Security Engineering on AWS

Overview

This course demonstrates how to efficiently use AWS security services to stay secure in the AWS Cloud. The course focuses on the security practices that AWS recommends for enhancing the security of your data and systems in the cloud. It highlights the security features of AWS key services including compute, storage, networking, and database services. You will also learn how to leverage AWS services and tools for automation, continuous monitoring and logging, and responding to security incidents.

Course Objective

In this course, you will learn to:
• Identify security benefits and responsibilities of using the AWS Cloud
• Build secure application infrastructures
• Protect applications and data from common security threats
• Perform and automate security checks
• Configure authentication and permissions for applications and resources
• Monitor AWS resources and respond to incidents
• Capture and process logs
• Create and configure automated and repeatable deployments with tools such as AMIs
and AWS CloudFormation

Who Should Attend

This course is intended for:
• security engineers
• security architects
• information security professionals

Prerequisites

We recommend that attendees of this course have:
• Working knowledge of IT security practices and infrastructure concepts
• Familiarity with cloud computing concepts
• Completed AWS Security Essentials and Architecting on AWS instructor-led courses

Analyzing Data with MS Excel

Training Calendar

Intake

Duration

Program Fees

Inquire further

3 Days

Contact us to find out more

Module


• Security in the AWS cloud
• AWS Shared Responsibility Model
• Incident response overview
• DevOps with Security Engineering


• Identify the different ways to access the AWS platform
• Understanding IAM policies
• IAM Permissions Boundary
• IAM Access Analyzer
• Multi-factor authentication
• AWS CloudTrail
• Lab 01: Cross-account access


• Threats in a three-tier architecture
• Common threats: user access
• Common threats: data access
• AWS Trusted Advisor


• Amazon Machine Images
• Amazon Inspector
• AWS Systems Manager
• Lab 02: Using AWS Systems Manager and Amazon Inspector

FAQs

Q: What is this course about?
This three-day course, Security Engineering on AWS, demonstrates how to efficiently use AWS security services to maintain the security of your data and systems in the AWS Cloud. The course focuses on AWS-recommended security practices, covering key AWS services in compute, storage, networking, and database management. You will learn to build secure application infrastructures, protect data from common threats, configure authentication and permissions, and automate security checks using AWS tools.

Q: Who should attend this course?
This course is intended for security engineers, security architects, and information security professionals who want to enhance their understanding of AWS security services and best practices for securing cloud environments.

Q: What are the prerequisites for this course?
Participants should have working knowledge of IT security practices and infrastructure concepts, familiarity with cloud computing concepts, and have completed the AWS Security Essentials and Architecting on AWS instructor-led courses.

Q: How long is the course?
The course spans three days, providing a mix of theory and practical hands-on labs to help reinforce the learning experience in securing AWS environments.

Q: What key topics are covered in this course?

  • Overview of security in the AWS cloud and the Shared Responsibility Model

  • Identifying and managing access points with IAM policies, multi-factor authentication, and IAM Access Analyzer

  • Securing web application environments and addressing common security threats

  • Application security, including using Amazon Machine Images (AMIs) and Amazon Inspector

  • Data protection strategies, including encryption, and securing data in services like Amazon S3 and RDS

  • Network security with Amazon VPC, traffic mirroring, and Elastic Load Balancing

  • Monitoring and responding to security incidents with Amazon CloudWatch and AWS Config

  • Automation and repeatable deployments with AWS CloudFormation

  • Security considerations in hybrid and serverless environments

  • Threat detection using Amazon GuardDuty, AWS Security Hub, and Amazon Detective

  • Managing secrets with AWS KMS, Secrets Manager, and CloudHSM

Q: Will I receive a certification after completing the course?
This course provides practical skills in AWS security but does not include a certification upon completion. However, it prepares participants for AWS security-related certifications such as the AWS Certified Security – Specialty exam.

Q: What foundational AWS concepts will I strengthen in this course?
This course will strengthen your understanding of AWS security practices, covering key areas such as the AWS Shared Responsibility Model, IAM policies and permissions, encryption strategies, network security with VPC, and secure application deployment. You will also learn to automate security checks, monitor AWS resources for security incidents, and manage security in serverless and hybrid environments.

Q: How does the course help me apply AWS knowledge to real-world scenarios?
Through hands-on labs and demonstrations, you will apply AWS security skills to real-world scenarios, including securing data and applications, implementing automated security checks, configuring authentication and permissions, and monitoring for potential security incidents. You will gain the confidence to address real-world security challenges and deploy secure AWS solutions.

Q: What skills will I develop in implementing AWS services?
You will develop essential skills in securing AWS environments, such as configuring IAM policies, protecting data at rest with Amazon S3 and RDS, implementing security measures for network communication, automating security checks with AWS tools, monitoring security events with Amazon CloudWatch and AWS Config, and securing serverless applications using AWS Lambda and API Gateway.

Q: Will I learn how to work with different AWS security and monitoring tools?
Yes, the course places a strong emphasis on using AWS security and monitoring tools. You will work extensively with AWS IAM, Amazon Inspector, Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Amazon CloudWatch, AWS KMS, and AWS WAF to secure, monitor, and respond to security incidents within your AWS environment.

Q: How does this course prepare me for using AWS professionally?
This course equips you with the necessary skills to secure applications and data on AWS, configure authentication and permissions, automate security processes, and monitor and respond to security incidents. It prepares you for roles such as AWS Security Engineer, Cloud Security Architect, or Security Operations Engineer, and strengthens your readiness for certifications like the AWS Certified Security – Specialty.

Submit your interest today !

Contact us