Security & Compliance Flashcards
How to protect against DDoS on AWS (5 ways)
- AWS Shield Standard
- AWS Shield Advanced
- AWS WAF
- CloudFront
- Route 53
What is AWS WAF?
Web Application Firewall, protects your application from common web exploits (layer 7)
What is penetration testing?
Attacking your own infrastructure to carry out tests
What is AWS KMS?
Key Management Service - AWS manages the encryption keys for us
What is Certificate Manager (ACM)?
Lets you easily provision, manage and deploy SSL/TLS certificates
What is Artifact?
A portal that provides customers with on-demand access to AWS compliance documentation and AWS agreements
What is GuardDuty?
Uses machine learning algorithms to provide intelligent threat discovery to protect AWS accounts
What is Inspector?
Provides automated security assessments for EC2 instances and ECR
What is config?
Helps with auditing and recording compliance of your AWS resources by recording configurations and changes over time
What is Macie?
A fully-managed data security and data privacy service that uses machine learning and pattern matching to discover and protect your sensitive data in AWS
What is Security Hub?
A central security tool to manage security across several AWS accounts and automate security checks
What is Amazon Detective?
Analyses, investigates and quickly identifies the root cause of security issues or suspicious activities
What is AWS Abuse
Report suspected AWS resources used for abusive or illegal purposes