Threat protection and security services
AWS offers many security services with confusingly similar names. The exam tests whether you can match each to the right job. This chapter gives each one a clear purpose.
Protecting against attacks at the edge
AWS Shield
| Shield Standard | Shield Advanced | |
|---|---|---|
| Cost | Free, automatic for all customers | Paid subscription |
| Protects against | Common network and transport layer (layer 3/4) DDoS attacks | Larger and more sophisticated DDoS attacks, including application layer with WAF |
| Extras | — | 24/7 AWS Shield Response Team, DDoS cost protection (credits for scaling charges during attacks), detailed attack visibility |
| Resources | All | CloudFront, Route 53, Global Accelerator, ELB, Elastic IPs |
AWS WAF
A web application firewall for layer 7 (HTTP/HTTPS) traffic. You create a web ACL with rules and attach it to CloudFront, Application Load Balancers, API Gateway, AppSync, Cognito user pools and some other services.
Rules can block or allow based on:
- SQL injection and cross-site scripting patterns.
- IP addresses and ranges, geographic location.
- Headers, query strings, body content, size constraints.
- Rate-based rules — block IPs sending too many requests (basic bot/brute-force protection).
- Managed rule groups from AWS and AWS Marketplace sellers (e.g. common vulnerabilities, known bad inputs, bot control).
WAF cannot be attached to a Network Load Balancer or directly to EC2 instances. For an NLB-fronted app needing WAF, put CloudFront in front, or use an ALB.
AWS Firewall Manager
Centrally configure and enforce WAF rules, Shield Advanced, security groups, Network Firewall and Route 53 Resolver DNS Firewall across all accounts in an organization. Cue: "apply the same WAF rules to every account automatically."
AWS Network Firewall
A managed, stateful network firewall for your VPCs — deep packet inspection, intrusion prevention, domain-name filtering for outbound traffic. Deployed in dedicated firewall subnets with routing through it. Cue: "inspect and filter all traffic entering/leaving VPCs, including allow-listing outbound domains."
Detecting threats and vulnerabilities
| Service | What it does | Think of it as |
|---|---|---|
| Amazon GuardDuty | Intelligent threat detection using CloudTrail events, VPC Flow Logs and DNS logs, with optional protection for S3, EKS, RDS, Lambda, malware and runtime monitoring | A security camera watching for suspicious behaviour (crypto-mining, compromised credentials, unusual API calls) |
| Amazon Inspector | Automated vulnerability scanning of EC2 instances, container images in ECR and Lambda functions for software vulnerabilities and network exposure | A scanner for unpatched software |
| Amazon Macie | Uses ML to discover sensitive data (PII) in S3 and assess bucket security | Finds personal data where it shouldn't be |
| AWS Security Hub | Aggregates findings from GuardDuty, Inspector, Macie and others; runs security best-practice checks | The single dashboard |
| Amazon Detective | Investigates findings — builds graphs of activity to find root cause | The detective after the alarm |
| AWS Config | Records resource configuration history and checks it against rules | Compliance auditor (see monitoring) |
| AWS CloudTrail | Logs API calls — who did what, when | Audit log |
Compliance and audit
| Service | Purpose |
|---|---|
| AWS Artifact | Download AWS compliance reports (SOC, ISO, PCI) and accept agreements (e.g. BAA) |
| AWS Audit Manager | Continuously collect evidence and map it to frameworks for audits |
Threats outside AWS
The exam guide calls out external threat vectors such as DDoS and SQL injection:
- DDoS → Shield (Standard/Advanced), CloudFront and Route 53 absorbing traffic at the edge, Auto Scaling to absorb spikes, WAF rate-based rules.
- SQL injection / XSS → WAF managed rules, plus secure coding and parameterised queries.
- Credential compromise → MFA, short-lived credentials, GuardDuty.
A layered security architecture
Users → Route 53 → CloudFront (+ WAF, Shield) → ALB (+ WAF) in public subnets
→ app tier (EC2/ECS) in private subnets, security groups only from ALB
→ database in private subnets, security group only from app tier
Monitoring: CloudTrail + Config + GuardDuty + Inspector + Macie → Security Hub
Exam patterns
- "Protect against SQL injection on an ALB" → AWS WAF.
- "24/7 DDoS response team and cost protection" → Shield Advanced.
- "Detect compromised EC2 instances communicating with known bad IPs" → GuardDuty.
- "Find S3 buckets containing credit card numbers" → Macie.
- "Scan container images for CVEs" → Inspector.
- "One place to see all security findings across accounts" → Security Hub.