Security & Complaince Section Flashcards

1
Q

What has KMS automatically enabled?

A
  • CloudTrail Logs
  • S3 Glacier
  • Storage Gateway
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What can opt-into KMS?

A
  • EBS volumes: encrypt volumes
  • S3 buckets: Server-side encryption of objects
  • Redshift database: encryption of data
  • RDS database: encryption of data
  • EFS drives: encryption of data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What captures information about IP traffic (VPC/Subnet/ElasticNetworkInterface flow logs) to help monitor & troubleshoot connectivity issues, and capture network infromation from AWS managed interfaces?

A

VPC Flow Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What 9 svcs can you not run pen test against?

A
  • Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers
  • Amazon RDS
  • Amazon CloudFront
  • Amazon Aurora
  • Amazon API Gateways
  • AWS Lambda and Lambda Edge functions
  • Amazon Lightsail resources
  • Amazon Elastic Beanstalk environments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly