All certifications / Security Specialty / Cheat sheet
Security Specialty SCS-C03 cheat sheet
Domain 1: Detection (16%)
Exam tips
- When a question asks how to detect that an application is down or slow, think CloudWatch alarms and health checks; when it asks who did something, think CloudTrail. Do not pick a threat detection service for a pure availability problem.
- Watch for the word 'object' in a question: reads, writes and deletes of S3 objects are data events. Also remember that encryption of log files protects confidentiality, while integrity validation proves they were not changed.
- If an answer says you must enable VPC Flow Logs or DNS logging before GuardDuty can use them, it is wrong. Also remember that GuardDuty detects and reports; it does not block traffic by itself.
- If a question says Security Hub controls show no data, check whether AWS Config is recording the relevant resource types. Many control checks depend on Config.
- Flow logs show REJECT for traffic blocked by a security group or network ACL, but not which one blocked it, and they never show DNS names or payloads. Choose the log that actually contains the data the question asks about.
- Match the time frame and format to the tool: recent operational logs in CloudWatch, Logs Insights; long-term files in S3, Athena; normalized cross-source data lake, Security Lake; full-text search dashboards, OpenSearch.
- For 'alert when X happens once, in near real time', choose an EventBridge rule; for 'alert when X happens more than N times', choose a metric filter and alarm. A scheduled query is almost never the fastest answer.
- When logs stop right after a change, the change is almost always the cause: a bucket policy edit, a new KMS key, or a new SCP or RCP. Look for the answer that restores the service principal's access in the narrowest way.
Key terms
- CloudWatch alarm
- A rule that watches a metric against a threshold over time and changes state to ALARM, which can trigger notifications or actions.
- Composite alarm
- An alarm whose state depends on a logical combination of other alarms, used to reduce noisy alerts.
- Route 53 health check
- A probe from AWS locations that tests whether an endpoint responds, or follows a CloudWatch alarm, and can drive DNS failover.
- Monitoring requirement
- A written statement of what must be observed for a workload, where the data comes from and who is alerted.
- Management event
- A control-plane API call, such as creating a user or changing a bucket policy, logged by trails by default.
- Data event
- A high-volume resource operation, such as reading an S3 object or invoking a Lambda function, logged only when enabled.
- Organization trail
- A trail created from the management or delegated administrator account that logs all member accounts and cannot be changed by them.
- Digest file
- An hourly signed file with hashes of delivered log files, used to validate log integrity.
- Foundational data sources
- CloudTrail management events, VPC Flow Logs and DNS logs that GuardDuty analyzes from its own streams.
- Protection plan
- An optional GuardDuty feature that adds a data source or scanning capability, such as S3 Protection or Runtime Monitoring.
- Suppression rule
- A filter that automatically archives findings matching criteria, used for known benign activity.
- Delegated administrator
- A member account given permission by the management account to manage a service for the whole organization.
- ASFF
- AWS Security Finding Format, the JSON format Security Hub uses for findings from all sources.
- Security standard
- A set of controls, such as CIS or AWS Foundational Security Best Practices, that Security Hub checks against your resources.
- Cross-Region aggregation
- A setting that brings findings from linked Regions into one aggregation Region.
- Automation rule
- A rule that automatically updates or suppresses findings that match criteria when Security Hub receives them.
- VPC Flow Logs
- Records of IP traffic metadata on network interfaces, subnets or VPCs, including ACCEPT or REJECT, without payloads.
- Resolver query logging
- A feature that logs DNS queries made by resources in a VPC to the Route 53 Resolver.
- S3 server access logs
- Best-effort logs of requests made to an S3 bucket, delivered to another bucket.
- Traffic Mirroring
- A VPC feature that copies actual network packets from an interface to a monitoring target.
- CloudWatch Logs Insights
- A query language and console for searching and aggregating data in CloudWatch Logs.
- Amazon Athena
- A serverless SQL engine that queries data where it sits in S3, billed by data scanned.
- OCSF
- Open Cybersecurity Schema Framework, an open, vendor-neutral schema for security events.
- Amazon Security Lake
- A service that collects and normalizes security data to OCSF in an S3 data lake owned by the customer.
- Event pattern
- A JSON filter in an EventBridge rule that selects which events trigger its targets.
- Metric filter
- A CloudWatch Logs pattern that turns matching log events into a CloudWatch metric.
- SNS topic
- A publish and subscribe channel that fans out notifications to subscribers such as email or Lambda.
- Cross-account event bus
- An EventBridge bus in another account that receives events, used to centralize security events.
- Service principal
- An identifier such as cloudtrail.amazonaws.com that represents an AWS service in policies.
- get-trail-status
- A CloudTrail API call that shows whether a trail is logging and any recent delivery errors.
- aws:SourceArn
- A condition key that ties a service principal's permission to one specific resource, such as a trail.
- Encryption context
- Extra key-value data bound to a KMS operation, used in policies and logged in CloudTrail.
Domain 2: Incident Response (14%)
Exam tips
- When a question asks how to make a response consistent and repeatable, prefer an automated runbook (Systems Manager Automation, Step Functions or Lambda) triggered by an event over a manual checklist.
- Look for 'before an incident' clues: the right answers pre-create roles, keys, accounts and runbooks. An answer that grants broad access only after the incident starts, or shares credentials informally, is a trap.
- Deactivate first, delete later. For roles, the answer is revoke sessions, not deleting the role, which would break healthy workloads.
- Any answer that stops or terminates the instance before capturing memory loses evidence. And if an attacker's session survives a security group change, the explanation is connection tracking; a network ACL fixes it.
- Detective is for visual investigation and relationships over time; CloudTrail Lake and Athena are for exact queries; GuardDuty raises the alert. Match the verb in the question: investigate and visualize, query, or detect.
- Single quick action: Lambda. Multi-step with retries or approvals: Step Functions. Fix a noncompliant configuration: Config remediation with an Automation document. Change or suppress findings: Security Hub automation rules.
- Snapshots encrypted with the default AWS managed EBS key cannot be shared with another account. For evidence sharing, the answer involves a customer managed key the forensics account can use, or re-encrypting the copy.
- Recovery answers restore from clean backups and rebuild from trusted images; answers that clean and reuse the compromised system are traps. For backups that even administrators cannot delete, look for Vault Lock in compliance mode.
Key terms
- Playbook
- A plan for handling one type of incident, including its detection, decision points and runbooks.
- Runbook
- A step-by-step procedure, ideally automated, for carrying out a response task.
- Systems Manager Automation
- A service that runs runbook documents with steps that call AWS APIs and scripts, triggered manually or by events.
- OpsCenter
- A Systems Manager capability that tracks operational issues as OpsItems with related resources and runbooks.
- Break-glass access
- Emergency credentials, tightly protected and monitored, used only when normal access paths fail.
- Forensics account
- An isolated AWS account used to store evidence and run analysis away from production.
- Game day
- A practice event that simulates an incident to test people, processes and tools.
- Tabletop exercise
- A discussion-based walkthrough of an incident scenario to test roles and decisions.
- Deactivate access key
- Setting an IAM access key to Inactive so it stops working but still exists for investigation.
- Revoke active sessions
- An IAM role action that denies all requests from sessions issued before a chosen time.
- aws:TokenIssueTime
- A condition key holding the time temporary credentials were issued.
- Persistence
- Changes an attacker makes to keep access, such as creating new users, keys or roles.
- Isolation security group
- A security group with no or minimal rules used to cut a compromised instance off from the network.
- Tracked connection
- A flow a stateful security group remembers, which stays open even after the rules that allowed it are removed.
- Memory capture
- Acquiring a copy of a running system's RAM to preserve volatile evidence.
- Termination protection
- An EC2 setting that prevents an instance from being terminated through the API or console until turned off.
- Behavior graph
- Detective's linked model of entities and their activity built from logs and findings.
- Finding group
- A Detective grouping of related findings and entities that likely belong to one security event.
- Event data store
- A CloudTrail Lake store of events that can be queried with SQL.
- Scoping
- Determining the extent of an incident: affected accounts, resources, data and time frame.
- Step Functions
- A workflow service that coordinates multiple steps with retries, branching and waits, useful for multi-step response.
- Automatic remediation
- An AWS Config feature that runs a Systems Manager Automation document when a rule finds a noncompliant resource.
- Custom action
- A Security Hub feature that sends chosen findings to EventBridge when an analyst selects them.
- Human approval step
- A pause in an automated workflow that waits for a person to confirm a risky action.
- Chain of custody
- A record of who collected, transferred, stored and accessed each piece of evidence, and when.
- Legal hold
- An S3 Object Lock setting that prevents deletion of an object version until the hold is removed, with no fixed end date.
- Hash
- A fixed-length fingerprint of a file, such as SHA-256, used to prove it has not changed.
- WORM
- Write once, read many: storage that cannot be modified or deleted after writing.
- AWS Backup
- A service that centrally manages backup plans and recovery points across AWS services and accounts.
- Backup Vault Lock
- A setting that enforces write-once retention on a backup vault, preventing deletion of recovery points.
- Root cause
- The underlying weakness that allowed an incident, as opposed to its symptoms.
- Post-incident review
- A blameless meeting after an incident to document the timeline, causes and improvements.
Domain 3: Infrastructure Security (18%)
Exam tips
- SQL injection, XSS, bad bots and HTTP floods point to AWS WAF; large network-layer DDoS points to Shield; non-HTTP traffic points to security groups, network ACLs or Network Firewall.
- Cost protection, the response team and advanced reporting only come with Shield Advanced. If a question says 'at no additional cost' for basic DDoS protection, the answer is Shield Standard.
- One file, or clients without cookie support: signed URLs. Many files: signed cookies. New designs use OAC rather than OAI, especially with SSE-KMS.
- Need to deny a specific IP: network ACL. Need to reference another tier: security group. Need domain filtering or IPS on traffic: Network Firewall. Need to block DNS lookups: DNS Firewall.
- S3 or DynamoDB with no hourly cost: gateway endpoint. Other services: interface endpoint. Restricting which buckets can be reached from the VPC: endpoint policy. Restricting which network can reach a bucket: bucket policy with aws:SourceVpce.
- Direct Connect is private but not encrypted. Encryption over it means MACsec (layer 2) or VPN over Direct Connect (IPsec, layer 3).
- No open ports, no keys, audited sessions: Session Manager. Protect instance role credentials from SSRF: require IMDSv2.
- Inspector finds vulnerabilities; it does not fix them. Pair it with Patch Manager, image rebuilds or code changes. Do not confuse it with GuardDuty (threats) or Macie (sensitive data).
- One path, why is it blocked: Reachability Analyzer. All unintended paths across the network: Network Access Analyzer. Actual packet contents: Traffic Mirroring.
Key terms
- Web ACL
- A set of AWS WAF rules and a default action attached to a protected web resource.
- Managed rule group
- A maintained set of WAF rules from AWS or a Marketplace seller, such as the core rule set.
- Rate-based rule
- A WAF rule that blocks or challenges sources whose request count exceeds a limit in a time window.
- Count action
- A WAF action that records matches without blocking, used to test rules safely.
- Shield Standard
- Free, automatic protection against common network and transport layer DDoS attacks.
- Shield Advanced
- A paid service adding enhanced detection, the Shield Response Team, cost protection and automatic layer 7 mitigation.
- Shield Response Team
- AWS DDoS experts available 24/7 to Shield Advanced customers during attacks.
- Firewall Manager
- A service that applies WAF, Shield Advanced, security group and firewall policies across an organization.
- Origin access control
- A CloudFront feature that signs requests to an S3 origin so the bucket can allow only that distribution.
- Signed URL
- A URL with an expiry and signature that grants access to one CloudFront object.
- Signed cookie
- A set of cookies that grants access to multiple CloudFront objects without changing their URLs.
- Field-level encryption
- CloudFront encryption of chosen request fields at the edge with a public key.
- Security group
- A stateful, allow-only firewall attached to network interfaces.
- Network ACL
- A stateless subnet firewall with numbered allow and deny rules evaluated in order.
- AWS Network Firewall
- A managed stateful firewall and intrusion prevention service deployed in VPC subnets.
- DNS Firewall
- A Route 53 Resolver feature that blocks or alerts on DNS queries for listed domains.
- Gateway endpoint
- A free route-table-based endpoint for private access to S3 or DynamoDB.
- Interface endpoint
- An elastic network interface with a private IP that provides PrivateLink access to a service.
- Endpoint policy
- A policy on a VPC endpoint that limits which actions and resources can be reached through it.
- aws:SourceVpce
- A condition key holding the ID of the VPC endpoint a request came through.
- Site-to-Site VPN
- An IPsec VPN with two tunnels between an on-premises gateway and AWS.
- Direct Connect
- A private, dedicated network connection to AWS that is not encrypted by default.
- MACsec
- IEEE 802.1AE layer-2 encryption available on supported Direct Connect dedicated connections.
- Verified Access
- A zero trust service that grants access to applications per request based on identity and device posture.
- Session Manager
- A Systems Manager capability that provides audited shell access without open inbound ports or SSH keys.
- IMDSv2
- The token-based version of the instance metadata service that protects instance credentials from SSRF.
- Patch baseline
- A Patch Manager rule set defining which patches are approved for installation.
- EC2 Image Builder
- A service that automates building, hardening and testing machine images.
- CVE
- Common Vulnerabilities and Exposures, a public identifier for a known software vulnerability.
- Network reachability finding
- An Inspector finding showing that a port on an instance can be reached from outside.
- Inspector score
- A risk score based on CVSS and adjusted using details of your environment.
- SBOM
- Software bill of materials, a list of the packages and versions in a workload.
- Reachability Analyzer
- A tool that analyzes configuration to show whether a network path exists between two resources and what blocks it.
- Network Access Analyzer
- A tool that finds network paths that violate a defined Network Access Scope.
- Network Access Scope
- A definition of which network access is or is not allowed, used by Network Access Analyzer.
- Mirror filter
- Rules that choose which traffic Traffic Mirroring copies.
Domain 4: Identity and Access Management (20%)
Exam tips
- Guardrails (SCPs, RCPs, boundaries, session policies) never grant anything; they only cap. If every answer choice adds a guardrail allow but no identity or resource allow, none of them will make the request succeed.
- ABAC questions often include a trap where users could change their own tags or a resource's tags. The complete answer also restricts tagging actions.
- Third-party vendor assuming a role: external ID. AWS service principal writing to or publishing into your resource: aws:SourceArn and aws:SourceAccount. Both prevent confused deputy problems.
- Many accounts plus an existing corporate IdP: IAM Identity Center with SAML and SCIM. IAM users for people, or per-account SAML setups, are usually the wrong answer at scale.
- Sign-in and tokens: user pool. AWS credentials for app users: identity pool. Business rules for who can do what inside the app: Verified Permissions.
- Outside AWS with certificates: Roles Anywhere. Pipelines with OIDC tokens: OIDC identity provider plus a role with strict sub conditions. Pods in EKS: Pod Identity or IRSA, never the node role.
- Root access keys should never exist. For many member accounts, the modern answer is centralized root access management, not a drawer full of MFA devices.
- Shared outside the account or organization: external access analyzer. Never used: unused access analyzer. Build a policy from what a role actually did: policy generation.
- For encrypted data, access needs permission on both the data (S3, EBS, RDS) and the KMS key. Many 'I have s3:GetObject but still get AccessDenied' questions are really KMS or endpoint policy questions.
Key terms
- Implicit deny
- The default result for any request that no policy allows.
- Explicit deny
- A Deny statement that matches a request and overrides every Allow.
- Permissions boundary
- A managed policy that sets the maximum permissions for one IAM user or role.
- Session policy
- A policy passed when creating a temporary session that further limits that session's permissions.
- Condition key
- A named value in the request context, such as aws:SourceIp, that a policy condition can test.
- ABAC
- Attribute-based access control: granting access by comparing tags on principals and resources.
- Policy variable
- A placeholder such as ${aws:username} that IAM replaces with a value from the request.
- Session tags
- Tags passed when assuming a role or federating, used as principal tags for that session.
- Trust policy
- The resource-based policy on a role that specifies who can assume it.
- AWS STS
- The Security Token Service, which issues temporary credentials for roles and federated users.
- External ID
- A unique value required in a role's trust policy to prevent confused deputy attacks by third parties.
- Confused deputy
- A situation where a trusted entity is tricked into using its permissions on behalf of an unauthorized party.
- IAM Identity Center
- The AWS service for central workforce sign-in and access to multiple accounts and applications.
- Permission set
- A template of policies that Identity Center turns into roles in assigned accounts.
- SCIM
- A standard for automatically provisioning and deprovisioning users and groups between systems.
- SAML 2.0
- An XML-based standard for exchanging authentication assertions between an identity provider and a service.
- User pool
- A Cognito user directory that authenticates users and issues JWT tokens.
- Identity pool
- A Cognito feature that exchanges identity tokens for temporary AWS credentials through IAM roles.
- JWT
- JSON Web Token, a signed token that carries claims about a user.
- Cedar
- The open policy language used by Amazon Verified Permissions for application authorization.
- IAM Roles Anywhere
- A service that lets workloads outside AWS exchange X.509 certificates for temporary role credentials.
- Trust anchor
- The CA certificate that Roles Anywhere uses to verify workload certificates.
- OIDC federation
- Trusting tokens from an OpenID Connect provider to assume an IAM role with AssumeRoleWithWebIdentity.
- EKS Pod Identity
- An EKS feature that maps an IAM role to a Kubernetes service account for pod credentials.
- Root user
- The identity created with an AWS account, with complete access that IAM policies cannot limit in a standalone account.
- Centralized root access
- An Organizations feature to remove member account root credentials and perform root tasks through short-term sessions.
- sts:AssumeRoot
- The STS action used to get a task-scoped root session for a member account.
- Credential report
- An IAM CSV report of all users' passwords, access keys, their ages and MFA status.
- Zone of trust
- The account or organization that Access Analyzer treats as trusted when reporting external access.
- External access finding
- A report that a resource policy allows access from outside the zone of trust.
- Unused access finding
- A report of unused roles, credentials or permissions over a tracking period.
- Archive rule
- A rule that automatically archives Access Analyzer findings that match expected patterns.
- AccessDenied
- The error code returned when an authorization check fails for a request.
- Policy simulator
- An IAM tool that evaluates policies for a principal, action and resource and explains the result.
- decode-authorization-message
- An STS command that decodes the detailed reason in some encoded access denied errors.
- get-caller-identity
- An STS call that returns the account, ARN and user ID of the credentials in use.
Domain 5: Data Protection (18%)
Exam tips
- To require TLS for S3, use an explicit Deny when aws:SecureTransport is false; an Allow with true is not enough because other statements could still allow HTTP.
- If a principal has kms:Decrypt in IAM but is still denied, check whether the key policy allows the account or the principal. Key policy first, IAM second.
- Decrypt in another Region without re-encrypting: multi-Region key. Single-tenant HSM under your control but still used through KMS: CloudHSM key store. Keys never inside AWS: external key store.
- Need key control and audit: SSE-KMS with a customer managed key. Need lower KMS cost at scale: Bucket Keys. Client must hold the key and AWS must not store it: SSE-C.
- The key difference: governance can be bypassed with a permission; compliance cannot be bypassed by anyone, not even root. If the question says 'including the root user', choose compliance mode.
- Automatic rotation of database credentials: Secrets Manager. Cheap encrypted configuration without rotation: Parameter Store SecureString. Internal certificates: AWS Private CA.
- Finding sensitive data in S3: Macie. Finding threats: GuardDuty. Finding vulnerabilities: Inspector. The exam often lists all three as options.
- No AWS data store lets you flip an existing unencrypted EBS volume or RDS instance to encrypted in place. The answer is almost always snapshot, encrypted copy, restore or new volume.
- Stop the model revealing PII: Guardrails with sensitive information filters. Keep traffic off the internet: interface VPC endpoint. Record what was asked and answered: invocation logging. Limit which models are used: IAM and SCPs.
Key terms
- ACM
- AWS Certificate Manager, which provisions, deploys and renews TLS certificates for AWS services.
- ELB security policy
- A predefined set of TLS protocol versions and ciphers a load balancer listener accepts.
- aws:SecureTransport
- A condition key that is true when a request arrives over TLS.
- Mutual TLS
- TLS in which both the client and server present certificates to authenticate each other.
- Customer managed key
- A KMS key you create and fully control, including its policy, rotation and deletion.
- Key policy
- The resource-based policy on a KMS key; it must allow access before IAM policies can grant it.
- Grant
- A KMS mechanism that delegates specific key operations to a principal and can be retired or revoked.
- Encryption context
- Non-secret key-value data bound to ciphertext that must match on decrypt and is logged in CloudTrail.
- Multi-Region key
- One of a set of KMS keys in different Regions sharing the same key ID and key material.
- Imported key material
- Key material you generate outside AWS and import into a KMS key.
- CloudHSM key store
- A KMS custom key store backed by a single-tenant CloudHSM cluster you control.
- External key store
- A KMS custom key store that uses keys held in an HSM outside AWS.
- SSE-KMS
- S3 server-side encryption using an AWS KMS key, with key policy control and CloudTrail logging.
- DSSE-KMS
- Dual-layer server-side encryption with KMS keys, applying two layers of encryption to objects.
- S3 Bucket Key
- A bucket-level key that reduces KMS requests and costs for SSE-KMS.
- Bucket owner enforced
- An Object Ownership setting that disables ACLs so the bucket owner owns all objects.
- Object Lock governance mode
- Retention that most users cannot override, but that principals with a bypass permission can.
- Object Lock compliance mode
- Retention that no one, including root, can shorten or remove until it expires.
- Legal hold
- An Object Lock flag that prevents deletion until it is removed, with no expiry date.
- Backup Vault Lock
- An AWS Backup feature that enforces WORM retention on recovery points in a vault.
- Secrets Manager rotation
- Automatic replacement of a secret's value on a schedule using managed or Lambda-based rotation.
- SecureString
- A Parameter Store parameter type encrypted with a KMS key.
- AWS Private CA
- A managed private certificate authority service for issuing internal certificates.
- Certificate revocation list
- A signed list of certificates a CA has revoked before their expiry.
- Managed data identifier
- A built-in Macie detection pattern for a type of sensitive data.
- Custom data identifier
- A user-defined pattern, such as a regular expression with keywords, for Macie to detect.
- Automated sensitive data discovery
- Macie sampling of objects across buckets to estimate where sensitive data lives.
- logs:Unmask
- The permission that lets a principal see values masked by a CloudWatch Logs data protection policy.
- EBS encryption by default
- An account and Region setting that encrypts all new EBS volumes and snapshot copies.
- Snapshot copy with encryption
- The method for creating an encrypted copy of unencrypted EBS or RDS data.
- Transparent Data Encryption
- Database-engine encryption for Oracle and SQL Server that encrypts data files.
- S3 Batch Operations
- A feature that runs an action, such as copy with new encryption, across many S3 objects.
- Bedrock Guardrails
- Configurable filters for prompts and responses, including content, topic, word and sensitive information filters.
- Model invocation logging
- A Bedrock setting that records prompts, responses and metadata to CloudWatch Logs or S3.
- Prompt injection
- An attack that hides instructions in input to make a model ignore its intended rules.
- Retrieval-augmented generation
- A pattern where a model answers using documents retrieved from a knowledge base.
Domain 6: Security Foundations and Governance (14%)
Exam tips
- The management account should be nearly empty and rarely used. Answers that run security tooling or workloads in the management account are usually wrong when a delegated administrator option exists.
- Limit what our people can do: SCP. Limit who can touch our resources, including outsiders: RCP. Enforce a service setting such as IMDSv2 or public sharing blocks: declarative policy.
- When the question asks how to manage a security service for all accounts including future ones, the answer is a delegated administrator with auto-enable, not scripts or invitations.
- Every account including future ones: StackSets with service-managed permissions and automatic deployment. Let users deploy without broad permissions: Service Catalog launch constraints. Catch problems before deployment: Guard or Hooks.
- Detective controls that report configuration: Config rules. A packaged set of them across the organization: conformance packs. One view of all accounts: aggregator. Blocking the action in the first place is not Config's job.
- The word 'AWS's report' or 'agreement with AWS' means Artifact. 'Collect evidence about our resources for an audit' means Audit Manager.
- Tag policies standardize, they do not require. When a question says 'prevent creation without a tag', the answer is an SCP or IAM policy with an aws:RequestTag condition.
- For shared responsibility questions, ask whether the customer can even reach the component. If you cannot log in to it, such as the RDS host OS or the hypervisor, it is AWS's job.
Key terms
- Organizational unit
- A group of accounts in AWS Organizations to which policies can be attached.
- Landing zone
- A well-architected multi-account baseline with shared accounts, logging, identity and guardrails.
- Log archive account
- A dedicated account that stores logs from all accounts with strict protections.
- Control Tower control
- A preventive, detective or proactive guardrail managed by Control Tower.
- Service control policy
- An Organizations policy that limits the maximum permissions of principals in member accounts.
- Resource control policy
- An Organizations policy that limits the maximum permissions on resources in member accounts.
- Declarative policy
- An Organizations policy that enforces a baseline configuration of a service, such as EC2 settings.
- Data perimeter
- A set of guardrails ensuring only trusted identities access trusted resources from expected networks.
- Trusted access
- An Organizations setting that allows an AWS service to work across the organization's accounts.
- Delegated administrator
- A member account registered to manage a specific service for the whole organization.
- Auto-enable
- A setting that turns on a security service automatically for new organization member accounts.
- Central configuration
- A Security Hub feature to set standards and controls for many accounts and Regions from one place.
- StackSet
- A CloudFormation feature that deploys one template to multiple accounts and Regions.
- Service-managed permissions
- A StackSets mode using Organizations that can auto-deploy to new accounts in target OUs.
- Launch constraint
- A Service Catalog setting that assigns the IAM role used to launch a product.
- CloudFormation Guard
- A policy-as-code tool that validates templates against rules.
- Configuration item
- A point-in-time record of a resource's configuration captured by AWS Config.
- Config rule
- A check that evaluates whether resources meet a desired configuration.
- Conformance pack
- A collection of Config rules and remediation actions deployed and reported as one unit.
- Aggregator
- A Config resource that gathers configuration and compliance data from multiple accounts and Regions.
- AWS Artifact
- A portal for downloading AWS compliance reports and accepting agreements such as the BAA.
- AWS Audit Manager
- A service that continuously collects evidence from your AWS usage and maps it to audit frameworks.
- Assessment report
- An Audit Manager output bundling selected evidence for auditors.
- Business Associate Addendum
- An agreement with AWS required before storing protected health information under HIPAA.
- Tag policy
- An Organizations policy that standardizes tag keys and allowed values across accounts.
- aws:RequestTag
- A condition key for tags included in a create or tag request.
- aws:TagKeys
- A condition key listing the tag keys in a request, used to limit which keys can be set.
- Backup policy
- An Organizations policy that deploys AWS Backup plans across accounts, often selecting resources by tag.
- Shared responsibility model
- The division of security duties between AWS (of the cloud) and the customer (in the cloud).
- Security pillar
- The Well-Architected Framework section with principles and best practices for security.
- Trusted Advisor
- An AWS service that checks accounts and recommends improvements, including security checks.
- STRIDE
- A threat modeling mnemonic: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
Study Security Specialty for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Security Specialty study planLessons, quizzes, exam simulations and hands-on labs.