Security & Compliance Flashcards

1
Q

What service protects against DDoS attacks for all customers at no additional costs

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Premium service that protects against more sophisticated attacks at a cost of $3,000 per month per org.

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What service is a web application firewall that helps you protect against common web exploits and bots that can affect availability, compromise security, or consume excessive resources?

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What two services help mitigate DDoS attacks by utilizing the Edge?

A

CloudFront & Route53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are prohibited activities when doing penetration test?

A

DNS
DoS or DDoS
Port Flooding
Protocol Flooding
Request Flooding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: You can do any type of penetration testing on your applications within AWS?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

At what two points does encryption need to take place for data?

A

At Rest & In Transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which service lets you create, manage, and control cryptographic keys across your applications and AWS services?

A

AWS KMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What service does AWS provision encryption hardware where users manage encryption keys?

A

CloudHSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What service provisions, manages, and deploys SSL/TLS Certificates?

A

AWS Certificate Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Helps you manage, retrieve, and rotate database credentials, API keys, and other secrets throughout their lifecycles.

A

AWS Secrets Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Provides on-demand access to security and compliance reports from AWS and ISVs who sell their products on AWS Marketplace.

A

AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation. Uses ML and 3rd, party data.

A

AWS GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What service can protect against CryptoCurrency attacks?

A

AWS GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Automated vulnerability/security management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure.

A

AWS Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What service continually assesses, audits, and evaluates the configurations and relationships of your resources on AWS, on premises, and on other clouds to check for compliance issues?

A

AWS Config

17
Q

Data security service that uses machine learning (ML) and pattern matching to discover and help protect your sensitive data, like PII (personally identifiable information).

A

AWS Macie

18
Q

What central security tool manages security across several AWS Accounts and is a cloud security posture management service that performs security best practice checks, aggregates alerts, and enables automated remediation?

A

Security Hub

19
Q

What service analyzes, investigates, let’s the user visualize, and quickly identifies the root cause of security issues or suspicious activities?

A

Amazon Detective

20
Q

What should you do if you encounter AWS services being used for abusive or illegal purposes?

A

Report it to the AWS Abuse Team

21
Q

What actions can only be performed by the Root User account?

A

Change account settings
Close your AWS account
Change or cancel AWS Support Plans
Register as a seller on the Reserved Instance Marketplace