Security on AWS

7 Labs · 59 Credits · 5h 28m

Use Case (Experienced) Security quest badge

In this quest, you’ll start by learning the basics of IAM and security-related features and tools such as Security Groups, VPCs, and the AWS Web Application Firewall. Then you'll tie these foundations together with AWS Lambda, CloudTrail, CloudWatch, EMR, Elasticsearch and Key Management Service to automate monitoring, alerting, and data mining the reports and logs of these tools to identify and report on security events.

Introduction to AWS Identity and Access Management (IAM)

This lab shows you how to manage access and permissions to your AWS services using AWS Identity and Access Management (IAM). Practice the steps to add users to groups, manage passwords, log in with IAM-created users, and see the effects of IAM policies on access to specific services.

For the lab to function as written, please DO NOT change the auto assigned region.

Icon  intro introductory 1 积分 25 Minutes

对 AWS 环境执行基本审核

本实验将逐步指导您对核心 AWS 资源执行基本审核。您将使用 AWS 管理控制台来了解如何对多项 AWS 服务、Amazon EC2、Amazon VPC、Amazon IAM、Amazon 安全组、AWS CloudTrail 和 Amazon CloudWatch 的使用情况进行审核。本实验将帮助您了解如何对与 AWS 中的组织监管、资产配置、逻辑访问控制、操作系统、数据库和应用程序安全配置相关的现有审核目标进行扩展。掌握本实验中的技能有助于实现可见性、可测试性和审核证据自动收集能力。

Icon  fundamental Fundamental 8 积分 30 Minutes

Monitoring Security Groups with Amazon CloudWatch Events

In this lab you will learn how to use AWS CloudWatch events with a Lambda function to detect changes to the ingress permissions of an EC2 security group. In an different lab, Monitoring Security Groups with AWS Config, you will do something similar but with different services. Both of these labs illustrate techniques that could be used to provide additional layers of protection to infrastructure controls. Prerequisites: To successfully complete this lab, you should be familiar with EC2 security groups. Python programming skills are helpful, although full solution code is provided. It would be helpful to have taken the Introduction to AWS Lambda lab at

Icon  advanced advanced 10 积分 45 Minutes

Update Security Groups Automatically Using AWS Lambda

Security is a top priority for Amazon Web Services (AWS). AWS provides many tools and services to meet your unique security needs. This lab will present a solution, among many, to enhance your security. This lab walks through a method to automatically update your Virtual Private Cloud (VPC) Security Groups to only allow access from Amazon CloudFront and AWS Web Application Firewall (WAF). Defining Security Groups rules this way prevents malicious requests from by-passing AWS WAF security rules and accessing your EC2 instances directly.

Icon  advanced Advanced 10 积分 47 Minutes

Visualizing Security Groups with Amazon Elasticsearch Service

Enforcing the principle of least privilege in Security Groups is an important component in the overall security of an application. This task can become more complicated as an application grows in scope and complexity. In this lab we will walk through using VPC Flow Logs and the Amazon Elasticsearch Service to visualize the usage of Security Groups in order to help identify which rules might be too permissive.

Icon  advanced Advanced 10 积分 50 Minutes

Protect Web Applications using AWS WAF

This lab shows how to use AWS WAF to protect website traffic served by a Amazon CloudFront distribution. This covers creation an Amazon S3 static hosted website, Amazon Cloudfront distribution to deliver that website and understanding of AWS WAF rules in blocking suspicious traffic patterns.
For the lab to function as written, please DO NOT change the auto assigned region.

Icon  advanced Advanced 10 积分 1 Hour

EMR File System Client-side Encryption Using AWS KMS-managed Keys

In this lab you will enable client-side at-rest encryption using AWS KMS-managed key for data stored in Amazon S3 with the EMR File System (EMRFS). Within Amazon EMR you will create security configuration to encrypt the object written to S3 with client-side encryption using the AWS KMS-managed key specified by you, and decrypt objects with the same key that was used to encrypt them. This will allow you to more easily leverage frameworks like Apache Spark, Apache Tez, and Apache Hadoop MapReduce on Amazon EMR to run big data analytics, stream processing, machine learning, and ETL workloads on confidential data.

Icon  advanced Advanced 10 积分 50 Minutes