Security & Complaince Section Flashcards
1
Q
What has KMS automatically enabled?
A
- CloudTrail Logs
- S3 Glacier
- Storage Gateway
2
Q
What can opt-into KMS?
A
- EBS volumes: encrypt volumes
- S3 buckets: Server-side encryption of objects
- Redshift database: encryption of data
- RDS database: encryption of data
- EFS drives: encryption of data
3
Q
What captures information about IP traffic (VPC/Subnet/ElasticNetworkInterface flow logs) to help monitor & troubleshoot connectivity issues, and capture network infromation from AWS managed interfaces?
A
VPC Flow Logs
4
Q
What 9 svcs can you not run pen test against?
A
- Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers
- Amazon RDS
- Amazon CloudFront
- Amazon Aurora
- Amazon API Gateways
- AWS Lambda and Lambda Edge functions
- Amazon Lightsail resources
- Amazon Elastic Beanstalk environments