50 Cloud / AWS Security Interview Questions and Answers
This pack has 50 cloud / AWS security interview Q&As on shared responsibility, IAM roles, SG/NACL, CloudTrail, S3 public access, KMS themes, IR in AWS and multi-account guardrails — common in India cloud teams and US AWS role panels. Account-you-own practise only.
Friends! In AWS security interviews, root MFA, roles not keys, private DB subnets, CloudTrail — these are basics. Practise the 50 Q&A out loud. Do not randomly experiment deny policies in a prod account.
मित्रांनो! AWS security interview मध्ये root MFA, roles not keys, private DB subnets, CloudTrail – हे basics. 50 Q&A बोलण्यासाठी. Prod account मध्ये random deny policy experiment नको.
मित्रों! AWS security interview में root MFA, roles not keys, private DB subnets, CloudTrail – ये basics. 50 Q&A बोलने के लिए. Prod account में random deny policy experiment नहीं.
How to use this pack
Keep an AWS Free Tier / sandbox account for demos you own. Answer with control + monitoring + blast radius. Be ready for Capital One–style misconfig lessons (public facts only). Draw VPC three-tier quickly on a whiteboard. Never paste real AKIA keys into chat or repos. No scanning other tenants or public buckets for 'research'.
Educational / lab-only
Practise IAM, VPC and logging in AWS accounts you own or employer sandboxes with approval. Do not stress-test production deny policies, attack metadata of systems you do not own, or share live credentials.
AWS security interviews: roles not keys, private tiers, Security Groups and CloudTrail with shared responsibility.
AWS security interviews: roles not keys, private tiers, Security Groups आणि CloudTrail with shared responsibility.
AWS security interviews: roles not keys, private tiers, Security Groups और CloudTrail with shared responsibility.
Questions 1–50
Q1. What is the AWS shared responsibility model? (Beginner)
AWS secures the underlying cloud; you secure data, IAM, OS (for EC2), apps, network configs and encryption choices. The split shifts for RDS/Lambda/SaaS. Misconfigurations remain the top customer-side failure mode.
Q2. Root user — how should it be handled? (Beginner)
Enable MFA, do not use for daily work, avoid access keys, alarm on root logins, and use SSO/IAM roles instead. Break-glass only with tickets.
Q3. IAM user vs role vs group vs policy? (Beginner)
User: long-lived human identity (prefer federation). Group: bundles permissions for users. Role: assumable identity with temporary creds. Policy: JSON permissions. Least privilege scopes Actions and Resources.
Q4. Why prefer IAM roles on EC2 over access keys? (Beginner)
Roles give temporary credentials via instance metadata — no static keys on disk, automatic rotation. Keys in git or AMIs cause breaches. Pair with IMDSv2 hardening per AWS guidance.
Q5. What is least privilege in AWS IAM? (Beginner)
Grant only needed actions on specific resources, use conditions (MFA, source VPC), permission boundaries and org SCPs. Remove unused permissions with Access Analyzer-style reviews.
Q6. MFA habits for AWS accounts? (Beginner)
Human console users need MFA; protect sensitive API actions when policy requires. Always MFA the root user. S3 MFA Delete is a specialised control for versioned buckets.
Q7. Security Group essentials? (Beginner)
Stateful virtual firewall at ENI level; allow rules only; default deny inbound. Restrict SSH/RDP; web 80/443; app tiers only from caller SGs. Audit 0.0.0.0/0 regularly.
Q8. NACL essentials? (Beginner)
Stateless subnet ACL with allow and deny; numbered rules; ephemeral ports matter for return traffic. Use sparingly for coarse blocks; SGs do most micro policy.
Q9. Public vs private subnet in a VPC? (Beginner)
Public routes to an IGW. Private has no IGW route; outbound via NAT if needed. Keep databases and most app tiers private.
Q10. What is a VPC flow log used for? (Intermediate)
Captures accept/reject metadata for ENIs/subnets/VPC to S3 or CloudWatch for troubleshooting and detection — not full payloads. Useful for unexpected accepts to sensitive ports.
Q11. CloudTrail — why mandatory? (Beginner)
Account activity audit for API/console events. Enable in all regions, protect logs, alert on stops/deletes and identity changes. Essential for IR.
Q12. GuardDuty vs Inspector vs Security Hub? (Intermediate)
GuardDuty: threat detection from logs/flow/DNS themes. Inspector: vulnerability findings. Security Hub: aggregates findings and standards checks. Know purpose, not marketing.
Q13. S3 public access — how prevent? (Beginner)
Block Public Access at account/bucket, avoid public ACLs, prefer CloudFront with origin access controls, encrypt, and least-privilege bucket policies. Identity plus misconfig lessons still apply.
Q14. Encryption at rest options to name? (Beginner)
S3 SSE-S3/SSE-KMS, EBS encryption, RDS encryption. Prefer KMS CMKs when you need key policy control and audit. Know rotation and who can decrypt.
Q15. KMS key policy vs IAM? (Intermediate)
KMS keys have resource policies that must allow the caller; IAM alone is not always enough. Both doors need to open. Separate duties for admins vs users.
Q16. AWS WAF / Shield themes? (Beginner)
WAF: Layer 7 web ACLs on ALB/CloudFront/API Gateway. Shield Standard covers common network DDoS; Advanced is paid enhanced. Tune WAF to limit false blocks.
Q17. Three-tier on AWS securely? (Beginner)
ALB public SG → app private SG → DB private SG; least ports; private subnets for app/db; bastion/SSM for admin; CloudTrail plus VPC flow logs. No DB in public subnet.
Q18. SSM Session Manager vs SSH bastion? (Intermediate)
Session Manager can give shell access without inbound 22 using IAM, agent and endpoints/NAT — better auditability. Bastions still appear in legacy designs; harden heavily if used.
Q19. What is IMDSv2 and why? (Intermediate)
IMDSv2 requires session-oriented metadata requests, reducing casual SSRF metadata theft themes. Prefer enforcing IMDSv2. Still keep instance roles tightly scoped.
Q20. Lambda security basics? (Beginner)
Least-privilege execution role, secrets in Secrets Manager/SSM not plain env when avoidable, private VPC only if needed, monitor with CloudWatch/CloudTrail.
Q21. Secrets Manager vs Parameter Store? (Beginner)
Both store config; Secrets Manager focuses on secrets with rotation; Parameter Store has standard/advanced params. Never commit secrets to git; grant decrypt only to needing roles.
Q22. Organisation SCPs — purpose? (Intermediate)
Service Control Policies set guardrails in AWS Organizations even for member-account admins (within limits). Examples: deny leaving org, deny disabling CloudTrail, restrict regions.
Q23. Cross-account access pattern? (Intermediate)
Prefer role assumption with external ID when appropriate, short sessions and least privilege — avoid long-lived keys shared across accounts. Audit AssumeRole events.
Q24. CloudFront security benefits? (Beginner)
Edge TLS, caching, geo controls, WAF integration and origin access controls so S3 stays private. Reduce origin attack surface. Monitor certs and origin auth.
Q25. RDS security checklist? (Beginner)
Private subnets, SG only from app tier, encryption at rest, TLS to DB when supported, rotated secrets, least-privilege DB users, protected snapshots.
Q26. EKS/ECS high-level security? (Intermediate)
IRSA/task roles instead of node-wide admin, network policies, secrets hygiene, image scanning and private API where design allows. Patch nodes/AMIs.
Q27. How do you detect AKIA keys leaked? (Beginner)
Git secret scanning, AWS alerts for public leaks, CloudTrail for unusual API use, and immediate disable/rotate. Train developers; pre-commit hooks help.
Q28. Billing alarms as a security control? (Beginner)
Sudden cost spikes can mean crypto-mining after compromise. Budgets and anomaly detection alert finance and security together. Free-tier students need this habit.
Q29. Landing zone / Control Tower theme? (Intermediate)
Opinionated multi-account structure with logging, security and sandbox accounts separated. Reduces blast radius versus one shared prod playground.
Q30. Account separation strategy? (Beginner)
Prod, non-prod, security tooling and shared services at minimum. A sandbox breach should not own billing or prod. Use SCPs and centralised CloudTrail.
Q31. IAM Access Analyzer — why mention? (Intermediate)
Finds resources shared externally and unused access themes. Strong continuous least-privilege talking point.
Q32. Config / compliance-as-code? (Intermediate)
AWS Config rules detect drift such as public buckets or unencrypted volumes. Pair with IaC reviews. Auto-remediate carefully with change control.
Q33. VPC endpoints — security why? (Intermediate)
Private connectivity to AWS APIs without hairpinning the internet; tighten with endpoint policies. Helps egress lock-down designs.
Q34. ALB vs NLB security notes? (Intermediate)
ALB: Layer 7, WAF, host/path routing. NLB: Layer 4 performance, different IP preservation. Choose by need; always restrict SGs.
Q35. Respond to suspected EC2 compromise? (Beginner)
Isolate via SG/EDR, snapshot volumes if forensics required, rotate reachable roles/keys, check CloudTrail from that role, rebuild from known-good AMI rather than cleaning in place when unsure.
Q36. S3 ransomware themes — defence? (Intermediate)
Versioning, Object Lock where fit, least privilege, MFA Delete themes, block public access, monitor mass deletes. Cross-account backups help.
Q37. Cloud IR data sources? (Beginner)
CloudTrail, VPC Flow Logs, GuardDuty, Config, ALB/WAF logs, DNS logs if enabled, and IdP logs for federation. Centralise before the incident.
Q38. Federation / SSO to AWS? (Beginner)
IAM Identity Center or SAML/OIDC from corporate IdP with MFA. Map groups to permission sets. Avoid per-user long-lived IAM users when SSO exists.
Q39. Privilege escalation in IAM (concept)? (Intermediate)
A limited principal uses permissions that grant broader rights (create keys, attach admin policies). Prevent with boundaries, SCPs and reviewing iam wildcards.
Q40. Tagging strategy for security? (Beginner)
Owner, environment, data classification and application tags enable blast-radius queries and IAM conditions. Untagged resources are audit debt.
Q41. Region selection security angle? (Beginner)
Data residency, latency and attack surface — deny unused regions via SCP. Forgotten regions hide incidents; multi-region CloudTrail matters.
Q42. Container image supply chain on AWS? (Intermediate)
Scan images (ECR), promote by digest, least-privilege task roles, no secrets in layers. Align with SBOM thinking.
Q43. How interviews test CloudTrail knowledge? (Beginner)
Expect multi-region trail, log protection, dedicated logging account, alerts on StopLogging, and who can read logs. Tie to IAM change detection.
Q44. Security Hub CIS / FSBP? (Intermediate)
Automated checks against baselines — public SG rules, root MFA, encryption. Use as backlog fuel with owned exceptions, not a paper-green dashboard.
Q45. What is a break-glass role? (Beginner)
Emergency elevated access with MFA, monitoring, short duration and mandatory ticket after use. Better than sharing root daily.
Q46. Data exfil paths in AWS to watch? (Intermediate)
Unusual S3 GetObject volumes, odd DNS from VPC, new sharing policies and large egress cost. Combine GuardDuty with custom detections.
Q47. How do you secure CI/CD to AWS? (Beginner)
OIDC federation from GitHub/GitLab to roles, no static keys, least-privilege deploy roles, required reviews and secret scanning. Pin actions to SHAs when possible.
Q48. Multi-account logging one-liner? (Intermediate)
Member accounts send CloudTrail/Config/GuardDuty findings to a security account that developers cannot delete. Separate duties.
Q49. Common junior mistakes on AWS? (Beginner)
Open 0.0.0.0/0 on 22/3389, AdminAccess for everyone, access keys on laptops, public S3 and no budgets. Fix with guardrails and training.
Q50. How to answer Capital One 2019 in interview? (Intermediate)
Stay factual from public reporting: SSRF/WAF misconfiguration themes leading to metadata credential abuse and broad data access lessons. Takeaway: scope instance roles, harden metadata, monitor CloudTrail, fix web bugs — no exploit steps.
Ravindra Bagale's Tip
💡 "AdministratorAccess was temporary" jokes do not land in interviews. Say: role + MFA + CloudTrail alert on AttachUserPolicy. Keys in git = instant red flag. Don't panic — practise in a sandbox.
Ravindra Bagale's Tip – मराठी
💡 Interview मध्ये 'AdministratorAccess temporary होता' joke चालत नाही. बोला: role + MFA + CloudTrail alert on AttachUserPolicy. Keys in git = instant red flag. घाबरू नका — sandbox मध्ये practise.
Ravindra Bagale's Tip – हिंदी
💡 Interview में 'AdministratorAccess temporary था' joke नहीं चलता. बोलो: role + MFA + CloudTrail alert on AttachUserPolicy. Keys in git = instant red flag. घबराओ मत — sandbox में practise.
Related guides on this site
Got it? Cloud security = shared responsibility, least privilege, private tiers, CloudTrail, budgets. 50 Q. Next: IAM MFA Zero Trust pack.
समजलं का? Cloud security = shared responsibility, least privilege, private tiers, CloudTrail, budgets. 50 Q. आता IAM MFA Zero Trust pack.
समझ में आया? Cloud security = shared responsibility, least privilege, private tiers, CloudTrail, budgets. 50 Q. आगे IAM MFA Zero Trust pack.
Frequently asked questions
What is the number-one junior AWS mistake?
Standing AdministratorAccess, static keys and 0.0.0.0/0 on admin ports — fix with roles, MFA and guardrails.
Root user daily use — OK?
No. MFA the root, alarm logins, and work via SSO/roles with break-glass tickets.
Why CloudTrail in every answer?
Without audit logs you cannot investigate IAM changes or prove what happened.
Shared responsibility in one line?
AWS secures the cloud; you secure what you put in it — data, identity, config and apps.
Is this pack only for AWS?
Examples are AWS-shaped; shared responsibility and least privilege transfer to Azure/GCP.
Related guides?
Cloud security explained, IAM MFA, least privilege and AWS security checklist guides.