← AWS Certified Security - Specialty
AWS · objective · 14% of the exam
Security Foundations and Governance — AWS Certified Security - Specialty
The official AWS documentation our Security Foundations and Governance practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — How to use trust policies with IAM roles | AWS Security Blog
This is referred to as the cross-account confused deputy problem.
-
Amazon Web Services — Get more out of service control policies in a multi-account environment | AWS Security Blog
a statement that allows access needs to exist at every level of a hierarchy; it’s not inherited. However, a Deny statement is inherited and evaluated
-
Amazon Web Services — Data protection in AWS Key Management Service - AWS Key Management Service
There is no mechanism for anyone, including AWS service operators, to view, access, or export plaintext key material. This principle applies even during catastrophic failures
-
Amazon Web Services — Features | AWS Key Management Service (KMS) | Amazon Web Services (AWS)
per FIPS 140 requirements, all firmware changes to KMS HSMs are submitted to a NIST accredited lab for validation in compliance with FIPS 140-3 Security
-
Amazon Web Services — Security best practices in IAM - AWS Identity and Access Management
To get started granting permissions to your users and workloads, use the AWS managed policies that grant permissions for many common use cases.
-
Amazon Web Services — Setting up a landing zone - AWS Prescriptive Guidance
AWS Control Tower automatically creates a Security OU that contains the Log Archive account and Audit account. These accounts enable centralized management and governance
-
Amazon Web Services — IAM roles - AWS Identity and Access Management
Emergency access – In a situation where you can't access your identity provider and you must take action in your AWS account.