certslothcertsloth
← SCS-C03 overview

Security Specialty / STUDY TOOLS

SCS-C03 quick review

Reviewed 10 October 2026 · Security Specialty

Memory hook: Identity, evidence, containment, key access and policy ceilings.

Detection 16%; incident response 14%; infrastructure 18%; identity 20%; data protection 18%; governance 14%.

Use this as a final revision pass after the chapters. Each task below maps to the published exam outline; the outline itself is not an exhaustive list of possible questions. Recheck the official guide for your booked exam version, especially beta releases.

Must remember by exam objective

1.1 — Design and implement monitoring and alerting solutions for an AWS account or organization

  • Choose signals deliberately: GuardDuty detects threats, Inspector assesses supported vulnerabilities, Macie finds sensitive S3 data and Security Hub consolidates findings/posture. CloudWatch alarms/EventBridge route actionable events. Define severity, ownership and response, suppress carefully and monitor the detection pipeline itself.

1.2 — Design and implement logging solutions

  • Organization trails can centralize CloudTrail activity; enable required data events explicitly. Protect log destinations with restrictive policies, encryption, retention, integrity validation and separate administration. Application, flow, DNS and API logs answer different questions; preserve actor and correlation information.

1.3 — Troubleshoot security monitoring, logging, and alerting solutions

  • When logs/findings disappear check service/Region coverage, event selectors, organization membership, target/KMS permissions, filters, retention and subscriptions. A quiet dashboard is not proof of safety. Distinguish event creation, delivery, ingestion, rule match and notification as separate stages.

2.1 — Design and test an incident response plan

  • Prepare owners, severity, escalation, communications, evidence handling, scoped response roles and forensic environments. Exercise realistic runbooks and service constraints before an incident. Define containment and recovery criteria that preserve necessary evidence while limiting harm.

2.2 — Respond to security events

  • Contain compromised principals/sessions and workloads, preserve logs/disks/volatile evidence as required, investigate scope/persistence, eradicate and recover from a trusted state. Deleting a long-lived key may not invalidate issued sessions. Termination can destroy evidence; capture deliberately and document custody.

3.1 — Design, implement, and troubleshoot security controls for network edge services

  • WAF filters application requests; Shield addresses DDoS; CloudFront/origin controls reduce direct exposure; Global Accelerator serves supported network routing. Protect both viewer and origin TLS and authorization. Rate limits/IP rules must account for actual client-IP forwarding and trusted proxies.

3.2 — Design, implement, and troubleshoot security controls for compute workloads

  • Separate task/runtime, execution/image-pull and infrastructure roles. Restrict metadata access, patch/scan supported OS/images/dependencies and protect secrets. Lambda/containers need scoped invocation/network/data access. For AI, treat prompts/retrieval as untrusted and authorize tool actions outside the model.

3.3 — Design and troubleshoot network security controls

  • SGs statefully permit; NACLs statelessly allow/deny. PrivateLink exposes supported services without broad routing. Network Firewall/appliances need symmetric, non-bypassable routes. Include IPv6, DNS and egress controls; private placement alone neither encrypts nor authorizes traffic.

4.1 — Design, implement, and troubleshoot authentication strategies

  • Federation and IAM Identity Center support workforce access; roles provide temporary workload credentials. Configure trust, MFA/session controls and an audited emergency path. Cognito user authentication and AWS credential federation solve separate application needs. Verify issuer/audience and actual assumed identity.

4.2 — Design, implement, and troubleshoot authorization strategies

  • Evaluate caller, action, resource and condition context across identity/resource policy, session policy, boundary, SCP/RCP and key policy where applicable. Explicit deny prevails. Cross-account assumptions need trust and caller permission. External IDs mitigate confused-deputy risk, not authentication alone; control iam:PassRole and boundary removal.

5.1 — Design and implement controls for data in transit

  • TLS protects sessions, certificates bind names and must validate chain/hostname/expiry. ACM automates supported certificate lifecycle; certificate Region must fit the consuming service. Private connectivity and dedicated DX do not alone guarantee encryption. Choose TLS/IPsec/MACsec from the actual protected segment.

5.2 — Design and implement controls for data at rest

  • KMS authorization includes key policy/grants and relevant identity permissions; encrypted cross-account data needs both data and key access. Customer-managed, AWS-managed and AWS-owned keys differ in control/sharing. Rotation retains old material for decryption and does not rewrite all stored objects; multi-Region keys retain regional policy/configuration concerns.

5.3 — Design and implement controls to protect confidential data, credentials, secrets, and cryptographic key materials

  • Classify sensitive data; use managed secrets, supported rotation, limited export/use and deliberate lifecycle. Parameter Store SecureString serves encrypted configuration. Protect backups, memory, logs and embeddings as well as sources. Key deletion can make retained ciphertext unrecoverable; retention locks/legal holds have distinct bypass/deletion semantics.

6.1 — Develop a strategy to centrally deploy and manage AWS accounts

  • Organizations/OUs establish account boundaries; SCPs constrain affected identities without granting access; resource control policies constrain supported resource access. Control Tower/delegated administrators establish baselines with scoped authority. Test region-deny/global-service exceptions and preserve emergency access.

6.2 — Implement a secure and consistent deployment strategy for cloud resources

  • Use reviewed IaC, pipeline roles, policy checks, immutable artifacts and staged deployment. Preventive controls block, detective controls identify and responsive controls repair. Remediation needs approvals/scope/rate limits/idempotency appropriate to consequence; do not create a loop that fights approved deployments.

6.3 — Evaluate the compliance of AWS resources

  • Config rules/aggregators, Security Hub standards, Audit Manager evidence and Artifact reports serve different audit needs. Scope resources/events, protect evidence and document exceptions/ownership. Passing a framework check does not prove every application risk is controlled or every data practice is lawful.

Choose under exam pressure

Deciding clue Recall the distinction
Who changed an IAM policy? CloudTrail with relevant event scope.
Sensitive data in S3? Macie; Inspector instead assesses supported vulnerabilities.
Delegate role creation but limit privilege Boundary plus controls on removal/change and PassRole.
S3 policy permits read, decryption denied Check KMS policy/grants/identity and cross-account support.
Compromised instance holds forensic evidence Isolate and preserve before destructive remediation.

Traps

  • Policy evaluation has same-account resource/role-session nuances; an “intersect every policy” slogan is incomplete.
  • A key administrator is not automatically an authorized decrypt caller.
  • Private networking is not tenant isolation by itself.
  • A service compliance report does not certify the customer application.
  • Changing security-group rules may leave tracked connections alive until timeout; verify existing-flow containment as well as blocking new sessions.

Verification cues

  • For AccessDenied, identify the exact ARN/session, action, resource, request conditions, applicable denies and key/endpoint boundaries.
  • Trace an object-read audit event from selector to protected destination; management logging alone does not capture all object access.
  • Explain how a containment action affects evidence, existing credentials/sessions, network state and later recovery.

Last-pass active recall

1. What does an external ID solve?

It helps a trusted third party distinguish customers and mitigate confused-deputy risk; it is not a password.

2. Does KMS rotation re-encrypt all S3 objects?

No. Rotation and rewriting existing ciphertext are separate operations.

3. Why can deleting one access key be insufficient?

Previously issued temporary sessions or other persistence may remain usable.

4. What does an SCP allow grant?

Nothing by itself; it sets a ceiling for affected permissions.

5. What proves incident recovery?

A trusted restored state, removed persistence, correct access and verified business behavior with continued monitoring.

Sources and version check

The numbered chapters provide worked distinctions and further technical sources. These are original revision notes and original recall scenarios, not real exam questions.

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Monitoring & Audit

Memory hook: Metrics show symptoms, logs explain events, traces follow requests, and audit records identify changes.

Must remember

Separate the evidence questions

  • CloudWatch: how is the workload behaving? Use metrics, logs, dashboards and alarms for operational evidence. CloudTrail: which identity called which API, against what resource and when? AWS Config: what resource configuration existed, and did an evaluated rule consider it compliant?
  • These sources complement each other. A slow API can require a latency alarm, application logs and a trace; identifying an administrator's change requires audit evidence. Check that the needed events, resources and retention were actually configured before promising historical answers.
  • AWS X-Ray follows instrumented requests across services and downstream calls. Its trace map helps find latency, errors and bottlenecks. Traces are not a replacement for every application log or API audit event; instrumentation and sampling affect visibility.

Metrics and logs

  • A metric is a numeric time series identified by namespace, name and dimensions. Choose meaningful statistics and evaluation periods: average latency can conceal slow tail requests, while a total error count without request volume may mislead.
  • Alarms evaluate metric conditions; actions notify or invoke supported responses. Composite alarms combine alarm states to reduce noisy paging. Treat missing data intentionally rather than assuming missing means healthy. Metric streams continuously deliver selected metric updates to downstream consumers.
  • Logs Insights queries log events. Metric filters count matching events into metrics. Subscriptions forward matching logs to supported destinations; export writes log data to S3 for a different processing workflow. These are distinct mechanisms.
  • The CloudWatch agent collects additional guest-OS and application signals. Standard EC2 metrics do not automatically reveal every filesystem or memory measurement.
  • Container Insights and Lambda Insights add workload-specific visibility; Contributor Insights identifies prominent contributors; Application Insights helps correlate application problems. Their scope and collection costs need deliberate configuration.

Events, audit and compliance

  • EventBridge rules match events on buses and deliver them to targets. Scheduler invokes targets on time-based schedules. An archive retains selected events for replay; a replay can repeat a business action, so consumers still need idempotency.
  • A successfully accepted event can fail to match a rule or fail later delivery. Check source/detail pattern, bus, target configuration, resource permissions and retry/dead-letter behavior separately.
  • CloudTrail management events describe control-plane activity; selected data events provide supported resource-level activity. CloudTrail Insights detects unusual supported API activity. A rule reacting to an API call via EventBridge needs the appropriate event path and coverage.
  • Config recording tracks selected resource configurations; rules evaluate compliance. Notifications and remediation are separately configured. A remediation role can mutate resources, so evaluation should not be confused with automatic repair.

Additional published-scope tools

  • Amazon Managed Service for Prometheus stores and queries compatible operational metrics, especially for container workloads using PromQL. Amazon Managed Grafana visualizes metrics, logs and traces from multiple sources. The dashboard layer is different from the metric storage/query layer.
  • AWS Health Dashboard reports AWS service events and account-relevant impacts. Combine it with workload telemetry: a healthy AWS status does not prove your application or configuration is healthy.
  • Keep logs and traces useful: redact sensitive data, set retention, scope collection and correlate request identifiers. Broad logging can create both sensitive-data exposure and substantial ingestion charges.

Choose under exam pressure

Clue in the requirement Choose or investigate
Alert on errors or latency CloudWatch metric alarm with an action
Determine who deleted a database CloudTrail audit events
Review a resource's historical configuration compliance Config history and rule evaluations
Find the slow downstream call in a distributed request X-Ray tracing
Query container metrics using PromQL Managed Service for Prometheus
Visualize several telemetry sources together Managed Grafana
Trigger work for matching application events EventBridge rule and target
Investigate a relevant AWS service disruption AWS Health Dashboard

Traps

  • An alarm with no action is not an email subscription; rule creation alone does not establish every permission needed for delivery.
  • A trace sample or a log metric is not a complete security audit record.
  • A Config rule can report a problem without correcting it. Replaying an event can repeat side effects rather than merely replaying a picture of history.

Practise this topic

02 · IAM Advanced

Memory hook: First identify the caller, then find its grants, its permission ceilings and every applicable explicit deny.

Must remember

Follow the permission decision

  • Identity policies grant actions to users, groups and roles. Permissions boundaries limit the permissions that identity policies can grant. Service control policies (SCPs) set organization-level permission ceilings for affected member accounts. Neither a boundary nor an SCP grants access merely by allowing an action.
  • SCP scope: member-account principals, including the member account's root user, are affected; management-account principals and service-linked roles are not. An account's SCP also does not constrain an external account's principal merely because it accesses that account's resource. Resource-access policies and controls must address that separate boundary.
  • Explicit deny wins. For ordinary identity-policy access, a grant must survive the applicable boundary, session policy and organization restrictions. Do not turn that mnemonic into a universal set-intersection algorithm: resource-policy grants to users, role principals and role-session principals have different evaluation details.
  • Role trust answers who may assume the role; the role's permission policies answer what the resulting session can do. Cross-account assumption normally needs suitable caller authorization and target trust. STS provides temporary credentials rather than a new long-lived access key.
  • A resource-based policy can authorize a supported resource directly; assuming a role changes the effective identity used for subsequent operations. Choose according to the service and access pattern. Cross-account access also requires the applicable permissions on both sides.
  • IAM simulation is useful evidence for supported policy evaluation, but it does not fully test every trust, organization, resource-policy or runtime context. A successful simulation of an action is not proof that MFA-conditioned role assumption will succeed.

Conditions carry request context

  • aws:SourceIp constrains supported source-IP contexts. Calls through services or private endpoints can have different context; a public source-IP restriction is not a universal VPC restriction.
  • aws:RequestedRegion tests the Region of the requested endpoint. Account for global services and cross-Region side effects; it is not automatically a guarantee that all resulting data stays in that Region.
  • aws:PrincipalOrgID constrains supported access by organization membership. It can reduce the need to enumerate account IDs in suitable resource policies, but does not grant every principal the intended action.
  • MFA conditions depend on how credentials and sessions were obtained. Do not assume a federated sign-in with MFA always supplies aws:MultiFactorAuthPresent in subsequent requests. A missing condition key matters to the selected policy operator.
  • Least privilege includes actions, resources and conditions. Keep the operator identity separate from the role being tested so an exercise cannot silently weaken your own account access.

Multi-account and workforce choices

  • Organizations groups accounts; OUs organize accounts for governance; SCPs constrain permissions. Separate production, development and shared services where isolation and governance require it. Organization policies do not replace each account's grants or data policies.
  • IAM Identity Center provides workforce access through permission sets and account assignments, commonly backed by an external identity provider and temporary credentials. Consumer signup belongs to a different pattern, such as Cognito; see application identity.
  • Directory Service: Managed Microsoft AD provides managed AD capabilities and supported trusts; AD Connector proxies authentication to an existing directory; Simple AD supplies a smaller compatible feature set where available. “Already have AD” is a clue to compare integration requirements rather than create another independent user database.
  • AWS Resource Access Manager (RAM) shares supported resources across accounts, organizations/OUs or supported principals. A centrally owned subnet or Transit Gateway can be shared instead of duplicated. Resource sharing does not give participants universal ownership or bypass their IAM restrictions; supported resource types and sharing rules differ.
  • Control Tower establishes governed multi-account landing zones with controls and integrated services. It is broader than one role or SCP. This pack treats Organizations and Control Tower as design concepts and leaves account-wide governance unchanged.

Choose under exam pressure

Clue in the requirement Choose or investigate
Employees need consistent temporary access across accounts Identity Center permission sets and assignments
Developers create roles but must stay inside a maximum scope Permissions boundaries plus controlled delegation
Restrict allowed services across an OU SCPs, alongside actual identity grants
Share an existing supported network resource across accounts RAM
Define who can assume an application role Role trust policy
Existing directory must authenticate supported AWS workloads Compare AD Connector and Managed Microsoft AD capabilities
Build a governed multi-account landing zone Control Tower concept

Traps

  • Adding another Allow cannot override an explicit Deny or a limiting permissions boundary.
  • A role ARN in a trust document is not the same thing as a resource permission granting that role every operation.
  • Organization membership, network origin and MFA are different request properties; one condition does not establish the other two.

Practise this topic

03 · Security & Encryption

Memory hook: Protect the connection, the stored data, the permission to use it and the evidence of misuse separately.

Must remember

Encryption and key control

  • TLS protects transit; encryption at rest protects stored data. Neither prevents an already-authorized compromised application from reading plaintext. Authentication, authorization, secret handling and monitoring remain necessary.
  • KMS: AWS-owned keys are managed within services; AWS-managed keys are visible in your account but have service-controlled administration; customer-managed keys provide your own policy/lifecycle control. Symmetric encryption, asymmetric operations and HMAC keys solve different cryptographic tasks.
  • A KMS key policy is central to authorization. IAM permissions alone are not a universal substitute for a suitable key policy. Supported rotation keeps older material available for decrypting existing ciphertext; rotating a key does not automatically re-encrypt every stored object.
  • Multi-Region KMS keys share related key material, enabling supported regional cryptographic use, but policies, grants, aliases and lifecycle remain regional decisions. Creating a replica does not copy every administrative setting or automatically replicate application data.
  • Encrypted snapshot/AMI sharing needs resource permissions and appropriate customer-key access for the recipient. S3 replication of SSE-KMS objects needs explicit replication configuration, source decryption and destination encryption permissions with the correct destination key. A generic S3 copy policy is insufficient.
  • CloudHSM provides dedicated hardware security modules and more direct cryptographic control, with greater administration/capacity responsibility. Choose it for a requirement that specifically needs that control or interface; ordinary managed encryption requirements often fit KMS better.

Configuration, secrets and certificates

  • Parameter Store provides hierarchical configuration, Standard/Advanced tiers and KMS-backed SecureString. Secrets Manager supplies secret versions, supported rotation workflows and optional regional replication. Rotation requires the relevant integration and permissions; merely storing a secret does not rotate a database password.
  • Applications should retrieve secrets using a role, with caching and refresh behavior appropriate to rotation. Terraform's sensitive flag controls some display behavior; it does not encrypt local state or prevent an authorized reader from recovering supplied values.
  • ACM manages certificates. An ALB uses a certificate in its Region; CloudFront's ACM certificate must be in us-east-1. Validate domain ownership and consider the whole client-to-edge-to-origin TLS path rather than securing only one connection.
  • AWS Private CA is an adjacent distinction: it issues certificates for a private trust hierarchy, such as internal services. Private certificates are not automatically trusted by public browsers, and a private CA introduces charges. It is not separately named in the current in-scope list, unlike ACM.

Filtering, detection and investigation

  • WAF filters supported HTTP requests with web ACLs, IP sets and rules, including rate-based rules. Shield Standard supplies baseline DDoS protection; Shield Advanced adds paid capabilities. Firewall Manager centrally manages supported security policies across an organization. None replaces least privilege or secure application logic.
  • DDoS resilience combines edge absorption, caching, rate controls, suitable scaling and protected origins. Keep expensive origin work from being the first line of defense. Network Firewall handles network inspection; WAF targets supported web request paths.
  • GuardDuty detects suspicious activity. Inspector finds vulnerabilities in supported workloads. Macie discovers sensitive data in S3. Select based on the finding needed, not the generic word “security.”
  • Security Hub, including its security-posture capabilities, consolidates findings and evaluates supported security controls. Detective helps investigate relationships and activity surrounding suspicious behavior. Aggregating a finding, investigating it and automatically remediating it are different steps.
  • Artifact provides AWS compliance reports and agreements. It does not certify your application's configuration. Audit Manager can collect and organize evidence for assessments; it is useful adjacent context rather than an explicitly named service in the current list, and it does not replace the auditor's judgment.
  • Modern Inspector remains relevant; Inspector Classic is retired. Consult service status for generation-specific dates. Never infer that a current service is unavailable solely because an older namesake ended support.

Operational boundaries

  • Shared responsibility changes with the service: AWS operates underlying infrastructure, while you still control data classification, identities and workload configuration. Managing EC2 also includes guest-OS responsibilities that a fully managed service takes off your hands.
  • Choose retention deliberately. Customer-key deletion has a waiting period; secret recovery settings and replicas affect deletion; immutable compliance retention can intentionally prevent removal. Such retention is valuable when required by a real workload and incompatible with this disposable lab's default.

Choose under exam pressure

Clue in the requirement Choose or investigate
Managed encryption with controlled key permissions Customer-managed KMS key and appropriate policies
Dedicated HSM control or required cryptographic integration CloudHSM
Automatically rotate supported database credentials Secrets Manager with configured rotation
Sensitive information found in S3 objects Macie
Vulnerable supported packages or images Modern Inspector
Suspicious account/workload activity GuardDuty
Consolidated findings and posture checks Security Hub
Investigate connected security events and entities Detective
Obtain AWS's compliance documentation Artifact
Block abusive HTTP requests at CloudFront WAF rules/IP sets/rate controls

Traps

  • Encryption is not authorization, and a resource share without key access can remain unusable.
  • A managed certificate is not a domain registration; a private CA certificate is not automatically public trust.
  • A detection service is not automatically a remediation engine. Enabling broad scans or organization controls can change account behavior and spending.

Practise this topic

04 · Networking: VPC

Memory hook: A working connection needs the right address, a forward route, permission and a return path.

Must remember

Addresses and routes come first

  • A VPC is a regional network boundary; a subnet occupies one AZ. Plan nonoverlapping CIDRs before connecting VPCs and on-premises networks. AWS reserves five IPv4 addresses in an ordinary subnet, so a /24 supplies 251 usable IPv4 addresses. Default-VPC conveniences should not be assumed in a custom VPC.
  • A route table selects the most specific matching destination route. A subnet is called public when it has an internet-gateway route, but an IPv4 instance also needs usable public addressing and suitable security rules. A public IP without the route, or the route without the public IP, is insufficient.
  • An internet gateway (IGW) supports the VPC's internet path. A bastion is a deliberate administrative hop; Session Manager can avoid inbound SSH by using the managed agent's outbound service connectivity and IAM permissions.
  • Private addressing does not itself guarantee isolation from every network. Check all routes: peering, transit, VPN and service endpoints may create intentional private connectivity.

Stateful and stateless filters

  • Security groups use stateful allow rules on interfaces/resources. Return traffic for an allowed connection is tracked; there is no explicit SG deny rule. Referencing another SG is useful for tier-to-tier access without maintaining individual IP lists.
  • NACLs apply ordered stateless allow/deny rules at subnet boundaries. Both directions need appropriate rules; HTTPS responses often need outbound ephemeral ports. Lower-numbered matching rules determine the decision, so an earlier deny can defeat a later allow.
  • A permitted filter cannot compensate for a missing route, and a correct route cannot override a denying filter. Trace the actual source/destination seen at each network hop.

Egress and service endpoints

  • NAT instances require operating-system management, routing, security rules and appropriate source/destination-check changes. NAT gateways reduce appliance management; time, processing and associated address charges still matter. NAT permits outbound-initiated connectivity, not unsolicited inbound sessions.
  • The traditional zonal public NAT gateway sits in a public subnet; same-AZ routing with one per required AZ avoids a single-AZ egress dependency. Current AWS also offers regional NAT gateways, which can automatically expand across AZs and do not require a hosting public subnet. Know which mode a question describes; regional mode currently does not provide private NAT. A single regional resource is not a promise of one-AZ pricing.
  • Gateway endpoints for S3 and DynamoDB add route-table targets without an endpoint-hour fee. They are not general transit access for clients in peered VPCs or on-premises networks.
  • Interface endpoints and AWS PrivateLink provide private access to supported services through endpoint networking and DNS, typically using private ENIs and SGs for interface endpoints. They can expose a particular service instead of granting full VPC-to-VPC routing. Hourly/per-AZ and data charges require comparison against the actual traffic pattern.
  • Endpoint policies, where supported, limit use through that endpoint. They do not override missing IAM permissions or a denying bucket/resource policy. Network reachability and API authorization are separate checks.

Connect networks and resolve names

  • VPC peering connects compatible nonoverlapping networks with explicit routes; it is not transitive. A–B and B–C do not establish an A–C path through B. Transit Gateway supplies a routed hub for many VPCs and on-premises connections; attachment and route-table configuration still control permitted paths.
  • Site-to-Site VPN connects networks using encrypted tunnels over IP connectivity. VPN CloudHub supports compatible hub-and-spoke VPN site communication. Client VPN supplies remote-user access, with authentication, authorization and routes; it is not the same workload as linking two corporate networks.
  • Direct Connect provides dedicated connectivity and more predictable network characteristics, with physical provisioning considerations. It is not encrypted by default. Use appropriate application TLS, supported MACsec or VPN designs when encryption is required. Direct Connect Gateway connects eligible virtual-interface designs to multiple VPCs/Regions; it is not an automatic transitive VPC router.
  • Route 53 Resolver inbound endpoints let external networks query supported AWS DNS namespaces. Outbound endpoints and forwarding rules send matching VPC queries toward external DNS. Direction follows the query, and DNS resolution still needs underlying network reachability. See DNS notes.

IPv6, observation and cost

  • Amazon-provided public IPv6 addresses are globally routable; routing and filters control reachability. An egress-only IGW permits outbound-initiated internet flows for public IPv6 addresses. Reaching IPv4-only destinations from IPv6 is a separate translation requirement.
  • AWS also supports private IPv6 through IPAM, including ULA and private GUA ranges. IGWs and egress-only IGWs drop these private ranges; internet access requires a suitable intermediary with public addressing. “Outbound-only” and “private IPv6 address” are different properties.
  • Flow logs summarize supported IP flows, including accepted/rejected traffic, rather than packet payloads. Delivering to S3 and querying with Athena supports analysis. Traffic mirroring copies supported packet traffic for inspection; Network Firewall provides managed network filtering/inspection. WAF specializes in supported HTTP request paths.
  • Add the whole path's cost: public IPv4, NAT processing, cross-AZ/Region transfer, endpoints, load balancers and inspection. Service quotas, subnet address capacity and standby-region limits can prevent scale-out even when an architecture diagram looks sound.

Choose under exam pressure

Clue in the requirement Choose or investigate
Private VPC workloads only need same-Region S3 Gateway endpoint and suitable policies
Expose one supported private service to another account PrivateLink rather than broad routed connectivity
Many VPCs need transitive routing Transit Gateway
Remote employees need authenticated private access Client VPN
On-premises DNS must query private AWS names Resolver inbound endpoint plus connectivity
VPC clients need corporate DNS zones Resolver outbound endpoint and rules
Outbound-only internet access using public IPv6 addresses Egress-only IGW
Inspect actual packet content Suitable mirroring/inspection design

Traps

  • A subnet name, SG rule or public IP alone does not establish a complete path.
  • A gateway endpoint is not a replacement for all interface endpoints or for hybrid connectivity.
  • Older “all NAT gateways are zonal” shorthand is incomplete. Preserve the availability mode and routing assumptions in the question.

Practise this topic

05 · S3 security

Memory hook: Encryption protects stored bytes, policies authorize callers, and browser rules do neither job for you.

Must remember

Match encryption to the key-control requirement

  • SSE-S3: S3 manages encryption keys. New S3 objects receive server-side encryption by default; that baseline does not mean every bucket satisfies a requirement for a particular customer-managed key.
  • SSE-KMS: KMS adds key-policy control and key-use auditing. A caller may need both S3 authorization and KMS authorization; an allowed object read can still fail when key access is missing.
  • S3 Bucket Keys reduce eligible SSE-KMS calls and cost. They do not replace the KMS key policy or make unauthorized callers trusted.
  • DSSE-KMS: two layers of server-side encryption for requirements explicitly calling for dual-layer protection. S3 Bucket Keys are not supported with DSSE-KMS. DSSE-KMS guidance
  • SSE-C: S3 performs encryption but the customer supplies the key over HTTPS for relevant operations; S3 does not retain that key. Losing it can make the object unrecoverable.
  • Current SSE-C caveat: since April 2026, new general-purpose buckets—and existing buckets in accounts without SSE-C objects—block new SSE-C writes by default. It requires deliberate enablement; these labs do not enable it. Client-side encryption is different: the client encrypts before uploading. SSE-C behavior

Separate defaults, enforcement and exposure

  • Default encryption supplies a storage behavior. A bucket-policy deny can enforce a required encryption header/key; design conditions carefully because a missing header and an explicitly incorrect header are different requests.
  • TLS enforcement uses a deny for insecure transport, commonly aws:SecureTransport = false. Encryption at rest does not protect HTTP traffic.
  • Block Public Access is another independent safeguard. Identity policies, resource policies, explicit denies and applicable account controls still participate in authorization.
  • CORS lets a browser expose responses across specified origins/methods. It is not an S3 permission and is not relevant to every non-browser client.
  • Pre-signed URLs temporarily use the signer's permission. Access can end when the URL expires, the signing credentials expire, or authorization is revoked; the requested URL lifetime is not a guaranteed lifetime.
  • Server access logs provide best-effort request records in a logging bucket. They are not a synchronous authorization gate or a complete substitute for selected CloudTrail data events. S3 security guidance

Retention and application-specific access

  • Object Lock protects object versions, not merely a filename. Governance permits specifically authorized bypass; compliance cannot be shortened or bypassed during retention, including by root.
  • A legal hold has no automatic expiry and remains until released by an authorized principal. It is independent of a version's timed retention. Either can prevent deletion.
  • MFA Delete adds MFA requirements to selected versioning/permanent-deletion operations and requires root-controlled setup. It is different from Object Lock and is not configured here.
  • Glacier Vault Lock fixes a retention policy for the separate legacy Glacier vault model. Do not confuse it with S3 Glacier storage classes or S3 Object Lock. Object Lock concepts
  • Access Points provide separate endpoints and policies over shared bucket data; they do not create independent object copies or bypass the bucket's security controls.
  • Object Lambda historically transformed S3 reads through Lambda. Since November 7, 2025 it is limited to existing users and selected partner solutions. Recognize the course pattern, but use supported application/edge transformation designs for new customers. Availability notice

Choose under exam pressure

Requirement in the question Best direction
Control and audit use of a customer-managed key SSE-KMS plus correct key/S3 policies
Explicit dual-layer encryption requirement DSSE-KMS
Data must arrive at AWS already encrypted Client-side encryption
Temporary download of one private object Pre-signed URL
Authorized browser request blocked cross-origin Inspect CORS
Non-bypassable retention of a version Object Lock compliance
Separate application policies over one bucket Access Points

Traps

  • Making CORS permissive cannot fix missing IAM or KMS permissions.
  • Changing a bucket's default encryption does not retroactively re-encrypt all existing versions.
  • force_destroy is not stronger than an AWS retention lock.
  • A URL is a temporary bearer capability: anyone receiving it can use its allowed access while it remains valid.

Practise this topic

06 · Containers on AWS

Memory hook: Separate the container image, application task, compute capacity and permissions before choosing an orchestrator.

Must remember

Understand what each resource represents

  • A Docker image packages application layers; a container is a running instance. Rebuilding an image and replacing running containers are separate operations.
  • ECR stores images and versions/tags. Immutable tags prevent accidental tag replacement; digests identify specific content. Lifecycle rules remove old registry artifacts, but stopping tasks does not clean the registry.
  • ECS task definitions describe containers, CPU/memory, roles, networking and logging. A task is an execution; a service maintains desired running tasks and replaces failures.
  • ECS on EC2 leaves host capacity/patching and placement choices to your design. Fargate removes server provisioning while still requiring task sizing, subnets, security groups and suitable network access.
  • An empty cluster or registered task definition is not running compute. Conversely, an idle-looking service with desired tasks can keep billing.

Learn the three ECS role boundaries

  • Task role: permissions used by application code, such as reading S3 or DynamoDB. Give each workload only its required data/API scope.
  • Execution role: actions the ECS/Fargate agent performs for the task, such as pulling a private ECR image and delivering configured logs.
  • EC2 instance role: host/agent permissions for EC2-backed capacity. Do not use the host role as a substitute for per-task application permissions.
  • A successful image pull does not prove the application can reach its database. IAM, routing, DNS, security groups and the data service's policies are separate checks. ECS IAM roles

Match scaling and storage to the workload

  • ALB routes HTTP(S) to tasks and evaluates target health. Tasks using awsvpc networking register as IP targets, not host instance targets.
  • Service auto scaling changes desired task count. Capacity scaling adds/removes EC2 hosts where needed. More desired tasks do not help if the cluster lacks capacity to place them.
  • Fargate manages underlying capacity, but tasks still need valid CPU/memory combinations, quotas and reachable image/log endpoints. A private subnet may need NAT or appropriate service endpoints.
  • EventBridge/Scheduler can start standalone tasks for a schedule or event. Choose this for intermittent work rather than an always-running service; target execution permissions and iam:PassRole matter.
  • EFS supplies shared persistent files outside disposable containers. Mount targets, access points, permissions and NFS security-group paths matter. Container-local writable storage is not a shared persistent database.
  • Separate application scaling from downstream limits: scaling containers can overload a fixed-capacity database. Service scaling

Recognize Kubernetes and hybrid variants

  • EKS provides a managed Kubernetes control plane. It fits requirements for Kubernetes APIs, controllers and ecosystem compatibility, rather than merely “we have a container image.”
  • Compute options include managed node groups, self-managed EC2, supported Fargate profiles and current managed options such as EKS Auto Mode. Responsibility and feature support differ.
  • CSI storage drivers connect Kubernetes storage to AWS services. EBS is AZ-scoped block storage; EFS supports shared file access. Check the chosen compute/storage combination rather than assuming every volume works with every node type.
  • ECS Anywhere runs registered external machines under the regional ECS control plane; you still manage those machines and connectivity.
  • EKS Anywhere is customer-managed Kubernetes for supported on-premises/edge environments, including disconnected designs. EKS Distro is the Kubernetes component distribution, not a hosted control plane. EKS Hybrid Nodes instead connect customer-managed nodes to an AWS-managed regional control plane. EKS deployment choices, ECS external instances
  • Remove controller-managed load balancers and persistent storage appropriately before removing Kubernetes controllers/cluster infrastructure, or external resources may be orphaned.
  • App Runner historically simplified managed web-container deployment; App2Container analyzed/containerized existing applications. They are restricted for new customers as documented in the availability record; recognize their purposes without treating them as new sandbox defaults.

Choose under exam pressure

Requirement in the question Best direction
Containers with minimal host management Fargate
Kubernetes compatibility EKS
Specialized EC2 hosts or detailed capacity control EC2-backed orchestration
Container code needs S3 access Task role
ECS must pull a private image Execution role
Occasional scheduled container job Event-driven standalone task
Existing external machines under ECS control ECS Anywhere
Customer-managed disconnected Kubernetes EKS Anywhere

Traps

  • Task count, host count and Kubernetes control-plane availability are separate decisions.
  • Giving a role permissions does not create a route or open a security-group path.
  • Container-local state can disappear during replacement; scaling makes that weakness more visible.
  • A distribution of Kubernetes software is not the same product as an AWS-managed Kubernetes cluster.

Practise this topic

07 · AI Security, Privacy and Governance

Memory hook: Protect the data path and the action path, then keep evidence of both.

Must remember

  • Apply least-privilege IAM roles to models, tools, data stores and logs. Separate end-user identity from workload identity. Agent identity and policy features support controls, but the application still needs tenant isolation and scoped tool permissions.
  • Use TLS in transit, suitable encryption at rest and controlled KMS key access. PrivateLink provides supported private connectivity; it does not replace identity authorisation. Macie helps discover sensitive S3 data. Secrets should not be included in prompts or source code.
  • Prompt injection tries to turn untrusted text into instructions. It may arrive in a user message, retrieved page or tool result. Poisoning corrupts training or indexed data. Jailbreaking seeks to defeat safety behaviour. Validate inputs/outputs, restrict actions and treat retrieved content as data.
  • Bedrock Guardrails can apply configured content, topic, sensitive-information and other supported controls. Grounding and output validation can help detect unsupported statements. Do not use model self-reported confidence as the sole authority for high-risk decisions.
  • Track provenance, licences and lineage from source data through transformations, model versions and outputs. Define residency, retention and deletion requirements for prompts, logs, embeddings and memory as well as primary datasets.
  • CloudTrail supplies supported API audit events; Config evaluates resource configuration; Inspector assesses supported workload vulnerabilities; Artifact supplies AWS compliance evidence; Trusted Advisor highlights supported recommendations. Choose evidence according to the question.
  • Governance needs accountable owners, approval gates, review cadence, staff training and documented exceptions. Use a risk framework appropriate to the application and shared-responsibility model. Service compliance does not certify that your own data collection or use is lawful.

Choose under exam pressure

Requirement Choice and reason
A retrieved document tells an agent to reveal secrets Treat as injection; enforce permissions and tool constraints outside the model.
Need evidence of configuration compliance Config plus the relevant audit process.
Need to prove where training material came from Data lineage, provenance and licensing records.

Traps

  • A private network does not prevent an authorised application from leaking data.
  • Encrypting vectors does not resolve the right to retain their source data.
  • Logging every prompt without redaction can create a second sensitive-data store.

Practise this topic

08 · Detection Engineering and Incident Response

Memory hook: Prepare, detect, contain, preserve evidence, eradicate, recover and learn.

Must remember

  • Define owners, severity, escalation, communication and legal/evidence requirements before an incident. Pre-authorise scoped response roles, prepare a forensic account and test runbooks through simulations. Isolation should contain the threat without needlessly destroying evidence.
  • An organisation trail centralises supported CloudTrail activity. Select needed data events explicitly; management events alone do not record every object access. Protect log storage with restrictive policies, encryption, retention and integrity validation appropriate to the evidence requirement.
  • GuardDuty, Inspector, Macie and Security Hub findings answer different questions. Route findings through EventBridge to a deduplicated workflow. Tune severity and suppression carefully; a finding is a lead requiring context, not automatic proof of compromise.
  • For suspected credential theft, identify the affected principal and sessions, scope exposure, revoke/contain access using supported mechanisms, rotate compromised secrets and investigate persistence. Deleting one access key does not necessarily invalidate every previously issued temporary session.
  • For compute compromise, isolate network access using prepared controls, preserve relevant disk snapshots/logs and collect volatile evidence when required. Terminating immediately can lose memory and local data. Use dedicated forensic tooling and documented chain of custody; do not run arbitrary suspect binaries.
  • Validate containment against existing connections, not only new ones. Security-group connection tracking can allow tracked flows to continue after rule changes; a replacement restrictive group alone is not universal proof that a compromised host has lost every active path. Select documented network/session controls appropriate to the incident while preserving the access needed for evidence collection.
  • For exposed data, contain access, determine affected objects/versions and callers, inspect encryption and key use, and preserve the access evidence. Recovery needs a clean trusted baseline and validation that the attacker's persistence is gone.
  • Troubleshoot missing detections by checking event scope, Region, organisation membership, service enablement, delivery permissions, KMS policy, retention and event-rule filters. A disabled log pipeline can look deceptively quiet. Monitor the monitoring system.

Choose under exam pressure

Requirement Choice and reason
Suspected compromised EC2 with valuable evidence Isolate and preserve before destructive remediation.
No S3 object API records in a trail Check data-event selection and delivery, not only management logging.
Same finding repeatedly triggers remediation Use durable deduplication/idempotency and state checks.

Traps

  • Rotation alone may not invalidate previously issued sessions.
  • An empty dashboard can mean broken telemetry.
  • Automated containment can disrupt evidence collection unless planned.

Practise this topic

09 · Policy Evaluation and Security at Scale

Memory hook: A grant, a ceiling, a trust relationship and a network path are four separate checks.

Must remember

  • Identify the actual principal ARN/session, requested action, resource and condition keys. Identity policies and resource policies can grant access under different rules; boundaries, session policies and SCPs constrain applicable permissions. An explicit deny dominates. Role-session and same-account resource-policy exceptions mean simplistic intersection slogans can mislead.
  • Cross-account role access needs a trusting target role and permission for the caller to assume it, plus no applicable deny. External IDs help prevent a third-party confused-deputy problem; they are not passwords. Use source-account/source-ARN conditions where supported for AWS service access.
  • IAM Identity Center permission sets support workforce account access. Federation trust, session duration, MFA and emergency access need deliberate design. Permission boundaries delegate role creation while limiting potential rights; control who may change or remove the boundary.
  • KMS has its own key-policy/grant and identity-permission evaluation. Cross-account encrypted-data access needs both data-resource access and the relevant key permissions. Rotating a key does not re-encrypt every existing object automatically. Multi-Region related keys do not make all policy and resource configuration global.
  • SCPs, resource control policies where supported, organisation conditions and account boundaries serve different purposes. Apply controls through OUs and delegated administration, test exceptions and keep an audited emergency path. A deny aimed at one Region must account for global service behaviour.
  • Use infrastructure pipelines, Config rules, security standards and automated remediation to maintain baselines. Classify controls as preventive, detective or responsive. Record evidence and exceptions; compliance frameworks guide controls but do not replace risk analysis.
  • For containers and serverless, separate runtime role, execution/image-pull role and infrastructure role. Scan images/dependencies, restrict network paths and secrets, and audit tool/service access. For AI, treat prompts/retrieved content as untrusted and authorise tool actions outside the model.

Choose under exam pressure

Requirement Choice and reason
Delegate role creation without unlimited escalation Permission boundaries plus control of boundary removal and PassRole.
Allow a vendor to assume a customer role safely Scoped trust and appropriate external-ID conditions.
S3 permits access but decryption fails Inspect KMS key policy, identity permissions and grants.

Traps

  • An external ID is not a secret authentication credential.
  • Allowing access in an SCP does not grant it.
  • Network reachability does not imply authorisation.

Practise this topic

10 · CloudFormation and Systems Manager Operations

Memory hook: Inspect the intended change, the actual state and the identity performing it.

Must remember

  • A CloudFormation stack tracks declared resources; dependencies control ordering. Change sets preview updates, drift detection compares supported properties with actual state, and StackSets apply stacks across selected accounts/Regions. These are different operations.
  • Know update-in-place versus replacement, rollback states and why a retained resource can survive stack deletion. DeletionPolicy controls supported deletion/retention behaviour; update-replacement retention is a separate concern. Imported resources and existing physical names need careful ownership checks.
  • Template parameters vary inputs; mappings select fixed values; conditions select resources/properties; outputs expose results. Resolve circular dependencies by reconsidering resource references and ordering. A creation signal or wait condition is not automatically satisfied by an EC2 instance entering running state.
  • Use service roles with least privilege and understand iam:PassRole. A user may initiate an operation while a service role performs it. Read stack events from the earliest meaningful failure, not only the final rollback summary.
  • Systems Manager managed nodes need a working agent, identity permissions and connectivity to required endpoints. Session Manager avoids opening SSH/RDP ports for supported access. Run Command executes commands, State Manager maintains associations, Automation coordinates runbooks, Patch Manager applies patch policies.
  • Maintenance windows define when approved work may run; patch baselines define approved patches. Inventory and compliance show state; remediation requires a configured action. Restrict runbook parameters and use approvals, rate controls and failure thresholds where the impact demands them.
  • Schedule start/stop and cleanup by explicit ownership tags. Stopped compute can leave charged storage and addresses. Cost Explorer, budgets, tags and anomaly detection provide evidence and alerts, not immediate universal spending caps.

Choose under exam pressure

Requirement Choice and reason
Same declared baseline across many accounts StackSets with appropriate delegated permissions.
Find console edits to managed resources Drift detection for supported properties.
Run an approved multi-step repair Systems Manager Automation runbook.

Traps

  • Drift detection does not automatically repair drift.
  • A successful stack update does not prove application readiness.
  • A service role can perform actions the initiating user cannot perform directly; control who may pass it.

Practise this topic

Search across every published topic.