Security, Identity & Compliance Flashcards
Allows you to manage users and their levels of access to the AWS resources.
IAM (Identity and Access Management)
Used for device authentication / OAuth service. This service provides end users temporary access to AWS resources.
Cognition
Used to monitor for malicious activity on your AWS account.
Guard Duty
An agent installed on your virtual machine, and you can run tests for security vulnerabilities etc.
Inspector
Check your entire suite of applications for personally identifiable information. It is a security service that uses machine learning to automatically discover, classify, and protect sensitive data in AWS.
Macie
Give certificates to any domain you have registered via AWS/Routes 53. This also helps in maintaining and updating certificates that are about to expire.
Certificate Manager
Dedicated hardware to store your hardware private and public keys, that are used to securely access your application/EC2 instances. You can also store a variety of exception keys.
Cloud HSMHardware Security Module
Integrates your Microsoft active directory services with AWS services.
Directory Services
Sits in front of your web server and it mitigates against injection, cross-scripting. WAF primarily protects your application layer from any malicious attacks.
WAF – Web Application Firewall
A DDoS mitigation service that prevents DDoS Attacks. Come by default with your load balancers, cloud front, and Route 53.
Shield
AWS will not charge you for any auto-scaling or added utilization of the AWS services during the DDOS attack.
Advance Shield
It is used for compliance and audit. Gives access to AWS SOC 1, 2, 3, PCI reports, etc. And provides on-demand access to AWS’ security posture.
Artifact