4Security and Compliance
- 4.1IAM and Access Management (Operations View)
Understand IAM identity-based/resource-based policies, evaluation logic (explicit deny wins, default deny), roles and temporary credentials, and least-privilege operations. The starting point for "Security and Compliance" in SOA-C02.
- 4.2Data Protection and Encryption (KMS, ACM)
Understand encryption at rest (KMS for S3/EBS/RDS), encryption in transit (TLS with ACM certificates), and secrets management operations.
- 4.3Compliance and Threat Detection (Config, GuardDuty)
Understand governance operations: AWS Config for configuration recording, rule evaluation, and auto-remediation; GuardDuty for threat detection; and Trusted Advisor best-practice checks.

