AWS Cloud Security & Infrastructure: Shared Responsibility, VPCs, IAM, and Services

0.0(0)
studied byStudied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/48

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:14 AM on 2/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

49 Terms

1
New cards

AWS' Responsibility

Security of the cloud.

2
New cards

AWS Shared Responsibility Model

AWS operates, manages, and controls the components from the software virtualization layer down to the physical security of the facilities where AWS services operate.

3
New cards

Customer's Responsibility

Security in the cloud.

4
New cards

Authorization

The process of verifying permissions.

5
New cards

Availability Zones

Can span multiple availability zones.

6
New cards

Internet Gateway

Bridge for connecting your subnet to the Internet.

7
New cards

VPC Endpoints

A private connection between your VPC and an AWS service in another VPC that doesn't require traffic to go over the public internet.

8
New cards

Amazon CloudFront

Amazon's Content Delivery Network (CDN) for managing the caching of your content around the globe.

9
New cards

Amazon GuardDuty

A threat-detection service for your AWS account using machine learning that continuously monitors for malicious activity.

10
New cards

Amazon Inspector

An automated security assessment service that helps improve the security and compliance of applications deployed on AWS.

11
New cards

AWS Artifact

A service that provides on-demand access to AWS compliance reports and security and privacy documentation.

12
New cards

PaaS (Platform as a Service)

Customer does not need to manage the underlying infrastructure; AWS handles the operating system, database patching, firewall configuration, and disaster recovery.

13
New cards

AWS Shield

A managed distributed denial of service (DDoS) protection tool.

14
New cards

IaaS (Infrastructure as a Service)

Customer is responsible for managing more aspects of the security such as patching the operating system, installing and patching any software installed on the instance, and configuring access controls.

15
New cards

SaaS (Software as a Service)

Customers do not need to manage the infrastructure that supports the service; software is centrally hosted.

16
New cards

Authentication

The process of verifying identity.

17
New cards

Principle of Least Privilege

Grant users the minimum set of permissions that they require to do their jobs.

18
New cards

Encryption of data at Rest

The concept of encrypting stored data so that if the storage is breached, the thief cannot read the data.

19
New cards

Encryption of data in Transit

The concept of encrypting data while it is moving across the network to protect it from eavesdroppers.

20
New cards

IAM User

A person or application that can authenticate with an AWS account.

21
New cards

IAM Group

A collection of IAM users that are granted identical authorization.

22
New cards

IAM Policy

A document that defines which resources can be accessed and the level of access to each resource.

23
New cards

IAM Role

A mechanism to grant a set of permissions for making AWS service requests.

24
New cards

Service Control Policies (SCPs)

Policies that restrict which accounts have access to which services and API actions.

25
New cards

IAM Best Practices

Do not use the AWS account root user except when necessary, enable multi-factor authentication, and store root user credentials securely.

26
New cards

AWS CloudTrail

A service to view all account activity for the last 90 days.

27
New cards

Amazon VPC

Enables you to provision a logically isolated section of the AWS Cloud where you can launch AWS resources in a virtual network that you define.

28
New cards

Subnets

Range of IP addresses that divide a VPC.

29
New cards

IP Ranges

Largest CIDR block size /16 (65536 addresses).

30
New cards

Elastic Network Interface (ENI)

Is a virtual network card for EC2 instances, specifies the IP address(es) for that instance.

31
New cards

Route Table

Specifies the rules on how traffic (data packets) will be routed based upon their destination IP address.

32
New cards

Network Address Translation (NAT) Gateway

Similar to an internet gateway but allows outbound traffic only.

33
New cards

VPC Sharing

Typically, a VPC is for one account only.

34
New cards

VPC Peering

A networking connection between two VPCs that allows them to communicate with each other as if they were part of the same network.

35
New cards

VPC Security Groups

Applied to instances.

36
New cards

Network Access Control Lists (ACLs)

Applied to subnets.

37
New cards

AWS Site-to-Site VPN

A service that connects your on-premises network to your AWS Virtual Private Cloud (VPC) over an encrypted VPN connection using the public internet.

38
New cards

AWS Direct Connect

An alternative to Site-to-Site VPN that instead uses a dedicated, private network connection between your network and AWS.

39
New cards

AWS Transit Gateway

A central hub that connects multiple VPCs and on-premises networks in a scalable and simplified way.

40
New cards

Amazon Cognito

Adds user sign-up, sign-in, and access control to your web and mobile applications.

41
New cards

Amazon Macie

A security service that uses machine learning to automatically discover, classify, and protect sensitive data stored in Amazon S3s.

42
New cards

Amazon Route 53

Amazon's Domain Name System (DNS) web service.

43
New cards

AWS Certificate Manager

A service that provisions, manages, and automatically renews SSL/TLS certificates.

44
New cards

AWS Config

A service that continuously monitors and records your AWS resource configurations and changes.

45
New cards

AWS Identity and Access Management (IAM)

Enables you to manage access to AWS services and resources securely.

46
New cards

AWS Key Management Service (AWS KMS)

Enables you to create and manage encryption keys.

47
New cards

AWS Organizations

Facilitates consolidated billing, supports delegated administration.

48
New cards

AWS Service Catalog

Enables organizations to create and manage catalogs of IT services that are approved for use.

49
New cards

Edge Locations

Physical servers spread around the global that host the data cached by Amazon CloudFront.