Multiple-choice
Question type with one correct answer from several options.
Getting Started: Exam Overview
Free knowledge base
Everything from the course in one searchable place: 251 entries. Use it to review before a practice test or look up a word you forgot.
251 results
Question type with one correct answer from several options.
Getting Started: Exam Overview
Question type requiring selection of two or more correct answers.
Getting Started: Exam Overview
Official AWS document outlining exam content, domains, and topics.
Getting Started: Exam Overview
Percentage indicating the proportion of questions from a specific exam domain.
Getting Started: Exam Overview
Minimum score required to pass the certification exam (750 for SCS-C02).
Getting Started: Exam Overview
Questions presenting a real-world situation to test practical application of knowledge.
Getting Started: Exam Overview
Strategically allocating time per question to complete the exam efficiently.
Getting Started: Exam Overview
To remember the exam domains and their weightings, think 'I LIKED Data'. I (Incident Response), L (Logging), I (Infrastructure), I (Identity), D (Data).
Getting Started: Exam Overview
The SCS-C02 exam has 65 questions and a 170-minute time limit. The passing score is 750 on a scale of 100-1000. Memorize the five domains and their approximate weightings: Incident Response (12%), Logging and Monitoring (20%), Infrastructure Security (26%), Identity and Access Management (20%), and Data Protection (22%).
Getting Started: Exam Overview
Not checking the official AWS SCS-C02 Exam Guide for the most current information.
Getting Started: Exam Overview
Spending too much time on a single difficult question, leading to not finishing the exam.
Getting Started: Exam Overview
Neglecting practice exams, which are crucial for understanding question style and pacing.
Getting Started: Exam Overview
Retrieving information from memory without cues.
Getting Started: Exam Overview
Reviewing material at increasing intervals to improve retention.
Getting Started: Exam Overview
Official AWS platform for digital training and certification prep.
Getting Started: Exam Overview
AWS guidance for building secure, high-performing, resilient, efficient, and cost-effective systems.
Getting Started: Exam Overview
Practical exercises using AWS services to gain experience.
Getting Started: Exam Overview
Simulated tests to assess knowledge and identify gaps.
Getting Started: Exam Overview
To remember the five domains: 'I Love Ice In Dry Places' (Incident Response, Logging and Monitoring, Infrastructure Security, Identity and Access Management, Data Protection).
Getting Started: Exam Overview
The exam guide is your single most important resource. Memorize the five domains and their approximate weighting. Keywords like 'design,' 'implement,' 'troubleshoot,' and 'evaluate' indicate the level of expertise expected for each objective.
Getting Started: Exam Overview
Relying solely on reading documentation without hands-on practice.
Getting Started: Exam Overview
Not taking full-length practice exams under timed conditions.
Getting Started: Exam Overview
Ignoring the official exam guide and whitepapers in favor of only third-party materials.
Getting Started: Exam Overview
Threat detection service for AWS accounts and workloads.
Incident Response Fundamentals
Records API calls and events in your AWS account.
Incident Response Fundamentals
Captures IP traffic information for network interfaces in a VPC.
Incident Response Fundamentals
Centralized view of security posture and findings.
Incident Response Fundamentals
Centralizes and monitors logs from various sources.
Incident Response Fundamentals
Serverless query service for data in Amazon S3 using SQL.
Incident Response Fundamentals
Information about known and emerging security threats.
Incident Response Fundamentals
To remember the core services: 'G-C-V-A-S' for GuardDuty, CloudTrail, VPC Flow Logs, Athena, Security Hub. It's like 'Give CVA Some' data to analyze!
Incident Response Fundamentals
The exam often presents scenarios where you need to choose the BEST AWS service for a specific incident response phase. For 'forensic data collection,' think CloudTrail and VPC Flow Logs. For 'threat detection,' think GuardDuty. For 'centralized security posture,' think Security Hub.
Incident Response Fundamentals
Failing to enable logging services (like CloudTrail or VPC Flow Logs) in advance, which means no data is available when an incident occurs.
Incident Response Fundamentals
Not centralizing security findings and logs, making it difficult to correlate events across different services and accounts.
Incident Response Fundamentals
Ignoring low-severity alerts, which can sometimes be precursors to larger, more significant security incidents.
Incident Response Fundamentals
Actions to stop the spread of an incident.
Incident Response Fundamentals
Removing the root cause of an incident.
Incident Response Fundamentals
Restoring systems to normal operation.
Incident Response Fundamentals
Investigating an incident to understand its cause.
Incident Response Fundamentals
Centralized backup service for AWS resources.
Incident Response Fundamentals
Keeps multiple versions of an object in S3.
Incident Response Fundamentals
CRER: 'C'almly 'R'estrict, 'E'radicate, 'R'ecover. Remember these three key phases in order!
Incident Response Fundamentals
The exam often tests your understanding of the incident response lifecycle phases and the specific AWS services applicable at each stage. Be ready to identify which service helps with containment (e.g., Security Groups, WAF), eradication (e.g., Inspector, GuardDuty for root cause), and recovery (e.g., AWS Backup, S3 Versioning).
Incident Response Fundamentals
Failing to fully eradicate the root cause, leading to re-infection.
Incident Response Fundamentals
Restoring systems from untrusted backups or before verifying the environment is clean.
Incident Response Fundamentals
Neglecting to document actions and lessons learned, hindering future incident response.
Incident Response Fundamentals
Actions triggered by specific security events.
Incident Response Fundamentals
Serverless event bus for routing events to targets.
Incident Response Fundamentals
Serverless compute service for running code in response to events.
Incident Response Fundamentals
Orchestrates operational tasks across AWS resources.
Incident Response Fundamentals
Automated steps to resolve or mitigate a security incident.
Incident Response Fundamentals
Separating a compromised resource to prevent further damage.
Incident Response Fundamentals
To remember the core services for automation: E.L.S.S. (EventBridge, Lambda, Security Hub, Systems Manager). Think of 'Elsa' from Frozen, building automated ice castles!
Incident Response Fundamentals
The exam often tests your ability to choose the MOST appropriate AWS service for a given automation task. Pay close attention to the specific capabilities of EventBridge, Lambda, Security Hub, and Systems Manager Automation documents.
Incident Response Fundamentals
Over-automating without proper testing, leading to unintended service disruptions.
Incident Response Fundamentals
Not having human oversight or approval for destructive automated actions.
Incident Response Fundamentals
Failing to log and audit automated actions for compliance and post-incident analysis.
Incident Response Fundamentals
Structured review of an incident to learn and improve.
Incident Response Fundamentals
Process to identify the fundamental reason for an incident.
Incident Response Fundamentals
Key insights and actionable improvements from an incident.
Incident Response Fundamentals
Average time to identify a security incident.
Incident Response Fundamentals
Average time to contain and resolve an incident.
Incident Response Fundamentals
Review focused on process improvement, not individual error.
Incident Response Fundamentals
Specific, measurable steps to improve security posture.
Incident Response Fundamentals
REPORT: *R*eview, *E*valuate, *P*lan, *O*wnership, *R*eport, *T*rack. This helps remember the steps of post-incident reporting.
Incident Response Fundamentals
The exam often tests your understanding of the *purpose* of post-incident analysis (continuous improvement, learning, preventing recurrence) and the *components* of a good report (timeline, impact, root cause, recommendations). Be ready to identify key metrics like MTTD and MTTR.
Incident Response Fundamentals
Focusing on blaming individuals instead of improving processes and systems.
Incident Response Fundamentals
Failing to document findings and recommendations thoroughly, leading to lost lessons.
Incident Response Fundamentals
Not assigning clear ownership and deadlines for implementing corrective actions.
Incident Response Fundamentals
Skipping the post-incident review entirely due to urgency or perceived lack of time.
Incident Response Fundamentals
Consolidating logs from multiple sources into a central location.
Logging and Monitoring for Security
Policy defining how long logs are stored, often for compliance.
Logging and Monitoring for Security
Ensuring logs are not tampered with, crucial for forensic evidence.
Logging and Monitoring for Security
Prevents objects from being deleted or overwritten for a fixed time.
Logging and Monitoring for Security
Centralizing logs from multiple AWS accounts into a dedicated logging account.
Logging and Monitoring for Security
To remember the core logging services: C-V-C. CloudTrail (API Calls), VPC Flow Logs (Network Traffic), CloudWatch Logs (Application/System Logs).
Logging and Monitoring for Security
The exam frequently tests your knowledge of which AWS service provides which type of log data. Memorize that CloudTrail is for API calls/management events, VPC Flow Logs for network traffic, and CloudWatch Logs for application/system logs.
Logging and Monitoring for Security
Not enabling CloudTrail in all regions, potentially missing critical events.
Logging and Monitoring for Security
Failing to centralize logs, making analysis and incident response difficult and slow.
Logging and Monitoring for Security
Inadequate log retention policies, leading to compliance failures or inability to perform forensic analysis.
Logging and Monitoring for Security
Granting overly permissive access to log storage, compromising log integrity.
Logging and Monitoring for Security
Logs API calls and events in your AWS account.
Logging and Monitoring for Security
Identifying deviations from expected or normal behavior.
Logging and Monitoring for Security
Establishing a normal pattern of activity for comparison.
Logging and Monitoring for Security
Centralized view of security alerts and posture.
Logging and Monitoring for Security
Linking related events from different log sources.
Logging and Monitoring for Security
To remember key log sources: 'C-V-S' for CloudTrail, VPC Flow Logs, and S3 Access Logs – 'See Very Secure' data in your logs!
Logging and Monitoring for Security
The exam frequently asks about specific log sources for particular security events. Memorize which AWS service generates logs for API calls (CloudTrail), network traffic (VPC Flow Logs), and object access (S3 Access Logs). Understand how GuardDuty findings integrate with Security Hub.
Logging and Monitoring for Security
Failing to centralize logs from all relevant sources, leading to blind spots.
Logging and Monitoring for Security
Not establishing a baseline of normal activity, making it hard to identify anomalies.
Logging and Monitoring for Security
Over-relying on a single log source instead of correlating across multiple types.
Logging and Monitoring for Security
Metric indicating issues with log data reaching its destination.
Logging and Monitoring for Security
CloudWatch Alarm state when not enough data points are available.
Logging and Monitoring for Security
Policy attached to a resource, defining who can access it.
Logging and Monitoring for Security
Limits on resources, actions, or items in AWS accounts.
Logging and Monitoring for Security
Software to collect logs and metrics from EC2 instances.
Logging and Monitoring for Security
A communication channel for publishing messages to subscribers.
Logging and Monitoring for Security
To fix log issues, remember 'C.P.S. M.A.D.': **C**onfig, **P**ermissions, **S**ervice Health, **M**etrics, **A**lerts, **D**estination.
Logging and Monitoring for Security
For the SCS-C02 exam, memorize the key CloudWatch metrics for CloudTrail and CloudWatch Logs that indicate delivery issues (e.g., `LogDeliveryErrors`, `IncomingLogEvents`). Understand how IAM and resource policies interact to grant logging permissions.
Logging and Monitoring for Security
Forgetting to check resource policies on the destination (e.g., S3 bucket, CloudWatch Log Group) after verifying source service configuration.
Logging and Monitoring for Security
Ignoring CloudWatch metrics for the logging services themselves (e.g., CloudTrail, CloudWatch Logs) which often show the first signs of trouble.
Logging and Monitoring for Security
Assuming an alert failure is due to the metric, when the issue might be with the SNS topic or its subscribers.
Logging and Monitoring for Security
Discovers and protects sensitive data in S3 buckets.
Logging and Monitoring for Security
Monitors and records AWS resource configurations.
Logging and Monitoring for Security
Triggers actions based on metric thresholds.
Logging and Monitoring for Security
To remember the core real-time monitoring services, think: 'C.G. M.A.C.S.' — CloudTrail, GuardDuty, Macie, Config, Security Hub. They're your monitoring 'MACS'!
Logging and Monitoring for Security
The exam frequently tests your knowledge of how different AWS security services integrate. Pay close attention to how CloudTrail, GuardDuty, Macie, Config, and Security Hub feed into each other and how EventBridge/Lambda are used for automated responses. Keywords like 'real-time threat detection', 'automated remediation', and 'centralized security posture' point to these integrations.
Logging and Monitoring for Security
Forgetting to enable logging for all relevant services (e.g., CloudTrail for all regions, S3 access logging).
Logging and Monitoring for Security
Not configuring CloudWatch Alarms or EventBridge rules to actually act on detected events, leading to 'alert fatigue' without action.
Logging and Monitoring for Security
Relying solely on one monitoring service instead of integrating multiple services for comprehensive coverage.
Logging and Monitoring for Security
Logically isolated section of the AWS Cloud.
Securing AWS Infrastructure
Segment of a VPC's IP address range.
Securing AWS Infrastructure
Stateless firewall at the subnet level.
Securing AWS Infrastructure
Stateful firewall at the instance level.
Securing AWS Infrastructure
Private connection to AWS services from a VPC.
Securing AWS Infrastructure
Enables private connectivity between VPCs and services.
Securing AWS Infrastructure
Subnet with direct internet access via an Internet Gateway.
Securing AWS Infrastructure
Subnet without direct internet access.
Securing AWS Infrastructure
NACLs are 'Nasty' because they are stateless and deny everything by default, forcing you to be explicit. Security Groups are 'Safe' because they are stateful and easier to manage for instances.
Securing AWS Infrastructure
The exam frequently tests the difference between Security Groups and NACLs. Remember: SGs are stateful, instance-level, allow-only. NACLs are stateless, subnet-level, and have explicit allow/deny rules evaluated by number.
Securing AWS Infrastructure
Confusing Security Groups (stateful, instance-level) with NACLs (stateless, subnet-level).
Securing AWS Infrastructure
Not configuring both inbound and outbound rules for NACLs, leading to unexpected traffic drops.
Securing AWS Infrastructure
Over-permissive Security Group rules, especially allowing '0.0.0.0/0' unnecessarily.
Securing AWS Infrastructure
Forgetting to update route tables when implementing VPC Endpoints, causing connectivity issues.
Securing AWS Infrastructure
Grants permissions to AWS services and resources.
Securing AWS Infrastructure
Prevents public access to S3 buckets and objects.
Securing AWS Infrastructure
Server-side encryption using AWS KMS managed keys.
Securing AWS Infrastructure
Encrypts EBS volumes and snapshots using KMS.
Securing AWS Infrastructure
Secure, auditable remote access to EC2 instances.
Securing AWS Infrastructure
Identifies vulnerabilities in container images.
Securing AWS Infrastructure
EC2: 'P.A.I.N.' - Patching, Access, IAM, Network. S3: 'B.A.D.D.E.' - Block Public Access, Access Control, Data Protection, Data Discovery, Encryption.
Securing AWS Infrastructure
The exam frequently tests S3 security. Pay close attention to the hierarchy of S3 access controls (IAM, Bucket Policy, ACLs, Block Public Access) and the different encryption options (SSE-S3, SSE-KMS, SSE-C). Remember that Block Public Access overrides other settings.
Securing AWS Infrastructure
Forgetting to encrypt EBS volumes, leaving data at rest vulnerable.
Securing AWS Infrastructure
Not enabling S3 Block Public Access, leading to accidental public buckets.
Securing AWS Infrastructure
Granting overly permissive IAM roles to EC2 instances or containers.
Securing AWS Infrastructure
Exposing EC2 instances directly to the internet via SSH/RDP instead of using Session Manager.
Securing AWS Infrastructure
A fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs.
Securing AWS Infrastructure
A Lambda function that controls access to your API Gateway API methods.
Securing AWS Infrastructure
An IAM role that grants an AWS Lambda function permissions to access AWS resources.
Securing AWS Infrastructure
Analyzing container images for known vulnerabilities before deployment.
Securing AWS Infrastructure
A web application firewall that helps protect web applications or APIs from common web exploits.
Securing AWS Infrastructure
A service to protect access to your applications, services, and IT resources' secrets.
Securing AWS Infrastructure
Enables API Gateway to connect to private resources within a VPC.
Securing AWS Infrastructure
APIs are a GATEWAY to your app's SECRETS, so LAMBDA functions need strong ROLES, and CONTAINERS must be SCANNED for VULNERABILITIES.
Securing AWS Infrastructure
The exam frequently tests the integration of multiple security services. For API Gateway, remember its native integrations with WAF, Shield, Cognito, and Lambda authorizers. For Lambda, focus on execution roles, VPC configuration, and secrets management. Always prioritize least privilege.
Securing AWS Infrastructure
Over-permissioning Lambda execution roles, granting more access than necessary, which violates the principle of least privilege.
Securing AWS Infrastructure
Hardcoding sensitive credentials (like database passwords or API keys) directly into application code or environment variables instead of using AWS Secrets Manager or Parameter Store.
Securing AWS Infrastructure
Failing to enforce encryption in transit (e.g., not using HTTPS/TLS) for all application communication, leaving data vulnerable to eavesdropping.
Securing AWS Infrastructure
Not regularly scanning container images for vulnerabilities or using unverified base images, introducing known security flaws into the application.
Securing AWS Infrastructure
Defines security responsibilities between AWS and the customer.
Securing AWS Infrastructure
Centrally manages multiple AWS accounts and applies policies.
Securing AWS Infrastructure
Define maximum permissions for accounts in an AWS Organization.
Securing AWS Infrastructure
Automates evidence collection for compliance audits.
Securing AWS Infrastructure
Set of guidelines or regulations for secure operations.
Securing AWS Infrastructure
SHARED: S-ecurity H-ardware A-WS R-esponsibility E-very D-ata (customer)
Securing AWS Infrastructure
The exam frequently tests the AWS Shared Responsibility Model. Remember: AWS is responsible for 'security OF the cloud' (infrastructure), and the customer is responsible for 'security IN the cloud' (data, configuration, applications). Know which services fall under customer responsibility for compliance (e.g., CloudTrail for auditing, Config for configuration management).
Securing AWS Infrastructure
Assuming AWS is solely responsible for all security aspects of workloads deployed in the cloud.
Securing AWS Infrastructure
Not understanding the difference between AWS's compliance certifications (OF the cloud) and the customer's responsibility to achieve compliance (IN the cloud).
Securing AWS Infrastructure
Failing to implement continuous monitoring and auditing, leading to compliance drift over time.
Securing AWS Infrastructure
Granting only necessary permissions for a task.
Mastering Identity and Access Management
An identity for a person or service with long-term credentials.
Mastering Identity and Access Management
A collection of IAM users to manage permissions efficiently.
Mastering Identity and Access Management
A JSON document defining permissions for AWS resources.
Mastering Identity and Access Management
Allowing external identities to access AWS via an IdP.
Mastering Identity and Access Management
The most privileged account in AWS, never for daily use.
Mastering Identity and Access Management
Multi-Factor Authentication for enhanced security.
Mastering Identity and Access Management
R.O.L.E.S. for Security: **R**oot secured, **O**nly necessary permissions, **L**east privilege, **E**xternal federation, **S**trong MFA.
Mastering Identity and Access Management
The exam frequently tests scenarios involving the principle of least privilege, especially when comparing IAM users vs. roles. Look for keywords like 'temporary access,' 'cross-account,' or 'AWS service access' to indicate a role, and 'human user' or 'long-term credentials' for an IAM user. Always remember the root user's unique power and the best practices for its security.
Mastering Identity and Access Management
Granting 'AdministratorAccess' to IAM users or roles unnecessarily, violating least privilege.
Mastering Identity and Access Management
Using the AWS root user for daily administrative tasks instead of a dedicated IAM administrator user.
Mastering Identity and Access Management
Not enabling Multi-Factor Authentication (MFA) for the root user and all IAM users with elevated privileges.
Mastering Identity and Access Management
Attaching policies directly to IAM users instead of using groups or roles, leading to complex and difficult-to-manage permissions.
Mastering Identity and Access Management
Policy attached to an IAM user, group, or role, defining what they can do.
Mastering Identity and Access Management
Policy attached to a resource (e.g., S3 bucket), defining who can access it.
Mastering Identity and Access Management
Advanced feature to set the maximum permissions an IAM identity can have.
Mastering Identity and Access Management
AWS Organizations policy that sets maximum permissions for accounts.
Mastering Identity and Access Management
Default behavior when no explicit Allow or Deny policy applies.
Mastering Identity and Access Management
D-A-I: Deny Always Wins. Allow is needed. Implicit Deny if neither.
Mastering Identity and Access Management
The exam frequently tests policy evaluation logic. Remember: an explicit DENY always wins, even if there's an explicit ALLOW. If no explicit DENY, an explicit ALLOW is needed. Otherwise, it's implicitly denied.
Mastering Identity and Access Management
Forgetting that an explicit DENY overrides any ALLOW, leading to unexpected access denials.
Mastering Identity and Access Management
Granting overly broad permissions (e.g., 's3:*') instead of specific actions and resources.
Mastering Identity and Access Management
Not regularly reviewing and updating policies, leading to stale or excessive permissions.
Mastering Identity and Access Management
A policy statement that specifically prohibits an action, overriding allows.
Mastering Identity and Access Management
AWS tool to test the effects of IAM policies before deployment.
Mastering Identity and Access Management
Identifies resources shared with external entities and validates policies.
Mastering Identity and Access Management
An advanced feature to set the maximum permissions an IAM entity can have.
Mastering Identity and Access Management
Remember the 'D.A.L.I.' rule for policy evaluation: Deny Always, then Look for Allows, else Implicitly Deny.
Mastering Identity and Access Management
For the SCS-C02 exam, be prepared to differentiate between the various policy types (identity-based, resource-based, permission boundaries, SCPs, session policies) and their evaluation order. Keywords to spot include 'explicit deny', 'implicit deny', 'maximum permissions', and 'organizational restrictions'. Remember that an explicit deny always takes precedence.
Mastering Identity and Access Management
Forgetting to check resource-based policies (e.g., S3 bucket policies, KMS key policies) when troubleshooting access to a specific resource.
Mastering Identity and Access Management
Ignoring the impact of Service Control Policies (SCPs) when an issue affects multiple accounts in an AWS Organization.
Mastering Identity and Access Management
Not using the IAM Policy Simulator or Access Analyzer before deploying policy changes, leading to unintended access or denials.
Mastering Identity and Access Management
Part of an IAM role that specifies who can assume the role.
Mastering Identity and Access Management
Attribute-Based Access Control; permissions based on tags.
Mastering Identity and Access Management
Roles are for 'Rolling' between accounts or services. SCPs 'Stop' actions at the organizational level. ABAC is 'About' Attributes (tags).
Mastering Identity and Access Management
The exam frequently tests the difference between IAM policies and SCPs. Remember: SCPs set guardrails (maximum permissions) at the Organization level and do not grant permissions; IAM policies grant permissions to identities within an account.
Mastering Identity and Access Management
Confusing IAM policies with SCPs: SCPs restrict, they don't grant. IAM policies grant permissions.
Mastering Identity and Access Management
Not enabling MFA for all users, especially root and administrators, leaving a critical attack vector open.
Mastering Identity and Access Management
Granting overly broad permissions (e.g., 's3:*') instead of adhering to the principle of least privilege.
Mastering Identity and Access Management
Categorizing data by sensitivity, value, and regulatory needs.
Comprehensive Data Protection
Personally Identifiable Information; data that can identify an individual.
Comprehensive Data Protection
Individual or entity responsible for specific data and its protection.
Comprehensive Data Protection
Measure of potential harm from unauthorized data disclosure.
Comprehensive Data Protection
Applying metadata labels to AWS resources for organization and control.
Comprehensive Data Protection
To classify data, remember: 'P-I-C-R' – Public, Internal, Confidential, Restricted. It's like a security 'PICR' for your data!
Comprehensive Data Protection
The exam often tests your ability to choose the most appropriate AWS service for data discovery and classification. Keywords to spot include 'discover sensitive data,' 'PII,' 'financial data,' and 'S3 buckets,' which strongly point to Amazon Macie. Remember Macie's primary focus is S3.
Comprehensive Data Protection
Treating all data with the same level of security, which is either over-securing less sensitive data or under-securing highly sensitive data.
Comprehensive Data Protection
Failing to regularly review and update data classification policies as data and regulations evolve.
Comprehensive Data Protection
Not involving data owners in the classification process, leading to inaccurate or incomplete classifications.
Comprehensive Data Protection
Encrypting data stored on persistent storage devices.
Comprehensive Data Protection
Encrypting data as it moves between systems over a network.
Comprehensive Data Protection
Managed service for creating and controlling encryption keys.
Comprehensive Data Protection
Customer Master Key, a primary key in KMS for encrypting other keys.
Comprehensive Data Protection
Server-side encryption where AWS manages the encryption keys for S3.
Comprehensive Data Protection
Encrypting data before sending it to an AWS service.
Comprehensive Data Protection
Transport Layer Security, a protocol for encrypting network communications.
Comprehensive Data Protection
KMS: Keep My Secrets safe. It's the central place for all your key management needs.
Comprehensive Data Protection
The exam frequently tests on the distinction between SSE-S3, SSE-KMS, and SSE-C for S3, focusing on who manages the encryption key. Remember that SSE-S3 uses AWS-managed keys, SSE-KMS uses KMS-managed keys (which you control), and SSE-C uses customer-provided keys.
Comprehensive Data Protection
Confusing the responsibility for key management between SSE-S3, SSE-KMS, and SSE-C. Always remember who controls the key.
Comprehensive Data Protection
Forgetting to enable encryption for data in transit, assuming at-rest encryption is sufficient for all scenarios.
Comprehensive Data Protection
Not understanding that while KMS manages the CMK, it doesn't directly encrypt your large data files; it provides data keys for that purpose.
Comprehensive Data Protection
Physical location where data is stored.
Comprehensive Data Protection
Data subject to laws of its nation, regardless of storage.
Comprehensive Data Protection
Geographic area with multiple Availability Zones.
Comprehensive Data Protection
Isolated data centers within an AWS Region.
Comprehensive Data Protection
General Data Protection Regulation (EU data privacy law).
Comprehensive Data Protection
Portal for AWS compliance reports and certifications.
Comprehensive Data Protection
AWS contractual agreement on data protection.
Comprehensive Data Protection
Residency is 'R' for 'Region' (where it Rests). Sovereignty is 'S' for 'Subject to' (whose laws it's Subject to).
Comprehensive Data Protection
On the exam, expect questions that distinguish between data residency and data sovereignty. Keywords like 'physical location' or 'within a country' point to residency, while 'subject to national laws' or 'government access' indicate sovereignty. Know that AWS Regions are the primary mechanism for residency.
Comprehensive Data Protection
Confusing data residency with data sovereignty; they are related but distinct concepts.
Comprehensive Data Protection
Assuming that storing data in a local AWS Region automatically satisfies all data sovereignty requirements.
Comprehensive Data Protection
Neglecting to review applicable legal and regulatory frameworks before designing data storage solutions.
Comprehensive Data Protection
Unauthorized transfer of data from a system or network.
Comprehensive Data Protection
ML-powered service for sensitive data discovery and protection in S3.
Comprehensive Data Protection
Managed service providing stateful inspection and intrusion prevention.
Comprehensive Data Protection
Resource-based policy to grant or deny access to an S3 bucket.
Comprehensive Data Protection
MACIE (M-onitor, A-nalyze, C-lassify, I-dentify, E-xamine) helps you remember Macie's core functions for data.
Comprehensive Data Protection
The exam often tests your understanding of which AWS service is best suited for a specific DLP task. For example, 'detecting PII in S3' immediately points to Macie, while 'monitoring network traffic' points to VPC Flow Logs. Know the primary function of each DLP service.
Comprehensive Data Protection
Failing to classify data before implementing DLP controls, leading to ineffective protection.
Comprehensive Data Protection
Relying solely on network-level controls without also securing access at the identity and resource level.
Comprehensive Data Protection
Not regularly reviewing and updating DLP policies as data types and business needs evolve.
Comprehensive Data Protection
An environment combining on-premises infrastructure with public cloud services.
Comprehensive Data Protection
Encrypting data with a data key, then encrypting the data key with a master key.
Comprehensive Data Protection
A dedicated, FIPS 140-2 Level 3 validated hardware security module in AWS.
Comprehensive Data Protection
Service to build, secure, and manage data lakes on AWS.
Comprehensive Data Protection
Techniques to obscure individual data points while retaining statistical properties.
Comprehensive Data Protection
For advanced data protection, think 'CHAMP': Compliance, Hybrid, Advanced Encryption, ML/Analytics, Protection (Incident Response).
Comprehensive Data Protection
The exam often presents scenarios involving specific compliance frameworks (e.g., HIPAA, PCI DSS, GDPR). Be prepared to identify which AWS services and features directly address requirements like data residency, auditability, and strong key management (KMS, CloudHSM).
Comprehensive Data Protection
Assuming AWS is solely responsible for compliance; customers share responsibility.
Comprehensive Data Protection
Neglecting to secure data in transit in hybrid environments, focusing only on data at rest.
Comprehensive Data Protection
Underestimating the complexity of key management for advanced encryption scenarios.
Comprehensive Data Protection