3Infrastructure Security
- 3.1Protecting the Network Perimeter
Understand VPC security—security groups/NACLs, subnet isolation, NAT/IGW, VPC endpoints (Gateway/Interface), and PrivateLink. Defend networks in depth.
- 3.2Edge Protection and DDoS Mitigation
Understand application-edge defense—WAF, Shield (Standard/Advanced), CloudFront, Route 53, Firewall Manager, and Network Firewall. Protect apps from L7 attacks and DDoS.
- 3.3Protecting Compute and Endpoints
Understand compute defense—Systems Manager (patch/Session Manager), hardening/golden AMIs, Inspector, bastion-less (SSM), and EC2 metadata (IMDSv2). Keep instances secure.
- 3.4Securing generative AI applications
Learn generative AI security, newly added in SCS-C03: mitigations for the OWASP Top 10 for LLM Applications (prompt injection, sensitive information disclosure, insecure output handling, etc.), Amazon Bedrock Guardrails (content filters, denied topics, PII masking, grounding), access control to Bedrock (IAM), data protection for prompts/outputs, and auditing/logging of model invocations.
- 3.5In-scope services for infrastructure security
A roundup of in-scope SCS-C03 services for infrastructure security.

