Domain 1: Design Secure Architectures
Regions, Availability Zones, edge locations, and a tour of the console
SAA-C03 scores four domains. This deck covers Domain 1. Domains 2 to 4 each have their own deck, labs, and challenges.
Domain 1
Design Secure Architectures
30%
of scored content
Domain 2
Design Resilient Architectures
26%
of scored content
Domain 3
Design High-Performing Architectures
24%
of scored content
Domain 4
Design Cost-Optimized Architectures
20%
of scored content
Getting Started with AWS
Regions, Availability Zones, edge locations, and a tour of the console
AWS Identity and Access Management
Users, groups, policies, MFA, roles, and the CLI and SDK
Amazon S3 Security
Encryption, CORS, MFA Delete, pre-signed URLs, Object Lock, and access points
Advanced Identity in AWS
Organizations, SCPs, IAM conditions, permission boundaries, Identity Center, and Control Tower
AWS Security and Encryption
KMS, Parameter Store, Secrets Manager, ACM, CloudHSM, WAF, Shield, GuardDuty, Inspector, and Macie
Amazon VPC
Subnets, gateways, NAT, NACLs, peering, endpoints, VPN, Direct Connect, and Transit Gateway




$90B
annual revenue in 2023
31%
of the cloud market in Q1 2024. Microsoft is second with 25%.
13 years
in a row as the cloud market leader
1M+
active users





Regions
Geographic areas such as us-east-1
Availability Zones
Isolated locations inside a Region
Data centers
The buildings that make up each AZ
Edge locations
Points of Presence that serve content near users
Explore it live at infrastructure.aws

us-east-1 or eu-west-3You need to launch a new application. Where should it run?
Compliance
Meet data governance and legal requirements. Data never leaves a Region without your explicit permission.
Proximity
Run close to your customers to reduce latency.
Available services
New services and features are not available in every Region.
Pricing
Pricing varies by Region. Each service's pricing page shows it.
ap-southeast-2a, ap-southeast-2b, ap-southeast-2c400+
Points of Presence
10+
Regional Caches
90+
cities
40+
countries
Content is delivered to end users with lower latency.
Orange: edge locations · Blue: regional edge caches

One copy, worldwide
Global services

Most AWS services
Region-scoped services
Region table: aws.amazon.com/about-aws/global-infrastructure/regional-product-services
Users, groups, policies, MFA, roles, and the CLI and SDK
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "ec2:Describe*",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"cloudwatch:ListMetrics",
"cloudwatch:GetMetricStatistics"
],
"Resource": "*"
}
]
}Users inherit the policies of every group they belong to. An inline policy attaches to one user only.
2012-10-17Allow or Deny{
"Version": "2012-10-17",
"Id": "S3-Account-Permissions",
"Statement": [
{
"Sid": "1",
"Effect": "Allow",
"Principal": {
"AWS": ["arn:aws:iam::123456789012:root"]
},
"Action": [
"s3:GetObject",
"s3:PutObject"
],
"Resource": ["arn:aws:s3:::mybucket/*"]
}
]
}Strong passwords mean higher security. An IAM password policy can:
Main benefit: if a password is stolen or hacked, the account is not compromised.


Virtual MFA device
Google Authenticator, Authy (phone only)
Multiple tokens on a single device

U2F security key
YubiKey by Yubico (third party)
Multiple root and IAM users on a single key

Hardware key fob
Gemalto (third party)
A dedicated device that shows a one-time code

Key fob for AWS GovCloud (US)
SurePassID (third party)
The hardware option for GovCloud accounts
AWS Management Console
Protected by password + MFA
AWS CLI
Protected by access keys
AWS SDK (for code)
Protected by access keys
Notional example. The access key ID works like a username, the secret access key like a password.
github.com/aws/aws-cli) and an alternative to the Management Console$ aws s3 cp myfile.txt s3://ccp-mybucket/myfile.txt upload: ./myfile.txt to s3://ccp-mybucket/myfile.txt $ aws s3 ls s3://ccp-mybucket 2025-05-14 03:22:52 0 myfile.txt
Account level
IAM Credentials Report
Lists every user in your account and the status of their credentials.
User level
IAM Access Advisor
Shows the service permissions granted to a user and when each service was last accessed. Use it to tighten policies.
Never share IAM users or access keys.
Users
Mapped to a physical person, with a password for the AWS Console
Groups
Contain users only
Policies
JSON documents that set permissions for users or groups
Roles
Permissions for AWS services, such as EC2 instances
Security
MFA + password policy
AWS CLI
Manage AWS services from the command line
AWS SDK
Manage AWS services from a programming language
Access keys
Access AWS with the CLI or SDK
Audit
IAM Credentials Report and IAM Access Advisor
Encryption, CORS, MFA Delete, pre-signed URLs, Object Lock, and access points
You can encrypt objects in S3 buckets with one of four methods:

Server-side · default
SSE-S3
Keys handled, managed, and owned by AWS. Enabled by default.

Server-side
SSE-KMS
Keys stored and managed in AWS Key Management Service (KMS).
Server-side
SSE-C
Customer-provided keys. You manage your own encryption keys.
Client-side
Client-side encryption
You encrypt before upload and decrypt after download.
For the exam, know which method fits which situation.
"x-amz-server-side-encryption": "AES256""x-amz-server-side-encryption": "aws:kms"GenerateDataKey KMS APIDecrypt KMS APIDeny any request where aws:SecureTransport is false. HTTP calls are refused.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*",
"Condition": {
"Bool": { "aws:SecureTransport": "false" }
}
}
]
}SSE-S3 is applied automatically to new objects. To force a specific method, a bucket policy can deny s3:PutObject calls on my-bucket/* that lack the right headers:
// Require SSE-KMS "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" } }
// Require SSE-C "Condition": { "Null": { "s3:x-amz-server-side-encryption-customer-algorithm": "true" } }
Bucket policies are evaluated before default encryption.
http://example.com/app1 and http://example.com/app2http://www.example.com and http://other.example.comAccess-Control-Allow-OriginOrigin = scheme + host + port
The implied port is 443 for HTTPS and 80 for HTTP.
* for all origins. A popular exam questionMFA required to
MFA not required to
Do not try this at home.
--expires-in seconds. Default 3600, max 604800 (~168 hours)Premium downloads
Let only logged-in users download a premium video from your S3 bucket.
Dynamic access
Let an ever-changing list of users download files by generating URLs on the fly.
Temporary uploads
Let a user upload a file to one precise location in your bucket, for a limited time.
WORM for individual object versions: block deletion for a set time. Versioning must be enabled.
Compliance mode
No user, not even root, can overwrite or delete a version. Modes can't change and periods can't shorten.
Governance mode
Most users can't overwrite, delete, or change lock settings. Users with special permissions can.
Retention period
Protects the object for a fixed period. The period can be extended.
Legal hold
Protects the object indefinitely. Placed and removed with s3:PutObjectLegalHold.
Organizations, SCPs, IAM conditions, permission boundaries, Identity Center, and Control Tower
Billing benefits
By business unit
By environment lifecycle
By project
Advantages
Security: Service Control Policies (SCP)
Blocklist: allow everything, then deny specific services
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowsAllActions",
"Effect": "Allow",
"Action": "*",
"Resource": "*"
},
{
"Sid": "DenyDynamoDB",
"Effect": "Deny",
"Action": "dynamodb:*",
"Resource": "*"
}
]
}Allowlist: allow only the services you list
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:*",
"cloudwatch:*"
],
"Resource": "*"
}
]
}More examples: docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_example-scps.html
{
"tags": {
"costcenter": {
"tag_key": { "@@assign": "CostCenter" },
"tag_value": { "@@assign": ["100", "200"] },
"enforced_for": { "@@assign": ["secretsmanager:*"] }
}
}
}aws:SourceIp restricts the client IP that API calls come from
{
"Effect": "Deny",
"Action": "*",
"Resource": "*",
"Condition": {
"NotIpAddress": {
"aws:SourceIp": [
"192.0.2.0/24",
"203.0.113.0/24"
]
}
}
}aws:RequestedRegion restricts the Region API calls go to
{
"Effect": "Deny",
"Action": ["ec2:*", "rds:*", "dynamodb:*"],
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:RequestedRegion": [
"eu-central-1",
"eu-west-1"
]
}
}
}ec2:ResourceTag restricts actions based on tags
{
"Effect": "Allow",
"Action": ["ec2:StartInstances", "ec2:StopInstances"],
"Resource": "arn:aws:ec2:*:*:instance/*",
"Condition": {
"StringEquals": {
"ec2:ResourceTag/Project": "DataAnalytics",
"aws:PrincipalTag/Department": "Data"
}
}
}aws:MultiFactorAuthPresent forces MFA
{
"Effect": "Deny",
"Action": ["ec2:StopInstances", "ec2:TerminateInstances"],
"Resource": "*",
"Condition": {
"BoolIfExists": {
"aws:MultiFactorAuthPresent": false
}
}
}
arn:aws:s3:::test
Bucket level
s3:ListBucket applies to the bucket ARN

arn:aws:s3:::test/*
Object level
s3:GetObject, s3:PutObject, s3:DeleteObject apply to objects
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket"],
"Resource": "arn:aws:s3:::test"
},
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject"
],
"Resource": "arn:aws:s3:::test/*"
}
]
}Use aws:PrincipalOrgID in any resource policy to allow only accounts that are members of your AWS Organization.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": ["s3:PutObject", "s3:GetObject"],
"Resource": "arn:aws:s3:::2022-financial-data/*",
"Condition": {
"StringEquals": {
"aws:PrincipalOrgID": ["o-yyyyyyyyyy"]
}
}
}
]
}Cross-account access: attach a resource-based policy to the resource (such as an S3 bucket policy), or use a role as a proxy.

Assume a role
A user, application, or service gives up its original permissions and takes the role's permissions.
Resource-based policy
The principal keeps its own permissions. Supported by S3 buckets, SNS topics, SQS queues, and more.
Example: a user in account A scans a DynamoDB table in account A and writes the dump to an S3 bucket in account B. With a role, they would lose access to the table. A bucket policy lets them keep both.
Permission boundary
{
"Effect": "Allow",
"Action": [
"s3:*",
"cloudwatch:*",
"ec2:*"
],
"Resource": "*"
}+
IAM policy
{
"Effect": "Allow",
"Action": "iam:CreateUser",
"Resource": "*"
}=
No permissions
iam:CreateUser is outside the boundary
docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "sqs:*",
"Effect": "Deny",
"Resource": "*"
},
{
"Action": [
"sqs:DeleteQueue"
],
"Effect": "Allow",
"Resource": "*"
}
]
}No
Can you perform sqs:CreateQueue?
The explicit deny on sqs:* blocks it.
No
Can you perform sqs:DeleteQueue?
An explicit deny always beats an allow.
No
Can you perform ec2:DescribeInstances?
Nothing allows it, so it is implicitly denied.

Successor to AWS Single Sign-On
One place to manage workforce access to every AWS account and business app.

1 Sign in
Users sign in once to the AWS access portal.

2 Pick an account
The portal lists every account the user can reach.

3 Choose a role
A permission set opens the console with the right access.
Multi-account permissions
Application assignments
Attribute-based access control

AWS Managed Microsoft AD

AD Connector

Simple AD
Benefits
Ongoing governance for every account in your Control Tower environment
Uses SCPs
Preventive guardrail
Example: restrict Regions across all accounts
Uses AWS Config
Detective guardrail
Example: find untagged resources
KMS, Parameter Store, Secrets Manager, ACM, CloudHSM, WAF, Shield, GuardDuty, Inspector, and Macie
Never store secrets in plaintext, especially in your code.
Use KMS through the API
KMS keys are the new name for KMS customer master keys (CMK).
AES-256
Symmetric
RSA and ECC key pairs
Asymmetric
aws/service-name, such as aws/rdsAutomatic rotation
Default key policy
Custom key policy
Create a snapshot encrypted with your customer managed key
Attach a key policy that allows cross-account access
Share the encrypted snapshot
In the target account, copy the snapshot and encrypt it with a key there
Create a volume from the snapshot
{
"Sid": "AllowUseByDestinationAccount",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::TARGET-ACCOUNT-ID:role/ROLENAME"
},
"Action": ["kms:Decrypt", "kms:CreateGrant"],
"Resource": "*",
"Condition": {
"StringEquals": {
"kms:ViaService": "ec2.REGION.amazonaws.com",
"kms:CallerAccount": "TARGET-ACCOUNT-ID"
}
}
}Replicated by default
Unencrypted objects and objects encrypted with SSE-S3
Can be replicated
Objects encrypted with SSE-C (customer-provided key)
SSE-KMS: enable the option
kms:Decrypt (source) and kms:Encrypt (target)Multi-Region KMS keys work, but S3 treats them as independent keys: objects are still decrypted and re-encrypted.
The AMI in the source account is encrypted with a KMS key from that account
Modify the image attribute: add a launch permission for the target account
Share the KMS key used for the AMI's snapshots with the target account or role
The target role or user needs DescribeKey, ReEncrypt*, CreateGrant, Decrypt
At launch, the target can re-encrypt the volumes with its own KMS key
Organize parameters in paths. Some paths are special:
/aws/reference/secretsmanager/<secret_ID> reads a Secrets Manager secret/aws/service/ami-amazon-linux-latest/... returns the latest public AMIExpiration: delete the parameter
{
"Type": "Expiration",
"Version": "1.0",
"Attributes": {
"Timestamp": "2020-12-02T21:34:33Z"
}
}ExpirationNotification (EventBridge)
{
"Type": "ExpirationNotification",
"Version": "1.0",
"Attributes": {
"Before": "15",
"Unit": "Days"
}
}NoChangeNotification (EventBridge)
{
"Type": "NoChangeNotification",
"Version": "1.0",
"Attributes": {
"After": "20",
"Unit": "Days"
}
}Mostly meant for RDS integration.
List the domain names
FQDN such as corp.example.com, or a wildcard such as *.example.com
Choose a validation method
DNS validation (preferred for automation, a CNAME record in Route 53) or email validation (WHOIS contacts)
Wait a few hours for verification
The certificate is enrolled for automatic renewal
ACM renews its own certificates 60 days before expiry
acm-certificate-expiration-check flags expiring certificates
Default · global clients
Edge-optimized
Clients in the same Region
Regional
Inside your VPC
Private
Create a custom domain name in API Gateway.

Edge-optimized
Regional
Then point a CNAME or, better, an A-Alias record in Route 53 at it.
IAM permissions cover creating, reading, updating, and deleting an HSM cluster. The CloudHSM software manages the keys and the users.

Deploy on
Web ACLs are Regional, except for CloudFront.
A rule group is a reusable set of rules you add to a web ACL.
DDoS: Distributed Denial of Service, many requests at the same time.

Free · on for every customer
Shield Standard

$3,000 per month per organization
Shield Advanced

Security policy: a common set of rules

AWS WAF
Define your web ACL rules. For granular protection of individual resources, WAF alone is the right choice.

AWS Firewall Manager
Use WAF across accounts, speed up configuration, and protect new resources automatically.

AWS Shield Advanced
Adds the Shield Response Team and advanced reporting on top of WAF. Worth it if you face frequent DDoS attacks.
They work together for comprehensive protection.

BP1
CloudFront

BP1
Global Accelerator

BP3
Route 53
BP1, BP3, BP6
Infrastructure layer defense

BP7
EC2 with Auto Scaling

BP6
Elastic Load Balancing
BP1, BP2
Detect and filter malicious requests

BP1, BP2, BP6
Shield Advanced
BP1, BP4, BP6
Obfuscate AWS resources
BP5
Security groups and NACLs

BP4
Protect API endpoints
Input data
Automated security assessments for:
Reports to Security Hub and sends findings to EventBridge.
Remember
Inspector is for EC2, container images, and Lambda only.
Subnets, gateways, NAT, NACLs, peering, endpoints, VPN, Direct Connect, and Transit Gateway
WW.XX.YY.ZZ/32 is one IP0.0.0.0/0 is all IPs192.168.0.0/26 is 192.168.0.0 to 192.168.0.63 (64 addresses)122.149.196.85/320.0.0.0/0Base IP
XX.XX.XX.XX)10.0.0.0, 192.168.0.0Subnet mask
/0, /24, /32/8 = 255.0.0.0, /16 = 255.255.0.0, /24 = 255.255.255.0, /32 = 255.255.255.255Quick memo
/32: no octet changes/24: last octet changes/16: last 2 octets/8: last 3 octets/0: all octets192.168.0.0/24
192.168.0.0 to 192.168.0.255 (256 IPs)
192.168.0.0/16
192.168.0.0 to 192.168.255.255 (65,536 IPs)
134.56.78.123/32
Just 134.56.78.123
0.0.0.0/0
All IPs
When in doubt, use ipaddressguide.com/cidr.
The Internet Assigned Numbers Authority (IANA) set aside blocks of IPv4 addresses for private (LAN) use. Everything else on the internet is public.
10.0.0.0/8172.16.0.0/12192.168.0.0/16/28 (16 IPs)/16 (65,536 IPs)Private ranges only
10.0.0.0/8172.16.0.0/12192.168.0.0/16We start with an empty VPC in a Region.
Add a public and a private subnet in one Availability Zone.
AWS reserves 5 IP addresses in every subnet: the first 4 and the last 1. For 10.0.0.0/24:
Exam tip: you need 29 IPs
/27 gives 32 - 5 = 27. Too few/26 gives 64 - 5 = 59. Choose thisAn IGW alone does not give internet access. You must also edit the route tables.
Attach an internet gateway to the VPC.
Route the public subnet to the internet gateway, then launch a public instance.
Private instances reach the internet through the NAT instance in the public subnet.
You manage the security groups
5 Gbps
with automatic scaling up to 100 Gbps
No security groups
nothing to manage
The NAT gateway lives in the public subnet and sends private traffic out through the IGW.
RNAT route table
Private subnet route table (AZ A and AZ B)
NACLs check every packet in both directions. Security groups remember allowed connections, so the reply is allowed automatically.
NACL rules
#100 ALLOW 10.0.0.10/32 beats #200 DENY 10.0.0.10/32*, denies anything unmatchedEach subnet gets a NACL that filters traffic at the subnet boundary.
Accepts everything inbound and outbound for its subnets. Don't modify it: create custom NACLs instead.
Inbound rules
Outbound rules
docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html#nacl-ephemeral-ports
sg-04991f9af3473b939 / default606412510120 / sg-027ad1f7865d4be76The second rule references a security group in another account by account ID.
Peering connections link this VPC to others.
VPC endpoints reach S3 and DynamoDB without leaving the AWS network.
PrivateLink
Interface endpoint
Route table target
Gateway endpoint
Flow logs record traffic metadata for the VPC and send it to CloudWatch Logs or S3.
Each flow log record is one line with these fields, in order. The bold fields matter most for troubleshooting.
version2account-id123456789010interface-ideni-1235b8ca123456789172.31.16.139172.31.16.212064122protocol6 (TCP)packets20bytes4249start1418530010end1418530070ACCEPTlog-statusOK2 123456789010 eni-1235b8ca123456789 172.31.16.139 172.31.16.21 20641 22 6 20 4249 1418530010 1418530070 ACCEPT OK 2 123456789010 eni-1235b8ca123456789 172.31.9.69 172.31.9.12 49761 3389 6 20 4249 1418530010 1418530070 REJECT OK
Look at the action field for the request and its response:
Security groups are stateful: once a request is accepted, its response is allowed. A rejected response points to the stateless NACL.
Find top talkers, alert on SSH or RDP attempts, or run SQL analytics and dashboards.
logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents",
"logs:DescribeLogGroups",
"logs:DescribeLogStreams"
],
"Resource": "*"
}]
}A Site-to-Site VPN links the VPC to your corporate data center over the public internet.

Virtual private gateway (VGW)

Customer gateway (CGW)
More bandwidth
Large data sets at lower cost
Consistent network
Apps with real-time data feeds
Hybrid environments
On-premises plus cloud
Direct Connect adds a private, dedicated link alongside (or instead of) the VPN.
1 Gbps to 400 Gbps
Dedicated connections
50 Mbps to 25 Gbps
Hosted connections
Lead times are often longer than 1 month to establish a new connection.
High resiliency for critical workloads
One connection at multiple locations
Maximum resiliency for critical workloads
Separate connections on separate devices in more than one location
If Direct Connect fails, fail over to a second DX connection (expensive) or a Site-to-Site VPN.
Peering is not transitive, so every new VPC adds more peering, VPN, and DX links.
Each VPN connection has 2 tunnels. With ECMP, the Transit Gateway uses both and scales as you add connections.
Share the Transit Gateway with other accounts using AWS Resource Access Manager (RAM).
x:x:x:x:x:x:x:x, where each x is hexadecimal from 0000 to ffff2001:db8:3333:4444:5555:6666:7777:8888::2001:db8::::1234:56782001:db8::1234:567810.0.0.0/162001:db8:1234:1a00::/560.0.0.0/0igw-id::/0igw-id10.0.0.0/162001:db8:1234:1a00::/560.0.0.0/0nat-gateway-id::/0eigw-idPrivate subnet 1 routes 0.0.0.0/0 to the NAT gateway. Private subnet 2 routes the S3 prefix list to the endpoint.
So far, you have seen these ways to protect your network:

NACLs
Subnet-level rules
Security groups
Instance-level rules

AWS WAF
Block malicious requests

AWS Shield
DDoS protection (and Advanced)

Firewall Manager
Manage them across accounts
What if you want to protect your entire VPC in a sophisticated way?
IP and port
Filter 10,000s of IPs
Protocol
Block SMB for outbound traffic
Domain lists
Only allow *.mycorp.com or a software repo
Pattern matching
General matching with regex