AWS Security Services (CLF-C02)

Welcome to the AWS Security Services practice lab. In this module, you will be provided with the instructions and devices needed to develop your hands-on skills.

AWS security services are designed to protect data, applications, and infrastructure within the AWS cloud. They offer comprehensive solutions for identity and access management, network security, encryption, threat detection, and compliance management. Some important implementation concepts are Security Groups and Network Access Control Lists (NACLs). These serve as fundamental components for controlling network traffic within Amazon Virtual Private Cloud (VPC) environments. Specifically, security groups acts as virtual firewalls at the instance level, allowing or denying traffic based on port, protocol, and IP address rules. NACLs operate at the subnet level, providing additional control over inbound and outbound traffic with rules based on IP addresses and port ranges.

AWS Marketplace complements these security measures by offering a vast selection of third-party security solutions and services, empowering users to enhance their cloud security posture through customizable and specialized offerings that address specific security needs and compliance requirements.

Overview

Learning Outcomes

In this module, you will complete the following exercises:

  • Exercise 1 – Security Groups and Network ACLs
  • Exercise 2 – AWS Marketplace

After completing this module, you should be able to:

  • Establish cloud infrastructure.
  • Use security group to block Internet Control Message Protocol (ICMP).
  • Use NACL to block Internet Control Message Protocol (ICMP).
  • Search for Center for Internet Security (CIS).

Exam Objectives

The following exam objectives are covered in this module:

2.4 Identify components and resources for security

  • Knowledge – Security capabilities that AWS provides.
  • Skills – Describing AWS security features and services (for example, security groups, NACLs, AWS WAF).
  • Skills – Understanding that third-party security products are available from AWS Marketplace.