Design Secure Architectures 16
- Q35: Shield Your Public App from Large-Scale DDoS Attacks
- Q34: Track Config Changes and API Calls with Config + CloudTrail
- Q31: Auto-Detect Untagged AWS Resources with Config Rules
- Q37: Secure, Keyless EC2 Access with Systems Manager Session Manager
- Q36: Encrypt S3 Data in Two Regions with One Multi-Region KMS Key
- Q28: Single Sign-On Across All Organization Accounts, Using On-Premises Active Directory
- Q27: Sharing a CloudWatch Dashboard With Someone Who Has No AWS Account
- Q26: Catching Unauthorized Configuration Changes on S3 Buckets
- Q19: Routing All Inbound Web Traffic Through a Third-Party Firewall Appliance
- Q17: The Right Way for EC2 Instances to Access an S3 Bucket
- Q16: Visualizing a Data Lake With Tiered Access for Management vs Everyone Else
- Q15: Replicating an On-Premises Inspection Server's Traffic Filtering in AWS
- Q13: Rotating RDS Credentials Across Multiple Regions With the Least Overhead
- Q11: Minimizing Operational Overhead of EC2-to-Aurora Credential Management
- Q4: Give an EC2 Instance Private Access to S3 With No Internet Connectivity
- Q3: Restrict an S3 Bucket to Only Accounts Inside Your AWS Organization