Slides Flashcards
How do you look into IAM permissions
IAM credential report (account level)
IAM access advisor (user level)
How do you distribute secured S3 content globally
CloudFront signed URLs
Access multiple files from CloudFront
CloudFront signed cookies
DynamoDB Streams
Allows to create a change log
AWS X-ray
analyze an application and its underlying services
to identify and troubleshoot performance issues
you can use X-ray across accounts
CloudWatch Events
near real-time stream of system events in AWS resources
cannot be used across accounts
IAM role
an IAM User in the same account
an IAM User in a different account
an AWS webservice
an external user authenticated by SAML
Which services can buffer requests
SQS
AWS Gateway API
Kinesis
but not Elastic Load Balancer, nor SNS, nor Lambda
Which services allow caching
ElastiCache DAX CloudFront Route53 Greengrass
AWS Resource Access Manager
share resources across accounts (VPC subnets, Licenses, Aurora,…)
NAT Instance
Support port forwarding
Can be attached to a security group
Can be used as a bastion server
EBS Snapshots
All encrypted by default
Data between Instance and EBS is encrypted
Data at rest in encrypted