Pritam Chakraborty
Certified Solutions Architect Associate Exam
Preparation Note
MODULE 20
AWS Security
Encryption
1
▪ 2 Types of Encryption
1. Encryption at Rest
Figure 1 : Data Encryption ~ Rest
2. Encryption during Flight
Figure 2 : Data Encryption ~ Flight
AWS KMS
▪ Anytime you hear "Encryption" for an AWS Service, it's Most Likely KMS AWS
Manages Encryption Keys for us when it is in Encryption at Rest
▪ Fully Integrated with IAM for Authorization***
▪ Easy Way to Control Access to your Data
▪ Able to Audit KMS Key usage Using CloudTrail***
▪ Seamlessly Integrated into Most AWS Services (EBS, S3, RDS, SSM...)
▪ Never ever store your secrets in plaintext, especially in your code!
o KMS Key Encryption also available through API calls (SDK, CLI)
o Encrypted secrets can be stored in the code / environment variables
Pritam
KMS Key Types –
2
▪ KMS Keys is the New Name of KMS Customer Master Key
▪ 2 Types of KMS Keys
1. Symmetric (AES-256 Keys)
o Single Encryption Key that is Used to Encrypt and Decrypt***
o AWS Services that are Integrated with KMS use Symmetric CMKs
Figure 3 : Symmetric Key for Encryption & Decryption
2. Asymmetric (RSA & ECC Key Pairs)
o Public (Encrypt) & Private Key (Decrypt) pair***
o Used for Encrypt/Decrypt, or Sign/Verify operations
o The Public Key is Downloadable can't Access the Private Key (Unencrypted)
Figure 4 : Asymmetric Key for Encryption & Decryption
KMS Multi Region –
▪ Identical KMS keys in different AWS Regions that can be Used Interchangeably Multi-
Region Keys have the Same Key ID, key material, automatic rotation...
▪ Encrypt in One Region and Decrypt in Other Regions***
▪ KMS Multi-Region are NOT Global (Primary + Replicas)***
▪ Each Multi-Region key is managed independently
▪ Use Cases: Global Client-Side Encryption, Encryption on Global DynamoDB, Global
Aurora
Pritam
3
Figure 5 : Multi Region Key
Encrypted AMI Sharing Process –
▪ AMI in Source Account is Encrypted with KMS Key from Source Account***
▪ Must Modify the Image Attribute to Add a Launch Permission which corresponds to
the specified target AWS account
▪ Must Share the KMS Keys used to Encrypted the Snapshot the AMI References with
the Target Account /IAM Role***
▪ The IAM Role/User in the Target Account Must Have the Permissions to DescribeKey,
ReEncrypted, CreateGrant, Decrypt
Figure 6 : Encrypted AMI Sharing Process
Pritam
SSM Parameter Store
4
▪ Secure Storage for Configuration and Secrets***
▪ Optional Seamless Encryption using KMS
▪ Serverless, scalable, durable, easy SDK
▪ Version tracking of configurations/secrets
▪ Security through IAM
▪ Notifications with Amazon EventBridge
▪ Integration with CloudFormation
▪ We can Assign TTL to Parameters
Figure 7 : SSM Parameters
Standard & Advanced Parameter Tiers***
Pritam
AWS Secrets Manager
5
▪ Newer Service Meant for Storing Secrets***
▪ Capability to Force Rotation of secrets Every X Days
▪ Automate generation of secrets on rotation (uses Lambda) Integration with Amazon RDS
(MySQL, PostgreSQL, Aurora)
▪ Secrets are Encrypted using KMS***
▪ Mostly meant for RDS Integration
AWS Secrets Manager - Multi Region Secrets –
▪ Replicate Secrets across Multiple AWS Regions***
▪ Secrets Manager Keeps Read Replicas in Sync with the Primary Secret ***
▪ Ability to promote a read replica Secret to a standalone Secret
▪ Use cases: multi-region apps, disaster recovery strategies, multi-region DB...
Figure 8 : Secret Managers ~ Multi Region Secrets
AWS Certificate Manager - ACM
▪ Easily Provision, Manage & deploy TLS Certificates***
▪ Provide In-Flight Encryption for Websites (HTTPS)
▪ Supports Both public and Private TLS Certificates
▪ Free of Charge for Public TLS Certificates Automatic TLS Certificate Renewal***
▪ Integrations with (load TLS certificates on)
o Elastic Load Balancers (CLB, ALB, NLB)
o CloudFront Distributions
o APIs on API Gateway
▪ Cannot Use ACM with EC2***
Pritam
ACM -Importing Public Certificates –
6
▪ Option to Generate the Certificate Outside of ACM and then Import It***
▪ No Automatic Renewal, must Import a New Certificate Before Expiry***
▪ ACM Sends Daily Expiration Events Starting 45 Days Prior to Expiration
o The # of Days can be Configured
o Events are appearing in EventBridge
▪ AWS Config Has a Managed Rule Named ACM-Certificate-Expiration-Check to
Check for Expiring Certificates (configurable number of days)***
Figure 9 : Certificates Manager
API Gateway - Endpoint Types
1. Edge-Optimized (default): For global clients
o Requests are Routed through the CloudFront Edge Locations (improves latency)
o The API Gateway still lives in only one region
2. Regional
o For Clients within the Same Region
o Could Manually Combine with CloudFront (more control over the caching
strategies and the distribution)
3. Private
o Can only be Accessed from your VPC using an Interface VPC Endpoint (ENI)
o Use a resource policy to define access
Pritam
ACM With API Gateway
7
1. Edge-Optimized (default): For global clients
o Requests are Routed through the CloudFront Edge Locations (improves latency)
o The API Gateway still lives in Only One Region
o The TLS Certificate Must be in the Same Region as CloudFront, in Us-East-1
o Then Setup CNAME or (better) A-Alias Record in Route 53
2. Regional:
o For Clients within the Same Region
o The TLS Certificate must be Imported on API Gateway, in the same region as
the API Stage
o Then setup CNAME or (better) A-Alias Record in Route 53
AWS WAF -Web Application Firewall
▪ Protects your Web Applications from Common Web Exploits (Layer 7)***
▪ Layer 7 is HTTP (vs Layer 4 is TCP/UDP)
▪ Deploy on
o Application Load Balancer***
o API Gateway***
o CloudFront
o AppSync
o GraphQL API
o Cognito User Pool
▪ Define Web ACL (Web Access Control List) Rules:
o IP Set: up to 10,000 IP addresses - use multiple Rules for more IPs
o HTTP headers, HTTP body, or URI strings Protects from common attack - SQL
injection and Cross-Site Scripting (XSS)
o Size constraints, geo-match (block countries)
o Rate-based rules (to count occurrences of events) - for DDoS protection
▪ WAF are Regional Except for CloudFront
▪ A rule group is a reusable set of rules that you can add to WAF
Pritam
WAF - Fixed IP while using WAF with a LoadBalancer –
8
▪ WAF doesn’t Support the NLB as Layer 4***
▪ We can use Global Accelerator for Fixed Ip and WAF on the ALB***
AWS Shield: Protect from DDoS attack
▪ DDOs: Distributed Denial of Service - Many Requests at The Same Time
▪ AWS Shield Standard:
o Free Service that is Activated for Every AWS Customer***
o Provides Protection from Attacks such as SYN/UDP Floods, Reflection Attacks
and other Layer 3/Layer 4 Attacks
▪ AWS Shield Advanced:
o Optional DDoS Mitigation Service ($3,000 per month Per Organization)***
o Protect Against More Sophisticated Attack on Amazon EC2, Elastic Load
Balancing (ELB), Amazon CloudFront, AWS Global Accelerator, and Route 53
o 24/7 Access to AWS DDOS Response Team (DRP)***
o Protect Against Higher Fees during usage spikes due to DDoS
o Shield Advanced Automatic Application Layer DDoS mitigation automatically
creates, evaluates and deploys AWS WAF rules to mitigate layer 7 attacks
AWS Firewall Manager
▪ Manage Rules in All Accounts of an AWS Organization***
▪ Security Policy: Common Set of Security Rules
o WAF Rules (Application Load Balancer, API Gateways, CloudFront)
o AWS Shield Advanced (ALB, CLB, NLB, Elastic IP, CloudFront)
o Security Groups for EC2, Application Load Balancer and ENI resources in VPC
o AWS Network Firewall (VPC Level)
o Amazon Route 53 Resolver DNS Firewall
o Policies are created at the region level
▪ Rules are applied to new resources as they are created (good for compliance) across all
and future accounts in your Organization
Pritam
AWS WAF vs Firewall Manager vs Shield
9
▪ WAF, Shield and Firewall Manager are Used Together for Comprehensive Protection
Define your Web ACL rules in WAF
▪ For Granular Protection of your resources, WAF alone is the Correct Choice***
▪ If you Want to Use AWS WAF Across Accounts, accelerate WAF Configuration,
automate the protection of new resources, use Firewall Manager with AWS WAF
▪ Shield Advanced adds additional features on top of AWS WAF, such as dedicated support
from the Shield Response Team (SRT) and advanced reporting.
▪ If you're Prone to Frequent DDoS Attacks, Consider Purchasing Shield Advanced***
AWS Guard Duty
▪ Intelligent Threat Discovery to Protect your AWS Account***
▪ Uses Machine Learning Algorithms for Anomaly Detection***
▪ One click to enable (30 days trial), no need to install software
▪ Input data includes:
o Cloud Trail Events Logs - Unusual API Calls, Unauthorized Deployments
▪ CloudTrail Management Events - create VPC subnet, create trail,...
▪ Cloud Trail S3 Data Events - get object, list objects, delete object, …
o VPC Flow Logs - Unusual Internal Traffic, Unusual IP Address
o DNS Logs - compromised EC2 instances sending encoded data within DNS queries
o Optional Features - EKS Audit Logs, RDS & Aurora, EBS, Lambda, S3 Data
Events...
▪ Can Setup EventBridge rules to be Notified in Case of Findings
▪ EventBridge rules can Target AWS Lambda or SNS
AWS Inspector
▪ Automated Security Assessments***
▪ For EC2 Instances
o Leveraging the AWS System Manager (SSM) agent
o Analyze against unintended network accessibility
o Analyze the Running OS Against Known Vulnerabilities***
Pritam
▪ For Container Images push to Amazon ECR
10
o Assessment of Container Images as they are pushed
▪ For Lambda Functions
o Identifies Software Vulnerabilities in Function Code and Package
Dependencies***
o Assessment of functions as they are deployed
▪ Reporting & Integration with AWS Security Hub
▪ Send Findings to Amazon Event Bridge
AWS Macie
▪ Amazon Macie is a Fully Managed Data Security & Data Privacy Service that Uses
Machine Learning & Pattern Matching to Discover & Protect your Sensitive Data in
AWS***
▪ Macie Helps Identify & Alert You to Sensitive Data such as Personally Identifiable
Information (PII)
Figure 10 : Macie for Discover Sensitive Data
Pritam