AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Security & identity

Threat protection and security services

3 min readChapter 09 of 48By Bipin Singh

AWS offers many security services with confusingly similar names. The exam tests whether you can match each to the right job. This chapter gives each one a clear purpose.

Protecting against attacks at the edge

AWS Shield

Shield Standard Shield Advanced
Cost Free, automatic for all customers Paid subscription
Protects against Common network and transport layer (layer 3/4) DDoS attacks Larger and more sophisticated DDoS attacks, including application layer with WAF
Extras — 24/7 AWS Shield Response Team, DDoS cost protection (credits for scaling charges during attacks), detailed attack visibility
Resources All CloudFront, Route 53, Global Accelerator, ELB, Elastic IPs

AWS WAF

A web application firewall for layer 7 (HTTP/HTTPS) traffic. You create a web ACL with rules and attach it to CloudFront, Application Load Balancers, API Gateway, AppSync, Cognito user pools and some other services.

Rules can block or allow based on:

Watch out

WAF cannot be attached to a Network Load Balancer or directly to EC2 instances. For an NLB-fronted app needing WAF, put CloudFront in front, or use an ALB.

AWS Firewall Manager

Centrally configure and enforce WAF rules, Shield Advanced, security groups, Network Firewall and Route 53 Resolver DNS Firewall across all accounts in an organization. Cue: "apply the same WAF rules to every account automatically."

AWS Network Firewall

A managed, stateful network firewall for your VPCs — deep packet inspection, intrusion prevention, domain-name filtering for outbound traffic. Deployed in dedicated firewall subnets with routing through it. Cue: "inspect and filter all traffic entering/leaving VPCs, including allow-listing outbound domains."

Detecting threats and vulnerabilities

Service What it does Think of it as
Amazon GuardDuty Intelligent threat detection using CloudTrail events, VPC Flow Logs and DNS logs, with optional protection for S3, EKS, RDS, Lambda, malware and runtime monitoring A security camera watching for suspicious behaviour (crypto-mining, compromised credentials, unusual API calls)
Amazon Inspector Automated vulnerability scanning of EC2 instances, container images in ECR and Lambda functions for software vulnerabilities and network exposure A scanner for unpatched software
Amazon Macie Uses ML to discover sensitive data (PII) in S3 and assess bucket security Finds personal data where it shouldn't be
AWS Security Hub Aggregates findings from GuardDuty, Inspector, Macie and others; runs security best-practice checks The single dashboard
Amazon Detective Investigates findings — builds graphs of activity to find root cause The detective after the alarm
AWS Config Records resource configuration history and checks it against rules Compliance auditor (see monitoring)
AWS CloudTrail Logs API calls — who did what, when Audit log

Compliance and audit

Service Purpose
AWS Artifact Download AWS compliance reports (SOC, ISO, PCI) and accept agreements (e.g. BAA)
AWS Audit Manager Continuously collect evidence and map it to frameworks for audits

Threats outside AWS

The exam guide calls out external threat vectors such as DDoS and SQL injection:

A layered security architecture

Users → Route 53 → CloudFront (+ WAF, Shield) → ALB (+ WAF) in public subnets
      → app tier (EC2/ECS) in private subnets, security groups only from ALB
      → database in private subnets, security group only from app tier
Monitoring: CloudTrail + Config + GuardDuty + Inspector + Macie → Security Hub

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me