Skip to content

Security and Compliance Questions

Practice questions for Security and Compliance topic in AWS Certified Cloud Practitioner. 58 questions covering this domain.

58 questions16 easy29 medium13 hard
Q1
easy

Under the AWS Shared Responsibility Model, which task is AWS solely responsible for?

Q2
easy

What is the security best practice when creating a new AWS account?

Q3
medium

Which service evaluates whether AWS resources comply with company policies and regulatory standards?

Q4
hard

Under the Shared Responsibility Model, which is the customer's responsibility when using Amazon RDS?

Q5
medium

Which AWS service provides managed SSL/TLS certificates for use with services such as Elastic Load Balancing and Amazon CloudFront?

Q6
medium

Encrypting data at rest and in transit primarily supports which AWS Well-Architected Framework pillar?

Q7
medium

What is AWS Key Management Service (AWS KMS) primarily used for?

Q8
easy

Which service provides DDoS protection automatically at no additional cost for all AWS customers?

Q9
medium

Which service stores and automatically rotates database credentials and API keys securely?

Q10
medium

Which security concept means users receive only the permissions needed to perform their job?

Q11
easy

Which service manages user identities, permissions, and access to AWS resources?

Q12
medium

Which service helps protect a web application from common exploits such as SQL injection and cross-site scripting?

Q13
hard

Which tool provides on-demand access to AWS compliance reports and certifications such as PCI DSS and SOC reports?

Q14
medium

Which service records AWS API calls for governance, compliance, and auditing?

Q15
medium

Which service identifies unusual API activity such as calls from unexpected IP addresses?

Q16
easy

Which AWS service provides advanced DDoS protection with always-on detection and access to a 24/7 DDoS Response Team?

Q17
easy

Which AWS service provides workforce identity and single sign-on across AWS accounts and business applications?

Q18
hard

Which IAM best practice should be applied to grant an application running on EC2 access to Amazon S3?

Q19
medium

A team needs to investigate the root cause of a security finding by visualizing related events across CloudTrail, VPC Flow Logs, and GuardDuty finding...

Q20
medium

A security analyst needs a single dashboard that aggregates security findings from GuardDuty, Inspector, Macie, and partner products. Which AWS servic...

Sign in to see all 58 questions

Create a free account to browse all questions — completely free during our launch phase.