Shield Flashcards

This deck aims to help retain concepts related to the AWS Shield service. (17 cards)

1
Q

Which managed service offers protection against distributed denial of service (DDoS) attacks for applications on AWS?

A

AWS Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which AWS Shield option is free of charge for AWS customers?

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of attacks does AWS Shield protect against?

A
  • Network volumetric attacks (Layer 3): capacity saturation
  • Network protocol attacks (Layer 4): TCP SYN flood
  • Application layer attacks (Layer 7): web request floods
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two options of AWS Shield?

A
  • Shield Standard – free for all AWS customers
  • Shield Advanced – paid option with additional features
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which AWS Shield option provides protection at the network perimeter (region for VPC) and at the edge (CloudFront or Global Accelerator)?

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which AWS Shield option defends against network (L3) and transport (L4) layer attacks?

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which AWS Shield option is a commercial product with extra features and additional cost?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Is AWS Shield Advanced enabled automatically?

A

No, must be explicitly enabled in Shield Advanced or AWS Firewall Manager Shield Advanced Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which AWS Shield option protects Route 53, CloudFront, Global Accelerator, and resources associated with Elastic IPs, ALBs, NLBs, and CLBs?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which AWS Shield option provides cost protection for EC2 scaling events caused by unmitigated attacks?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS Shield option provides proactive engagement and access to the Shield Response Team (SRT) when availability or performance is affected by an attack?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which AWS Shield option provides health-based detection (application-specific health checks) to enable proactive engagement by the Shield Response Team?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which AWS Shield option provides health-based detection (requires application-specific health checks) to enable proactive engagement by the Shield Response Team?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which AWS Shield option integrates with AWS Web Application Firewall (WAF) to provide application-layer (L7) protection?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which AWS Shield option provides real-time metrics and reports of DDoS events and attacks?

A

AWS Shield Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What AWS Shield Advanced feature allows creating logical collections of protected resources and managing them together?

A

Protection groups

14
Q

What is the pricing model for AWS Shield Advanced?

A
  • $3,000 per month per organization (minimum 12-month commitment)
  • Data-transfer-out/month usage fees