Security Hub Flashcards

1
Q

Security hub

What is Security Hub?

A

Single location for management and remediation of security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security hub

How do you turn it on?

A

Enable per-region (so enable it in all regions)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security hub

I turned on Security Hub. Why isn’t it flagging all my bad stuff?

A

It isn’t retroactive – works from enabled-point forward.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security hub

How does Security Hub decide what is an issue?

A

Compares your AWS account set up with industry standards like PCI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security hub

How do you get issues out of Security Hub?

A

Interactive on AWS console or via EventBridge events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security hub

Where does Security Hub get its raw data to look at?

A

Lots of AWS services and 3rd party services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security hub

Examples of some AWS services?

A

Macie, Inspector, IAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security hub

What’s the structure of findings that Security Hub produces?

A

ASFF: AWS Security Findings Format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security hub

Why is this structure so important?

A

Single structure across findings from all the other AWS and 3rd party products

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Multi-Account

How does Security Hub work with multiple AWS accounts?

A

Account invites other accounts to join. Admin and Member accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Multi-Account

How do Security Hub accounts overlap with AWS Organizations accounts?

A

They don’t. Totally separate structure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Multi-Account

How does Security Hub work across regions?

A

It’s regional, but can aggregate across regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly