6Network Security, Compliance, and Governance
- 6.1Defense in Depth and Traffic Control
Defend in layers—understand security groups (stateful), NACLs (stateless), defense in depth, and least-privilege networking. Protect at every layer.
- 6.2Centralized Inspection and Firewalls
Inspect at one point—understand AWS Network Firewall, an inspection VPC, routing via Transit Gateway, appliance insertion with GWLB, and the Route 53 Resolver DNS Firewall.
- 6.3DDoS Protection and Governance
Attacks and governance—understand Shield Standard/Advanced, WAF, Firewall Manager, certificate management (ACM), and org-wide policy. Apply protection and control across the board.

