Module 6: Security Flashcards
A way to consolidate and manage multiple AWS accounts within a central location.
AWS Organizations
In AWS Organizations, you can centrally control permissions for the accounts in your organization by using
service control policies (SCPs)
This enable you to place restrictions on the AWS services, resources, and individual API actions that users and roles in each account can access.
service control policies (SCPs)
What can SCPs be applied to
An individual member account
root
OU
An identity that you create in AWS
IAM user
IAM users have no default permissions assigned, True or False
True
A document that allows or denies permissions to AWS services and resources
IAM policy
A collection of IAM users
IAM group
An identity that you can assume to gain temporary access to permissions
IAM role
shared responsibility model: Database
AWS
shared responsibility model: Server side encryption
Customer
shared responsibility model: Networking
AWS
shared responsibility model: Storage
AWS
shared responsibility model: Customer Data
Customer
shared responsibility model: Storage
AWS
shared responsibility model: Regions
AWS
shared responsibility model: Network traffic protection
Customer
a service that provides on-demand access to AWS security and compliance reports and select online agreements
AWS Artifact
With this you can review, accept, and manage agreements for an individual account and for all your accounts in AWS Organizations. Different types of agreements are offered to address the needs of customers who are subject to specific regulations, such as the Health Insurance Portability and Accountability Act (HIPAA).
AWS Artifact Agreements
This report provides compliance reports from third-party auditors
AWS Artifact Reports
A service that protects applications against DDoS attacks
AWS Shield
AWS Shield provides two levels of protection:
Standard and Advanced
This level of aws shield automatically protects all AWS customers at no cost. It protects your AWS resources from the most common, frequently occurring types of DDoS attacks.
Standard
This level of aws shield is a paid service that provides detailed attack diagnostics and the ability to detect and mitigate sophisticated DDoS attacks.
Advanced
This level of aws shield integrates with other services such as Amazon CloudFront, Amazon Route 53, and Elastic Load Balancing. Additionally, you can integrate AWS Shield with AWS WAF by writing custom rules to mitigate complex DDoS attacks.
Advanced