AWS Certified Security – Specialty flashcards
159 free flashcards. Tap a card to flip it.
Client-Side Encryption with On-Premises HSM
Flip cardClient-Side Encryption (CSE) integrated with an on-premises Hardware Security Module (HSM) allows an application to encrypt data locally using keys stored and managed exclusively within the on-premises HSM, ensuring keys never leave the HSM for cryptographic operations before data is sent to cloud storage.
- Data is encrypted at the application layer before being sent to AWS services like S3.
- Encryption keys are generated, stored, and used within the customer's on-premises HSM.
- Cryptographic operations are performed by the on-premises HSM, maintaining full key control.
- Ensures the highest level of key control and compliance for sensitive data.
Memory trick: Client-Side Cryptography Controls Keys Completely On-Premises.
AWS Data Sovereignty Enforcement with SCPs
Flip cardAWS Organizations Service Control Policies (SCPs) are used to centrally manage permissions across multiple AWS accounts, enabling preventative controls to enforce data sovereignty by restricting resource provisioning to specific geographic regions.
- SCPs apply to all accounts in an Organizational Unit (OU) or the entire organization.
- They can deny actions like resource creation (e.g., S3 buckets, EC2 instances, Lambda functions) in specified AWS Regions.
- SCPs are preventative controls, ensuring compliance from the outset by preventing non-compliant actions.
Memory trick: SCPs Secure Sovereignty, Preventing Prohibited Provisioning.
CloudTrail Organization Trails
Flip cardAn organization trail in AWS CloudTrail logs events for all AWS accounts in an AWS Organization, with centralized management and immutability from member accounts.
- Centralized logging for all accounts in an organization.
- Managed by the management account or a delegated administrator.
- Member accounts cannot disable, modify, or delete organization trails.
- Delivers logs to a single S3 bucket.
Memory trick: Organization Trails are the immutable logs for all accounts.
IAM Role Trust Policy "AWS": "*"
Flip cardA trust policy that allows any authenticated AWS principal from any AWS account to assume the role.
- Extremely dangerous when combined with high-privilege permissions.
- Should almost never be used in production environments.
- Can lead to cross-account compromise if a principal in another account is compromised.
Memory trick: Think of leaving your safe deposit box open for anyone with 'an ID' (any AWS principal) to access.
DynamoDB Encryption with CMKs & Rotation
Flip cardAmazon DynamoDB encryption at rest can be configured with customer-managed keys (CMKs) from AWS KMS, allowing customers to control key policies, enable automatic annual key rotation, and meet strict compliance requirements.
- Uses AWS KMS Customer Master Keys (CMKs) for encryption.
- CMKs provide granular control over key usage and access policies.
- Automatic annual key rotation can be enabled for CMKs within AWS KMS.
Memory trick: CMKs Control DynamoDB, Compliantly Rotating Keys.
S3 Bucket Policy
Flip cardA resource-based access policy attached directly to an S3 bucket, allowing granular control over who can access the bucket and its objects, and under what conditions.
- Defines permissions at the bucket level.
- Can grant or deny access to IAM principals, AWS services, and external accounts.
- Supports conditions based on source IP, VPC endpoint, MFA status, and more.
Memory trick: Bucket Policies are the King, for all your S3 access string.
AWS Directory Service for Microsoft Active Directory
Flip cardA fully managed service that hosts Microsoft Active Directory in the AWS Cloud, enabling seamless integration with existing on-premises AD and AD-aware applications.
- Managed, highly available Microsoft AD.
- Supports standard AD features (GPO, Kerberos, LDAP).
- Enables seamless hybrid identity with on-premises AD.
- Allows AD-aware applications to run without modification.
Memory trick: Managed AD extends your on-prem AD to AWS.
SSE-KMS for Multi-Team Data Encryption
Flip cardServer-Side Encryption with AWS KMS (SSE-KMS) allows Amazon S3 to encrypt objects using customer-managed keys (CMKs) within AWS KMS, enabling centralized key management and granular access control.
- Uses customer-managed keys (CMKs) stored in AWS KMS.
- Keys never leave the KMS service boundary.
- Supports separate CMKs for different applications or teams, enabling fine-grained security and compliance.
Memory trick: KMS Keys Keep S3 Securely Separate for Each Squad.
Cross-Account Resource Access
Flip cardSecurely granting access to an AWS resource in one account to a principal (user, role, or service) in another account, typically using resource-based policies or IAM roles.
- Resource-based policies (S3, SQS, KMS) are ideal for specific resources.
- IAM roles (trust policies) allow principals to assume roles in other accounts.
- Avoid sharing long-lived credentials.
- Adhere to the principle of least privilege.
Memory trick: Resource Policies Reach Resources.
EC2 Dedicated Hosts
Flip cardAn Amazon EC2 Dedicated Host is a physical server with EC2 instance capacity fully dedicated to your use. It allows you to use your existing server-bound software licenses and provides physical isolation for stricter compliance and security requirements.
- Provides physical server isolation for EC2 instances.
- Supports existing server-bound software licenses.
- Offers visibility into sockets and physical cores.
- More expensive than other EC2 options due to dedicated hardware.
Memory trick: A 'Dedicated Host' is like having your own private server room in the cloud.
Default EBS Encryption
Flip cardAWS allows you to enable default encryption for all newly created Amazon EBS volumes and snapshot copies in a specific AWS Region for your account. Once enabled, all new EBS volumes created in that Region are automatically encrypted.
- Applies to new EBS volumes and snapshot copies in a specific region.
- Uses the default KMS key for EBS or a specified custom KMS key.
- A simple, proactive way to enforce encryption at rest.
- Does not affect existing unencrypted volumes.
Memory trick: To encrypt all EBS, just 'flip the default switch' in the account settings.
EC2 Remote Forensic Data Collection
Flip cardAWS Systems Manager (SSM) provides secure, remote management of EC2 instances. Its agent allows security engineers to execute forensic scripts and collect data (e.g., process lists, network states) without direct SSH/RDP login, minimizing impact on potential evidence.
- SSM Agent is pre-installed on many AMIs.
- Enables remote command execution without SSH/RDP.
- Integrates with IAM for granular permissions.
Memory trick: SSM Agent is your ghost in the machine, collecting evidence silently.
AWS Forensic Environment Setup
Flip cardA secure AWS forensic environment involves creating a highly isolated VPC (no internet gateway) for analysis. This prevents contamination and ensures evidence integrity, with controlled access to necessary services like S3 via VPC endpoints.
- Requires strict network isolation (dedicated VPC, no internet gateway).
- Compromised volumes are attached to a clean forensic instance.
- VPC endpoints provide secure access to AWS services (e.g., S3) without public internet.
Memory trick: Build a secure sandbox for your forensics, locked away from the internet.
Hybrid Cloud Connectivity
Flip cardDesigning robust hybrid cloud connectivity involves combining AWS Direct Connect for high-throughput with VPN for encryption and redundancy, often leveraging Transit Gateway for centralized routing.
- Direct Connect: Dedicated, high-bandwidth connection.
- Site-to-Site VPN: Encrypted tunnel over public internet.
- Direct Connect Gateway: Connects DX to multiple VPCs/regions.
- Transit Gateway: Central routing hub for VPCs and on-premises.
Memory trick: Direct Connect for Speed, VPN for Backup, Gateway for Global.
AWS Transit Gateway
Flip cardAWS Transit Gateway is a network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks to a single gateway.
- Simplifies network topology for many VPCs.
- Enables inter-region VPC connectivity.
- Traffic stays within the AWS global network.
- Supports dynamic routing and centralized management.
Memory trick: Transit Gateway Takes on Topology Troubles.
Secure Outbound Internet Access with Inspection
Flip cardA VPC architecture pattern where private instances securely access the internet via a NAT Gateway, with all outbound traffic subjected to deep packet inspection by a Network Firewall.
- Private subnets for application instances.
- NAT Gateway for outbound internet access.
- AWS Network Firewall for centralized deep packet inspection.
Memory trick: Private Apps Need NAT and Firewall Guard!
Encrypted Hybrid Cloud Connectivity (Direct Connect + VPN)
Flip cardA robust hybrid cloud connectivity solution that combines the dedicated, private, and high-bandwidth connection of AWS Direct Connect with the end-to-end encryption capabilities of AWS Site-to-Site VPN. The VPN is established over the Direct Connect link.
- Direct Connect provides a private, dedicated network connection.
- VPN adds a layer of encryption over the private Direct Connect link.
- Ensures data in transit is both private and encrypted.
- Offers high availability and predictable network performance.
Memory trick: Direct Connect is the 'private road', and VPN is the 'armored car' on that road.
S3 Data Protection Best Practices
Flip cardA combination of S3 features like encryption, access control, and public access blocking is essential for securing sensitive data in S3.
- Default encryption ensures all new objects are encrypted.
- Block Public Access prevents accidental public exposure.
- IAM policies and bucket policies control authorized access.
Memory trick: Encrypt, Block, and Control for S3 Data Security.
NAT Gateway
Flip cardA NAT Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Allows outbound internet from private subnets.
- Resides in a public subnet.
- Requires an Elastic IP address.
- Provides a centralized point for outbound traffic.
Memory trick: NAT Gateway Nurtures Network Access for Private Subnets.
Security Groups
Flip cardSecurity Groups act as a virtual firewall for your EC2 instances to control inbound and outbound traffic. They operate at the instance level.
- Stateful: automatically allows return traffic.
- Operate at the instance level.
- Allow or deny based on IP, port, and protocol.
Memory trick: Security Groups Guard Instances, NACLs Nurture Subnets.
Centralized S3 Public Access Monitoring
Flip cardMonitoring for publicly accessible S3 buckets across an AWS Organization is critical for data protection. AWS Security Hub offers a consolidated view of security findings, including S3 public access, making it effective for this task.
- Security Hub aggregates findings from various services.
- Pre-defined controls like S3.3 detect public S3 buckets.
- Provides a centralized dashboard for multi-account security posture.
Memory trick: Security Hub is the central security command center for all your AWS accounts.
Lambda VPC Integration
Flip cardTo securely access resources in a private VPC subnet (like RDS) from AWS Lambda, the Lambda function must be configured to run within that VPC and use private networking.
- Lambda in VPC allows access to private resources.
- Place Lambda in private subnets for security.
- Use security groups for granular access control.
- Traffic remains within the AWS network, not public internet.
Memory trick: Lambda Lives in VPC, Links to RDS Privately.
S3 Access Behavioral Analysis
Flip cardAnalyzing an IAM user's S3 access patterns requires capturing object-level API activity via CloudTrail data events. Amazon Athena can then query these logs in S3 for deep behavioral insights into successful, failed, and unusual access attempts.
- CloudTrail data events record object-level S3 actions.
- Logs are stored in S3 for long-term retention.
- Athena enables SQL queries over S3 data for analysis.
Memory trick: CloudTrail records the story, and Athena helps you read between the lines of S3 access.
Web Application Security Stack
Flip cardA combination of AWS services designed to protect web applications against various threats, including DDoS attacks and common web exploits, offering layered security and automated mitigation.
- AWS Shield provides DDoS protection (Standard for basic, Advanced for enhanced).
- AWS WAF protects against common web exploits (SQL injection, XSS) at the application layer.
- WAF integrates with Application Load Balancer, CloudFront, and API Gateway.
- This combination offers automated, scalable, and managed security.
Memory trick: For web apps, 'Shield' blocks the big waves (DDoS), and 'WAF' catches the 'bad fish' (exploits).
Secure Cross-Account S3 Access for Lambda
Flip cardEnabling AWS Lambda functions to securely and privately access S3 buckets in a different AWS account using VPC Endpoints and S3 Bucket Policies.
- VPC Endpoint for S3 ensures private access.
- S3 Bucket Policy grants cross-account access.
- Least privilege enforced by targeting specific Lambda roles.
Memory trick: Lambda's S3 Secret: VPC Endpoint, Bucket Policy!
API Gateway Private Endpoints
Flip cardAmazon API Gateway Private API endpoints are accessible only from within your Amazon VPC by using an interface VPC endpoint.
- API is not exposed to the public internet.
- Access controlled via VPC Endpoint policies and resource policies.
- Traffic remains within the AWS network.
- Ideal for internal applications and microservices.
Memory trick: Private Endpoint Protects API Privately.
Lambda VPC Configuration
Flip cardConnecting AWS Lambda functions to a Virtual Private Cloud (VPC) by configuring them to run within private subnets, allowing secure access to private VPC resources.
- Lambda ENIs are created in specified subnets.
- Private subnets restrict public internet access.
- Security Groups control traffic to/from Lambda ENIs.
- No NAT Gateway if no internet access is required.
Memory trick: Lambda's VPC Home: Private Subnets, Secure Talk!
Secure EC2 Remote Access
Flip cardAWS Systems Manager Session Manager provides a secure, auditable, and port-free way to remotely access and manage EC2 instances.
- No open inbound ports (SSH/RDP) needed.
- Uses IAM for granular access control.
- Records sessions for auditing (S3/CloudWatch Logs).
- Works with Windows and Linux instances.
Memory trick: Session Manager Secures SSH Sessions.
Idempotent Automated Remediation
Flip cardIdempotent automated remediation ensures that a security action (e.g., revoking access keys) can be safely executed multiple times without unintended side effects. This is often achieved using AWS Lambda triggered by EventBridge, with the Lambda function designed to handle repeated calls gracefully.
- Idempotency means repeated execution yields same result.
- EventBridge triggers Lambda for security findings.
- Lambda functions use AWS SDK for remediation actions (e.g., IAM key rotation/deletion).
Memory trick: EventBridge and Lambda ensure your automated fixes are one-and-done, even if called twice.
Automated IR with EventBridge & Lambda
Flip cardAmazon EventBridge acts as the central event bus to receive security findings (e.g., from GuardDuty) and trigger AWS Lambda functions to execute automated incident response actions, such as revoking IAM roles.
- EventBridge reacts to events from AWS services.
- Lambda executes custom code in response to triggers.
- Together, they form a powerful serverless automation pattern.
Memory trick: EventBridge is the traffic cop directing security alerts to the right Lambda responders.
S3 Access Log Analysis with Athena
Flip cardS3 server access logs record detailed requests made to an S3 bucket. Amazon Athena provides a powerful, serverless SQL query engine to efficiently analyze these logs directly in S3, crucial for forensic investigations of data access and exfiltration.
- S3 server access logs record every request to a bucket.
- Logs are stored in S3.
- Athena enables SQL queries for fast analysis of S3 data.
Memory trick: Athena is your SQL-powered librarian for S3 access logs.
EC2 Instance Isolation
Flip cardThe process of preventing a potentially compromised Amazon EC2 instance from communicating with other systems while preserving its state for investigation.
- Crucial for containing security incidents.
- Network-level isolation is often the first step.
- Preservation of state is vital for forensic analysis.
Memory trick: Security Groups are your first fence for a compromised EC2.
Lambda VPC Configuration for Private Resources and Outbound Internet
Flip cardTo allow AWS Lambda functions to access resources within a private VPC (like RDS) and also connect to the internet for external APIs securely, the Lambda function must be configured to operate within the VPC's private subnets, with outbound internet access facilitated by a NAT Gateway.
- Lambda functions need VPC access enabled to connect to resources in a VPC.
- Place Lambda in *private* subnets to prevent inbound internet access.
- Private subnets must have a route to a NAT Gateway for outbound internet connectivity.
Memory trick: Lambda needs a 'Private Door' to the database and a 'NAT Gate' to the Internet.
AWS Systems Manager Session Manager
Flip cardA fully managed AWS service that provides secure, auditable, and browser-based or CLI-based remote management of EC2 instances and other supported resources without the need to open inbound ports, manage bastion hosts, or handle SSH keys.
- No open inbound ports (e.g., SSH, RDP) required on instances.
- Uses IAM for granular access control and authorization.
- Sessions are logged to CloudWatch Logs or S3 for auditing.
- Works with instances in private subnets without a public IP.
Memory trick: For EC2 access, 'Session Manager' is like a 'secret tunnel' with no visible doors.
Secure Container Image Pipeline
Flip cardA set of automated processes and tools within a CI/CD pipeline designed to build, scan for vulnerabilities, and store container images securely, ensuring that only approved and secure images are deployed to production environments.
- Involves building images from trusted base images.
- Includes automated vulnerability scanning (e.g., Amazon ECR with Inspector).
- Enforces security policies to block vulnerable images.
- Stores images in a secure, private registry (Amazon ECR).
Memory trick: ECR + Inspector is like a 'security checkpoint' for container images before they board the 'production train'.
Cross-Account Access with IAM Roles
Flip cardAWS Identity and Access Management (IAM) roles can be used to securely delegate access to AWS resources between different AWS accounts. This involves one account defining a role that can be assumed by an entity (like an IAM role or user) in another account, providing temporary credentials.
- Eliminates the need to share long-term credentials (access keys).
- Adheres to the principle of least privilege by granting temporary, specific permissions.
- Requires a trust policy on the role in the resource account and a permissions policy on the assuming entity in the calling account.
Memory trick: IAM Roles are like 'Guest Passes' for different accounts.
Secure Container Supply Chain
Flip cardA process flow that integrates container image scanning, automated build and deployment pipelines, and runtime enforcement to ensure only secure and approved container images are deployed.
- ECR image scanning for vulnerability detection.
- CodePipeline for automated CI/CD with gates.
- Fargate task definitions enforce approved images.
Memory trick: ECR Scan, CodePipeline Plan, Fargate Run!
Secure RDS Configuration
Flip cardBest practices for securing Amazon RDS instances involve network isolation, in-transit encryption, and robust authentication mechanisms.
- Private subnets for network isolation.
- SSL/TLS for in-transit encryption.
- IAM database authentication for strong access control.
Memory trick: RDS: Private Network, Encrypted Data, IAM Power!
AWS Web Application Firewall (WAF)
Flip cardAWS WAF helps protect web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources.
- Protects against common web exploits (SQL injection, XSS).
- Filters traffic based on custom rules (IPs, HTTP headers).
- Integrates with ALB, CloudFront, API Gateway, AppSync.
- Provides granular control over web requests.
Memory trick: WAF Watches Web Attacks, Shield Stops DDoS.
EC2 Instance Isolation with Security Groups
Flip cardSecurity groups act as a virtual firewall for EC2 instances, controlling inbound and outbound traffic. They are stateful and operate at the instance level, making them ideal for granular instance isolation during an incident.
- Operate at the instance level, not subnet.
- Are stateful: return traffic is automatically allowed.
- Can be modified dynamically to restrict traffic instantly.
Memory trick: Security Groups are like personal bodyguards for each EC2 instance.
Live EC2 Memory Forensics
Flip cardLive memory forensics involves capturing the volatile memory (RAM) of a running EC2 instance to analyze processes, network connections, and other ephemeral data. This is typically achieved by running a memory capture tool via AWS Systems Manager.
- Focuses on volatile data not stored on disk.
- Requires capturing memory while the instance is running.
- Systems Manager is key for remote execution of capture tools.
Memory trick: Systems Manager is your remote control for live memory evidence collection.
Secure EC2-S3 Access
Flip cardUsing IAM roles attached to EC2 instances to grant secure, temporary, and least-privilege access to AWS resources like S3 buckets and KMS keys.
- IAM roles provide temporary credentials.
- Principle of least privilege is applied.
- Eliminates hardcoding credentials.
Memory trick: EC2's S3 Key: IAM Roles, Not Hardcoded!
Centralized Egress Inspection with Transit Gateway
Flip cardA network architecture pattern where all outbound internet traffic from multiple VPCs is routed through a central inspection VPC containing security appliances (like firewalls) before reaching the internet, typically using AWS Transit Gateway.
- Enhances security by forcing all egress traffic through inspection devices.
- Provides a scalable and manageable solution for multi-VPC environments.
- Utilizes AWS Transit Gateway for inter-VPC routing and NAT Gateway for internet access.
Memory trick: Transit Gateway routes traffic through the 'Inspection Checkpoint' before it goes to the Internet.
AWS API Call Forensics
Flip cardAWS CloudTrail provides a complete history of API calls made in an AWS account, including who made the call, when, from where, and what resources were affected. It is essential for security investigations involving compromised credentials.
- Records all AWS API calls and related events.
- Logs are delivered to S3 and can be sent to CloudWatch Logs.
- Crucial for security auditing, compliance, and incident response.
Memory trick: CloudTrail is the ultimate detective's notebook for every AWS action.
Centralized Encrypted Network Connectivity
Flip cardUsing AWS Transit Gateway with Site-to-Site VPN to achieve encrypted and centrally managed network connectivity between multiple AWS VPCs and on-premises networks.
- Transit Gateway for hub-and-spoke routing.
- Site-to-Site VPN for encrypted on-premises connectivity.
- Scalable and centrally managed.
Memory trick: Transit Gateway + VPN: Centralized, Encrypted, Connected!
EBS Default Encryption
Flip cardYou can enable default encryption for all new EBS volumes and snapshot copies created in a specific AWS Region for your account, using either AWS-managed or customer-managed KMS keys.
- Applied per AWS Region.
- Affects newly created volumes and snapshot copies.
- Can use AWS-managed keys or customer-managed (CMK) keys.
- Enforces encryption without manual intervention.
Memory trick: EBS Encryption is Enabled Easily by Default.
AWS Security Groups
Flip cardAWS Security Groups act as a virtual firewall for your EC2 instances, controlling inbound and outbound traffic at the instance level.
- Stateful: automatically allows return traffic for permitted inbound/outbound rules.
- Operate at the instance level, not the subnet level.
- Can be associated with one or more EC2 instances.
Memory trick: Think of Security Groups as a personal bouncer for your EC2 instance, checking IDs for every connection.
VPC Flow Log Analysis
Flip cardVPC Flow Logs capture information about the IP traffic going to and from network interfaces in a VPC. CloudWatch Logs Insights is the primary tool for interactively querying and analyzing these logs for security investigations.
- Records network flow data (source/destination IP, port, protocol).
- Can be published to CloudWatch Logs or S3.
- CloudWatch Logs Insights offers interactive query capabilities.
Memory trick: Logs Insights is the magnifying glass for your CloudWatch Logs.
Private API Gateway Configuration
Flip cardConfiguring Amazon API Gateway with a 'Private' endpoint type and a VPC Endpoint to restrict access solely to internal VPCs, combined with IAM authorizers for secure authentication.
- Private endpoint type for internal VPC access.
- VPC Endpoint for private connectivity.
- IAM authorizer for IAM credential-based authentication.
Memory trick: API Gateway: Private Endpoints, IAM Authorizers, Internal Access!
EKS Container Logging & Monitoring
Flip cardUsing Fluent Bit DaemonSet for log collection and CloudWatch Logs/Container Insights for centralized logging and performance metrics for Amazon EKS.
- Fluent Bit is a lightweight log processor.
- DaemonSet ensures Fluent Bit runs on every EKS node.
- CloudWatch Logs provides centralized log storage and analysis.
- CloudWatch Container Insights offers specialized metrics for EKS.
Memory trick: Fluent Bit gathers container's chatter, CloudWatch Insights shows what truly matters.
CloudTrail for Access Key Forensics
Flip cardUsing AWS CloudTrail's Event History and CloudTrail Lake to investigate the usage of compromised access keys, including source IP, time, and services accessed.
- CloudTrail logs all API calls and console actions.
- Records `sourceIPAddress`, `userIdentity`, and `eventName` (API call).
- Event History provides a 90-day searchable view.
- CloudTrail Lake allows advanced queries over long-term, aggregated logs.
Memory trick: CloudTrail's history, like a detective's eye, reveals where a key has flown, and why.
EventBridge for CloudFormation API Monitoring
Flip cardUsing Amazon EventBridge to monitor AWS CloudTrail events for critical CloudFormation API calls (e.g., UpdateStack, DeleteStack) and trigger immediate alerts via SNS.
- EventBridge reacts to events from AWS services.
- CloudTrail events include all API calls to CloudFormation.
- Rules can filter for specific `eventName` patterns.
- SNS topics provide immediate, flexible notification options.
Memory trick: EventBridge watches CloudFormation's call, 'Update' or 'Delete' will warn us all.
AWS Security Hub
Flip cardA cloud security posture management service that aggregates, organizes, and prioritizes security findings from multiple AWS services and partner solutions.
- Provides a single pane of glass for security posture.
- Automates security best practice checks.
- Integrates with Amazon EventBridge for automated remediation actions.
Memory trick: Security Hub gathers all risks in one place, then helps automate their chase.
Multi-Account CloudTrail Log Aggregation & Compliance
Flip cardAggregating CloudTrail logs from multiple accounts into a central S3 bucket with KMS encryption and S3 Object Lock in compliance mode for immutable, long-term, and secure retention.
- CloudTrail provides audit logs of AWS API calls.
- Centralized S3 bucket acts as the log repository.
- KMS encryption ensures data encryption at rest.
- S3 Object Lock (Compliance Mode) guarantees WORM and immutability for regulatory needs.
Memory trick: CloudTrail to S3, KMS encrypts, Object Lock keeps history, for ten years and beyond.
SSE-KMS Benefits
Flip cardServer-Side Encryption with AWS KMS provides encryption at rest for S3 objects using KMS-managed keys, offering automatic key rotation, auditability, and integration with AWS services.
- Uses AWS KMS Customer Master Keys (CMKs)
- Supports automatic annual key rotation
- Key usage is logged in AWS CloudTrail for auditability
- Managed service, reducing operational burden
Memory trick: KMS: Keys Managed Securely, Audited Regularly.
VPC Flow Logs
Flip cardA feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.
- Records source/destination IP, port, protocol, action (ACCEPT/REJECT), bytes, packets.
- Can be published to Amazon CloudWatch Logs or Amazon S3.
- Useful for network troubleshooting, security analysis, and compliance.
Memory trick: VPC Flow Logs show network's ebb and flow, where data dares to go.
AWS WAF Logging
Flip cardAWS WAF protects web applications from common exploits, and its logging feature sends detailed web request information to a Kinesis Data Firehose stream for analysis.
- AWS WAF filters web traffic based on defined rules.
- Protects against SQL injection, XSS, and other OWASP Top 10 threats.
- WAF logs provide granular details of every web request.
- Kinesis Data Firehose is an ideal destination for WAF logs for real-time processing.
Memory trick: WAF blocks web threats, Firehose logs the deeds, for forensic needs.
Amazon Inspector
Flip cardAn automated security assessment service that helps improve the security and compliance of applications deployed on AWS by identifying vulnerabilities and deviations from best practices.
- Discovers and scans EC2 instances, container images, and Lambda functions.
- Identifies software vulnerabilities and unintended network exposure.
- Generates prioritized, actionable security findings.
- Integrates with AWS Security Hub for centralized management of findings.
Memory trick: Inspector scans, finds flaws, keeps your AWS secure by its aws.
Amazon Kinesis Data Firehose
Flip cardA fully managed service for delivering real-time streaming data to destinations like S3, Redshift, Splunk, and other HTTP endpoints.
- Automatically scales to match data throughput.
- Supports data transformation via AWS Lambda.
- Integrates with various AWS services as sources and destinations.
Memory trick: Firehose funnels logs, fast and full, to your SIEM system's pool.
AWS Config for Security Group Compliance
Flip cardAWS Config continuously audits security group rules using managed or custom rules to ensure compliance with security policies, alerting on non-compliant configurations.
- AWS Config evaluates resource configurations against desired states.
- Managed rules exist for common security best practices (e.g., restricted SSH).
- Non-compliant findings can trigger notifications via SNS.
- Provides a compliance timeline and history for audited resources.
Memory trick: Config checks security doors, warns if they're too wide, no more.