Introduction
  • Course Expectations
  • Shared Responsibility Model
  • Encryption at rest
  • Encryption in transit
  • Services - Recap - Part 1
  • Services - Recap - Part 2
  • Services - Recap - Part 3
Key Management Service
  • Encryption Basics
  • Introduction to the Key Management Service
  • Encrypting and Decrypting
  • Working with Keys
  • Controlling Access
  • AWS KMS and Simple Storage Service
  • AWS KMS and Simple Storage Service - Demo
  • AWS KMS and EBS
  • Importing your key material
  • AWS KMS - Additional Aspects
  • Alias Keys
  • DynamoDB Encryption
  • Using your own key pair for EC2
  • Cloud HSM
Security Perspective
  • AWS Security
  • Securing your account
  • Incident Response Plan
  • What happens if resources have been compromised
  • Penetration Testing
  • AWS Inspector
  • S3 Lifecycle policies
Identity and Access Management
  • IAM Policies
  • IAM Policies - Demo
  • S3 Bucket Policies
  • S3 Bucket Policy Conditions - Demo
  • IAM Roles
  • IAM Roles - Demo
  • IAM Policies Additional aspects
  • Cross Account Roles
  • Cross Account Access - Further aspects
  • Cross Account Roles - External ID Demo
  • AWS Organizations
  • S3 Pre-Signed URLs
  • Cloudfront - Private Content
  • AWS Cognito
Networking - Security
  • Encryption of data in transit
  • VPC Security - Introduction
  • Security Groups - Demo
  • Network Access Control Lists - Demo
  • Elastic Load Balancer Security Groups
  • NAT Instances and Gateways
  • NAT gateway - Demo
  • VPC Peering
  • VPC peering - Demo
  • Mitigation against DDoS attacks
  • Windows AD and DNS Security
  • VPC Endpoints
  • VPC Endpoints - Further aspects
  • VPC Endpoints and KMS
  • VPC Endpoints and KMS - Additional aspects
  • How to tackle packet inspection on AWS EC2 Instances
  • Web Application Firewall
  • AWS Trusted Advisor
  • Security for AWS VPC
Monitoring
  • Cloudtrail
  • CloudTrail Demo
  • CloudTrail File Validation
  • Cloud Trail Logs from Multiple accounts
  • Cloudwatch Logs - Using the agent
  • Monitoring your KMS Keys
  • VPC Flow Logs
AWS Resource Configuration
  • AWS Config Service
  • AWS Config - Using Rules
  • AWS Systems Manager - Introduction
  • AWS Systems Manager - Inventory
  • AWS Systems Manager - Run Command
  • AWS Systems Manager - Parameter Store
  • AWS Systems Manager - Agent Troubleshooting
  • AWS Systems Manager - Patch Manager
Conclusion
  • The Exam itself
  • Exam Details
  • Practice Test