Domain 2: Security and Compliance (25%) Flashcards
Customer Responsibility Elements
- Customer Data
- Platform, applications, IAM
- OS, Network, and Firewall Configurations
- Client-side Data Encryption & Data Integrity Authentication
- Server-side encryption (file systems and/or data)
- Network Traffic protection (encryption, integrity, identity)
AWS Responsibility Elements
Compute
Storage
Database
Networking
Regions
Availability Zones
Edge Locations
Responsibility Differences between IaaS and PaaS
Customer accepts responsibility of OS, Middleware, and runtime with IaaS vs PaaS where these functions are managed for the customer
Compliance Information Location
https://aws.amazon.com/compliance/programs/
Encryption Key Management Solutions
Internal Storage
External Storage
Independent System or service
DLP Components
Discovery and classification
Monitoring
Enforcement
Define Federated Access
Integrate other technologies such as SAML or Microsoft Active Directory into the IAM account creation process
Security, Identity, and Compliance Services
- AWS Artifact
- AWS Certificate Manager (ACM)
- AWS CloudHSM
- Amazon Cognito
- Amazon Detective
- Amazon GuardDuty
- AWS Identity and Access Management (IAM)
- Amazon Inspector
- AWS License Manager
- Amazon Macie
- AWS Shield
- AWS WAF
Explain the Principle of Least Privilege
Limit user access to the minimum privileges required to do their job
User and Identity Management Features
- Access keys and password policies (rotation, complexity)
- MFA
- Groups/Users
- Roles
- Managed polices vs custom policies
- Root account tasks and protections
Root Only AWS Tasks
- Change account settings
- Restore IAM user permissions
- Activate IAM access to billing and cost management console
- Close AWS account
- Change/cancel support plan
- Register as a seller
- Configure S3 bucket to enable MFA
- Edit/delete S3 bucket policy with invalid VPC ID or endpoint ID
- Sign up for GovCloud
AWS Security Support Levels
Free
Developer
Business
Enterprise
AWS Developer Support Plan Features
AWS Trusted Advisor (7 checks)
AWS Personal Health Dashboard
Technical Support
Architecture Support
AWS Developer Support Plan Technical Support Response Times
(Business hours only)
24 hours general guidance
12 hours system problems and issues
AWS Business Support Plan Features
AWS Trusted Advisor (115 checks)
AWS Personal Health Dashboard
Technical Support
Architecture Support
AWS Support API
Third-Party Software Support
Access to Proactive Support Programs