Instiq

3Infrastructure Security

Practice questions →Glossary →
  • 3.1Protecting the Network Perimeter

    Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.

  • 3.2Edge Protection and DDoS Mitigation

    Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.

  • 3.3Protecting Compute and Endpoints

    Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.