Security Flashcards
AWS WAF
Web Application Firewall- gives you control over how traffic reaches your applications by enabling you to create security rules
Amazon GuardDuty
threat detection service that continuously monitors for malicious activity and unauthorized behavior
AWS CloudTrail
service that enables governance, compliance, operational auditing, and risk auditing of your AWS account.
Permitted security assessments
– Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers
– Amazon RDS
– Amazon CloudFront
– Amazon Aurora
– Amazon API Gateways
– AWS Lambda and Lambda Edge functions
– Amazon Lightsail resources
– Amazon Elastic Beanstalk environments
Prohibited Security assesments
– DNS zone walking via Amazon Route 53 Hosted Zones
– Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS
– Port flooding
– Protocol flooding
– Request flooding (login request flooding, API request flooding)
Amazon Cognito Identity Pool
provides temporary AWS credentials for users who are guests (unauthenticated) and for users who have been authenticated and received a token.
Amazon Cognito User Pool
a user pool is a user directory in Amazon Cognito.
AWS Single Sign-On
this service lets you centrally manage SSO access to multiple AWS accounts.
AWS Shield
this is simply a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.
AWS CloudHSM
is standards-compliant and enables you to export all of your keys to most other commercially available HSMs, subject to your configurations.