Memory hook: CloudWatch observes, CloudTrail records API activity, Config evaluates configuration.
Must remember
- CloudWatch handles operational metrics, logs, dashboards and alarms. CloudTrail records account/API activity for audit. AWS Config records resource configurations and evaluates rules; it is not a replacement for application logs.
- GuardDuty detects suspicious activity from supported telemetry. Inspector finds software vulnerabilities and unintended exposure in supported workloads. Macie discovers sensitive data in S3. Security Hub aggregates and prioritises security findings and posture checks.
- WAF filters application-layer web requests. Shield addresses DDoS protection; Standard and the paid Advanced offering differ. Firewall Manager centrally applies supported security policies across an organisation.
- KMS manages encryption keys. Encryption at rest protects stored data; TLS protects data in transit. Key access, application access and network access all need appropriate controls. ACM manages supported TLS certificates; it does not encrypt a database's stored files.
- AWS Artifact provides AWS compliance reports and agreements. AWS service certification does not certify every workload a customer builds. Evidence, customer controls and data residency still matter.
- Organizations groups accounts and offers consolidated billing and service control policies. SCPs restrict the maximum permissions available to affected accounts; they grant no permissions. Control Tower helps establish and govern a landing zone with controls.
- Trusted Advisor recommends improvements in areas such as cost, security and resilience. AWS Health reports events affecting AWS services or specific account resources. Security documentation, the Security Blog and re:Post support investigation; Marketplace offers third-party tools whose licensing and configuration still need review.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Who changed a resource? | CloudTrail event history or a configured trail. |
| Which buckets contain personal data? | Macie discovery. |
| Keep account configurations within policy | Config rules and organisation governance controls. |
Traps
- GuardDuty findings do not automatically patch software.
- Artifact is evidence about AWS, not an application vulnerability scanner.
- An alarm can notify without preventing spending or damage.
Active recall
1. A team needs a graph of CPU utilisation. Which service?
CloudWatch metrics and dashboards.
2. A team needs to know who deleted a security-group rule. Which service?
CloudTrail.
3. A library contains a known vulnerability. Which service is the closest fit?
Inspector for supported workloads.
4. An SCP allows S3, but the user has no S3 permission. Can the user read a bucket?
No. The SCP is a ceiling, not a grant.
5. Does an AWS compliance report prove customer access policies are correct?
No. Customers must implement and evidence their own controls.