Training Course Highlights
60-Hour Instructor-led Online Training
Live Demos on 30+ AWS Services
Access to Recorded Sessions
Simulation Exam & Mock Test
Certified Trainers
24x7 Post-Training Support
3 Capstone Projects
Earn CPEs
* Conditions Apply
AWS Architect + Security Training - An Overview
The AWS combo course (AWS Solutions Architect Associate + AWS Security Specialty) from InfosecTrain is a comprehensive training course that combines the Architect Associate and Security Specialty certifications training. This intensive program covers the fundamentals of AWS Architect Associate and goes in-depth with Security Specialty. It equips participants with the essential knowledge and skills required to excel in both areas of expertise within the Amazon Web Services (AWS) ecosystem.
Course Curriculum
-
AWS Certified Solutions Architect – Associate
- Cloud Computing Fundamentals
- Cloud Computing Concepts
- Service and Deployment models
- Shared Responsibility Model
- Virtualization Concepts
- Architecture and Security Concepts
- Compute
- AWS EC2
- Amazon LightSail
- AWS Elastic Beanstalk
- Serverless
- Lambda
- AWS Fargate
- Data Storage and Transfer Services
- AWS Backup
- Amazon Elastic Block Store (EBS)
- Amazon Elastic File System (EFS)
- Amazon FSx
- Amazon S3
- AWS Snow Family
- Storage Gateway
- AWS Transfer Family
- DataSync
- Database
- Amazon RDS
- Amazon DynamoDB
- Amazon Aurora
- ElastiCache
- Container Services
- Amazon Elastic Container Service (ECS)
- Amazon Elastic Kubernetes Service (EKS)
- Amazon Elastic Container Registry (ECR)
- Networking
- Amazon VPC
- Amazon VPN
- Amazon Transit Gateway
- AWS Private Link
- AWS Direct Connect
- VPC Flow logs
- DNS, Load Balancing and Edge Services
- Amazon CloudFront
- Elastic Load Balancing (ELB)
- AWS Global Accelerator
- Amazon Route 53
- Security, Identity and Compliance
- AWS Artifact
- AWS Audit Manager
- AWS Certificate Manager (ACM)
- AWS CloudHSM
- Amazon Cognito
- Amazon Detective
- AWS Directory Service
- AWS Firewall Manager
- Amazon GuardDuty
- AWS Identity and Access Management (IAM)
- Amazon Inspector
- AWS Key Management Service (AWS KMS)
- Amazon Macie
- AWS Network Firewall
- AWS Resource Access Manager (AWS RAM)
- AWS Secrets Manager
- AWS Security Hub
- AWS Shield
- AWS WAF
- IAM Identity Center
- AWS Cost Management
- AWS Budget
- AWS Cost and Usage Report
- AWS Cost Explorer
- Savings Plans
- Management and Governance
- AWS CloudFormation
- AWS CloudTrail
- Amazon CloudWatch
- AWS Config
- AWS Organizations
- AWS Systems Manager
- AWS Trusted Advisor
- ML Services
- Rekognition
- Transcribe
- Polly
- Translate
- Lex
- Comprehend
- SageMaker
- Kendra
- Personalize
- Textract
- Domain 1: Threat Detection and Incident Response
- Design and implement an incident response plan
- Incident Response Strategy
- Roles and responsibilities in IR plan specific to cloud incidents
- Use case 1: Credentials compromise
- Use case 2: Compromised EC2 Instances/li>
- Playbooks and Runbooks for IR
- AWS Specific services helpful in Incident Response
- Third-party integration concepts
- Centralize security finding with security hub
- Detect security threats and anomalies by using AWS services
- Threat detection services specific to AWS
- Visualizing and Detecting anomalies and correlation techniques
- Evaluate finding from security services
- Performing queries for validating security events
- Create metrics filters and dashboards to detect Anomalous activity
- Respond to compromised resources and workloads
- AWS Security IR Guide
- Automating remediation by using AWS services
- Compromised resource management
- Investigating and analyzing to conduct Root cause and log analysis
- Capturing relevant forensics data from a compromised resource
- Protecting and preserving forensic artifacts
- Post-incident recovery
- Design and implement an incident response plan
- Domain 2 : Security Logging and Monitoring
- Design and Implement monitoring and alerting to address security events
- Key AWS services for monitoring and alerting
- Monitoring metrics and baselines
- Analyzing environments and workloads to determine monitoring requirements according to business and security requirements
- Setting up tools and scripts to perform regular audits
- Troubleshoot security monitoring and alerting
- Configuring monitoring services and collecting event data
- Application monitoring, alerting, and visibility challenges
- Design and implement a logging solution
- Key logging services and attributes
- Log destinations, Ingestion points, and lifecycle management
- Logging specific to services and applications
- Design a log analysis solution
- Services and tools to analyze captured logs
- Identifying patterns in logs to indicate anomalies and known threats
- Log analysis features for AWS services
- Log format and components
- Normalizing, parsing, and correlating logs
- Troubleshoot logging solutions
- AWS services that provide data sources and logging capabilities
- Access permissions that are necessary for logging
- Identifying misconfigurations and remediations specific to logging
- Reasons for missing logs and performing remediation steps
- Domain 3 : Infrastructure Security
- Design and implement security controls for edge services
- Define edge security strategies and security features
- Select proper edge services based on anticipated threats and attacks and define proper protection mechanisms based on that
- Define layered Defense (Defense in Depth) mechanisms
- Applying restrictions based on different criteria
- Enable logging and monitoring across edge services to indicate attacks
- Design and implement network security controls
- VPC security mechanisms, including Security Groups, NACLs and Network firewall
- Traffic Mirroring and VPC Flow Logs
- VPC Security mechanisms and implement network segmentation based on security requirements
- Network traffic management and segmentation
- Inter-VPC connectivity, Traffic isolation, and VPN concepts and deployment
- Peering and Transit Gateway
- AWS Point to Site and Site to Site VPN, Direct Connect
- Continuous optimization by identifying and removing unnecessary network access
- Design and implement security controls for compute workloads
- Provisioning and maintenance of EC2 instances
- Create hardened images and backups
- Applying instance and service roles for defining permissions
- Host-based security mechanisms
- Vulnerability assessment using AWS Inspector
- Passing secrets and credentials security to computing workloads
- Troubleshoot network security
- Identifying, interpreting, and prioritizing network connectivity and analyzing reachability
- Analyze log sources to identify problems
- Network traffic sampling using traffic mirroring
- Design and implement security controls for edge services
- Domain 4 : Identity And Access Management
- Design, implement, and troubleshoot authentication for AWS resources
- Identity and Access Management
- Establish identity through an authentication system based on requirements
- Managed Identities, Identity federation
- AWS Identity center, IAM, and Cognito
- MFA, Conditional access, STS
- Troubleshoot authentication issues
- Design, implement, and troubleshoot authorization for AWS resources
- IAM policies and types
- Policy structure and troubleshooting
- Troubleshoot authorization issues
- ABAC and RBAC strategies
- Principle of least privilege and Separation of duties
- Investigate unintended permissions, authorization, or privileges
- Design, implement, and troubleshoot authentication for AWS resources
- Domain 5 : Data Protection
- Design and implement controls that provide confidentiality and integrity for data in transit
- Design secure connectivity between AWS and on-premises networks
- Design mechanisms to require encryption when connecting to resources
- Requiring DIT encryption for AWS API calls
- Design mechanisms to forward traffic over secure connections
- Designing cross-region networking
- Design and implement controls that provide confidentiality and integrity for data at rest
- Encryption and integrity concepts
- Resource policies
- Configure services to activate encryption for data at rest and to protect data integrity by preventing modifications
- Cloud HSM and KMS
- Design and implement controls to manage the data lifecycle at rest
- Lifecycle policies and configurations
- Automated life cycle management
- Establishing schedules and retention for AWS backup across AWS services
- Design and implement controls to protect credentials, secrets,and cryptographic key materials
- Designing management and rotation of secrets for workloads using a secret manager
- Designing KMS key policies to limit key usage to authorized users
- Establishing mechanisms to import and remove customer-provider key material
- Design and implement controls that provide confidentiality and integrity for data in transit
- Domain 6 : Management and Security Governance
- Design a strategy to centrally deploy and manage AWS accounts
- Multi-account strategies using AWS organization and Control tower
- SCPs and Policy multi-account policy enforcement
- Centralized management of security services and aggregation of findings Securing root account access
- Implement a secure and consistent deployment strategy for cloud resources
- Deployment of best practices with Infrastructure as a code
- Tagging and metadata
- Configure and deploy portfolios of approved AWS services
- Securely sharing resources across AWS accounts
- Visibility and control over AWS infrastructure
- Evaluate compliance of AWS resources
- Data classification by using AWS services
- Define config rules for detection of non- compliant AWS resources
- Collecting and organizing evidence by using Security Hub and AWS audit manager
- Identify security gaps through architectural reviews and cost analysis
- AWS cost and usage anomaly identification
- Strategies to reduce attack surfaces
- AWS well-architected framework to identify security gaps
- Design a strategy to centrally deploy and manage AWS accounts
AWS Certified Security – Specialty
Course Objectives
- Understand the security controls for AWS environments and workloads.
- Understand security logging and monitoring capabilities.
- Able to design and implement Identity and Access Management architecture.
- Learn Encryption and Key Management for DAR and DIT.
- Manage Data retention and lifecycle management.
- Multi-account governance and organizational compliance.
- Threat detection and Incident response strategies.
- Vulnerability Management and Security Automation.
- Demonstrate your skills and working experience on AWS services.
- Learn the authentication of technical expertise to design, deploy and operate AWS applications.
Target Audience
The training is ideal for:
- Candidates with an understanding of IT security and Cybersecurity concepts
- Professionals working as Solutions Architects
- Those who are working in cloud computing and security domains
- Those who want to build their career as an AWS Security Architect
- Anyone interested in gaining the AWS Solution Architect Associate and AWS Security Speciality Certification
- Anyone wishing to enhance deep Architect and security knowledge related to AWS
Pre-requisites
- Knowledge of IT/Cyber Security concepts.
- 3+ years of IT experience in job roles related to System Administration Security, Network Administrators, Operations/DevOps Engineers, etc.
- Basic understanding of Virtualization fundamentals and Virtualization concepts.
- 1+ years of experience in IT security domains.
- Basic understanding of networking and OS concepts.
Exam Details
| Certification Name | AWS Certified Security Specialty (SCS-C03) | AWS Certified Solutions Architect-Associate(SAA-C03) |
| Exam Duration | 170 Minutes | 130 minutes |
| Number of Questions | 65 | 65 |
| Exam Format | Multiple-choice Questions | Multiple-choice Questions or Multiple Response Questions |
| Passing Score | 750 out of 1000 | 720 on a scale of 100-1000 |
| Exam Language | English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese, Spanish (Latin America) | English, French (France), Italian, Japanese, Korean, Portuguese (Brazil), Spanish (Latin America), Spanish (Spain), Simplified Chinese, and Traditional Chinese |
Please note that the certification exam fee is not included in the training cost. Candidates are required to schedule and purchase the exam separately through AWS.
AWS Combo Training Calendar
Can't Find a Suitable Schedule? Talk to Our Training Advisor!
Choose Your Preferred Learning Mode
1-TO-1 TRAINING
- Customized Schedule
- Learn at Your Dedicated Hour
- Instant Clarification of Doubts
- Guaranteed to Run
ONLINE TRAINING
- Flexible, Convenient & Time Saving
- Highly Interactive
- Affordable Yet Effective
- Guaranteed to Run
CORPORATE TRAINING
- Anytime, Anywhere - Across The Globe
- Hire a Trainer
- Your Schedule, Your Pace
- Customized for Your Team
Our Expert Course Advisors
Why Choose InfosecTrain?
Learn from certified trainers and industry experts
Practice with labs, regular assessments, and case studies
Immerse in scenario-based learning
Best Quality Training with Best Price Guarantee
Conquer the skills required to ace AWS Cloud Security
Prepare to excel with mock tests, exam tips, and real-world examples
Updated curriculum aligned with the latest updates
Choose Flexible Learning options including weekend batches
Benefits of AWS Architect + Security Combo Training
Get global recognition
Maximize your earning potential
Earn the status of a Cloud Security expert
Advanced career growth
Become a part of an esteemed community
Average Salary Range for Cloud Security Profiles
Confused if this is the right course for you?
Words Have Power
Success Speaks Volumes
Get a Sample Certificate
Frequently Asked Questions
What is AWS Combo Training?
Which AWS certifications are covered in this course?
Does the training prepare for AWS Solutions Architect Associate and Security Specialty exams?
Are AWS certification exams included in the training fee?
Is this course suitable for beginners in AWS cloud and security?
Does the training include hands-on AWS labs?
What AWS security concepts are covered in the course?
How does AWS Combo training help in cloud security careers?