AWS SHIELD Flashcards

1
Q

What is AWS Organizations?

A

AWS Organizations is an account management service that allows consolidation of multiple AWS accounts into an organization that can be centrally managed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of Organizational Units (OUs) in AWS Organizations?

A

OUs in AWS Organizations are used to group multiple accounts and attach different access policies (Service Control Policies) to each OU for managing permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are Service Control Policies (SCPs) in AWS Organizations?

A

SCPs are policies in AWS Organizations that define maximum permissions for accounts or OUs, ensuring that accounts stay within access control guidelines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How are SCPs similar to IAM policies?

A

SCPs in AWS Organizations are similar to IAM permission policies and use JSON syntax to specify maximum permissions but do not grant permissions directly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the relationship between AWS Organizations and IAM?

A

AWS Organizations extends IAM control to account levels, providing centralized control over what users and roles in an account can do.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is AWS Key Management Service (KMS)?

A

AWS KMS is a service that allows the creation and management of encryption keys to control encryption across various AWS services and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does AWS KMS enhance security?

A

AWS KMS uses hardware security modules to protect keys, integrates with AWS CloudTrail for logs, and helps meet regulation and compliance needs regarding key usage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Amazon Cognito used for?

A

Amazon Cognito provides solutions for controlling access to AWS resources from applications, allowing roles to be defined and mapped to users for authorized access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What standards does Amazon Cognito support?

A

Amazon Cognito supports standards such as Security Assertion Markup Language (SAML) version 2.0, enabling single sign-on (SSO) and integration with identity service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is AWS Shield?

A

AWS Shield is a managed Distributed Denial of Service (DDoS) attack protection service that safeguards applications running on AWS from various types of DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What types of DDoS attacks does AWS Shield protect against?

A

AWS Shield protects against infrastructure layer attacks like UDP floods, state exhaustion attacks like TCP SYN floods, and application layer attacks like HTTP floods.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the differences between AWS Shield Standard and AWS Shield Advanced?

A

AWS Shield Standard is automatically enabled for all AWS customers at no additional cost, while AWS Shield Advanced is a paid service that provides additional protection and features.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What additional protection does AWS Shield Advanced provide?

A

AWS Shield Advanced provides protection against more sophisticated and larger DDoS attacks for applications running on various AWS services like EC2 instances and Elastic Load Balancers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can customers access the DDoS response team with AWS Shield Advanced?

A

Customers need to have either business or enterprise support to contact the DDoS response team while using AWS Shield Advanced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some key security features provided by AWS Organizations?

A

AWS Organizations offers features like Service Control Policies (SCPs) for permissions management, identity and access management controls, and account-level security enhancements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly