← AWS Certified Solutions Architect - Associate
AWS · objective · 30% of the exam
Design Secure Architectures — AWS Certified Solutions Architect - Associate
The official AWS documentation our Design Secure Architectures practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — How to use trust policies with IAM roles | AWS Security Blog
This is referred to as the cross-account confused deputy problem. This section shows you a way to mitigate this risk.
-
Amazon Web Services — Security best practices in IAM - AWS Identity and Access Management
such as for WordPress plugins. In these situations, use IAM user long-term access keys for that workload to authenticate to AWS
-
Amazon Web Services — Custom network ACLs for your VPC - Amazon Virtual Private Cloud
If the packet had been destined for port 139 (NetBIOS), it wouldn't match any of the numbered rules, so the * rule for IPv4 traffic
-
Amazon Web Services — Features | AWS Key Management Service (KMS) | Amazon Web Services (AWS)
you can create a KMS key in an AWS KMS external key store (XKS), where all keys are generated and stored in an external key
-
Amazon Web Services — Intelligent Threat Detection – Amazon GuardDuty Features – AWS
Runtime Monitoring analyzes runtime events in Amazon EKS, Amazon ECS, and Amazon EC2 workloads to detect suspicious or potentially malicious activities at the operating system
-
Amazon Web Services — AWS Identity and Access Management (IAM) Best Practices - Amazon Web Services
use permissions boundaries , which use a managed policy to set the maximum permissions that an identity-based policy can grant to an IAM role
-
Amazon Web Services — Encrypting Data-at-Rest and Data-in-Transit - Logical Separation on AWS
AWS simplifies the process of generating, distributing, and rotating digital certificates with AWS Certificate Manager (ACM) . ACM offers publicly trusted certificates at no cost
-
Amazon Web Services — Manage access keys for IAM users - AWS Identity and Access Management
Do NOT use your account's root credentials to create access keys.
-
Amazon Web Services — AWS WAF or AWS Shield? - AWS WAF or AWS Shield?
Use AWS Shield to turn on always-on detection and automatic mitigations, and protect against common DDoS attacks at the network and transport layers.
-
Amazon Web Services — Default network ACL for a VPC - Amazon Virtual Private Cloud
A default network ACL is configured to allow all traffic to flow in and out of the subnets with which it is associated.
-
Amazon Web Services — Rotate AWS Secrets Manager secrets - AWS Secrets Manager
Managed rotation – For most managed secrets , you use managed rotation, where the service configures and manages rotation for you. Managed rotation doesn't use