Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

AWS CERTIFIED ASSOCIATE DEVELOPER EXAMS: INSIGHTFUL A+ QUESTIONS AND ANSWERS

Rating
-
Sold
-
Pages
26
Grade
A+
Uploaded on
22-02-2025
Written in
2024/2025

AWS CERTIFIED ASSOCIATE DEVELOPER EXAMS: INSIGHTFUL A+ QUESTIONS AND ANSWERS Document that formally states one or more permissions. By default a deny all is given. Deny overrides Allow policies IAM Policy IAM Policy Statements 3 Parts: 1) Effect - Allow or Deny 2) Action - What action is allowed or denied 3) Resource - What resource the allow or deny is applied IAM Users Non-explicit deny when new user is created Can configure MFA on a per-user basis IAM Roles Something another entity can "assume", acquires the specific permissions defined by a role Security Token Service (STS) Grants users limited and temporary access to AWS resources. Security Token Service (STS) get-session-token API call return 3 components: 1) Security Token 2) Access Key ID 3) Secret Access Key STS API Calls AssumeRole -Cross-account delegation and federation through custom identity broker AssumeRoleWithWebIdentity -Federation through web-based IdP AssumeRoleWithSAML -Federation through enterprise IdP compatible with SAML 2.0 GetFederationToken -Federation through a custom IdP GetSessionToken -Temp credentials for users in untrusted Environments STS Benefits -No distributing or embedding long-term AWS credentials in app -Grant access without having to create an IAM identity -Since credentials are temporary, there is no need to rotate or revoke When to use STS Identity Federation -Enterprise Identity Federation, Web Based (Google, FB, etc) Roles for cross-account access Roles for services IAM API Keys -Required to make API calls -Only available ONCE - when new user is created or when keys are reissued -AWS will not regenerate the same set of keys -API keys are associated with a user -Roles do not have API keys -Only able to see the Access Key ID, never the secret -NEVER create or store API keys on an EC2 instance Key Management Service (KMS) Managed service to create and control the encryption keys used to encrypt your data KMS Customer Master Keys (CMKs) -Used to encrypt/decrypt up to 4KB of data, and are the primary resource in KMS -CMKs generate, encrypt, decrypt data keys that you use outside of AWS KMS -2 kinds: Customer-managed and AWS-managed Customer-managed CMK CMKs you create, enable/disable, rotate, and manage the policied that allow access to use the CMK AWS-managed CMK -CMKs that are created, managed, and used by AWS services integrated with KMS -Naming convention = aws/service-name i.e. aws/s3 KMS Data Keys -Keys for encrypting large amounts of data or other data encryption keys -CMKs can generate, encrypt, and decrypt data keys -AWS does not manage or store your data keys -KMS cannot use data keys to encrypt data for you KMS Envelope Encryption -Plaintext data is encrypted with a data key -Data keys are encrypted with a key encryption key (KEK) -A KEK may be encrypted by another KEK, but eventually there is a master key (the KMS CMK in this case) that decrypts one or more keys KMS API Actions -Encrypt = Encrypt plaintext using CMK -GenerateDataKey = Uses a CMK to return a plaintext and ciphertext version of a data encryption key -Decrypt = Decrypts ciphertext that was encrypted with the Encrypt, GenerateDataKey, or GenerateDataKeyWithoutPlaintext API actions Amazon Cognito -Single user identity and data synchronization service -Helps manage and sync app data for users across their mobile devices -Create unique identities for users through public login providers (Facebook, google, amazon) and support unathenticated guests -Save any kind of data in the AWS cloud without writing any backend code or managing infrastructure. EC2 Instance Types General Purpose Compute Optimized Memory Optimized Accelerated Computing Storage Optimized

Show more Read less
Institution
Course

Content preview

AWS CERTIFIED ASSOCIATE DEVELOPER EXAMS: INSIGHTFUL A+
QUESTIONS AND ANSWERS
Document that formally states one or more permissions. By default a deny all is
given. Deny overrides Allow policies
IAM Policy
IAM Policy Statements
3 Parts:


1) Effect - Allow or Deny
2) Action - What action is allowed or denied
3) Resource - What resource the allow or deny is applied
IAM Users
Non-explicit deny when new user is created
Can configure MFA on a per-user basis
IAM Roles
Something another entity can "assume", acquires the specific permissions defined by a
role
Security Token Service (STS)
Grants users limited and temporary access to AWS resources.
Security Token Service (STS) get-session-token API call return
3 components:
1) Security Token
2) Access Key ID
3) Secret Access Key
STS API Calls
AssumeRole
-Cross-account delegation and federation through custom identity broker
AssumeRoleWithWebIdentity
-Federation through web-based IdP
AssumeRoleWithSAML
-Federation through enterprise IdP compatible with SAML 2.0

,GetFederationToken
-Federation through a custom IdP
GetSessionToken
-Temp credentials for users in untrusted Environments
STS Benefits
-No distributing or embedding long-term AWS credentials in app
-Grant access without having to create an IAM identity
-Since credentials are temporary, there is no need to rotate or revoke
When to use STS
Identity Federation
-Enterprise Identity Federation, Web Based (Google, FB, etc)
Roles for cross-account access
Roles for services
IAM API Keys
-Required to make API calls
-Only available ONCE - when new user is created or when keys are reissued
-AWS will not regenerate the same set of keys
-API keys are associated with a user
-Roles do not have API keys
-Only able to see the Access Key ID, never the secret
-NEVER create or store API keys on an EC2 instance
Key Management Service (KMS)
Managed service to create and control the encryption keys used to encrypt your data
KMS Customer Master Keys (CMKs)
-Used to encrypt/decrypt up to 4KB of data, and are the primary resource in KMS
-CMKs generate, encrypt, decrypt data keys that you use outside of AWS KMS
-2 kinds: Customer-managed and AWS-managed
Customer-managed CMK
CMKs you create, enable/disable, rotate, and manage the policied that allow access to
use the CMK
AWS-managed CMK

, -CMKs that are created, managed, and used by AWS services integrated with KMS
-Naming convention = aws/service-name i.e. aws/s3
KMS Data Keys
-Keys for encrypting large amounts of data or other data encryption keys
-CMKs can generate, encrypt, and decrypt data keys
-AWS does not manage or store your data keys
-KMS cannot use data keys to encrypt data for you
KMS Envelope Encryption
-Plaintext data is encrypted with a data key
-Data keys are encrypted with a key encryption key (KEK)
-A KEK may be encrypted by another KEK, but eventually there is a master key (the
KMS CMK in this case) that decrypts one or more keys
KMS API Actions
-Encrypt = Encrypt plaintext using CMK
-GenerateDataKey = Uses a CMK to return a plaintext and ciphertext version of a data
encryption key
-Decrypt = Decrypts ciphertext that was encrypted with the Encrypt, GenerateDataKey,
or GenerateDataKeyWithoutPlaintext API actions
Amazon Cognito
-Single user identity and data synchronization service
-Helps manage and sync app data for users across their mobile devices
-Create unique identities for users through public login providers (Facebook, google,
amazon) and support unathenticated guests
-Save any kind of data in the AWS cloud without writing any backend code or managing
infrastructure.
EC2 Instance Types
General Purpose
Compute Optimized
Memory Optimized
Accelerated Computing
Storage Optimized

Written for

Course

Document information

Uploaded on
February 22, 2025
Number of pages
26
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$14.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeSolutions Chamberlain College Of Nursing
Follow You need to be logged in order to follow users or courses
Sold
101
Member since
2 year
Number of followers
9
Documents
13384
Last sold
1 day ago
TOPGRADESOLUTIONS

Here we offer revised study materials to elevate your educational outcomes. We have verified learning materials (Research, Exams Questions and answers, Assignments, notes etc) for different courses guaranteed to boost your academic results. We are dedicated to offering you the best services and you are encouraged to inquire further assistance from our end if need be. Having a wide knowledge in Nursing, trust us to take care of your Academic materials and your remaining duty will just be to Excel. Remember to give us a review, it is key for us to understand our clients satisfaction. We highly appreciate clients who always come back for more of the study content we offer, you are extremely valued. All the best.

Read more Read less
4.9

172 reviews

5
159
4
7
3
5
2
0
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions