Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 43 pages
Exam (elaborations)

AWS Cloud Practitioner Security, Governance & Compliance Practice Test 2026–2027 | AWS Security Questions, Answers & Detailed Rationales

Document preview thumbnail
Preview 4 out of 43 pages

Prepare for the AWS Certified Cloud Practitioner CLF-C02 2026–2027 exam with comprehensive practice covering AWS security, governance, and compliance. Review IAM, shared responsibility, encryption, logging, monitoring, AWS Organizations, Service Control Policies, AWS Artifact, security services, compliance concepts, and governance controls. Realistic certification-style questions test your ability to identify appropriate AWS security and governance solutions across practical cloud scenarios. Detailed answers and rationales reinforce core concepts and explain why specific services or controls are appropriate. Ideal for students, IT professionals, cloud learners, cybersecurity candidates, and AWS certification learners seeking focused security preparation.

Content preview

AWS Cloud Practitioner Security,
Governance & Compliance Practice Test
2026–2027 | AWS Security Questions,
Answers & Detailed Rationales


1. Which AWS security principle most directly describes the practice of granting
only the permissions required to perform a specific task?

A. Defense in depth
B. Least privilege
C. Fault tolerance
D. Elasticity

Answer: B. Least privilege

Rationale: Least privilege means granting identities only the permissions
necessary to perform their required tasks. This reduces the potential impact of
compromised credentials or accidental misuse.

,2. A company wants to provide an application running on Amazon EC2 with
permission to access an Amazon S3 bucket without storing long-term access
keys on the instance. What should the company use?

A. IAM user
B. IAM group
C. IAM role
D. AWS account root user

Answer: C. IAM role

Rationale: An IAM role provides temporary credentials to AWS resources such as
EC2 instances. This avoids embedding long-term access keys in application code
or configuration files.



3. Which AWS service continuously records API activity and account actions for
auditing and governance purposes?

A. Amazon GuardDuty
B. AWS CloudTrail
C. AWS Shield
D. Amazon Inspector

Answer: B. AWS CloudTrail

Rationale: AWS CloudTrail records AWS API calls and related account activity. Its
logs can be used for security investigations, compliance auditing, and
operational troubleshooting.



4. An organization needs to identify suspicious activity such as unusual API calls,
credential compromise indicators, or communication with known malicious IP
addresses. Which service is most appropriate?

,A. Amazon GuardDuty
B. AWS Artifact
C. AWS Config
D. AWS Audit Manager

Answer: A. Amazon GuardDuty

Rationale: Amazon GuardDuty is a threat-detection service that analyzes AWS
account and workload-related data to identify potentially malicious or
unauthorized activity.



5. Which AWS service provides access to AWS compliance reports and
agreements?

A. AWS Artifact
B. AWS CloudTrail
C. AWS Security Hub
D. AWS Config

Answer: A. AWS Artifact

Rationale: AWS Artifact provides on-demand access to AWS security and
compliance documentation, including reports and agreements that customers
may need for regulatory or audit purposes.



6. A company wants to automatically evaluate whether AWS resources comply
with predefined configuration rules. Which service should it use?

A. AWS Config
B. AWS Shield
C. Amazon Macie
D. AWS WAF

Answer: A. AWS Config

, Rationale: AWS Config continuously evaluates AWS resource configurations
against desired rules and provides configuration history and compliance
information.



7. Which AWS service is designed to protect web applications from common
Layer 7 attacks such as SQL injection and cross-site scripting?

A. AWS Shield
B. AWS WAF
C. Amazon GuardDuty
D. AWS Network Firewall

Answer: B. AWS WAF

Rationale: AWS WAF is a web application firewall that allows organizations to
inspect and control HTTP and HTTPS requests using configurable rules.



8. Which AWS service provides managed protection against distributed denial-
of-service attacks?

A. AWS Shield
B. Amazon Inspector
C. AWS Artifact
D. AWS Config

Answer: A. AWS Shield

Rationale: AWS Shield provides managed DDoS protection for AWS applications.
AWS Shield Standard is automatically included, while Shield Advanced provides
additional protection and capabilities.

Document information

Uploaded on
September 1, 2026
Number of pages
43
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
mml1030
2.6
(5)
Sold
8
Followers
0
Items
1207
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions