AWS Security Services

AWS security questions are mostly about choosing the service whose job matches the sentence. GuardDuty detects, Inspector scans, Macie finds data, Config records posture, Security Hub aggregates. Held that way, the catalog is a short list of verbs rather than a long list of names.

Threat detection and investigation

ServiceJobInputs
GuardDutyContinuous threat detection with findingsCloudTrail, VPC Flow Logs, DNS logs, EKS audit, S3 data events
DetectiveInvestigate findings with a behavior graphGuardDuty findings, CloudTrail, VPC Flow Logs
Security HubAggregate findings and score against standardsGuardDuty, Inspector, Macie, Config, partner tools
InspectorVulnerability scanningEC2, container images in ECR, Lambda functions
MacieDiscover and classify sensitive dataS3 buckets

Posture, configuration and audit

ServiceJob
ConfigRecord resource configuration over time and evaluate rules
CloudTrailAPI activity log per account and organization; the audit trail
IAM Access AnalyzerFind resources shared outside the account, unused access, policy validation
Trusted AdvisorChecks including security groups, IAM use, MFA on root
Audit ManagerCollect evidence continuously against frameworks
ArtifactDownload AWS compliance reports and agreements
Organizations SCPsMaximum permissions for accounts in the organization

Keys, secrets and certificates

ServiceJobNote
KMSCreate and control keys; envelope encryptionAWS managed, customer managed and AWS owned keys; key policies plus IAM
CloudHSMDedicated single-tenant hardware security modulesYou control the HSM; FIPS 140-2 Level 3
Secrets ManagerStore and rotate secretsBuilt-in rotation for RDS and other services
Systems Manager Parameter StoreConfiguration and secrets as parametersSecureString uses KMS; no built-in rotation
Certificate Manager (ACM)Provision and renew TLS certificatesPublic certificates free for use on ELB, CloudFront, API Gateway
Private CARun a private certificate authorityIssues certificates for internal use

Network and edge protection

ServiceJobLayer
Security groupsStateful allow rules on instances and interfacesInstance
Network ACLsStateless allow and deny rules on subnetsSubnet
Network FirewallManaged stateful firewall with Suricata-compatible rulesVPC
WAFRules against web requests: SQL injection, XSS, rate limits, botsCloudFront, ALB, API Gateway, AppSync
Shield Standard and AdvancedDDoS protection; Advanced adds response team and cost protectionEdge
Firewall ManagerApply WAF, Shield and security group policies across accountsOrganization
Route 53 Resolver DNS FirewallBlock or allow DNS queries by domain listVPC DNS
PrivateLink and VPC endpointsReach AWS services without traversing the internetVPC

Identity and access

Service or featureJob
IAMUsers, groups, roles and policies for the account
IAM Identity CenterWorkforce SSO to accounts and applications
STSTemporary credentials: AssumeRole, federation
CognitoSign-in and identity for application users
Resource Access ManagerShare resources across accounts
Verified PermissionsFine-grained application authorization with Cedar policies

Try it here

Three verified practice questions on this material. Answer one, and see the official page behind the answer.

Security Logging and Monitoring

A team is choosing where VPC Flow Logs should be published. Which destinations are supported?

Five free questions on every practice exam. No account, no card.