Security Flashcards

1
Q

Threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.

A

AWS GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat service that uses machine learning to automatically discover, classify, and protect sensitive data

A

AWS Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat service that manages DDoS Protection

A

AWS Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Permitted Services for Pen Test (No Approval needed)

A
EC2, NAT Gateway, ELB
RDS (Aurora)
Cloudfront
API GW
Lambda (inc Edge)
Lightsail
Elastic Beanstalk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Prohibited Pen Tests

A

DNS zone walking via Amazon Route 53 Hosted Zones
Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS
Port flooding
Protocol flooding
Request flooding (login request flooding, API request flooding)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CloudTrail

A

Enabled by default

New Trail defaults to all regions, can modify

One free trail

Additional Trails at cost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly