AWS Hands-On Security by Pearson
4h 49mIntermediate2026-09-08
Authors

Pearson
Course details
In AWS Hands-On Security, you explore managing identities and permissions, learning to safeguard your AWS environment through Identity and Access Management (IAM) best practices. Understand how to secure your resources with effective policies, roles, and access controls. Discover the essentials of AWS CloudTrail and Config for maintaining security, compliance, and operational visibility. You investigate multiple account management through AWS Organizations, improving your ability to centralize control and automate security protocols. Learn the intricacies of AWS Key Management Service (KMS), Secrets Manager, and Certificate Manager to secure data and workloads throughout the cloud environment. This course is optimally suited for IT professionals, cloud administrators, and security personnel seeking to deepen their understanding of AWS security services. By learning how to efficiently manage and secure AWS infrastructure, you can gain the confidence to uphold security and compliance in even the most complex environments. Whether you're tasked with securing organizational data, optimizing identity controls, or maintaining compliance with industry standards, this course can equip you with the skills you need to succeed in cloud security initiatives.
Concepts
Introduction
- Amazon Web Services (AWS) hands-on security - Introduction
Amazon Web Services (AWS) Identities
- Learning objectives
- AWS root user best practices
- Demo - Protect root user (console)
- Identity and access management (IAM) users and groups
- Demo - Create IAM administrator (console)
- Demo - Create IAM power user (console)
- IAM roles
- Demo - Create IAM role (console)
- Account federation options
AWS Permissions
- Learning objectives
- AWS policy types
- Identity-based policies
- Demo - Create IAM policy (console)
- Resource-based policies
- Demo - Create resource policy (console)
Accessing AWS Services
- Learning objectives
- AWS access options
- AWS command-line interface (CLI)
- Demo - AWS CloudShell (console)
- Demo - Install and configure AWS CLI (terminal)
- AWS programming language SDKs
- Demo - Install and test AWS Python SDK (terminal)
- Demo - Assume an IAM role (terminal)
- AWS identity and permissions management real-world scenario
AWS CloudTrail and Config
- Learning objectives
- AWS CloudTrail basics
- Demo - Enable CloudTrail features (console)
- AWS Config Basics
- Demo - Enable Config and create Config rules (console)
Multiple Account Management
- Learning objectives
- AWS Organizations basics
- AWS Organizations features
- Demo - Organizations configuration management (console)
- Demo - Deploy organizations service control policy (SCP) (console)
- AWS IAM Identity Center
- Demo - IAM Identity Center (console)
- AWS Control Tower
- AWS Backup
- Demo - Implement AWS Backup (console)
- AWS governance services real-world scenario
Secrets and Key Management
- Learning objectives
- AWS Key Management Service (KMS)
- Demo - Create and use KMS key (console)
- AWS Secrets Manager
- Demo - Create and use secret (console and terminal)
- AWS Certificate Manager
- Demo - Create and use Transport Layer Security (TLS) certificate (console)
Security Reporting Services
- Learning objectives
- Amazon GuardDuty
- Demo - Deliver GuardDuty findings to Simple Notification Service (SNS) (console)
- Amazon Inspector
- Demo - Explore Inspector findings (console)
- AWS Security Hub
- Demo - Enable Security Hub standards (console)
Edge Protection Services
- Learning objectives
- AWS Web Application Firewall (WAF)
- Demo - Create WAF web access control list (ACL) (console)
- Demo - Associate WAF with edge services (console)
- AWS Shield
- AWS security services real-world scenario
Conclusion
- AWS hands-on security - Summary