AWS DevOps Engineer Professional — Part 6 (English)
Contents
- Human and machine identities
- Federation and IAM Identity Center
- Policy evaluation and least privilege
- RBAC, ABAC, and delegated permissions
- Chapter project: Identity and access management at scale
- STS, workload roles, and temporary credentials
- Secrets Manager rotation and secret lifecycle
- KMS key architecture and envelope encryption
- Data classification and encryption controls
- Chapter project: Machine credentials, secrets, and data protection
- Security groups, network ACLs, and routing controls
- AWS WAF, Shield, and edge protection
- AWS Network Firewall and centralized network controls
- ACM, private CA, and certificate automation
- Chapter project: Network security and public key infrastructure
- Organizations, SCPs, and delegated security administration
- Control Tower controls and security baselines
- AWS Config rules, conformance packs, and remediation
- Security controls in CI/CD and infrastructure as code
- Chapter project: Automated security controls and governance
- Security Hub organization posture management
- GuardDuty threat detection and investigation
- Inspector vulnerability management
- Macie and sensitive-data discovery
- Chapter project: Security detection and posture management
- CloudTrail, Config, and immutable audit evidence
- VPC Flow Logs, access logs, and network investigation
- IAM Access Analyzer and external-access validation
- Automated security finding response and audit readiness
- Chapter project: Security monitoring, auditing, and response
- Domain 6 glossary
- Milestone 1: Multi-account security platform
- Milestone 2: Domain 6 readiness assessment
- Official AWS references
- Scenario answers
- Welcome to Part 6
- How to study Part 6
- Domain 6 exam map
- Four-week study plan