udemy 3 Flashcards

1
Q

SCP

A

service control policies, manage across accounts. apply to groups or OUs

allowlist or blocklist
need explicit allows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IAM conditions

A

aws sourceip: restrict client calls from source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

resource based polies

A

sms sqs lamda cloudwath logs api calls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IAM role

A

kinesis, systems manager, run command, ecs task

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IAM Permission boundaries

A

for uses and roles, not goups. sets maximum permissions for a user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AWS Identity Center

A

Single sign on. SAML 2.0 integration. multiple aws account logins.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AD flavors

A

Ms AD
AD Conector (direct connect)
AD Simple no on prem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control tower

A

govern multi-accounts using organizations

preventive guardrails using scps
detecitive : compliance using config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

KMS

A

Encryption Keys managed by AWS
can be audited by cloudtrail
requires policies: default or custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

KMS Key Types

A

Symmetric: One key AES-256 always encrypt
Assymetric: public encrypt, private decrypt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

S3 encryption

A

SSE-s3 encrypted objects are replicated by default
SSE-C: can be replicated, but not by default.
SSE:KMS has to be specified at bucket level target. enable replication (multi region decrypted and encrypted)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sharing an AMI between accounts

A

Change the launch permission
Share the KMS key
Role or permisson to use key KMS side to encrypt or dencrypt.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SSM Parameter Store

A

Secure for configurations and secretes
serverless
version tracking
IAM
EventBridge
(Secrets mngr difference: you can rotate and force a rotate)
RDS Auroa
Multi-region secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Sheild, shiel Advanced vs. WAF

A

Shield: layer 3 and 4
WAF : layer 7 (no NLB)
advanced: 24/7 shield advanced team: auto applies WAF rules at layer 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Inspector

A

EC2 instances, Lambda, and ECR: sends findings into security hub and eventbridge

looks for vulnerabiliites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CIDR
192.168.0.0-192168.0.255
(256 IPs b/c 0-255)

192.168.0.0/16
192.168/255/255

A

/32 no octet can change
/24 last octet can change
/16 last two octets can change
/8 last 3 octets can change
/0 all octets can change

17
Q

Private IPs

A

10.0.0.0-10.255.255.255 (private)
172.16.0.0/12 AEP private IPs
192.168.0.0/16 (private IP home)

18
Q

bastion host

A

security group set up allow public inbound from internet on port 22 restriceted to CIDR

private: allows the bastion host or private IP

A bastion host is a publicly accessible host that allows traffic to connect to it. Then, an additional connection is made from the bastion host into a private subnet and the hosts within that subnet.

19
Q

RTO
RPO

A

Recovery time objective (when you recover) how much downtime?
Revover point objective (how often run backups)

20
Q

Backup and Restore

A

High RPO
recreate and restore
cost of storing backups

21
Q

Pilot Light

A

small app version is always running in the cloud. all other systems get added on in time of recovery

22
Q

warm standby

A

full sytem up and running but minimal size.

23
Q

Multi site

A

expensive and active active setup

24
Q

ENA

A

Elastic Network Adaptor (speeds eC2 for high computing)
EFA: same but only for Linux must be used with AWS Parallell cluster

25
Q

SES

A

Simple Emailing Service

26
Q

Pinpoint

A

inbound/outbound marketing communication service

27
Q

SSM session manager service

A

session into ec2 without opening port 22

28
Q

appflow

A

SaaS to AWS (salesforce for example) int redshift or s3 etc.

29
Q

amplify

A

web and mobile app tool

30
Q

7 pillars

A

operational excellence
security
reliability
Performance efficiency
cost optimization
sustainability