SERVICE DOMAIN
Security
Identity, access management, and threat protection.PUBLIC NOTES
Knowledge Notes
AWS IAM
Verify who is making the request, then use policies to decide what that identity may do to which resources.
→IAM Access Analyzer
Analyze external access, policies, and unused permissions to enforce least privilege.
→AWS Security Interview Guide
Answer AWS security interviews with an identity, network, data, detection, response, and shared-responsibility framework.
→AWS Organizations
Centrally manage AWS accounts, OUs, SCP permission boundaries, and consolidated billing.
→AWS Control Tower
Build and continuously govern a standardized multi-account AWS environment using best practices.
→Amazon Cognito
Provides sign-up, sign-in, and access control for web and mobile applications.
→Amazon Detective
GuardDuty tells you that something suspicious happened; Detective helps explain why, who was involved, and what was affected.
→Amazon GuardDuty
Continuously analyzes account, network, and workload signals to detect suspicious attacks.
→Amazon Inspector
Continuously scans workloads for software vulnerabilities and exposure risks.
→Amazon Macie
Uses machine learning and automation to discover sensitive data in Amazon S3.
→AWS Certificate Manager
Centrally provisions, deploys, and renews SSL/TLS certificates used for HTTPS.
→AWS IAM Identity Center
Gives employees one entry point to multiple AWS accounts and applications.
→AWS KMS
Manages the encryption keys used to lock and unlock data; it does not store the business data itself.
→AWS Secrets Manager
Securely stores and can automatically rotate database passwords, API keys, and tokens.
→AWS Security Hub
Standardizes findings from multiple security services and brings them into one security view.
→AWS Shield
Protects applications on AWS from denial-of-service and distributed denial-of-service attacks.
→AWS WAF
Inspects HTTP(S) requests and allows, blocks, or counts them according to web rules.
→TOPIC INDEX