# AWS Security Specialty

*2024-06-11*

> Notes from studying for the AWS Security Specialty certification


Following on from my [Associate]({{< relref "/posts/2024/aws-associate" >}}) certifications, I tackled the [**AWS Certified Security – Specialty**](https://aws.amazon.com/certification/certified-security-specialty/) as my next milestone. Security felt like a natural progression given my growing focus on infrastructure protection, and honestly, this exam rewards hands-on familiarity more than any Associate-level test I've taken.

These are my study notes, organised by the exam's five domains: threat detection and incident response, security logging and monitoring, infrastructure security, identity and access management, and data protection.

Unlike my earlier Associate notes, these capture the core material more thoroughly, since much of it was new territory for me. My primary resource was the official [AWS Certified Security Specialty path](https://www.pluralsight.com/paths/aws-certified-security-specialty-scs-c01) on [Pluralsight](https://www.pluralsight.com).

I hope they help others on a similar path.

---

## Contents

1. [Domain 1: Threat Detection and Incident Response](#threat-detection-and-incident-response)
2. [Domain 2: Security Logging and Monitoring](#security-logging-and-monitoring)
3. [Domain 3: Infrastructure Security](#infrastructure-security)
4. [Domain 4: Identity and Access Management](#identity-and-access-management)
5. [Domain 5: Data Protection](#data-protection)
6. [Management and Security Governance](#management-and-security-governance)

## Domain 1: Threat Detection and Incident Response{#threat-detection-and-incident-response}

**AWS Config**
- Evaluation modes: **proactive** (validates resources before deployment) and **detective** (after deployment).
- The Resource Timeline shows CloudTrail, Configuration, and Compliance events — remember "**CCC**."
- Config **records** changes but never **prevents** them.
- Customisable managed rules, or custom rules via Lambda.
- Aggregators centralise configuration recording across an AWS Organisations structure.

**Trusted Advisor**
- Account-level checks against industry best practices.
- Basic support plans get only 6 checks; **Business and Enterprise unlock all checks plus EventBridge integration**.
- Four categories: cost optimisation, performance, security, fault tolerance (plus service limits).

**GuardDuty** *(analyses VPC flow logs, CloudTrail management and data events, DNS logs)*
- Threat detection combining multiple data sources with ML and threat intelligence feeds.
- Supports Organizations with a delegated administrator account.
- Custom threat lists and trusted IP lists, suppression rules.
- Alerting via EventBridge → SNS or Lambda; integrates with Security Hub and Detective.

**Inspector**
- **Network assessments** are agentless, scanning for network reachability; **host assessments** use the SSM Agent and can inspect the OS for CVEs.
- Findings are scored based on the NVD, with detailed reports.
- Works in Organizations with a delegated admin account.

**Systems Manager**
- **Patch baselines** (predefined or custom) and **patch groups** (resource tags).
- Approval rules can auto-approve patches after a number of days.

**Incident Response Essentials**
- The **AWS Security Finding Format (ASFF)** is the JSON schema used by Security Hub.
- **Playbooks** identify security issues; **runbooks** execute the remediation procedures.
- Classic scenario: preventing CloudTrail tampering — EventBridge detects a `StopLogging` event → triggers Lambda → calls `StartLogging`.
- Incident domains: infrastructure, service, application.

**Detective** — Analyses Security Hub, GuardDuty, CloudTrail, EKS audit logs, and VPC flow logs. **Requires GuardDuty to be enabled.**

**AWS Artifact** — Provides compliance reports for AWS services and infrastructure only — *not* how your company uses AWS.

## Domain 2: Security Logging and Monitoring{#security-logging-and-monitoring}

**CloudWatch**
- Max **2 subscription filters** per log group.
- Destinations: Lambda, Kinesis Data Streams (real-time), Kinesis Data Firehose (near real-time).
- Metrics published more than **2 hours in the past** won't be streamed.

**CloudTrail**
- Management events cover operations on resources (excluding RDS Data API and KMS events); insight events flag unusual activity.
- Alerts via SNS; EventBridge reacts to trail events.
- CloudTrail **cannot** monitor SSH-level activity — it's API-level.
- Validate log integrity: `aws cloudtrail validate-logs`.

**Kinesis**
- **Data Streams** (real-time, sub-second) vs. **Data Firehose** (buffered, near real-time, ideal for SIEM ingestion).
- Lambda + Firehose transforms records before loading into OpenSearch.

**VPC Flow Logs** — Custom formats require at least one field.

**Audit Manager**
- Automates assessments and report generation.
- Evidence comes from control data sources: AWS Config rules, CloudTrail logs, IAM roles, and VPC components (security groups, NACLs).
- **Frameworks** structure and automate assessments and can be shared across Organizations.

## Domain 3: Infrastructure Security{#infrastructure-security}

**KMS**
- Customer-managed keys (CMKs) allow custom rotation and deletion schedules; AWS-managed keys rotate annually.
- FIPS 140-2 Level 2 certified (Level 3 since May 2023).
- **Data keys** for encrypting outside KMS; **envelope encryption** encrypts those keys.
- `kms:EncryptionContext:context-key` conditions control access to symmetric encryption.
- Key types: customer-managed, AWS-managed, AWS-owned. Symmetric uses one key; asymmetric (RSA) keeps the private key inside KMS; **HMAC keys** (`GenerateMac`/`VerifyMac`) ensure integrity and authenticity. All key usage is logged to CloudTrail.

**WAF**
- Layer 7 firewall for HTTP/S requests.
- Supported resources: CloudFront, API Gateway, ALBs, AppSync.
- Web ACLs match on priority-ordered criteria: IP, geo, regex, request size, SQL injection.

**Network Firewall and Firewall Manager** — Managed Layer 4 stateful firewall protecting VPC perimeters (IGW, NAT GW, VPN, DX). Exam clue: **Suricata rules = Network Firewall**.

**CloudFront and S3**
- **Origin Access Control (OAC)** restricts S3 bucket access to CloudFront only.
- **Signed URLs** for single objects (legacy RTMP); **signed cookies** for multiple objects without changing URLs.
- Gotcha: a signer can generate signed URLs for objects it has no permission to read — and assuming roles can produce invalid signatures.

**VPN Options**
- **Site-to-Site**: full IPSec tunnels between networks.
- **Client VPN**: TLS-based sessions from end-user devices.
- **VPN CloudHub**: hub-and-spoke with multiple site-to-site VPNs to one VGW (unique BGP ASNs required for multiple VGWs).
- **Third-party VPN** on EC2: full control, fully your responsibility.

**VPC Connectivity**
- Peered VPCs in the **same region** can reference each other's security groups.
- **Egress-only internet gateways**: stateful, outbound-only IPv6.
- NAT Gateway (managed) vs. NAT instance (unmanaged, more flexible).
- **Session Manager (SSM)** connects to instances without opening SSH/RDP.

**VPC Endpoints**
- **Interface endpoints**: ENIs in your subnets, TCP, PrivateLink-based.
- **Gateway endpoints**: S3 and DynamoDB only, update route tables automatically.
- Remember: S3 supports both — the exam tests choosing between on-prem access (interface) and intra-VPC access (gateway).

**Lambda@Edge** — Four phases: viewer request → origin request → origin response → viewer response. Functions in Node.js or Python, and they **must be created in us-east-1**.

**Shield** — Advanced tier protects Layers 3/4/7, includes 24/7 response, priced around **USD $3,000/month with a 1-year commitment**.

**Security Hub** — Central hub integrating Audit Manager, Config, Detective, Firewall Manager, GuardDuty, and Health. **Requires AWS Config enabled.**

## Domain 4: Identity and Access Management{#identity-and-access-management}

**Identities**
- IAM users, groups, roles; trust policies and permission policies.
- SAML 2.0 identity providers enable federation — great fit when you already have an IdP, and roles enable cross-account access.

**Policy Evaluation**
- Cross-account access means a role **in the target account**.
- Evaluation order: SCPs → explicit deny → explicit allow → implicit deny.
- `NotAction`, `NotPrincipal`, `NotResource` shorten policies by inversion.

**Credential Report** — Refreshable only every **4 hours**; shows long-term credential status.

**Cognito**
- **User Pools**: user directories issuing JWTs.
- **Identity Pools**: exchange federated identities for temporary STS credentials.

**Directory Service**
- **Managed Microsoft AD**: trusts are one-way incoming from on-prem, one-way outgoing to AWS.
- **AD Connector**: proxies without storing data — smaller footprint, under 5k users.
- **Simple AD**: Samba 4-compatible, no MFA, under 5k users.

**Organizations**
- SCPs **always trump** member-account IAM permissions but never *grant* anything — they only filter what's allowed.
- `OrganizationAccountAccessRole` is auto-created in member accounts.

## Domain 5: Data Protection{#data-protection}

**Certificate Manager**
- Integrates with Nitro Enclaves, API Gateway, CloudFront, and ALB/NLB listeners.
- ACM-issued certs renew automatically; imported third-party certs don't get the same benefits and must be deployed in-region with the resources.
- Supports single, multiple, wildcard, and combined domains. Private CAs build internal PKI hierarchies — unusable publicly.

**Load Balancers**
- CLBs: legacy, avoid.
- ALBs: Layer 7, HTTP/S, SAN and SNI support, auth offloading.
- NLBs: Layer 4 (TCP, TLS, UDP), **unbroken SSL via TLS passthrough on 443**, static IPs, PrivateLink backbone.
- GLBs: Layer 3 GENEVE for virtual appliances.
- The `ELBSecurityPolicy-FS` policy enables Perfect Forward Secrecy.

**DynamoDB** — Gateway VPC endpoints keep traffic on the AWS network; per-table CMKs; DAX offers AES-256 at rest (enabled at creation only).

**S3 Object Lock (WORM)**
- **Retention period** vs. **legal hold** (no expiry until explicitly removed).
- **Governance mode**: privileged users can override. **Compliance mode**: *no one* can override — not even root.
- Glacier Vault Lock applies the same concept to entire Glacier vaults.

**Other Data Services**
- Data Lifecycle Manager schedules snapshots but **can't manage external snapshots or instance-store-backed AMIs**.
- AWS Backup requires a **vault** before creating a backup plan.
- Parameter Store: String, StringList, SecureString; native to EC2, Lambda, and CloudFormation.
- Secrets Manager: automated rotation with Lambda (a paid feature).
- EC2 traffic inspection caveat: **deep packet inspection requires third-party solutions**; allow/block lists require a proxy on managed compute.
- Kinesis encryption nuances: Data Firehose encrypts delivered data but not the producer side; Data Streams encryption applies only from activation onward; Kinesis Data Analytics inherits source encryption but doesn't support CMKs directly.
- Cross-region networking: Direct Connect supports MACsec and IPsec; know your three virtual interface types (private, public, transit).

## Management and Security Governance{#management-and-security-governance}

*(these cut across all domains)*

- **Control Tower**: guardrail statuses are "Enforced" or "Not enabled"; Account Factory templates new accounts; the landing zone creates Security and Log Archive accounts by default.
- **QuickSight**: Row-level security (Enterprise edition) and column-level security control data visibility.
- **KMS scenarios**: recover encrypted EBS volumes after key changes; S3 large-object encryption natively uses envelope encryption — and requires both `kms:Decrypt` and `kms:GenerateDataKey` permissions.

---

If you're studying for this exam, I hope these notes save you some late nights!
