Incident Response Flashcards

1
Q

AWS AUP Categories

A
  1. No Illegal, Harmful or Offensive Use or Content
  2. No Security Violations
  3. No Network Abuse
  4. No Mass or unsolicited message abuse
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Pre approved PT services

A
Amazon EC2 instances
NAT Gateways
Elastic Load Balancers
Amazon RDS
Amazon CloudFront
Amazon Aurora
Amazon API Gateways
AWS Lambda and Lambda Edge functions
Amazon Lightsail resources
Amazon Elastic Beanstalk environments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Prohibited PT Services

A

DNS zone walking via Amazon Route 53 Hosted Zones
Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS
Port flooding
Protocol flooding
Request flooding (login request flooding, API request flooding)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How long does it take the AWS team to approve Other Simulated Events?

A

7 days post acknowledgement of the request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who are the 3 Pre-approved vendors that provide DDoS Simulation?

A

1) Red Wolf Security
2) NCC Group
3) AWS ProServ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Components of AWS CAF Security Perspective

A

1) Directive controls
2) Preventive controls
3) Detective controls
4) Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Directive Controls

A

establish the governance, risk, and compliance models within which the environment operates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Preventive Controls

A

protect your workloads
and
mitigate threats and vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Detective Controls

A

provide full visibility and transparency over the operation of your deployments in AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Responsive Controls

A

drive remediation of potential deviations from your security baselines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Cloud Security Incident domains that are the Customer’s Responsibility?

A

1) Service Domain
2) Infrastructure Domain
3) Application Domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In the Incident domains in which domain is AWS API solely used for Incident response

A

Service Domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Indicators of Cloud Security Events

A

1) Logs and Monitors
2) Billing Activity
3) Threat Intelligence
4) Partner Tools
5) AWS Outreach
6) One-time Contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the AWS centralized logging solution?

A

Amazon Elasticsearch Service (Amazon ES)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly