From the course: AWS Certified Data Engineer Associate (DEA-C01) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Amazon Redshift security
From the course: AWS Certified Data Engineer Associate (DEA-C01) Cert Prep
Amazon Redshift security
- [Instructor] Like most AWS services, security for your Redshift data warehouse is a shared responsibility. When using Redshift Serverless, you don't need to worry about infrastructure security, but you still need to define user privileges and access. For clusters you also need to configure the infrastructure security using a VPC. So in this lesson, we'll learn about data encryption, user authentication, and infrastructure security for Redshift. In Amazon Redshift, you can enable database encryption for your clusters to help protect data at rest. When you enable encryption for a cluster, the data blocks and system metadata are encrypted for the cluster as well as its snapshots. You can enable encryption when you launch your cluster, or you can modify an encrypted cluster to use an AWS key Management Service or KMS encryption key. When you modify your cluster to enable KMS encryption, Amazon Redshift automatically migrates your data to a new encrypted cluster. Be aware that this…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
-
-
-
-
-
(Locked)
Introduction43s
-
(Locked)
AWS Key Management Service (KMS)4m 19s
-
(Locked)
Virtual private cloud (VPC) overview8m 10s
-
(Locked)
Defining VPC Classless Interdomain Routing (CIDR) blocks6m 26s
-
(Locked)
Hands-on learning: Create a custom VPC10m 16s
-
(Locked)
Security groups and network ACLs10m 48s
-
(Locked)
Hands-on learning: Configure security groups and NACLs10m 11s
-
(Locked)
VPC peering5m 44s
-
(Locked)
Hands-on learning: Configure VPC peering9m 42s
-
VPC endpoints4m 27s
-
(Locked)
Hands-on learning: Create a VPC endpoint9m 27s
-
(Locked)
AWS Systems Manager Parameter Store2m 50s
-
(Locked)
AWS Secrets Manager2m 26s
-
(Locked)
Hands-on learning: Work with secrets6m 5s
-
(Locked)
AWS Config2m 47s
-
(Locked)
AWS CloudTrail4m 33s
-
(Locked)
Hands-on learning: Create a CloudTrail trail3m 59s
-
(Locked)
AWS CloudTrail Lake1m 43s
-
(Locked)
Hands-on learning: Query CloudTrail Lake events5m 18s
-
(Locked)
Amazon RDS security4m 6s
-
(Locked)
Amazon Redshift security5m 15s
-
(Locked)
Database audit logging1m 38s
-
(Locked)
AWS Audit Manager1m 35s
-
(Locked)
Amazon Macie3m 4s
-
(Locked)