1/159
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the shared responsibility model in AWS?
It explains how security responsibilities are divided between AWS (responsible for security of the cloud) and the customer (responsible for security in the cloud).
What is AWS responsible for in the shared responsibility model?
AWS is responsible for protecting the infrastructure that runs AWS Cloud services, including hardware, software, networking, and facilities.
What are customers responsible for in the shared responsibility model?
Customers are responsible for securing the resources and configurations they control within AWS, including managing the guest operating system and protecting their data.
How does responsibility change with different AWS service models?
As AWS manages more of the underlying environment, customers have fewer infrastructure components to manage directly.
What is Infrastructure as a Service (IaaS) in AWS?
IaaS gives customers greater control over the cloud environment, requiring them to perform more security configuration and management tasks.
What is Platform as a Service (PaaS) in AWS?
PaaS shifts more responsibility for the underlying infrastructure to AWS, allowing customers to focus more on their applications and data.
What is Software as a Service (SaaS) in AWS?
SaaS provides centrally hosted software that customers use without managing the infrastructure that supports the service.
What is AWS Identity and Access Management (IAM)?
IAM is a service that securely controls access to AWS resources, determining who is authenticated and what they are authorized to do.
What are IAM users?
IAM users represent people or applications that require access to AWS resources.
What are IAM groups?
IAM groups are collections of IAM users that can share the same permissions.
What are IAM roles?
IAM roles provide temporary permissions that can be assumed by users, applications, or AWS services.
What are IAM policies?
IAM policies define permissions by specifying which actions are allowed or denied on AWS resources.
What is the principle of least privilege in IAM?
It means granting only the permissions necessary to perform required tasks.
What does authentication in AWS verify?
Authentication verifies the identity of a user or system attempting to access AWS.
What is multi-factor authentication (MFA) in AWS?
MFA requires another authentication factor in addition to the user's regular sign-in credentials for added security.
What is the default behavior of AWS access evaluation?
An explicit allow is required for an action to be permitted; an explicit deny overrides an allow.
How do IAM groups simplify permission management?
Permissions can be assigned to a group instead of each user, allowing for easier management and updates.
What is the role of AWS services in managing security?
AWS provides services and programs that help organizations manage security and support compliance requirements.
What does AWS manage in terms of physical security?
AWS manages the physical security of its data centers, network infrastructure, and virtualization infrastructure.
What is the significance of understanding AWS's responsibilities?
It helps customers identify the security tasks they need to perform based on the services they are using.
What is the role of IAM policies in authorization?
IAM policies define what AWS resources and actions an authenticated identity is permitted to access.
What happens if an action is not explicitly allowed in AWS?
Access is denied by default.
What is the impact of using Amazon EC2 on customer responsibilities?
Customers must manage the guest operating system, install updates, and configure security settings.
What is the focus of AWS Elastic Beanstalk as a PaaS?
It allows customers to focus on their applications and data while AWS manages the underlying infrastructure.
What is AWS Trusted Advisor?
AWS Trusted Advisor is an example of SaaS that provides insights and recommendations for AWS accounts.
What is the purpose of AWS Shield?
AWS Shield is a managed DDoS protection service for AWS applications.
What is the significance of managing access to AWS resources?
It ensures that only authorized users can access sensitive data and perform actions on AWS services.
What happens when permissions associated with a group are changed?
The change applies to users who receive their permissions through that group.
Why are IAM roles useful?
They allow AWS services, applications, or users to have temporary access to AWS resources without storing permanent credentials.
What is the first step in securing a new AWS account?
Protecting the AWS account root user, which has complete access to the account.
What precautions should be taken for the AWS account root user?
Use a strong password, enable multi-factor authentication (MFA), keep credentials private, avoid creating access keys unless necessary, and use the root user only for essential tasks.
Why is maintaining accurate account contact information important?
It ensures that important AWS communications regarding account, billing, operations, and security reach the appropriate people.
What is AWS CloudTrail?
AWS CloudTrail records actions performed through AWS services, providing information about the identity that performed an action, when it occurred, and which resources were involved.
What is the purpose of reviewing account activity in AWS?
To support auditing, troubleshooting, and investigation of unexpected actions.
What is AWS Organizations?
AWS Organizations enables centralized management of multiple AWS accounts, allowing accounts to be arranged into organizational units (OUs).
What are Service Control Policies (SCPs)?
SCPs provide centralized controls over the maximum permissions available to accounts within AWS Organizations.
Do Service Control Policies grant permissions?
No, SCPs establish boundaries within which permissions can be granted.
What is AWS Key Management Service (AWS KMS)?
AWS KMS helps organizations create and manage cryptographic keys used to protect data.
How does AWS KMS integrate with other AWS services?
It allows keys to be used when encrypting AWS resources and application data.
What is Amazon Cognito?
Amazon Cognito provides identity capabilities for web and mobile applications, including user sign-up, sign-in, and access control.
What is the focus of Amazon Cognito compared to IAM?
Amazon Cognito is focused on managing identities for users of applications, while IAM manages permissions for AWS resources.
What does AWS Shield do?
AWS Shield is a managed service that protects applications running on AWS against distributed denial-of-service (DDoS) attacks.
What is the goal of a DDoS attack?
To disrupt the availability of an application or service by overwhelming it with malicious traffic.
What should organizations do to secure their AWS accounts?
Implement security measures such as protecting the root user, maintaining accurate contact information, and establishing visibility into account activity.
What is the significance of establishing visibility into account activity?
It helps in auditing and identifying unexpected actions or resource usage.
What is the benefit of using organizational units (OUs) in AWS Organizations?
It allows related accounts to be managed together, applying organizational controls consistently.
How can organizations restrict access to AWS services across accounts?
By using Service Control Policies (SCPs) to establish consistent restrictions.
What is the role of hardware security modules (HSMs) in AWS KMS?
HSMs help protect cryptographic key material.
What should organizations do to manage encryption keys effectively?
Control who is permitted to administer or use particular keys and monitor their usage.
What is the relationship between AWS KMS and AWS CloudTrail?
AWS KMS integrates with AWS CloudTrail to record activities involving keys.
What is the primary purpose of AWS security services?
To address different security requirements beyond the initial protection of an individual AWS account.
What is the importance of keeping root user credentials secure?
It reduces unnecessary exposure of credentials that provide unrestricted access to the AWS account.
What should organizations do when personnel change regarding account contact information?
Maintain contact information that remains accessible to ensure timely attention to security-related notifications.
What is the purpose of DDoS attacks?
To disrupt the availability of an application or service by overwhelming it with malicious traffic.
What does AWS Shield Standard protect against?
Common network and transport layer DDoS attacks at no additional charge.
What additional capabilities does AWS Shield Advanced provide?
Enhanced DDoS protection for organizations with greater protection requirements.
What are the two states of data protection in AWS?
Data at rest and data in transit.
What does 'data at rest' refer to?
Data that is stored rather than actively moving between systems.
What is the role of encryption for data at rest?
To transform stored data into a form that cannot be easily understood without the appropriate encryption key.
Which AWS services support encryption of stored data?
Amazon S3, Amazon EBS, Amazon EFS, and Amazon RDS.
What does 'data in transit' refer to?
Data that is moving between systems, applications, or network locations.
What secure communication protocols does AWS support for data in transit?
Transport Layer Security (TLS) and Secure Sockets Layer (SSL).
What is the purpose of AWS Certificate Manager (ACM)?
To provision and manage SSL/TLS certificates for supported AWS services.
How does Amazon S3 store data?
As objects inside buckets.
What is S3 Block Public Access?
A feature used to restrict public access to buckets and objects in Amazon S3.
What are IAM policies in the context of Amazon S3?
Policies that specify actions that an identity is permitted to perform.
What are bucket policies in Amazon S3?
Policies that define permissions directly on an S3 bucket.
What are Access Control Lists (ACLs) used for in Amazon S3?
To specify which accounts or groups are granted access to a bucket or object.
How does encryption protect Amazon S3 objects?
It encrypts the contents of objects, requiring decryption for access.
What does AWS Config do?
Helps assess, audit, and evaluate the configurations of AWS resources.
What is AWS Artifact?
A service that provides on-demand access to AWS security and compliance documents.
What types of compliance requirements can AWS help organizations meet?
Certifications, attestations, laws, regulations, and privacy.
What is the importance of encryption and access control in data protection?
Encryption protects the contents of data, while access controls determine who can access it.
What is the purpose of AWS compliance programs?
To help organizations address different regulatory and industry requirements.
What does AWS Config provide visibility into?
Resource configurations and records of how those configurations change over time.
How can organizations use AWS Artifact?
To obtain AWS compliance reports and manage AWS agreements relevant to their use of AWS.
What is the benefit of using both encryption and access controls?
It allows for restricted access while also protecting the information stored within an object.
What is the default setting for public access to new S3 buckets?
New S3 buckets do not allow public access by default.
What is the role of encryption in protecting stored information?
It helps protect information if unauthorized access to the underlying data occurs.
What is the primary purpose of networking in the AWS Cloud?
To enable devices, applications, and services to communicate and exchange data.
What foundational AWS service is used to build and deliver cloud-based networks?
Amazon Virtual Private Cloud (Amazon VPC)
What is an Internet Protocol (IP) address?
A numerical address used to identify a device on a network.
What is the structure of an IPv4 address?
Four decimal numbers separated by periods, representing a 32-bit address.
What are the private IPv4 address ranges?
10.0.0.0 - 10.255.255.255, 172.16.0.0 - 172.31.255.255, 192.168.0.0 - 192.168.255.255.
What is the main advantage of IPv6 over IPv4?
IPv6 provides a much larger address space using 128-bit addresses.
What does Classless Inter-Domain Routing (CIDR) represent?
A method to specify the range of IP addresses available within a network using an IP address and a prefix length.
What is the significance of the prefix length in CIDR notation?
It indicates how many bits identify the network portion of the address.
What is the OSI model?
A model that organizes network communication into seven layers, each representing a set of networking functions.
Name the seven layers of the OSI model.
Physical, Data Link, Network, Transport, Session, Presentation, Application.
What is Amazon VPC?
An AWS service that enables customers to provision a logically isolated virtual network in the AWS Cloud.
How does a VPC relate to AWS Regions and Availability Zones?
A VPC belongs to a single AWS Region but can span multiple Availability Zones within that Region.
What is a subnet in the context of a VPC?
A range of IP addresses within a VPC that resides entirely within one Availability Zone.
What distinguishes a public subnet from a private subnet?
A public subnet has a route to an internet gateway, while a private subnet does not.
What are the reserved IP addresses in each IPv4 subnet CIDR block?
The first four IP addresses and the last IP address are reserved and not available for assignment.
What is the purpose of Elastic IP addresses in AWS?
They are static public IPv4 addresses that can be associated with supported AWS resources.
What is the role of routing in a VPC?
Routing determines how traffic is directed between resources within the VPC and to external networks.
What is the importance of understanding basic networking concepts in AWS?
It is crucial for configuring network resources effectively.
What does the transport layer of the OSI model manage?
End-to-end communication and data delivery.
How are public IP addresses used in AWS?
They enable communication through the internet when necessary routing and security settings are configured.
What is the maximum number of usable IP addresses in a /24 subnet?
251 usable IP addresses after excluding the five reserved addresses.