AWS Services Flashcards
Inspector
Inspects EC2 Instances
Network Assessments - Agentless
Host Assessments - With Agen (Installed on OS)
Macie
- Discovers & protects sensitive data in AWS
Think personal info. (PII)
GuardDuty
Threat detection
Analyse logs uses machine learning to detect threats.
Macie
Uses ML to find and protect sensitive data - PII
GuardDuty
Uses ML to analyse logs to detect an attack.
WAF - Web App Firewall
Web Exploits - Layer 7. App Load Balancer, API GW, CloudFront
Think SQL Injection & Cross-Site Scripting - XSS
Blacklist threats - Geo Match - Rate-based rules.
SSM Parameter Store
Store config & secrets. Can use KMS. CloudFormation Intergration.
Think encrypt parameters in Lambda.
Neptune
Graph database
Common uses-
Social Networking - Think likes & Comments
Step Functions
SWF - Simple WorkFlow
SF
State Machine, Workflow, Orchestrate Lambda funct. - Think Step Functions.
SWF - Now legacy unless external signals and child processes
AppSync
Store and sync data across web app and mobile apps
Uses GraphQL
Transit Gateway
Connects VPC’s and On-Prem networks
PrivateLink
Expose service to VPC e.g. MSP serving app in their VPC to customers VPC.
Resource Access Manager - RAM
Share AWS resources with other AWS accounts
Share VPC
AWS Transit GW
Route53 Resolver Rules
Licence Manager Configs
CloudTrail
Log events and API calls. Think audit, compliance and governance.
EventBridge
NextGen CloudWatch Events
Event Bus - AWS Events - CloudWatch Events
Partner Event Bus - Saas Providers can send events i.e. ZenDesk, DataDog
Custom Events - Custom application events.