← AWS Certified Security - Specialty
AWS · objective · 18% of the exam
Infrastructure Security — AWS Certified Security - Specialty
The official AWS documentation our Infrastructure Security practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — How patch baseline rules work on Linux-based systems - AWS Systems Manager
Because it's not possible to reliably determine the release dates of update packages for Ubuntu Server, the auto-approval options aren't supported for this operating system.
-
Amazon Web Services — Infrastructure security in Amazon VPC - Amazon Virtual Private Cloud
Return traffic Automatically allowed (stateful) Must be explicitly allowed (stateless)
-
Amazon Web Services — Scanning Amazon EC2 instances with Amazon Inspector - Amazon Inspector
The following endpoints are required: com.amazonaws. region .ec2messages com.amazonaws. region .inspector2-telemetry com.amazonaws. region .s3 com.amazonaws. region .ssm com.amazonaws. region .ssmmessages
-
Amazon Web Services — AWS Systems Manager Patch Manager - AWS Systems Manager
Patch Manager doesn't derive severity levels from third-party sources, such as the Common Vulnerability Scoring System (CVSS), or from metrics released by the National Vulnerability
-
Amazon Web Services — AWS WAF or AWS Shield? - AWS WAF or AWS Shield?
AWS WAF defends against common web exploits such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).
-
Amazon Web Services — Control subnet traffic with network access control lists - Amazon Virtual Private Cloud
NACLs are stateless , which means that information about previously sent or received traffic is not saved.
-
Amazon Web Services — Control traffic to your AWS resources using security groups - Amazon Virtual Private Cloud
When you add inbound rules for ports 22 (SSH) or 3389 (RDP) so that you can access your EC2 instances, authorize only specific IP address
-
Amazon Web Services — Filter network traffic using AWS Network Firewall - Amazon Virtual Private Cloud
You can define stateless rule groups to inspect each network packet in isolation. Stateless rule groups are similar in behavior and use to Amazon VPC
-
Amazon Web Services — Security groups and network ACLs (BP5) - AWS Best Practices for DDoS Resiliency
you could provide the Elastic Load Balancer access to the required target listener ports using a Security Group rule that allows access to 0.0.0.0/0 (to