AWS Security Services Flashcards

1
Q

AWS Security Services (high-level)

Hook up to Oracle to do transparent encryption?

A

CloudHSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS Security Services (high-level)

Most secure way to secure a CA?

A

CloudHSM store issuing certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Security Services (high-level)

Service for finding root cause of security findings

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS Security Services (high-level)

Integrates network traffic with security events like strange logins and AWS activity?

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Security Services (high-level)

Can help find suspicious activity on the network

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AWS Security Services (high-level)

Detective use case?

A

Help find root cause of security findings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AWS Security Services (high-level)

Does Detective alert you or do you go to Detective for info?

A

Passive only: go to Detective to look thru data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AWS Security Services (high-level)

System uses ML to find outliers in data

A

Detective and GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS Security Services (high-level)

Continuous security monitoring service?

A

GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS Security Services (high-level)

Uses threat intelligence feeds?

A

GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AWS Security Services (high-level)

Inputs to GuardDuty?

A

threat intelligence feeds, logs from everywhere

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

AWS Security Services (high-level)

How does GuardDuty find things?

A

ML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS Security Services (high-level)

How do Detective and GuardDuty relate?

A

GuardDuty findings are inputs to Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS Security Services (high-level)

Uses ML to look thru things, creates Findings for you

A

GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

AWS Security Services (high-level)

Where does GuardDuty send findings?

A

Detective and Security Hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AWS Security Services (high-level)

Example finding from GuardDuty?

A

Known malicious source IPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

AWS Security Services (high-level)

Example finding from Inspector?

A

Bad ssh configuration

18
Q

AWS Security Services (high-level)

Checks EC2 instances and containers for vulnerabilities

19
Q

AWS Security Services (high-level)

Run it for a while and see whats in its report?

20
Q

AWS Security Services (high-level)

Has an agent to collect things on EC2

21
Q

AWS Security Services (high-level)

Pokes at an EC2 from the outside to see what it is

22
Q

AWS Security Services (high-level)

Reports on reachability

23
Q

AWS Security Services (high-level)

Finds open and unusual ports

24
Q

AWS Security Services (high-level)

Dealswith CVEs and CIS benchmarks?

25
# *AWS Security Services (high-level)* Single location for management and remediation of security
SecurityHub
26
# *AWS Security Services (high-level)* Compares your account against industry standards?
Security Hub
27
# *AWS Security Services (high-level)* Sends EventBridge events when it finds something
Security Hub, Trusted Advisor
28
# *AWS Security Services (high-level)* Looks at your AWS services configurations looking for bad practices
Security Hub and Trusted Advisor
29
# *AWS Security Services (high-level)* Produces a report with findings across many other tools
Security Hub
30
# *AWS Security Services (high-level)* Can automate findings to fix things when they pop up
Security Hub
31
# *AWS Security Services (high-level)* Gets all its findings from other AWS services
Security Hub
32
# *AWS Security Services (high-level)* How are Security Hub and Config different?
Config does actual work finding probs, Security Hub gets Config output
33
# *AWS Security Services (high-level)* Systems that send findings to Security Hub?
Config, GuardDuty, Inspector
34
# *AWS Security Services (high-level)* Security Hub sends findings to what services?
Detective, Trusted Advisor
35
# *AWS Security Services (high-level)* Example of something Trusted Advisor finds?
Unused EC2 instances
36
# *AWS Security Services (high-level)* System fueled by AWS Support cases
Trusted Advisor
37
# *AWS Security Services (high-level)* System that can recommend cost savings?
Trusted Advisor
38
# *AWS Security Services (high-level)* What other systems send data to Trusted Advisor?
Config, Security Hub
39
# *AWS Security Services (high-level)* What powers some of the Trusted Advisor checks?
Config
40
# *AWS Security Services (high-level)* Finds sensitive data in S3?
Macie
41
# *AWS Security Services (high-level)* Where does Macie send results?
Security Hub
42
# *AWS Security Services (high-level)* Gathers evidence for a compliance audit
Audit Manager