What's changed: Added figure aws-genai-security (OWASP LLM risks → AWS mitigations) to the gen-AI security section s4. The cloned base chapters inherit SCS-C02 figures; s4 was the only section lacking one, now filled.
3.5In-scope services for infrastructure security
A roundup of in-scope SCS-C03 services for infrastructure security.
3.5.1In-scope services for infrastructure security
For infrastructure security, beyond Network Firewall/WAF/Shield, know: Network ACLs (subnet boundary), AWS Site-to-Site VPN (site-to-site), AWS Client VPN (user devices), AWS Direct Connect (dedicated line), AWS Verified Access (Zero Trust app access without a VPN), Amazon Route 53 Resolver DNS Firewall (DNS query threat protection), AWS IoT Core (secure IoT device connectivity), EC2 Instance Connect (secure EC2 access without a bastion), and AWS Resilience Hub (assess and improve recovery objectives).
3.5.2Section summary
- Boundary/connectivity: Network ACLs / Site-to-Site VPN / Client VPN / Direct Connect / IoT Core / EC2 Instance Connect
- Zero Trust/defense/recovery: Verified Access / Route 53 Resolver DNS Firewall / Resilience Hub
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which Zero Trust service grants secure access to corporate apps without a VPN by evaluating identity and device trust per request?
Q2. Which inspects DNS queries from a VPC and blocks resolution of known malicious domains?

