AWS Chapter 6 Flashcards

1
Q

Shared Responsibility Model

A

shares responsibility between AWS and the customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Customer Responsibilities

A

Data/Server side encryption, network traffic protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Responsibilities

A

storage, hardware, regions, security of the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS Identity and Access Management (IAM)

A

manage AWS services securely, create users policies etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Account Root User

A

user who creates the AWS account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IAM Users

A

identity created in AWS, default no permissions but assign permissions over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IAM Policy

A

document that allows/denies permissions to AWS services and resources, least privilege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IAM Group

A

collection of IAM users, shared permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IAM Roles

A

identity that you can assume to give temp access to permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS Organizations

A

used to consolidate and manage multiple AWS accounts centrally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Service Control Policies (SCP)

A

restrictions on AWS services, resources, and individual API actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Organizational Units

A

similar to a group, all policies to the OU apply to all accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS Artifact

A

services that provides on demand access to AWS security/compliance reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS Shield

A

protects against DDoS attacks, Standard (free) and Advanced (paid) protections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

AWS Key Management Service (AWS KMS)

A

perform encryption through crypto keys, manage/use/create

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AWS WAF

A

Web app firewall, works with cloudfront and the app load balancer

17
Q

Amazon Inspector

A

automated security assessments on applications

18
Q

Amazon GuardDuty

A

intelligent threat detection for your AWS infrastructure and resources