security Flashcards

1
Q

AWS responsibility?

A

Physical
Network
Hypervisor
Virtualization infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Customer responsibility?

A

Data
Application
OS
Permissions
Patching OS software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Identity and Access Management (IAM)

A

enables you to manage access to AWS services and resources securely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IAM Root user

A

created by default, should not share, has the most power
MFA should be enabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IAM Users

A

can be part of 0 to n groups

no permission by default.
need permission to provide :
launching an Amazon EC2 instance or creating an Amazon S3 bucke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IAM Identities

A

Users
Groups
Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IAM Group

A

Contains users only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IAM policy

A

JSON document that describes that what API calls that a user can and cannot make.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IAM role

A

an identity that you can assume to gain temporary access to permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS organization

A

allows to manage multiple aws accounts from a central location
centralized management
bulk discounts
consolidated bills
hierarchical groupings of accounts
control for Aws sercie and API actions access control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

you can apply SCP to whom?

A

Organization root,
individual member account
OU (Organizational Unit)

if affects all IAM users, groups and roles within an account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DDOS

A

is a deliberate attempt to make a website or application unavailable to users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS Shield

A

no cost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS Shield Advanced

A

paid service.
provided detailed attack diagnosis
ability to detect and mitigate sophisticated DDoS attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

KMS (Key manager service)

A

Data at rest (lying in storage)
Data in transit (Moving from one location to another)
AWS manages the encryption key
Services that have encyption enabled by default:
CloudTrail logs
S3 Glacier
Storage Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AWS WAF

A

is a web application firewall that lets you monitor network requests that come into your web applications.

17
Q

aws kms

A

Create cryptographic keys.

18
Q

amazon guard duty

A

A service that provides intelligent threat detection for your AWS infrastructure and resources.

19
Q

amazon inspector

A

A service that checks applications for security vulnerabilities and deviations from security best practices

20
Q

Security group

A

controls inbound and outbound traffic for Amazon EC2 instances?

21
Q

ACL network access control list

A

virtual firewall that controls inbound and outbound traffic at the subnet level.

22
Q

subnet

A

a section of a VPC in which you can group resources based on security or operational needs.