1Designing Secure Architectures
- 1.1IAM and Access Management
Understand IAM users, groups, roles, and policies, least privilege, IAM roles for EC2/services, and federation. The starting point for designing secure architectures in SAA-C03.
- 1.2Data Protection and Encryption
Understand data protection design: encryption at rest/in transit, key management with AWS KMS, encrypting S3/EBS/RDS, and secrets management with Secrets Manager.
- 1.3VPC and Network Security
Understand VPCs and subnets (public/private), the difference between security groups and network ACLs, and network defenses like WAF/Shield.

