certslothcertsloth
SAP-C02/Topic 24

AWS / Professional

Security & Encryption

6 min read5 recall promptsReviewed 2026-10-10

Memory hook: Protect the connection, the stored data, the permission to use it and the evidence of misuse separately.

Must remember

Encryption and key control

  • TLS protects transit; encryption at rest protects stored data. Neither prevents an already-authorized compromised application from reading plaintext. Authentication, authorization, secret handling and monitoring remain necessary.
  • KMS: AWS-owned keys are managed within services; AWS-managed keys are visible in your account but have service-controlled administration; customer-managed keys provide your own policy/lifecycle control. Symmetric encryption, asymmetric operations and HMAC keys solve different cryptographic tasks.
  • A KMS key policy is central to authorization. IAM permissions alone are not a universal substitute for a suitable key policy. Supported rotation keeps older material available for decrypting existing ciphertext; rotating a key does not automatically re-encrypt every stored object.
  • Multi-Region KMS keys share related key material, enabling supported regional cryptographic use, but policies, grants, aliases and lifecycle remain regional decisions. Creating a replica does not copy every administrative setting or automatically replicate application data.
  • Encrypted snapshot/AMI sharing needs resource permissions and appropriate customer-key access for the recipient. S3 replication of SSE-KMS objects needs explicit replication configuration, source decryption and destination encryption permissions with the correct destination key. A generic S3 copy policy is insufficient.
  • CloudHSM provides dedicated hardware security modules and more direct cryptographic control, with greater administration/capacity responsibility. Choose it for a requirement that specifically needs that control or interface; ordinary managed encryption requirements often fit KMS better.

Configuration, secrets and certificates

  • Parameter Store provides hierarchical configuration, Standard/Advanced tiers and KMS-backed SecureString. Secrets Manager supplies secret versions, supported rotation workflows and optional regional replication. Rotation requires the relevant integration and permissions; merely storing a secret does not rotate a database password.
  • Applications should retrieve secrets using a role, with caching and refresh behavior appropriate to rotation. Terraform's sensitive flag controls some display behavior; it does not encrypt local state or prevent an authorized reader from recovering supplied values.
  • ACM manages certificates. An ALB uses a certificate in its Region; CloudFront's ACM certificate must be in us-east-1. Validate domain ownership and consider the whole client-to-edge-to-origin TLS path rather than securing only one connection.
  • AWS Private CA is an adjacent distinction: it issues certificates for a private trust hierarchy, such as internal services. Private certificates are not automatically trusted by public browsers, and a private CA introduces charges. It is not separately named in the current in-scope list, unlike ACM.

Filtering, detection and investigation

  • WAF filters supported HTTP requests with web ACLs, IP sets and rules, including rate-based rules. Shield Standard supplies baseline DDoS protection; Shield Advanced adds paid capabilities. Firewall Manager centrally manages supported security policies across an organization. None replaces least privilege or secure application logic.
  • DDoS resilience combines edge absorption, caching, rate controls, suitable scaling and protected origins. Keep expensive origin work from being the first line of defense. Network Firewall handles network inspection; WAF targets supported web request paths.
  • GuardDuty detects suspicious activity. Inspector finds vulnerabilities in supported workloads. Macie discovers sensitive data in S3. Select based on the finding needed, not the generic word “security.”
  • Security Hub, including its security-posture capabilities, consolidates findings and evaluates supported security controls. Detective helps investigate relationships and activity surrounding suspicious behavior. Aggregating a finding, investigating it and automatically remediating it are different steps.
  • Artifact provides AWS compliance reports and agreements. It does not certify your application's configuration. Audit Manager can collect and organize evidence for assessments; it is useful adjacent context rather than an explicitly named service in the current list, and it does not replace the auditor's judgment.
  • Modern Inspector remains relevant; Inspector Classic is retired. Consult service status for generation-specific dates. Never infer that a current service is unavailable solely because an older namesake ended support.

Operational boundaries

  • Shared responsibility changes with the service: AWS operates underlying infrastructure, while you still control data classification, identities and workload configuration. Managing EC2 also includes guest-OS responsibilities that a fully managed service takes off your hands.
  • Choose retention deliberately. Customer-key deletion has a waiting period; secret recovery settings and replicas affect deletion; immutable compliance retention can intentionally prevent removal. Such retention is valuable when required by a real workload and incompatible with this disposable lab's default.

Choose under exam pressure

Clue in the requirement Choose or investigate
Managed encryption with controlled key permissions Customer-managed KMS key and appropriate policies
Dedicated HSM control or required cryptographic integration CloudHSM
Automatically rotate supported database credentials Secrets Manager with configured rotation
Sensitive information found in S3 objects Macie
Vulnerable supported packages or images Modern Inspector
Suspicious account/workload activity GuardDuty
Consolidated findings and posture checks Security Hub
Investigate connected security events and entities Detective
Obtain AWS's compliance documentation Artifact
Block abusive HTTP requests at CloudFront WAF rules/IP sets/rate controls

Traps

  • Encryption is not authorization, and a resource share without key access can remain unusable.
  • A managed certificate is not a domain registration; a private CA certificate is not automatically public trust.
  • A detection service is not automatically a remediation engine. Enabling broad scans or organization controls can change account behavior and spending.

Active recall

1. A shared encrypted snapshot is visible to another account but cannot be restored. What missing permission should you investigate?

Investigate access to the appropriate customer-managed KMS key as well as snapshot permissions. Permission to see the snapshot does not necessarily permit decryption or use of its encrypted storage.

2. A customer requires direct control of dedicated cryptographic hardware. Why might KMS alone not satisfy the requirement?

The requirement points to CloudHSM's dedicated HSM model and supported cryptographic interfaces. KMS reduces key-management operations but is a different control model; choose based on the actual compliance/interface requirement.

3. One team needs vulnerability findings, another needs suspicious-activity alerts, and a third needs sensitive S3 data discovery. Which services fit?

Modern Inspector, GuardDuty and Macie respectively. They assess different evidence; choosing one because it is a security service does not cover all three use cases.

4. An auditor requests AWS compliance reports while developers need evidence about their own controls. Are these the same artifact?

No. Artifact supplies AWS reports and agreements. Workload evidence must reflect the customer's own controls; tools such as Audit Manager can help organize it, but neither service automatically certifies the application.

5. Terraform redacts a database password in a plan. Does that satisfy encryption, rotation and state-security requirements?

No. Redaction is presentation. Protect state, use a suitable secret store and runtime permissions, configure rotation where required, and secure connections independently.

Terraform anchor: Explicit secret/key lifecycle settings and narrow policies make teardown reviewable; local state still needs protection even when values are marked sensitive.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.