Security and Compliance Flashcards
What framework specified requirements for establishing implementing operating monitoring reviewing maintaining and improving a documented information security management system
ISO 27001:2005
What framework is government wide program that provides a standardized approach to security assessment authorization and continuous monitoring for cloud services
Fed ramp
What framework has the goal of the level to make it easier for people keep health insurance protect confidentiality and security of health information
HIPAA
What framework is focused on critical infrastructure cyber security
NIST
What framework is a widely accepted set of policies to optimize the scrutiny of card transactions
PCI
What AWS service protects against DDOS attacks
AWS shield
What technologies mitigate a DDOS attack?
ELB Route53 Cloudfront wAF Auto scaling Cloudwatch
Do you need to request pen test authorization if you plan on using a pen testing product from the AWS marketplace?
Yes
What tools can you use to create custom policies?
JSON
Visual editor
When can you attach roles to EC2 instances?
Anytime
When does a policy change take effect when made
Immediately
How can you enable MFA
CLI
Console
What service enables you to enforce MFA at the command line?
STS
What service allow temporary access to AWS resources?
STS
What are three STS sources
Federation AD
Federation mobile apps
Cross account access
What are the four logging services in AWS?
Cloudtrail
Config
Cloudwatch logs
VPC flow logs
What logging service tracks API calls?
Cloudtrail
What log service track all configure changes?
AWS config
What log service tracks network traffic?
VPC flow logs
Who can access AWS hypervisors?
AWS administrators