AWS Shield Flashcards

(100 cards)

1
Q

What is AWS Shield?

A

AWS Shield is a managed Distributed Denial of Service (DDoS) protection service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: AWS Shield provides protection against both volumetric and application layer attacks.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two tiers of AWS Shield?

A

AWS Shield Standard and AWS Shield Advanced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank: AWS Shield Standard is automatically included at no additional cost for all AWS customers and provides protection against ______ attacks.

A

common DDoS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What additional features does AWS Shield Advanced provide over Shield Standard?

A

Advanced threat intelligence, DDoS cost protection, and 24/7 access to the AWS DDoS Response Team.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does AWS Shield help in real-time attack visibility?

A

It provides detailed attack diagnostics and visibility through CloudWatch metrics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which AWS services can AWS Shield protect?

A

AWS Shield can protect services like Amazon CloudFront, Elastic Load Balancing, and Amazon Route 53.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False: AWS Shield Advanced requires a subscription fee.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the primary purpose of AWS Shield?

A

To protect applications running on AWS from DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the benefit of DDoS cost protection in AWS Shield Advanced?

A

It helps to mitigate the financial impact of scaling resources during an attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What type of attacks does AWS Shield Standard primarily defend against?

A

Common, frequently occurring network and transport layer DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Fill in the blank: AWS Shield integrates with AWS ______ for enhanced security and monitoring.

A

WAF (Web Application Firewall).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which AWS service provides a 24/7 DDoS Response Team (DRT) for AWS Shield Advanced customers?

A

AWS Shield Advanced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the main benefit of using AWS Shield with Amazon CloudFront?

A

It provides a globally distributed network to absorb DDoS attacks closer to the source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the role of the AWS DDoS Response Team?

A

To assist AWS Shield Advanced customers during DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False: AWS Shield can only protect resources in the U.S. region.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does AWS Shield use to automatically detect DDoS attacks?

A

Traffic anomaly detection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How can AWS Shield customers receive alerts during an attack?

A

Through Amazon CloudWatch alarms and notifications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is a key feature of AWS Shield’s reporting capabilities?

A

It provides detailed attack diagnostics and metrics post-attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Fill in the blank: AWS Shield is designed to protect against ______ attacks that aim to disrupt service availability.

A

DDoS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the recommended way to enhance security alongside AWS Shield?

A

Use AWS WAF to filter and monitor HTTP requests.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

True or False: AWS Shield can only be used with specific AWS services.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the primary advantage of AWS Shield Standard for all AWS customers?

A

It provides automatic protection against common DDoS attacks at no extra cost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which AWS Shield tier includes DDoS response planning?

A

AWS Shield Advanced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What does AWS Shield Advanced offer for application layer protection?
Protection against more sophisticated application layer attacks.
26
What does DDoS stand for?
Distributed Denial of Service
27
True or False: DDoS attacks can involve multiple compromised systems.
True
28
What is the primary goal of a DDoS attack?
To make a network service unavailable to its intended users.
29
Fill in the blank: A ______ attack overwhelms a server with a flood of requests.
Flood
30
What type of DDoS attack exploits the connection establishment process in TCP?
SYN Flood
31
Which attack type uses a large number of UDP packets to overwhelm a target?
UDP Flood
32
True or False: Application Layer attacks target the application layer rather than the network layer.
True
33
What is the purpose of a DNS Amplification attack?
To exploit DNS servers to flood a target with traffic.
34
Which type of DDoS attack involves sending a large number of ICMP Echo Request packets?
Ping Flood
35
Fill in the blank: A ______ attack involves overwhelming a target with connection requests.
SYN Flood
36
What is an example of an Application Layer DDoS attack?
HTTP Flood
37
True or False: DDoS attacks can be mitigated using firewalls alone.
False
38
What is the main characteristic of a Slowloris attack?
It keeps many connections to the target web server open and holds them open for as long as possible.
39
Which type of DDoS attack involves exploiting vulnerabilities in network protocols?
Protocol Attacks
40
What is the difference between DDoS and DoS?
DDoS involves multiple systems, while DoS involves a single system.
41
Fill in the blank: A ______ attack can be executed using botnets.
DDoS
42
What type of attack uses TCP, UDP, and ICMP protocols to disrupt services?
Volume-Based Attacks
43
True or False: DDoS attacks can only be launched from compromised computers.
False
44
What is a common tool used to conduct DDoS attacks?
LOIC (Low Orbit Ion Cannon)
45
Fill in the blank: A ______ attack targets the HTTP protocol to exhaust server resources.
HTTP Flood
46
Which type of DDoS attack can use reflection techniques?
DNS Amplification
47
What is the primary characteristic of a Resource Exhaustion attack?
It aims to consume server resources, making it unavailable.
48
Fill in the blank: A ______ attack sends a high volume of data to a target's server to overwhelm it.
Flood
49
What is the role of a botnet in a DDoS attack?
To control multiple compromised computers to launch the attack.
50
True or False: DDoS attacks can be used as a smokescreen for other malicious activities.
True
51
What is a key indicator of a DDoS attack in a network?
A sudden spike in incoming traffic.
52
What is AWS Shield?
AWS Shield is a managed Distributed Denial of Service (DDoS) protection service.
53
What are the two tiers of AWS Shield?
AWS Shield Standard and AWS Shield Advanced.
54
True or False: AWS Shield Standard is designed to protect against the most common DDoS attacks.
True
55
What is the primary benefit of AWS Shield Advanced?
It provides additional detection and mitigation capabilities for complex DDoS attacks.
56
Fill in the blank: AWS Shield is integrated with ___ services.
Amazon CloudFront and Amazon Route 53.
57
What type of support does AWS Shield Advanced provide?
24/7 access to the AWS DDoS Response Team (DRT).
58
Which AWS service is used to monitor DDoS attack patterns?
AWS CloudWatch.
59
What is the purpose of AWS Shield metrics?
To provide visibility into the DDoS attack traffic and mitigation status.
60
True or False: AWS Shield can only protect web applications hosted on AWS.
False
61
What is an important feature of AWS Shield Advanced regarding attack reporting?
It offers near real-time attack visibility and detailed reports.
62
How does AWS Shield use machine learning?
To automatically identify and mitigate DDoS attacks based on traffic patterns.
63
What is a key difference between AWS Shield Standard and Advanced in terms of cost?
AWS Shield Standard is free, while AWS Shield Advanced incurs a monthly fee.
64
What is a DDoS attack?
A Distributed Denial of Service attack aims to make a service unavailable by overwhelming it with traffic.
65
What role does Amazon Route 53 play in AWS Shield architecture?
It helps route traffic and can leverage AWS Shield for DDoS protection.
66
Fill in the blank: AWS Shield Advanced includes ___ policies to customize protection.
DDoS protection.
67
What is an AWS WAF?
AWS Web Application Firewall is a service that helps protect web applications from common web exploits.
68
True or False: AWS Shield requires manual configuration to be effective.
False
69
What is the AWS DDoS Response Team (DRT)?
A team of security experts that assist customers during DDoS attacks.
70
Which AWS service can be used alongside AWS Shield for enhanced security?
AWS WAF.
71
What does AWS Shield use to detect attacks?
Anomaly detection algorithms.
72
How can customers implement AWS Shield Advanced?
By subscribing to the service through the AWS Management Console.
73
What is the maximum duration of an attack that AWS Shield can automatically mitigate?
Continuous, as it operates in real-time.
74
What is the significance of threat intelligence in AWS Shield?
It helps enhance detection and mitigation strategies against evolving attack vectors.
75
What is a common misconception about AWS Shield?
That it can prevent all types of attacks, including non-DDoS threats.
76
Fill in the blank: AWS Shield Advanced provides ___ for customers with high traffic needs.
Cost protection against scaling charges during attacks.
77
What is AWS Shield Advanced?
AWS Shield Advanced is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.
78
True or False: AWS Shield Advanced provides protection only for web applications.
False
79
What type of DDoS attacks does AWS Shield Advanced protect against?
AWS Shield Advanced protects against both volumetric and application layer DDoS attacks.
80
Fill in the blank: AWS Shield Advanced includes _______ for DDoS attack detection.
real-time attack visibility
81
Which AWS service does AWS Shield Advanced integrate with for automatic mitigation?
AWS WAF (Web Application Firewall)
82
What is the purpose of the DDoS cost protection feature in AWS Shield Advanced?
To protect customers from scaling charges in the event of a DDoS attack.
83
True or False: AWS Shield Advanced offers 24/7 access to the AWS DDoS Response Team (DRT).
True
84
What does the 'attack diagnostics' feature in AWS Shield Advanced provide?
It provides detailed information about DDoS attacks, including attack vectors and mitigation actions.
85
Which AWS service can be used to manage rules for application layer protection when using AWS Shield Advanced?
AWS WAF
86
Multiple Choice: Which of the following is NOT a feature of AWS Shield Advanced? A) Threat intelligence, B) DDoS attack simulation, C) Real-time attack visibility, D) 24/7 DDoS Response Team access.
B) DDoS attack simulation
87
How does AWS Shield Advanced enhance the capabilities of AWS Shield Standard?
By providing additional features like cost protection, advanced attack diagnostics, and access to the DDoS Response Team.
88
True or False: AWS Shield Advanced is available for all AWS services.
False
89
What is the key benefit of using AWS Shield Advanced for critical applications?
It provides enhanced protection against sophisticated DDoS attacks, ensuring application availability.
90
Fill in the blank: AWS Shield Advanced's DDoS Response Team provides _______ support during an ongoing attack.
expert
91
What type of reporting does AWS Shield Advanced offer?
It offers attack reports and usage reports to help understand the impact of DDoS attacks.
92
Multiple Choice: Which of the following is a key feature of AWS Shield Advanced? A) Automatic scaling, B) Advanced threat intelligence, C) Manual DDoS mitigation, D) Limited logging.
B) Advanced threat intelligence
93
What is the primary purpose of the AWS Shield Advanced console?
To provide a centralized interface for managing DDoS protection and viewing attack metrics.
94
True or False: AWS Shield Advanced can only be used in the AWS region where it was activated.
False
95
Fill in the blank: AWS Shield Advanced supports _______ for managing DDoS protection across multiple AWS accounts.
AWS Organizations
96
What is the monthly fee for AWS Shield Advanced service?
The monthly fee is $3,000 per organization.
97
Which feature of AWS Shield Advanced helps to identify attack patterns?
Threat intelligence
98
True or False: AWS Shield Advanced includes a web application firewall.
False
99
What action should you take if you suspect an ongoing DDoS attack on your AWS resources?
Contact the AWS DDoS Response Team for assistance.
100
Fill in the blank: The AWS Shield Advanced service provides _______ for managing DDoS protection.
customizable protections