Security Flashcards
Explain the shared responsibility model?
Customers are responsible for security IN the cloud, aws responsible for security of the cloud
What is a root user?
A root user is the owner, gives permission to other users
What is the default for an IAM user?
No permissions
Do you need to grant permissions to an IAM user?
Yes
What are policies?
Documents that allow and deny permissions
What are a collection of IAM users known as?
A collection of IAM users are known as an IAM group
When should an IAM user be assigned an IAM role?
An IAM user be assigned an IAM role when they need TEMPORARY permissions
What is the name given to a combination of multiple AWS groups?
An organization is a combination of multiple AWS groups
In an Organization, who is the root user?
In an organization the root user is automatically generated as the parent container of the AWS groups
What is the name given to groups of accounts that are created to make it easier to manage permissions?
Organizational units
What is Artifact?
Artifact lets you:
1. Access compliance reports
2. Select online agreements
What is the Customer Compliance Centre?
the Customer Compliance Centre is where you learn about compliance
ie., overview of risk, auditing security checklist
Customers are responsible for security IN the cloud. Give some examples:
- Customer data
- Platforms, apps, identity and access management
- Operating systems, network and firewall config
- client-side data encryption
- server side encryption
- network traffic protection
ie., selecting, configuring and patching operating systems that will run on EC2 instances, configuring security groups and managing user accounts
AWS are responsible for security “OF” the cloud. Give some examples:
- Software
- Compute, Storage, Database, Networking
- Hardware / AWS global infrastructure
- Regions, availability zones, edge locations
ie.,
physical security of data centers
hardware and software infrastructure
network infrastructure
virtualization infrastructure
What real life example could you compare the shared responsibility model to?
AWS - responsible for constructing the house
Customer - responsible for ensuing the house is secure by locking the doors