Security and Monitoring Flashcards

1
Q

Default security group behavior

A

deny all inbound traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SNMP

A

Simple Network Mgmt Protocol

monitor and manage network devices connected over an IP. SNMP is used for communication between routers, switches, firewalls, load balancers, servers, CCTV cameras, and wireless devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

HTTP

A

Hypertext transfer protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

TCP

A

Transmission Control Protocol

enables application programs and computing devices to exchange messages over a network. It is designed to send packets across the internet and ensure the successful delivery of data and messages over networks.

TCP port 80 is used for non-encrypted web services, and TCP port 443 is used for encrypted web services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IP

A

Internet Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ICMP

A

Internet Message Control Protocol

used for reporting errors and performing network diagnostics. In the error reporting process, ICMP sends messages from the receiver to the sender when data does not come though as it should.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

WMI

A

Windows Management Instrumentation Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SSL

A

Secure Socket Layers

securing an internet connection by encrypting data sent between a website and a browser (or between two servers). It prevents hackers from seeing or stealing any information transferred, including personal or financial data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Traceroute

A

Tool that use successive echo packets to display the path to the destination and the response time of each hop (ping)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Simple fault monitoring

A

system polls registered devices at established intervals to verify if they respond.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

packet analyzer…or packet sniffer

A

standard tool for capturing packets.

Logs each packet it intercepts, decodes the packet, and presents the values of the various fields within the packet for examination.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Traffic Mirroring

A

direct network traffic coming to and from an EC2 instance to a separate Amazon EC2 based packet analyzerto analye

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

five phases of reliability pillar

A

generate, aggregate, alert, analyze, , storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cloudwatch

A

Monitoring service for AWS workloads and resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cloudwatch Events

A

near real-time stream of events which describe resources changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What do you use to send an email with a Cloudwatch Alarm?

A

SNS topic

17
Q

Most important metrics to track

A
  1. Bandwidth capacity maximum data transmission rate
  2. Throughput: megabyte or gigabyte per second of data packets that are successfully being sent
  3. Latency
  4. Packet Loss
  5. Retransmission
  6. Availability (up tiime)
    7 Connectivity: Nodes properly working
  7. Network and Server response time
  8. Cloudwatch Metrics
18
Q

Transit Gateway Manager

A

provides a single global view of your private network to visualize and monitor the health of your Amazon VPCs, Transit Gateways, Direct Connect, and VPN connections to branch locations and on-premises networks.

19
Q

Wavelength

A

AWS Wavelength embeds AWS compute and storage services within 5G networks, providing mobile edge computing infrastructure for developing, deploying, and scaling ultra-low-latency application

20
Q

VPC Flow Logs

A

information about the IP traffic going to and from network interfaces in your VPC.

21
Q

SIM

A

Security Information Monitoring

22
Q

SEM

A

Security Event Monitoring

23
Q

AWS Compliance Frameworks

A

ensure regulation of data happens securely.

24
Q

Benching Tools

A

How your network is performing.
Throughput and bandwidth are measured by benching tools

25
Q

iPerf and IPefr3

A

Tools for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, buffers, and protocols (TCP, UDP, SCTP with IPv4 and IPv6). For each test, they report the bandwidth, loss, and other parameters.

26
Q

ExtraHop

A

monitoring solution for security, network performance, and the cloud. It gives detailed metrics on average bandwidth utilization, average throughput, and more.

27
Q

Netperf

A

CLI tool similar to iPerf that measures throughput and benchmarking speeds.

28
Q

CloudWatch agent

A

collect metrics for your Amazon EC2 instances and your on-premises servers.

29
Q

How does Cloudwatch categorize Data?

A

A Namespace contains data and each different namespace holds different data. For example, all AWS data is contained inside a namespace named AWS/service.

Dimensions separates resources in the namespace

30
Q

Systems Manager Agent (formerly ssm)

A

view and control your infrastructure on AWS

automate operational tasks across your AWS resources

maintain security and compliance by scanning your managed instances and reporting on (or taking corrective action on) any policy violations it detects.

Once installed EC2 becomes a managed instance

31
Q

How do you collect Systems Mgr Agent logs

A

Sending to cloudwatch

32
Q

T/F you can connect Cloudwatch Logs to your VPC using an endpoint.

A

True

33
Q

Cloudwatch Insights

A

Visualize data in graphs and supports Cloudwatch Query language

34
Q

Cloudwatch alarm types

A

Metric (one) , Composite (group)

35
Q
A