In: Computer Science
Summarize the built-in security features and tools used in modern cloud infrastructures. You may select among Amazon AWS, Microsoft Azure and Google Cloud. Use internet resources to answer this question.
Some of the modern cloud infrastructure are Amazon AWS, Microsoft Azure, Google Cloud. Amazon designed their cloud platform infrastructure to be highly available and scalable and also comply with industry standards. Google Cloud Platform security features are among the best on the market, including traditional network security.Azure’s infrastructure is designed from facility to applications for hosting millions of customers simultaneously.
Common Built in security features and tools used in modern cloud infrastructure are-
1. In AWS and Google Cloud, Using Identity and Access Management (IAM), you can create users, groups, and roles, and use permissions to allow and deny their access to AWS resources .24/7/365 operations are performed as device security detection and response from both internal and external threats.Cloud Identity, Cloud Identity-Aware Proxy, and Security Keys are used for IAM in google cloud.
2.Virtual Private Cloud give you complete control over all inbound and outbound network traffic. You can use AWS Direct Connect to establish a private virtual interface between your on-premise network and your Amazon Virtual Private Cloud. In Azure, Mandatory Security training, background checks are performed .
3. AWS provides Data encryption for EBS volumes, S3 buckets, and Relational Database Service (RDS) and Glacier data stores. Data in-transit encrypted communication to and from Google’s public cloud, including layered defense redundancies to protect customers from denial-of-service (DoS) attacks. Also in Microsoft azure Penetration testing, intrusion detection, DDoS, Audits & logging plays a major role. Access Control Lists (ACLs) in AWS work at the network subnet level. Network ACLs can be especially useful in the prevention of DDOS attacks when you have a particular need to blacklist traffic from specific IP addresses.