All Flashcards
KMS multi region keys what limits on them?
Keys are not global related, not cloned but replicated
Cannot be converted from single region key.
make management of keys more complex
What does kinesis data streams offer for security features?
Control access via IAM.
Encryption in flight.
Encryption at rest with KMS.
VPC endpoint
What two services support VPC Gateway Endpoints
S3.
Dynamo DB
Define AWS firewall manager
Security management service to centrally, configure firewall rules across organizations includes
WAF rules.
Security groups.
Network firewall rules
R 53 resolver
Define IAM ID Center
Allows for sign in for all accounts business cloud apps, like salesforce
Third-party app supporting SAML 2.0
Aurora supports these databases
MYSQL
POSTGRES
How many replicas in aurora cluster max?
15
RDS technology, which does not support IAM
Oracle
Define cloud watch metric stream
Send cloud watch metrics in near real time to S3 via kinesis firehose or third-party destinations
Five tenants of AWS well architected application
Cost
Performance
Reliability
Security.
Operational excellence
aws: principal org ID
For any resource policy to restrict to accounts that are member of an AWS Org
Define comprehend medical is it HIPPA compliant
Detect extract analyze info from unstructured sources, such as doctors notes, radiology reports
Supports HIPAA
Define Kendra
Document search service using machine learning
Define Sagemaker
Fully manage service for deploying machine learning models quickly
Define AWS Polly
Text to speech service.
Uses lexicons for pronunciations.
Uses SSML = speech synthesis markup language
Define Transcribe
Auto convert speech to text
Auto remove PII.
Auto language
Define VPC sharing versus VPC peering
Sharing is for sharing subnets with other AWS accounts or to centrally manage VPCs for multiple accounts.
Peering is a peering connection between two VPCs in same or multiple accounts
What are SCP’s?
Service control policies.
IAM policies applied to OU or accounts to restrict access.
Does not apply to management account
What is S3 max object size
Five TB
What is lambda max execution time?
15 minutes
What are RCU and WCU in Dynamo DB
Read capacity units and write capacity units.
Can be scaled independently
What is the purpose of increasing visibility timeout in SQS?
Gives consumers more time to process messages, resulting in less duplicates
Define SQS visibility timeout
Period of time where SQS prevents other consumers from receiving and processing messages
What is a glacier vault lock?
Uses WORM.
Right once read many
Locks added for never delete