Security and Compliance Services Flashcards

1
Q

What is the Customer responsible for in the Cloud

A

Managment of guest OS, customer data, IAM, NACL, client and server side encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is AWS responsible for of the Cloud

A

Setup and maintenance of physical hardware, maintenace of host virtualisation software, compute, storage, database, networking, global infrastructure (regions, az and edge locations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

DDoS and penetration testing

A

AWS customers can do this without prior approval. They cannot however do DNS zone walking, DDoS and floodings.
CloudFront and Route 53 aid in DDoS mitigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Other AWS Security Services

A
  1. AWS Org = centralised management of AWS accounts and billings
  2. Amazon GuardDuty = Threat detection
  3. Amazon Inspector = Analyses VPC environment for potential security issues (gives findings and recommendations)
  4. AWS Shield = Managed DDoS protection
  5. WAF = Monitors web requests (can allow/deny access)
  6. AWS Artifact = Portal access to AWS compliance docs e.g PCI and ISO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is AWS Key Management Service

A

Encryptes data and provided key storage. Keys can be made in KMS, CloudHSM or imported. KMS integrates with S3, Databases, CloudTrail and SNS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Other Services?

A

Amazon Athena = Serverless sql service
Amazon EMR = Managed Hadoop framework, big data
Amazon Lightsail = private virtual server with prepackaged setups
Amazon Rekognition = Video/image analysis
Amazon Mech Turk = crowdsourced marketplace

How well did you know this?
1
Not at all
2
3
4
5
Perfectly