Security - Encryption Flashcards
What is AWS KMS?
HA, Managed key encryption service for key storage, management, auditing to encrypt data.
What are some feature of KMS?
regional based, keys can only be used in the region you create them
symmetric keys - single key for encrypting and decrypting
asymmetric - public & private key
How is KMS configured?
Name & describe Define administrative permissions Define usage permissions Encrypt things (S3) using KMS key Objects will show what key was used to encrypt
Which AWS services are integrated with KMS?
EBS S3 Redshift Elastic Transcode WorkMail RDS
What is AWS Cloudtrail?
AWS CloudTrail is a web service that records AWS API calls for your account and delivers log files to you
sent to S3 bucket and you manage the retention
delivered every 5 minutes with 15 min delay
can be aggregated across regions and accounts
What is AWS CloudWatch?
performance monitoring, resource utilization, operational performance, log aggregation, hooks to event triggers
real-time, metrics, alarms, notifications, custom metrics