AWS Certified Security – Specialty flashcards
159 free flashcards. Tap a card to flip it.
Amazon Macie
Flip cardA data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS, primarily in Amazon S3.
- Automatically discovers sensitive data (PII, financial, etc.).
- Provides visibility into S3 bucket security and access.
- Helps identify and prevent data leaks.
Memory trick: Macie finds the sensitive, labels the data, keeps it protected.
S3 Object Lock Compliance Mode
Flip cardAn Amazon S3 feature that prevents an object from being deleted or overwritten for a fixed amount of time or indefinitely. In Compliance mode, no user, including the root user, can delete the object version or change its lock settings.
- Provides WORM (Write Once, Read Many) protection.
- Compliance mode offers the strongest protection, even against the root user.
- Used for regulatory compliance and data retention requirements.
Memory trick: To lock data forever, compliance is clever.
IAM Condition Key: aws:MultiFactorAuthAge
Flip cardAn IAM condition key that specifies the number of seconds since the IAM principal authenticated with multi-factor authentication (MFA).
- Value is an integer representing seconds.
- A value of '0' means MFA was not used for the current session.
- Commonly used with `NumericGreaterThan` to enforce MFA for sensitive actions.
- Can be used in `Allow` or `Deny` statements to control access based on MFA.
Memory trick: MFA Age greater than zero, makes your access a secure hero.
IAM Identity Center Permission Sets
Flip cardA collection of administrative policies that define a user's access to an AWS account, managed centrally by IAM Identity Center.
- Defines permissions for users/groups to access AWS accounts.
- Applied to groups and assigned to specific accounts or OUs.
- IAM Identity Center automatically provisions corresponding IAM roles in target accounts.
- Simplifies access management across multiple AWS accounts.
Memory trick: Permission Sets are the key to groups' access, across accounts with grace.
S3 Object Tags with Lifecycle Rules
Flip cardS3 Object Tags are key-value pairs that can be applied to individual S3 objects, enabling granular data classification. S3 Lifecycle rules can then be configured to perform actions (e.g., transition to different storage classes, expire) based on these object tags.
- Allows up to 10 tags per object.
- Enables fine-grained control over data lifecycle.
- Reduces the need for multiple buckets for classification.
Memory trick: Tag your S3 objects to dictate their 'Time' and 'Place' in storage.
CloudTrail Organization Trails with S3 Object Lock
Flip cardA centralized logging solution for AWS Organizations that delivers immutable audit logs to a secure S3 bucket.
- CloudTrail organization trails capture all AWS API activity across all member accounts.
- S3 Object Lock in compliance mode prevents deletion or modification of objects for a specified retention period, even by the root user.
- Ensures audit trail integrity and non-repudiation for compliance.
Memory trick: Think of a 'master ledger' (CloudTrail) locked inside a 'vault' (S3 Object Lock) that no one, not even the owner, can alter.
External Key Management (Client-Side Encryption)
Flip cardEncrypting data on the client side using an encryption library that interfaces with an external Key Management System (KMS) located outside of AWS, ensuring that encryption keys never enter the AWS environment.
- Keys are fully controlled and managed by the customer outside AWS.
- Data is encrypted before transmission to AWS.
- Provides the highest level of key sovereignty and data control.
Memory trick: External keys mean your data's safe, even before it hits the cloud wave.
IAM Condition Key: iam:MFAPresent
Flip cardAn IAM condition key that evaluates whether the principal making the request has authenticated with MFA.
- Used to enforce MFA for sensitive actions.
- Value is 'true' if MFA was used, 'false' otherwise.
- Can be used in a `Deny` statement to prevent actions without MFA.
Memory trick: Think of a 'secret handshake' (MFA) required before you can perform sensitive 'admin tasks'.
S3 Object Lock Compliance Mode for WORM
Flip cardAmazon S3 Object Lock, specifically in Compliance mode, enforces a Write Once, Read Many (WORM) model, making data immutable for a specified retention period against any user, including the root account. It's crucial for regulatory compliance requiring tamper-proof storage.
- Prevents objects from being overwritten or deleted by *any* user during the retention period.
- Ideal for regulatory compliance (e.g., FINRA, HIPAA, SEC Rule 17a-4).
- Can be combined with S3 Lifecycle policies for automatic object expiration after the retention period.
Memory trick: Compliance Mode Confirms Complete Content Control, Can't be Deleted.
S3 Glacier Deep Archive
Flip cardThe lowest-cost Amazon S3 storage class designed for long-term data archival that is accessed rarely (e.g., once or twice a year) and can tolerate retrieval times of several hours.
- Offers the lowest storage price in S3.
- Suitable for data retained for 7-10 years or more.
- Retrieval times typically range from 12 to 48 hours.
- Provides 99.999999999% (11 nines) durability across multiple Availability Zones.
Memory trick: Deep Archive for Deep Sleep Data.
Amazon S3 Glacier Deep Archive
Flip cardThe lowest-cost Amazon S3 storage class for long-term archival, designed for data that is accessed once or twice a year and can tolerate retrieval times of 12-48 hours.
- Lowest storage cost among S3 classes.
- Ideal for long-term data retention (7-10+ years).
- Retrieval times range from 12 to 48 hours for standard requests.
Memory trick: When data sleeps deep, cost savings you reap.
Amazon Cognito Identity Pools
Flip cardAn AWS service that provides temporary, limited-privilege AWS credentials to users who have been authenticated by an identity provider, enabling them to access AWS resources.
- Also known as Federated Identities.
- Integrates with Cognito User Pools, social identity providers (Google, Facebook), and SAML.
- Exchanges identity tokens for temporary AWS credentials.
- Allows authenticated users to access AWS resources using IAM roles.
Memory trick: User Pool + Identity Pool = Customer Access cool.
IAM Policy Evaluation Logic
Flip cardThe order in which IAM policies are evaluated: explicit deny > explicit allow > implicit deny (default).
- Explicit Deny always overrides Explicit Allow.
- Explicit Allow overrides Implicit Deny.
- If no matching Allow policy, access is implicitly denied.
Memory trick: Deny is king, then Allow takes wing, if nothing, deny's the final thing.
AWS Data Residency Enforcement
Flip cardEnsuring that data is stored and processed exclusively within a specified geographic region to comply with local regulations, typically achieved by selecting appropriate AWS regions for resources.
- Involves selecting specific AWS regions for data storage and processing.
- Critical for compliance with regulations like GDPR.
- Affects where S3 buckets, EC2 instances, Lambda functions, etc., are provisioned.
Memory trick: Keep the data where the law says it needs to stay.
SSE-KMS for Central Key Management & Audit
Flip cardServer-Side Encryption with AWS KMS customer managed keys (CMKs) provides encryption at rest for Amazon S3 objects, offering central key management, granular access control via key policies, and auditability of key usage through AWS CloudTrail.
- CMKs are managed within AWS KMS, providing a central point of control.
- Key policies define who can use and manage the CMK.
- All API calls to KMS for key usage are logged in AWS CloudTrail for auditing.
- Can be set as default bucket encryption for automatic encryption of new objects.
Memory trick: KMS CMK: Central, Managed, Audited.
AWS Directory Service for Microsoft AD (Enterprise)
Flip cardA fully managed, highly available Microsoft Active Directory hosted in AWS, offering full AD functionality, Kerberos, LDAP, and trust relationships with on-premises AD.
- True Microsoft Active Directory functionality.
- Supports Kerberos and LDAP for enterprise applications.
- Enables trust relationships with on-premises AD for hybrid environments.
- Provides high availability and disaster recovery within AWS.
Memory trick: ADDS, Simple, Connect, Cognito - choose wisely for your domain's needs!
S3 Default Encryption & Batch Operations
Flip cardS3 Default Encryption automatically encrypts new objects. S3 Batch Operations allow large-scale operations (like encryption) on existing objects.
- Default encryption prevents unencrypted uploads.
- SSE-KMS offers managed key control.
- Batch Operations for re-encrypting existing objects.
- Comprehensive solution without application code changes.
Memory trick: Default encryption secures new, Batch Ops re-encrypts old.
DynamoDB Encryption at Rest
Flip cardAmazon DynamoDB encrypts all data at rest by default. Customers can choose between AWS-owned keys, AWS-managed keys (KMS), or customer-managed keys (KMS CMKs) for encryption, providing flexibility for compliance.
- Always encrypted at rest.
- Choice of AWS-owned, AWS-managed, or customer-managed (KMS CMK) keys.
- Configured in table settings during creation or modification.
- No performance impact for encryption.
Memory trick: DynamoDB's 'Encryption' is a 'Switch' you control with KMS.
IAM Role Trust Policy
Flip cardA JSON policy attached to an IAM role that specifies which principals are allowed to assume the role.
- Defines the 'who' can assume the role.
- Uses the `Principal` element to specify trusted entities (AWS accounts, IAM users/roles).
- Must grant `sts:AssumeRole` action.
- Separate from the permissions policy, which defines 'what' the role can do.
Memory trick: Trust Policy is the gatekeeper, for who can assume the role's keeper.
Service Control Policies (SCPs)
Flip cardPolicy type used in AWS Organizations to manage permissions and set maximum available permissions for all accounts in an organization.
- Apply to all IAM users and roles in affected accounts, including the root user.
- Are preventative controls; they define the maximum available permissions.
- Do not grant permissions; they filter permissions granted by IAM policies.
Memory trick: Think of SCPs as the 'corporate police' that set the rules for everyone in the AWS Organization.
Cross-Account Role Assumption
Flip cardAllows an IAM principal in one AWS account to temporarily access resources in another AWS account by assuming a role.
- Relies on a trust policy in the target account's role, specifying which principals can assume it.
- Provides temporary security credentials, reducing the risk of long-lived access keys.
- Enables granular, least-privilege access across account boundaries.
Memory trick: Think of a 'secure bridge' between accounts, where only authorized 'messengers' (roles) can cross with specific 'delivery instructions' (permissions).
SSE-S3 for Minimal Overhead
Flip cardServer-Side Encryption with S3-managed encryption keys (SSE-S3) automatically encrypts objects before saving them to S3 and decrypts them when downloaded, with AWS managing all key lifecycle, offering the lowest operational overhead.
- AWS manages the encryption keys completely.
- Encrypts data at rest automatically.
- Requires no changes to your application code for encryption/decryption.
- Supports encryption in transit via HTTPS/TLS.
Memory trick: Simple S3 is SSE-S3.
S3 Standard-IA for Infrequent Access
Flip cardAmazon S3 Standard-Infrequent Access (S3 Standard-IA) is an S3 storage class optimized for data that is accessed less frequently but requires rapid access when needed, offering lower storage costs compared to S3 Standard.
- Ideal for long-lived, infrequently accessed data.
- Offers millisecond retrieval times.
- Has a minimum storage duration of 30 days and a retrieval fee per GB.
Memory trick: Standard-IA is the Smart Switch for Seldom-Seen Stuff.
KMS Custom Key Stores with CloudHSM
Flip cardA KMS Custom Key Store backed by AWS CloudHSM allows you to create KMS keys whose cryptographic operations are performed within a dedicated, FIPS 140-2 Level 3 validated CloudHSM cluster that you own and control.
- Customer owns and manages the CloudHSM cluster.
- KMS provides a streamlined API for using these keys.
- Combines KMS ease of use with dedicated HSM security.
Memory trick: KMS + CloudHSM = 'Key Master' for your 'Hardware Safe Mode' data.
KMS CMK Automatic Key Rotation
Flip cardAWS Key Management Service (KMS) customer managed keys (CMKs) can be configured to automatically rotate their cryptographic material annually, providing enhanced security without manual intervention for key management.
- Applies to CMKs, not AWS-managed keys.
- Rotates the underlying cryptographic material, but the key ID remains the same.
- Previous key versions are retained for decryption of older data.
- Automatically happens once a year.
Memory trick: KMS CMK Rotates Itself Annually.
S3 Object Lock Compliance + Lifecycle
Flip cardCombining S3 Object Lock in Compliance mode for strict immutability with S3 Lifecycle rules to manage data transitions to lower-cost storage classes and eventual expiration after the retention period.
- Object Lock Compliance ensures WORM for a defined period.
- S3 Versioning must be enabled for Object Lock.
- Lifecycle rules automate cost optimization and deletion post-retention.
Memory trick: Lock it tight with compliance, then lifecycle for less expense.
IAM Roles for Service Accounts (IRSA)
Flip cardA feature that allows you to associate an IAM role with a Kubernetes service account, providing fine-grained permissions for pods.
- Eliminates the need to share credentials or use instance profiles for pod identity.
- Uses OpenID Connect (OIDC) to authenticate Kubernetes service accounts with IAM.
- Enables fine-grained, least-privilege permissions for individual microservices.
Memory trick: Think of giving each microservice its own 'ID badge' (IAM role) inside the EKS 'office' (cluster).
Principle of Least Privilege
Flip cardGranting only the permissions required to perform a specific task, and nothing more.
- Reduces the attack surface by limiting potential damage from compromised credentials.
- Should be applied to all IAM users, roles, and resources.
- Requires careful analysis of necessary actions for each component.
Memory trick: Imagine a key that only opens one specific door, not a master key for the whole building.
S3 Block Public Access & Bucket Policies
Flip cardA combination of account-level S3 Block Public Access settings to ensure default privacy, and S3 bucket policies for explicit, granular access grants.
- S3 Block Public Access prevents public read/write access and public ACLs/policies.
- Enabled at account level, applies to all buckets in that account.
- S3 bucket policies define resource-based access permissions.
- Together, they enforce private by default while allowing controlled, explicit grants.
Memory trick: Block Public ensures private start, Bucket Policies play the granting part.
IAM Password Policy & AWS Config for MFA
Flip cardIAM password policies enforce password complexity and rotation, while AWS Config rules detect non-compliance with MFA requirements for IAM users.
- IAM password policy is set at the account level.
- AWS Config managed rules exist for MFA compliance (e.g., `iam-user-mfa-enabled`).
- Config can provide continuous monitoring and remediation for MFA.
- This combination provides both enforcement (passwords) and detection/monitoring (MFA).
Memory trick: Password policy sets the rules, Config checks for MFA tools.
Application-Level Encryption for Multi-Tenancy
Flip cardApplication-level encryption involves the application encrypting data with unique, tenant-specific keys before storing it in the database. This provides strong logical isolation, granular key management, and individual key revocation capabilities for multi-tenant SaaS architectures.
- Each tenant's data is encrypted with its own distinct key.
- Keys are managed by the application, often integrating with KMS or an external HSM.
- Enables individual tenant key revocation without affecting other tenants.
- Provides the highest level of logical isolation between tenant data.
Memory trick: Application-Level Encryption Allows Awesome Isolation and A La Carte Key Control.
DynamoDB Encryption with AWS Managed Keys (KMS)
Flip cardAmazon DynamoDB encryption at rest with AWS managed keys uses AWS Key Management Service (KMS) to encrypt table data, providing automatic annual key rotation and minimal operational overhead for key management.
- Encryption keys are managed by AWS KMS on the customer's behalf.
- Automatically rotates annually without customer intervention.
- Provides encryption at rest for DynamoDB tables.
- Lower operational overhead compared to customer-managed keys.
Memory trick: AWS-Managed Keys Make DynamoDB Data Secure and Simple.
AWS Managed Microsoft AD
Flip cardA fully managed, highly available Microsoft Active Directory service in the AWS cloud that supports integration with on-premises AD and SSO.
- Enterprise Edition offers multi-Region replication and higher scale.
- Supports Kerberos, LDAP, and Group Policy.
- Enables seamless domain join for EC2 instances.
Memory trick: Think of managing your company's 'people directory' in the cloud, just like your office directory.
S3 Bucket Policy for Encryption Enforcement
Flip cardAn S3 bucket policy using conditions to deny `s3:PutObject` actions if specific server-side encryption headers are not present in the request.
- Uses `Effect: Deny` for `s3:PutObject` action.
- Condition `Null` with `"s3:x-amz-server-side-encryption": "true"` denies if encryption header is missing.
- Alternatively, `StringNotEquals` can deny if a specific encryption type is not used.
- Enforces encryption at rest for all new objects uploaded to the bucket.
Memory trick: Deny null encryption, for data's protection.
Automated S3 Data Classification with Macie
Flip cardUsing Amazon Macie for automated discovery and classification of sensitive data in Amazon S3, integrating its findings with AWS EventBridge to trigger subsequent actions like applying S3 Object Tags or invoking workflows.
- Macie continuously monitors S3 buckets for sensitive data.
- Macie findings can be published to EventBridge.
- EventBridge rules can trigger various AWS services (e.g., Lambda) based on Macie findings.
- S3 Object Tags are effective for metadata-driven workflow automation.
Memory trick: Macie Finds, EventBridge Tags.
S3 Access via VPC Endpoint with Bucket Policy
Flip cardAccessing S3 via a VPC Endpoint ensures that traffic remains within the AWS network, never traversing the public internet. An S3 Bucket Policy can then enforce that access is only permitted if it originates from a specific VPC Endpoint, providing network isolation and granular control.
- VPC Endpoints for S3: Gateway (free) or Interface (PrivateLink, paid).
- Gateway endpoints are for S3 and DynamoDB only.
- Bucket policies with `aws:sourceVpce` condition enforce endpoint usage.
- Prevents public internet exposure for S3 access.
Memory trick: Route S3 through the 'VPC Gate' and 'Policy Guard' it.
Client-Side Encryption (CSE)
Flip cardClient-Side Encryption involves encrypting data on the client's side before it is sent to an AWS service. This ensures that AWS services only ever receive and store ciphertext, and never have access to the plaintext data or the encryption keys.
- Customer manages all encryption keys and processes.
- AWS stores only encrypted data.
- Prevents AWS services from automatic decryption.
- Highest level of customer control over data privacy.
Memory trick: Encrypt 'Client-Side' to keep AWS 'out of the loop' on your data.
Client-Side Encryption with On-Premises HSMs
Flip cardEncrypting data before sending it to a cloud service using keys generated and managed entirely within the customer's on-premises Hardware Security Modules (HSMs), ensuring keys never leave the customer's control.
- Data is encrypted locally before upload.
- Encryption keys are managed outside of AWS.
- Provides the highest level of key control and data sovereignty.
Memory trick: To keep keys truly home, encrypt before you roam.
AWS Service Control Policies (SCPs)
Flip cardPolicies that provide central control over the maximum available permissions for all accounts in an AWS Organization, allowing organizations to enforce compliance and security standards across all member accounts.
- Apply to OUs or the organization root, affecting all child accounts.
- Can be used to whitelist or blacklist AWS services and actions.
- Do not grant permissions; they filter permissions granted by IAM policies.
Memory trick: SCPs are the organizational cops, keeping everyone in line.
Queryable Archived Data for GDPR
Flip cardA strategy for storing large volumes of data in cost-effective archival storage (like S3 Glacier Deep Archive) while maintaining the ability to efficiently identify and delete specific customer records to comply with regulations like GDPR or CCPA.
- Involves storing data in structured, self-describing formats (e.g., Parquet, ORC).
- Leverages data catalogs (AWS Glue) and query services (Amazon Athena).
- Allows for targeted deletion of records without full archive restoration, minimizing cost and time.
Memory trick: Query Structured Archives, Delete with Athena.
SSE-KMS for Multi-Team Data Encryption
Flip cardServer-Side Encryption with AWS KMS (SSE-KMS) allows Amazon S3 to encrypt objects using customer-managed keys (CMKs) within AWS KMS, enabling centralized key management and granular access control.
- Uses customer-managed keys (CMKs) stored in AWS KMS.
- Keys never leave the KMS service boundary.
- Supports separate CMKs for different applications or teams, enabling fine-grained security and compliance.
Memory trick: KMS Keys Keep S3 Securely Separate for Each Squad.
AWS Directory Service for Microsoft Active Directory
Flip cardA fully managed service that hosts Microsoft Active Directory in the AWS Cloud, enabling seamless integration with existing on-premises AD and AD-aware applications.
- Managed, highly available Microsoft AD.
- Supports standard AD features (GPO, Kerberos, LDAP).
- Enables seamless hybrid identity with on-premises AD.
- Allows AD-aware applications to run without modification.
Memory trick: Managed AD extends your on-prem AD to AWS.
S3 Bucket Policy
Flip cardA resource-based access policy attached directly to an S3 bucket, allowing granular control over who can access the bucket and its objects, and under what conditions.
- Defines permissions at the bucket level.
- Can grant or deny access to IAM principals, AWS services, and external accounts.
- Supports conditions based on source IP, VPC endpoint, MFA status, and more.
Memory trick: Bucket Policies are the King, for all your S3 access string.
DynamoDB Encryption with CMKs & Rotation
Flip cardAmazon DynamoDB encryption at rest can be configured with customer-managed keys (CMKs) from AWS KMS, allowing customers to control key policies, enable automatic annual key rotation, and meet strict compliance requirements.
- Uses AWS KMS Customer Master Keys (CMKs) for encryption.
- CMKs provide granular control over key usage and access policies.
- Automatic annual key rotation can be enabled for CMKs within AWS KMS.
Memory trick: CMKs Control DynamoDB, Compliantly Rotating Keys.
IAM Role Trust Policy "AWS": "*"
Flip cardA trust policy that allows any authenticated AWS principal from any AWS account to assume the role.
- Extremely dangerous when combined with high-privilege permissions.
- Should almost never be used in production environments.
- Can lead to cross-account compromise if a principal in another account is compromised.
Memory trick: Think of leaving your safe deposit box open for anyone with 'an ID' (any AWS principal) to access.
CloudTrail Organization Trails
Flip cardAn organization trail in AWS CloudTrail logs events for all AWS accounts in an AWS Organization, with centralized management and immutability from member accounts.
- Centralized logging for all accounts in an organization.
- Managed by the management account or a delegated administrator.
- Member accounts cannot disable, modify, or delete organization trails.
- Delivers logs to a single S3 bucket.
Memory trick: Organization Trails are the immutable logs for all accounts.
AWS Data Sovereignty Enforcement with SCPs
Flip cardAWS Organizations Service Control Policies (SCPs) are used to centrally manage permissions across multiple AWS accounts, enabling preventative controls to enforce data sovereignty by restricting resource provisioning to specific geographic regions.
- SCPs apply to all accounts in an Organizational Unit (OU) or the entire organization.
- They can deny actions like resource creation (e.g., S3 buckets, EC2 instances, Lambda functions) in specified AWS Regions.
- SCPs are preventative controls, ensuring compliance from the outset by preventing non-compliant actions.
Memory trick: SCPs Secure Sovereignty, Preventing Prohibited Provisioning.
IAM Roles for EC2
Flip cardAn IAM role that can be associated with an EC2 instance, allowing applications on the instance to securely make API calls to AWS services using temporary credentials.
- Provides temporary, automatically rotated credentials.
- Eliminates the need to store long-lived access keys on the instance.
- Credentials are retrieved via the EC2 instance metadata service.
- Enforces the principle of least privilege.
Memory trick: EC2 roles are the smart choice, no keys to voice.
Client-Side Encryption with On-Premises HSM
Flip cardClient-Side Encryption (CSE) integrated with an on-premises Hardware Security Module (HSM) allows an application to encrypt data locally using keys stored and managed exclusively within the on-premises HSM, ensuring keys never leave the HSM for cryptographic operations before data is sent to cloud storage.
- Data is encrypted at the application layer before being sent to AWS services like S3.
- Encryption keys are generated, stored, and used within the customer's on-premises HSM.
- Cryptographic operations are performed by the on-premises HSM, maintaining full key control.
- Ensures the highest level of key control and compliance for sensitive data.
Memory trick: Client-Side Cryptography Controls Keys Completely On-Premises.
Amazon Cognito Identity Pools (Federated Identities)
Flip cardCognito Identity Pools allow you to grant your users (authenticated or unauthenticated) temporary access to AWS services by exchanging tokens from identity providers (like User Pools) for AWS credentials.
- Provides temporary AWS credentials.
- Supports authenticated and unauthenticated access.
- Integrates with User Pools for identity management.
- Enables fine-grained access control using IAM policies and user attributes.
Memory trick: Identity Pools federate users to AWS with fine-grained roles.
RDS Data Residency
Flip cardEnsuring that Amazon RDS database instances and all associated data, including backups and snapshots, are stored and processed exclusively within a specific geographic AWS Region to comply with regulatory requirements.
- Data residency is enforced by selecting the appropriate AWS Region during resource provisioning.
- Multi-AZ deployments keep all data within the chosen Region.
- Automated backups and manual snapshots are also confined to the Region of the RDS instance.
Memory trick: Regional Residency Rules Restrict Remote Resources.
AWS Data Sovereignty Enforcement
Flip cardEnforcing data sovereignty on AWS involves preventing data from leaving specific geographic regions, often achieved through a combination of organizational boundaries, global policy controls, and resource-level restrictions.
- AWS Organizations SCPs are key for broad 'deny' rules.
- Separate AWS Accounts/OUs create clear administrative boundaries.
- S3 Bucket Policies can enforce region-specific API calls.
- Avoid services designed for cross-region data movement.
Memory trick: Separate 'Zones' with 'SCPs' and 'Bucket Guards' to keep data home.
S3 VPC Endpoint with Bucket Policy
Flip cardCombining an Amazon S3 VPC endpoint with a bucket policy containing the `aws:SourceVpce` condition to ensure S3 access is restricted to specific IAM roles and only originates from within a specified VPC, never over the public internet.
- VPC endpoints provide private connectivity to S3.
- `aws:SourceVpce` condition in a bucket policy restricts access to specific VPC endpoints.
- Bucket policies enforce access control at the S3 bucket level.
- Ensures data never traverses the public internet.
Memory trick: VPC Endpoint + SourceVpce locks S3.
CloudWatch Logs KMS Encryption
Flip cardAmazon CloudWatch Logs can encrypt log data at rest using AWS Key Management Service (KMS). This allows customers to use their own Customer Master Keys (CMKs) to encrypt log groups, providing control over key access and auditability.
- Configured per CloudWatch Log Group.
- Requires specifying `kmsKeyId` during creation or update.
- Leverages KMS for key management and audit trails.
- Default encryption uses AWS-managed keys.
Memory trick: To encrypt logs, 'Key' the 'Log Group' with KMS.
IAM Policy Evaluation Order
Flip cardThe specific sequence in which AWS IAM evaluates different policy types to determine whether a principal is allowed or denied access to a resource.
- Explicit Deny always overrides Explicit Allow.
- SCPs set the maximum permissions for an account.
- Permissions boundaries set the maximum permissions for an IAM entity.
- Implicit Deny occurs if no policy explicitly allows an action.
Memory trick: Think of a 'series of security checkpoints' where each type of policy is a gatekeeper, with Explicit Deny being the ultimate 'veto'.
KMS Envelope Encryption (Data Keys)
Flip cardAWS KMS uses envelope encryption, where a unique data key (DEK) is generated for each data object and used to encrypt the object. The DEK itself is then encrypted by a Customer Master Key (CMK) in KMS. This strategy limits the impact of a compromised DEK to a single object.
- Unique data key for every object.
- Data key encrypted by a CMK.
- CMK rotation does not re-encrypt data, only the data key.
- Minimizes blast radius of key compromise.
Memory trick: KMS 'envelopes' each object with its own 'unique key' for security.
IAM Role Trust Policy Conditions
Flip cardConditions in an IAM role's trust policy add constraints that must be met for a principal to successfully assume the role, such as requiring MFA or specific source IPs.
- Refine when `sts:AssumeRole` is allowed.
- Can include `aws:MultiFactorAuthPresent` to enforce MFA.
- Applied at the time of role assumption.
Memory trick: Trust policy conditions gate role assumption with MFA.
S3 Gateway VPC Endpoint with Bucket Policy
Flip cardAn S3 Gateway VPC Endpoint enables private connectivity from a VPC to Amazon S3, preventing traffic from traversing the public internet. An S3 bucket policy can then restrict access to only requests originating from this specific VPC endpoint.
- Provides a reliable and secure connection to S3 from a VPC.
- Traffic remains entirely within the AWS network.
- Bucket policies use the `aws:SourceVpce` condition key to enforce access via the endpoint.
Memory trick: Gateway Guards S3, Guiding Good VPC Traffic.
Amazon Cognito User Pools
Flip cardA managed user directory service for customer-facing web and mobile applications, supporting various authentication methods.
- Supports username/password, social logins (Google, Facebook, Apple), and SAML/OIDC identity providers.
- Provides user profiles with custom attributes.
- Integrates with Amazon Cognito Identity Pools for AWS resource access.
Memory trick: Think of Cognito as the 'front desk' for your app's users, handling their IDs and sign-ins.