Deck 3 Flashcards

1
Q

Compliance of AWS

A
PCI DSS Level l (QSA Audit Still Required)
ISO 9001
ISo 27001
SOC 1,2,3
FISMA/DIACAP and FEDRAMP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Industry specific standards

A

HIPAA
Cloud Security Alliance (CSA)
Motion Picture Association of America (MPAA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Areas of AWS you are responsible for

A
EC2 patching
VPC setup
S3
Account management 
Users access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is used to monitor API access

A

CloudTrail is recommended to be enabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How storage decommissioned at Amazon

A
  • DoD 5220.22-M or NIST 800-88 Guidelines

- All storage devices are wiped and physically destroyed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Network security components

A

HTTPS using SSL/TLS
VPC
IpSec VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is the Amazon Corporate network segregated from the corporate network

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Network monitoring provided by Amazon

A
DDos blocks
Man in the middle
IP Spoofing
Port Scanning
Sniffing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS password requirements

A

6 characters minimum, up to 128.

You can also require mixed case, numbers and special characters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Keypair security

A

Required by EC2 instances - 2048-bit SSH-2 RSA keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Keys used by S3, API, REST, AWS SDK

A

Access Keys (comprised of Key ID and Secret

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Use of X509 Certs

A

Used to sign SOAP based requests (S3). You can used Amazon based certs or generate your own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS Trusted Adviser can make recommendations on:

A
Open Ports
No internal IAM accounts
Public S3 access
CloudTrail logging not enabled for 
Not using MFA for root account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How is virtual machine data protected

A

VDs are zeroed out

Memory is scrubbed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Does Amazon have access to VM’s

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Default network traffic restriction

A

All ingress blocked and all outbound allowed

17
Q

EBS Encryption

A

Available on volumes and snapshots 256AES

Occurs on the EC2 Instance that host the volume

18
Q

Types of instance EBS encryption is available on

A

Only the more power types M3,C3,R3,G2

19
Q

Additional layer of security that act at the subnet level

A

Network ACLs

20
Q

Default # of VPC per region

A

5

21
Q

How many internet gateways can you attache to your custom VPC?

A

1

22
Q

What could be required to be assigned to an EC2 instance if it required internet access with no NAT

A

The instance needs either an Elastic IP address/Public IP address assigned to it.

23
Q

Amazon SWF restrict me to use specific programming languages.

A

False. SWF.

24
Q

A __________ is a document that provides a formal statement of one or more permissions.

A

Policy

25
Q

What function of an AWS VPC is stateless

A

Network ACLs

26
Q

Amazon’s SNS has the following subscribers

A

Lambda, SQS, HTTPS, Email, SMS