Skip to main content

AWS Security Engineering: Detect, Encrypt, Respond

Learn to secure AWS workloads end to end: threat detection with GuardDuty, encryption with KMS, secrets management, WAF, and incident response.

~3 hours
11 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why AWS Security Is Different From On-Premises Security

Who secures what: the shared responsibility model AWS secures the cloud itself, and you secure everything you put in it.

Understanding the AWS Security Services Landscape

Six services, six different questions AWS has no single security service.

Encrypting Data with AWS KMS

Choosing between the three KMS key types KMS key choice comes down to how much control your compliance or architecture needs.

Managing Secrets with Secrets Manager and Parameter Store

Choosing between Secrets Manager and Parameter Store Pick Secrets Manager when a credential must rotate automatically or be shared across accounts...

Stopping Web Attacks with WAF and Shield

Configuring AWS WAF rules A load balancer routes traffic but does not inspect intent, and that is what AWS WAF does.

Designing Defence in Depth and Zero Trust

Layering independent controls Defence in depth means layering independent controls so that when one fails, another still stands.

Skills You'll Master

GUARDDUTYKMSSECRETS-MANAGERWAFSECURITY-HUB

Curriculum Index11 topics

1

Understanding Why AWS Security Is Different From On-Premises Security

Who secures what: the shared responsibility model AWS secures the cloud itself, and you secure everything you put in it.

2

Understanding the AWS Security Services Landscape

Six services, six different questions AWS has no single security service.

3

Encrypting Data with AWS KMS

Choosing between the three KMS key types KMS key choice comes down to how much control your compliance or architecture...

4

Managing Secrets with Secrets Manager and Parameter Store

Choosing between Secrets Manager and Parameter Store Pick Secrets Manager when a credential must rotate automatically...

5

Stopping Web Attacks with WAF and Shield

Configuring AWS WAF rules A load balancer routes traffic but does not inspect intent, and that is what AWS WAF does.

6

Designing Defence in Depth and Zero Trust

Layering independent controls Defence in depth means layering independent controls so that when one fails, another...

7

Responding to a Security Incident in AWS

The response sequence: isolate, preserve, revoke, investigate A High severity finding at 3 AM is decided in the next...

8

Running Continuous Compliance with Security Hub

Understanding Security Hub and its 2025 naming changes Security Hub aggregates findings from GuardDuty, Inspector...

9

Choosing the Right Service for a Security Problem

Mapping symptoms to services In an interview or architecture review, the skill is picking the right service quickly...

10

Running the Hands-On Lab: A Security Incident Simulation

Before you start This lab runs one incident end to end on resources it creates: an alert, an isolated instance, a...

11

Quick Reference and Common Mistakes

Quick reference Common mistakes Assuming GuardDuty replaces Inspector is a frequent architecture error.

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

  • Platform Engineer

  • Cloud Engineer

  • DevOps Engineer

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

GuardDuty looks for malicious behavior happening now, such as a credential used from an impossible location. Inspector looks for weaknesses that could be exploited later, such as an unpatched library. You usually want both.

No. AWS managed keys are enough when you only need encryption at rest and audit visibility. Use a customer managed key when you need control over who can use it, cross-account sharing, or custom rotation and deletion rules.

No. Isolate it, snapshot its volumes, and revoke the credentials it used first. Terminating early destroys the running state that shows how the attacker got in.

Use Secrets Manager when a credential must rotate automatically or be shared across accounts. Use Parameter Store for static configuration and values you are happy to rotate by hand.