Every AWS workload lives inside a network boundary, and misconfigured security groups, over-permissive IAM roles, or absent WAF rules are the most common root causes of production security incidents. This pillar gives you the foundation to design, audit, and lock down AWS environments correctly, from the VPC layer up through identity and threat detection.
What This Pillar Covers
- VPC and subnets — CIDR design, public/private subnets, NAT gateways, VPC peering, Transit Gateway
- Route 53 — DNS routing policies, health checks, and private hosted zones
- CloudFront — CDN distributions, cache behaviors, and origin access control
- IAM — roles, policies, permission boundaries, and the principle of least privilege
- KMS, WAF, and GuardDuty — encryption key management, web application firewall rules, and threat detection
Who This Is For
Cloud engineers and security-conscious DevOps engineers responsible for designing network topology, enforcing least-privilege access, and detecting threats across AWS accounts.