Domain 2: Security and Compliance

Security, Governance, and Compliance Concepts (Task 2.2)

AWS Artifact Amazon Inspector AWS Security Hub Amazon GuardDuty AWS Shield Amazon CloudWatch AWS CloudTrail AWS Config AWS Audit Manager AWS WAF
Exam Tip
Compliance docs = AWS Artifact. Threat DETECTION = GuardDuty (ML on logs). Vulnerability SCANNING = Inspector. Security posture AGGREGATION = Security Hub. DDoS = Shield (Standard free / Advanced $3,000/mo with DRT). Audit trail of API calls = CloudTrail. Resource config compliance = Config. Logs live in CloudWatch Logs — know where to FIND logs.

AWS Cloud Security, Governance, and Compliance

Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/security-and-compliance-model.html

The exam tests WHERE each security capability lives: compliance evidence (Artifact), threat detection (GuardDuty), vulnerability scanning (Inspector), aggregation (Security Hub), DDoS (Shield), web attacks (WAF), audit trail (CloudTrail), config compliance (Config). Senior engineers wire these into a working detection-and-response loop, not a shopping list. Each service: brief, how it works, real use-case, gotchas.

Where to Find AWS Compliance Information

AWS Artifact

Brief: Self-service portal for AWS compliance reports (SOC, ISO, PCI) and for accepting agreements (HIPAA BAA, DPA). No ticket, no sales call.

How it works: AWS's auditors produce third-party attestations; Artifact exposes the signed PDFs to every customer on demand, plus the agreements you must sign before putting regulated workloads on AWS.

Real use-case: An auditor emails Monday: "Provide your SOC 2 Type II report for the sub-processor." You log into Artifact, download it, and reply in 10 minutes — historically this took a vendor-management cycle of weeks.

Gotchas & interview notes: Compliance varies by Region and service — not every Region carries every certification (some programs are US- or EU-only), and a certification covering EC2 may not cover a brand-new service. Check the Region/service compliance pages BEFORE designing a regulated workload; data-sovereignty law (GDPR, DPDP) may dictate the Region too.

Threat Detection and Protection Services

Amazon GuardDuty — intelligent threat detection

Brief: ML-powered threat detection that analyzes CloudTrail management events, VPC Flow Logs, DNS logs, and (advanced) S3 data events and EKS audit logs — no agents, no sensors to deploy.

How it works: GuardDuty continuously streams account/network telemetry into threat-intelligence and ML models, then emits findings ranked by severity (Low/Medium/High). GuardDuty findings include credential use from Tor exit nodes, crypto-currency mining patterns (EC2 talking to mining pools), anomalous S3 API activity, and data exfiltration signatures. Findings flow to Security Hub and EventBridge for automated response.

Real use-case: An engineer's leaked access key is used from an unusual country at 3 a.m. GuardDuty raises "UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B" + "Credential exfiltration" findings; an EventBridge rule auto-triggers a Lambda that disables the key within 90 seconds of the anomaly.

Gotchas & interview notes: GuardDuty DETECTS — it does not block. Pair it with automated remediation for response. It is the "ML on logs" exam answer; remember its three classic log sources: CloudTrail, VPC Flow Logs, DNS.

Amazon Inspector — vulnerability scanning

Brief: Automated vulnerability scanning for EC2 instances and container images (ECR), plus Lambda functions — finds CVEs, network exposure, and missing patches.

How it works: For EC2, a lightweight SSM-agent-based scan (no reboot); for ECR, images are scanned on push; for Lambda, code dependencies are checked. Findings are scored (CVSS), deduplicated, and sent to Security Hub.

Real use-case: A team's CI pipeline fails the build when Inspector rates a new container image CRITICAL (an outdated OpenSSL in the base layer) — the vulnerability never reaches production because the gate caught it at push time.

Gotchas & interview notes: Inspector = "find MY software's vulnerabilities" (inside-out); GuardDuty = "detect malicious BEHAVIOR" (outside-in). The exam's verb tells you which: "CVE/patch/scan" → Inspector; "suspicious activity/threat" → GuardDuty.

AWS Security Hub — the aggregation layer

Brief: Single pane of glass for security findings across accounts and services; runs automated compliance checks (CIS AWS Benchmark, PCI DSS, AWS Foundational Security Best Practices).

How it works: Security Hub ingests findings from GuardDuty, Inspector, Macie, Firewall Manager, Config, and third-party tools into a normalized format (ASFF — AWS Security Findings Format), deduplicates, and correlates. Central configuration across an Organization via delegated admin.

Real use-case: A CISO's Monday dashboard shows 1,200 findings across 15 accounts ranked by severity; instead of 6 consoles, triage happens in one queue, and the same findings also satisfy the auditor's "continuous monitoring" control.

Gotchas & interview notes: Security Hub is the HUB of the spokes — on architecture questions about "centralized security visibility across accounts," it is the answer. Do not confuse it with Detective (investigation graph) or Firewall Manager (WAF rule distribution).

AWS Shield — DDoS protection

Brief: Shield Standard is free, automatic DDoS protection for every AWS customer at the network/transport layer. Shield Advanced is $3,000/month (1-year commit) and adds 24/7 DDoS Response Team (DRT), advanced detection/mitigation, and cost protection (scaled billing during attacks).

How it works: Standard absorbs common Layer 3/4 floods (SYN floods, UDP reflection) inline at the edge — you do nothing, it is already on. Advanced adds application-layer detection, integration with WAF (DRT writes custom WAF rules during live attacks), and reimbursement of scaling costs caused by an attack.

Real use-case: A gaming launch is hit by a 2 Tbps UDP flood targeting the game's Elastic IP; Standard absorbs it at the edge. Later, a Layer 7 HTTP flood of expensive search requests gets mitigated by DRT-authored WAF rate-limit rules under Advanced.

Gotchas & interview notes: Exam trigger words: "DDoS" → Shield; "$3,000/month, DRT, cost protection" → Advanced specifically. Layer 7 (application) attacks are NEVER stopped by Shield alone — the answer pairs Shield + WAF (and CloudFront for absorption at edge).

AWS WAF — web application firewall

Brief: Layer 7 firewall protecting HTTP/HTTPS applications from SQL injection, XSS, bots, and rate abuse — attaches to CloudFront, ALB, API Gateway, AppSync, or Cognito.

How it works: You attach a Web ACL (ordered rule groups) to the resource in front of your app. Rules match on request properties: IP, geography, headers, query strings, URI, request body (first 8 KB), rate per IP. Actions: allow, block, or count (count = silent testing mode). Managed rule groups (AWS Managed Rules, marketplace) cover the OWASP Top 10 without writing regex.

Real use-case: A checkout API gets credential-stuffing traffic from 10,000 IPs. A rate-based rule (2,000 requests/5 min per IP) plus a managed rule group blocking known anonymizer ranges cuts fraudulent logins by 94% in a week — all in "count" mode first to validate no real users were hit.

Gotchas & interview notes: WAF is the only Layer 7 firewall in the exam's toolbox; Security Groups/NACLs operate at Layer 3/4 — they cannot inspect an SQL injection inside an HTTPS body. Always deploy new rules in count mode first.

Encryption Options

Brief: Data has two states and both need protection: in transit (moving across networks — TLS/HTTPS) and at rest (sitting on disk — S3 SSE, EBS, RDS, DynamoDB encryption).

How it works: In transit, TLS is enforced with certificates from AWS Certificate Manager (ACM issues/renews free public certs for ALB/CloudFront/API Gateway). At rest, nearly every AWS storage service supports SSE-S3 (AWS-managed keys), SSE-KMS (your KMS customer-managed keys, with audit via CloudTrail and granular grants), or SSE-C (you supply the key). Enabling is a config choice — which is why it is YOUR responsibility (see Shared Responsibility).

Example: "Data traveling over the network" → in transit (TLS). "Data sitting on disk" → at rest (SSE). Exam phrasing always reduces to this distinction.

Real use-case: A healthcare app enables RDS encryption at rest with SSE-KMS, forces TLS connections (requiring ssl_mode=REQUIRED), and puts an ACM cert on its ALB — satisfying HIPAA technical safeguards for both data states with three configuration changes.

Gotchas & interview notes: KMS is the key service to remember for at-rest encryption with AUDIT and granular control; SSE-S3 is simpler but gives no per-key audit trail. Field-level encryption needs application-level design (or DynamoDB Encryption Client) — storage-level SSE encrypts the whole object only.

Governance and Compliance Services

  • Amazon CloudWatch — metrics, logs, and alarms. CloudWatch Logs is where application and AWS logs land; alarms turn metrics into pages ("unauthorized API calls > 0").
  • AWS CloudTrail — records every API call (who, what, when, source IP) — the immutable audit trail. 90-day event history free; full history delivered to S3. Management events vs data events (S3 object reads are DATA events — not logged by default).
  • AWS Config — records resource configurations over time; rules check compliance ("every EBS volume must be encrypted"); can auto-remediate (e.g., mark noncompliant SGs). The answer for "drift detection" and "configuration compliance."
  • AWS Audit Manager — automates audit evidence collection against frameworks (HIPAA, PCI, CIS, NIST) by mapping your resource usage to control requirements.
  • IAM access analyzer / credential & access reports — show what identities exist, what they can reach, and which keys are unused — feeding your least-privilege cleanups.
  • AWS Organizations + SCPs — enforce guardrails across all accounts (see the IAM topic).
  • Architect: choose US Regions with HIPAA eligibility; sign the BAA in AWS Artifact.
  • Data: enable RDS encryption at rest (KMS) and enforce TLS in transit (ACM certificate).
  • Detection: enable GuardDuty for threat intel; Inspector scans the EC2 AMIs; findings roll into Security Hub.
  • Audit: CloudTrail records every API call; Config rules flag unencrypted EBS volumes; Audit Manager maps controls to HIPAA requirements.
  • Perimeter: AWS WAF on CloudFront blocks SQL injection; Shield Standard is already on; annual review considers Shield Advanced.
How they interlock (senior view): CloudTrail logs land in CloudWatch Logs/S3 → GuardDuty analyzes them for threats → findings land in Security Hub → a high-severity finding fires an EventBridge rule → Lambda remediates (disable key, quarantine SG) → Config confirms the resource is compliant again → Audit Manager snapshots the evidence. That closed loop — detect, alert, respond, evidence — is what "security operations on AWS" means.

Worked Example: Securing a Regulated Workload

A healthcare app must satisfy HIPAA:

  • Amazon CloudWatch — metrics, logs, and alarms. CloudWatch Logs is where application and AWS logs land; alarms turn metrics into pages ("unauthorized API calls > 0").
  • AWS CloudTrail — records every API call (who, what, when, source IP) — the immutable audit trail. 90-day event history free; full history delivered to S3. Management events vs data events (S3 object reads are DATA events — not logged by default).
  • AWS Config — records resource configurations over time; rules check compliance ("every EBS volume must be encrypted"); can auto-remediate (e.g., mark noncompliant SGs). The answer for "drift detection" and "configuration compliance."
  • AWS Audit Manager — automates audit evidence collection against frameworks (HIPAA, PCI, CIS, NIST) by mapping your resource usage to control requirements.
  • IAM access analyzer / credential & access reports — show what identities exist, what they can reach, and which keys are unused — feeding your least-privilege cleanups.
  • AWS Organizations + SCPs — enforce guardrails across all accounts (see the IAM topic).
  • Architect: choose US Regions with HIPAA eligibility; sign the BAA in AWS Artifact.
  • Data: enable RDS encryption at rest (KMS) and enforce TLS in transit (ACM certificate).
  • Detection: enable GuardDuty for threat intel; Inspector scans the EC2 AMIs; findings roll into Security Hub.
  • Audit: CloudTrail records every API call; Config rules flag unencrypted EBS volumes; Audit Manager maps controls to HIPAA requirements.
  • Perimeter: AWS WAF on CloudFront blocks SQL injection; Shield Standard is already on; annual review considers Shield Advanced.

Compliance Varies by Service

The exam reminds you that compliance programs differ among AWS services — e.g., a certification covering EC2 may not yet cover a newer service, and Region availability of a compliance program matters. Check the service-specific compliance pages before designing a regulated workload.