AWS Certified Cloud Practitioner Security & Compliance
Certification Exam | Complete Practice Test & Verified Answers
2026/2027
QUESTION 1
According to the AWS Shared Responsibility Model, which of the
following tasks is the sole responsibility of the customer?
• A. Patching the virtualization hypervisor layer running on host
servers.
• B. Configuring operating system updates, network firewalls, and
data encryption.
• C. Maintaining physical security guards and biometric access at
data center entrances.
• D. Repairing and replacing failed physical server hardware
components.
Correct Answer: B. Configuring operating system updates, network
firewalls, and data encryption.
Detailed Rationale: Under the shared responsibility model, AWS is
responsible for security of the cloud (hardware, facilities, and
virtualization infrastructure), while the customer is responsible for
security in the cloud, which includes guest operating systems, patch
management, firewall configurations, and data encryption.
QUESTION 2
,What is the primary purpose of applying the principle of least privilege
in AWS Identity and Access Management (IAM)?
• A. To ensure that every user has full administrative access to all
AWS cloud services.
• B. To limit user and application permissions strictly to what is
required to perform their specific tasks.
• C. To minimize monthly compute costs across EC2 instances
automatically.
• D. To enforce multi-factor authentication for root accounts
unconditionally.
Correct Answer: B. To limit user and application permissions strictly to
what is required to perform their specific tasks.
Detailed Rationale: The principle of least privilege is a core security
best practice that restricts access rights for users, services, and
processes to only those permissions essential for performing intended
tasks, minimizing potential security blast radiuses.
QUESTION 3
Which AWS service provides customers with on-demand, self-service
access to AWS compliance reports, such as ISO certifications and SOC
reports?
• A. AWS Artifact
• B. Amazon Inspector
• C. AWS Trusted Advisor
• D. AWS Audit Manager
,Correct Answer: A. AWS Artifact
Detailed Rationale: AWS Artifact is your go-to central resource for
compliance-related information, providing on-demand downloads of
AWS security and compliance audit reports required for regulatory
reviews.
QUESTION 4
Which AWS service uses machine learning and threat intelligence feeds
to continuously monitor AWS accounts, VPC flow logs, and workloads
for malicious or unauthorized behavior?
• A. Amazon Inspector
• B. Amazon GuardDuty
• C. AWS WAF
• D. Amazon Macie
Correct Answer: B. Amazon GuardDuty
Detailed Rationale: Amazon GuardDuty is a managed threat detection
service that analyzes cloud logs and account activity to identify
unexpected and potentially malicious behavior, such as compromised
credentials or unauthorized bitcoin mining.
QUESTION 5
Which AWS service helps protect web applications against common
web exploits like SQL injection and cross-site scripting (XSS) using
custom inspection rules?
• A. AWS Shield
• B. AWS WAF (Web Application Firewall)
, • C. Amazon GuardDuty
• D. AWS Firewall Manager
Correct Answer: B. AWS WAF (Web Application Firewall)
Detailed Rationale: AWS WAF allows you to monitor HTTP and HTTPS
requests forwarded to Amazon CloudFront, Application Load Balancers,
or API Gateways, blocking common web attack vectors based on rules
you define.
QUESTION 6
What is the primary purpose of AWS Shield?
• A. To manage internal user password complexity rules.
• B. To provide managed distributed denial-of-service (DDoS)
protection for applications running on AWS.
• C. To scan container images for operating system vulnerabilities.
• D. To audit configuration changes made to cloud resources over
time.
Correct Answer: B. To provide managed distributed denial-of-service
(DDoS) protection for applications running on AWS.
Detailed Rationale: AWS Shield safeguards web applications against
DDoS attacks, offering baseline inline protection automatically
(Standard) alongside advanced protection options for complex
volumetric attacks (Advanced).
QUESTION 7
Certification Exam | Complete Practice Test & Verified Answers
2026/2027
QUESTION 1
According to the AWS Shared Responsibility Model, which of the
following tasks is the sole responsibility of the customer?
• A. Patching the virtualization hypervisor layer running on host
servers.
• B. Configuring operating system updates, network firewalls, and
data encryption.
• C. Maintaining physical security guards and biometric access at
data center entrances.
• D. Repairing and replacing failed physical server hardware
components.
Correct Answer: B. Configuring operating system updates, network
firewalls, and data encryption.
Detailed Rationale: Under the shared responsibility model, AWS is
responsible for security of the cloud (hardware, facilities, and
virtualization infrastructure), while the customer is responsible for
security in the cloud, which includes guest operating systems, patch
management, firewall configurations, and data encryption.
QUESTION 2
,What is the primary purpose of applying the principle of least privilege
in AWS Identity and Access Management (IAM)?
• A. To ensure that every user has full administrative access to all
AWS cloud services.
• B. To limit user and application permissions strictly to what is
required to perform their specific tasks.
• C. To minimize monthly compute costs across EC2 instances
automatically.
• D. To enforce multi-factor authentication for root accounts
unconditionally.
Correct Answer: B. To limit user and application permissions strictly to
what is required to perform their specific tasks.
Detailed Rationale: The principle of least privilege is a core security
best practice that restricts access rights for users, services, and
processes to only those permissions essential for performing intended
tasks, minimizing potential security blast radiuses.
QUESTION 3
Which AWS service provides customers with on-demand, self-service
access to AWS compliance reports, such as ISO certifications and SOC
reports?
• A. AWS Artifact
• B. Amazon Inspector
• C. AWS Trusted Advisor
• D. AWS Audit Manager
,Correct Answer: A. AWS Artifact
Detailed Rationale: AWS Artifact is your go-to central resource for
compliance-related information, providing on-demand downloads of
AWS security and compliance audit reports required for regulatory
reviews.
QUESTION 4
Which AWS service uses machine learning and threat intelligence feeds
to continuously monitor AWS accounts, VPC flow logs, and workloads
for malicious or unauthorized behavior?
• A. Amazon Inspector
• B. Amazon GuardDuty
• C. AWS WAF
• D. Amazon Macie
Correct Answer: B. Amazon GuardDuty
Detailed Rationale: Amazon GuardDuty is a managed threat detection
service that analyzes cloud logs and account activity to identify
unexpected and potentially malicious behavior, such as compromised
credentials or unauthorized bitcoin mining.
QUESTION 5
Which AWS service helps protect web applications against common
web exploits like SQL injection and cross-site scripting (XSS) using
custom inspection rules?
• A. AWS Shield
• B. AWS WAF (Web Application Firewall)
, • C. Amazon GuardDuty
• D. AWS Firewall Manager
Correct Answer: B. AWS WAF (Web Application Firewall)
Detailed Rationale: AWS WAF allows you to monitor HTTP and HTTPS
requests forwarded to Amazon CloudFront, Application Load Balancers,
or API Gateways, blocking common web attack vectors based on rules
you define.
QUESTION 6
What is the primary purpose of AWS Shield?
• A. To manage internal user password complexity rules.
• B. To provide managed distributed denial-of-service (DDoS)
protection for applications running on AWS.
• C. To scan container images for operating system vulnerabilities.
• D. To audit configuration changes made to cloud resources over
time.
Correct Answer: B. To provide managed distributed denial-of-service
(DDoS) protection for applications running on AWS.
Detailed Rationale: AWS Shield safeguards web applications against
DDoS attacks, offering baseline inline protection automatically
(Standard) alongside advanced protection options for complex
volumetric attacks (Advanced).
QUESTION 7