---
tags:
- cloud
- l1
- flashcard-deck
- aws-security
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [AWS IAM](../../../../library/portal/topics.md) | **Domain:** Cloud
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
aws-security/021054911ff6	aws-security	medium	aws, iam	What security tools AWS IAM provides?	* IAM Credentials Report: lists all the account users and the status of their credentials\n* IAM Access Advisor: Shows service permissions granted to a user and information on when he accessed these services the last time\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/018-what-security-tools-aws-iam-provides.txt
aws-security/0453a477d2c2	aws-security	easy	aws, acm	What is AWS ACM (Certificate Manager) and how does it manage TLS certificates?	"Amazon definition: ""AWS Certificate Manager is a service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources.""\n\nLearn more [here](https://aws.amazon.com/certificate-manager)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/229-what-is-aws-acm.txt
aws-security/0635d8e27a0e	aws-security	hard	aws, iam, scp	What are Service Control Policies and to what service they belong?	"AWS organizations service and the definition by Amazon: ""SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization’s access control guidelines.""\n\nLearn more [here](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/346-what-are-service-control-policies-and-to-what-serv.txt
aws-security/0c95bf65d2f4	aws-security	medium	aws, config, scp	Which service would you use for centrally manage billing, control access, compliance, and security across multiple AWS accounts?	AWS Organizations\n\nRemember: AWS security services layered defense: IAM (identity), VPC/SG (network), KMS (encryption), GuardDuty (threat detection), CloudTrail (audit), Config (compliance).\n\nGotcha: the root account is the most powerful and most dangerous. Enable MFA, create an admin IAM user, and lock away root credentials.	projects/knowledge/interview/aws/285-which-service-would-you-use-for-centrally-manage-b.txt
aws-security/15f8e2809fca	aws-security	easy	aws, kms	What is AWS Key Management Service (KMS)?	"AWS definition: ""KMS makes it easy for you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications.""\nMore on KMS [here](https://aws.amazon.com/kms)\n\nRemember: KMS = Key Management Service. Manages encryption keys for S3, EBS, RDS, etc. Envelope encryption: KMS key encrypts a data key, data key encrypts your data."	projects/knowledge/interview/aws/223-what-is-aws-key-management-service-kms.txt
aws-security/1b0690a6baf0	aws-security	medium	aws, cloudtrail	What would you use to check why certain EC2 instances were terminated?	AWS CloudTrail — it logs every API call made in your account (who, what, when, from where), so you can audit actions like instance terminations, identify the IAM principal responsible, and feed events into SIEM or alerting tools.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/277-what-would-you-use-to-check-why-certain-ec2-instan.txt
aws-security/202b0f39f2ed	aws-security	easy	aws, iam, security	What is AWS IAM and how does it manage access to AWS resources?	AWS Identity and Access Management (IAM) is the service for managing access to AWS resources. It allows you to create users, groups, and roles, and define permissions through policies to securely control who can do what on which resources.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/468-what-is-iam.txt
aws-security/24c825ff5f15	aws-security	medium	aws, guardduty	Which service would you use for monitoring malicious activity and unauthorized behavior in regards to AWS accounts and workloads?	Amazon GuardDuty\n\nRemember: AWS security services layered defense: IAM (identity), VPC/SG (network), KMS (encryption), GuardDuty (threat detection), CloudTrail (audit), Config (compliance).\n\nGotcha: the root account is the most powerful and most dangerous. Enable MFA, create an admin IAM user, and lock away root credentials.	projects/knowledge/interview/aws/284-which-service-would-you-use-for-monitoring-malicio.txt
aws-security/294d6481d29a	aws-security	easy	aws, scp	What is AWS Service Catalog?	"Amazon definition: ""AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS.""\n\nLearn more [here](https://aws.amazon.com/servicecatalog)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/375-what-is-aws-service-catalog.txt
aws-security/30a57fcf7761	aws-security	medium	aws, inspector	Which service would you use for performing security assessment?	AWS Inspector — an automated vulnerability management service that continuously scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, producing prioritized findings.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/288-which-service-would-you-use-for-performing-securit.txt
aws-security/3439e7c564ca	aws-security	easy	aws, cloudhsm, kms	What is AWS CloudHSM?	"Amazon definition: ""AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud.""\n\nLearn more [here](https://aws.amazon.com/cloudhsm)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/222-what-is-aws-cloudhsm.txt
aws-security/352a62aa7e3f	aws-security	medium	aws, iam	What are components of IAM ?	* Users: Individuals needing access to AWS.\n* Groups: Collections of users with the same permissions.\n* Roles: Define a set of permissions for making AWS service requests.\n* Policies: Define permissions and attach them to users, groups, or roles.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/452-what-are-components-of-iam.txt
aws-security/4676ff73c33b	aws-security	hard	aws, iam	What is trust relationship in context with IAM ?	Trust relationship is like a handshake between different identities (services or users) in your office. It defines which accounts or services are allowed to assume a particular IAM role.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/411-what-is-trust-relationship-in-context-with-iam.txt
aws-security/475e7fb3d3f6	aws-security	medium	aws, iam	What is AWS IAM? Explain IAM Roles and Policies.	* IAM (Identity and Access Management): It's used to control access to AWS services and resources. \n* IAM Roles: Define a set of permissions for making AWS service requests. They're used to grant specific permissions to entities that you trust. \n* IAM Policies: These are documents that define permissions. They specify what actions are allowed or denied and on what resources.\n\nRemember: roles = temporary credentials via STS AssumeRole. Use for EC2 instances, Lambda, cross-account access. No long-lived access keys.	projects/knowledge/interview/aws/426-what-is-aws-iam-explain-iam-roles-and-policies.txt
aws-security/4d4483f13368	aws-security	medium	aws, waf	Which service would you use for web application protection?	AWS WAF (Web Application Firewall). It filters HTTP/S traffic at the edge using rules for SQL injection, XSS, rate limiting, and IP reputation — attached to ALB, CloudFront, or API Gateway.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/286-which-service-would-you-use-for-web-application-pr.txt
aws-security/4ff21fb43786	aws-security	medium	aws, iam	What permissions does a new user have?	Only a login access.\n\nRemember: AWS security services layered defense: IAM (identity), VPC/SG (network), KMS (encryption), GuardDuty (threat detection), CloudTrail (audit), Config (compliance).\n\nGotcha: the root account is the most powerful and most dangerous. Enable MFA, create an admin IAM user, and lock away root credentials.	projects/knowledge/interview/aws/009-what-permissions-does-a-new-user-have.txt
aws-security/52ac7ad51cce	aws-security	easy	aws, config	What is AWS Artifact?	"AWS definition: ""AWS Artifact is your go-to, central resource for compliance-related information that matters to you. It provides on-demand access to AWS’ security and compliance reports and select online agreements.""\n\nRead more about it [here](https://aws.amazon.com/artifact)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/218-what-is-aws-artifact.txt
aws-security/5a954ece1ddd	aws-security	medium	aws, iam	What statements AWS IAM policies are consist of?	* Sid: identifier of the statement (optional)\n* Effect: allow or deny access\n* Action: list of actions (to deny or allow)\n* Resource: a list of resources to which the actions are applied\n* Principal: role or account or user to which to apply the policy\n* Condition: conditions to determine when the policy is applied (optional)\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers.	projects/knowledge/interview/aws/016-what-statements-aws-iam-policies-are-consist-of.txt
aws-security/5bcf9a395630	aws-security	hard	aws, inspector	what is AWS inspector ? How does it work ?	Inspector is like a security guard that checks for any weaknesses or problems in your office building's security system. It looks for possible entry points for intruders and suggests ways to strengthen security. Over here It's a service that identifies security vulnerabilities within AWS resources.\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers.	projects/knowledge/interview/aws/416-what-is-aws-inspector-how-does-it-work.txt
aws-security/5f9e1030620d	aws-security	medium	aws, shield	True or False? DDoS attack is an example of allowed penetration testing activity	False. DDoS attacks are explicitly prohibited, even in penetration testing. AWS allows authorized pen testing on specific services (EC2, RDS, Lambda, etc.) but never DDoS.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/226-true-or-false-ddos-attack-is-an-example-of-allowed.txt
aws-security/6199cae6d15d	aws-security	hard	aws, cloudhsm, kms	How does AWS KMS (Key Management Service) work?	AWS KMS: It's a service for managing cryptographic keys. It uses Hardware Security Modules (HSM) to protect your keys and offers secure key creation, storage, and management.\n\nRemember: KMS = Key Management Service. Manages encryption keys for S3, EBS, RDS, etc. Envelope encryption: KMS key encrypts a data key, data key encrypts your data.	projects/knowledge/interview/aws/432-how-does-aws-kms-key-management-service-work.txt
aws-security/61d6bf635ad3	aws-security	easy	aws, scp	"What is ""AWS Organizations""?"	"AWS definition: ""AWS Organizations helps you centrally govern your environment as you grow and scale your workloads on AWS.""\n\nRead more on Organizations [here](https://aws.amazon.com/organizations)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/355-what-is-aws-organizations.txt
aws-security/64020150c01b	aws-security	hard	aws, iam, well-architected	What is the AWS Well-Architected Framework and its importance?	The AWS Well-Architected Framework provides best practices across six pillars:\n\n1. **Operational Excellence**: Automate changes, respond to events, define standards\n2. **Security**: Protect data, systems, and assets. IAM, encryption, detection\n3. **Reliability**: Recover from failures, meet demand. Multi-AZ, auto-scaling\n4. **Performance Efficiency**: Use resources efficiently. Right-size, monitor\n5. **Cost Optimization**: Avoid unnecessary costs. Reserved instances, right-sizing\n6. **Sustainability**: Minimize environmental impact\n\nUse the Well-Architected Tool in AWS Console to review workloads against these pillars.\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers.	projects/knowledge/interview/aws/438-what-is-the-aws-well-architected-framework-and-its.txt
aws-security/647177cabd95	aws-security	medium	aws, iam	True or False? AWS Access Key is a type of MFA device used for AWS resources protection	False. Security key is an example of an MFA device.\n\nRemember: MFA = something you know (password) + something you have (device). Enable on root account first, then all IAM users with console access.	projects/knowledge/interview/aws/227-true-or-false-aws-access-key-is-a-type-of-mfa-devi.txt
aws-security/67bcda71a3f1	aws-security	medium	aws, iam, scp	True or False? When creating an AWS account, root account is created by default. This is the recommended account to use and share in your organization	False. Instead of using the root account, you should be creating users and use them.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/006-true-or-false-when-creating-an-aws-account-root-ac.txt
aws-security/6e7c159414d0	aws-security	easy	aws, iam	What is Amazon Cloud Directory?	"Amazon definition: ""Amazon Cloud Directory is a highly available multi-tenant directory-based store in AWS. These directories scale automatically to hundreds of millions of objects as needed for applications.""\n\nLearn more [here](https://docs.aws.amazon.com/clouddirectory/latest/developerguide/what_is_cloud_directory.html)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/369-what-is-amazon-cloud-directory.txt
aws-security/7135fd1fda84	aws-security	medium	aws, iam, scp	What's an OU in regards to AWS Organizations?'	"OU (Organizational Units) is a way to group multiple accounts together so you can treat them as a single unit.\n\nBy default there is the ""Root"" OU created in AWS Organizations.\n\nMost of the time OUs are based on functions or common set of controls.\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers."	projects/knowledge/interview/aws/356-whats-an-ou-in-regards-to-aws-organizations.txt
aws-security/757f1251829a	aws-security	hard	aws, iam	How to secure instances in AWS?	"* Instance IAM roles should have minimal permissions needed. You don't want an instance-level incident to become an account-level incident\n  * Use ""AWS System Manager Session Manager"" for SSH\n  * Using latest OS images with your instances\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/217-how-to-secure-instances-in-aws.txt
aws-security/7c024ac30be1	aws-security	hard	aws, config, well-architected	"Explain ""Shared Controls"" in regards to the shared responsibility model"	"AWS definition: ""apply to both the infrastructure layer and customer layers, but in completely separate contexts or perspectives. In a shared control, AWS provides the requirements for the infrastructure and the customer must provide their own control implementation within their use of AWS services""\n\nLearn more about it [here](https://aws.amazon.com/compliance/shared-responsibility-model)\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers."	projects/knowledge/interview/aws/216-explain-shared-controls-in-regards-to-the-shared-r.txt
aws-security/7fea5852e30f	aws-security	hard	aws, iam, secrets-manager	Explain the AWS Secrets Manager and its role in security.	Secrets Manager: It's a service for managing sensitive information such as passwords, API keys, and other secrets. \nSecurity Role: It helps protect sensitive data by controlling access and enabling rotation of secrets for enhanced security. projects/knowledge/interview/aws/449-explain-the-aws-secrets-manager-and-its-role-in-se.txt\n\nRemember: Secrets Manager = automatic secret rotation + retrieval via API. Supports RDS credentials, API keys, and custom secrets. Costs $0.40/secret/month.	
aws-security/89adbf6c3af9	aws-security	easy	aws, scp	What is the AWS Cloud Adoption Framework (CAF)?	"Amazon definition: ""AWS Professional Services created the AWS Cloud Adoption Framework (AWS CAF) to help organizations design and travel an accelerated path to successful cloud adoption. ""\n\nLearn more [here](https://aws.amazon.com/professional-services/CAF)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/376-what-is-aws-caf.txt
aws-security/8a30cb7e9199	aws-security	hard	aws, iam	What are some best practices regarding IAM in AWS?	"* Delete root account access keys and don't use root account regularly\n* Create IAM user for any physical user. Don't share users.\n* Apply ""least privilege principle"": give users only the permissions they need, nothing more than that.\n* Set up MFA and consider enforcing using it\n* Make use of groups to assign permissions ( user -> group -> permissions )\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers."	projects/knowledge/interview/aws/008-what-are-some-best-practices-regarding-iam-in-aws.txt
aws-security/8cd61f237802	aws-security	easy	aws, cloudtrail, config	What is AWS CloudTrail?	"AWS definition: ""AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account.""\n\nRead more on CloudTrail [here](https://aws.amazon.com/cloudtrail)\n\nRemember: CloudTrail logs all AWS API calls — the 'security camera' for your AWS account. Enable in all regions, send to a centralized S3 bucket with Object Lock for tamper resistance."	projects/knowledge/interview/aws/345-what-is-aws-cloudtrail.txt
aws-security/93e5ccfaf3b5	aws-security	medium	aws, iam	Which tool would you use to optimize user permissions by identifying which services he doesn't regularly (or at all) access?	IAM Access Advisor\n\nRemember: AWS security services layered defense: IAM (identity), VPC/SG (network), KMS (encryption), GuardDuty (threat detection), CloudTrail (audit), Config (compliance).\n\nGotcha: the root account is the most powerful and most dangerous. Enable MFA, create an admin IAM user, and lock away root credentials.	projects/knowledge/interview/aws/019-which-tool-would-you-use-to-optimize-user-permissi.txt
aws-security/9528b8ce8226	aws-security	hard	aws, config, control-tower	what is AWS control tower ?	Think of Control Tower as the manager of all your office buildings (AWS accounts). It helps set up and govern multiple accounts following security best practices and compliance requirements. It's a service that sets up and governs a secure, multi-account AWS environment.\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers.	projects/knowledge/interview/aws/418-what-is-aws-control-tower.txt
aws-security/958b87558bea	aws-security	medium	aws, iam	True or False? Users in AWS IAM, can belong only to a single group	False. Users can belong to multiple groups.\n\nRemember: AWS security services layered defense: IAM (identity), VPC/SG (network), KMS (encryption), GuardDuty (threat detection), CloudTrail (audit), Config (compliance).\n\nGotcha: the root account is the most powerful and most dangerous. Enable MFA, create an admin IAM user, and lock away root credentials.	projects/knowledge/interview/aws/007-true-or-false-users-in-aws-iam-can-belong-only-to-.txt
aws-security/98dc6acfa258	aws-security	easy	aws, iam	What is AWS Acceptable Use Policy?	It describes prohibited uses of the web services offered by AWS.\nMore on AWS Acceptable Use Policy [here](https://aws.amazon.com/aup)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/224-what-is-aws-acceptable-use-policy.txt
aws-security/9b056840b1bc	aws-security	hard	aws, iam	How does assume role works ?	Assume role is when one identity temporarily wears another identity’s hat to access specific resources, with permission. It's used to temporarily grant permissions to an IAM user, role, or AWS service.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/412-how-does-assume-role-works.txt
aws-security/9c203ba57d1c	aws-security	medium	aws, iam	True or False? EC2 is a regional service	True. As opposed to IAM for example, which is a global service, EC2 is a regional service.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/021-true-or-false-ec2-is-a-regional-service.txt
aws-security/9e3ccd00b6e5	aws-security	medium	aws, cognito, iam	Using which service, can you add user sign-up, sign-in and access control to mobile and web apps?	Amazon Cognito. It provides user pools (sign-up/sign-in, MFA, password policies) and identity pools (federated access to AWS resources via temporary credentials).\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/269-using-which-service-can-you-add-user-sign-up-sign-.txt
aws-security/a333c5fd62ca	aws-security	medium	aws, cognito	Which service would you use to add access control (or sign-up, sign-in forms) to your web/mobile apps?	Amazon Cognito — a managed identity service that provides sign-up, sign-in, and access control for web and mobile apps. It supports social identity providers, SAML/OIDC federation, and built-in MFA.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/291-which-service-would-you-use-to-add-access-control-.txt
aws-security/a6bad815017d	aws-security	medium	aws, config	For what use cases, EC2 dedicated hosts are useful for?	* Compliance needs\n* When the software license is complex (Bring Your Own License) and doesn't support cloud or multi-tenants\n* Regulatory requirements\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/067-for-what-use-cases-ec2-dedicated-hosts-are-useful-.txt
aws-security/b47b4e583a1c	aws-security	easy	aws, shield	What is AWS Shield and how does it protect against DDoS attacks?	"AWS definition: ""AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.""\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/221-what-is-aws-shield.txt
aws-security/ba95f35d17fc	aws-security	medium	aws, config	What considerations to take when choosing an AWS region for running a new application?	* Services Availability: not all service (and all their features) are available in every region\n* Reduced latency: deploy application in a region that is close to customers\n* Compliance: some countries have more strict rules and requirements such as making sure the data stays within the borders of the country or the region. In that case, only specific region can be used for running the application\n* Pricing: the pricing might not be consistent across regions so, the price for the same service in different regions might be different.	projects/knowledge/interview/aws/004-what-considerations-to-take-when-choosing-an-aws-r.txt
aws-security/bfc26f8955fd	aws-security	easy	aws, iam	What is IAM? What are some of its features?	In short, it's used for managing users, groups, access policies & roles\nFull explanation can be found [here](https://aws.amazon.com/iam)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/005-what-is-iam-what-are-some-of-its-features.txt
aws-security/c8dbc33c40a7	aws-security	medium	aws, iam	True or False? If a user in AWS is using password for authenticating, he doesn't needs to enable MFA	False(!). MFA is a great additional security layer to use for authentication.\n\nRemember: MFA = something you know (password) + something you have (device). Enable on root account first, then all IAM users with console access.	projects/knowledge/interview/aws/010-true-or-false-if-a-user-in-aws-is-using-password-f.txt
aws-security/c9f7c100eaca	aws-security	easy	aws, config, iam, well-architected	What is the shared responsibility model? What AWS is responsible for and what the user is responsible for based on the shared responsibility model?	The shared responsibility model defines what the customer is responsible for and what AWS is responsible for.\n\nMore on the shared responsibility model [here](https://aws.amazon.com/compliance/shared-responsibility-model)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/214-what-is-the-shared-responsibility-model-what-aws-i.txt
aws-security/cbc2420e70e6	aws-security	hard	aws, cloudtrail, config, iam	Explain AWS CloudTrail and its role in AWS security.	CloudTrail: It's a service for logging and monitoring AWS API calls for auditing and security analysis. \nRole in Security: CloudTrail provides a record of actions taken by a user, role, or an AWS service for security and compliance needs. projects/knowledge/interview/aws/442-explain-aws-cloudtrail-and-its-role-in-aws-securit.txt\n\nRemember: CloudTrail logs all AWS API calls — the 'security camera' for your AWS account. Enable in all regions, send to a centralized S3 bucket with Object Lock for tamper resistance.	
aws-security/cbc2e450d3e3	aws-security	hard	aws, inspector, security-hub	What is securityHub ? How does it work ?	SecurityHub is like a supervisor overlooking security measures across your office buildings (AWS accounts). It collects and prioritizes security findings to help you manage and improve security. It provides a comprehensive view of the security state of AWS resources. Majorly when you enable AWS inspector, it sends data to securityHub automatically.\n\nGotcha: security group rules are additive (allow-only). To deny specific traffic, use NACLs at the subnet level. This distinction trips up many AWS newcomers.	projects/knowledge/interview/aws/417-what-is-securityhub-how-does-it-work.txt
aws-security/d0ac861a2ebb	aws-security	medium	aws, iam	What are policies in Kubernetes/OPA and how do they enforce governance?	Policies documents used to give permissions as to what a user, group or role are able to do. Their format is JSON.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/013-what-are-policies.txt
aws-security/d5dd6c3c6657	aws-security	easy	aws, cognito, iam	What is Amazon Cognito?	"Amazon definition: ""Amazon Cognito handles user authentication and authorization for your web and mobile apps.""\n\nLearn more [here](https://docs.aws.amazon.com/cognito/index.html)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/228-what-is-amazon-cognito.txt
aws-security/da048de31210	aws-security	easy	aws, security	"What is ""IAM""?"	Identity and Access Management, used to control access to resources.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/470-iam.txt
aws-security/dbb420b95c78	aws-security	medium	aws, shield	Which service would you use if you need managed DDOS protection?	AWS Shield. Standard tier is free and protects against common L3/L4 DDoS. Advanced ($3k/mo) adds 24/7 DDoS Response Team, cost protection, and enhanced detection for L7.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/294-which-service-would-you-use-if-you-need-managed-dd.txt
aws-security/e3fdaae77b86	aws-security	easy	aws, cloudtrail, config	What is AWS Config and how does it track resource compliance?	"Amazon definition: ""AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources.""\n\nLearn more [here](https://aws.amazon.com/config)\n\nRemember: AWS Config continuously evaluates resource configurations against rules. Detects drift and non-compliance. Use conformance packs for frameworks like CIS, PCI-DSS."	projects/knowledge/interview/aws/364-what-is-aws-config.txt
aws-security/e465df559924	aws-security	hard	aws, config, iam	You try to run EC2 commands in an EC2 instance you've just created but it fails due to missing credentials. What would you do?	DO NOT configure AWS credentials on the instance (this means anyone else in your account would be able to use and see your credentials). \nThe best practice is to attach an IAM role with sufficient permissions (like `IAMReadOnlyAccess`)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/078-you-try-to-run-ec2-commands-in-an-ec2-instance-you.txt
aws-security/f16211193f82	aws-security	medium	aws, config	What type of autoscaling policies are there in AWS ?	* *Target Tracking*: Scales based on predefined metrics to maintain a target value.\n* *Step Scaling*: Scales based on configured steps with different scaling adjustments.\n* *Simple/Manual Scaling*: Allows fixed scaling actions manually.\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies.	projects/knowledge/interview/aws/450-what-type-of-autoscaling-policies-are-there-in-aws.txt
aws-security/f1d28509a964	aws-security	easy	aws, config, inspector	What is AWS Inspector?	"AWS definition: ""Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.""""\n\nLearn more [here](https://aws.amazon.com/inspector)\n\nRemember: AWS follows the shared responsibility model: AWS secures the infrastructure; you secure your configurations, data, and access policies."	projects/knowledge/interview/aws/219-what-is-aws-inspector.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [AWS IAM](../../../../library/topics/aws-iam/index.md) (Topic Pack, L1) — AWS IAM

<!-- wiki:related:end -->
