udemy 3 Flashcards
SCP
service control policies, manage across accounts. apply to groups or OUs
allowlist or blocklist
need explicit allows
IAM conditions
aws sourceip: restrict client calls from source
resource based polies
sms sqs lamda cloudwath logs api calls
IAM role
kinesis, systems manager, run command, ecs task
IAM Permission boundaries
for uses and roles, not goups. sets maximum permissions for a user
AWS Identity Center
Single sign on. SAML 2.0 integration. multiple aws account logins.
AD flavors
Ms AD
AD Conector (direct connect)
AD Simple no on prem
Control tower
govern multi-accounts using organizations
preventive guardrails using scps
detecitive : compliance using config
KMS
Encryption Keys managed by AWS
can be audited by cloudtrail
requires policies: default or custom
KMS Key Types
Symmetric: One key AES-256 always encrypt
Assymetric: public encrypt, private decrypt
S3 encryption
SSE-s3 encrypted objects are replicated by default
SSE-C: can be replicated, but not by default.
SSE:KMS has to be specified at bucket level target. enable replication (multi region decrypted and encrypted)
Sharing an AMI between accounts
Change the launch permission
Share the KMS key
Role or permisson to use key KMS side to encrypt or dencrypt.
SSM Parameter Store
Secure for configurations and secretes
serverless
version tracking
IAM
EventBridge
(Secrets mngr difference: you can rotate and force a rotate)
RDS Auroa
Multi-region secrets
Sheild, shiel Advanced vs. WAF
Shield: layer 3 and 4
WAF : layer 7 (no NLB)
advanced: 24/7 shield advanced team: auto applies WAF rules at layer 7
Inspector
EC2 instances, Lambda, and ECR: sends findings into security hub and eventbridge
looks for vulnerabiliites