Free knowledge base

AWS Certified Security – Specialty — key terms, tricks & tips

Everything from the course in one searchable place: 251 entries. Use it to review before a practice test or look up a word you forgot.

251 results

Key term

Multiple-choice

Question type with one correct answer from several options.

Getting Started: Exam Overview

Key term

Multiple-response

Question type requiring selection of two or more correct answers.

Getting Started: Exam Overview

Key term

Exam Guide

Official AWS document outlining exam content, domains, and topics.

Getting Started: Exam Overview

Key term

Domain Weighting

Percentage indicating the proportion of questions from a specific exam domain.

Getting Started: Exam Overview

Key term

Passing Score

Minimum score required to pass the certification exam (750 for SCS-C02).

Getting Started: Exam Overview

Key term

Scenario-based question

Questions presenting a real-world situation to test practical application of knowledge.

Getting Started: Exam Overview

Key term

Time Management

Strategically allocating time per question to complete the exam efficiently.

Getting Started: Exam Overview

Memory trick

Understanding the SCS-C02 Exam Format

To remember the exam domains and their weightings, think 'I LIKED Data'. I (Incident Response), L (Logging), I (Infrastructure), I (Identity), D (Data).

Getting Started: Exam Overview

Exam tip

Understanding the SCS-C02 Exam Format

The SCS-C02 exam has 65 questions and a 170-minute time limit. The passing score is 750 on a scale of 100-1000. Memorize the five domains and their approximate weightings: Incident Response (12%), Logging and Monitoring (20%), Infrastructure Security (26%), Identity and Access Management (20%), and Data Protection (22%).

Getting Started: Exam Overview

Common mistake

Understanding the SCS-C02 Exam Format

Not checking the official AWS SCS-C02 Exam Guide for the most current information.

Getting Started: Exam Overview

Common mistake

Understanding the SCS-C02 Exam Format

Spending too much time on a single difficult question, leading to not finishing the exam.

Getting Started: Exam Overview

Common mistake

Understanding the SCS-C02 Exam Format

Neglecting practice exams, which are crucial for understanding question style and pacing.

Getting Started: Exam Overview

Key term

Active Recall

Retrieving information from memory without cues.

Getting Started: Exam Overview

Key term

Spaced Repetition

Reviewing material at increasing intervals to improve retention.

Getting Started: Exam Overview

Key term

AWS Skill Builder

Official AWS platform for digital training and certification prep.

Getting Started: Exam Overview

Key term

Well-Architected Framework

AWS guidance for building secure, high-performing, resilient, efficient, and cost-effective systems.

Getting Started: Exam Overview

Key term

Hands-on Labs

Practical exercises using AWS services to gain experience.

Getting Started: Exam Overview

Key term

Practice Exams

Simulated tests to assess knowledge and identify gaps.

Getting Started: Exam Overview

Memory trick

Effective Study Strategies and Resources for SCS-C02

To remember the five domains: 'I Love Ice In Dry Places' (Incident Response, Logging and Monitoring, Infrastructure Security, Identity and Access Management, Data Protection).

Getting Started: Exam Overview

Exam tip

Effective Study Strategies and Resources for SCS-C02

The exam guide is your single most important resource. Memorize the five domains and their approximate weighting. Keywords like 'design,' 'implement,' 'troubleshoot,' and 'evaluate' indicate the level of expertise expected for each objective.

Getting Started: Exam Overview

Common mistake

Effective Study Strategies and Resources for SCS-C02

Relying solely on reading documentation without hands-on practice.

Getting Started: Exam Overview

Common mistake

Effective Study Strategies and Resources for SCS-C02

Not taking full-length practice exams under timed conditions.

Getting Started: Exam Overview

Common mistake

Effective Study Strategies and Resources for SCS-C02

Ignoring the official exam guide and whitepapers in favor of only third-party materials.

Getting Started: Exam Overview

Key term

Amazon GuardDuty

Threat detection service for AWS accounts and workloads.

Incident Response Fundamentals

Key term

AWS CloudTrail

Records API calls and events in your AWS account.

Incident Response Fundamentals

Key term

VPC Flow Logs

Captures IP traffic information for network interfaces in a VPC.

Incident Response Fundamentals

Key term

AWS Security Hub

Centralized view of security posture and findings.

Incident Response Fundamentals

Key term

Amazon CloudWatch Logs

Centralizes and monitors logs from various sources.

Incident Response Fundamentals

Key term

AWS Athena

Serverless query service for data in Amazon S3 using SQL.

Incident Response Fundamentals

Key term

Threat Intelligence

Information about known and emerging security threats.

Incident Response Fundamentals

Memory trick

Evaluating Incidents with AWS Security Services

To remember the core services: 'G-C-V-A-S' for GuardDuty, CloudTrail, VPC Flow Logs, Athena, Security Hub. It's like 'Give CVA Some' data to analyze!

Incident Response Fundamentals

Exam tip

Evaluating Incidents with AWS Security Services

The exam often presents scenarios where you need to choose the BEST AWS service for a specific incident response phase. For 'forensic data collection,' think CloudTrail and VPC Flow Logs. For 'threat detection,' think GuardDuty. For 'centralized security posture,' think Security Hub.

Incident Response Fundamentals

Common mistake

Evaluating Incidents with AWS Security Services

Failing to enable logging services (like CloudTrail or VPC Flow Logs) in advance, which means no data is available when an incident occurs.

Incident Response Fundamentals

Common mistake

Evaluating Incidents with AWS Security Services

Not centralizing security findings and logs, making it difficult to correlate events across different services and accounts.

Incident Response Fundamentals

Common mistake

Evaluating Incidents with AWS Security Services

Ignoring low-severity alerts, which can sometimes be precursors to larger, more significant security incidents.

Incident Response Fundamentals

Key term

Containment

Actions to stop the spread of an incident.

Incident Response Fundamentals

Key term

Eradication

Removing the root cause of an incident.

Incident Response Fundamentals

Key term

Recovery

Restoring systems to normal operation.

Incident Response Fundamentals

Key term

Forensic Analysis

Investigating an incident to understand its cause.

Incident Response Fundamentals

Key term

AWS Backup

Centralized backup service for AWS resources.

Incident Response Fundamentals

Key term

S3 Versioning

Keeps multiple versions of an object in S3.

Incident Response Fundamentals

Memory trick

Containing and Recovering from Incidents

CRER: 'C'almly 'R'estrict, 'E'radicate, 'R'ecover. Remember these three key phases in order!

Incident Response Fundamentals

Exam tip

Containing and Recovering from Incidents

The exam often tests your understanding of the incident response lifecycle phases and the specific AWS services applicable at each stage. Be ready to identify which service helps with containment (e.g., Security Groups, WAF), eradication (e.g., Inspector, GuardDuty for root cause), and recovery (e.g., AWS Backup, S3 Versioning).

Incident Response Fundamentals

Common mistake

Containing and Recovering from Incidents

Failing to fully eradicate the root cause, leading to re-infection.

Incident Response Fundamentals

Common mistake

Containing and Recovering from Incidents

Restoring systems from untrusted backups or before verifying the environment is clean.

Incident Response Fundamentals

Common mistake

Containing and Recovering from Incidents

Neglecting to document actions and lessons learned, hindering future incident response.

Incident Response Fundamentals

Key term

Event-Driven Automation

Actions triggered by specific security events.

Incident Response Fundamentals

Key term

Amazon EventBridge

Serverless event bus for routing events to targets.

Incident Response Fundamentals

Key term

AWS Lambda

Serverless compute service for running code in response to events.

Incident Response Fundamentals

Key term

AWS Systems Manager Automation

Orchestrates operational tasks across AWS resources.

Incident Response Fundamentals

Key term

Remediation Action

Automated steps to resolve or mitigate a security incident.

Incident Response Fundamentals

Key term

Isolation

Separating a compromised resource to prevent further damage.

Incident Response Fundamentals

Memory trick

Automating Incident Response Workflows

To remember the core services for automation: E.L.S.S. (EventBridge, Lambda, Security Hub, Systems Manager). Think of 'Elsa' from Frozen, building automated ice castles!

Incident Response Fundamentals

Exam tip

Automating Incident Response Workflows

The exam often tests your ability to choose the MOST appropriate AWS service for a given automation task. Pay close attention to the specific capabilities of EventBridge, Lambda, Security Hub, and Systems Manager Automation documents.

Incident Response Fundamentals

Common mistake

Automating Incident Response Workflows

Over-automating without proper testing, leading to unintended service disruptions.

Incident Response Fundamentals

Common mistake

Automating Incident Response Workflows

Not having human oversight or approval for destructive automated actions.

Incident Response Fundamentals

Common mistake

Automating Incident Response Workflows

Failing to log and audit automated actions for compliance and post-incident analysis.

Incident Response Fundamentals

Key term

Post-Incident Analysis (PIA)

Structured review of an incident to learn and improve.

Incident Response Fundamentals

Key term

Root Cause Analysis (RCA)

Process to identify the fundamental reason for an incident.

Incident Response Fundamentals

Key term

Lessons Learned

Key insights and actionable improvements from an incident.

Incident Response Fundamentals

Key term

MTTD (Mean Time To Detect)

Average time to identify a security incident.

Incident Response Fundamentals

Key term

MTTR (Mean Time To Respond)

Average time to contain and resolve an incident.

Incident Response Fundamentals

Key term

Blameless Post-Mortem

Review focused on process improvement, not individual error.

Incident Response Fundamentals

Key term

Actionable Recommendations

Specific, measurable steps to improve security posture.

Incident Response Fundamentals

Memory trick

Post-Incident Analysis and Reporting

REPORT: *R*eview, *E*valuate, *P*lan, *O*wnership, *R*eport, *T*rack. This helps remember the steps of post-incident reporting.

Incident Response Fundamentals

Exam tip

Post-Incident Analysis and Reporting

The exam often tests your understanding of the *purpose* of post-incident analysis (continuous improvement, learning, preventing recurrence) and the *components* of a good report (timeline, impact, root cause, recommendations). Be ready to identify key metrics like MTTD and MTTR.

Incident Response Fundamentals

Common mistake

Post-Incident Analysis and Reporting

Focusing on blaming individuals instead of improving processes and systems.

Incident Response Fundamentals

Common mistake

Post-Incident Analysis and Reporting

Failing to document findings and recommendations thoroughly, leading to lost lessons.

Incident Response Fundamentals

Common mistake

Post-Incident Analysis and Reporting

Not assigning clear ownership and deadlines for implementing corrective actions.

Incident Response Fundamentals

Common mistake

Post-Incident Analysis and Reporting

Skipping the post-incident review entirely due to urgency or perceived lack of time.

Incident Response Fundamentals

Key term

Log Aggregation

Consolidating logs from multiple sources into a central location.

Logging and Monitoring for Security

Key term

Log Retention

Policy defining how long logs are stored, often for compliance.

Logging and Monitoring for Security

Key term

Log Integrity

Ensuring logs are not tampered with, crucial for forensic evidence.

Logging and Monitoring for Security

Key term

S3 Object Lock

Prevents objects from being deleted or overwritten for a fixed time.

Logging and Monitoring for Security

Key term

Cross-Account Logging

Centralizing logs from multiple AWS accounts into a dedicated logging account.

Logging and Monitoring for Security

Memory trick

Designing and Implementing Security Logging

To remember the core logging services: C-V-C. CloudTrail (API Calls), VPC Flow Logs (Network Traffic), CloudWatch Logs (Application/System Logs).

Logging and Monitoring for Security

Exam tip

Designing and Implementing Security Logging

The exam frequently tests your knowledge of which AWS service provides which type of log data. Memorize that CloudTrail is for API calls/management events, VPC Flow Logs for network traffic, and CloudWatch Logs for application/system logs.

Logging and Monitoring for Security

Common mistake

Designing and Implementing Security Logging

Not enabling CloudTrail in all regions, potentially missing critical events.

Logging and Monitoring for Security

Common mistake

Designing and Implementing Security Logging

Failing to centralize logs, making analysis and incident response difficult and slow.

Logging and Monitoring for Security

Common mistake

Designing and Implementing Security Logging

Inadequate log retention policies, leading to compliance failures or inability to perform forensic analysis.

Logging and Monitoring for Security

Common mistake

Designing and Implementing Security Logging

Granting overly permissive access to log storage, compromising log integrity.

Logging and Monitoring for Security

Key term

CloudTrail

Logs API calls and events in your AWS account.

Logging and Monitoring for Security

Key term

Anomaly Detection

Identifying deviations from expected or normal behavior.

Logging and Monitoring for Security

Key term

Baselining

Establishing a normal pattern of activity for comparison.

Logging and Monitoring for Security

Key term

Security Hub

Centralized view of security alerts and posture.

Logging and Monitoring for Security

Key term

Correlation

Linking related events from different log sources.

Logging and Monitoring for Security

Memory trick

Analyzing Logs for Threat Detection

To remember key log sources: 'C-V-S' for CloudTrail, VPC Flow Logs, and S3 Access Logs – 'See Very Secure' data in your logs!

Logging and Monitoring for Security

Exam tip

Analyzing Logs for Threat Detection

The exam frequently asks about specific log sources for particular security events. Memorize which AWS service generates logs for API calls (CloudTrail), network traffic (VPC Flow Logs), and object access (S3 Access Logs). Understand how GuardDuty findings integrate with Security Hub.

Logging and Monitoring for Security

Common mistake

Analyzing Logs for Threat Detection

Failing to centralize logs from all relevant sources, leading to blind spots.

Logging and Monitoring for Security

Common mistake

Analyzing Logs for Threat Detection

Not establishing a baseline of normal activity, making it hard to identify anomalies.

Logging and Monitoring for Security

Common mistake

Analyzing Logs for Threat Detection

Over-relying on a single log source instead of correlating across multiple types.

Logging and Monitoring for Security

Key term

Log Delivery Errors

Metric indicating issues with log data reaching its destination.

Logging and Monitoring for Security

Key term

Insufficient Data

CloudWatch Alarm state when not enough data points are available.

Logging and Monitoring for Security

Key term

Resource Policy

Policy attached to a resource, defining who can access it.

Logging and Monitoring for Security

Key term

Service Quotas

Limits on resources, actions, or items in AWS accounts.

Logging and Monitoring for Security

Key term

CloudWatch Agent

Software to collect logs and metrics from EC2 instances.

Logging and Monitoring for Security

Key term

SNS Topic

A communication channel for publishing messages to subscribers.

Logging and Monitoring for Security

Memory trick

Troubleshooting Logging and Monitoring

To fix log issues, remember 'C.P.S. M.A.D.': **C**onfig, **P**ermissions, **S**ervice Health, **M**etrics, **A**lerts, **D**estination.

Logging and Monitoring for Security

Exam tip

Troubleshooting Logging and Monitoring

For the SCS-C02 exam, memorize the key CloudWatch metrics for CloudTrail and CloudWatch Logs that indicate delivery issues (e.g., `LogDeliveryErrors`, `IncomingLogEvents`). Understand how IAM and resource policies interact to grant logging permissions.

Logging and Monitoring for Security

Common mistake

Troubleshooting Logging and Monitoring

Forgetting to check resource policies on the destination (e.g., S3 bucket, CloudWatch Log Group) after verifying source service configuration.

Logging and Monitoring for Security

Common mistake

Troubleshooting Logging and Monitoring

Ignoring CloudWatch metrics for the logging services themselves (e.g., CloudTrail, CloudWatch Logs) which often show the first signs of trouble.

Logging and Monitoring for Security

Common mistake

Troubleshooting Logging and Monitoring

Assuming an alert failure is due to the metric, when the issue might be with the SNS topic or its subscribers.

Logging and Monitoring for Security

Key term

Amazon Macie

Discovers and protects sensitive data in S3 buckets.

Logging and Monitoring for Security

Key term

AWS Config

Monitors and records AWS resource configurations.

Logging and Monitoring for Security

Key term

CloudWatch Alarms

Triggers actions based on metric thresholds.

Logging and Monitoring for Security

Memory trick

Real-time Monitoring with AWS Services

To remember the core real-time monitoring services, think: 'C.G. M.A.C.S.' — CloudTrail, GuardDuty, Macie, Config, Security Hub. They're your monitoring 'MACS'!

Logging and Monitoring for Security

Exam tip

Real-time Monitoring with AWS Services

The exam frequently tests your knowledge of how different AWS security services integrate. Pay close attention to how CloudTrail, GuardDuty, Macie, Config, and Security Hub feed into each other and how EventBridge/Lambda are used for automated responses. Keywords like 'real-time threat detection', 'automated remediation', and 'centralized security posture' point to these integrations.

Logging and Monitoring for Security

Common mistake

Real-time Monitoring with AWS Services

Forgetting to enable logging for all relevant services (e.g., CloudTrail for all regions, S3 access logging).

Logging and Monitoring for Security

Common mistake

Real-time Monitoring with AWS Services

Not configuring CloudWatch Alarms or EventBridge rules to actually act on detected events, leading to 'alert fatigue' without action.

Logging and Monitoring for Security

Common mistake

Real-time Monitoring with AWS Services

Relying solely on one monitoring service instead of integrating multiple services for comprehensive coverage.

Logging and Monitoring for Security

Key term

VPC

Logically isolated section of the AWS Cloud.

Securing AWS Infrastructure

Key term

Subnet

Segment of a VPC's IP address range.

Securing AWS Infrastructure

Key term

NACL

Stateless firewall at the subnet level.

Securing AWS Infrastructure

Key term

Security Group

Stateful firewall at the instance level.

Securing AWS Infrastructure

Key term

VPC Endpoint

Private connection to AWS services from a VPC.

Securing AWS Infrastructure

Key term

PrivateLink

Enables private connectivity between VPCs and services.

Securing AWS Infrastructure

Key term

Public Subnet

Subnet with direct internet access via an Internet Gateway.

Securing AWS Infrastructure

Key term

Private Subnet

Subnet without direct internet access.

Securing AWS Infrastructure

Memory trick

Designing Secure Network Infrastructure

NACLs are 'Nasty' because they are stateless and deny everything by default, forcing you to be explicit. Security Groups are 'Safe' because they are stateful and easier to manage for instances.

Securing AWS Infrastructure

Exam tip

Designing Secure Network Infrastructure

The exam frequently tests the difference between Security Groups and NACLs. Remember: SGs are stateful, instance-level, allow-only. NACLs are stateless, subnet-level, and have explicit allow/deny rules evaluated by number.

Securing AWS Infrastructure

Common mistake

Designing Secure Network Infrastructure

Confusing Security Groups (stateful, instance-level) with NACLs (stateless, subnet-level).

Securing AWS Infrastructure

Common mistake

Designing Secure Network Infrastructure

Not configuring both inbound and outbound rules for NACLs, leading to unexpected traffic drops.

Securing AWS Infrastructure

Common mistake

Designing Secure Network Infrastructure

Over-permissive Security Group rules, especially allowing '0.0.0.0/0' unnecessarily.

Securing AWS Infrastructure

Common mistake

Designing Secure Network Infrastructure

Forgetting to update route tables when implementing VPC Endpoints, causing connectivity issues.

Securing AWS Infrastructure

Key term

IAM Role

Grants permissions to AWS services and resources.

Securing AWS Infrastructure

Key term

S3 Block Public Access

Prevents public access to S3 buckets and objects.

Securing AWS Infrastructure

Key term

SSE-KMS

Server-side encryption using AWS KMS managed keys.

Securing AWS Infrastructure

Key term

EBS Encryption

Encrypts EBS volumes and snapshots using KMS.

Securing AWS Infrastructure

Key term

Session Manager

Secure, auditable remote access to EC2 instances.

Securing AWS Infrastructure

Key term

Container Image Scan

Identifies vulnerabilities in container images.

Securing AWS Infrastructure

Memory trick

Securing Compute and Storage Resources

EC2: 'P.A.I.N.' - Patching, Access, IAM, Network. S3: 'B.A.D.D.E.' - Block Public Access, Access Control, Data Protection, Data Discovery, Encryption.

Securing AWS Infrastructure

Exam tip

Securing Compute and Storage Resources

The exam frequently tests S3 security. Pay close attention to the hierarchy of S3 access controls (IAM, Bucket Policy, ACLs, Block Public Access) and the different encryption options (SSE-S3, SSE-KMS, SSE-C). Remember that Block Public Access overrides other settings.

Securing AWS Infrastructure

Common mistake

Securing Compute and Storage Resources

Forgetting to encrypt EBS volumes, leaving data at rest vulnerable.

Securing AWS Infrastructure

Common mistake

Securing Compute and Storage Resources

Not enabling S3 Block Public Access, leading to accidental public buckets.

Securing AWS Infrastructure

Common mistake

Securing Compute and Storage Resources

Granting overly permissive IAM roles to EC2 instances or containers.

Securing AWS Infrastructure

Common mistake

Securing Compute and Storage Resources

Exposing EC2 instances directly to the internet via SSH/RDP instead of using Session Manager.

Securing AWS Infrastructure

Key term

API Gateway

A fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs.

Securing AWS Infrastructure

Key term

Lambda Authorizer

A Lambda function that controls access to your API Gateway API methods.

Securing AWS Infrastructure

Key term

Execution Role

An IAM role that grants an AWS Lambda function permissions to access AWS resources.

Securing AWS Infrastructure

Key term

Container Image Scanning

Analyzing container images for known vulnerabilities before deployment.

Securing AWS Infrastructure

Key term

AWS WAF

A web application firewall that helps protect web applications or APIs from common web exploits.

Securing AWS Infrastructure

Key term

AWS Secrets Manager

A service to protect access to your applications, services, and IT resources' secrets.

Securing AWS Infrastructure

Key term

VPC Link

Enables API Gateway to connect to private resources within a VPC.

Securing AWS Infrastructure

Memory trick

Implementing Secure Application Infrastructure

APIs are a GATEWAY to your app's SECRETS, so LAMBDA functions need strong ROLES, and CONTAINERS must be SCANNED for VULNERABILITIES.

Securing AWS Infrastructure

Exam tip

Implementing Secure Application Infrastructure

The exam frequently tests the integration of multiple security services. For API Gateway, remember its native integrations with WAF, Shield, Cognito, and Lambda authorizers. For Lambda, focus on execution roles, VPC configuration, and secrets management. Always prioritize least privilege.

Securing AWS Infrastructure

Common mistake

Implementing Secure Application Infrastructure

Over-permissioning Lambda execution roles, granting more access than necessary, which violates the principle of least privilege.

Securing AWS Infrastructure

Common mistake

Implementing Secure Application Infrastructure

Hardcoding sensitive credentials (like database passwords or API keys) directly into application code or environment variables instead of using AWS Secrets Manager or Parameter Store.

Securing AWS Infrastructure

Common mistake

Implementing Secure Application Infrastructure

Failing to enforce encryption in transit (e.g., not using HTTPS/TLS) for all application communication, leaving data vulnerable to eavesdropping.

Securing AWS Infrastructure

Common mistake

Implementing Secure Application Infrastructure

Not regularly scanning container images for vulnerabilities or using unverified base images, introducing known security flaws into the application.

Securing AWS Infrastructure

Key term

Shared Responsibility Model

Defines security responsibilities between AWS and the customer.

Securing AWS Infrastructure

Key term

AWS Organizations

Centrally manages multiple AWS accounts and applies policies.

Securing AWS Infrastructure

Key term

Service Control Policies (SCPs)

Define maximum permissions for accounts in an AWS Organization.

Securing AWS Infrastructure

Key term

AWS Audit Manager

Automates evidence collection for compliance audits.

Securing AWS Infrastructure

Key term

Compliance Framework

Set of guidelines or regulations for secure operations.

Securing AWS Infrastructure

Memory trick

Compliance and Governance in Infrastructure

SHARED: S-ecurity H-ardware A-WS R-esponsibility E-very D-ata (customer)

Securing AWS Infrastructure

Exam tip

Compliance and Governance in Infrastructure

The exam frequently tests the AWS Shared Responsibility Model. Remember: AWS is responsible for 'security OF the cloud' (infrastructure), and the customer is responsible for 'security IN the cloud' (data, configuration, applications). Know which services fall under customer responsibility for compliance (e.g., CloudTrail for auditing, Config for configuration management).

Securing AWS Infrastructure

Common mistake

Compliance and Governance in Infrastructure

Assuming AWS is solely responsible for all security aspects of workloads deployed in the cloud.

Securing AWS Infrastructure

Common mistake

Compliance and Governance in Infrastructure

Not understanding the difference between AWS's compliance certifications (OF the cloud) and the customer's responsibility to achieve compliance (IN the cloud).

Securing AWS Infrastructure

Common mistake

Compliance and Governance in Infrastructure

Failing to implement continuous monitoring and auditing, leading to compliance drift over time.

Securing AWS Infrastructure

Key term

Least Privilege

Granting only necessary permissions for a task.

Mastering Identity and Access Management

Key term

IAM User

An identity for a person or service with long-term credentials.

Mastering Identity and Access Management

Key term

IAM Group

A collection of IAM users to manage permissions efficiently.

Mastering Identity and Access Management

Key term

IAM Policy

A JSON document defining permissions for AWS resources.

Mastering Identity and Access Management

Key term

Federation

Allowing external identities to access AWS via an IdP.

Mastering Identity and Access Management

Key term

Root User

The most privileged account in AWS, never for daily use.

Mastering Identity and Access Management

Key term

MFA

Multi-Factor Authentication for enhanced security.

Mastering Identity and Access Management

Memory trick

Designing Secure IAM Solutions

R.O.L.E.S. for Security: **R**oot secured, **O**nly necessary permissions, **L**east privilege, **E**xternal federation, **S**trong MFA.

Mastering Identity and Access Management

Exam tip

Designing Secure IAM Solutions

The exam frequently tests scenarios involving the principle of least privilege, especially when comparing IAM users vs. roles. Look for keywords like 'temporary access,' 'cross-account,' or 'AWS service access' to indicate a role, and 'human user' or 'long-term credentials' for an IAM user. Always remember the root user's unique power and the best practices for its security.

Mastering Identity and Access Management

Common mistake

Designing Secure IAM Solutions

Granting 'AdministratorAccess' to IAM users or roles unnecessarily, violating least privilege.

Mastering Identity and Access Management

Common mistake

Designing Secure IAM Solutions

Using the AWS root user for daily administrative tasks instead of a dedicated IAM administrator user.

Mastering Identity and Access Management

Common mistake

Designing Secure IAM Solutions

Not enabling Multi-Factor Authentication (MFA) for the root user and all IAM users with elevated privileges.

Mastering Identity and Access Management

Common mistake

Designing Secure IAM Solutions

Attaching policies directly to IAM users instead of using groups or roles, leading to complex and difficult-to-manage permissions.

Mastering Identity and Access Management

Key term

Identity-based Policy

Policy attached to an IAM user, group, or role, defining what they can do.

Mastering Identity and Access Management

Key term

Resource-based Policy

Policy attached to a resource (e.g., S3 bucket), defining who can access it.

Mastering Identity and Access Management

Key term

Permissions Boundary

Advanced feature to set the maximum permissions an IAM identity can have.

Mastering Identity and Access Management

Key term

Service Control Policy (SCP)

AWS Organizations policy that sets maximum permissions for accounts.

Mastering Identity and Access Management

Key term

Implicit Deny

Default behavior when no explicit Allow or Deny policy applies.

Mastering Identity and Access Management

Memory trick

Managing Access to AWS Resources

D-A-I: Deny Always Wins. Allow is needed. Implicit Deny if neither.

Mastering Identity and Access Management

Exam tip

Managing Access to AWS Resources

The exam frequently tests policy evaluation logic. Remember: an explicit DENY always wins, even if there's an explicit ALLOW. If no explicit DENY, an explicit ALLOW is needed. Otherwise, it's implicitly denied.

Mastering Identity and Access Management

Common mistake

Managing Access to AWS Resources

Forgetting that an explicit DENY overrides any ALLOW, leading to unexpected access denials.

Mastering Identity and Access Management

Common mistake

Managing Access to AWS Resources

Granting overly broad permissions (e.g., 's3:*') instead of specific actions and resources.

Mastering Identity and Access Management

Common mistake

Managing Access to AWS Resources

Not regularly reviewing and updating policies, leading to stale or excessive permissions.

Mastering Identity and Access Management

Key term

Explicit Deny

A policy statement that specifically prohibits an action, overriding allows.

Mastering Identity and Access Management

Key term

IAM Policy Simulator

AWS tool to test the effects of IAM policies before deployment.

Mastering Identity and Access Management

Key term

IAM Access Analyzer

Identifies resources shared with external entities and validates policies.

Mastering Identity and Access Management

Key term

Permission Boundary

An advanced feature to set the maximum permissions an IAM entity can have.

Mastering Identity and Access Management

Memory trick

Troubleshooting IAM Issues

Remember the 'D.A.L.I.' rule for policy evaluation: Deny Always, then Look for Allows, else Implicitly Deny.

Mastering Identity and Access Management

Exam tip

Troubleshooting IAM Issues

For the SCS-C02 exam, be prepared to differentiate between the various policy types (identity-based, resource-based, permission boundaries, SCPs, session policies) and their evaluation order. Keywords to spot include 'explicit deny', 'implicit deny', 'maximum permissions', and 'organizational restrictions'. Remember that an explicit deny always takes precedence.

Mastering Identity and Access Management

Common mistake

Troubleshooting IAM Issues

Forgetting to check resource-based policies (e.g., S3 bucket policies, KMS key policies) when troubleshooting access to a specific resource.

Mastering Identity and Access Management

Common mistake

Troubleshooting IAM Issues

Ignoring the impact of Service Control Policies (SCPs) when an issue affects multiple accounts in an AWS Organization.

Mastering Identity and Access Management

Common mistake

Troubleshooting IAM Issues

Not using the IAM Policy Simulator or Access Analyzer before deploying policy changes, leading to unintended access or denials.

Mastering Identity and Access Management

Key term

Trust Policy

Part of an IAM role that specifies who can assume the role.

Mastering Identity and Access Management

Key term

ABAC

Attribute-Based Access Control; permissions based on tags.

Mastering Identity and Access Management

Memory trick

Advanced IAM Features and Best Practices

Roles are for 'Rolling' between accounts or services. SCPs 'Stop' actions at the organizational level. ABAC is 'About' Attributes (tags).

Mastering Identity and Access Management

Exam tip

Advanced IAM Features and Best Practices

The exam frequently tests the difference between IAM policies and SCPs. Remember: SCPs set guardrails (maximum permissions) at the Organization level and do not grant permissions; IAM policies grant permissions to identities within an account.

Mastering Identity and Access Management

Common mistake

Advanced IAM Features and Best Practices

Confusing IAM policies with SCPs: SCPs restrict, they don't grant. IAM policies grant permissions.

Mastering Identity and Access Management

Common mistake

Advanced IAM Features and Best Practices

Not enabling MFA for all users, especially root and administrators, leaving a critical attack vector open.

Mastering Identity and Access Management

Common mistake

Advanced IAM Features and Best Practices

Granting overly broad permissions (e.g., 's3:*') instead of adhering to the principle of least privilege.

Mastering Identity and Access Management

Key term

Data Classification

Categorizing data by sensitivity, value, and regulatory needs.

Comprehensive Data Protection

Key term

PII

Personally Identifiable Information; data that can identify an individual.

Comprehensive Data Protection

Key term

Data Owner

Individual or entity responsible for specific data and its protection.

Comprehensive Data Protection

Key term

Data Sensitivity

Measure of potential harm from unauthorized data disclosure.

Comprehensive Data Protection

Key term

AWS Tagging

Applying metadata labels to AWS resources for organization and control.

Comprehensive Data Protection

Memory trick

Designing Data Classification Solutions

To classify data, remember: 'P-I-C-R' – Public, Internal, Confidential, Restricted. It's like a security 'PICR' for your data!

Comprehensive Data Protection

Exam tip

Designing Data Classification Solutions

The exam often tests your ability to choose the most appropriate AWS service for data discovery and classification. Keywords to spot include 'discover sensitive data,' 'PII,' 'financial data,' and 'S3 buckets,' which strongly point to Amazon Macie. Remember Macie's primary focus is S3.

Comprehensive Data Protection

Common mistake

Designing Data Classification Solutions

Treating all data with the same level of security, which is either over-securing less sensitive data or under-securing highly sensitive data.

Comprehensive Data Protection

Common mistake

Designing Data Classification Solutions

Failing to regularly review and update data classification policies as data and regulations evolve.

Comprehensive Data Protection

Common mistake

Designing Data Classification Solutions

Not involving data owners in the classification process, leading to inaccurate or incomplete classifications.

Comprehensive Data Protection

Key term

Encryption at Rest

Encrypting data stored on persistent storage devices.

Comprehensive Data Protection

Key term

Encryption in Transit

Encrypting data as it moves between systems over a network.

Comprehensive Data Protection

Key term

AWS KMS

Managed service for creating and controlling encryption keys.

Comprehensive Data Protection

Key term

CMK

Customer Master Key, a primary key in KMS for encrypting other keys.

Comprehensive Data Protection

Key term

SSE-S3

Server-side encryption where AWS manages the encryption keys for S3.

Comprehensive Data Protection

Key term

Client-Side Encryption

Encrypting data before sending it to an AWS service.

Comprehensive Data Protection

Key term

TLS

Transport Layer Security, a protocol for encrypting network communications.

Comprehensive Data Protection

Memory trick

Implementing Data Encryption Strategies

KMS: Keep My Secrets safe. It's the central place for all your key management needs.

Comprehensive Data Protection

Exam tip

Implementing Data Encryption Strategies

The exam frequently tests on the distinction between SSE-S3, SSE-KMS, and SSE-C for S3, focusing on who manages the encryption key. Remember that SSE-S3 uses AWS-managed keys, SSE-KMS uses KMS-managed keys (which you control), and SSE-C uses customer-provided keys.

Comprehensive Data Protection

Common mistake

Implementing Data Encryption Strategies

Confusing the responsibility for key management between SSE-S3, SSE-KMS, and SSE-C. Always remember who controls the key.

Comprehensive Data Protection

Common mistake

Implementing Data Encryption Strategies

Forgetting to enable encryption for data in transit, assuming at-rest encryption is sufficient for all scenarios.

Comprehensive Data Protection

Common mistake

Implementing Data Encryption Strategies

Not understanding that while KMS manages the CMK, it doesn't directly encrypt your large data files; it provides data keys for that purpose.

Comprehensive Data Protection

Key term

Data Residency

Physical location where data is stored.

Comprehensive Data Protection

Key term

Data Sovereignty

Data subject to laws of its nation, regardless of storage.

Comprehensive Data Protection

Key term

AWS Region

Geographic area with multiple Availability Zones.

Comprehensive Data Protection

Key term

Availability Zone

Isolated data centers within an AWS Region.

Comprehensive Data Protection

Key term

GDPR

General Data Protection Regulation (EU data privacy law).

Comprehensive Data Protection

Key term

AWS Artifact

Portal for AWS compliance reports and certifications.

Comprehensive Data Protection

Key term

Data Processing Addendum

AWS contractual agreement on data protection.

Comprehensive Data Protection

Memory trick

Ensuring Data Residency and Sovereignty

Residency is 'R' for 'Region' (where it Rests). Sovereignty is 'S' for 'Subject to' (whose laws it's Subject to).

Comprehensive Data Protection

Exam tip

Ensuring Data Residency and Sovereignty

On the exam, expect questions that distinguish between data residency and data sovereignty. Keywords like 'physical location' or 'within a country' point to residency, while 'subject to national laws' or 'government access' indicate sovereignty. Know that AWS Regions are the primary mechanism for residency.

Comprehensive Data Protection

Common mistake

Ensuring Data Residency and Sovereignty

Confusing data residency with data sovereignty; they are related but distinct concepts.

Comprehensive Data Protection

Common mistake

Ensuring Data Residency and Sovereignty

Assuming that storing data in a local AWS Region automatically satisfies all data sovereignty requirements.

Comprehensive Data Protection

Common mistake

Ensuring Data Residency and Sovereignty

Neglecting to review applicable legal and regulatory frameworks before designing data storage solutions.

Comprehensive Data Protection

Key term

Data Exfiltration

Unauthorized transfer of data from a system or network.

Comprehensive Data Protection

Key term

AWS Macie

ML-powered service for sensitive data discovery and protection in S3.

Comprehensive Data Protection

Key term

AWS Network Firewall

Managed service providing stateful inspection and intrusion prevention.

Comprehensive Data Protection

Key term

S3 Bucket Policy

Resource-based policy to grant or deny access to an S3 bucket.

Comprehensive Data Protection

Memory trick

Preventing Data Loss with AWS Services

MACIE (M-onitor, A-nalyze, C-lassify, I-dentify, E-xamine) helps you remember Macie's core functions for data.

Comprehensive Data Protection

Exam tip

Preventing Data Loss with AWS Services

The exam often tests your understanding of which AWS service is best suited for a specific DLP task. For example, 'detecting PII in S3' immediately points to Macie, while 'monitoring network traffic' points to VPC Flow Logs. Know the primary function of each DLP service.

Comprehensive Data Protection

Common mistake

Preventing Data Loss with AWS Services

Failing to classify data before implementing DLP controls, leading to ineffective protection.

Comprehensive Data Protection

Common mistake

Preventing Data Loss with AWS Services

Relying solely on network-level controls without also securing access at the identity and resource level.

Comprehensive Data Protection

Common mistake

Preventing Data Loss with AWS Services

Not regularly reviewing and updating DLP policies as data types and business needs evolve.

Comprehensive Data Protection

Key term

Hybrid Cloud

An environment combining on-premises infrastructure with public cloud services.

Comprehensive Data Protection

Key term

Envelope Encryption

Encrypting data with a data key, then encrypting the data key with a master key.

Comprehensive Data Protection

Key term

AWS CloudHSM

A dedicated, FIPS 140-2 Level 3 validated hardware security module in AWS.

Comprehensive Data Protection

Key term

AWS Lake Formation

Service to build, secure, and manage data lakes on AWS.

Comprehensive Data Protection

Key term

Differential Privacy

Techniques to obscure individual data points while retaining statistical properties.

Comprehensive Data Protection

Memory trick

Advanced Data Protection Scenarios

For advanced data protection, think 'CHAMP': Compliance, Hybrid, Advanced Encryption, ML/Analytics, Protection (Incident Response).

Comprehensive Data Protection

Exam tip

Advanced Data Protection Scenarios

The exam often presents scenarios involving specific compliance frameworks (e.g., HIPAA, PCI DSS, GDPR). Be prepared to identify which AWS services and features directly address requirements like data residency, auditability, and strong key management (KMS, CloudHSM).

Comprehensive Data Protection

Common mistake

Advanced Data Protection Scenarios

Assuming AWS is solely responsible for compliance; customers share responsibility.

Comprehensive Data Protection

Common mistake

Advanced Data Protection Scenarios

Neglecting to secure data in transit in hybrid environments, focusing only on data at rest.

Comprehensive Data Protection

Common mistake

Advanced Data Protection Scenarios

Underestimating the complexity of key management for advanced encryption scenarios.

Comprehensive Data Protection