Uni Cert / SAA-C03 / Workload protection and threat detection

Workload protection and threat detection

WAF, Shield, GuardDuty, Inspector, and securing applications at the edge.

Estimated reading: ~20 min

Secure workloads, not just networks

After IAM and VPC basics, SAA-C03 tests application-layer protection, DDoS resilience, and continuous detection — often in front of CloudFront + ALB architectures.

AWS WAF (Web Application Firewall)

Attach WAF to CloudFront, ALB, or API Gateway:

  • Managed rule groups — AWS and Marketplace (SQLi, XSS, known bad inputs).
  • Custom rules — IP sets, rate-based rules, geo match, size constraints.
  • Logging to S3 / Kinesis for forensics.

Exam pattern: Public API abused by bots → WAF rate-based rule + optional CloudFront caching/shield.

AWS Shield

  • Shield Standard — free, automatic DDoS protection for CloudFront and Route 53.
  • Shield Advanced — 24/7 DRT, cost protection, advanced metrics; pairs with WAF.

Know which services Shield protects by default vs Advanced engagement.

Amazon GuardDuty

Threat detection from VPC Flow Logs, DNS logs, CloudTrail:

  • Finds crypto mining, recon, anomalous API calls.
  • No agents — enable per Region/account; delegate admin in Organizations.
  • Findings export to Security Hub / EventBridge for automation.

GuardDuty detects; it does not block (pair with NACL/SG/WAF remediation via Lambda).

Amazon Inspector

Automated vulnerability scanning for EC2, container images (ECR), Lambda (where supported):

  • CVE-based findings with severity.
  • Integrates with Systems Manager for patch workflows.

Use Inspector for posture; GuardDuty for runtime threats.

AWS Config & Security Hub

  • Config — record configuration timeline, rules (e.g. "S3 bucket public read prohibited").
  • Security Hub — aggregate findings from GuardDuty, Inspector, Macie, third party.

Architect answer for compliance audits: Config rules + Conformance packs + centralized logging account.

Edge-first secure architecture

User → Route 53 → CloudFront (Shield, WAF, ACM TLS)
      → ALB (optional second WAF) → private EC2/ECS
  • Origin access control for S3-backed static sites.
  • Signed URLs/cookies for private content.
  • Geo restriction when licensing requires it.

Shared responsibility reminder

AWS secures of the cloud; you secure in the cloud — OS patching, security groups, WAF rules, data classification.

Exam traps

  • WAF runs on regional ALB or global CloudFront scope — web ACL must match resource type.
  • GuardDuty needs enabling per account/Region; not retroactive before enablement.
  • Inspector vs Trusted Advisor — Inspector is vulnerability scanning; Advisor is high-level best-practice checks.

Official reference

SAA-C03 exam guide — secure workloads and applications.

Official reference: AWS documentation

Chat with G.U.S.

Share suggestions to improve the site or any complaints. We use your feedback to make unigrat.com better.

Hi, I am G.U.S. — Growth Upgrade Suggestions.

Share your suggestions or complaints below.