Service Definitions 3 Flashcards

1
Q
  • Stateless, subnet rules for inbound and outbound
  • Firewall which controls traffic from and to subnet
  • Can have ALLOW and Deny rules
  • Attached at subnet level
A

NACL (Network ACL)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  • Stateful, operate at the EC2 instance level or ENI
  • Firewall that controls traffic to and from an ENI/EC2
    instance
  • Can have ONLY allow rules
  • Rules include IP addys and other __________
A

Security Groups (SGs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Connect two VPC with non overlapping IP ranges, nontransitive

A

VPC Peering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
  • Provide private access to AWS Services within VPC
  • Endpoints allow you to connect to AWS services using a
    Private network instead of public network
  • Give enhanced security and lower latency
A

VPC Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Connect thousands of VPC and on-premises networks together

A

Transit Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

VPN over public internet between on-premises Datacenter and AWS.

  • On prem use Customer Gateway (CGW)
  • AWS use Virtual Private Gateway (VPW)
A

Site to Site VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

protects against DDOS attack for your website and applications,
for all customers at no additional costs

A

AWS Shield and shield Advanced for 24/7 premium protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Filter specific requests based on rules

  • Layer 7 Http level
  • Deploy on Application Load Balancer, API Gateway, Cloudfront
A

AWS Web Application Firewall (WAF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  • Anytime you hear “encryption” for an AWS service, it’s most likely _____
  • AWS manages the encryption keys for us
A

AWS KMS (Key Mgmt Service)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  • Let you easily provision, manage, deploy SSL/TLS Certificates
A

AWS Certificate Manager (ACM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
  • Intelligent Threat (ML) discovery to protect AWS Account

- find in VPC, DNS, CloudTrail logs

A

Amazon GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  • analyzes, investigates and quickly identifies THE ROOT CAUSE OF SECURITY ISSUES (using ML and graphs)
A

Amazon Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  • Find objects, people, text, scenes, in images or videos using ML
  • Facial analysis/searching
A

Amazon Rekognition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
  • Central security tool to manage security across several AWS accounts and automate security checks
A

AWS Security Hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
  • auditing and recording compliance of your AWS resources

- Track record configurations and compliance changes over time

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  • Convert speech to text, speech recognition

- subtitles

A

Amazon Transcribe

17
Q
  • Turn text to speech
A

Amazon Polly

18
Q
  • Natural and accurate language translation
A

AWS Translate

19
Q

_________: same tech as Alexa, conversational Bots, chatbots

________: virtual/cloud contact center, receive calls and create contact flows

A

Amazon Lex & Connect

20
Q
  • Natural Language Processing – NLP

- ML to gain insights and relationships in text

A

Amazon Comprehend

21
Q
  • Fully managed service for developers/ data scientists, build ML models
A

Sagemaker

22
Q
  • fully managed service, use ML to deliver accurate forecasts
A

Amazon Forecast

23
Q
  • fully managed document search service, using ML

- Extract info from document, search engine

A

Amazon Kendra

24
Q
  • ML service, to build apps with real time personalized recommendations
  • same tech used by Amazon.com
A

Amazon Personalize

25
Q
  • Global Service
  • Manage multiple AWS accounts in one place
  • Consolidated billing across accounts
  • Restrict account privileges using service control policies (SCP)
A

AWS Organizations

26
Q
  • Whitelist/blacklist IAM actions
  • Applied at OU or Account level
  • SCP applied to all users and roles of account, including root
  • SCP must have explicit Allow
A

Service Control Policies (SCP)

27
Q
  • easy way setup and govern a secure and compliant multi-account AWS environment
  • Runs on top of AWS Organizations
    AWS Compute Optimizer:
  • reduce costs and improve performance
  • uses ML to see resource configurations and utilization CloudWatch metrics
A

AWS Control Tower

28
Q

Analyze your AWS accounts and provide recommendations for 5 categories:

  • cost optimization
  • performance
  • security
  • fault tolerance
  • service limits
A

AWS Trusted Advisor