AWS Security Services
AWS security questions are mostly about choosing the service whose job matches the sentence. GuardDuty detects, Inspector scans, Macie finds data, Config records posture, Security Hub aggregates. Held that way, the catalog is a short list of verbs rather than a long list of names.
AWS Security Services · firsttry.app/cheatsheets/aws-security-services · original reference written from published exam objectives. Not affiliated with any certification body.
Threat detection and investigation
| Service | Job | Inputs |
|---|---|---|
| GuardDuty | Continuous threat detection with findings | CloudTrail, VPC Flow Logs, DNS logs, EKS audit, S3 data events |
| Detective | Investigate findings with a behavior graph | GuardDuty findings, CloudTrail, VPC Flow Logs |
| Security Hub | Aggregate findings and score against standards | GuardDuty, Inspector, Macie, Config, partner tools |
| Inspector | Vulnerability scanning | EC2, container images in ECR, Lambda functions |
| Macie | Discover and classify sensitive data | S3 buckets |
Posture, configuration and audit
| Service | Job |
|---|---|
| Config | Record resource configuration over time and evaluate rules |
| CloudTrail | API activity log per account and organization; the audit trail |
| IAM Access Analyzer | Find resources shared outside the account, unused access, policy validation |
| Trusted Advisor | Checks including security groups, IAM use, MFA on root |
| Audit Manager | Collect evidence continuously against frameworks |
| Artifact | Download AWS compliance reports and agreements |
| Organizations SCPs | Maximum permissions for accounts in the organization |
Keys, secrets and certificates
| Service | Job | Note |
|---|---|---|
| KMS | Create and control keys; envelope encryption | AWS managed, customer managed and AWS owned keys; key policies plus IAM |
| CloudHSM | Dedicated single-tenant hardware security modules | You control the HSM; FIPS 140-2 Level 3 |
| Secrets Manager | Store and rotate secrets | Built-in rotation for RDS and other services |
| Systems Manager Parameter Store | Configuration and secrets as parameters | SecureString uses KMS; no built-in rotation |
| Certificate Manager (ACM) | Provision and renew TLS certificates | Public certificates free for use on ELB, CloudFront, API Gateway |
| Private CA | Run a private certificate authority | Issues certificates for internal use |
Network and edge protection
| Service | Job | Layer |
|---|---|---|
| Security groups | Stateful allow rules on instances and interfaces | Instance |
| Network ACLs | Stateless allow and deny rules on subnets | Subnet |
| Network Firewall | Managed stateful firewall with Suricata-compatible rules | VPC |
| WAF | Rules against web requests: SQL injection, XSS, rate limits, bots | CloudFront, ALB, API Gateway, AppSync |
| Shield Standard and Advanced | DDoS protection; Advanced adds response team and cost protection | Edge |
| Firewall Manager | Apply WAF, Shield and security group policies across accounts | Organization |
| Route 53 Resolver DNS Firewall | Block or allow DNS queries by domain list | VPC DNS |
| PrivateLink and VPC endpoints | Reach AWS services without traversing the internet | VPC |
Identity and access
| Service or feature | Job |
|---|---|
| IAM | Users, groups, roles and policies for the account |
| IAM Identity Center | Workforce SSO to accounts and applications |
| STS | Temporary credentials: AssumeRole, federation |
| Cognito | Sign-in and identity for application users |
| Resource Access Manager | Share resources across accounts |
| Verified Permissions | Fine-grained application authorization with Cedar policies |
Try it here
Three verified practice questions on this material. Answer one, and see the official page behind the answer.
Security Logging and Monitoring
A team is choosing where VPC Flow Logs should be published. Which destinations are supported?
2-1Design Resilient Architectures
A retail site caches product prices in ElastiCache. Prices are updated frequently, and users see stale prices for minutes after a change. Which caching strategy fixes this?
4-1Billing, Pricing, and Support
How much warning does an EC2 Spot Instance get before it is interrupted?
Five free questions on every practice exam. No account, no card.