Security & Compliance Flashcards

1
Q

AWS Shield Standard

A

Default DDOS protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS Shield Advanced

A

24/7 premium DDOS protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS WAF

A

Rules based filtering
Layer 7 protection (HTTP)
Deploy on ALB, API, CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CloudFront and Route53

A

Protection at the edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Shield

A

Protects against common attacks (syn floods, reflection attacks, etc.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AWS Shield Advanced

A

Protects against more sophisticated attacks on major AWS services
24/7 Response Team
$3,000/month/organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Web ACL

A

WAF feature
Rules for IP, HTTP headers, HTTP body, URI
SQL Injection, XSS
geo-block

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Best way to protect entire VPC?

A

AWS Network Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Pentesting on AWS Cloud

A

Don’t need auth for 8 core services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Pentesting restrictions

A

No DOS
No network flooding
No Request flooding
No DNS zone walking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AWS KMS

A

AWS manages encryption keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Services needing encryption opt-in (5)

A

EBS volumes
S3
Redshift
RDS
EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Services with default encryption (3)

A

Cloudtrail logs
S3 Glacier
Storage gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CloudHSM

A

AWS provisioned encryption HW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CloudHSM

A

Manage your own keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Customer managed CMK

A

Customer managed keys, BYOK, rotation policy

17
Q

AWS managed CMK

A

AWS manages keys

18
Q

AWS owned CMK

A

Collection of CMK’s to use in multiple accounts

19
Q

AWS Certificate Manager (ACM)

A

Create TLS certs

20
Q

Certificate Manager cost

A

Free

21
Q

AWS Secrets Manager

A

Store secrets
Capable of rotation

22
Q

Secrets Manager integrated with which service?

A

RDS

23
Q

AWS Artifact

A

Compliance and agreements portal

24
Q

Guard Duty

A

Looks at logs and events to find threats and unusual traffic

25
Q

Which service is good for finding cryptocurrency attacks?

A

GuardDuty

26
Q

Amazon Inspector

A

Automated vulnerability inspections

27
Q

Which service performs vulnerability scanning on EC2, container images, and Lambda?

A

Amazon inspector

28
Q

AWS Config

A

Records configurations and changes
Ensures settings compliance
Stored in S3

29
Q

Amazon Macie

A

Fully managed service to discover and protect sensitive data (PII) in AWS

29
Q

AWS Security Hub

A

Centralized security dashboard
Aggregates alerts
Requires AWS Config
Costs $

29
Q

Amazon Detective

A

Root cause analysis for security issues or suspicious activity

30
Q

AWS Abuse

A

Report suspicious AWS services to AWS

31
Q

Root user is who?

A

Account owner

32
Q

Root user unique permissions

A

Change account settings
Close account
Change/Cancel support plan
Register as a reseller for reserved instances
More

33
Q

IAM Access Analyzer

A

Find services shared externally

34
Q

Zone of trust

A

AWS Account or org. Anything outside of the zone may be an finding.