What's changed: Deepened SCS-C02 Chapter 6 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
6.3Operational Governance and Cost/Secret Control
Understand operational governance—tagging strategy, Trusted Advisor, cost anomaly detection, patch/config compliance, org-wide secret management, and backup policies. Balance security and operations.
Security is inseparable from operational governance. Keep consistency with tags and automated checks, and catch anomalies early.
6.3.1Operational governance
- Tagging strategy: classify by owner/environment/sensitivity for policy application and cost allocation.
- Trusted Advisor: check best practices across security/cost/fault tolerance.
- Cost anomaly detection: detect suspicious usage spikes (possible compromise signal).
- Org secret/backup management: Secrets Manager cross-account sharing, centralized AWS Backup policies.
Common on SCS-C02: classification/cost allocation/policy = tagging strategy, best-practice checks = Trusted Advisor, usage anomalies = cost anomaly detection (also a compromise signal), patch/config maintenance = Systems Manager. Tags also enable security (ABAC: attribute-based access control).
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

