AWS Shared Responsibility Security Model Flashcards
1
Q
What is meant by SHARED security responsibility?
A
AWS is responsible for portions of the cloud and you, the customer, also have portions of the cloud that you are responsible for.
2
Q
Can you give some examples of YOUR responsibility?
A
- IAM
- Multi-factor authentication
- Password/Key rotation
- Access Advisor
- Trusted Advisor
- Security Groups
- Resource-based Policies
- Access Control Lists
- Virtual Private Cloud (VPC)
- Port scanning is against the rules on your own environment (ask AWS if you want to do this)
- Operating system level patches
3
Q
Can you give some examples of AWS’s responsibilities?
A
- Physical server level & below
- Physical environment security & protection
- Storage device decommissioning according to industry standards
- Personnel security
- Network device security and ACLs
- AWS API endpoints - SSL
- DDOS protection
- EC2 instances and spoofing protection (Ingress/Egress filtering)
- EC2 Instance hypervisor isolation (instances on the same physical device but still independent)