AWS Security

Build practical AWS security skills from security foundations through identity, encryption, detection, infrastructure protection, data protection, compliance, incident response, application security, and production security architecture.

Topic 1: Security Foundations and Shared Responsibility

Understand AWS shared responsibility, defense in depth, threat modeling, and secure-by-design principles.

Topic 2: Account and Root User Security

Secure AWS accounts, root credentials, alternate contacts, and emergency access.

Topic 3: Identity Federation and IAM Identity Center

Use centralized workforce identities and temporary AWS access instead of long-lived IAM user credentials.

Topic 4: Temporary Credentials and AWS STS

Use AWS Security Token Service for short-lived credentials and controlled role assumption.

Topic 5: IAM Policy Evaluation

Understand identity policies, resource policies, explicit deny, boundaries, and policy evaluation logic.

Topic 6: IAM Access Analyzer

Identify unintended public and cross-account access and validate IAM policies.

Topic 7: Permission Boundaries and Guardrails

Use permission boundaries, SCPs, and policy conditions as layered authorization guardrails.

Topic 8: Encryption Fundamentals

Understand encryption at rest, encryption in transit, envelope encryption, and key ownership.

Topic 9: AWS KMS

Create, manage, rotate, authorize, and audit customer managed KMS keys.

Topic 10: Secrets Manager

Store, retrieve, rotate, and audit application secrets using AWS Secrets Manager.

Topic 11: AWS Certificate Manager

Manage TLS certificates for AWS services and understand public and private certificate use.

Topic 12: CloudTrail and Audit Logging

Capture AWS API activity for security investigation, governance, and forensic analysis.

Topic 13: CloudTrail Lake

Use CloudTrail Lake for searchable event data stores and security investigations.

Topic 14: AWS Config

Record resource configurations, evaluate rules, and track configuration compliance.

Topic 15: Amazon GuardDuty

Detect threats and suspicious activity across AWS accounts and workloads.

Topic 16: AWS Security Hub

Centralize, prioritize, and respond to security findings and posture signals.

Topic 17: Amazon Inspector

Scan supported compute and application artifacts for vulnerabilities and exposures.

Topic 18: Amazon Macie

Discover and protect sensitive data stored in Amazon S3.

Topic 19: Amazon Detective

Investigate security findings by analyzing relationships and activity across AWS resources.

Topic 20: AWS WAF

Protect HTTP and HTTPS applications with web application firewall rules and managed protections.

Topic 21: AWS Shield

Understand DDoS protection and the role of AWS Shield Standard and Advanced.

Topic 22: AWS Network Firewall

Protect VPC traffic using managed stateful and stateless firewall policies.

Topic 23: AWS Firewall Manager

Centralize firewall and security policy management across AWS Organizations.

Topic 24: VPC Security Controls

Apply security groups, network ACLs, VPC endpoints, flow logs, and network analysis as layered controls.

Topic 25: Amazon S3 Security

Secure S3 buckets using Block Public Access, bucket policies, encryption, versioning, and logging.

Topic 26: EC2 Security

Secure EC2 instances with IAM roles, IMDSv2, patching, security groups, and host hardening.

Topic 27: RDS and Database Security

Protect managed databases with network isolation, encryption, IAM authentication where supported, and secrets management.

Topic 28: Container and Serverless Security

Apply IAM, secrets, image, runtime, and network controls to ECS, EKS, and Lambda workloads.

Topic 29: Data Protection and Classification

Classify data, choose controls by sensitivity, and minimize unnecessary access to sensitive information.

Topic 30: Logging, Monitoring, and Security Alerts

Build centralized security logging and alerting using CloudTrail, CloudWatch, Config, and service findings.

Topic 31: Security Automation and Event-Driven Response

Automate detection, enrichment, containment, and remediation of security events.

Topic 32: Incident Response Fundamentals

Prepare, detect, contain, eradicate, recover, and learn from AWS security incidents.

Topic 33: Forensics and Evidence Preservation

Collect AWS evidence safely while preserving integrity, timelines, and chain of custody.

Topic 34: Security Compliance and Governance

Understand compliance frameworks, AWS Artifact, audit evidence, controls, and continuous compliance.

Topic 35: AWS Security Lake

Understand centralized security data collection and normalization for security analytics.

Topic 36: Security Architecture with AWS Organizations

Combine accounts, OUs, SCPs, delegated security services, and centralized findings.

Topic 37: Cross-Account Resource Sharing Security

Secure cross-account access using resource policies, IAM roles, AWS RAM, and trust boundaries.

Topic 38: Application Security on AWS

Integrate secure coding, dependency management, secrets, authentication, authorization, and testing into AWS workloads.

Topic 39: Security Operations with Systems Manager

Use Systems Manager for secure access, patching, inventory, and operational security controls.

Topic 40: Security Testing and Validation

Validate security controls using policy simulation, reachability analysis, configuration checks, and controlled testing.

Topic 41: Security Cost and Operational Trade-offs

Balance security controls, operational complexity, performance, and cost.

Topic 42: AWS Well-Architected Security Pillar

Apply the AWS Well-Architected Security Pillar to review and improve workload security.

Topic 43: Production AWS Security Architecture Capstone

Design a multi-account, defense-in-depth AWS security architecture and demonstrate detection and response.

Course content is locked. Please purchase or enroll to access all lessons and topics.
Course Progress
0%

Enroll to start learning!

Course Stats
  • Total Topics 43
  • Total Lessons 43
  • Total Sessions 43
  • Total Notes 43
  • Estimated Time 54.300000000000004 hours
Program Enrollment Only

This course is only available through program enrollment.

View Program: AWS