Secure workloads, not just networks
After IAM and VPC basics, SAA-C03 tests application-layer protection, DDoS resilience, and continuous detection — often in front of CloudFront + ALB architectures.
AWS WAF (Web Application Firewall)
Attach WAF to CloudFront, ALB, or API Gateway:
- Managed rule groups — AWS and Marketplace (SQLi, XSS, known bad inputs).
- Custom rules — IP sets, rate-based rules, geo match, size constraints.
- Logging to S3 / Kinesis for forensics.
Exam pattern: Public API abused by bots → WAF rate-based rule + optional CloudFront caching/shield.
AWS Shield
- Shield Standard — free, automatic DDoS protection for CloudFront and Route 53.
- Shield Advanced — 24/7 DRT, cost protection, advanced metrics; pairs with WAF.
Know which services Shield protects by default vs Advanced engagement.
Amazon GuardDuty
Threat detection from VPC Flow Logs, DNS logs, CloudTrail:
- Finds crypto mining, recon, anomalous API calls.
- No agents — enable per Region/account; delegate admin in Organizations.
- Findings export to Security Hub / EventBridge for automation.
GuardDuty detects; it does not block (pair with NACL/SG/WAF remediation via Lambda).
Amazon Inspector
Automated vulnerability scanning for EC2, container images (ECR), Lambda (where supported):
- CVE-based findings with severity.
- Integrates with Systems Manager for patch workflows.
Use Inspector for posture; GuardDuty for runtime threats.
AWS Config & Security Hub
- Config — record configuration timeline, rules (e.g. "S3 bucket public read prohibited").
- Security Hub — aggregate findings from GuardDuty, Inspector, Macie, third party.
Architect answer for compliance audits: Config rules + Conformance packs + centralized logging account.
Edge-first secure architecture
User → Route 53 → CloudFront (Shield, WAF, ACM TLS)
→ ALB (optional second WAF) → private EC2/ECS
- Origin access control for S3-backed static sites.
- Signed URLs/cookies for private content.
- Geo restriction when licensing requires it.
Shared responsibility reminder
AWS secures of the cloud; you secure in the cloud — OS patching, security groups, WAF rules, data classification.
Exam traps
- WAF runs on regional ALB or global CloudFront scope — web ACL must match resource type.
- GuardDuty needs enabling per account/Region; not retroactive before enablement.
- Inspector vs Trusted Advisor — Inspector is vulnerability scanning; Advisor is high-level best-practice checks.
Official reference
SAA-C03 exam guide — secure workloads and applications.