1/23
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
AWS Audit Manager
Your Company's Evidence; continuous compliance auditing; automatically collects evidence to assess risk against frameworks (SOC 2 / HIPAA)
AWS Secrets Manager
Credential & API key management; securely stores; rotates; and retrieves database passwords and API keys automatically
VPC Interface Endpoint (PrivateLink)
Private ENI connection for Bedrock / SageMaker / & Rekognition APIs; keeps traffic off the public internet
Amazon EMR
Big Data Processing; distributed frameworks (PySpark / Hadoop); petabyte-scale data prep
AWS IAM (Identity & Access Management)
Authentication & authorization; fine-grained access control using Roles; Policies; and Least Privilege
VPC Interface Endpoint (PrivateLink)
Private ENI connection for Bedrock, SageMaker, & Rekognition APIs; keeps traffic off the public internet
Amazon EMR
Big Data Processing; distributed frameworks (PySpark, Hadoop); petabyte-scale data prep
AWS Data Exchange
Third-Party Datasets; independent software vendor (ISV) data feeds for ML training
AWS IAM (Identity & Access Management)
Authentication & authorization; fine-grained access control using Roles, Policies, and Least Privilege
AWS RAM (Resource Access Manager)
Cross-account resource sharing; securely share subnets or Transit Gateways across AWS Organizations
AWS Security Hub
Centralized security dashboard; aggregates alerts from multiple services; checks against CIS benchmarks
AWS Network Firewall
Managed network perimeter security; stateful inspection and web filtering for VPC traffic
Amazon Macie
Data privacy & PII discovery; uses ML and pattern matching to discover and protect sensitive data in Amazon S3
AWS CloudTrail
Governance & Compliance Audit Trail; logs and tracks all API actions/calls made across your AWS account
Prompt Injection
Malicious Inputs; user inputs designed to alter model behavior in unintended ways or bypass safety guardrails
Insecure Output Handling
Unsanitized Output; failure to clean or validate model outputs before passing them to downstream systems / users
Training Data Poisoning
Manipulated Training Sets; inserting harmful or biased data into training datasets to corrupt model behavior
Model Denial of Service (DoS)
Resource Exhaustion; exploiting vulnerabilities or high-cost prompts to render the model unavailable or unusable
Supply Chain Vulnerabilities
Third-Party Risks; security weaknesses in pre-trained models; datasets; or third-party components used in deployment
Sensitive Information Disclosure
Data Leakage; unauthorized exposure of confidential data or PII through model outputs or unintended channels
Insecure Plugin Design
Flawed Integrations; security flaws in optional extensions / plugins that can be exploited by malicious inputs
Excessive Agency
Unconstrained Autonomy; granting too much operational freedom or permissions to a model without human validation
Overreliance
Blind Trust; trusting model outputs excessively without adequate human review; validation; or verification
Model Theft
Unauthorized Exfiltration; unauthorized access; copying; or duplication of proprietary model parameters and weights