Security & Compliance Flashcards
AWS Shield Standard
Default DDOS protection
AWS Shield Advanced
24/7 premium DDOS protection
AWS WAF
Rules based filtering
Layer 7 protection (HTTP)
Deploy on ALB, API, CloudFront
CloudFront and Route53
Protection at the edge
AWS Shield
Protects against common attacks (syn floods, reflection attacks, etc.)
AWS Shield Advanced
Protects against more sophisticated attacks on major AWS services
24/7 Response Team
$3,000/month/organization
Web ACL
WAF feature
Rules for IP, HTTP headers, HTTP body, URI
SQL Injection, XSS
geo-block
Best way to protect entire VPC?
AWS Network Firewall
Pentesting on AWS Cloud
Don’t need auth for 8 core services
Pentesting restrictions
No DOS
No network flooding
No Request flooding
No DNS zone walking
AWS KMS
AWS manages encryption keys
Services needing encryption opt-in (5)
EBS volumes
S3
Redshift
RDS
EFS
Services with default encryption (3)
Cloudtrail logs
S3 Glacier
Storage gateway
CloudHSM
AWS provisioned encryption HW
CloudHSM
Manage your own keys