Designed specifically for students looking to gain a deep understanding of AWS security services, including the many different security mechanisms and techniques that AWS offers to secure your infrastructure and data from both internal and external threats and exposures. The AWS Certified Security - Specialty certification allows you to demonstrate and validate your AWS knowledge across security topics such as data protection and encryption, infrastructure security, incident response, identity and access management, monitoring and logging. With a blend of instructional courses, hands on labs, quizzes and a preparation exam, this Learning Path helps you prepare and master the AWS Certified Security - Specialty exam.
Benefits of achieving this certification
- Cloud Security is crucial to ALL use cases
- AWS certifications provide a reputable benchmark for AWS partners and practitioners
- Ensures team members are following security best practices
- Provides professional progression for team members
- Contributes to AWS partner certification requirements
This learning path is ideal for anyone interested in learning to recognize, explain, and implement solutions to enforce strict security controls across all levels of AWS infrastructure deployments.
This learning path will enable you to:
- Understand the differences between each of the security services offered by AWS and how they can be used within your environment
- Select the appropriate level of security based on your deployments and the sensitivity of your data using a variety of services
- Implement the correct security services and mechanisms to meet business objectives and requirements
- Understand how to select the most appropriate data protection techniques including encryption mechanisms
- Implement logging and monitoring solutions to detect and analyze security vulnerabilities and weaknesses within your infrastructure
This learning path has been designed to take you through the numerous security services along with the different security features that are available within other AWS services.
It begins with an introduction to the most common security service that is available, Identity & Access Management (IAM). During the first few courses and labs it looks at access management and identities, both internally and externally, covering different authentication and authorization methods.
Next it introduces a number of AWS security services related to auditing and compliance some of which are based on Machine Learning, such as Amazon GuardDuty and Amazon Macie.
Monitoring and logging is then covered, examining how you can use the different AWS services to monitor and track log data and use it to help you find vulnerabilities.
Next there are a number of courses and labs that look into encryption and data protection using different services and techniques. Different encryption mechanisms are covered here across a range of common AWS services.
Application and Network security is covered next, looking at different services and techniques that can be implemented to help protect your Web Apps along with your VPC infrastructure, again from both internal and external threats.
Finally there are a number of courses and labs covering security best practices, governance, and risk.
Over 31 hours of high definition video, 11 hands on labs, and a final preparation exam.
Prior to taking this Security Specialty certification you must have passed the AWS Practitioner certification or ANY of the AWS Associate level certifications
We welcome all feedback so if you are unsure about where to start or if would like help getting started please direct any comments or questions to us at email@example.com
07/06/18: Added Lab - Detecting EC2 Threats with Amazon GuardDuty
Added: How to implement & enable logging Across AWS Services (Part 1 of 2)
Added: How to implement & enable logging Across AWS Services (Part 2 of 2)
Added: Understanding S3 Encryption Mechanisms to secure your data
Learning Path Steps
Learn how to create and manage IAM users, groups and policies to securely control access to AWS services and resources.
Learn how to manage our organization using IAM Users and Groups and IAM Roles
Knowledge Check: Overview of AWS Identity and Access Management (IAM)
Authentication, Authorization & Accounting
AWS CloudTrail Intermediate
Learn how to configure and use AWS CloudTrail and CloudWatch in cooperation with each other to monitor AWS infrastructure and services. Whenever an Instance is stopped or terminated and alarm will trigger (using AWS SNS) and deliver an email notification to...
AWS Config Intermediate
Compliance check using AWS Config Rules: See how AWS Config can enhance your security and compliance with AWS managed rules and custom rules with AWS Lambda
Follow best practices with AWS Trusted Advisor auditing your AWS environment and advising you on performance, and security improvements.
Learn how to use Amazon GuardDuty to automatically uncover malicious EC2 activity and configure threat lists to improve the security of your AWS environments.
Monitor Amazon CloudWatch Security Logs for failed SSH attempts
Learn how to use CloudWatch to monitor EC2 instance logs for failed SSH attempts
AWS Key Management Service (KMS) Intermediate
In this lab, you'll learn about Amazon Key Management Service to encrypt S3 and EBS Data at an intermediate level. Get started today!
Learn how to increment the network security creating a public and private subnet on VPC and filter traffic using network ACL
Using S3 Bucket Policies and Conditions to Restrict Specific Permissions
You will learn the steps to create and apply AWS S3 Bucket Policies with embedded conditions to restrict a user's ability to perform specific functions within S3 Buckets.
Use Amazon Athena to query encrypted data on S3 and encrypt the query results as well.
Cloud Governance, Risk and Compliance Intermediate
Code Red: Repair an AWS Environment with a Linux Bastion Host
Preparation Exam: AWS Security Specialty Certification
About the Author
Stuart has been working within the IT industry for two decades covering a huge range of topic areas and technologies, from data centre and network infrastructure design, to cloud architecture and implementation.
To date, Stuart has created 50+ courses relating to Cloud, most within the AWS category with a heavy focus on security and compliance
He is AWS certified and accredited in addition to being a published author covering topics across the AWS landscape.
In January 2016 Stuart was awarded ‘Expert of the Year Award 2015’ from Experts Exchange for his knowledge share within cloud services to the community.
Stuart enjoys writing about cloud technologies and you will find many of his articles within our blog pages.