AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Security & identity

Securing workloads and applications

3 min readChapter 10 of 48By Bipin Singh

Task statement 1.2 is about securing the application itself: controlling network traffic, keeping tiers private, giving applications credentials safely and protecting databases. This chapter pulls those threads together.

Security groups vs network ACLs

Security group Network ACL (NACL)
Applies to Network interfaces (instances, load balancers, RDS…) Subnets
Rules Allow only Allow and deny
State Stateful — return traffic automatically allowed Stateless — return traffic must be allowed explicitly (ephemeral ports)
Evaluation All rules evaluated Rules evaluated in number order, first match wins
Default New SG: deny all inbound, allow all outbound Default NACL: allow all; custom NACL: deny all
Can reference Other security groups Only CIDR ranges
Key idea

Use security groups as the main control, referencing each other between tiers ("app SG allows port 8080 from ALB SG"). Use NACLs for coarse subnet-level rules — especially to explicitly block an IP range, which security groups can't do.

Network segmentation

A classic three-tier design:

Tier Subnet Inbound allowed from
Load balancer Public subnets in 2+ AZs Internet on 443
Application Private subnets Load balancer security group only
Database Private (isolated) subnets Application security group only, on the DB port

Admin access without exposing servers

Option Security
SSH/RDP from the internet to every server ✗ Avoid
Bastion host in a public subnet, restricted to company IPs Acceptable, but another server to patch
AWS Systems Manager Session Manager ✓ Best: no inbound ports, no bastion, no SSH keys; IAM-controlled and logged
EC2 Instance Connect (including Endpoint for private instances) ✓ Short-lived keys, IAM-controlled

Private access to AWS services

By default, an instance in a private subnet calls S3 or DynamoDB through a NAT gateway and the public internet. VPC endpoints keep this traffic on the AWS network:

Cue: "access S3 from private subnets without traversing the internet" → gateway VPC endpoint. Covered fully in VPC connectivity.

Application credentials and configuration

Securing databases

Control How
Network Private subnets; security group allowing only the app tier
Authentication Database users; IAM database authentication for RDS/Aurora MySQL and PostgreSQL (short-lived tokens instead of passwords)
Credentials Secrets Manager with automatic rotation
Encryption at rest KMS, enabled at creation
Encryption in transit Require TLS connections
Connection management RDS Proxy — pools connections, can enforce IAM auth and uses Secrets Manager
Auditing Database audit logs to CloudWatch Logs; CloudTrail for API actions

Securing external connections

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me