Security, Governance, and Compliance Concepts (Task 2.2)
AWS Cloud Security, Governance, and Compliance
Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/security-and-compliance-model.htmlThe exam tests WHERE each security capability lives: compliance evidence (Artifact), threat detection (GuardDuty), vulnerability scanning (Inspector), aggregation (Security Hub), DDoS (Shield), web attacks (WAF), audit trail (CloudTrail), config compliance (Config). Senior engineers wire these into a working detection-and-response loop, not a shopping list. Each service: brief, how it works, real use-case, gotchas.
Where to Find AWS Compliance Information
AWS Artifact
Brief: Self-service portal for AWS compliance reports (SOC, ISO, PCI) and for accepting agreements (HIPAA BAA, DPA). No ticket, no sales call.
How it works: AWS's auditors produce third-party attestations; Artifact exposes the signed PDFs to every customer on demand, plus the agreements you must sign before putting regulated workloads on AWS.
Real use-case: An auditor emails Monday: "Provide your SOC 2 Type II report for the sub-processor." You log into Artifact, download it, and reply in 10 minutes — historically this took a vendor-management cycle of weeks.
Gotchas & interview notes: Compliance varies by Region and service — not every Region carries every certification (some programs are US- or EU-only), and a certification covering EC2 may not cover a brand-new service. Check the Region/service compliance pages BEFORE designing a regulated workload; data-sovereignty law (GDPR, DPDP) may dictate the Region too.
Threat Detection and Protection Services
Amazon GuardDuty — intelligent threat detection
Brief: ML-powered threat detection that analyzes CloudTrail management events, VPC Flow Logs, DNS logs, and (advanced) S3 data events and EKS audit logs — no agents, no sensors to deploy.
How it works: GuardDuty continuously streams account/network telemetry into threat-intelligence and ML models, then emits findings ranked by severity (Low/Medium/High). GuardDuty findings include credential use from Tor exit nodes, crypto-currency mining patterns (EC2 talking to mining pools), anomalous S3 API activity, and data exfiltration signatures. Findings flow to Security Hub and EventBridge for automated response.
Real use-case: An engineer's leaked access key is used from an unusual country at 3 a.m. GuardDuty raises "UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B" + "Credential exfiltration" findings; an EventBridge rule auto-triggers a Lambda that disables the key within 90 seconds of the anomaly.
Gotchas & interview notes: GuardDuty DETECTS — it does not block. Pair it with automated remediation for response. It is the "ML on logs" exam answer; remember its three classic log sources: CloudTrail, VPC Flow Logs, DNS.
Amazon Inspector — vulnerability scanning
Brief: Automated vulnerability scanning for EC2 instances and container images (ECR), plus Lambda functions — finds CVEs, network exposure, and missing patches.
How it works: For EC2, a lightweight SSM-agent-based scan (no reboot); for ECR, images are scanned on push; for Lambda, code dependencies are checked. Findings are scored (CVSS), deduplicated, and sent to Security Hub.
Real use-case: A team's CI pipeline fails the build when Inspector rates a new container image CRITICAL (an outdated OpenSSL in the base layer) — the vulnerability never reaches production because the gate caught it at push time.
Gotchas & interview notes: Inspector = "find MY software's vulnerabilities" (inside-out); GuardDuty = "detect malicious BEHAVIOR" (outside-in). The exam's verb tells you which: "CVE/patch/scan" → Inspector; "suspicious activity/threat" → GuardDuty.
AWS Security Hub — the aggregation layer
Brief: Single pane of glass for security findings across accounts and services; runs automated compliance checks (CIS AWS Benchmark, PCI DSS, AWS Foundational Security Best Practices).
How it works: Security Hub ingests findings from GuardDuty, Inspector, Macie, Firewall Manager, Config, and third-party tools into a normalized format (ASFF — AWS Security Findings Format), deduplicates, and correlates. Central configuration across an Organization via delegated admin.
Real use-case: A CISO's Monday dashboard shows 1,200 findings across 15 accounts ranked by severity; instead of 6 consoles, triage happens in one queue, and the same findings also satisfy the auditor's "continuous monitoring" control.
Gotchas & interview notes: Security Hub is the HUB of the spokes — on architecture questions about "centralized security visibility across accounts," it is the answer. Do not confuse it with Detective (investigation graph) or Firewall Manager (WAF rule distribution).
AWS Shield — DDoS protection
Brief: Shield Standard is free, automatic DDoS protection for every AWS customer at the network/transport layer. Shield Advanced is $3,000/month (1-year commit) and adds 24/7 DDoS Response Team (DRT), advanced detection/mitigation, and cost protection (scaled billing during attacks).
How it works: Standard absorbs common Layer 3/4 floods (SYN floods, UDP reflection) inline at the edge — you do nothing, it is already on. Advanced adds application-layer detection, integration with WAF (DRT writes custom WAF rules during live attacks), and reimbursement of scaling costs caused by an attack.
Real use-case: A gaming launch is hit by a 2 Tbps UDP flood targeting the game's Elastic IP; Standard absorbs it at the edge. Later, a Layer 7 HTTP flood of expensive search requests gets mitigated by DRT-authored WAF rate-limit rules under Advanced.
Gotchas & interview notes: Exam trigger words: "DDoS" → Shield; "$3,000/month, DRT, cost protection" → Advanced specifically. Layer 7 (application) attacks are NEVER stopped by Shield alone — the answer pairs Shield + WAF (and CloudFront for absorption at edge).
AWS WAF — web application firewall
Brief: Layer 7 firewall protecting HTTP/HTTPS applications from SQL injection, XSS, bots, and rate abuse — attaches to CloudFront, ALB, API Gateway, AppSync, or Cognito.
How it works: You attach a Web ACL (ordered rule groups) to the resource in front of your app. Rules match on request properties: IP, geography, headers, query strings, URI, request body (first 8 KB), rate per IP. Actions: allow, block, or count (count = silent testing mode). Managed rule groups (AWS Managed Rules, marketplace) cover the OWASP Top 10 without writing regex.
Real use-case: A checkout API gets credential-stuffing traffic from 10,000 IPs. A rate-based rule (2,000 requests/5 min per IP) plus a managed rule group blocking known anonymizer ranges cuts fraudulent logins by 94% in a week — all in "count" mode first to validate no real users were hit.
Gotchas & interview notes: WAF is the only Layer 7 firewall in the exam's toolbox; Security Groups/NACLs operate at Layer 3/4 — they cannot inspect an SQL injection inside an HTTPS body. Always deploy new rules in count mode first.
Encryption Options
Brief: Data has two states and both need protection: in transit (moving across networks — TLS/HTTPS) and at rest (sitting on disk — S3 SSE, EBS, RDS, DynamoDB encryption).
How it works: In transit, TLS is enforced with certificates from AWS Certificate Manager (ACM issues/renews free public certs for ALB/CloudFront/API Gateway). At rest, nearly every AWS storage service supports SSE-S3 (AWS-managed keys), SSE-KMS (your KMS customer-managed keys, with audit via CloudTrail and granular grants), or SSE-C (you supply the key). Enabling is a config choice — which is why it is YOUR responsibility (see Shared Responsibility).
Example: "Data traveling over the network" → in transit (TLS). "Data sitting on disk" → at rest (SSE). Exam phrasing always reduces to this distinction.
Real use-case: A healthcare app enables RDS encryption at rest with SSE-KMS, forces TLS connections (requiring ssl_mode=REQUIRED), and puts an ACM cert on its ALB — satisfying HIPAA technical safeguards for both data states with three configuration changes.
Gotchas & interview notes: KMS is the key service to remember for at-rest encryption with AUDIT and granular control; SSE-S3 is simpler but gives no per-key audit trail. Field-level encryption needs application-level design (or DynamoDB Encryption Client) — storage-level SSE encrypts the whole object only.
Governance and Compliance Services
- Amazon CloudWatch — metrics, logs, and alarms. CloudWatch Logs is where application and AWS logs land; alarms turn metrics into pages ("unauthorized API calls > 0").
- AWS CloudTrail — records every API call (who, what, when, source IP) — the immutable audit trail. 90-day event history free; full history delivered to S3. Management events vs data events (S3 object reads are DATA events — not logged by default).
- AWS Config — records resource configurations over time; rules check compliance ("every EBS volume must be encrypted"); can auto-remediate (e.g., mark noncompliant SGs). The answer for "drift detection" and "configuration compliance."
- AWS Audit Manager — automates audit evidence collection against frameworks (HIPAA, PCI, CIS, NIST) by mapping your resource usage to control requirements.
- IAM access analyzer / credential & access reports — show what identities exist, what they can reach, and which keys are unused — feeding your least-privilege cleanups.
- AWS Organizations + SCPs — enforce guardrails across all accounts (see the IAM topic).
- Architect: choose US Regions with HIPAA eligibility; sign the BAA in AWS Artifact.
- Data: enable RDS encryption at rest (KMS) and enforce TLS in transit (ACM certificate).
- Detection: enable GuardDuty for threat intel; Inspector scans the EC2 AMIs; findings roll into Security Hub.
- Audit: CloudTrail records every API call; Config rules flag unencrypted EBS volumes; Audit Manager maps controls to HIPAA requirements.
- Perimeter: AWS WAF on CloudFront blocks SQL injection; Shield Standard is already on; annual review considers Shield Advanced.
Worked Example: Securing a Regulated Workload
A healthcare app must satisfy HIPAA:
- Amazon CloudWatch — metrics, logs, and alarms. CloudWatch Logs is where application and AWS logs land; alarms turn metrics into pages ("unauthorized API calls > 0").
- AWS CloudTrail — records every API call (who, what, when, source IP) — the immutable audit trail. 90-day event history free; full history delivered to S3. Management events vs data events (S3 object reads are DATA events — not logged by default).
- AWS Config — records resource configurations over time; rules check compliance ("every EBS volume must be encrypted"); can auto-remediate (e.g., mark noncompliant SGs). The answer for "drift detection" and "configuration compliance."
- AWS Audit Manager — automates audit evidence collection against frameworks (HIPAA, PCI, CIS, NIST) by mapping your resource usage to control requirements.
- IAM access analyzer / credential & access reports — show what identities exist, what they can reach, and which keys are unused — feeding your least-privilege cleanups.
- AWS Organizations + SCPs — enforce guardrails across all accounts (see the IAM topic).
- Architect: choose US Regions with HIPAA eligibility; sign the BAA in AWS Artifact.
- Data: enable RDS encryption at rest (KMS) and enforce TLS in transit (ACM certificate).
- Detection: enable GuardDuty for threat intel; Inspector scans the EC2 AMIs; findings roll into Security Hub.
- Audit: CloudTrail records every API call; Config rules flag unencrypted EBS volumes; Audit Manager maps controls to HIPAA requirements.
- Perimeter: AWS WAF on CloudFront blocks SQL injection; Shield Standard is already on; annual review considers Shield Advanced.
Compliance Varies by Service
The exam reminds you that compliance programs differ among AWS services — e.g., a certification covering EC2 may not yet cover a newer service, and Region availability of a compliance program matters. Check the service-specific compliance pages before designing a regulated workload.