Skip to main content

AWS Security Baseline and Guardrails

Learn to set an AWS security baseline: Identity Center, guardrails with SCPs, CloudTrail, Config, Access Analyzer, and Security Hub across accounts.

~3 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Most AWS Breaches Are Misconfigurations

A Friday evening bucket policy A retail team at a fictional company, acme-shop, needs to share an order export with a vendor in Hyderabad.

Securing the Root User and Account Basics

Locking down the root user Every AWS account has a root user with unlimited power that cannot be restricted by IAM policies, so protecting it is the...

Giving People Access with IAM Identity Center

Why Identity Center replaces IAM users A long-lived access key on a laptop is a breach waiting for a git push.

Setting Guardrails with Organizations and SCPs

What a service control policy does Permissions inside an account can be changed by anyone with enough IAM rights, including an attacker who gets...

Recording Everything with an Organisation CloudTrail

What CloudTrail records and for how long Without an audit trail you cannot answer who did what, when, and from where.

Finding Unintended Access with IAM Access Analyzer

What Access Analyzer reports You cannot review every resource policy by hand, and a wrong one can expose data to the whole internet.

Skills You'll Master

AWS-SECURITYSCPIAM-IDENTITY-CENTERAWS-CONFIGCLOUDTRAIL

Curriculum Index10 topics

1

Understanding Why Most AWS Breaches Are Misconfigurations

A Friday evening bucket policy A retail team at a fictional company, acme-shop, needs to share an order export with a...

2

Securing the Root User and Account Basics

Locking down the root user Every AWS account has a root user with unlimited power that cannot be restricted by IAM...

3

Giving People Access with IAM Identity Center

Why Identity Center replaces IAM users A long-lived access key on a laptop is a breach waiting for a git push.

4

Setting Guardrails with Organizations and SCPs

What a service control policy does Permissions inside an account can be changed by anyone with enough IAM rights...

5

Recording Everything with an Organisation CloudTrail

What CloudTrail records and for how long Without an audit trail you cannot answer who did what, when, and from where.

6

Finding Unintended Access with IAM Access Analyzer

What Access Analyzer reports You cannot review every resource policy by hand, and a wrong one can expose data to the...

7

Tracking Configuration with AWS Config and Security Hub

What AWS Config does Config answers a question CloudTrail cannot: what did this resource look like last Tuesday, and...

8

Turning On Threat Detection as Part of the Baseline

GuardDuty in the baseline A baseline that only records what happened still needs something watching in real time.

9

Running the Hands-On Lab: Baseline a Sandbox Account

Before you start You will turn on Access Analyzer and Config in one Region, create a deliberately exposed bucket, watch...

10

Quick Reference and Common Mistakes

Quick reference Common mistakes Using the root user for daily work leaves an unrestrictable credential in constant use.

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Cloud Security Engineer

    ₹14L - ₹32L a year

    High Demand
  • Cloud Engineer

    ₹10L - ₹24L a year

    High Demand
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Identity Center gives people one sign-in and short-lived credentials for every account, so there are no long-lived access keys to leak or rotate. It also connects to your company identity provider, which means MFA and offboarding happen in one place. IAM users with static keys are the legacy approach.

No. An SCP only sets the maximum permissions available in the accounts it is attached to. A user still needs an IAM policy that allows the action, and an explicit deny in an SCP overrides any allow.

Management events are enough for most baselines, because they record who changed what. Data events record object-level activity such as S3 reads and bill per event, so enable them only for sensitive buckets or functions where you need that audit trail.

Config records how resources are configured over time and evaluates them against rules. Security Hub collects findings from several services and runs security standards, giving you a posture view. Config is the recorder and rule engine, and Security Hub is the dashboard on top.