Security and Compliance Flashcards

1
Q

Managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS

A

AWS Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A web application firewall that helps protect your web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Service that lets you create, manage, and control cryptographic keys across your applications and more than 100 AWS services

A

Amazon Key Management Service (KMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Service that lets you manage and access your keys on FIPS-validated hardware, protected with customer-owned, single-tenant HSM instances that run in your own Virtual Private Cloud (VPC).

A

AWS CloudHSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources

A

AWS Certificate Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Central resource for compliance-related information

A

AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation. Service checks VPC, DNS, and CloudTrail Logs

A

AWS GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure

A

AWS Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A service that enables you to assess, audit, and evaluate the configurations of your AWS resources

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data security and data privacy service that uses machine learning (ML) and pattern matching to discover and protect sensitive data

A

Amazon Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Service that monitors and records account API activity across your AWS infrastructure, giving you control over storage, analysis, and remediation actions

A

AWS CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Service that provides you with a comprehensive view of your security state in AWS and helps you check your environment against security industry standards and best practices

A

AWS Security Hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Service that automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables you to easily conduct faster and more efficient security investigations

A

Amazon Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the behaviors considered AWS abuse?

A

Spam
Port Scanning
Denial-of-service (DoS) attacks
Intrusion attempts
Hosting prohibited content
Distributing malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the actions exclusively permitted to the root user account?

A

Change account settings
Close AWS account
Change or cancel your AWS support plan
Register as a seller in the Reserved Instance Marketplace

How well did you know this?
1
Not at all
2
3
4
5
Perfectly