← AWS Certified Cloud Practitioner
AWS · objective · 30% of the exam
Security and Compliance — AWS Certified Cloud Practitioner
The official AWS documentation our Security and Compliance practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — Policies and permissions in AWS Identity and Access Management - AWS Identity and Access Management
Use an AWS Organizations service control policy (SCP) to define the maximum permissions for IAM users and IAM roles within accounts in your organization or
-
Amazon Web Services — Unified Cloud Security Solution Cloud Security Posture Management – AWS Security Hub FAQ - AWS
Security Hub CSPM, which is a core capability of Security Hub, requires that you enable AWS Config in your account and configure it to record
-
Amazon Web Services — Compliance FAQ - Amazon Web Services (AWS)
AWS Artifact is your go-to, central resource for compliance-related information that matters to you. It provides on-demand access to AWS’s security and compliance reports
-
Amazon Web Services — Shared Security Responsibility Model - Navigating GDPR Compliance on AWS
Responsibilities include managing user access, encrypting data, setting up monitoring, and implementing technical and organizational measures to meet their own compliance needs
-
Amazon Web Services — IAM roles - AWS Identity and Access Management
a role does not have standard long-term credentials such as a password or access keys associated with it. Instead, when you assume a role, it
-
Amazon Web Services — Compliance validation for Amazon Redshift - Amazon Redshift
AWS Config , an AWS service, can assess how well your resource configurations comply with internal practices, industry guidelines, and regulations.
-
Amazon Web Services — Customer Compliance Guides now available on AWS Artifact | AWS Security Blog
CCGs don’t cover compliance topics such as physical and maintenance controls, or organization-specific requirements such as policies and human resources controls.
-
Amazon Web Services — Data encryption - AWS CloudShell
encrypted by sending everything through an HTTPS/TLS connection. You don't need to do anything to enable the use of HTTPS/TLS for communication
-
Amazon Web Services — Network and Application Protection on AWS
Network and Application Protection on AWS provides a single place to centrally manage firewall rules across your accounts, aggregate security event reporting
-
Amazon Web Services — Security groups and network ACLs (BP5) - AWS Best Practices for DDoS Resiliency
security groups allow you to control inbound and outbound traffic at the instance level, while network ACLs offer similar capabilities at the VPC subnet level
-
Amazon Web Services — Using AWS KMS encryption with AWS services - AWS Key Management Service
AWS services that are integrated with AWS KMS use only symmetric encryption KMS keys to encrypt your data. These services do not support encryption with