Skip to content
BytePatterns

CLF-C02 · Domain 2: Security and Compliance · 30% of the exam

Task 2.2: Understand AWS Cloud security, governance, and compliance concepts.

Where to find compliance reports, how encryption protects data at rest and in transit, and which services record, monitor and audit what happens in an account.

Study it

  • Encryption in transit and at rest, KMS basics

    Lesson coming

  • Governance and audit: CloudTrail, Config, CloudWatch, Artifact

    Partly covered by: CloudWatch, Alarms & X-Ray

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An auditor asks a company for AWS's own SOC reports and ISO certifications. Where can the company download them?

  1. AAWS Trusted Advisor
  2. BAWS Config
  3. CAWS Artifact
  4. DAmazon Inspector
Show the answer and why
  • AAWS Trusted Advisor

    Incorrect

    Trusted Advisor inspects your own environment and recommends improvements. It does not hold AWS's audit reports.

  • BAWS Config

    Incorrect

    AWS Config records how your resources are configured and how that changes over time. It is evidence about your account, not AWS's.

  • CAWS Artifact

    Correct

    Artifact provides on-demand downloads of AWS security and compliance documents, such as SOC reports and ISO and PCI reports, free of charge.

  • DAmazon Inspector

    Incorrect

    Inspector scans your workloads for software vulnerabilities and unintended network exposure. It does not publish compliance reports.

AWS's compliance documents live in AWS Artifact, and auditors can use them as evidence for the AWS side of the shared responsibility model.

Question 2 · choose 1

A security team needs to find out which IAM user deleted an Amazon S3 bucket yesterday, and whether the request came from the console or the AWS CLI. Which service records this?

  1. AAmazon CloudWatch
  2. BAWS CloudTrail
  3. CAWS Config
  4. DAmazon GuardDuty
Show the answer and why
  • AAmazon CloudWatch

    Incorrect

    CloudWatch monitors resources and applications through metrics, logs, alarms and dashboards. The record of who called which API is not its job.

  • BAWS CloudTrail

    Correct

    CloudTrail records actions taken by a user, role or AWS service as events — from the console, the CLI, SDKs and APIs — so you can see who did what, to which resource and when.

  • CAWS Config

    Incorrect

    AWS Config records how resources are configured and how those configurations change over time; the event naming the caller is CloudTrail's.

  • DAmazon GuardDuty

    Incorrect

    GuardDuty analyzes sources such as CloudTrail events to detect suspicious activity and raise findings. It is not the record of every action.

"Who did what, when, and from where" is an audit question, and CloudTrail is the audit log of an AWS account.

Question 3 · choose 1

A company must encrypt the data it stores in Amazon S3 and on Amazon EBS volumes. Its security team wants to create and control the encryption keys itself and decide who may use them. Which service should it use?

  1. AAWS Key Management Service (AWS KMS)
  2. BAWS Certificate Manager (ACM)
  3. CAWS Artifact
  4. DAmazon GuardDuty
Show the answer and why
  • AAWS Key Management Service (AWS KMS)

    Correct

    AWS KMS lets you create and control the keys used to encrypt your data, with key policies that decide who may use each key.

  • BAWS Certificate Manager (ACM)

    Incorrect

    ACM creates, stores and renews SSL/TLS certificates that protect websites and applications — encryption in transit, not keys for data at rest.

  • CAWS Artifact

    Incorrect

    Artifact provides AWS's compliance reports and agreements. It does not create or manage encryption keys.

  • DAmazon GuardDuty

    Incorrect

    GuardDuty is a threat detection service that analyzes logs and raises findings. It does not encrypt data.

Data at rest is encrypted with keys, and AWS KMS is where those keys are created, protected and controlled; services such as S3 and EBS use them.

Question 4 · choose 1

An online store runs behind an Application Load Balancer. It wants the traffic between customers' browsers and the load balancer to be encrypted over HTTPS, without paying extra for certificates or renewing them by hand. Which service provides this?

  1. AAWS Key Management Service (AWS KMS)
  2. BAmazon Macie
  3. CAWS Shield
  4. DAWS Certificate Manager (ACM)
Show the answer and why
  • AAWS Key Management Service (AWS KMS)

    Incorrect

    AWS KMS creates and controls keys for encrypting and signing data. It does not issue the SSL/TLS certificates a website uses for HTTPS.

  • BAmazon Macie

    Incorrect

    Macie discovers and helps protect sensitive data stored in Amazon S3. It does not encrypt traffic.

  • CAWS Shield

    Incorrect

    Shield protects against DDoS attacks. It does not provide certificates or encrypt connections.

  • DAWS Certificate Manager (ACM)

    Correct

    ACM creates, stores and renews SSL/TLS certificates for integrated services such as Elastic Load Balancing, and there is no additional charge for the certificates it manages.

Encryption in transit for a website means TLS, and TLS needs a certificate. ACM issues it, deploys it to the load balancer and renews it.

Question 5 · choose 1

A company wants to be alerted if one of its EC2 instances starts unauthorized cryptocurrency mining or if an access key is used in a way that suggests it was stolen. It wants a service that continuously analyzes its account's logs for such threats. Which service should it enable?

  1. AAmazon Inspector
  2. BAmazon GuardDuty
  3. CAWS Config
  4. DAWS Artifact
Show the answer and why
  • AAmazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure. It does not watch account activity for attacks in progress.

  • BAmazon GuardDuty

    Correct

    GuardDuty continuously monitors data sources such as CloudTrail events, VPC flow logs and DNS logs, and detects threats including compromised credentials and unauthorized cryptomining.

  • CAWS Config

    Incorrect

    AWS Config records resource configurations and evaluates them against rules. It does not detect malicious activity.

  • DAWS Artifact

    Incorrect

    Artifact provides AWS's compliance reports and agreements, not threat detection for your account.

Suspicious behavior in an account is GuardDuty's job; Inspector looks for weaknesses in software before anyone exploits them.

Question 6 · choose 1

For an audit, a company must show how each of its security groups was configured at any point during the past year, and it wants to be notified automatically whenever a resource stops following its internal rules. Which service provides both?

  1. AAWS CloudTrail
  2. BAmazon CloudWatch
  3. CAmazon Inspector
  4. DAWS Config
Show the answer and why
  • AAWS CloudTrail

    Incorrect

    CloudTrail records who made which API call and when. It does not keep a configuration history per resource or evaluate resources against rules.

  • BAmazon CloudWatch

    Incorrect

    CloudWatch collects metrics and logs and raises alarms on them. It does not record how a resource was configured over time.

  • CAmazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure; it does not track configuration history.

  • DAWS Config

    Correct

    AWS Config records resource configurations and how they change over time, and its rules flag a resource as noncompliant and send a notification when it breaks a rule.

"How was this resource configured, and is it compliant now?" is AWS Config. "Who changed it?" is CloudTrail. Audits often need both.

Practise domain 2 →Practise all domains →