
Explore cloud security with AWS and Azure, and learn about security services like GuardDuty, Inspector, Shield, Certificate Manager, Directory Service, and Single Sign-On, plus Azure Security Center.
Explore artifact, a no-cost, self-service portal for on-demand security and compliance reports, NDA management, and governance across cloud services on AWS and beyond.
Explore how the Amazon artifact functions as a security identity and compliance tool, offering access control documents, certificates, and non-disclosure agreements to load artifacts for scenario cloud compliance across languages.
Provision, manage, deploy public, private, DNS SSL certificates with certificate manager on amazon cloud, automating renewals and integrating with load balancers and API gateway to secure identities.
Provision, manage, and apply SSL and private certificates with AWS certificate manager, including public certificates, private certificate authority options, domain validation, and advanced settings.
Learn how AWS Cloud HSM provides a hardware security module to manage your own encryption keys with FIPS 140-3 level compliance, enabling certificate authority, SSL authentication, and secure, compliant workloads.
Learn to create an Amazon cloud hsm instance, configure a cluster with a VPC in a chosen region, add nodes, enable backups, and delete unused clusters.
Explore how AWS Directory Service enables managed Microsoft Active Directory integration, single sign-on, group policy, and seamless domain joins for cloud workloads and hybrid environments.
Learn a workflow for creating and managing an AWS directory service from the Amazon dashboard, covering directory types, vpc and subnet settings, dns names, cognito user pools, and password resets.
GuardDuty uses machine learning to detect anomalies and potential account compromise by analyzing AWS events across accounts with CloudWatch events, enabling automated responses with Lambda.
learn to set up an AWS GuardDuty instance, a security tool under the security, identity and compliance category, that detects activity and analyzes DNS queries to surface findings.
Explore Amazon Inspector, an automated security and compliance assessment tool for cloud applications, generating prioritized findings and integrating with config rules and trusted advisor to harden environments.
Practical use of Amazon Inspector to analyze security issues, run assessments, check GuardDuty findings, apply hardening benchmarks, and generate template rule sets with defined execution duration.
Learn how Secrets Manager protects sensitive information such as credentials, database passwords, and API keys in the cloud using cryptographic protection, rotation, and centralized access controls.
Learn to use secrets manager to securely store encrypted credentials and api keys as key-value secrets, with automatic rotation and lambda integration, while noting password storage is discouraged.
Explore how single sign-on centralizes authentication across cloud apps, enabling one login and centralized access control via SAML integration with Active Directory and apps like Salesforce and Office 365.
Implement a practical single sign-on cloud service to manage access for users and groups through Microsoft Active Directory, integrate with AWS and Azure, and automate SSL provisioning.
Learn to protect applications using WAF and Shield by configuring custom rules, IP and geo restrictions, and application-layer protections across CloudFront and load balancers to block attacks.
Configure AWS web application firewall and shield to protect websites and apps from web exploits and DDoS attacks using access control lists and IP match conditions to block malicious traffic.
Explore the AWS VPC dashboard to manage subnets, routing tables, internet gateways, and elastic IPs across regions. Learn inbound and outbound rules and core security considerations for cloud networking.
Create a virtual private cloud (VPC) in AWS by defining IP blocks and subnets. Configure routing, logs, tags, and S3 storage, and consider VPN connections for secure networking.
Create subnets within your cloud environment by naming the subnet, selecting a region and IP version, and configuring a routing table and an internet gateway.
Create and attach an internet gateway to your AWS VPC to enable internet access. Manage the gateway via the console, CLI, or PowerShell and detach it if needed.
Create and manage route tables in AWS, edit subnet associations and route propagation, connect to a VPC, and tag and customize configurations.
Customize route tables and network components in AWS VPC, including creating a VPC and subnets, configuring internet and NAT gateways, and managing DHCP options and elastic IPs.
Explore the security center as a unified, one-place solution for monitoring and assessments of on-premises and cloud resources, with automated recommendations and a security score to guide remediation.
Onboard and configure security center in Azure, review the security score, and implement data storage, firewall, and access control recommendations while mapping policies to regulatory compliance.
Azure Active Directory provides a fully managed identity and access platform that extends on-premises directories to the cloud, enabling single sign-on, conditional access, and threat protection for apps and partners.
Explore how a vpn gateway enables encrypted site-to-site and point-to-site connections between on-premises networks and cloud environments, sharing bandwidth across tunnels and supporting multiple connections.
Guard cloud resources from distributed denial of service with always-on monitoring, automatic mitigation, adaptive tuning, and web application firewall integration for real-time DDoS protection.
Discover how Azure Key Vault safeguards cryptographic keys, secrets, and certificates using hardware security modules, with strict access control, backups, and automatic rotation for cloud apps and services.
Learn to create and manage cryptographic keys in a key vault on AWS, configure access policies and firewall rules, and monitor keys and certificates.
Explore dedicated hardware security modules in the cloud, providing isolated, customer-controlled cryptographic key storage with tamper-resistant hardware, migration support, and certifications like Common Criteria to ensure security and compliance.
activate application gateway as an application-layer load balancer that routes web traffic by HTTP attributes, enabling scalable, secure front-end delivery with integration to security center and log analytics.
Engage in a practical exercise to create an application gateway in Azure, configure its name, capacity, network, IP addresses, DNS, and listener settings, and monitor deployment.
Learn to deploy and configure an application gateway, monitor its resources and status, manage back-end pools, listeners, and front-end settings, and apply ssl policies and a web application firewall.
Cloud Security has almost been overlooked by a lot of professionals, where they just tend to focus on getting some sort of Cloud Certifications. When they are building an application, or working on some project, people generally forget to implement the Security aspect correctly. In this rapidly changing world, where everything is moving to Cloud platforms, with exponential rise in Cyber threats, no individual or organization can risk their job or business to an open Vulnerability waiting to be harnessed by any kind of Black hat guy. You can avoid such situations simply by taking a few simple decisions, adding a few compliance on your Cloud Project.
This course is all about implementing the Cloud Security in the first place, where you will learn all the security tools and services available on AWS (Amazon Web Services) and Microsoft Azure. You will learn how you can create instances for Security services and how you can manage them by integrating with you cloud applications. You will also learn some of the best practices that you can put forward in your overall cloud strategy.
You will be learning a range of services from Hardware Security to firewall, network security to adding a single sign-on and a lot more. You will learn Cloud security on AWS in the starting sections, followed by Cloud security on Microsoft Azure. You will learn following security services in this course:
Cloud Security on AWS
Artifact
CloudHSM (Hardware Security Module)
Certificate Manager
Directory Service
Guard Duty
Inspector
Single Sign-on
WAF and Shield
Cloud Security on Microsoft Azure
Security Center
Azure Active Directory
VPN Gateway
DDoS Protection
Key Vault
Dedicated HSM
Application Gateway
Azure Sentinel
Information Protection