AWS for Architects: Advanced Security
3h 6mAdvanced2018-05-23
Authors

Lynn Langit
Cloud Architect
Course details
Regulations like GDPR have made security a top priority for every organization. Luckily, Amazon Web Services offers a plethora of tools for securing cloud-based architecture. This course teaches IT pros how to use AWS advanced security services, techniques, and tools to protect their users, data, apps, and infrastructure. Instructor Lynn Langit begins with the core tasks and services: setting up the AWS root account, billing, and tagging. She then shows how to set up strong authentication with AWS Identity and Access Management (IAM), Config, Simple AD, and full-fledged Active Directory. She covers infrastructure protection with VPC objects such as subnets, and data protection with KMS and Macie. Finally, she reviews security requirements for different application architectures and the associated AWS security solutions.
Note: This course can also be used to prepare for the corresponding domain of the AWS Certified Solutions Architect (Professional) exam.
Learning objectives
Five principals of well-architected security solutions
Core AWS account tools and IAM objects
Implementing IAM
Implementing infrastructure protection
Implementing data protection
Implementing app security
Preparing for a security audit
Note: This course can also be used to prepare for the corresponding domain of the AWS Certified Solutions Architect (Professional) exam.
Learning objectives
Five principals of well-architected security solutions
Core AWS account tools and IAM objects
Implementing IAM
Implementing infrastructure protection
Implementing data protection
Implementing app security
Preparing for a security audit
Skills covered
Amazon Web Services (AWS)AmazonCloud ServicesCloud PlatformsCloud ComputingDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Welcome
- 02 - What you should know
- 03 - About using cloud services
1. Implement Core Security Tasks
- 04 - AWS Shared Security Responsibility Model overview
- 05 - Well-architected five security principles
- 06 - Core AWS account tools
- 07 - Core AWS IAM objects
- 08 - AWS organizations and root account
- 09 - Object tagging
- 10 - Billing management
- 11 - CloudWatch logs and alerts
- 12 - CloudTrail analysis with Athena
- 13 - Trusted Advisor security alerts
2. Implement Identity and Access Management
- 14 - IAM users and groups
- 15 - IAM policies
- 16 - IAM roles
- 17 - Design user authentication
- 18 - User authentication using AWS Simple AD
- 19 - Secure authentication with Cognito
- 20 - Secure user authentication using AD Federation
3. Implement Infrastructure Protection
- 21 - Infrastructure and threat models
- 22 - VPC and security groups
- 23 - VPC Flow Logs and GuardDuty
- 24 - Certificate Manager and WAF to secure load balancers
- 25 - Inspector to monitor EC2 configurations
- 26 - Config for locking service deployment
- 27 - Service Catalog for AMI deployment
- 28 - Systems Manager for OS management
4. Implement Data Protection
- 29 - Data classification and protection
- 30 - Use Macie to locate sensitive data
- 31 - Encryption on AWS
- 32 - AWS IAM Key Management Service
- 33 - Data protection at rest in S3
- 34 - Encrypt data in transit and VPC endpoints
- 35 - Data backup, replication, and recovery
5. Implement Application Security
- 36 - Application security concerns
- 37 - Secure a serverless website
- 38 - Secure a dynamic website
- 39 - Secure an internal business application
- 40 - Secure a big data pipeline
- 41 - Secure an IoT and machine learning application
- 42 - Prepare for a security audit
Conclusion
- 43 - Next steps