7 of 7 cards free · no sign-in needed
1. Enable MFA on root account 2. Create individual IAM users 3. Use groups to assign permissions 4. Apply least-privilege principle 5. Use IAM roles for applications on EC2 6. Never share credentials
Explicit Deny > Allow. If any policy has an explicit Deny, access is denied regardless of other Allows. If no explicit Allow exists, access is implicitly denied. AWS root account has unrestricted access.
Centrally manage multiple AWS accounts. Apply Service Control Policies (SCPs) to restrict what accounts can do. Consolidated billing — single payment for all accounts. Create organisational units (OUs) for grouping.
Managed DDoS protection. Shield Standard: automatically protects all AWS customers at no extra cost (layer 3/4 protection). Shield Advanced: enhanced protection + WAF credits + 24/7 DDoS Response Team (DRT) + cost protection.
Stores and automatically rotates secrets (database passwords, API keys) on a defined schedule. Applications retrieve secrets via API — no hardcoded credentials. Integrates with RDS, Redshift, DocumentDB.
Automated security assessment service for EC2 instances and Lambda functions. Scans for software vulnerabilities and unintended network exposure. Provides a prioritised findings list with remediation guidance.
Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.
After sign-in: Space flip · ←→ navigate · K knew it · S skip