AWS Chapter 6 Flashcards
Shared Responsibility Model
shares responsibility between AWS and the customer
Customer Responsibilities
Data/Server side encryption, network traffic protection
AWS Responsibilities
storage, hardware, regions, security of the cloud
AWS Identity and Access Management (IAM)
manage AWS services securely, create users policies etc
AWS Account Root User
user who creates the AWS account
IAM Users
identity created in AWS, default no permissions but assign permissions over time
IAM Policy
document that allows/denies permissions to AWS services and resources, least privilege
IAM Group
collection of IAM users, shared permissions
IAM Roles
identity that you can assume to give temp access to permissions
AWS Organizations
used to consolidate and manage multiple AWS accounts centrally
Service Control Policies (SCP)
restrictions on AWS services, resources, and individual API actions
Organizational Units
similar to a group, all policies to the OU apply to all accounts
AWS Artifact
services that provides on demand access to AWS security/compliance reports
AWS Shield
protects against DDoS attacks, Standard (free) and Advanced (paid) protections
AWS Key Management Service (AWS KMS)
perform encryption through crypto keys, manage/use/create