AWS Keyword Connect Flashcards
Recommendation, guidance
Trusted Advisor
Multi-account for enterprises through Account vending machine (AVM)
AWS Landing Zones (4 accounts)
Automatic provision new accounts/ uses SSO via service catalog template
AVM
Digital catalog of 1000’s of software listings. Independent vendors. Free/associated charge.
AWS marketplace (SaaS offering/CloudFormation templates/web ACL)
Metadata for organizing AWS resources
Tag
Collection of resources that share 1 or more tags
Resource Group
Protects from web exploits. Attached to Cloudfront or ALB
AWS WAF
Encrypting your encryption key
Envelope Encryption
Ebs
Fully managed. Continuously monitors sensitive data access. Generates alerts for unauthorized access (uses ML)
Amazon Macie
Create and control encryption keys to encrypt data
KMS (Key Management Service)
Threat detection service (IDS). Use ML
GuardDuty
Fully Managed
DynamoDB
2 services
Role
Minimum of 1 year
Reserved instance
Eliminating as many security risks as possible
Hardening
Runs security assessments benchmark audits 1 single ec2 instance
vulnerabilities
AWS Inspector
Premade packages/templates for deployment of functional architecture in <1 hour
Quick start
Authorized simulated attack to Evaluate the security of the system
Pentesting
No cost/self-service for on-demand access to AWS compliance report. Audit
Artifact
Managed DDoS protection. Route53 /CloudFront protection
AWS Shield
Short period, unpredictable
On-Demand Instances
All checks in trusted Advisor
Business, Enterprise
7 core checks in Trusted Advisor
basic
Secures EC2 Instances
Security Groups
number of services migrated
TCO (Total Cost Ownership)
Geographical Location
AWS Region
Data Center
AZ
Isolated section to launch AWS resources.
VPC
Enables access to the internet
Internet Gateway
Determines where network from subnet is directed
Route Table
API activity/call, traceability, account activity. Governance, compliance
CloudTrail
Service activity, health, performance metrics, monitor
CloudWatch
CDN (Content Distribution Network). Copy file to all distribution around the World. High transfer speed. Uses edge locations to cache content
CloudFront
Subnet security/firewall
NACL
Logical partition of IP network in small segments
Subnet
Firewall for instances
Security Group
Distribute loads across instance. If AZ is down, they distribute to next available one. Protects against DDOS
Elastic Load Balancer
Deploy and scale web apps. Health monitoring
Elastic Beanstalk
Config. Management service. Managed instances (chef, puppet)
OpsWorks
Flooding website with large amount of fake traffic
DDoS
Create/terminate instances
AWS Autoscaling
Best/manage monthly payment
Consolidated Billing
Plan your service usage/cost/instance reservation
First 2 budgets free
AWS Billing
Visualize usage of consolidated billing
Cost Explorer
The more you use, the more you save
Volume discounts
Evaluate assess instance
AWS Inspector
Archive 40 terabytes
Glacier
Information about Prohibited actions
AWS Accepted Use Policy
Send notification/alerts/email. Uses email/text format. Subscribers, publishers, topic
SNS
Decouple/scale microservice distributed services. Places messages into a queue. Good for delayed tasks
SQS
Analyze/debug production/troubleshoot
X-Ray
Cost-effective, send email from app. Uses HTML
SES
Outbound inbound marketing campaign communication service
Pinpoint
Hybrid storage solution enables on-premises to use AWS cloud storage. Backup/archive/migration/disaster recovery
Storage gateway
Object level storage
S3
Analyze data in S3, serverless database for S3 query
Athena
enables AWS architects to manage infrastructure as code. JSON/YAML
CloudFormation
Manage EC2 capacity automatically/scale according to needs
benefits: automated provisioning, adjustable capacity, launch template support
Autoscaling group
Function-run up to 15min
Lambda
Call Center
Amazon Connect
Virtual remote desktop
Workspaces
AWS version of Sharepoint/ collaboration service
WorkDoc