Security and Compliance Flashcards
Amazon’s automated security assessment service is called?
Amazon Inspector
What is Amazon Inspector?
An automated security assessment service
What is Amazon GuardDuty?
A continuous security monitoring service that analyzes and processes a variety data sources and machine learning to identify unexpected and potentially unauthorized or malicious activity within your AWS environment
Amazon’s continuous security monitoring service that analyzes and processes a variety data sources and machine learning to identify unexpected and potentially unauthorized or malicious activity within your AWS environment is called?
Amazon GuardDuty
What does Amazon CloudTrail do?
Logs activity across your AWS infrastructure (who did what when)
Amazon’s service that enables governance, compliance, operational auditing, and risk auditing by logging activity across your AWS infrastructure is called
Amazon CloudTrail
Which AWS tool captures information about IP traffic going to and from network interfaces in your Virtual Private Cloud (VPC)?
VPC Flow Logs
Which AWS tool is a managed service for mitigating distributed denial of service (DDoS) attacks?
AWS Shield
An internet gateway traffic into and out of? How is that different than a virtual private gateway?
The internet gateway controls traffic from the internet into and out of the Virtual Private Cloud (VPC). The Virtual Private Gateway controls traffic in and out of a Security Group.
What are Service Control Policies (SCPs)?
Service Control Policies are a feature of AWS Organizations and restrict available permissions. They do not grant permissions.
What is the difference between managed IAM policies and custom IAM policies?
Custom polices are editable. Managed policies are not.
What is AWS WAF?
Configurable web application firewall
Amazon’s configurable web application firewall is called?
AWS WAF
What does AWS Shield cost?
AWS Shield is automatically included at no extra cost. For added protection against DDoS attacks, AWS offers AWS Shield Advanced for an additional charge.