Security Engineering on AWS
Your AWS resources need protection suited to their uses and exposure. Connect identities, access and security measures to structure your configurations. Strengthen your ability to examine areas requiring attention and coordinate protective actions.
- Duration
- 3 days 21 hours
- Code
- AWS16FR Code
Presentation
Security is a major concern for businesses adopting the cloud, especially as cyberattacks and data breaches continue to increase. This Security Engineering on AWS course addresses that concern by giving you a better understanding of how to interact with Amazon Web Services (AWS) and build secure architectures.
The programme runs over 3 days, incorporating hands-on exercises and demonstrations for a comprehensive, immersive approach. It explores protecting data stored on AWS in depth, including encryption and access controls. You will also learn to generate, collect and monitor logs to identify security incidents quickly and respond effectively to threats.
Throughout this course, you will gain a solid understanding of security in the AWS cloud, based on the CIA triad (Confidentiality, Integrity, Availability). You will learn to create and analyse authentication and authorisation mechanisms with IAM, manage secrets and protect your infrastructure against external attacks.
Objectives
Program
Module 1: understand and explore security
- How security works in the AWS cloud.
- The AWS shared responsibility model.
- Fundamentals of IAM, data protection, threat detection and response.
- Different ways to interact with AWS (console, CLI and SDK).
- Using multi-factor authentication (MFA) for additional protection.
- Protecting the root user account and access keys.
Module 2: secure entry points on AWS
- IAM policies, roles, policy components and permissions boundaries.
- How API requests can be logged and viewed with AWS CloudTrail, and how to view and analyse access history.
Practical exercise
- Use identity-based and resource-based policies.
Module 3: manage and provision accounts on AWS
- Managing multiple AWS accounts with AWS Organizations and AWS Control Tower.
- Using identity providers and brokers to access AWS services (demo).
- Using AWS IAM Identity Center (successor to AWS Single Sign-On) and AWS Directory Service.
- Managing domain user access with Directory Service and IAM Identity Center (demo).
Practical exercise
- Manage domain user access with AWS Directory Service.
Module 4: manage secrets on AWS
- Features of AWS KMS, CloudHSM, AWS Certificate Manager (ACM) and AWS Secrets Manager.
- Creating an AWS KMS multi-region key (demo).
- Encrypting a Secrets Manager secret with an AWS KMS key (demo).
- Using an encrypted secret to connect to an Amazon Relational Database Service (Amazon RDS) database in multiple AWS regions (demo).
Practical exercise
- Use AWS KMS to encrypt secrets in Secrets Manager.
Module 5: protect data
- Monitoring data to detect sensitive information with Amazon Macie.
- Describing data-at-rest protection through encryption and access controls.
- Identifying AWS services used to replicate data for protection.
- Determining how data is protected after archiving.
Practical exercise
- Secure data in Amazon S3.
Module 6: protect edge infrastructure
- AWS capabilities used to build secure infrastructure.
- Identifying AWS services used to build resilience during an attack.
- Identifying AWS services used to protect workloads from external threats.
- Comparing AWS Shield and AWS Shield Advanced capabilities.
- How centralised deployment of AWS Firewall Manager can improve security.
Practical exercise:
- Use AWS WAF to mitigate malicious traffic.
Module 7: monitor and collect logs on AWS
- Identifying the value of log generation and collection.
- Using Amazon Virtual Private Cloud (Amazon VPC) flow logs to monitor security events.
- Monitoring deviations from the baseline.
- Managing events in Amazon EventBridge.
- Managing metrics and alarms in Amazon CloudWatch.
- Available log analysis options and techniques.
- Identifying VPC Traffic Mirroring use cases.
Practical exercise
- Monitor and respond to security incidents.
Module 8: respond to threats
- Classifying incident types within incident response.
- Incident response workflows.
- Discovering information sources for incident response using AWS services.
- Methods for preparing for incidents.
- Detecting threats using AWS services.
- Analysing and responding to security findings.
Practical exercise
- Conduct incident response.
Audience
This course is intended for:
- Security engineers seeking to strengthen their skills in implementing and managing security measures specific to the AWS environment.
- Security architects who want to design robust, secure cloud architectures on AWS.
- Cloud architects seeking to integrate security best practices from the design stage of their AWS infrastructure.
- Cloud operators responsible for securely maintaining AWS services and infrastructure.
Prerequisites
The following prerequisites are recommended for this AWS course:
- Basic knowledge of AWS services (recommended course: AWS Security Essentials).
- Basic knowledge of design and architecture on AWS (recommended course: Architecting on AWS).
- Knowledge of IT security practices and infrastructure concepts.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Instructor expertise: benefit from AWS instructors specialising in security, with in-depth knowledge of secure architectures, advanced encryption methods and AWS security engineering best practices.
- Interactive hands-on learning: master complex AWS security engineering concepts through clear presentations and practical labs, preparing you to apply infrastructure protection and incident response principles.
- Develop key skills: course content is carefully designed to build essential skills in identity and access management, sensitive data protection, proactive monitoring and effective threat response within AWS.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
AWS is a registered trademark of Amazon.com, Inc. or its affiliates.
fr
en