Incident Response Flashcards

1
Q

AWS AUP Categories

A
  1. No Illegal, Harmful or Offensive Use or Content
  2. No Security Violations
  3. No Network Abuse
  4. No Mass or unsolicited message abuse
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Pre approved PT services

A
Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers
Amazon RDS
Amazon CloudFront
Amazon Aurora
Amazon API Gateways
AWS Lambda and Lambda Edge functions
Amazon Lightsail resources
Amazon Elastic Beanstalk environments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Prohibited PT Services

A

DNS zone walking via Amazon Route 53 Hosted Zones
Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS
Port flooding
Protocol flooding
Request flooding (login request flooding, API request flooding)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Time taken by AWS team to approve Other Simulated Events

A

7 days post acknowledgement of the request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Preapproved vendors who can do DDoS Simulation

A

Red Wolf Security
NCC Group
AWS ProServ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Components of AWS CAF Security Perspective

A

Directive controls
Preventive controls
Detective controls
Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Directive Controls

A

establish the governance, risk, and compliance models within which the environment operates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Preventive Controls

A

protect your workloads and mitigate threats and vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Detective Controls

A

provide full visibility and transparency over the operation of your deployments in AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Responsive Controls

A

drive remediation of potential deviations from your security baselines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Cloud Security Incident domains that comes under Customer responsibility

A

Service Domain
Infrastructure Domain
Application Domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In the Incident domains in which domain is AWS API solely used for Incident response

A

Service Domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Indicators of Cloud Security Events

A
Logs and Monitors
Billing Activity
Threat Intelligence
Partner Tools
AWS Outreach
One-time Contract
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is AWS centralized logging solution

A

Amazon Elasticsearch Service (Amazon ES)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly