← AWS Certified Developer - Associate
AWS · objective · 26% of the exam
Security — AWS Certified Developer - Associate
The official AWS documentation our Security practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — How to use trust policies with IAM roles | AWS Security Blog
The suffix :root in the policy’s Principal element equates to the principals in the account, not the root user of that account.
-
Amazon Web Services — Security best practices in IAM - AWS Identity and Access Management
there is no need to distribute long lived credentials for an IAM user to your workloads running on AWS
-
Amazon Web Services — Encryption - AWS Prescriptive Guidance
The use of a KMS key to encrypt data removes some of the burden of managing encryption libraries. Additionally, KMS keys cannot be exported from
-
Amazon Web Services — AWS WAF or AWS Shield? - AWS WAF or AWS Shield?
Use AWS WAF to create customizable web security rules to filter malicious traffic, protect against attacks such as SQL injection and cross-site scripting (XSS)
-
Amazon Web Services — Infrastructure security in Amazon VPC - Amazon Virtual Private Cloud
Use security groups as the primary mechanism for controlling network access to your VPCs.
-
Amazon Web Services — Intelligent Threat Detection – Amazon GuardDuty Features – AWS
you can automate the response workflow by using EventBridge as an event source to invoke a Lambda function
-
Amazon Web Services — Manage access keys for IAM users - AWS Identity and Access Management
The secret access key can be retrieved only at the time you create it. If you lose your secret access key, you must delete the
-
Amazon Web Services — Create a network ACL for your VPC - Amazon Virtual Private Cloud
you must add a new rule with the new rule
-
Amazon Web Services — DynamoDB encryption at rest - Amazon DynamoDB
AWS owned key – Default encryption type. The key is owned by DynamoDB (no additional charge).
-
Amazon Web Services — GuardDuty S3 Protection - Amazon GuardDuty
S3 Protection helps you detect potential security risks for data, such as data exfiltration and destruction, in your Amazon Simple Storage Service (Amazon S3) buckets.
-
Amazon Web Services — Rotate AWS Secrets Manager secrets - AWS Secrets Manager
Rotation by Lambda function – For other types of secrets, Secrets Manager rotation uses a Lambda function to update the secret and the database or