Instiq
Chapter 3 · Infrastructure Security·v3.1.0·Updated 6/11/2026·~8 min

What's changed: Added figure aws-genai-security (OWASP LLM risks → AWS mitigations) to the gen-AI security section s4. The cloned base chapters inherit SCS-C02 figures; s4 was the only section lacking one, now filled.

3.5In-scope services for infrastructure security

Key points

A roundup of in-scope SCS-C03 services for infrastructure security.

3.5.1In-scope services for infrastructure security

For infrastructure security, beyond Network Firewall/WAF/Shield, know: Network ACLs (subnet boundary), AWS Site-to-Site VPN (site-to-site), AWS Client VPN (user devices), AWS Direct Connect (dedicated line), AWS Verified Access (Zero Trust app access without a VPN), Amazon Route 53 Resolver DNS Firewall (DNS query threat protection), AWS IoT Core (secure IoT device connectivity), EC2 Instance Connect (secure EC2 access without a bastion), and AWS Resilience Hub (assess and improve recovery objectives).

Diagram grouping boundary/connectivity (Network ACLs / Site-to-Site VPN / Client VPN / Direct Connect), secure connection (IoT Core / EC2 Instance Connect), and Zero Trust/recovery (Verified Access / Route 53 Resolver DNS Firewall / Resilience Hub).
Infrastructure security services

3.5.2Section summary

  • Boundary/connectivity: Network ACLs / Site-to-Site VPN / Client VPN / Direct Connect / IoT Core / EC2 Instance Connect
  • Zero Trust/defense/recovery: Verified Access / Route 53 Resolver DNS Firewall / Resilience Hub

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which Zero Trust service grants secure access to corporate apps without a VPN by evaluating identity and device trust per request?

Q2. Which inspects DNS queries from a VPC and blocks resolution of known malicious domains?

Check your understandingPractice questions for Chapter 3: Infrastructure Security