
This chapter gives out the expectations on the course
Understand the shared responsibility model and security boundaries between AWS and you. Learn which controls you must implement for resources like EC2, including patching, traffic monitoring, and security groups.
Explore encryption in transit, securing data as it moves between sources and destinations, with examples like ssl termination on an elastic load balancer and https traffic on port 443.
Review identity and access management concepts, policies, and cross-account roles, and recap key services like KMS, CloudHSM, WAF, CloudWatch, CloudTrail, and AWS Config for secure asset protection.
This chapter looks at the basics of Encryption
This chapter looks at the Key Management Service
This chapter looks at Encryption and Decryption using KMS
This chapter looks at working with Keys
This chapter looks at controlling access
This chapter looks at the AWS KMS and Simple Storage Service
This chapter looks at AWS KMS and Simple Storage Service Demo
This chapter looks at AWS KMS and the EBS Service
This chapter looks at importing your own key material in AWS
This chapter looks at additional aspects for the KMS Service
This chapter looks at DynamoDB Encryption
Learn to use your own key pair for EC2 by generating a public/private key and importing the public key to AWS. Log in to the instance with the private key.
This chapter looks at Cloud HSM
This chapter looks at AWS Security
This chapter looks at securing your account
This chapter looks at Incident Response Plan
This chapter looks at compromised resources in AWS
This chapter looks at penetration testing
This chapter looks into the AWS Inspector Service
This chapter looks at S3 Lifecycle policies
This chapter looks at IAM policies
This chapter looks at an example on IAM Policies
This chapter looks at S3 bucket policies
This chapter looks ate Bucket policy conditions
This chapter looks at IAM Roles
This chapter looks at a demo on IAM Roles
This chapter looks at additional aspects for IAM Policies
This chapter looks at AWS Organizations
This chapter looks at S3 Pre-signed URL's
This chapter looks at AWS Cognito
This chapter looks at Encryption of data in transit
This chapter looks at VPC Security
This chapter goes into a demo on Security Groups
This chapter looks at a demo on Network Security Groups
Configure the application load balancer and EC2 security groups to allow port 80 from the ALB, enable port 443 for secure traffic, and restrict 3306 to the web security group.
This chapter looks at NAT instances and gateways
This chapter looks at a demo on NAT gateways
This chapter looks at VPC peering
This chapter looks at the steps which can be performed to help mitigation against DDoS attacks
Learn how VPC endpoints let a private subnet instance reach public services like S3 and DynamoDB without internet access, by creating a gateway endpoint and updating route tables.
Create VPC endpoints in the same region as the bucket and apply endpoint and bucket policies to restrict access to S3 resources.
Apply a key policy to restrict KMS access to a specific VPC endpoint, permitting encrypt, decrypt, and data key generation only from that endpoint.
This chapter looks at other tools which can be used for Packet inspection for traffic going to EC2 Instances
This chapter looks at the web application firewall
This chapter looks at the AWS Trusted Advisor
This chapter looks at CloudTrail
This chapter looks at a demo on Cloudtrail
This chapter looks at Cloud Trail File Validation
This chapter looks at Cloud Trail Logs from Multiple Accounts
This chapter looks at Cloudwatch Logs - Using the agent
This chapter looks at VPC Flow Logs
This chapter looks at the AWS Config Service
This chapter looks at AWS Config Rules
This chapter looks into the Introduction of AWS Systems Manager
This chapter looks at AWS Systems Manager - Inventory Service
This chapter looks at the AWS Systems Manager Run Command
This chapter looks at AWS Systems Manager Parameter Store
This chapter looks at AWS Systems Manager agent troubleshooting
This chapter looks at AWS Systems Manager - Patch Manager
Navigate the aws certified security exam: 65 scenario-based questions in roughly three hours, with strategies to mark for review and spot keywords like patch management, roles, and policies.
This chapter looks into the Exam Details
This course is specially built to prepare you for taking on the AWS Certified Security Specialty Exam. This course also has a quiz which will help you see how well prepared you are for the exam
Security is a key aspects in today's spectrum of the IT Industry. The newest exam from AWS helps fortify your concepts on the various security aspects of various AWS resources
In this course you will learn the following
1. The AWS Key Management Service
2. Security in Networking
3. Using Identity and Access Management
4. Core AWS services from a security aspects such as CloudTrail , AWS Config, AWS WAF etc.
5. Key concepts that are required from an exam perspective such as Incident Response , penetration testing etc.
This course also has a quiz that will help you better assess how well you are prepared for the exam.