Security and Compliance

Domain 2: Security and Compliance

66 practice questions for Domain 2 of the AWS Certified Cloud Practitioner (CLF-C02) exam, which makes up 30% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 2: Security and Compliance

30% of scored content · 66 practice questions

50. Under the AWS shared responsibility model, a company runs an application on Amazon EC2 instances launched from a Linux AMI. Who is responsible for applying security patches to the guest operating system on those instances?

Answer and explanation

Answer: B. EC2 is an IaaS offering, so the customer controls and must patch the guest operating system, along with application software and security group configuration. AWS is responsible for security *of* the cloud — the hypervisor, physical hosts, networking hardware, and facilities. The split is defined by service model rather than divided evenly; for a managed service such as Amazon RDS, AWS patches the underlying OS instead. An AMI publisher supplies the initial image but does not patch running instances.

51. Under the AWS shared responsibility model, who is responsible for configuring an S3 bucket policy?

Answer and explanation

Answer: B. Access configuration for customer data is security in the cloud and always belongs to the customer. AWS is responsible for the durability and security of the underlying storage infrastructure. Bucket policies must be authored deliberately. There is no transitional period in which AWS manages customer permissions.

52. Under the AWS shared responsibility model, who is responsible for patching the guest operating system on an Amazon EC2 instance?

Answer and explanation

Answer: C. The guest operating system is the customer's responsibility on EC2, which is security in the cloud. AWS patches the underlying hypervisor and host infrastructure. Responsibility is divided rather than shared equally for this item. There is no separate Availability Zone operator.

53. Under the AWS shared responsibility model, who is responsible for patching the database engine on an Amazon RDS instance?

Answer and explanation

Answer: D. RDS is a managed service, so AWS patches the database engine and underlying operating system while the customer manages data, schema, and access. On a self-managed database on EC2 the customer would patch the engine, which is how responsibility shifts with the service used.

54. Which responsibility is shared between AWS and the customer under the shared responsibility model?

Answer and explanation

Answer: B. Patch management is divided between the two parties depending on the layer, which is why it is described as shared. Physical security is entirely AWS. Security group configuration and application data encryption are entirely the customer's.

55. Which task is entirely the responsibility of AWS under the shared responsibility model?

Answer and explanation

Answer: A. Physical media decommissioning is part of security of the cloud and belongs entirely to AWS. IAM policies, application credentials, and bucket encryption settings are all customer configuration.

56. A company must encrypt data at rest in Amazon S3 and retain control over the key policy and rotation schedule. Which approach meets this requirement with the least operational overhead?

Answer and explanation

Answer: A. A customer managed KMS key gives the customer a key policy they author, controllable rotation, and CloudTrail visibility into key usage, while AWS still runs the key infrastructure. AWS owned keys require no management but expose no key policy or rotation control. Client-side encryption with on-premises keys grants maximum control at a substantial operational cost, which the question rules out. Bucket policies control access, not encryption, and leave data unencrypted at rest.

57. Which AWS service continuously analyses account activity and network telemetry to detect threats such as compromised credentials and cryptocurrency mining?

Answer and explanation

Answer: B. GuardDuty analyses CloudTrail events, DNS queries, and VPC Flow Logs against threat intelligence to surface findings of exactly this kind. Config records configuration state and evaluates compliance rules rather than detecting active threats. Artifact distributes AWS audit reports. Macie discovers and classifies sensitive data in S3.

58. A compliance rule requires that data in transit between clients and an Application Load Balancer is encrypted. What should be configured?

Answer and explanation

Answer: B. Encryption in transit is delivered by terminating TLS at the load balancer, and ACM provisions and renews the certificate at no cost. Server-side encryption and encrypted EBS volumes protect data at rest, not on the wire. An S3 bucket policy governs object access and is unrelated to load balancer traffic.

59. Which service records API calls made in an AWS account, including who made the call and from which IP address?

Answer and explanation

Answer: B. CloudTrail is the account activity log, capturing the identity, time, source address, and parameters of API calls. CloudWatch collects metrics and logs about resource performance rather than the API audit trail. Config records how resource configurations change over time. X-Ray traces requests through a distributed application.

60. A company must scan EC2 instances and container images for known software vulnerabilities. Which service should be used?

Answer and explanation

Answer: C. Inspector performs automated vulnerability assessment of EC2 instances, container images in ECR, and Lambda functions. Macie discovers sensitive data in S3. GuardDuty detects threat activity from account and network telemetry. Config evaluates resource configuration compliance.

61. What is the difference between encryption at rest and encryption in transit?

Answer and explanation

Answer: C. Encryption at rest protects persisted data, and encryption in transit protects data as it crosses a network, typically with TLS. Both apply across storage types rather than being split by resource. They are distinct controls, and the definitions are not reversed.

62. Which service continuously records configuration changes to AWS resources and can evaluate them against defined rules?

Answer and explanation

Answer: C. Config records resource configuration over time and evaluates compliance with rules. CloudTrail records API activity and who made each call. CloudWatch collects metrics and logs. Systems Manager operates and configures resources rather than recording their compliance state.

63. Which service helps a company find and classify sensitive data such as personal information stored in Amazon S3?

Answer and explanation

Answer: D. Macie uses managed and custom data identifiers to discover and classify sensitive data in S3. Inspector assesses software vulnerabilities. Detective investigates the context behind security findings. Artifact distributes AWS compliance documents.

64. Where can a customer obtain AWS agreements such as the Business Associate Addendum and compliance reports on demand?

Answer and explanation

Answer: D. Artifact is the self-service portal for AWS agreements and audit artifacts including SOC and ISO reports. Audit Manager collects evidence about the customer's own environment against control frameworks. Security Hub aggregates security findings. Organizations manages multiple accounts.

65. A security review finds the AWS account root user has only a password and is used for daily administrative work. Which two actions best address this? (Select TWO.)

Answer and explanation

Answer: D, E. The root user has unrestricted access that cannot be limited by IAM policy, so it should be protected with MFA and reserved for the small set of tasks that genuinely require it. Routine administration belongs to individual IAM users or federated identities, which give per-person attribution and least privilege. Sharing credentials destroys attribution and is never acceptable. Attaching a policy to root changes nothing, because root already bypasses IAM policy evaluation. The root user cannot be deleted; it exists for the life of the account.

66. An application running on EC2 needs to read from an S3 bucket. What is the recommended way to grant this access?

Answer and explanation

Answer: A. An IAM role supplies temporary credentials that rotate automatically, so no long-term secret is stored on the instance at all. Keys in a file persist, must be rotated manually, and are exposed to anyone with access to the instance or its snapshots. Keys in source code leak through version control. Root access keys should never exist, let alone be used by an application.

67. Which principle should guide the permissions attached to a new IAM identity?

Answer and explanation

Answer: D. Least privilege means starting from the minimum permissions the task requires and adding only what proves necessary, which limits the damage from a mistake or a compromise. Granting administrator access first almost always becomes permanent. Copying a senior colleague's permissions propagates over-provisioning. Blanket read access across all services still exposes data that identity has no need to see.

68. Which service stores database credentials and rotates them automatically on a schedule?

Answer and explanation

Answer: B. Secrets Manager stores secrets encrypted and can invoke a rotation function on a schedule so credentials change without an application redeploy. KMS manages encryption keys rather than the secrets themselves. Certificate Manager provisions TLS certificates. Cognito handles application user sign-up and sign-in.

69. What is the correct relationship between IAM users, groups, and policies?

Answer and explanation

Answer: A. Permissions live in policies, which can be attached to identities directly or to groups that collect users for convenience. Groups exist precisely to contain users. Policies attach to groups and roles as well as users. There is no inheritance between users.

70. Which service provides centralized workforce access to multiple AWS accounts using an existing corporate identity provider?

Answer and explanation

Answer: D. IAM Identity Center connects to an external identity source and assigns permission sets across organization accounts from one place. Cognito manages identities for customer-facing applications. Simple AD provides a basic managed directory rather than multi-account access management. Secrets Manager stores secrets.

71. Which service should be used when regulations require encryption keys to be stored in dedicated, single-tenant hardware security modules that the customer controls?

Answer and explanation

Answer: A. CloudHSM provides dedicated FIPS-validated hardware security modules under exclusive customer control. KMS with AWS managed keys uses shared infrastructure and gives the customer no key policy control. Secrets Manager stores secrets rather than providing HSMs. Certificate Manager issues and renews TLS certificates.

72. Which practice is required for the AWS account root user according to AWS security best practice?

Answer and explanation

Answer: A. The root user cannot be restricted by IAM policy, so it should be protected with MFA and used only for tasks that genuinely require it. Everyday administration belongs to IAM identities with per-person attribution. Sharing credentials destroys attribution. Root access keys should not exist.

73. Which combination best protects an AWS account against credential compromise? (Select TWO.)

Answer and explanation

Answer: B, E. MFA raises the bar on authentication and roles or federation remove long-term secrets that can be stolen or leaked. A shared spreadsheet of keys is a direct exposure. Broad administrator access widens the damage of any compromise. Disabling CloudTrail removes the record needed to detect and investigate one.

74. An auditor asks for AWS SOC 2 and ISO 27001 compliance reports. Where should the customer obtain them?

Answer and explanation

Answer: C. AWS Artifact is the self-service portal for downloading AWS audit artifacts, including SOC reports, ISO certifications, and PCI documents. Trusted Advisor gives best-practice checks across cost, performance, security, fault tolerance, and limits — recommendations, not third-party attestations. Inspector performs automated vulnerability assessment of workloads. Security Hub aggregates and prioritizes findings from security services; neither Trusted Advisor, Inspector, nor Security Hub distributes AWS compliance reports.

75. Which statement correctly describes the difference between a security group and a network ACL?

Answer and explanation

Answer: A. A security group tracks connection state, so return traffic is permitted automatically, and it is attached to an elastic network interface. A network ACL evaluates each packet independently and must permit return traffic explicitly, and it applies to a whole subnet. The levels are not reversed. Network ACLs uniquely support explicit deny rules as well as allow rules.

76. Which service helps protect a web application against common exploits such as SQL injection and cross-site scripting?

Answer and explanation

Answer: B. AWS WAF inspects HTTP requests against configurable and managed rules, which is how injection and scripting attempts are blocked. Shield Standard provides automatic protection against common network and transport layer DDoS attacks, not application-layer exploits. Inspector assesses workloads for software vulnerabilities. Secrets Manager stores and rotates credentials.

77. Under the shared responsibility model, which task is always the responsibility of AWS?

Answer and explanation

Answer: D. Physical and environmental security of the facilities is part of security of the cloud and is never delegated to customers. Security group configuration, IAM administration, and the decision to encrypt customer data are all security in the cloud and belong to the customer, even though AWS supplies the tools for each.

78. A company must apply a permission ceiling that no administrator in a member account can exceed. Which feature provides this?

Answer and explanation

Answer: B. A service control policy sets the maximum permissions available in a member account and cannot be overridden from inside that account. IAM policies within an account can be edited by that account's administrators. Security groups filter network traffic and have nothing to do with API permissions. Config rules report non-compliance after the fact rather than preventing an action.

79. Which report lists every IAM user in an account with the status of their passwords, access keys, and MFA devices?

Answer and explanation

Answer: D. The credential report is a downloadable list of all IAM users and the state of their credentials. Artifact distributes AWS audit artifacts. A Config snapshot records resource configuration. Trusted Advisor summarises best-practice findings rather than enumerating credentials.

80. Which statement about AWS Shield is correct?

Answer and explanation

Answer: C. Shield Standard is automatically enabled for all AWS customers at no extra charge and mitigates common infrastructure-layer DDoS attacks, with Shield Advanced available as a paid tier. Application-layer exploits such as SQL injection are addressed by AWS WAF. Security groups remain necessary for network access control.

81. A security team must be able to reconstruct which principal launched a particular EC2 instance and when. Which service holds this record?

Answer and explanation

Answer: C. CloudTrail records each API call with the calling identity, timestamp, source address, and parameters. CloudWatch Logs holds application and system log data. Config records what the configuration was rather than attributing the call. Trusted Advisor provides recommendations.

82. What is AWS's policy on customers performing penetration testing against their own resources?

Answer and explanation

Answer: A. AWS permits testing of a defined list of services without prior approval provided the published rules are followed, with some activities still requiring authorization. Testing is not blanket prohibited. Approval is not required for every permitted service. Testing another customer's account is never permitted.

83. Which task remains the customer's responsibility when using Amazon S3?

Answer and explanation

Answer: A. Access configuration and encryption settings are customer responsibility. Hardware replacement, service patching, and inter-zone networking are all AWS responsibilities.

84. Under the AWS shared responsibility model, who is responsible for the physical security of AWS data centers?

Answer and explanation

Answer: D. Physical security is entirely AWS responsibility as part of security of the cloud. Customers cannot access the facilities. An auditor reviews rather than provides security.

85. How does the division of responsibility change when a customer moves from Amazon EC2 to AWS Lambda?

Answer and explanation

Answer: D. More abstracted services shift more responsibility to AWS. The customer never becomes responsible for physical hardware, and the division does change by service.

86. Which service provides on-demand access to AWS compliance reports such as SOC and ISO certifications?

Answer and explanation

Answer: D. Artifact is the self-service portal for AWS compliance reports and agreements. Audit Manager collects evidence about the customer's own environment. Config records resource configuration. Trusted Advisor provides best-practice checks.

87. Which service continuously monitors AWS accounts for malicious or unauthorized activity using threat intelligence?

Answer and explanation

Answer: B. GuardDuty analyses account and network telemetry against threat intelligence. Inspector assesses software vulnerabilities. Macie classifies sensitive data. Config records configuration.

88. Which service aggregates security findings from several AWS security services into a single view?

Answer and explanation

Answer: C. Security Hub aggregates findings from services such as GuardDuty, Inspector, and Macie into one view with standards checks. Detective investigates an individual finding in depth. Artifact distributes compliance reports. Audit Manager collects evidence against audit frameworks.

89. What is the purpose of encryption in transit?

Answer and explanation

Answer: B. Encryption in transit protects data crossing a network. Encryption at rest protects stored data. In-memory protection is a separate concern. Restricting requesters is access control rather than encryption.

90. Which statement describes data encryption at rest?

Answer and explanation

Answer: D. Encryption at rest protects stored data. Encryption in transit protects data crossing a network. Processing and backup are narrower cases rather than definitions of at-rest encryption.

91. Which practice should be followed for the AWS account root user?

Answer and explanation

Answer: C. The root user should be protected with multi-factor authentication and reserved for the few tasks requiring it. Daily use, credential sharing, and root access keys all increase risk unnecessarily.

92. Which IAM entity is assumed temporarily rather than having permanent credentials?

Answer and explanation

Answer: A. A role is assumed and issues temporary credentials. A user has permanent credentials. A group collects users. A policy defines permissions.

93. Which principle states that an identity should be granted only the permissions it needs to perform its function?

Answer and explanation

Answer: B. Least privilege grants only the necessary permissions. Defence in depth layers controls. Separation of duties divides responsibilities between people. Shared responsibility divides security between AWS and the customer.

94. Which method allows users to sign in to AWS using credentials from an existing corporate identity provider?

Answer and explanation

Answer: C. Federation lets users authenticate with their existing provider. Per-employee IAM users duplicate the directory. Sharing root credentials and issuing access keys are both poor practice.

95. Which service stores and automatically rotates database credentials?

Answer and explanation

Answer: A. Secrets Manager stores secrets and rotates them on a schedule. Parameter Store holds configuration and can hold encrypted values but does not rotate them natively. KMS manages encryption keys. Certificate Manager manages TLS certificates.

96. Which statement describes a security group?

Answer and explanation

Answer: A. Security groups are stateful, attach to resources, and support allow rules only. Network ACLs are stateless and operate at the subnet level. Encryption and load distribution are separate functions.

97. Which service protects web applications from common exploits such as SQL injection?

Answer and explanation

Answer: B. WAF inspects web requests for exploit patterns. Shield mitigates DDoS attacks. GuardDuty detects threats from telemetry. Firewall Manager centrally administers WAF and other policies.

98. Which service provides managed protection against distributed denial of service attacks at no additional charge?

Answer and explanation

Answer: A. Shield Standard is included for all customers at no additional charge. Shield Advanced is a paid subscription. WAF filters application-layer requests and is charged. Inspector assesses vulnerabilities.

99. Where can a customer find security-related best-practice recommendations for their AWS account?

Answer and explanation

Answer: B. Trusted Advisor provides best-practice checks including security recommendations. Artifact distributes compliance reports. The Pricing Calculator estimates cost. Marketplace distributes third-party software.

100. Under the shared responsibility model, who is responsible for classifying the data an organization stores in AWS?

Answer and explanation

Answer: C. Data classification is entirely the customer's responsibility. AWS secures the infrastructure, responsibility is divided rather than equal, and there is no separate Region operator.

101. Under the shared responsibility model, who is responsible for patching the hypervisor on which EC2 instances run?

Answer and explanation

Answer: C. The hypervisor is part of security of the cloud and belongs to AWS. Customers patch the guest operating system.

102. Under the shared responsibility model, who configures the network traffic rules for a customer's VPC?

Answer and explanation

Answer: C. Security group and network ACL configuration is customer responsibility. AWS provides the network infrastructure.

103. How does responsibility differ between Amazon EC2 and Amazon S3 under the shared responsibility model?

Answer and explanation

Answer: A. More abstracted services shift more responsibility to AWS, so EC2 leaves the customer the guest operating system as well. The division is not identical, and AWS always retains infrastructure responsibility.

104. Which task is the customer's responsibility for a managed database service?

Answer and explanation

Answer: D. Users, permissions, and data remain the customer's responsibility on a managed service. Engine patching, hardware, and facilities belong to AWS.

105. Which statement describes the shared responsibility model accurately?

Answer and explanation

Answer: A. The model divides security of the cloud from security in the cloud. Neither party holds all responsibility and the division is not equal per task.

106. Which service continuously evaluates AWS resource configurations against defined rules?

Answer and explanation

Answer: D. Config records configuration and evaluates it against rules. CloudTrail records API calls, CloudWatch collects metrics, and Trusted Advisor runs best-practice checks.

107. Which service helps investigate the scope of a security finding by correlating activity into a behaviour graph?

Answer and explanation

Answer: B. Detective builds investigative context around a finding. GuardDuty detects threats, Inspector assesses vulnerabilities, and Security Hub aggregates findings.

108. Which practice helps an organization demonstrate compliance with a regulatory standard on AWS?

Answer and explanation

Answer: C. Continuous evidence collection against the controls demonstrates the customer's own compliance. A diagram review is not evidence, AWS certification covers AWS responsibilities rather than the customer's, and Region choice addresses residency alone.

109. Which concept describes applying multiple independent security controls so a bypass of one is caught by another?

Answer and explanation

Answer: A. Defence in depth layers independent controls. Least privilege minimises permissions, separation of duties divides responsibilities, and shared responsibility divides security between AWS and the customer.

110. Which IAM feature allows permissions to be granted to a set of users at once?

Answer and explanation

Answer: D. A group collects users so permissions apply to all of them. A role is assumed, a policy defines permissions, and an instance profile delivers a role to an EC2 instance.

111. Which credential type should an application running on an EC2 instance use to call AWS services?

Answer and explanation

Answer: A. An instance profile supplies automatically rotated temporary credentials. Stored keys, root keys, and shared credential files are all long-term secrets.

112. What is the purpose of a permissions boundary in IAM?

Answer and explanation

Answer: B. A boundary caps effective permissions. It does not grant, define membership, or record usage.

113. Which practice should be applied when creating IAM policies?

Answer and explanation

Answer: B. Least privilege grants only what is required. Broad grants, uniform permissions, and administrator access with auditing all over-permit.

114. Which service centralizes security findings from several AWS security services?

Answer and explanation

Answer: A. Security Hub aggregates findings from other services. GuardDuty, Inspector, and Detective each produce or investigate findings rather than aggregating them.

115. What does the principle of least privilege mean in practice?

Answer and explanation

Answer: B. Least privilege grants only what the task requires. Uniform baselines, broad grants with later review, and administrator-only access all fail the principle.