Cloud Security Flashcards
What is the AWS Abuse team?
Team to be contacted when AWS resources are being used for abusive behaviour.
What is the AWS Security team?
AWS team responsible for security of services offered by AWS.
IAM Group vs Security Group
IAM Group is a group of users with similar permissions.
Security Group is established on EC2 instance to control network traffic.
What is a NACL or ACL?
Network Access Control List – optional layer of security for VPC that acts as a firewall on subnet level.
What are Route Tables?
A route table contains a set of rules, called routes, that are used to determine where network traffic is directed.
What do Security Groups do?
Act as a firewall for associated Amazon EC2 instances, controlling both inbound and outbound traffic at the instance level.
What is the AWS Shared Responsibility Model?
A security model that defines what you (as an AWS account holder/user) and Amazon Web Services are responsible for when it comes to security and compliance.
AWS is responsible for security of the cloud, you are responsible for security in the cloud.
What aspects of Security and Compliance is AWS responsible for in the Shared Responsibility Model?
Components from the host operating system and the virtualization layer down to the physical security of the facilities in which the service operates.
What aspects of Security and Compliance are you responsible for in the Shared Responsibility Model?
Guest operating system (including updates and security patches), other associated application software, as well as the configuration of the AWS provided security group firewall.
How would the Shared Responsibility Model apply to an EC2 instance?
AWS is responsible for:
1. The setup and maintenance of the physical hardware located at each AWS data centre
2. The physical security of the data centres
(locks, keys, security guards, etc.)
3. The setup and maintenance of the host virtualization software
You are responsible for:
- Network level security (Security groups & NACL’s)
- OS patches and updates
- IAM user access management
- Client and Server side data encryption
What are the AWS services with built-in DDOS attack protection/mitigation?
- Cloudfront
- Route 53
- WAF (Web Application Firewall)
- Elastic Load Balancing
- Security groups & VPC’s
What services are customers allowed to carry out security assessments/pen tests on with no prior approval required?
- Amazon EC2 instances, NAT gateways, and ELB’s
- RDS
- Cloudfront
- Aurora
- API gateways
- Lambda & Lambda edge functions
- Lightsail resources
- Elastic Beanstalk environments
What are the currently prohibited security activities?
- DNS Zone walking via Route 53 hosted zones
- DOS, DDOS, simulated DOS, simulated DDOS
- Port flooding
- Protocol flooding
- Request flooding
(login request flooding, API request flooding)
What are the AWS Assurance/Compliance 3 Major Categories?
Certifications/Attestations
Laws, Regulations, and Privacy
Alignments/Frameworks
What are the major AWS Compliance Certifications to be aware of?
ISO 27001
PCI DSS Level 1
SOC 1
SOC 2
SOC 3
A _____ _____ is a check to see if your AWS infrastructure meets a given compliance standard.
(I.e. - even though AWS itself might,
your infrastructure or application may not)
Gap Audit
What is WAF?
Web Application Firewall
Protects from common web exploits that could
affect availability
compromise security
consume excessive resources
What is the difference between using
Elastic Load Balancers with security groups as security
vs
using a WAF?
ELB/Security Groups secure protocols and ports (Layer 4)
WAF - Can actually read the data being sent (Layer 7)
What is AWS Shield?
Managed DDoS protection
safeguards web apps
always-on detection
enacts inline mitigations
What are the two tiers of AWS Shield?
Standard - free and comes by default
Advanced $3K/month
What is AWS Inspector?
Automated Security Assessment
Audits for vulnerabilities or deviation from best practices
Produces a lined report ordered by criticality
Installed on your EC2 instances
What is AWS Trusted Advisor?
Optimization guidance for your environment for
cost optimization
performance
security
fault tolerance
What are the two levels of AWS Trusted Advisor?
Core Checks and Recommendations (free)
Full Trusted Advisor - Business and Enterprise only