Security and Compliance Flashcards
What service would you use if you want access to 24/7 DDoS response team?
AWS Shield Advanced (Standard is free)
What is AWS Inspector?
Runs checks against your instances to check for vulnerabilities
How would you analyze ELB access logs?
Use Athena in conjunction with S3 and ELB logs
What is GuardDuty?
It is Intelligent Threat Discovery using machine learning algorithms
How do you enable emails for Trusted Advisor?
Via the UI
What is Cloud HSM?
Cloud Hardware Security Model
What would you use if you need FIPS 140-2 level 3 compliance?
CloudHSM
How do we know if our users are using MFA?
Download the Credentials Report
How can we make sure a user can assign a role to an AWS resource?
Assign the IAM:PassRole to the user
What is STS?
It grants limited and temporary access to AWS resources
What is Identity Federation?
Federation lets users outside of AWS assume a temporary role to access AWS resources
How can I find compliance documentation on AWS?
Use AWS Artifact