AWS Shield Flashcards
(100 cards)
What is AWS Shield?
AWS Shield is a managed Distributed Denial of Service (DDoS) protection service.
True or False: AWS Shield provides protection against both volumetric and application layer attacks.
True.
What are the two tiers of AWS Shield?
AWS Shield Standard and AWS Shield Advanced.
Fill in the blank: AWS Shield Standard is automatically included at no additional cost for all AWS customers and provides protection against ______ attacks.
common DDoS.
What additional features does AWS Shield Advanced provide over Shield Standard?
Advanced threat intelligence, DDoS cost protection, and 24/7 access to the AWS DDoS Response Team.
How does AWS Shield help in real-time attack visibility?
It provides detailed attack diagnostics and visibility through CloudWatch metrics.
Which AWS services can AWS Shield protect?
AWS Shield can protect services like Amazon CloudFront, Elastic Load Balancing, and Amazon Route 53.
True or False: AWS Shield Advanced requires a subscription fee.
True.
What is the primary purpose of AWS Shield?
To protect applications running on AWS from DDoS attacks.
What is the benefit of DDoS cost protection in AWS Shield Advanced?
It helps to mitigate the financial impact of scaling resources during an attack.
What type of attacks does AWS Shield Standard primarily defend against?
Common, frequently occurring network and transport layer DDoS attacks.
Fill in the blank: AWS Shield integrates with AWS ______ for enhanced security and monitoring.
WAF (Web Application Firewall).
Which AWS service provides a 24/7 DDoS Response Team (DRT) for AWS Shield Advanced customers?
AWS Shield Advanced.
What is the main benefit of using AWS Shield with Amazon CloudFront?
It provides a globally distributed network to absorb DDoS attacks closer to the source.
What is the role of the AWS DDoS Response Team?
To assist AWS Shield Advanced customers during DDoS attacks.
True or False: AWS Shield can only protect resources in the U.S. region.
False.
What does AWS Shield use to automatically detect DDoS attacks?
Traffic anomaly detection.
How can AWS Shield customers receive alerts during an attack?
Through Amazon CloudWatch alarms and notifications.
What is a key feature of AWS Shield’s reporting capabilities?
It provides detailed attack diagnostics and metrics post-attack.
Fill in the blank: AWS Shield is designed to protect against ______ attacks that aim to disrupt service availability.
DDoS.
What is the recommended way to enhance security alongside AWS Shield?
Use AWS WAF to filter and monitor HTTP requests.
True or False: AWS Shield can only be used with specific AWS services.
False.
What is the primary advantage of AWS Shield Standard for all AWS customers?
It provides automatic protection against common DDoS attacks at no extra cost.
Which AWS Shield tier includes DDoS response planning?
AWS Shield Advanced.