Course Details
Course Outline
1 - Module 1: Security On AWS
Security in the AWS cloudAWS Shared Responsibility ModelIncident response overviewDevOps with Security Engineering
2 - Module 2: Identifying Entry Points on AWS
Identify the different ways to access the AWS platformUnderstanding IAM policiesIAM Permissions BoundaryIAM Access AnalyzerMulti-factor authenticationAWS CloudTrailLab 01: Cross-account access
3 - Module 3: Security Considerations: Web Application Environments
Threats in a three-tier architectureCommon threats: user accessCommon threats: data accessAWS Trusted Advisor
4 - Module 4: Application Security
Amazon Machine ImagesAmazon InspectorAWS Systems ManagerLab 02: Using AWS Systems Manager and Amazon Inspector
5 - Module 5: Data Security
Data protection strategiesEncryption on AWSProtecting data at rest with Amazon S3, Amazon RDS, Amazon DynamoDBProtecting archived data with Amazon S3 GlacierAmazon S3 Access AnalyzerAmazon S3 Access Points
6 - Module 6: Securing Network Communications
Amazon VPC security considerationsAmazon VPC Traffic MirroringResponding to compromised instancesElastic Load BalancingAWS Certificate Manager
7 - Module 7: Monitoring and Collecting Logs on AWS
Amazon CloudWatch and CloudWatch LogsAWS ConfigAmazon MacieAmazon VPC Flow LogsAmazon S3 Server Access LogsELB Access LogsLab 3: Monitor and Respond with AWS Config
8 - Module 8: Processing Logs on AWS
Amazon KinesisAmazon AthenaLab 4: Web Server Log Analysis
9 - Module 9: Security Considerations: Hybrid Environments
AWS Site-to-Site and Client VPN connectionsAWS Direct ConnectAWS Transit Gateway
10 - Module 10: Out-Of-Region Protection
Amazon Route 53AWS WAFAmazon CloudFrontAWS ShieldAWS Firewall ManagerDDoS mitigation on AWS
11 - Module 11: Security Considerations: Serverless Environments
Amazon CognitoAmazon API GatewayAWS Lambda
12 - Module 12: Threat Detection and Investigation
Amazon GuardDutyAWS Security HubAmazon Detective
13 - Module 13: Secrets Management on AWS
AWS KMSAWS CloudHSMAWS Secrets ManagerLab 05: Using AWS KMS
14 - Module 14: Automation and Security by Design
AWS CloudFormationAWS Service CatalogLab 06: Security automation on AWS with AWS Service Catalog
15 - Module 15: Account Management and Provisioning on AWS
AWS OrganizationsAWS Control TowerAWS SSOAWS Directory ServiceLab 07: Federated Access with ADFS
Actual course outline may vary depending on offering center. Contact your sales representative for more information.
Who is it For?
Target Audience
This course is intended for:
Security engineers
Security architects
Information security professionals
Other Prerequisites
We recommend that attendees of this course have:
Working knowledge of IT security practices and infrastructure concepts
Familiarity with cloud computing concepts
Completed AWS Security Essentials and Architecting on AWS instructor-led courses