AWS Security Services Flashcards
AWS Security Services (high-level)
Hook up to Oracle to do transparent encryption?
CloudHSM
AWS Security Services (high-level)
Most secure way to secure a CA?
CloudHSM store issuing certificate
AWS Security Services (high-level)
Service for finding root cause of security findings
Detective
AWS Security Services (high-level)
Integrates network traffic with security events like strange logins and AWS activity?
Detective
AWS Security Services (high-level)
Can help find suspicious activity on the network
Detective
AWS Security Services (high-level)
Detective use case?
Help find root cause of security findings
AWS Security Services (high-level)
Does Detective alert you or do you go to Detective for info?
Passive only: go to Detective to look thru data
AWS Security Services (high-level)
System uses ML to find outliers in data
Detective and GuardDuty
AWS Security Services (high-level)
Continuous security monitoring service?
GuardDuty
AWS Security Services (high-level)
Uses threat intelligence feeds?
GuardDuty
AWS Security Services (high-level)
Inputs to GuardDuty?
threat intelligence feeds, logs from everywhere
AWS Security Services (high-level)
How does GuardDuty find things?
ML
AWS Security Services (high-level)
How do Detective and GuardDuty relate?
GuardDuty findings are inputs to Detective
AWS Security Services (high-level)
Uses ML to look thru things, creates Findings for you
GuardDuty
AWS Security Services (high-level)
Where does GuardDuty send findings?
Detective and Security Hub
AWS Security Services (high-level)
Example finding from GuardDuty?
Known malicious source IPs
AWS Security Services (high-level)
Example finding from Inspector?
Bad ssh configuration
AWS Security Services (high-level)
Checks EC2 instances and containers for vulnerabilities
Inspector
AWS Security Services (high-level)
Run it for a while and see whats in its report?
Inspector
AWS Security Services (high-level)
Has an agent to collect things on EC2
Inspector
AWS Security Services (high-level)
Pokes at an EC2 from the outside to see what it is
Inspector
AWS Security Services (high-level)
Reports on reachability
Inspector
AWS Security Services (high-level)
Finds open and unusual ports
Inspector
AWS Security Services (high-level)
Dealswith CVEs and CIS benchmarks?
Inspector
AWS Security Services (high-level)
Single location for management and remediation of security
SecurityHub
AWS Security Services (high-level)
Compares your account against industry standards?
Security Hub
AWS Security Services (high-level)
Sends EventBridge events when it finds something
Security Hub, Trusted Advisor
AWS Security Services (high-level)
Looks at your AWS services configurations looking for bad practices
Security Hub and Trusted Advisor
AWS Security Services (high-level)
Produces a report with findings across many other tools
Security Hub
AWS Security Services (high-level)
Can automate findings to fix things when they pop up
Security Hub
AWS Security Services (high-level)
Gets all its findings from other AWS services
Security Hub
AWS Security Services (high-level)
How are Security Hub and Config different?
Config does actual work finding probs, Security Hub gets Config output
AWS Security Services (high-level)
Systems that send findings to Security Hub?
Config, GuardDuty, Inspector
AWS Security Services (high-level)
Security Hub sends findings to what services?
Detective, Trusted Advisor
AWS Security Services (high-level)
Example of something Trusted Advisor finds?
Unused EC2 instances
AWS Security Services (high-level)
System fueled by AWS Support cases
Trusted Advisor
AWS Security Services (high-level)
System that can recommend cost savings?
Trusted Advisor
AWS Security Services (high-level)
What other systems send data to Trusted Advisor?
Config, Security Hub
AWS Security Services (high-level)
What powers some of the Trusted Advisor checks?
Config
AWS Security Services (high-level)
Finds sensitive data in S3?
Macie
AWS Security Services (high-level)
Where does Macie send results?
Security Hub
AWS Security Services (high-level)
Gathers evidence for a compliance audit
Audit Manager