AWS Certified Security – Specialty flashcards
159 free flashcards. Tap a card to flip it.
AWS SCP for Data Residency
Flip cardService Control Policies (SCPs) in AWS Organizations enforce maximum permissions for AWS accounts, allowing organizations to restrict resource creation to specific AWS regions to ensure data residency.
- Part of AWS Organizations
- Enforces guardrails at the account/OU level
- Can deny actions like 's3:CreateBucket' or 'lambda:CreateFunction' in unauthorized regions
- Effective for enforcing data residency and sovereignty
Memory trick: SCPs Keep Regions Securely Controlled.
Multi-Account CloudTrail Log Aggregation & Compliance
Flip cardAggregating CloudTrail logs from multiple accounts into a central S3 bucket with KMS encryption and S3 Object Lock in compliance mode for immutable, long-term, and secure retention.
- CloudTrail provides audit logs of AWS API calls.
- Centralized S3 bucket acts as the log repository.
- KMS encryption ensures data encryption at rest.
- S3 Object Lock (Compliance Mode) guarantees WORM and immutability for regulatory needs.
Memory trick: CloudTrail to S3, KMS encrypts, Object Lock keeps history, for ten years and beyond.
Application-Level Encryption for Multi-Tenancy (AWS Encryption SDK)
Flip cardApplication-level encryption for multi-tenancy encrypts each tenant's data with a unique key at the application layer before it's sent to the database, ensuring strong data isolation. The AWS Encryption SDK simplifies this process by integrating with KMS.
- Encrypts data before it leaves the application
- Each tenant's data encrypted with a unique key
- Uses AWS KMS to manage and derive tenant-specific data keys
- Provides granular control over encryption for multi-tenant isolation
Memory trick: SDK Secures Distinct Keys for Each Tenant.
EventBridge for CloudFormation API Monitoring
Flip cardUsing Amazon EventBridge to monitor AWS CloudTrail events for critical CloudFormation API calls (e.g., UpdateStack, DeleteStack) and trigger immediate alerts via SNS.
- EventBridge reacts to events from AWS services.
- CloudTrail events include all API calls to CloudFormation.
- Rules can filter for specific `eventName` patterns.
- SNS topics provide immediate, flexible notification options.
Memory trick: EventBridge watches CloudFormation's call, 'Update' or 'Delete' will warn us all.
AWS Security Hub
Flip cardA cloud security posture management service that aggregates, organizes, and prioritizes security findings from multiple AWS services and partner solutions.
- Provides a single pane of glass for security posture.
- Automates security best practice checks.
- Integrates with Amazon EventBridge for automated remediation actions.
Memory trick: Security Hub gathers all risks in one place, then helps automate their chase.
VPC Traffic Mirroring
Flip cardA feature that allows you to copy network traffic from an Elastic Network Interface (ENI) and send it to a monitoring tool for deep packet inspection.
- Copies actual network packets
- Used for security monitoring, anomaly detection, troubleshooting
- Targets can be EC2 instances or Network Load Balancers
Memory trick: Mirror the traffic, catch the bad actors.
AWS WAF Logging to CloudWatch Logs with Filters
Flip cardA method to capture detailed AWS WAF traffic logs, send them to Amazon CloudWatch Logs, and use CloudWatch Logs subscription filters to stream specific log patterns for real-time analysis and alerting.
- WAF provides detailed logs of requests it processes.
- CloudWatch Logs offers centralized log storage and analysis.
- Subscription filters enable real-time pattern matching and streaming.
- Integrates with Lambda for custom alerting and S3 for archiving.
Memory trick: WAF logs to CloudWatch, filters trigger Lambda to shout for patterns.
Amazon GuardDuty
Flip cardA fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.
- Uses machine learning, anomaly detection, and threat intelligence.
- Identifies unusual API calls, unauthorized access, and known malicious IP addresses.
- Provides findings that can be integrated with other security services.
Memory trick: GuardDuty is your always-on security guard, watching for threats.
S3 Object Lock (Compliance Mode)
Flip cardA feature of Amazon S3 that prevents an object from being overwritten or deleted for a fixed amount of time or indefinitely, even by the root user. Compliance mode offers the strongest protection.
- Ensures WORM (Write Once, Read Many) storage.
- Prevents deletion or modification by any user, including root.
- Critical for meeting strict regulatory compliance requirements for data immutability.
Memory trick: Object Lock's Compliance mode makes logs as solid as a rock.
AWS Config Conformance Packs
Flip cardCollections of AWS Config rules and remediation actions that can be easily deployed as a single entity to establish a common baseline for compliance.
- Automates compliance checks across accounts/regions
- Provides a consolidated compliance dashboard
- Supports predefined and custom rules for various standards
Memory trick: Config's Conformance Packs, keep compliance on track.
Organization-wide CloudTrail
Flip cardA single CloudTrail trail created in the management account that logs events from all AWS accounts in an organization.
- Centralized logging for AWS Organizations
- Captures API calls and configuration changes
- Simplifies compliance and auditing across accounts
Memory trick: One trail for all, secure and never fall.
Centralized Custom Log Management
Flip cardCollecting diverse custom logs from EC2, centralizing them for real-time querying, analysis, and long-term archival.
- Requires flexible ingestion for varied formats
- Needs real-time search and analytics for threat hunting
- Long-term, cost-effective archival is crucial
Memory trick: Gather, transform, then search and store.
CloudTrail S3 Data Events
Flip cardRecords object-level API activity for Amazon S3 buckets, providing detailed logs of GetObject, PutObject, DeleteObject, and other object operations.
- Captures detailed object-level API calls.
- Essential for auditing data access and changes.
- Can be integrated with CloudWatch Logs and SIEMs for real-time monitoring.
Memory trick: CloudTrail Data Events track every S3 object's journey.
Lambda Logging & Monitoring
Flip cardAWS Lambda integrates with CloudWatch Logs for function execution logs and CloudTrail for invocation events.
- CloudWatch Logs stores function output and errors
- CloudTrail records API calls, including Lambda invocations
- Essential for troubleshooting serverless applications
Memory trick: CloudWatch shows what Lambda did, CloudTrail shows who called it.
AWS Config
Flip cardA service that enables you to assess, audit, and evaluate the configurations of your AWS resources.
- Records configuration changes over time
- Evaluates against desired configurations (rules)
- Provides compliance status and generates alerts
Memory trick: Config checks your stuff, making sure it's tough.
Cross-Account CloudTrail Monitoring
Flip cardCentralized, immutable logging and alerting for all API activities across multiple AWS accounts in an organization.
- Organization trail for centralization
- S3 Object Lock for immutability and retention
- CloudWatch Alarms for tampering detection
Memory trick: One trail, one lock, one alarm, keeps the org safe from harm.
Application Logs
Flip cardLogs generated directly by an application (e.g., web server, database, custom software) that record events, errors, and user activities specific to that application's operations.
- Provide granular details about application-level events.
- Essential for troubleshooting application issues and security incidents.
- Location and format vary by application and operating system.
Memory trick: For EC2 logins, check the app's own diary.
GuardDuty Findings to CloudWatch Metrics
Flip cardThe process of forwarding Amazon GuardDuty security findings, which are published to Amazon EventBridge, to Amazon CloudWatch as custom metrics for monitoring and visualization on dashboards.
- GuardDuty findings are emitted as events to EventBridge.
- EventBridge rules can filter and transform these events.
- Custom metrics can be published to CloudWatch based on EventBridge events.
- CloudWatch Dashboards visualize these metrics for security monitoring.
Memory trick: EventBridge routes GuardDuty findings to CloudWatch metrics, dashboard shows the story.
AWS CloudTrail for Forensics
Flip cardA service that records all API calls and related events made in an AWS account, providing an audit trail for security analysis, compliance, and operational troubleshooting.
- Captures management and data events.
- Records identity of the caller (IAM user/role), IP address, time, and API call.
- Essential for forensic investigations to trace actions and identify responsible principals.
Memory trick: CloudTrail leaves the trail of who did what, when, and where.
EKS Container Logging
Flip cardCollecting and centralizing application and container runtime logs from Amazon EKS pods for monitoring and analysis.
- Requires a robust, scalable collection mechanism
- Centralized storage and analysis are critical
- Common patterns include sidecars or DaemonSets
Memory trick: Sidecar grabs logs, Firehose streams, OpenSearch finds the gleam.
AWS Config Rules with Remediation
Flip cardAWS Config allows you to define rules to evaluate the configuration of your AWS resources. These rules can be integrated with AWS Systems Manager Automation for automatic remediation of non-compliant resources.
- Continuously monitors resource configurations.
- Detects non-compliant settings (e.g., overly permissive security groups).
- Enables automatic remediation using Systems Manager Automation documents.
- Scalable across multiple accounts and regions.
Memory trick: Config rules set the standard, Systems Manager fixes the flaws.
EKS Container Logging with Fluent Bit/Firehose
Flip cardA common architecture for collecting logs from Amazon EKS containers using Fluent Bit (deployed as a DaemonSet) to aggregate logs, and Amazon Kinesis Data Firehose to reliably deliver them to a centralized destination like Amazon OpenSearch Service.
- Fluent Bit/Fluentd are lightweight log collectors for Kubernetes.
- DaemonSet ensures a collector runs on every node.
- Kinesis Data Firehose provides managed, scalable, and reliable delivery.
- Enables centralized logging for EKS applications in OpenSearch Service.
Memory trick: Fluent Bit collects from every pod, Firehose pipes them to OpenSearch.
AWS CloudTrail
Flip cardA service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by recording API calls.
- Records API calls made to AWS services.
- Provides event history including identity, time, source IP, and API call.
- Logs to S3 and can integrate with CloudWatch Logs.
Memory trick: CloudTrail is the 'black box recorder' for all AWS API actions, revealing who did what, when, and from where.
CloudTrail Organization Trail
Flip cardA single CloudTrail trail created in the AWS Organizations management account that records events for all member accounts in the organization.
- Automatically applies to all existing and future member accounts.
- Logs to a central S3 bucket.
- Ensures consistent logging across the organization.
Memory trick: The Organization Trail is the 'master logger' for the entire AWS family, sending all secrets securely to the central vault.
EKS Container Logging with Fluent Bit
Flip cardUtilizing Fluent Bit as a DaemonSet in Amazon EKS to collect and forward application logs from containers to a centralized logging service.
- Fluent Bit runs on each EKS node.
- Collects logs from stdout/stderr of pods.
- Forwards logs to destinations like CloudWatch Logs or Kinesis Firehose.
Memory trick: Fluent Bit is the reliable 'log truck' on every EKS node, picking up logs from all containers and driving them to CloudWatch.
EventBridge for CloudFormation Monitoring
Flip cardUsing Amazon EventBridge to monitor AWS CloudTrail events related to CloudFormation stack operations for real-time alerting and automated responses.
- Listens for specific CloudTrail API calls.
- Can filter events based on criteria.
- Triggers targets like Lambda, SNS, SQS for actions.
Memory trick: EventBridge listens to CloudTrail events about CloudFormation, then rings the alarm.
EC2 Network Isolation
Flip cardThe process of immediately restricting network access to a potentially compromised EC2 instance to prevent further malicious activity while preserving its state for investigation.
- Primary method is security group modification.
- Aims to block all ingress/egress traffic.
- Preserves instance state for forensic analysis.
Memory trick: Security Groups are your first line of defense for network isolation.
Isolated Forensic VPC
Flip cardAn AWS VPC specifically designed with high network isolation (private subnets, no internet gateway, VPC endpoints) to securely house forensic analysis tools and evidence, preventing unauthorized egress or ingress.
- Uses private subnets exclusively.
- No Internet Gateway for outbound internet access.
- VPC Endpoints for controlled AWS service communication.
- Ensures evidence integrity and isolation.
Memory trick: Private subnets and VPC endpoints: your forensic no-fly zone.
VPC Traffic Mirroring for Forensics
Flip cardA VPC feature that allows copying network traffic from an Elastic Network Interface (ENI) to a target ENI, enabling full packet capture and deep forensic analysis without impacting the source instance.
- Provides full packet capture (payloads).
- Non-intrusive to the source instance.
- Traffic sent to a dedicated analysis instance.
- Ideal for deep network protocol inspection.
Memory trick: Traffic Mirroring: your forensic traffic cop, copying everything.
CloudTrail AssumeRole Tracing
Flip cardUsing AWS CloudTrail logs to trace the assumption of IAM roles and subsequent actions performed with those temporary credentials, vital for identifying insider threats or unauthorized access via roles.
- CloudTrail logs 'AssumeRole' events.
- Subsequent API calls link to the assumed role session.
- Provides a forensic trail for role-based access.
Memory trick: CloudTrail is your detective for role-playing in AWS.
CloudTrail Event History
Flip cardA feature in the AWS Management Console that displays a record of the past 90 days of management events and data events (if configured) in your AWS account.
- Provides a quick overview of recent API activity.
- Allows filtering by event name, user, resource type, etc.
- Useful for immediate incident investigation.
Memory trick: For quick checks, Event History is your instant replay.
AWS WAF Rate-Based Rule
Flip cardAn AWS WAF rule that allows you to specify the number of requests that are allowed from a single IP address within a 5-minute period. If the request rate exceeds the threshold, WAF takes the specified action (e.g., block).
- Mitigates Layer 7 DDoS attacks.
- Blocks IP addresses exceeding a request threshold.
- Operates at the application layer.
Memory trick: WAF's rate rules are your bouncer for web traffic.
S3 Versioning for Recovery
Flip cardS3 Versioning keeps multiple versions of an object in the same bucket, allowing for recovery from unintended deletions or modifications by retrieving a previous version.
- Protects against accidental overwrites and deletions.
- Enables quick rollback to a previous state.
- Each write operation creates a new object version.
Memory trick: Versioning is your time machine for S3 objects.
AWS EC2 Dedicated Hosts
Flip cardAmazon EC2 Dedicated Hosts are physical servers with EC2 instance capacity fully dedicated to your use. This allows you to use your existing server-bound software licenses and addresses stringent compliance requirements.
- Provides complete physical isolation from other AWS accounts.
- Suitable for compliance needs and specific licensing models.
- You control instance placement on a specific host.
- Can be purchased On-Demand or as Reserved Instances.
Memory trick: Dedicated Hosts are like reserving a private island for your application's servers, no one else can land there.
CloudTrail Lake for Forensics
Flip cardA managed data lake for CloudTrail events, providing immutable storage and SQL-like query capabilities for deep forensic analysis and security investigations over extended periods.
- Immutable storage of CloudTrail events.
- Advanced SQL-like querying for detailed analysis.
- Ideal for long-term forensic timelines and security investigations.
Memory trick: CloudTrail Lake is your forensic magnifying glass for root activity.
Lambda Version Rollback
Flip cardUtilizing AWS Lambda's versioning feature to quickly revert a function's code to a previous, known good state after a suspected compromise or unauthorized modification.
- Lambda automatically saves versions of code.
- Allows immediate rollback to any published version.
- Minimizes downtime during recovery.
Memory trick: Lambda versions are your quick-travel time machine for code.
SCP for Regional Network Lockdown
Flip cardUsing AWS Organizations Service Control Policies (SCPs) to enforce a preventative, broad denial of all network-related AWS API actions within a specific AWS Region for an account or Organizational Unit.
- Applies at the API level, preventing actions.
- Effective across all AWS services in the scope.
- Ideal for broad, preventative containment strategies.
Memory trick: SCPs are the regional border patrol for your AWS accounts.
RDS Forensic Snapshot
Flip cardCreating a manual snapshot of an Amazon RDS instance and restoring it to a new, isolated instance for forensic analysis, preserving the original evidence and avoiding production impact.
- Creates an immutable point-in-time copy.
- Allows analysis in an isolated environment.
- Preserves original evidence without impacting production.
Memory trick: Snapshot and restore: your RDS forensic photocopy.
IoT Device Revocation
Flip cardThe process of immediately revoking an AWS IoT device's authorization to connect to AWS IoT Core and perform actions, typically by detaching and revoking its X.509 certificate.
- Uses X.509 certificates for authentication.
- Certificates are attached to IoT policies.
- Detaching and revoking the certificate is the most effective revocation method.
Memory trick: Certificates are the keys; detach and revoke to lock the device out.