AWS Security And Compliance Flashcards
By default, Amazon S3 applies _____________ encryption to all new objects
Server-Side Encryption
You can also enforce encryption through _____ _______ , ensuring that all objects uploaded to the bucket are encrypted
Bucket Policies
a vulnerability management service that automatically discovers and scans your AWS workloads, such as Amazon EC2 instances, container images in Amazon ECR, and Lambda functions
Amazon Inspector
This identifies software vulnerabilities and unintended network exposure, providing detailed reports to help you prioritize and remediate issues
Amazon Inspector
A threat detection service that continuously monitors your AWS environment for malicious activity and unauthorized behavior.
Amazon GuardDuty
This uses machine learning, anomaly detection, and threat intelligence feeds to identify potential threats, such as compromised credentials, data exfiltration, and unauthorized crypto mining
Amazon GuardDuty
Helps you securely manage, retrieve, and rotate credentials, such as database passwords, API keys, etc.
AWS Secrets Manager
This supports automatic rotation of secrets to enhance security
AWS Secrets Manager
A security investigation service that automatically collects and analyzes log data from your AWS resources
Amazon Detective
Using machine learning, statistical analysis, and graph theory, it helps you quickly identify the root cause of security issues or suspicious activities
It also provides visualizations and interactive dashboards to streamline your security investigation
Amazon Detective
Service that helps you continually audit your AWS usage to simplify risk and compliance assessments
AWS Audit Manager
It automates evidence collection and provides prebuilt frameworks to map your AWS resources to compliance standards and regulations.
This makes it easier to build audit-ready reports and manage stakeholder reviews
AWS Audit Manager
Service that provides dedicated hardware security modules in the AWS Cloud
AWS Cloud HSM (Hardware Security Modules)
These modules are used to generate, store, and manage cryptographic keys, ensuring high security and compliance with regulatory standards and offers low-latency access and complete control over your cryptographic keys
AWS Cloud HSM (Hardware Security Modules)
Service that enables you to share AWS resources with other AWS accounts within your organization
AWS Resource Access Manager