Security and Compliance Flashcards

1
Q

What service would you use if you want access to 24/7 DDoS response team?

A

AWS Shield Advanced (Standard is free)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is AWS Inspector?

A

Runs checks against your instances to check for vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How would you analyze ELB access logs?

A

Use Athena in conjunction with S3 and ELB logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is GuardDuty?

A

It is Intelligent Threat Discovery using machine learning algorithms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do you enable emails for Trusted Advisor?

A

Via the UI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Cloud HSM?

A

Cloud Hardware Security Model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What would you use if you need FIPS 140-2 level 3 compliance?

A

CloudHSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do we know if our users are using MFA?

A

Download the Credentials Report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can we make sure a user can assign a role to an AWS resource?

A

Assign the IAM:PassRole to the user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is STS?

A

It grants limited and temporary access to AWS resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Identity Federation?

A

Federation lets users outside of AWS assume a temporary role to access AWS resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How can I find compliance documentation on AWS?

A

Use AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly