Domain 2: Security and Compliance (25%) Flashcards

1
Q

Customer Responsibility Elements

A
  • Customer Data
  • Platform, applications, IAM
  • OS, Network, and Firewall Configurations
  • Client-side Data Encryption & Data Integrity Authentication
  • Server-side encryption (file systems and/or data)
  • Network Traffic protection (encryption, integrity, identity)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS Responsibility Elements

A

Compute
Storage
Database
Networking
Regions
Availability Zones
Edge Locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Responsibility Differences between IaaS and PaaS

A

Customer accepts responsibility of OS, Middleware, and runtime with IaaS vs PaaS where these functions are managed for the customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Compliance Information Location

A

https://aws.amazon.com/compliance/programs/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Encryption Key Management Solutions

A

Internal Storage
External Storage
Independent System or service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

DLP Components

A

Discovery and classification
Monitoring
Enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define Federated Access

A

Integrate other technologies such as SAML or Microsoft Active Directory into the IAM account creation process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security, Identity, and Compliance Services

A
  • AWS Artifact
  • AWS Certificate Manager (ACM)
  • AWS CloudHSM
  • Amazon Cognito
  • Amazon Detective
  • Amazon GuardDuty
  • AWS Identity and Access Management (IAM)
  • Amazon Inspector
  • AWS License Manager
  • Amazon Macie
  • AWS Shield
  • AWS WAF
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain the Principle of Least Privilege

A

Limit user access to the minimum privileges required to do their job

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

User and Identity Management Features

A
  • Access keys and password policies (rotation, complexity)
  • MFA
  • Groups/Users
  • Roles
  • Managed polices vs custom policies
  • Root account tasks and protections
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Root Only AWS Tasks

A
  • Change account settings
  • Restore IAM user permissions
  • Activate IAM access to billing and cost management console
  • Close AWS account
  • Change/cancel support plan
  • Register as a seller
  • Configure S3 bucket to enable MFA
  • Edit/delete S3 bucket policy with invalid VPC ID or endpoint ID
  • Sign up for GovCloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

AWS Security Support Levels

A

Free
Developer
Business
Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS Developer Support Plan Features

A

AWS Trusted Advisor (7 checks)
AWS Personal Health Dashboard
Technical Support
Architecture Support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS Developer Support Plan Technical Support Response Times

A

(Business hours only)
24 hours general guidance
12 hours system problems and issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

AWS Business Support Plan Features

A

AWS Trusted Advisor (115 checks)
AWS Personal Health Dashboard
Technical Support
Architecture Support
AWS Support API
Third-Party Software Support
Access to Proactive Support Programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AWS Business Support Plan Technical Support Response Times

A

(24/7)
24 hours general guidance
12 hours system problems and issues
4 hours production system problems
1 hour production system outages

17
Q

AWS Enterprise Support Plan Features

A

Technical Support
Proactive Support Programs
Support Concierge
Account Onboarding

18
Q

AWS Enterprise Support Plan Technical Support Response Times

A

(24/7)
24 hours general guidance
12 hours system problems and issues
4 hours production system problems
1 hour production system outages
15 minutes for critical systems outages

19
Q

AWS Documentation Sources

A

AWS Knowledge Center
Security Center
Security Forum
Security Blogs
Partner System Integrators

20
Q

Trusted Advisor Features

A

Cost Optimization
Performance
Security Checks
Service Limits

21
Q

Network Security Capabilities

A
  • Security Groups
  • Network ACLs
  • AWS WAF
  • 3rd Party products form Marketplace
22
Q

Management, Montitoring, and Governance Services

A
  • AWS Auto Scaling
  • AWS Budgets
  • AWS CloudFormation
  • AWS CloudTrail
  • Amazon CloudWatch
  • AWS Config
  • AWS Cost and Usage Report
  • Amazon EventBridge (Amazon CloudWatch Events)
  • AWS License Manager
  • AWS Managed Services
  • AWS Organizations
  • AWS Secrets Manager
  • AWS Systems Manager
23
Q

Describe Credential Report

A

User and access privileges report for audit and compliance