Security - Well-Architected Framework Flashcards

To build a secured cloud platform.

1
Q

4 areas of “security in the cloud” and related Key AWS Services

A

Data protection : ELB,EBS,S3, RDS;
Privilege management : IAM, MFA;
Infrastructure protect : VPC;
Detective control : CloudTrail; CloudWatch; Config;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Best Practise - Data protection

A
  • customer keep full control of their data;
  • data encryption and key management (regular key rotation)
  • Detailed logging: files access and change
  • data storage: durability and resiliency eg. S3
  • Versioning: data lifecycle management process
  • Data retained in the region until the customer transfer it to another region.

Questions (How):
encryption data at rest and in transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Privilege Management

A

*Access Contol Lists;
*Role-based access controls;
*Password management (Password rotation policies);
Questions (How):
*AWS root account credentials management
*roles and responsibility definition to control access of AWS Management Console and APIs.
*Limitation of automated access to AWS resources;
*Key and credential management;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Infrastructure Protection

A
  • protection of the data centers: RFID controls, security guard, lockable cabinets, CCTV etc
    Questions (How):
    *network and host-level boundary protection;
    *AWS service level protection;
    *Integrity of the EC2 instances etc.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Detective Controls

A

*AWS Service related to this pillar:
CloudTrail; CloudWatch; Config; S3; Glacier
Questions (HOW) :
capturing and analyzing AWS logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Furthermore

A

whitepaper

How well did you know this?
1
Not at all
2
3
4
5
Perfectly