AWS Certified Security - Specialty (SCS-C02) Cert Prep
6h 7mIntermediate2025-05-05
Authors
Noah Gift
MLOps Expert | Solopreneur | Author | Adjunct Professor | CTO
Course details
Dive into this AWS Certified Security - Specialty Certification course and enhance your understanding of securing applications and infrastructure on AWS. Industry expert Noah Gift shows you how to detect and respond to threats using AWS services like GuardDuty and AWS Security Hub while building robust incident response strategies. Learn about effective logging and monitoring with AWS CloudWatch and CloudTrail. Explore infrastructure security techniques and master data protection strategies, including encryption and lifecycle management. Join in-depth discussions on AWS governance tools and techniques for effective centralized auditing and configuration management. By the end of the course, you'll be well-prepared to address security threats, manage secure cloud environments, and align with industry standards, making a substantial impact on your organization's security posture.
Skills covered
Cloud SecurityIncident ResponseAmazon Web Services (AWS)AmazonCybersecurityCert PrepCloud Computing
Concepts
Introduction - Threat Detection and Incident Response
- 01 - Course overview
Domain 1 - Threat Detection and Incident Response
- 02 - Designing and implementing incident response plans
- 03 - Demo - AWS Security Hub
- 04 - Responding to compromised resources and workloads
- 05 - Automating incident response with AWS Lambda
- 06 - Conducting root cause analysis with Amazon Detective
- 07 - Capturing forensics data from compromised resources
- 08 - Querying logs to validate security events
- 09 - Preserving forensic artifacts with S3 Object Lock
- 10 - Preparing and recovering services after incidents
- 11 - High availability
- 12 - Compliance
Conclusion - Threat Detection and Incident Response
- 13 - Threat detection and incident response summary
Introduction - Security Logging and Monitoring
- 14 - Domain 2 overview
Domain 2 - Security Logging and Monitoring
- 15 - Designing and implementing monitoring and alerting
- 16 - Troubleshooting systems with five whys
- 17 - Using grep, cut, sort, and uniq
- 18 - Popular Linux tools and how to use them
- 19 - Designing log analysis solutions
- 20 - Configuring AWS CloudTrail for logging
- 21 - Analyzing logs with Amazon Athena
- 22 - Configuring AWS CloudShell for Bash
- 23 - Logging and monitoring with CloudWatch
- 24 - Optimizing log storage lifecycles
- 25 - Third-party log analysis tools
Conclusion - Security Logging and Monitoring
- 26 - Security logging and monitoring summary
Introduction - Infrastructure Security
- 27 - Domain 3 overview
Domain 3 - Infrastructure Security
- 28 - Security benefits of microservices
- 29 - Operationalizing microservices
- 30 - CI for microservices
- 31 - AWS App runner
- 32 - Building a flask random fruit microservice
- 33 - Containerized .NET with AWS App runner
- 34 - Distroless containers
- 35 - Audit network security
- 36 - Integrating AWS firewall manager
- 37 - Applying security best practices to Lambdas
- 38 - Hardening AMIs with EC2 image builder
- 39 - Network segmentation
- 40 - Troubleshooting network security
Conclusion - Infrastructure Security
- 41 - Infrastructure security summary
Introduction - Identity and Access Management
- 42 - Domain 4 overview
Domain 4 - Identity and Access Management
- 43 - Designing security access strategy
- 44 - Rust secure by design
- 45 - Rust crate audits
- 46 - Evaluate authentication infrastructure
- 47 - Learn AWS CloudShell
- 48 - Building a secret decoder ring with Rust
- 49 - Using Rust for S3 storage
- 50 - Multi-factor authentication
Conclusion - Identity and Access Management
- 51 - Identity and access management summary
Introduction - Data Protection
- 52 - Domain 5 overview
Domain 5 - Data Protection
- 53 - Disaster recovery
- 54 - Managing and protecting data
- 55 - Design for data privacy
- 56 - Design for data retention policy
- 57 - Cloud developer workspace advantage
- 58 - AWS integrated security
- 59 - Building AWS data tools from scratch
- 60 - Python NLP CLI tools
- 61 - Preventing data races with rust compiler
- 62 - Data poisoning
- 63 - Encryption concepts
Conclusion - Data Protection
- 64 - Data protection summary
Introduction - Management and Security Governance
- 65 - Domain 6 overview
Domain 6 - Management and Security Governance
- 66 - Strategies for central audit
- 67 - IAC for secure deployment
- 68 - IAC for continuous delivery
- 69 - Using AWS config for security
- 70 - Effective AWS organizations strategy
- 71 - AWS shared security model
- 72 - Audit environment
- 73 - Containerized FastAPI NLP microservice
- 74 - AWS trusted advisor demo
- 75 - Least privilege access
Conclusion - Management and Security Governance
- 76 - Management and security governance conclusion