Review questions
- In the Shared Responsibility Model presented by AWS for IaaS, who is responsible for operating system security and patching?
- What are the major differences between a user and a role from the choices presented here?
a. A role can be assumed by multiple principals; a user cannot be assumed.
b. A role uses long-term credentials.
c. A role can be part of a group.
d. A role does not use long-term credentials.
- Which comes first: authorization or authentication?
- Which native service in AWS that stores secrets offers automatic secret rotation?
- A company wants to extend their current AD into the AWS cloud but doesn't want to manage more servers. Which service is the best choice for them?
a. AWS Simple Directory Service
b. AWS Cognito
c. AWS User Pools
d. AWS AD Connector