0%

Explore Courses Defend What Matters

Your Bag

AWS Security Essentials

04 Cloud Security

AWS Security Essentials

Secure a real AWS account: IAM policies that hold up, VPC design, encryption with KMS, and detection with GuardDuty and CloudTrail.

Levels
04
Skill Range
Beginner Expert
Track
Cloud Security
Lifetime Access
AWS Security Essentials
From 204CREDS

AWS gives you every control you need and no opinion about how to use them. This course supplies the opinion. You will write IAM policies properly, including the conditions, boundaries, and service control policies that stop privilege creep across an organisation, and learn to read the policy evaluation logic rather than guess at it. VPC work covers subnet design, security groups against network ACLs, and private connectivity to AWS services. S3 gets dedicated treatment because it causes so many incidents. You will configure KMS and envelope encryption, then build detection with CloudTrail, Config, GuardDuty, and Security Hub, and practise responding to a simulated compromise of a key and an instance.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    204 CREDS

    Purpose

    Write AWS IAM policies properly, since AWS gives every control and no opinion on using them.

    Outcome

    You can write and reason about AWS IAM policies.

    What You'll Learn
    • Write identity and resource policies and read the evaluation logic.
    • Apply conditions and permission boundaries to contain privilege.
    • Explain why a request was allowed or denied rather than guessing.
  2. Level 02

    Intermediate

    447 CREDS

    Purpose

    Secure AWS networking and the S3 service that causes so many public incidents.

    Outcome

    You can secure AWS networking and storage against common exposure.

    What You'll Learn
    • Design subnets, security groups, and private connectivity to AWS services.
    • Lock down S3 with block public access, policies, and encryption.
    • Test that a bucket is actually private rather than assuming it.
  3. Level 03

    Advanced

    660 CREDS

    Purpose

    Apply encryption and organisation-wide guardrails with KMS and service control policies.

    Outcome

    You can enforce encryption and guardrails across an AWS organisation.

    What You'll Learn
    • Configure KMS and envelope encryption and control who can decrypt.
    • Apply service control policies to stop privilege creep across accounts.
    • Structure an organisation so security is enforced centrally.
  4. Level 04

    Expert

    1,033 CREDS

    Purpose

    Build AWS detection and respond to a simulated compromise.

    Outcome

    You can detect and respond to an incident inside AWS.

    What You'll Learn
    • Deploy detection with CloudTrail, Config, GuardDuty, and Security Hub.
    • Investigate a simulated compromise of a key and an instance.
    • Contain, rotate, and recover while preserving the evidence.