AWS Security
Build practical AWS security skills from security foundations through identity, encryption, detection, infrastructure protection, data protection, compliance, incident response, application security, and production security architecture.
Topic 1: Security Foundations and Shared Responsibility
Understand AWS shared responsibility, defense in depth, threat modeling, and secure-by-design principles.
Topic 2: Account and Root User Security
Secure AWS accounts, root credentials, alternate contacts, and emergency access.
Topic 3: Identity Federation and IAM Identity Center
Use centralized workforce identities and temporary AWS access instead of long-lived IAM user credentials.
Topic 4: Temporary Credentials and AWS STS
Use AWS Security Token Service for short-lived credentials and controlled role assumption.
Topic 5: IAM Policy Evaluation
Understand identity policies, resource policies, explicit deny, boundaries, and policy evaluation logic.
Topic 6: IAM Access Analyzer
Identify unintended public and cross-account access and validate IAM policies.
Topic 7: Permission Boundaries and Guardrails
Use permission boundaries, SCPs, and policy conditions as layered authorization guardrails.
Topic 8: Encryption Fundamentals
Understand encryption at rest, encryption in transit, envelope encryption, and key ownership.
Topic 9: AWS KMS
Create, manage, rotate, authorize, and audit customer managed KMS keys.
Topic 10: Secrets Manager
Store, retrieve, rotate, and audit application secrets using AWS Secrets Manager.
Topic 11: AWS Certificate Manager
Manage TLS certificates for AWS services and understand public and private certificate use.
Topic 12: CloudTrail and Audit Logging
Capture AWS API activity for security investigation, governance, and forensic analysis.
Topic 13: CloudTrail Lake
Use CloudTrail Lake for searchable event data stores and security investigations.
Topic 14: AWS Config
Record resource configurations, evaluate rules, and track configuration compliance.
Topic 15: Amazon GuardDuty
Detect threats and suspicious activity across AWS accounts and workloads.
Topic 16: AWS Security Hub
Centralize, prioritize, and respond to security findings and posture signals.
Topic 17: Amazon Inspector
Scan supported compute and application artifacts for vulnerabilities and exposures.
Topic 18: Amazon Macie
Discover and protect sensitive data stored in Amazon S3.
Topic 19: Amazon Detective
Investigate security findings by analyzing relationships and activity across AWS resources.
Topic 20: AWS WAF
Protect HTTP and HTTPS applications with web application firewall rules and managed protections.
Topic 21: AWS Shield
Understand DDoS protection and the role of AWS Shield Standard and Advanced.
Topic 22: AWS Network Firewall
Protect VPC traffic using managed stateful and stateless firewall policies.
Topic 23: AWS Firewall Manager
Centralize firewall and security policy management across AWS Organizations.
Topic 24: VPC Security Controls
Apply security groups, network ACLs, VPC endpoints, flow logs, and network analysis as layered controls.
Topic 25: Amazon S3 Security
Secure S3 buckets using Block Public Access, bucket policies, encryption, versioning, and logging.
Topic 26: EC2 Security
Secure EC2 instances with IAM roles, IMDSv2, patching, security groups, and host hardening.
Topic 27: RDS and Database Security
Protect managed databases with network isolation, encryption, IAM authentication where supported, and secrets management.
Topic 28: Container and Serverless Security
Apply IAM, secrets, image, runtime, and network controls to ECS, EKS, and Lambda workloads.
Topic 29: Data Protection and Classification
Classify data, choose controls by sensitivity, and minimize unnecessary access to sensitive information.
Topic 30: Logging, Monitoring, and Security Alerts
Build centralized security logging and alerting using CloudTrail, CloudWatch, Config, and service findings.
Topic 31: Security Automation and Event-Driven Response
Automate detection, enrichment, containment, and remediation of security events.
Topic 32: Incident Response Fundamentals
Prepare, detect, contain, eradicate, recover, and learn from AWS security incidents.
Topic 33: Forensics and Evidence Preservation
Collect AWS evidence safely while preserving integrity, timelines, and chain of custody.
Topic 34: Security Compliance and Governance
Understand compliance frameworks, AWS Artifact, audit evidence, controls, and continuous compliance.
Topic 35: AWS Security Lake
Understand centralized security data collection and normalization for security analytics.
Topic 36: Security Architecture with AWS Organizations
Combine accounts, OUs, SCPs, delegated security services, and centralized findings.
Topic 37: Cross-Account Resource Sharing Security
Secure cross-account access using resource policies, IAM roles, AWS RAM, and trust boundaries.
Topic 38: Application Security on AWS
Integrate secure coding, dependency management, secrets, authentication, authorization, and testing into AWS workloads.
Topic 39: Security Operations with Systems Manager
Use Systems Manager for secure access, patching, inventory, and operational security controls.
Topic 40: Security Testing and Validation
Validate security controls using policy simulation, reachability analysis, configuration checks, and controlled testing.
Topic 41: Security Cost and Operational Trade-offs
Balance security controls, operational complexity, performance, and cost.
Topic 42: AWS Well-Architected Security Pillar
Apply the AWS Well-Architected Security Pillar to review and improve workload security.
Topic 43: Production AWS Security Architecture Capstone
Design a multi-account, defense-in-depth AWS security architecture and demonstrate detection and response.
Course Progress
Enroll to start learning!
Course Stats
- Total Topics 43
- Total Lessons 43
- Total Sessions 43
- Total Notes 43
- Estimated Time 54.300000000000004 hours
This course is only available through program enrollment.
View Program: AWS