Security, Tracking and Compliance Flashcards

1
Q

Cognito

A

User authentication/sign-in/access control through social identity providers (SAML).

Save data locally on devices for offline use.

Synchronization across multiple devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which service uses SAML

A

Cognito and Amazon SSO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Root cause analysis of security issues or suspicious activity

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Difference between Detective and Inspector?

A

Detective : Used for root cause analysis of security issues.

Inspector : Used for finding unintended network access or vulnerabilities and recommends action accord to best practice.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Finds unintended network access or vulnerabilities in EC2 instances and recommends action accord to best practice.

A

Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Threat detection service that alerts when it detects suspicious activity and indicators of account compromise.

A

GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

DDoS protection

A

Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Difference between Amazon Cloud Directory and Amazon Directory Service?

A

Cloud Directory is fully managed, auto-scaling cloud-native directory service.

Directory Service just allows Amazon services to be managed by your existing Microsoft AD setup (not cloud-native). Can be managed or unmanaged.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Used for building firewall rules and WAF deployments

A

Firewall Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS Identity and Access Management (IAM) enables what?

A

Fedarated identity

Roles, users, groups.

MFA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Where would you enable MFA for a user?

A

IAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between a role and a group?

A

Roles are permissions for actions performed by services.

Groups are permissions for actions performed by users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Grants users permissions

A

groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Grants services permissions

A

role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which service allows federation, social identity providers, and SSO respectively?

A

federation - IAM

social identity provider - Cognito

SSO - AWS SSO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

WAF vs Network Firewall?

A

WAF - protection from common web threats

Network firewall - protection from common network threats

17
Q

Part of Organization that handles licenses, consolidated billing, and sharing access to resources across Organization

A

RAM (resource access manager)

18
Q

Eliminates the need to hard code sensitive information in plain text for databases

A

Secrets Manager

19
Q

Secrets Manager

A

rotates, manages, and retrieves database credentials or API keys

20
Q

Aggregates and prioritizes security findings from other AWS services in one place

A

Security Hub

21
Q

Single web based portal for login

A

Amazon SSO