Security Flashcards

1
Q

Security

What service provides visibility into user & resource activity and helps you enable operational and risk auditing, governance, and compliance of your AWS account

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security

What 4 pieces of informaiton does CloudTrail record

A

User
Account
Source IP
Timestamp

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security

What 2 use cases is CloudTrain good for

A

After-the-fact incident investigation
near real time intrusion detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security

What service acts as “CCTV for your AWS account”

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security

What service provides free DDOS protection against layer 3 & 4 attacks

A

Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security

What service provides protection against http/https (layer 7) attacks

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security

AWS WAF has 3 opperating modes

what are they?

A

(1) Allow all but …
(2) Deny all but …
(3) Count all that match …

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security

What service provides threat detection using AI to determine a baseline for your account

A

Guard Duty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security

AWS Guard Duty monitors 3 things

What are they?

A

CloudTrail Logs
VPC Flow Logs
DNS Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security

Service that provides a single-pane-of-glass for all firewall rules accross accounts

A

Firewall Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Security

Service that searches for PII within your S3 buckets

A

Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Security

Automated security assesment service providing continuous scanning of either network’s (VPC’s) or hosts (EC2’s)

A

Amazon Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Security

When would you choose to use Parameter Store over secrets manager

A

Its free
Dont need key rotation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security

When would you choose to use Secrets Manager over Parameter Store

A

You need key rotation
You need PW Generation from cloudformation
You have more than 10k secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Security

How can you allow access to single files within a S3 bucket securely

A

Use a presigned URL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Security

How can you allow access to a group of files within a S3 bucket securely

A

Use cookies

17
Q

Security

What is the term given to the unique identifier for an AWS resource

A

ARN

18
Q

Security

What service can you use to create, manage and deploy & automatically renew your SSL certs

A

Certificate Manager

19
Q

Security

Certificate Manager supports SSL certs for 3 AWS services

what are they

A

ELB
CloudFront
API Gateway

20
Q

Security

What service allows you to Continually audit your AWS usage to simplify risk and compliance assessment and map your compliance requirements to AWS usage data with prebuilt and custom frameworks and automated evidence collection.

A

AWS Audit Manager

21
Q

Security

What service is a source of all your compliance reports

iso, pci….

A

AWS Artifact

22
Q

Security

What service provides Authentication and Authorization

like Okta

A

Amazon Cognito

23
Q

Security

What service is great for root-cause analysis of security events & for linking interactions between users and resources

A

Amazon Detective

24
Q

Security

What service provides a physical firewall to filter traffic before it gets to your VPC

A

AWS Network Firewall

25
Q

Security

What service acts as a single-pane-of-glass to view all your security alerts accross multiple accounts and services

A

AWS Security Hub

26
Q

Security

Service to automate the detection of fraud using machine learning and artificial intelligence

A

Fraud Detector