A: A tool to create custom IAM policies, bucket policies, and SQS/SNS policies for controlling access to AWS resources.

22
Q

Q: What is ISO 27001, and how does AWS comply with it?

A

A: ISO 27001 is an international standard for information security. AWS achieves compliance through strong security controls and audits.

23
Q

Q: What are AWS Config Aggregators?

A

A: Tools that combine configuration data from multiple accounts or regions into a single view for compliance monitoring.

24
Q

Q: What is AWS Backup Audit Manager?

A

A: A tool to track and validate backup activity to ensure compliance with organizational and regulatory requirements.

25
Q

Q: How does tagging help with governance?

A

A: By assigning metadata to resources, enabling cost tracking, compliance enforcement, and resource organization.

26
Q

Q: How do Cost Allocation Reports support governance?

A

A: They provide detailed cost breakdowns by tags, accounts, or services for better financial management and compliance.

27
Q

Q: Which AWS services provide compliance reporting?

A

A: AWS Artifact and Security Hub.

28
Q

Q: How do you monitor compliance in AWS?

A

A: Using AWS Config, Security Hub, CloudTrail, and GuardDuty to track resource usage, configuration, and activity.

29
Q

Q: What is an AWS Landing Zone?

A

A: A solution to set up a secure, multi-account AWS environment with governance controls, SCPs, and security baselines.

30
Q

Q: What are preventative controls in AWS governance?

A

A: Policies and configurations like SCPs, IAM policies, and encryption that prevent non-compliant actions.

31
Q

Q: What are detective controls in AWS governance?

A

A: Tools like AWS Config and CloudTrail that identify and report non-compliant activities after they occur.

32
Q

Q: What are AWS Quick Starts for compliance?

A

A: Pre-built templates to deploy secure and compliant AWS environments quickly.

33
Q

Q: How does AWS help achieve HIPAA compliance?

A

A: By offering the AWS Business Associate Addendum (BAA) and services that support PHI encryption, logging, and auditing.

34
Q

Q: What are SOC reports?

A

A: Service Organization Control (SOC) reports provide assurance about AWS’s security controls (SOC 1, SOC 2, SOC 3).

35
Q

Q: What is FedRAMP compliance in AWS?

A

A: A U.S. government program ensuring secure cloud services, with AWS offering FedRAMP Moderate and High certifications.