A Cantrill - Security, Deployment and OPs Flashcards

1
Q

What is AWS Secrets manager?

A

AWS Secrets manager is a product which can manage secrets within AWS. There is some overlap between it and the SSM Parameter Store but Secrets manager is specialised for secrets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Anything to do with Secrets and Rotation ?

A

Secrets Manager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is AWS Shield?

A

AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is difference between CloudHSM and KMS?

A

AWS doesnt have access to Keys in CloudHSM only in KMS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What product should you use for a geo match condition?

A

AWS WAF. ALB does not support geo match.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Whats Amazon Macie?

A

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect your sensitive data in AWS.

Think - PII

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is amazon Inspector?

A

Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is guard duty?

A

Guard Duty is an automatic threat detection service which reviews data from supported services and attempts to identify any events outside of the ‘norm’ for a given AWS account or Accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Shield Standard is automatically provided with which services?

A

Cloudfront and Route 53.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What layer does Shield operate at? And what does it protect against?

A

Layer 3. DDOS attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What layer does WAF operate at? And what does it protect against?

A

Layer 7. SQL injection and CSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What services fore WAF integrate with?

A

Cloudfront, API GW, and ALB.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The main feature which Secrets Manager provides over SSM Parameter store is..

A

PW rotation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly