AWS Security Services Flashcards
AWS Security Services (high-level)
Hook up to Oracle to do transparent encryption?
CloudHSM
AWS Security Services (high-level)
Most secure way to secure a CA?
CloudHSM store issuing certificate
AWS Security Services (high-level)
Service for finding root cause of security findings
Detective
AWS Security Services (high-level)
Integrates network traffic with security events like strange logins and AWS activity?
Detective
AWS Security Services (high-level)
Can help find suspicious activity on the network
Detective
AWS Security Services (high-level)
Detective use case?
Help find root cause of security findings
AWS Security Services (high-level)
Does Detective alert you or do you go to Detective for info?
Passive only: go to Detective to look thru data
AWS Security Services (high-level)
System uses ML to find outliers in data
Detective and GuardDuty
AWS Security Services (high-level)
Continuous security monitoring service?
GuardDuty
AWS Security Services (high-level)
Uses threat intelligence feeds?
GuardDuty
AWS Security Services (high-level)
Inputs to GuardDuty?
threat intelligence feeds, logs from everywhere
AWS Security Services (high-level)
How does GuardDuty find things?
ML
AWS Security Services (high-level)
How do Detective and GuardDuty relate?
GuardDuty findings are inputs to Detective
AWS Security Services (high-level)
Uses ML to look thru things, creates Findings for you
GuardDuty
AWS Security Services (high-level)
Where does GuardDuty send findings?
Detective and Security Hub
AWS Security Services (high-level)
Example finding from GuardDuty?
Known malicious source IPs