03 - AWS WAF & AWS Shield Flashcards

1
Q

What is AWS WAF (Web Access Firewall)?

A
  • Layer 7 Firewall which is Application Aware designed to stop hackers
  • AWS WAF is a web application firewall that lets you monitor the HTTP and HTTPS requests that are forwarded to Amazon CloudFront, an Application Load Balancer, or API Gateway
  • AWS WAF also lets you control access to your content
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

WAF integrates with the following services

A
  • Application Load Balancers (only works with a Layer 7 load balancer (no other types))
  • CloudFront
  • API Gateway
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

WAF does NOT integrate with

A
  • Classic Load Balancers
  • Network Load Balancers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

DDoS (Distributed Denial of Service Attack)

AWS Shield

A

AWS Shield (on exam)

  • Free service that protects all AWS customers on Elastic Load Balancing (ELB) , Amazon CloudFront, and Route53
  • Protects against
    • SYN / UDP Floods
    • Reflection Attacks
    • Other Layer 3 / 4 attacks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Shield Advanced

A
  • Provides enhanced protections for your applications running on Elastic Load Balancing (ELB), Amazon CloudFront, Route53 against larger more sophisticated attacks (costs $3,000 per month)
  • Features:
    • Always-on, flow-based monitoring of network traffic and active application monitoring to provide near real time notifications of DDoS attacks
    • DDoS Response Team (DRT) - 24x7 to manage and mitigate application layer DDoS attacks
    • Protects your AWS bill against higher fees due to Elastic Load Balancer (ELB), Amazon CloudFront, and Route53 usage spikes during DDoS attacks
    • Costs $3,000 per month
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Technologies used to mitigate a DDoS Attack

A
  • AWS Shield Protects
    • CloudFront
    • Route53
    • Elastic Load Balancers (ELB)
  • Web Application Firewalls (WAF)
  • Autoscaling (use for both WAF’s and Web Servers)
  • CloudWatch
How well did you know this?
1
Not at all
2
3
4
5
Perfectly