Week 2-Security Flashcards

1
Q

What are the 4 key strategic benefits of AWS security services and solutions?

A
  1. Prevent:
  2. Detect
  3. Respond
  4. Remediate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS supports more ________________ and _______________ than any other offering,
including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171, helping customers
satisfy compliance requirements for ____________________________________.

A
  1. security standards
  2. compliance certifications
  3. virtually every regulatory agency around the globe
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 benefits of compliance on AWS?

A
  1. Third-Party validation for 1000s of global requirements:
  2. Inherit the latest security controls AWS uses on its own infrastructure
  3. Streamline and automate compliance:
  4. Automated Compliance Reporting:
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

_______ and ____________ is a shared responsibility between AWS and the customer.

A
  1. Security

2. Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security and Compliance is a shared responsibility between AWS and the customer. What is AWS responsible for here vs the customer?

A

AWS: AWS operates, manages
and controls the components from the host operating system and virtualization layer down to the
physical security of the facilities in which the service operates.
2. The customer assumes responsibility and management of the guest operating system (including
updates and security patches), other associated application software as well as the configuration of
the AWS provided security group firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the difference between security in the cloud vs security on-premises?

A

• In the cloud, you don’t have to manage physical servers or storage devices.
• Instead, you use software-based security tools to monitor and protect the flow of information into and out
of your cloud resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

While AWS manages security of the cloud, you are responsible for security in the cloud. Explain what this means.

A

This means that you retain control of the security you choose to implement to protect your own content,
platform, applications, systems, and networks no differently than you would in an on-site data center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AWS security controls provides AWS customers with _____ and ______

A

Flexibility and agility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are 4 benefits of AWS Security?

A
  1. Keep Your Data Safe
    – The AWS infrastructure puts strong safeguards in place to help protect your privacy.
    – All data is stored in highly secure AWS data centers.
  2. Meet Compliance Requirements
    – AWS manages dozens of compliance programs in its infrastructure.
    – This means that segments of your compliance have already been completed.
  3. Save Money
    – Cut costs by using AWS data centers. Maintain the highest standard of security without having to manage your own facility
  4. Scale Quickly
    – Security scales with your AWS Cloud usage.
    – No matter the size of your business, the AWS infrastructure is designed to keep your data safe.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are 4 benefits of AWS Security?

A
  1. Keep Your Data Safe
    – The AWS infrastructure puts strong safeguards in place to help protect your privacy.
    – All data is stored in highly secure AWS data centers.
  2. Meet Compliance Requirements
    – AWS manages dozens of compliance programs in its infrastructure.
    – This means that segments of your compliance have already been completed.
  3. Save Money
    – Cut costs by using AWS data centers. Maintain the highest standard of security without having to manage your own facility
  4. Scale Quickly
    – Security scales with your AWS Cloud usage.
    – No matter the size of your business, the AWS infrastructure is designed to keep your data safe.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does AWS Cloud compliance enable?

A

Enables you to understand the robust controls in place at AWS to maintain security and data protection
in the cloud. As systems are built on top of AWS Cloud infrastructure, compliance responsibilities will be shared.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

List some programs with which AWS complies with:

A

-AWS provides customers a wide range of information on its IT control environment in whitepapers, reports, certifications, accreditations, and other third-party attestations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

With AWS, the customer manages what things about your data? (hint: 4 things)

A
  • The privacy controls of your data
  • Control how your data is used
  • Who has access to it,
  • How it is encrypted.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Describe the following:

  1. Data control
  2. Data Privacy
  3. Data sovereignty
A

Data control: AWS tools determine where your data is stored, how it is secured, and who has access to it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do you implement privacy protection?

A

Based on your specific industry requirements and satisfy regulators and auditors using our services, tooling, and resources to control and protect your data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Maintaining customer trust involves AWS making ongoing commitments to its customers. These commitments include: (hint: 3)

A
  • You own and control your data on AWS
  • You control your data. You determine who can access your data.
  • Using AWS Regions, you control where your data is stored, based on your specific needs.
17
Q

What sort of privacy safeguard capabilities does AWS provide? (hint 2)

A
  1. The option to manage your own encryption keys with AWS Key Management Service
  2. The ability to continuously monitor, log, and retain account activity with AWS Config and AWS CloudTrail.
18
Q

What is an AWS MSSP Partner?

A

• AWS MSSP Partners can provide full outsourcing or integrate and join forces with your internal security teams to help you fully operationalize your AWS security.
-Increases cloud security by allowing experts to watch it 24/7

19
Q

For this reason, cloud security is a ______________ between the customer and AWS, where
customers are responsible for “security in the cloud” and AWS is responsible for “security of the
cloud.”

A

Shared responibility

20
Q

What is Whitepapers, Technical Guides, and Reference Materials?

A

Technical content that is crafted by AWS security specialists that helps expand your knowledge of cloud security
-These references cover the best practices for leading trends in the industry, including incident response, compliance in the cloud, and privacy considerations

21
Q

Amazon still publishes _____ _______ to notify its customers of ________ and _______ events.

A
  1. Security bulletins

2. security and privacy events

22
Q

What does AWS security hub do? (3 things)

A
• Detect deviations from security best 
practices with a single click.
• Automatically aggregate security 
findings in a standardized data 
format from AWS and partner 
services.
• Accelerate mean time to resolution 
with automated response and 
remediation actions.
23
Q

What is Amazon GuardDuty? (specifics of how it works)

A

A threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3
-Cost-effective option for continuous threat detection in AWS
-Service uses machine learning, anomaly detection, and integrated threat intelligence to identify
and prioritize potential threats.
-GuardDuty analyzes tens of billions of events across multiple AWS data sources, such as AWS
CloudTrail event logs, Amazon VPC Flow Logs, and DNS logs.
-GuardDuty alerts are easy to aggregate across multiple platforms
-Amazon GuardDuty threat detection identifies activity that can be associated with account
compromise, instance compromise, malicious reconnaissance, and bucket compromise.
-For example, GuardDuty detects unusual API calls, suspicious outbound communications to known
malicious IP addresses, or possible data theft using DNS queries as the transport mechanism.
• GuardDuty delivers more accurate findings using machine learning enriched by threat intelligence,
such as lists of malicious IPs and domains.

24
Q

What are the 3 core benefits of Amazon Guard-Duty?

A
  1. Comprehensive threat identification
  2. Strengthens security through automation: automated responses to threats
  3. Enterprise scale and central management: Multi-account support
25
Q

What sort of events across your AWS account does GuardDuty analyze? (4 examples)

A

AWS CloudTrail Management
Events (AWS user and API activity in your accounts), AWS CloudTrail S3 Data Events (Amazon S3
activity), Amazon VPC Flow Logs (network traffic data), and DNS Logs (name query patterns).

26
Q

How is Amazon GuardDuty priced?

A

Amazon GuardDuty is priced based on the quantity of AWS CloudTrail Events analyzed and the volume of Amazon VPC Flow Log and DNS Log data analyzed.

27
Q

What is Amazon Inspector?

A

• Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS.
• Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best
practices.
• After performing an assessment, Amazon Inspector produces a detailed list of security findings prioritized by level of severity.
• These findings can be reviewed directly or as part of detailed assessment reports which are available via the Amazon Inspector console or API
• Pricing is based on two dimensions, the number of EC2 instances included in each assessment, and the type(s) of rules package you select.
-You only pay for what you use

28
Q

What is AWS Config?

A

• AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your
AWS resources.
• Config continuously monitors and records your AWS resource configurations and allows you to
automate the evaluation of recorded configurations against desired configurations.
• With Config, you can review changes in configurations and relationships between AWS resources,
dive into detailed resource configuration histories, and determine your overall compliance against
the configurations specified in your internal guidelines.
• This enables you to simplify compliance auditing, security analysis, change management, and
operational troubleshooting
-Charged based on the number of configuration items recorded, the
number of active AWS Config rule evaluations and the number of conformance pack evaluations in
your account.

29
Q

What is AWS Cloudtrail?

A

-Service that enables governance, compliance, operational auditing, and risk
auditing of your AWS account.
- You can log, continuously monitor, and retain account activity related to actions
across your AWS infrastructure.
- Provides event history of your AWS account activity
-Allows you to detect unusual activity

30
Q

What is Amazon Macie?

A

-Fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect your sensitive data in AWS
• Amazon Macie automates the discovery of sensitive data at scale and lowers the cost of protecting your data.
• Macie automatically provides an inventory of Amazon S3 buckets including a list of unencrypted buckets,
publicly accessible buckets, and buckets shared with AWS accounts outside those you have defined in AWS
Organizations
-Macie’s alerts, or findings, can be searched and filtered in the AWS Management Console and sent to Amazon
EventBridge, formerly called Amazon CloudWatch Events, for easy integration with existing workflow or event
management systems, or to be used in combination with AWS services