udemy 3 Flashcards

(30 cards)

1
Q

SCP

A

service control policies, manage across accounts. apply to groups or OUs

allowlist or blocklist
need explicit allows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IAM conditions

A

aws sourceip: restrict client calls from source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

resource based polies

A

sms sqs lamda cloudwath logs api calls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IAM role

A

kinesis, systems manager, run command, ecs task

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IAM Permission boundaries

A

for uses and roles, not goups. sets maximum permissions for a user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AWS Identity Center

A

Single sign on. SAML 2.0 integration. multiple aws account logins.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AD flavors

A

Ms AD
AD Conector (direct connect)
AD Simple no on prem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control tower

A

govern multi-accounts using organizations

preventive guardrails using scps
detecitive : compliance using config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

KMS

A

Encryption Keys managed by AWS
can be audited by cloudtrail
requires policies: default or custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

KMS Key Types

A

Symmetric: One key AES-256 always encrypt
Assymetric: public encrypt, private decrypt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

S3 encryption

A

SSE-s3 encrypted objects are replicated by default
SSE-C: can be replicated, but not by default.
SSE:KMS has to be specified at bucket level target. enable replication (multi region decrypted and encrypted)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sharing an AMI between accounts

A

Change the launch permission
Share the KMS key
Role or permisson to use key KMS side to encrypt or dencrypt.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SSM Parameter Store

A

Secure for configurations and secretes
serverless
version tracking
IAM
EventBridge
(Secrets mngr difference: you can rotate and force a rotate)
RDS Auroa
Multi-region secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Sheild, shiel Advanced vs. WAF

A

Shield: layer 3 and 4
WAF : layer 7 (no NLB)
advanced: 24/7 shield advanced team: auto applies WAF rules at layer 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Inspector

A

EC2 instances, Lambda, and ECR: sends findings into security hub and eventbridge

looks for vulnerabiliites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CIDR
192.168.0.0-192168.0.255
(256 IPs b/c 0-255)

192.168.0.0/16
192.168/255/255

A

/32 no octet can change
/24 last octet can change
/16 last two octets can change
/8 last 3 octets can change
/0 all octets can change

17
Q

Private IPs

A

10.0.0.0-10.255.255.255 (private)
172.16.0.0/12 AEP private IPs
192.168.0.0/16 (private IP home)

18
Q

bastion host

A

security group set up allow public inbound from internet on port 22 restriceted to CIDR

private: allows the bastion host or private IP

A bastion host is a publicly accessible host that allows traffic to connect to it. Then, an additional connection is made from the bastion host into a private subnet and the hosts within that subnet.

19
Q

RTO
RPO

A

Recovery time objective (when you recover) how much downtime?
Revover point objective (how often run backups)

20
Q

Backup and Restore

A

High RPO
recreate and restore
cost of storing backups

21
Q

Pilot Light

A

small app version is always running in the cloud. all other systems get added on in time of recovery

22
Q

warm standby

A

full sytem up and running but minimal size.

23
Q

Multi site

A

expensive and active active setup

24
Q

ENA

A

Elastic Network Adaptor (speeds eC2 for high computing)
EFA: same but only for Linux must be used with AWS Parallell cluster

25
SES
Simple Emailing Service
26
Pinpoint
inbound/outbound marketing communication service
27
SSM session manager service
session into ec2 without opening port 22
28
appflow
SaaS to AWS (salesforce for example) int redshift or s3 etc.
29
amplify
web and mobile app tool
30
7 pillars
operational excellence security reliability Performance efficiency cost optimization sustainability