What's changed: Deepened SOA-C02 Chapter 4 to Associate depth (tables, scenarios, FAQ, traps; localized figures)
4.4In-scope services for security and compliance
A roundup of in-scope SOA-C03 services for security and compliance—protection, detection, identity, and network boundaries.
4.4.1In-scope services for security and compliance
For security and compliance, focus on protection, detection, identity, and network boundaries. Protection/encryption: AWS Certificate Manager (HTTPS certs), AWS Key Management Service (keys), AWS Secrets Manager (secrets), AWS WAF (web protection), AWS Shield (DDoS), and AWS Network Firewall (L3/4 inspection). Detection/audit: Amazon GuardDuty (threat detection), AWS Security Hub (findings aggregation), Amazon Macie (data classification), and AWS IAM Access Analyzer (over-permission detection). Identity: AWS IAM Identity Center (employee SSO). Network boundaries: Amazon EC2 security groups (instance-level), Network ACLs (subnet-level), Internet gateways (VPC↔internet), plus outbound-only NAT gateways (IPv4) and Egress-only internet gateways (IPv6).
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

