Security Flashcards
Threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.
AWS GuardDuty
Threat service that uses machine learning to automatically discover, classify, and protect sensitive data
AWS Macie
Threat service that manages DDoS Protection
AWS Shield
Permitted Services for Pen Test (No Approval needed)
EC2, NAT Gateway, ELB RDS (Aurora) Cloudfront API GW Lambda (inc Edge) Lightsail Elastic Beanstalk
Prohibited Pen Tests
DNS zone walking via Amazon Route 53 Hosted Zones
Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS
Port flooding
Protocol flooding
Request flooding (login request flooding, API request flooding)
CloudTrail
Enabled by default
New Trail defaults to all regions, can modify
One free trail
Additional Trails at cost