Skip to main content

Four-week study plan

Week 1

  • human and machine identities,
  • federation and IAM Identity Center,
  • policy evaluation,
  • RBAC, ABAC, permission boundaries, and SCPs,
  • STS and workload roles.

Week 2

  • Secrets Manager,
  • KMS and envelope encryption,
  • data classification,
  • security groups and NACLs,
  • WAF, Shield, Network Firewall, ACM, and PKI.

Week 3

  • Organizations and delegated administration,
  • Control Tower,
  • AWS Config and conformance packs,
  • CI/CD security controls,
  • Security Hub and GuardDuty.

Week 4

  • Inspector,
  • Macie,
  • CloudTrail and audit archives,
  • Flow Logs,
  • Access Analyzer,
  • automated finding response,
  • milestones and assessment.

Maintain comparison sheets for role vs user, SCP vs permissions boundary, identity policy vs resource policy, KMS key policy vs IAM, Security Hub vs GuardDuty vs Inspector vs Macie, and CloudTrail vs Config vs Flow Logs.