Security Flashcards
When creating an IAM user group, is it best practice to attach a policy or role?
Policy
You can not attach a role to a group
You have been asked by the auditors to produce regular reports in regards to your PCI compliance. Which service should you use to produce this as fast and as efficiently as possible?
AWS Audit Manager
AWS Audit Manager is an automated service that produces reports specific to auditors for PCI compliance, GDPR, and more.
AWS service that acts as a single source to get the compliance-related information that matters to you, such as AWS security and compliance reports or select online agreements.
AWS Artifact
Which web service can be used to provide users that you authenticate with short-term security credentials that can control access to your AWS resources?
AWS STS
Default Configuration of the Default NACL
Allow
Default Configuration of a Custom NACL
Deny
Instance states in which an attached security group can be changed?
Running
Stopped
For auditing purposes you would like to be informed if an object is restored to S3 from Glacier. What is the most efficient way you can do this?
Configure S3 notifications for restore operations from Glacier
- first add a notification configuration that identifies the events you want Amazon S3 to publish and the destinations where you want Amazon S3 to send the notification
Steps to Authenticate with Cognito
- Authenticate and Get Tokens
- Exchage Token for AWS credentials
- Access AWS services using credentials
How to easily generate Cost and Billing reports for multiple AWS Accounts?
AWS Cost and Usage Reports to generate reports,
How to easily put AWS Cost and Usage Reports to generate reports in CSV format into an S3 bucket
Can be setup to automatically store updated reports in Amazon S3 every 24 hours.
WS service can help you optimize your AWS environment by giving recommendations to reduce cost, increase performance, and improve security
Trusted Advisor
Which AWS service can you use to help ensure you don’t have cost overruns for your AWS resources?
AWS Budgets
Allows you to have alerts when getting to a certain budget threshold
AWS AI service that is built to detect fraud in your data.
AWS Fraud Detector
This allows you to centrally set up and manage firewall rules across multiple AWS accounts and applications in AWS Organizations.
AWS Firewall Manager