EC2 - Security Groups/Ports/SSH Flashcards

1
Q

What is a Security Group?

A

A Security Group is a virtual firewall for your EC2 instances that controls inbound and outbound traffic. It only allows specific types of traffic based on set rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of traffic do Security Groups control?

A

Security groups control inbound (from the internet to your EC2 instance) and outbound (from the EC2 instance to the internet) traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What information do you define in a security group rule?

A

Each rule specifies:

Type (e.g., SSH, HTTP)
Protocol (e.g., TCP)
Port (e.g., port 22 for SSH)
Source (e.g., IP range like 0.0.0.0/0 or another security group).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the default behaviors of a Security Group?

A

By default, all inbound traffic is blocked and outbound traffic is allowed.

Security groups can be attached to multiple EC2 instances, and each instance can have multiple security groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What happens if an EC2 instance is not accessible or times out?

A

If an EC2 instance doesn’t respond or times out, it’s likely a security group issue blocking inbound traffic. If you see a connection refused error, the traffic reached the instance but the application rejected it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the advanced feature of referencing other security groups?

A

You can configure a security group to allow traffic from other security groups, regardless of the EC2 instances’ IP addresses. This simplifies communication between instances without needing to manage IP addresses directly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does an inbound security group rule look like?

A

Type: SSH
Protocol: TCP
Port: 22
Source: 0.0.0.0/0 (all IPs, but typically more restrictive).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some important ports to remember for security groups?

A

22: SSH (for Linux EC2)
21: FTP (for file transfer)
80: HTTP (unsecured websites)
443: HTTPS (secured websites)
3389: RDP (for Windows EC2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is SSH used for in AWS EC2?

A

SSH (Secure Shell) is used to securely connect to EC2 instances for maintenance or other tasks, typically on Linux-based systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you connect to an EC2 instance using SSH on Mac or Linux?

A

On Mac or Linux, you can use the terminal and run the ssh command with the private key (.pem file) to connect to your EC2 instance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do you connect to an EC2 instance using SSH on Windows (pre-Windows 10)?

A

On Windows versions before 10, use PuTTY, a free SSH client, to connect to the EC2 instance using your private key.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you connect to an EC2 instance using SSH on Windows 10 and newer versions?

A

On Windows 10 or later, you can use the built-in SSH command in the Command Prompt or PowerShell (similar to Mac/Linux).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is EC2 Instance Connect and how does it work?

A

EC2 Instance Connect allows you to connect to EC2 instances directly from your web browser without needing to install anything. It supports Mac, Linux, and Windows.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which EC2 instance types are compatible with EC2 Instance Connect?

A

EC2 Instance Connect currently works with Amazon Linux 2 instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What should you do if you’re having trouble connecting to an EC2 instance via SSH?

A

Double-check your security group rules (make sure port 22 is open).
Verify the SSH command or Putty settings.
Check for typos in the IP address or command.
Try EC2 Instance Connect, as it might bypass other issues.
If all else fails, consult the troubleshooting guide.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly