What does AWS CloudHSM stand for?
AWS managed dedicated hardware security model (HSM) in AWS Cloud
What is the primary function of AWS CloudHSM?
Enables you to securely generate, store, and manage your own cryptographic keys
Which industry-standard APIs can integrate with AWS CloudHSM?
Fill in the blank: AWS CloudHSM allows you to store _______ key material in a custom key store.
non-extractable
What is a use case for AWS CloudHSM?
Use KMS to create a CMKs in a custom key store and store non-extractable key material in AWS CloudHSM to get full control on encryption keys
In AWS Systems Manager, was does Session Manager replace
The need for Bastions to access instances in private subnet
What is AWS Shield?
Managed Distributed Denial of Service protection service
What type of attacks does AWS Shield protect against?
Layer 3 and 4
What are the tiers of service for AWS Shield
What is AWS WAF
Web application firewall, protects web applications against common web exploits
What attacks does AWS WAF protect against
Layer 7, like SQL injection and Cross-site scripting
Where can you deploy AWS WAF
What does AWS Firewall Manager do?
Centralizes configuration and management of AWS WAF rules, AWS Shield Advanced, Network Firewall rules, and Route 53 DNS firewall rules across accounts and resources in AWS Organization
What is a use case for AWS Firewall Manager
Meet Gov regulations to deploy AWS WAF rule to block traffic from embargoed countries across acounts and resources
What is AWS Guard Duty
How is ECS with Fargate charged
On vCPU and memory resources that the container requests. Charged rounded up per the nearest second
What is Babelfish
Allows Aurora PostgreSQL to understand T-SQL and SQL Server wire protocol, enabling applications to communicate with Aurora using SQL Server-style queries with minimal code changes
Using an autoscaling group, how can you make sure 10 instances are up at a specific time of day/month
Setup a scheduled action that kicks off at the designated time and set the desired capacity of the instances to 10
With Amazon API Gateway and Websocket APIs, which is Stateful and which is stateless
Gateway - Stateless
Websocket - Stateful
By default, FIFO queues (SQS) support how many messages per second
300
With SQS FIFO, what is the max number of messages you can batch per second
10
How might you restrict traffic by country for an EC2
AWS web application firewall with ALB. Geo match Conditions in WAF can restrict traffic based on location
T/F Cloudfront can have a custom origin pointing to the DNS record of a website on Route 53
False, It can have a custom origin pointing to on-premise servers
In S3, when you apply a retention period to an object version, what do you specify
Retain Until Date