udemy 3 Flashcards
SCP
service control policies, manage across accounts. apply to groups or OUs
allowlist or blocklist
need explicit allows
IAM conditions
aws sourceip: restrict client calls from source
resource based polies
sms sqs lamda cloudwath logs api calls
IAM role
kinesis, systems manager, run command, ecs task
IAM Permission boundaries
for uses and roles, not goups. sets maximum permissions for a user
AWS Identity Center
Single sign on. SAML 2.0 integration. multiple aws account logins.
AD flavors
Ms AD
AD Conector (direct connect)
AD Simple no on prem
Control tower
govern multi-accounts using organizations
preventive guardrails using scps
detecitive : compliance using config
KMS
Encryption Keys managed by AWS
can be audited by cloudtrail
requires policies: default or custom
KMS Key Types
Symmetric: One key AES-256 always encrypt
Assymetric: public encrypt, private decrypt
S3 encryption
SSE-s3 encrypted objects are replicated by default
SSE-C: can be replicated, but not by default.
SSE:KMS has to be specified at bucket level target. enable replication (multi region decrypted and encrypted)
Sharing an AMI between accounts
Change the launch permission
Share the KMS key
Role or permisson to use key KMS side to encrypt or dencrypt.
SSM Parameter Store
Secure for configurations and secretes
serverless
version tracking
IAM
EventBridge
(Secrets mngr difference: you can rotate and force a rotate)
RDS Auroa
Multi-region secrets
Sheild, shiel Advanced vs. WAF
Shield: layer 3 and 4
WAF : layer 7 (no NLB)
advanced: 24/7 shield advanced team: auto applies WAF rules at layer 7
Inspector
EC2 instances, Lambda, and ECR: sends findings into security hub and eventbridge
looks for vulnerabiliites
CIDR
192.168.0.0-192168.0.255
(256 IPs b/c 0-255)
192.168.0.0/16
192.168/255/255
/32 no octet can change
/24 last octet can change
/16 last two octets can change
/8 last 3 octets can change
/0 all octets can change
Private IPs
10.0.0.0-10.255.255.255 (private)
172.16.0.0/12 AEP private IPs
192.168.0.0/16 (private IP home)
bastion host
security group set up allow public inbound from internet on port 22 restriceted to CIDR
private: allows the bastion host or private IP
A bastion host is a publicly accessible host that allows traffic to connect to it. Then, an additional connection is made from the bastion host into a private subnet and the hosts within that subnet.
RTO
RPO
Recovery time objective (when you recover) how much downtime?
Revover point objective (how often run backups)
Backup and Restore
High RPO
recreate and restore
cost of storing backups
Pilot Light
small app version is always running in the cloud. all other systems get added on in time of recovery
warm standby
full sytem up and running but minimal size.
Multi site
expensive and active active setup
ENA
Elastic Network Adaptor (speeds eC2 for high computing)
EFA: same but only for Linux must be used with AWS Parallell cluster
SES
Simple Emailing Service
Pinpoint
inbound/outbound marketing communication service
SSM session manager service
session into ec2 without opening port 22
appflow
SaaS to AWS (salesforce for example) int redshift or s3 etc.
amplify
web and mobile app tool
7 pillars
operational excellence
security
reliability
Performance efficiency
cost optimization
sustainability