AWS GuardDuty
AWS Inspector
AWS Trusted Advisor
AWS Config
AWS Certificate Manager (ACM)
AWS Secrets Manager
AWS Resource Account Manager (RAM)
AWS Personal Health Dashboard
- AWS outages
AWS CloudHSM
AWS Shield
AWS SAM (Serverless Application Model)
AWS Systems Manager
AWS CloudFormation
CloudFormation Stacksets
AWS Athena supports SSE and Client Side encryption on S3
Yes… you can read and write using encryption
Run single jobs that span multiple EC2 instances. Can run large scale, tightly coupled, HPC, app and distributed GPU model.
AWS Batch
AWS Tool to display current service limits?
AWS Trusted Advisor
Can you use CloudHSM to distribute encryption keys?
No. Used for mgt and storage not for distribution
How can you Connect ec2 app in private subnet to API gateway and ensure no traffic goes over inet
Use an interface endpoint with private link. “Private API”
Does aws allow pen testing?
Yes. For some resources without prior approval
SCPs do not affect service linked role
True
SCPs affect all users and roles in attached accounts including the root user?
True
Can you attach identity based policies to resources
No
AWS service that allows rules to filter web traffic based on conditions that include IP addy, http headers and body, custom urls, or location
AWS WAF