Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
SAP-C02 · ProfessionalSolutions Architect - Professional
DOP-C02 · ProfessionalDevOps Engineer - Professional
SCS-C03 · SpecialtySecurity - Specialty
  • Week 1
    • 1.Shared Responsibility Model and SCS-C03's 6 Domains: The Big Picture for Security Engineers
    • 2.IAM Core: Users, Groups, Roles, Policies, and Policy Evaluation Flow
    • 3.Advanced IAM Policies: Identity vs Resource, Condition Keys, and Least-Privilege Design
    • 4.STS and Temporary Credentials: AssumeRole, Federation, Role Chaining, Confused Deputy Prevention
    • 5.Week 1 Synthesis: Integrating IAM and Credentials Through Scenarios
  • Week 2
    • 1.Master IAM Policy Evaluation Logic: Explicit Deny Beats Everything
    • 2.Permission Boundary and Delegation: The Safe Way to Grant Permissions to Developers
    • 3.AWS Organizations and SCP: Account-Level Guardrail Design
    • 4.Day 4
    • 5.Day 5
  • Week 3
    • 1.Enable VPC Flow Logs (detailed in Day 3)
    • 2.Scenario: Web server (443) receiving Internet connection
    • 3.1. CloudWatch Logs — suits real-time alarms (Metric Filter)
    • 4.Gateway Endpoint (S3) — add route to table, free
    • 5.Day 5
  • Week 4
    • 1.Day 1
    • 2.AWS Shield (Standard/Advanced) and DDoS Protection: Layered Defense, CloudFront/Route 53 Integration
    • 3.AWS Network Firewall and DNS Firewall: Stateful Inspection, Domain Filtering, Centralized Inspection VPC
    • 4.Edge Security Integration: CloudFront (OAC, Signed URLs), ACM Certificates, Perimeter Security Architecture
    • 5.Week 4 Synthesis: Integrated Review of Edge and Perimeter Defense Scenarios
  • Week 5
    • 1.AWS KMS Fundamentals: CMK Types, Key Policy vs IAM, Symmetric/Asymmetric Keys
    • 2.Envelope Encryption and Data Keys: GenerateDataKey, Encryption Context
    • 3.Key Policies, Grants, and Cross-Account Sharing: ViaService Condition and Key Governance
    • 4.Encryption at Rest/in Transit: TLS, Service-Specific Encryption, Key Rotation
    • 5.Week 5 Synthesis: Integrated Review of Encryption and Key Management Scenarios
  • Week 6
    • 1.Secrets Manager: Automatic Rotation (Lambda), Parameter Store Comparison, Cross-Account Secrets
    • 2.S3 Data Protection: SSE-S3/SSE-KMS/DSSE, Bucket Keys, Object Lock, Versioning, Block Public Access
    • 3.S3 Access Control Deep Dive: Bucket Policies, ACLs, Access Points, Encryption Enforcement, Exfiltration Prevention
    • 4.ACM and Macie: Certificate Lifecycle and Integration, Macie Sensitive Data (PII) Detection and Classification
    • 5.Week 6 Integration: Secrets, Storage, and Sensitive Data Scenario Review
  • Week 7
    • 1.CloudTrail: Management/Data Events, Organization Trail, Log File Integrity Validation, CloudTrail Lake
    • 2.AWS Config: Configuration Items and Records, Rules (Managed/Custom Lambda), Conformance Pack, Auto-Remediation
    • 3.VPC Flow Logs and Network Logging: Detecting Breaches/Misconfig via Traffic, Route 53 Resolver Query Logs
    • 4.Log Integrity, Retention, and Centralization: S3 Object Lock, Cross-Account Log Aggregation, KMS Encryption of Logs
    • 5.Week 7 Integration: Audit Trail Scenario Review
  • Week 8
    • 1.CloudWatch: Log Groups, Metric Filters, Alarms, Anomaly Detection, Security Event Notifications
    • 2.Security Hub: Security Standards (CIS/FSBP), Consolidated Score, Finding Aggregation and Normalization (ASFF), Automated Response
    • 3.Log Analysis: Query CloudTrail/VPC Flow with Athena, OpenSearch, CloudWatch Logs Insights
    • 4.EventBridge Security Automation: Finding Routing, Alert Pipelines, Security Data Lake Concept
    • 5.Week 8 Integration: Monitoring, Aggregation, Analysis Scenario Comprehensive Review
  • Week 9
    • 1.Amazon GuardDuty: Threat Detection Principles, Finding Types, Threat Intelligence, Multi-Account Delegated Administrator
    • 2.Amazon Detective: Finding Investigation and Root Cause, Behavior Graph, GuardDuty Integration
    • 3.Amazon Inspector: EC2/ECR/Lambda Vulnerability Scanning, CVE, Automated Assessment
    • 4.Detection Integration: GuardDuty + Security Hub + Detective + Inspector One Picture, Multi-Account Detection Baseline
    • 5.Week 9 Synthesis: Integrated Review of Threat Detection Scenarios
  • Week 10
    • 1.Automated Response Pipeline: EventBridge + SSM Automation + Lambda for Auto-Remediation of Findings
    • 2.Incident Response for Compromised EC2: Isolation, Snapshots, Forensics, Credential Revocation
    • 3.Credential Exposure Response: Access Key Exposure, Root Compromise, IAM Neutralization and Rotation Playbook
    • 4.Incident Response Framework: NIST Phases, Runbooks, Automation vs Human Judgment Boundary
    • 5.Week 10 Synthesis: Integrated Incident Response Scenario Review
  • Week 11
    • 1.AWS Organizations Security Governance: SCP Design, Delegated Administrators, Central Security Account Model
    • 2.Control Tower and Landing Zone: Guardrails (Preventive/Detective), Account Factory, Compliance Baseline
    • 3.Audit Manager and Compliance: Automated Evidence Collection, Frameworks (CIS/PCI), Config Integration
    • 4.Multi-Account Security Operations: Firewall Manager, Central Policy Distribution, Cost/Tag Governance, Security Baseline Automation
    • 5.Week 11 Comprehensive Review: Integrated Governance Scenarios
  • Week 12
    • 1.Integrated Review Domains 1 & 2: Threat Detection and Incident Response ↔ Security Logging and Monitoring
    • 2.Integrated Review Domains 3 & 4: Infrastructure Security ↔ Identity and Access Management
    • 3.Integrated Review Domains 5 & 6: Data Protection ↔ Management and Governance
    • 4.Full Practice Exam Pace: Six-Domain Synthesis Scenario Review
    • 5.D-Day Final: Exam Strategy, Keyword Translation, Trap Summary
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← SCS-C03/Week 6/Day 5
SCS-C03· AssociateWeek 6 · Day 5~15 min read

Day 5 - Week 6 Integration: Secrets, Storage, and Sensitive Data Scenario Review

This week we covered the second axis of data protection — secrets (Secrets Manager), storage security (S3 encryption, access control, exposure prevention), certificates (ACM), and sensitive information classification (Macie). Today we integrate individual services into scenarios, reviewing in the way exams actually test — combining multiple controls to satisfy one requirement. The key is not "what does each service do" but "which combination is correct for this requirement."

Integrated Mental Model: Four Layers of Data Protection

[1. Discovery·Classification]  Macie → "Where is what" (sensitivity labeling)
       ↓
[2

The rest is Pro only

Week 1 is free for everyone. Week 2 onwards — plus mock exams and unlimited review — is included in the Pro plan.

See ProLogin
PreviousACM and Macie: Certificate Lifecycle and Integration, Macie Sensitive Data (PII) Detection and ClassificationWeek 6 · Day 4Next CloudTrail: Management/Data Events, Organization Trail, Log File Integrity Validation, CloudTrail LakeWeek 7 · Day 1