Security and Compliance
CLF-C02 · 90 questions
- A city team assumes AWS automatically patches the guest operating system on every Amazon EC2 instance. Under the shared responsibility model, what is correct?
- Parks and Recreation runs Amazon RDS and asks who manages database engine patching compared with a self-managed database on EC2. What is the accurate shared-responsibility shift?
- Staff running AWS Lambda notification functions believe they own no security duties because the service is serverless. What should the Cloud Practitioner clarify?
- A county auditor asks who is responsible for hiring and managing physical security guards at AWS Region datacenters that host the city's workloads. Which answer is correct?
- A city HR portal runs on AWS. Leadership asks who decides how employee records are classified and who may access them. Which statement is accurate?
- A city board asks whether the AWS shared responsibility model always splits security work exactly 50/50 between AWS and the city. Which response is accurate?
- A municipal IT lead compares Amazon EC2, Amazon RDS, and AWS Lambda for who manages the operating system or runtime layer. Which ordering correctly shows increasing AWS responsibility for that layer?
- A vendor tells the city council that moving workloads to AWS means the city will have zero remaining security work. Which statement correctly rejects that claim?
- Network firewall-style rules the city configures on Amazon EC2 security groups for a permitting system are under whose responsibility?
- Which statement correctly distinguishes AWS infrastructure duties from customer duties on Amazon EC2 for a city website?
- During shared-responsibility training, staff ask how the model is framed at Cloud Practitioner depth. Which description best matches the guide-style components?
- The city adopts a managed AWS database service and a manager asks whether IAM policies for that service can be ignored. Which statement is correct?
- The city uses AWS Key Management Service (AWS KMS) for encryption. Who is responsible for key policy and encryption configuration choices that protect municipal data?
- A council member asks whether city staff operate closed-circuit cameras inside AWS Region facilities that host the permitting system. Which answer is correct?
- Developers find a vulnerability in city-written API code running on Amazon EC2. Who is responsible for fixing that application security issue?
- The city uses Amazon RDS. Which statement best describes responsibility for automated backup features versus remaining customer duties?
- For an AWS Lambda function used by a city chatbot, which split correctly separates AWS and customer responsibilities?
- A council training slide states: "AWS is responsible for security OF the cloud; customers are responsible for security IN the cloud." How should staff apply that framing?
- The city wants staff to sign in to AWS with existing municipal SSO. Who is responsible for configuring identity federation into AWS?
- Which statement correctly assigns responsibility for a hypervisor flaw versus an unpatched WordPress site on Amazon EC2 used by a city department?
- A compliance questionnaire asks who maintains the AWS global infrastructure that hosts the city's cloud workloads. What is the correct answer?
- Architects debate placing a city API in a public subnet versus a private subnet in a VPC. Under shared responsibility, whose decision is that architecture choice?
- The city runs containers on managed Amazon ECS or Amazon EKS. Which customer security duties still apply?
- After migrating departmental file shares to Amazon S3, who must apply correct access policies on the buckets?
- An external auditor asks where the city can download AWS compliance reports and security/compliance agreements. Which AWS resource should staff use?
- A municipal health clinic workload may need industry-specific compliance evidence that a parks website does not. Which statement reflects how compliance needs relate to AWS?
- Security operations wants intelligent threat detection findings across AWS accounts used by the city. Which service is designed for that purpose at Cloud Practitioner depth?
- The city needs automated vulnerability assessment of Amazon EC2 instances. Which AWS service is intended for that purpose at Cloud Practitioner identify depth?
- A county security office is drowning in separate findings from GuardDuty, Inspector, and partner tools and wants one place to see prioritized security posture across the AWS accounts it manages. Which service provides that central view?
- A city clerk launches a public citizen portal that must stay available during traffic floods and volumetric attacks. At foundational identify depth, which AWS service is purpose-built for DDoS protection of such internet-facing workloads?
- A building department stores permit PDFs in Amazon S3 and uploads them from browsers over HTTPS. Staff ask how encryption at rest differs from encryption in transit for those permits. Which statement is accurate?
- Operations needs graphs, metrics, and alarms for a wastewater treatment API running on AWS so on-call staff get notified when error rates spike. Which service is the primary AWS monitoring destination for those metrics and alarms?
- After a suspicious IAM policy change in a municipal AWS account, auditors ask who called which AWS API and when. Which service provides that account API activity audit trail?
- A compliance officer wants to detect when AWS resources drift from approved settings — for example, when a security group or S3 bucket configuration no longer matches policy. Which service records and evaluates resource configurations for that purpose?
- A city risk office wants to continuously collect and organize evidence mapped to common audit frameworks instead of chasing screenshots before every annual review. Which AWS service is designed for that continuous audit-evidence workflow?
- City counsel asks whether every AWS service automatically carries the exact same compliance certifications and scope for municipal workloads. Which statement reflects how AWS compliance applicability works at a foundational level?
- A parks permit site terminates HTTPS at an Application Load Balancer so browsers talk to the ALB over TLS. What type of encryption control is that primarily illustrating?
- A public-works team enables encryption on an Amazon EBS volume attached to an EC2 instance that holds GIS files. Which encryption category does that control primarily represent?
- External assessors ask a municipal cloud team for official AWS compliance documentation packages rather than unofficial blog summaries. Where should the team obtain those AWS compliance reports?
- A security analyst must explain how Amazon GuardDuty differs from AWS CloudTrail for a city AWS environment. Which contrast is accurate?
- A county IT lead confuses Amazon Inspector with AWS Shield while planning controls for web apps and compute. Which statement correctly separates their purposes?
- A new hire describes AWS Security Hub as a packet-filtering firewall that should replace security groups for a library website. What is the more accurate purpose of Security Hub?
- In a governance meeting, leaders ask which service answers operational health questions (metrics and alarms) versus who-did-what API history. Which pairing is correct?
- A governance team wants continuous evaluation that flags publicly accessible Amazon S3 buckets as noncompliant with city policy. Which AWS service is designed to evaluate resource configurations against such rules?
- International data-residency questions push a municipal legal team to review AWS compliance resources for programs that differ by geography. What foundational idea should staff keep in mind?
- A city’s IAM administrators want a governance report that helps review account credentials and access-related hygiene across IAM users. Which approach aligns with that AWS governance reporting need?
- Compared with designing a bespoke on-premises HSM project from scratch, what Cloud Practitioner-level benefit of AWS cloud security is most accurate regarding encryption?
- A municipal CISO wants one official place to download AWS compliance artifacts before the annual external audit. Which service should the CISO use?
- A new cloud admin proposes sharing the AWS account root user daily among the public-works team for routine changes. What is the correct foundational response?
- Which practice is a key foundational control for protecting the AWS account root user for a municipal account?
- Parks staff only need to read objects in one Amazon S3 bucket for seasonal reports. How should permissions be granted under the principle of least privilege?
- Outside contractors need temporary access to a city AWS account without long-lived shared IAM user passwords. Which IAM identity approach best fits that temporary access pattern?
- A workforce team wants single sign-on so municipal employees can reach multiple AWS accounts with centralized workforce identity instead of separate IAM users in every account. Which AWS capability is intended for that workforce SSO pattern?
- A parks department scripts that call AWS from a workstation accidentally committed IAM access keys into a public GitHub repository. What should the city treat as the core lesson about those keys?
- A municipal IT board wants IAM users who still sign in with passwords to meet stronger authentication rules for length, complexity, and change cadence. Which IAM feature addresses that requirement at Cloud Practitioner depth?
- A city's permit API should load the database password at runtime instead of hard-coding it in application source. Which AWS service is designed to store and retrieve that kind of secret?
- Operations staff need a place in AWS to keep operational parameters and credential-style values that automation and instances can look up, alongside related Systems Manager capabilities. Which service family fits that pattern at foundational depth?
- Human IAM users in the finance office sign into the AWS Management Console with passwords. Which additional authentication method best hardens those console sign-ins?
- A central security account must review CloudTrail logs stored in several department AWS accounts without sharing long-term access keys with those departments. What IAM pattern enables that cross-account access?
- Which statement correctly describes root-user responsibilities at Cloud Practitioner depth for a city AWS account?
- A library IT team wants permissions that start from AWS-authored baselines and then tailor narrower access when those baselines are too broad, while still aiming for least privilege. How should they think about managed versus custom policies?
- City employees already authenticate to on-premises Active Directory. Leadership wants them to access AWS without creating a unique long-term IAM password for every person. Which approach matches that goal?
- A department placed every employee into a single IAM group with AdministratorAccess. What redesign best aligns with least privilege?
- Automation that stops unused lab EC2 instances every night currently uses root user access keys. What is the recommended Cloud Practitioner guidance?
- A break-glass human administrator needs console access in an emergency, while an EC2 fleet needs permissions to read objects from a specific S3 bucket. How should those identities typically be modeled?
- A city of about 2,000 employees needs workforce access to AWS accounts. Which pattern is the better foundational choice compared with creating thousands of long-lived IAM users?
- A custom IAM policy for a reporting tool should follow least privilege for one S3 prefix. Which policy design best matches that goal?
- Which authentication hardening method should a Cloud Practitioner recommend first when asked how to strengthen IAM user console logins that already use passwords?
- A Lambda-backed civic chatbot needs a third-party API token. Which approach best matches foundational guidance on where to keep that secret?
- All library helpdesk staff need the same set of IAM permissions. What is the cleanest foundational way to grant that shared policy?
- How do federated identities differ from IAM users at Cloud Practitioner depth?
- Closing the AWS account or changing certain account settings is treated as root-level territory. What should the city do for ordinary daily cloud work?
- A public permits website is seeing SQL injection style attempts in HTTP requests. Which AWS service is designed to filter those Layer 7 web exploits?
- What is the primary purpose of a security group for EC2 instances in a VPC?
- How do network ACLs differ from security groups at Cloud Practitioner depth?
- A security team wants a third-party firewall or IDS appliance image they can run in AWS. Where can they commonly procure such products?
- Where should a practitioner look for official AWS security bulletins and guidance materials?
- Which AWS capability commonly flags security findings such as overly open security groups and other best-practice gaps?
- A city public-works portal is hit with malicious HTTP patterns such as injection-style requests. Shield is already discussed for DDoS, but which service should filter those web-layer attacks with customizable HTTP rules?
- A municipal security team must enforce the same firewall and WAF policy sets across dozens of AWS accounts from one control point. Which service provides that centralized firewall policy management?
- City cloud reviewers want an AWS security capability that continuously analyzes account activity and network findings to help identify threats. Which service fits that role?
- A city analyst needs official AWS answers to common security how-to questions instead of relying on random internet forums. Where should the analyst look first for that authoritative guidance?
- A parks department EC2 web server sits behind a security group. What is the foundational inbound behavior of that security group before any custom allow rules are added?
- A county network lead wants subnet-level allow and deny controls for traffic entering and leaving a VPC subnet, not only instance-level rules. Which construct provides that subnet firewall behavior?
- During a city security workshop, someone claims Trusted Advisor can fully replace GuardDuty for threat intelligence. How should the team separate the two purposes?
- A city security team wants official write-ups when AWS announces or explains new security features. Which resource is an official information source for that guidance?
- City policy mandates a specific third-party WAF or IDS brand that is not a native AWS service. Where does the team procure that third-party security software for use with AWS?
- A transit-agency diagram must place instance-level traffic filters in one layer and subnet-level filters in another. Which pairing is correct?
- A public citizen portal needs filtering for common web exploits in HTTP requests, while a separate concern is absorbing large volumetric DDoS floods. Which service pairing matches those attack types?
- In a weekly city cloud review, leaders want a service that surfaces security-related recommendations about common account misconfigurations. Which service provides those checks?