Class Overview
covers fundamental AWS Cloud security concepts, including AWS access control, data encryption methods, and how network access to your AWS infrastructure can be secured. Based on the AWS Shared Security Model, this course teaches where in the AWS Cloud you are responsible for implementing security. You’ll also learn what security-oriented services are available to you, as well as why and how the security services can help meet the security needs of your organization.
This course enables you to dive deep, ask questions, work through solutions, and get feedback from AWS-accredited instructors with deep technical knowledge. This fundamental-level course is part of the AWS Training and Certification Security learning path.
Course Objectives
In this course, you will learn how to:
• Identify security benefits and responsibilities of using the AWS Cloud.
• Describe the access control and management features of AWS.
• Explain the available methods for encrypting data at rest and in transit.
• Describe how to secure network access to your AWS resources.
• Determine which AWS services can be used for monitoring and incident response.
Security Pillar:
-------------------------------------------
AWS Well-Architected Framework
Security Pillar
AWS Well-Architected Tool FAQs
AWS Artifact
AWS Config
AWS IAM
Amazon VPC
AWS WAF
AWS Shield
Amazon Inspector
AWS KMS
AWS Secrets Manager
AWS CloudTrail
Amazon CloudWatch
Amazon EventBridge
AWS System Manager Incident Manager
AWS Lambda
Security of the Cloud:
-------------------------------------------
AWS Data Centers
AWS Regions and Availability Zones
AWS Compliance Center
AWS Compliance Center (Finance)
IAM:
-------------------------------------------
AWS Identity & Access Management
AWS Account Root User
Tasks which need root user credentials
SEC 1 How do you securely operate your workload?
AWS Directory Service
Amazon Cognito
AWS IAM Identity Center
Access policy guidelines
Managing access to your Amazon S3 resources
Protecting data using encryption
Protecting data using client-side encryption
Protecting data using server-side encryption
AWS KMS
AWS Secrets Manager
Amazon Macie
AWS Certificate Manager
AWS Policies and Permissions
Protecting Infrastructure and Data:
-------------------------------------------
Amazon VPC
AWS Networking
Detection and Response:
-------------------------------------------
AWS CloudTrail
Amazon CloudWatch
AWS Trusted Advisor
Amazon EventBridge
AWS Security Hub
Amazon GuardDuty
AWS Systems Manager Incident Manager
Automate incident response
Offline Website Software