Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
SAP-C02 · ProfessionalSolutions Architect - Professional
DOP-C02 · ProfessionalDevOps Engineer - Professional
SCS-C03 · SpecialtySecurity - Specialty
  • Week 1
    • 1.Shared Responsibility Model and SCS-C03's 6 Domains: The Big Picture for Security Engineers
    • 2.IAM Core: Users, Groups, Roles, Policies, and Policy Evaluation Flow
    • 3.Advanced IAM Policies: Identity vs Resource, Condition Keys, and Least-Privilege Design
    • 4.STS and Temporary Credentials: AssumeRole, Federation, Role Chaining, Confused Deputy Prevention
    • 5.Week 1 Synthesis: Integrating IAM and Credentials Through Scenarios
  • Week 2
    • 1.Master IAM Policy Evaluation Logic: Explicit Deny Beats Everything
    • 2.Permission Boundary and Delegation: The Safe Way to Grant Permissions to Developers
    • 3.AWS Organizations and SCP: Account-Level Guardrail Design
    • 4.Day 4
    • 5.Day 5
  • Week 3
    • 1.Enable VPC Flow Logs (detailed in Day 3)
    • 2.Scenario: Web server (443) receiving Internet connection
    • 3.1. CloudWatch Logs — suits real-time alarms (Metric Filter)
    • 4.Gateway Endpoint (S3) — add route to table, free
    • 5.Day 5
  • Week 4
    • 1.Day 1
    • 2.AWS Shield (Standard/Advanced) and DDoS Protection: Layered Defense, CloudFront/Route 53 Integration
    • 3.AWS Network Firewall and DNS Firewall: Stateful Inspection, Domain Filtering, Centralized Inspection VPC
    • 4.Edge Security Integration: CloudFront (OAC, Signed URLs), ACM Certificates, Perimeter Security Architecture
    • 5.Week 4 Synthesis: Integrated Review of Edge and Perimeter Defense Scenarios
  • Week 5
    • 1.AWS KMS Fundamentals: CMK Types, Key Policy vs IAM, Symmetric/Asymmetric Keys
    • 2.Envelope Encryption and Data Keys: GenerateDataKey, Encryption Context
    • 3.Key Policies, Grants, and Cross-Account Sharing: ViaService Condition and Key Governance
    • 4.Encryption at Rest/in Transit: TLS, Service-Specific Encryption, Key Rotation
    • 5.Week 5 Synthesis: Integrated Review of Encryption and Key Management Scenarios
  • Week 6
    • 1.Secrets Manager: Automatic Rotation (Lambda), Parameter Store Comparison, Cross-Account Secrets
    • 2.S3 Data Protection: SSE-S3/SSE-KMS/DSSE, Bucket Keys, Object Lock, Versioning, Block Public Access
    • 3.S3 Access Control Deep Dive: Bucket Policies, ACLs, Access Points, Encryption Enforcement, Exfiltration Prevention
    • 4.ACM and Macie: Certificate Lifecycle and Integration, Macie Sensitive Data (PII) Detection and Classification
    • 5.Week 6 Integration: Secrets, Storage, and Sensitive Data Scenario Review
  • Week 7
    • 1.CloudTrail: Management/Data Events, Organization Trail, Log File Integrity Validation, CloudTrail Lake
    • 2.AWS Config: Configuration Items and Records, Rules (Managed/Custom Lambda), Conformance Pack, Auto-Remediation
    • 3.VPC Flow Logs and Network Logging: Detecting Breaches/Misconfig via Traffic, Route 53 Resolver Query Logs
    • 4.Log Integrity, Retention, and Centralization: S3 Object Lock, Cross-Account Log Aggregation, KMS Encryption of Logs
    • 5.Week 7 Integration: Audit Trail Scenario Review
  • Week 8
    • 1.CloudWatch: Log Groups, Metric Filters, Alarms, Anomaly Detection, Security Event Notifications
    • 2.Security Hub: Security Standards (CIS/FSBP), Consolidated Score, Finding Aggregation and Normalization (ASFF), Automated Response
    • 3.Log Analysis: Query CloudTrail/VPC Flow with Athena, OpenSearch, CloudWatch Logs Insights
    • 4.EventBridge Security Automation: Finding Routing, Alert Pipelines, Security Data Lake Concept
    • 5.Week 8 Integration: Monitoring, Aggregation, Analysis Scenario Comprehensive Review
  • Week 9
    • 1.Amazon GuardDuty: Threat Detection Principles, Finding Types, Threat Intelligence, Multi-Account Delegated Administrator
    • 2.Amazon Detective: Finding Investigation and Root Cause, Behavior Graph, GuardDuty Integration
    • 3.Amazon Inspector: EC2/ECR/Lambda Vulnerability Scanning, CVE, Automated Assessment
    • 4.Detection Integration: GuardDuty + Security Hub + Detective + Inspector One Picture, Multi-Account Detection Baseline
    • 5.Week 9 Synthesis: Integrated Review of Threat Detection Scenarios
  • Week 10
    • 1.Automated Response Pipeline: EventBridge + SSM Automation + Lambda for Auto-Remediation of Findings
    • 2.Incident Response for Compromised EC2: Isolation, Snapshots, Forensics, Credential Revocation
    • 3.Credential Exposure Response: Access Key Exposure, Root Compromise, IAM Neutralization and Rotation Playbook
    • 4.Incident Response Framework: NIST Phases, Runbooks, Automation vs Human Judgment Boundary
    • 5.Week 10 Synthesis: Integrated Incident Response Scenario Review
  • Week 11
    • 1.AWS Organizations Security Governance: SCP Design, Delegated Administrators, Central Security Account Model
    • 2.Control Tower and Landing Zone: Guardrails (Preventive/Detective), Account Factory, Compliance Baseline
    • 3.Audit Manager and Compliance: Automated Evidence Collection, Frameworks (CIS/PCI), Config Integration
    • 4.Multi-Account Security Operations: Firewall Manager, Central Policy Distribution, Cost/Tag Governance, Security Baseline Automation
    • 5.Week 11 Comprehensive Review: Integrated Governance Scenarios
  • Week 12
    • 1.Integrated Review Domains 1 & 2: Threat Detection and Incident Response ↔ Security Logging and Monitoring
    • 2.Integrated Review Domains 3 & 4: Infrastructure Security ↔ Identity and Access Management
    • 3.Integrated Review Domains 5 & 6: Data Protection ↔ Management and Governance
    • 4.Full Practice Exam Pace: Six-Domain Synthesis Scenario Review
    • 5.D-Day Final: Exam Strategy, Keyword Translation, Trap Summary
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← SCS-C03/Week 1/Day 5
SCS-C03· AssociateWeek 1 · Day 5~20 min read

Day 5 - Week 1 Synthesis: Integrating IAM and Credentials Through Scenarios

Week 1 has laid the foundation of SCS-C03. We drew the big picture with the Shared Responsibility Model and 6 domains (Day 1), mastered IAM building blocks and policy evaluation algorithm (Day 2), dug into Identity/Resource policies, Condition keys, and least-privilege design (Day 3), and covered STS, federation, role chaining, Confused Deputy prevention (Day 4). Separately, each is its topic. But exam scenario questions always bundle two or three together.

One problem tangles implicit Deny, SCP guardrails, cross-account both-sides allowing, and Permissions Boundary simultaneously: "Why is access denied?" A "delegate safely to third parties" question tests Role + trust policy + ExternalId + least privilege all at once. Today we solidify that synthesis through scenario solving. Week 1's one-liner: "Every access decision at AWS reduces to the IAM evaluation algorithm, and a security engineer's job is inputting precise policies into that algorithm."

One-Page Compact — Week 1 Core

Shared Responsibility + Control Types (Day 1)

AxisCore
Responsibility lineIaaS(EC2) high customer burden, SaaS(S3) low. Data and access control always customer
Control typesPreventive(IAM/SCP/SG/KMS) · Detective(CloudTrail/GuardDuty/Config) · Responsive(EventBridge→SSM)
6 domainsThreat detection 14 / Logging 18 / Infrastructure 20 / IAM 16 / Data 18 / Governance 14

IAM Evaluation Algorithm (Day 2·3)

1. Any explicit Deny?             ──▶ Yes → DENY (absolute)
2. Does SCP allow the Action?      ──▶ No → DENY
3. Does Permissions Boundary allow? ──▶ No → DENY
4. (cross-account) Both allow?      ──▶ Either missing → DENY
5. Any explicit Allow?              ──▶ No → implicit DENY
   All pass ──▶ ALLOW
  • SCP·Boundary are filters that cut ceilings, not grant permissions
  • Same account: Identity OR Resource policy enough / cross-account: both needed
  • KMS: key policy is first authority — key policy must open before IAM policy works

Policy Types and Tools (Day 3)

PolicyAttached toPrincipalcross-account
IdentityUser/Group/RoleNoneCan't work alone
ResourceS3/KMS/SQS/Role trustRequiredWorks alone
SCPOU/account—Org guardrail
Permissions BoundaryUser/Role—Principal ceiling
  • Condition traps: BoolIfExists(MFA), aws:SourceArn/SourceAccount(Confused Deputy), use aws:SourceVpc for VPC
  • ABAC: aws:PrincipalTag == aws:ResourceTag keeps policies constant as scale grows

STS·Credentials (Day 4)

  • Temporary credentials = AccessKeyId + SecretAccessKey + SessionToken(expiring)
  • AssumeRole: trust(who) + permission(what) two policies
  • Federation: SAML(AssumeRoleWithSAML)·OIDC(AssumeRoleWithWebIdentity)·Identity Center
  • Confused Deputy: third-party uses ExternalId(vendor-issued), AWS service uses aws:SourceArn
  • Role chaining: session max 1 hour fixed / IMDSv2 enforced to stop credential theft

Scenario Solving 4-Step Flow

When facing IAM problems in exam, consciously decompose by this order:

  1. Decompose the request: Who(Principal) · What(Action) · Where(Resource) · same-account or cross-account? KMS involved?
  2. Check filters: Explicit Deny? SCP? Boundary? Cross-account both sides? KMS key policy?
  3. Judge least privilege: Among choices, pick one narrowing wildcards, using temp credentials, forcing guardrails
  4. Remove traps: Long-key use / root use / Bool vs BoolIfExists / missing ExternalId / single control only

🎯 Scenario: "Developer has admin, but specific S3 bucket access is denied." Four-step decomposition — admin is explicit Allow (passes step 5). But denied means hitting filters 1-4. Most common: SCP or bucket policy's explicit Deny, or that bucket is KMS-encrypted but key policy doesn't allow developer. "Permissions exist but denied" almost always hits a filter (upper ceiling).


📝 10 Comprehensive Scenarios

📝 Practice Questions

Click a choice to reveal the answer and explanation.

Question 1

Company wants application running on EC2 to access S3. Most security best-practice method is?

Question 2

Account A's CodePipeline deploys to Account B's ECS service; artifacts encrypted with Account A KMS key. For deployment to work, required permission boundaries are?

Question 3

User has `PowerUserAccess`, no SCP or Boundary restrictions, yet `dynamodb:Query` call is denied. Most likely cause?

Question 4

Company wants to safely delegate cross-account S3 bucket access to third-party backup vendor. Most appropriate setup?

Question 5

Security team wants to prevent anyone (admin, root) in all member accounts from disabling CloudTrail and block non-US region use. Most appropriate combo is?

Question 6

A policy intended to block sensitive actions without MFA used `"Bool": {"aws:MultiFactorAuthPresent": "false"}`, unexpectedly blocking service automation calls. Correct fix?

Question 7

Dozens of teams operate resources; policy additions per new team causes explosion. Most scalable least-privilege approach?

Question 8

Thousands of corporate employees need multi-account access. Avoid IAM User-per-account anti-pattern most appropriately how?

Question 9

Account A's role can't read KMS-encrypted S3 object in Account B. S3 bucket and A's IAM policy correctly allow GetObject. Most likely gap?

Question 10

SNS topic policy allows S3 service principal to post events. Block other people's S3 buckets from triggering this topic how?

Week 1 Closing — Bridge to Next Week

This week's five — Shared Responsibility Model, policy evaluation algorithm, Identity/Resource policies, Condition and least privilege, STS and federation — are Domain 4 (IAM) core and prerequisite for all other five domains. Next week we enter data protection (KMS, encryption) in-depth; key policies, grants, encryption context there all unlock on these two questions learned here:

  1. "At which stage of the IAM evaluation algorithm is this access decided?" (explicit Deny → filters → explicit Allow)
  2. "Is this credential temporary or long-term, and is the delegation boundary safe?" (STS · trust policy · ExternalId)

Hold these two questions, and next week's KMS key policies, S3 encryption enforcement, Secrets Manager rotation become "this week's IAM thinking applied to data" instead of "separate tools to memorize."

PreviousSTS and Temporary Credentials: AssumeRole, Federation, Role Chaining, Confused Deputy PreventionWeek 1 · Day 4Next Master IAM Policy Evaluation Logic: Explicit Deny Beats EverythingWeek 2 · Day 1

On this page

  • One-Page Compact — Week 1 Core
  • Shared Responsibility + Control Types (Day 1)
  • IAM Evaluation Algorithm (Day 2·3)
  • Policy Types and Tools (Day 3)
  • STS·Credentials (Day 4)
  • Scenario Solving 4-Step Flow
  • 10 Comprehensive Scenarios
  • Week 1 Closing — Bridge to Next Week