Term for a single local account in which I must assign unique credentials for
IAM User
This service is AWS' primary storage service which offers OBJECT bases storage
Simple Storage Service (S3)
This service acts as the bare network infrastructure boundary. Within this service, you can deploy additional resources such as compute instances
VPC
Service that records all management and data plane events within AWS
CloudTrail
Term used for a collection of local accounts that will all share the same permissions as the permissions are assigned to the body, and not the individual
IAM Group
This service offers BLOCK storage and is attached to compute instances
Elastic Block Storage (EBS)
STATELESS firewall most commonly used to control access to subnets
Network Access Control List (NACL)
I will use this service to see what required patches / vulnerabilities are on my compute instances
By default, CloudTrail logs will be readily available in the event history for how many days?
90 days
IAM entity I will use if I want to avoid provisioning unique credentials
IAM Role
This storage acts as Network File Storage and can be used simultaneously by multiple compute instances
Elastic File Storage (EFS)
Stateful firewall most commonly used to protect compute instances
Security Groups
I will use this service to store and maintain my container images
Elastic Container Registry (ECR)
Service which will record all service configurations which helps me track and audit configurations over a pre-defined time period
AWS Config
Service Control Policies (SCPs) / Permission Boundary
This service is AWS' core offering which allows the automatic implementation and scaling of relational database servers
Relational Database Service (RDS)
This component of AWS WAF offers additional layer 7 protections, specifically against DDoS attacks
AWS Shield / AWS Shield Advanced
Alternative to creating SSH keys in order to access my EC2 instances
EC2 Instance Connect / Session Manager
CloudWatch Events was renamed to this. It is a place where I can aggregate logs from CloudTrail and create response actions
EventBridge
AWS Security Token Service (AWS STS)
This service is a fully managed proprietary NoSQL database offered by Amazon.com as part of the Amazon Web Services portfolio
DynamoDB
Two types of VPC endpoints used to securely and privately connect to AWS resources / other VPCs
Interface and Gateway
The IP address I will use to connect to my instances' metadata service
169.254.169.254
This is AWS' version of a proprietary CSPM AND name one rules package that it uses
AWS SecurityHub / AWS Best Practices and/or CIS