AWS Cloud Practitioner Essentials T2.4
20 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

What is the main purpose of AWS Marketplace?

  • To provide an environment for developing applications.
  • To find alternative hosting solutions for websites.
  • To buy and deploy software, including security products. (correct)
  • To offer training and certification programs for AWS.

Which service is NOT considered a third-party security tool available in AWS Marketplace?

  • Fortinet Firewall
  • AWS Systems Manager (correct)
  • Splunk Security Analytics
  • Trend Micro Antivirus

Which resource is primarily focused on providing centralized security-related information?

  • AWS Trusted Advisor
  • AWS Security Blog
  • AWS Knowledge Center
  • AWS Security Center (correct)

What function does the AWS WAF (Web Application Firewall) serve?

<p>It protects web applications from common threats. (C)</p> Signup and view all the answers

How does AWS GuardDuty function in threat detection?

<p>Using machine learning and log analysis. (D)</p> Signup and view all the answers

What is the purpose of AWS Trusted Advisor?

<p>To optimize performance by offering security insights. (B)</p> Signup and view all the answers

Which service helps to identify security issues by analyzing network traffic in a VPC?

<p>VPC Flow Logs (C)</p> Signup and view all the answers

What is a key feature of Security Groups in AWS?

<p>They deny all inbound traffic unless explicitly allowed. (D)</p> Signup and view all the answers

What feature does AWS Systems Manager Patch Manager provide?

<p>Automated patching for EC2 instances. (A)</p> Signup and view all the answers

Which service is responsible for logging and tracking all API activity in an AWS account?

<p>CloudTrail (A)</p> Signup and view all the answers

Which of the following is a distinguishing characteristic of Amazon Macie?

<p>Detection and protection of sensitive data in S3. (C)</p> Signup and view all the answers

What is the primary purpose of AWS Secrets Manager?

<p>Securely store and manage sensitive credentials. (D)</p> Signup and view all the answers

Which of these is NOT a feature of AWS security services?

<p>Automated machine learning for data analysis. (C)</p> Signup and view all the answers

How does Network Access Control Lists (NACLs) evaluate rules?

<p>In numerical order based on the rule number. (A)</p> Signup and view all the answers

What distinguishes AWS IAM from AWS IAM Identity Center?

<p>IAM Identity Center allows single sign-on for managing multiple accounts. (A)</p> Signup and view all the answers

What is a characteristic of NACLs regarding default traffic policy?

<p>They allow all inbound and outbound traffic by default. (C)</p> Signup and view all the answers

Which of the following best describes how Security Groups handle inbound and outbound traffic?

<p>They automatically allow response traffic based on inbound rules. (C)</p> Signup and view all the answers

Which service is NOT primarily used for compliance auditing in AWS?

<p>AWS S3 (B)</p> Signup and view all the answers

What would be a suitable use case for NACLs within a VPC?

<p>Block a range of IP addresses from accessing an entire subnet. (B)</p> Signup and view all the answers

Which of the following statements about systems managing encryption keys is true?

<p>KMS can manage both AWS-managed and customer-managed keys. (B)</p> Signup and view all the answers

Flashcards

AWS Marketplace

An online store offering third-party software, including security tools.

Third-Party Security Tools

Security products offered outside of AWS for advanced security.

Firewalls (AWS)

Tools that control network traffic to protect your AWS environment.

WAF

Web Application Firewall - protects web apps from attacks like SQL injection and XSS attacks.

Signup and view all the flashcards

Security Groups

Instance-level firewalls controlling traffic to and from EC2 instances.

Signup and view all the flashcards

GuardDuty

AWS threat detection service using machine learning for suspicious activity.

Signup and view all the flashcards

AWS Security Center

Central hub for AWS security resources and tools.

Signup and view all the flashcards

AWS Systems Manager Patch Manager

Automates patching for EC2 instances with security updates.

Signup and view all the flashcards

AWS Trusted Advisor

Provides security recommendations for cost reduction and performance optimization.

Signup and view all the flashcards

AWS Knowledge Center

A library of FAQs for AWS security and compliance information.

Signup and view all the flashcards

IAM (Identity and Access Management)

A service that controls and manages user access and permissions to AWS resources.

Signup and view all the flashcards

AWS Secrets Manager

A service for securely storing and rotating secrets like API keys and database credentials.

Signup and view all the flashcards

AWS IAM Identity Center (Single Sign-On)

A service that allows centralized access to multiple AWS accounts with a single sign-on experience.

Signup and view all the flashcards

KMS (Key Management Service)

A service for managing and encrypting data using AWS or customer-managed keys.

Signup and view all the flashcards

AWS Config

Tracks configuration changes and checks resource compliance with set rules.

Signup and view all the flashcards

CloudTrail

A service that logs and tracks all API activity in your AWS account for auditing purposes.

Signup and view all the flashcards

Security Hub

Provides a centralized view of security alerts and compliance checks from various AWS services.

Signup and view all the flashcards

NACLs (Network Access Control Lists)

Firewalls that control traffic to and from entire subnets in your VPC.

Signup and view all the flashcards

Stateful vs. Stateless Firewalls

Stateful firewalls allow response traffic for approved inbound traffic automatically, while stateless firewalls require explicit rules for both inbound and outbound traffic.

Signup and view all the flashcards

Study Notes

AWS Security Services

  • AWS Marketplace: Online store for deploying software, including security products.
  • Third-Party Security Tools: Offer specialized features and advanced security for complex use cases (e.g., Fortinet/Palo Alto firewalls, Trend Micro antivirus).
  • Security Information Resources:
    • AWS Knowledge Center: FAQs on security and compliance.
    • AWS Security Center: Central hub for security resources, tools, and best practices.
    • AWS Security Blog: Updates on new services, features, use cases.
    • AWS Documentation: In-depth guides and tutorials for all AWS services.
    • AWS Trusted Advisor: Actionable insights and recommendations for security, cost optimization, and performance.

Security Service Categories

  • Infrastructure Security:

    • WAF (Web Application Firewall): Protects web apps from threats (SQL injection, XSS).
    • Shield: Protects against DDoS attacks (Standard and Advanced).
    • Security Groups: Instance-level firewalls controlling traffic to/from EC2 instances.
    • NACLs (Network Access Control Lists): Subnet-level firewalls controlling traffic to/from subnets.
    • AWS Systems Manager Patch Manager: Automates patching of EC2 instances (security updates).
    • VPC Flow Logs: Monitor and analyze network traffic in VPC for security threats and troubleshooting.
  • Threat Detection:

    • GuardDuty: Threat detection (machine learning, log analysis).
    • Inspector: Scans EC2 instances and containers for vulnerabilities and unpatched software.
    • Amazon Macie: Detects and protects sensitive data in S3.
    • AWS Trusted Advisor: Identifies exposed S3 buckets and provides security recommendations.
  • Identity and Access Management:

    • IAM (Identity and Access Management): Manages user access and permissions for AWS resources.
    • AWS Secrets Manager: Securely stores and rotates secrets (API keys, database credentials).
    • AWS IAM Identity Center: Centralized access to multiple AWS accounts using SSO (Single Sign-On).
    • KMS (Key Management Service): Manages and encrypts data using AWS or customer-managed keys.
  • Compliance and Governance:

    • AWS Config: Tracks configuration changes and checks resource compliance.
    • CloudTrail: Logs and tracks all API activity for auditing.
    • Security Hub: Centralized view of security alerts and compliance checks.
    • AWS Audit Manager: Automates evidence collection for compliance audits.

Security Groups vs. NACLs

  • Security Groups: Instance-level, stateful, default deny, fine-grained control.
  • NACLs: Subnet-level, stateless, default allow, broader control.
  • Key Differences:
    • Statefulness: Security Groups are stateful; NACLs are stateless.
    • Scope: Security Groups control individual instances; NACLs control entire subnets.
  • Use Cases:
    • Security Groups: Traffic control for specific instances, allowing only specific ports (e.g. HTTP, HTTPS).
    • NACLs: Blocking traffic from specific IPs or ranges for entire subnets.
  • Complementary Tools: Both used together for comprehensive security.

Studying That Suits You

Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

Quiz Team

Description

This quiz covers the essential AWS Security Services including the AWS Marketplace, third-party security tools, and various security information resources. Learn about the key components like WAF, Shield, and the AWS Security Center that help protect your infrastructure. Test your knowledge on the latest best practices and tools available for securing your AWS environment.

More Like This

Use Quizgecko on...
Browser
Browser