AWS Mgt Tools Flashcards
AWS GuardDuty
- Intelligent Threat Detection
- Continuous Monitoring for Malicious Activity
- Delivers detailed findings
AWS Inspector
- Vulnerability Scanning
- EC2 and ECR
- Continually scans AWS workloads for vulns / unintended Network Exposure
AWS Trusted Advisor
- AWS Best Practices
- Evaluates your account to optimize your AWS infra
- Base and Dev support - Core checks
- Business and Enterprise support - All checks
AWS Config
- Evaluates AWS configs for desired settings
- Active and Historical
- Notifications when ever resources are created or modified
AWS Certificate Manager (ACM)
- Create, Store, and Renew SSL/TLS Certs
AWS Secrets Manager
- Stores and Rotates secrets without the need for code
- Auto Rotate for
- RDS (MySQL, Postgress, Aurora)
- Redshift
- Document DB
AWS Resource Account Manager (RAM)
- Sharing of resources
- Across AWS accounts
- Within Orgs and OUs
- IAM Roles and Users
AWS Personal Health Dashboard
- Provides Alerts and Remediation
- AWS outages
AWS CloudHSM
- Generate and Use your own encryption keys on AWS
- In your vpc
- Protects private keys from issuing CA
AWS Shield
- Managed DDOS Protection
- Integrated with CloudFront
- Standard - No Cost
- Advanced - 3k a month / 1 year commitment
AWS SAM (Serverless Application Model)
- Extension of CloudFormation for Serverless
AWS Systems Manager
- Centralized console and toolset for a wide variety of system management tasks
- centralize operation data from multiple AWS services
- ## automate tasks across your aws resources
AWS CloudFormation
- IaaS provisioning
- Creates Stacks
- Uses Templates
CloudFormation Stacksets
- Create, Update, or delete stacks across multiple accounts and regions with a single operation
AWS Athena supports SSE and Client Side encryption on S3
Yes… you can read and write using encryption
Run single jobs that span multiple EC2 instances. Can run large scale, tightly coupled, HPC, app and distributed GPU model.
AWS Batch
AWS Tool to display current service limits?
AWS Trusted Advisor
Can you use CloudHSM to distribute encryption keys?
No. Used for mgt and storage not for distribution
How can you Connect ec2 app in private subnet to API gateway and ensure no traffic goes over inet
Use an interface endpoint with private link. “Private API”
Does aws allow pen testing?
Yes. For some resources without prior approval
SCPs do not affect service linked role
True
SCPs affect all users and roles in attached accounts including the root user?
True
Can you attach identity based policies to resources
No
AWS service that allows rules to filter web traffic based on conditions that include IP addy, http headers and body, custom urls, or location
AWS WAF
AWS IOT Core
allows IOT devices to securely connect to cloud
Do you need to enable rate based rules in shield?
No. It’s always on and running
An ec2 instance is querying IP addresses used for crypto mining and it does not host any authorized app related to mining. What service can protect ec2 from such unauthorized use
GuardDuty
AWS cost resource optimization
Reports ec2 instances that are idle or have low utilization
AWS cloud optimization
Instance type recommendations