Module 6 - Security Flashcards

1
Q

What is the model that describes the responsibility of the customer and of AWS?

A

Shared responsibility model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What enables you to manage access to AWS services and resources securely.

A

AWS Identity and Access Management (IAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the principle of least privilege?

A

A user is granted access only to what they need.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Suppose that your company has multiple AWS accounts. You can use ________ to consolidate and manage multiple AWS accounts within a central location.

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What can you use to centrally control permissions for the accounts in your organization?

A

Service control policies (SCPs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is AWS Artifact?

A

It is a service that provides on-demand access to AWS security and compliance reports and select online agreements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Suppose that your company needs to sign an agreement with AWS regarding your use of certain types of information throughout AWS services. You can do this through _______

A

AWS Artifact Agreements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Next, suppose that a member of your company’s development team is building an application and needs more information about their responsibility for complying with certain regulatory standards. You can advise them to access this information in ________

A

AWS Artifact Reports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

___________ automatically protects all AWS customers at no cost. It protects your AWS resources from the most common, frequently occurring types of DDoS attacks.

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

________ is a paid service that provides detailed attack diagnostics and the ability to detect and mitigate sophisticated DDoS attacks.

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is AWS Key Management Service (AWS KMS)

A

It allows you to use cryptographic keys to access your encrypted data whether at rest or on transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a web application firewall that lets you monitor network requests that come into your web applications?

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

To perform automated security assessments, they decide to use __________
_________ helps to improve the security and compliance of applications by running automated security assessments. It checks applications for security vulnerabilities and deviations from security best practices, such as open access to Amazon EC2 instances and installations of vulnerable software versions.

A

Amazon Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

______ is a service that provides intelligent threat detection for your AWS infrastructure and resources. It identifies threats by continuously monitoring the network activity and account behavior within your AWS environment.

A

Amazon GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly