Security Features Flashcards
Shared Responsibility Model
AWS is responsible for physical, network & hypervisor security. User is responsible for user data & application security. Security of the guest OS can belong to user (on EC2) or AWS (on other services).
IAM
A user is a person/service. A person is a member of a group. A person or group can be assigned a role, which describes the authentication credentials. A policy document exists which specifies which users, groups, or roles have which permissions.
Amazon Inspector
Assesses apps for common security vulnerabilities on an automatic basis; available in CLI, SDK, API & console.
AWS Shield
DDOS protection & mitigation. Free & paid tiers of service.
AWS Trusted Advisor
Checks 4 areas: Cost optimization, performance, security & fault-tolerance + provides recommendations to fix.
Support / Customer Service
Each project has a technical accounts manager & a “support concierge” for dedicated assistance for that one group. There are 4 levels of support - Basic, Developer, Business + Enterprise