AWS Environment Flashcards
A ____ is a physical location in the world that consists of two or more Availability Zones (AZs).
Region
An _____ is one or more discrete data centers - each with redundant power, networking, and connectivity - house in separate facilities.
AZ (Availability Zone)
____________ are endpoints of AWS that are used for caching content. Typically, this consists of CloudFront, Amazon’s CDN (Content Delivery Network).
Edge Locations
Cloud service providers adhere to a _______________, which means your security team maintains some responsibilities for security as you move applications, data, containers, and workloads to the cloud, while the provider takes some responsibility, but not all.
Shared Responsibility Model
The _______ is responsible for security IN the cloud.
Customer
The ________ is responsible for security OF the cloud.
Cloud Provider or AWS
What question can you ask yourself to determine who is responsible for an area of AWS services?
“Can you do this yourself in the AWS Management Console?”
In regards of the shared responsibility model, who is responsible for: security groups, IAM users, patching EC2 operating systems, patching databases running on EC2?
Customer / You are.
In regards of the shared responsibility model, who is responsible for: management of data centers, security cameras within the data center, cabling, patching RDS operating systems?
AWS
Who is responsible for encryption?
Both AWS and the Customer. Encryption is a shared responsibility.