Intellectual Point Amazon Web Services
Cloud Architect Pathway

AWS Solutions Architect Associate

Domain 1: Design Secure Architectures

AWS Solutions Architect Associate · Domain 1 001
Intellectual Point Amazon Web Services
Section 1

Getting Started with AWS

Regions, Availability Zones, edge locations, and a tour of the console

AWS Solutions Architect Associate · Domain 1 002
Intellectual Point Amazon Web Services
Getting started

Course overview

SAA-C03 scores four domains. This deck covers Domain 1. Domains 2 to 4 each have their own deck, labs, and challenges.

1This deck

Domain 1

Design Secure Architectures

30%

of scored content

2

Domain 2

Design Resilient Architectures

26%

of scored content

3

Domain 3

Design High-Performing Architectures

24%

of scored content

4

Domain 4

Design Cost-Optimized Architectures

20%

of scored content

AWS Solutions Architect Associate · Domain 1 003
Intellectual Point Amazon Web Services
Getting started

Agenda

1

Getting Started with AWS

Regions, Availability Zones, edge locations, and a tour of the console

2

AWS Identity and Access Management

Users, groups, policies, MFA, roles, and the CLI and SDK

3

Amazon S3 Security

Encryption, CORS, MFA Delete, pre-signed URLs, Object Lock, and access points

4

Advanced Identity in AWS

Organizations, SCPs, IAM conditions, permission boundaries, Identity Center, and Control Tower

5

AWS Security and Encryption

KMS, Parameter Store, Secrets Manager, ACM, CloudHSM, WAF, Shield, GuardDuty, Inspector, and Macie

6

Amazon VPC

Subnets, gateways, NAT, NACLs, peering, endpoints, VPN, Direct Connect, and Transit Gateway

AWS Solutions Architect Associate · Domain 1 004
Intellectual Point Amazon Web Services
Getting started

AWS Cloud History

2002Internallylaunched2003Infrastructure is a corestrength: idea to market2004Launched publiclywith SQS2006Relaunched withSQS, S3 and EC22007Launched inEurope
AWS Solutions Architect Associate · Domain 1 005
Intellectual Point Amazon Web Services
Getting started

AWS Cloud Number Facts

$90B

annual revenue in 2023

31%

of the cloud market in Q1 2024. Microsoft is second with 25%.

13 years

in a row as the cloud market leader

1M+

active users

Gartner Magic Quadrant for Strategic Cloud Platform Services
AWS Solutions Architect Associate · Domain 1 006
Intellectual Point Amazon Web Services
Getting started

AWS Cloud Use Cases

  • AWS lets you build sophisticated, scalable applications
  • It applies to a diverse set of industries
  • Use cases include
    • Enterprise IT, backup and storage, big data analytics
    • Website hosting, mobile and social apps
    • Gaming
AWS Solutions Architect Associate · Domain 1 007
Intellectual Point Amazon Web Services
Getting started

AWS Global Infrastructure

Regions

Geographic areas such as us-east-1

Availability Zones

Isolated locations inside a Region

Data centers

The buildings that make up each AZ

Edge locations

Points of Presence that serve content near users

Explore it live at infrastructure.aws

AWS Solutions Architect Associate · Domain 1 008
Intellectual Point Amazon Web Services
Getting started

AWS Regions

  • AWS has Regions all around the world
  • Region names look like us-east-1 or eu-west-3
  • A Region is a cluster of data centers
  • Most AWS services are Region-scoped
us-east-1us-west-2sa-east-1eu-west-3af-south-1ap-south-1ap-southeast-2ap-northeast-1
AWS Solutions Architect Associate · Domain 1 009
Intellectual Point Amazon Web Services
Getting started

How to choose an AWS Region?

You need to launch a new application. Where should it run?

Compliance

Meet data governance and legal requirements. Data never leaves a Region without your explicit permission.

Proximity

Run close to your customers to reduce latency.

Available services

New services and features are not available in every Region.

Pricing

Pricing varies by Region. Each service's pricing page shows it.

AWS Solutions Architect Associate · Domain 1 010
Intellectual Point Amazon Web Services
Getting started

AWS Availability Zones

  • Each Region has several Availability Zones: usually 3, minimum 3, maximum 6
    • ap-southeast-2a, ap-southeast-2b, ap-southeast-2c
  • Each AZ is one or more discrete data centers with redundant power, networking, and connectivity
  • AZs are separate from each other, so they are isolated from disasters
  • They connect over high bandwidth, ultra-low latency networking
AWS Region · Sydney ap-southeast-2ap-southeast-2aap-southeast-2bap-southeast-2c
AWS Solutions Architect Associate · Domain 1 011
Intellectual Point Amazon Web Services
Getting started

AWS Points of Presence (Edge Locations)

400+

Points of Presence

10+

Regional Caches

90+

cities

40+

countries

Content is delivered to end users with lower latency.

Orange: edge locations · Blue: regional edge caches

AWS Solutions Architect Associate · Domain 1 012
Intellectual Point Amazon Web Services
Getting started

Tour of the AWS Console

One copy, worldwide

Global services

  • Identity and Access Management (IAM)
  • Route 53 (DNS service)
  • CloudFront (content delivery network)
  • WAF (web application firewall)

Most AWS services

Region-scoped services

  • Amazon EC2 (infrastructure as a service)
  • Elastic Beanstalk (platform as a service)
  • Lambda (function as a service)
  • Rekognition (software as a service)

Region table: aws.amazon.com/about-aws/global-infrastructure/regional-product-services

AWS Solutions Architect Associate · Domain 1 013
Intellectual Point Amazon Web Services
Section 2

AWS Identity and Access Management

Users, groups, policies, MFA, roles, and the CLI and SDK

AWS Solutions Architect Associate · Domain 1 014
Intellectual Point Amazon Web Services
IAM

IAM: Users & Groups

  • IAM = Identity and Access Management, a global service
  • The root account is created by default. Do not use or share it
  • Users are people in your organization and can be grouped
  • Groups contain users only, never other groups
  • A user can belong to no group, one group, or several
DevelopersAudit TeamOperationsNo group Alice Bob Charles David Edward Fred
AWS Solutions Architect Associate · Domain 1 015
Intellectual Point Amazon Web Services
IAM

IAM: Permissions

  • Users or groups can be assigned JSON documents called policies
  • Policies define the permissions of the users
  • Apply the least privilege principle: never grant more permissions than a user needs
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:Describe*",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cloudwatch:ListMetrics",
        "cloudwatch:GetMetricStatistics"
      ],
      "Resource": "*"
    }
  ]
}
AWS Solutions Architect Associate · Domain 1 016
Intellectual Point Amazon Web Services
IAM

IAM Policies Inheritance

DevelopersAudit TeamOperationsNo group Alice Bob Charles David Edward Fred inline

Users inherit the policies of every group they belong to. An inline policy attaches to one user only.

AWS Solutions Architect Associate · Domain 1 017
Intellectual Point Amazon Web Services
IAM

IAM Policies Structure

  • A policy consists of
    • Version: the policy language version. Always 2012-10-17
    • Id: an identifier for the policy (optional)
    • Statement: one or more statements (required)
  • Each statement consists of
    • Sid: an identifier for the statement (optional)
    • Effect: Allow or Deny
    • Principal: the account, user, or role it applies to
    • Action: the actions it allows or denies
    • Resource: the resources the actions apply to
    • Condition: when the statement is in effect (optional)
{
  "Version": "2012-10-17",
  "Id": "S3-Account-Permissions",
  "Statement": [
    {
      "Sid": "1",
      "Effect": "Allow",
      "Principal": {
        "AWS": ["arn:aws:iam::123456789012:root"]
      },
      "Action": [
        "s3:GetObject",
        "s3:PutObject"
      ],
      "Resource": ["arn:aws:s3:::mybucket/*"]
    }
  ]
}
AWS Solutions Architect Associate · Domain 1 018
Intellectual Point Amazon Web Services
IAM

IAM: Password Policy

Strong passwords mean higher security. An IAM password policy can:

  • Set a minimum password length
  • Require character types: uppercase, lowercase, numbers, non-alphanumeric
  • Let all IAM users change their own passwords
  • Require password expiration after a set time
  • Prevent password reuse
Password policyMinimum length12 charactersCharacter typesAa · 0-9 · #!Self-service changeAllowedExpiration90 daysPrevent reuseLast 5 passwords
AWS Solutions Architect Associate · Domain 1 019
Intellectual Point Amazon Web Services
IAM

Multi-Factor Authentication (MFA)

  • Users can change configurations or delete resources in your AWS account
  • Protect your root account and your IAM users
  • MFA = a password you know + a security device you own
Alice Passwordsomething you know+MFA devicesomething you own Successful login

Main benefit: if a password is stolen or hacked, the account is not compromised.

AWS Solutions Architect Associate · Domain 1 020
Intellectual Point Amazon Web Services
IAM

MFA Device Options in AWS

Virtual MFA device

Google Authenticator, Authy (phone only)

Multiple tokens on a single device

U2F security key

YubiKey by Yubico (third party)

Multiple root and IAM users on a single key

Hardware key fob

Gemalto (third party)

A dedicated device that shows a one-time code

Key fob for AWS GovCloud (US)

SurePassID (third party)

The hardware option for GovCloud accounts

AWS Solutions Architect Associate · Domain 1 021
Intellectual Point Amazon Web Services
IAM

How Can Users Access AWS?

AWS Management Console

Protected by password + MFA

AWS CLI

Protected by access keys

AWS SDK (for code)

Protected by access keys

  • Access keys are generated in the AWS Console
  • Users manage their own access keys
  • Access keys are secret, like a password. Never share them
Access key ID
AKIASK4E37PV4983d6C
Secret access key
AZPN3zojWozWCndIjhB0Unh8239a1bzbzO5fqqkZq

Notional example. The access key ID works like a username, the secret access key like a password.

AWS Solutions Architect Associate · Domain 1 022
Intellectual Point Amazon Web Services
IAM

What's the AWS CLI?

  • A tool to interact with AWS services using commands in your shell
  • Direct access to the public APIs of AWS services, so you can script your resources
  • Open source (github.com/aws/aws-cli) and an alternative to the Management Console
Terminal
$ aws s3 cp myfile.txt s3://ccp-mybucket/myfile.txt
upload: ./myfile.txt to s3://ccp-mybucket/myfile.txt

$ aws s3 ls s3://ccp-mybucket
2025-05-14 03:22:52          0 myfile.txt
AWS Solutions Architect Associate · Domain 1 023
Intellectual Point Amazon Web Services
IAM

What's the AWS SDK?

  • AWS Software Development Kit: language-specific APIs (libraries)
  • Access and manage AWS services programmatically
  • Embedded within your application
  • Supports
    • SDKs: JavaScript, Python, PHP, .NET, Ruby, Java, Go, Node.js, C++
    • Mobile SDKs: Android, iOS
    • IoT device SDKs: Embedded C, Arduino
  • The AWS CLI is built on the AWS SDK for Python
Your applicationAWS servicesAWS SDKPython · Java · JavaScript · Go · .NET ...API callsAmazon S3Amazon EC2IAM
AWS Solutions Architect Associate · Domain 1 024
Intellectual Point Amazon Web Services
IAM

IAM Roles for Services

  • Some AWS services need to perform actions on your behalf
  • Give AWS services permissions with IAM roles
  • Common roles
    • EC2 instance roles
    • Lambda function roles
    • Roles for CloudFormation
IAM RoleEC2 instancevirtual serverAccess AWSAWS services
AWS Solutions Architect Associate · Domain 1 025
Intellectual Point Amazon Web Services
IAM

IAM Security Tools

Account level

IAM Credentials Report

Lists every user in your account and the status of their credentials.

User level

IAM Access Advisor

Shows the service permissions granted to a user and when each service was last accessed. Use it to tighten policies.

AWS Solutions Architect Associate · Domain 1 026
Intellectual Point Amazon Web Services
IAM

IAM Guidelines & Best Practices

  • Use the root account only for account setup
  • One physical user = one AWS user
  • Assign users to groups and give permissions to groups
  • Create a strong password policy
  • Use and enforce MFA
  • Use roles to give permissions to AWS services
  • Use access keys for programmatic access (CLI / SDK)
  • Audit permissions with the Credentials Report and Access Advisor

Never share IAM users or access keys.

AWS Solutions Architect Associate · Domain 1 027
Intellectual Point Amazon Web Services
IAM

IAM Section Summary

Users

Mapped to a physical person, with a password for the AWS Console

Groups

Contain users only

Policies

JSON documents that set permissions for users or groups

Roles

Permissions for AWS services, such as EC2 instances

Security

MFA + password policy

AWS CLI

Manage AWS services from the command line

AWS SDK

Manage AWS services from a programming language

Access keys

Access AWS with the CLI or SDK

Audit

IAM Credentials Report and IAM Access Advisor

AWS Solutions Architect Associate · Domain 1 028
Intellectual Point Amazon Web Services
Section 3

Amazon S3 Security

Encryption, CORS, MFA Delete, pre-signed URLs, Object Lock, and access points

AWS Solutions Architect Associate · Domain 1 029
Intellectual Point Amazon Web Services
S3 security

Amazon S3: Object Encryption

You can encrypt objects in S3 buckets with one of four methods:

Server-side · default

SSE-S3

Keys handled, managed, and owned by AWS. Enabled by default.

Server-side

SSE-KMS

Keys stored and managed in AWS Key Management Service (KMS).

Server-side

SSE-C

Customer-provided keys. You manage your own encryption keys.

Client-side

Client-side encryption

You encrypt before upload and decrypt after download.

For the exam, know which method fits which situation.

AWS Solutions Architect Associate · Domain 1 030
Intellectual Point Amazon Web Services
S3 security

Amazon S3 Encryption: SSE-S3

  • Encryption with keys handled, managed, and owned by AWS
  • Objects are encrypted server-side with AES-256
  • Set header "x-amz-server-side-encryption": "AES256"
  • Enabled by default for new buckets and new objects
Amazon S3UserHTTP(S) + headerObject+S3-owned keyEncryptionS3 bucket
AWS Solutions Architect Associate · Domain 1 031
Intellectual Point Amazon Web Services
S3 security

Amazon S3 Encryption: SSE-KMS

  • Encryption with keys handled and managed by AWS KMS
  • KMS advantages: user control + audit key usage with CloudTrail
  • Objects are encrypted server-side
  • Set header "x-amz-server-side-encryption": "aws:kms"
Amazon S3UserHTTP(S) + headerObject+KMS keyAWS KMSEncryptionS3 bucket
AWS Solutions Architect Associate · Domain 1 032
Intellectual Point Amazon Web Services
S3 security

SSE-KMS Limitation

  • SSE-KMS can hit KMS request limits
  • Upload calls the GenerateDataKey KMS API
  • Download calls the Decrypt KMS API
  • Calls count toward the KMS quota per second
  • Request a quota increase in the Service Quotas console
5,500 req/s10,000 req/s30,000 req/s (varies by Region)
UsersUpload / downloadS3 bucketSSE-KMSAPI callKMS keyGenerateDataKey on uploadDecrypt on download
AWS Solutions Architect Associate · Domain 1 033
Intellectual Point Amazon Web Services
S3 security

Amazon S3 Encryption: SSE-C

  • Server-side encryption with keys fully managed by you, outside AWS
  • Amazon S3 does not store the encryption key you provide
  • HTTPS is required
  • Provide the key in HTTP headers on every request
Amazon S3UserHTTPS only + key in headerClient-provided keyObject+Client-provided keyEncryptionS3 bucket
AWS Solutions Architect Associate · Domain 1 034
Intellectual Point Amazon Web Services
S3 security

Amazon S3 Encryption: Client-Side

  • Use client libraries such as the Amazon S3 Client-Side Encryption Library
  • Clients encrypt data before sending it to Amazon S3
  • Clients decrypt data after retrieving it from Amazon S3
  • You fully manage the keys and the encryption cycle
Amazon S3UserFile+Client keyEncryptEncrypted fileHTTP(S) uploadS3 bucket
AWS Solutions Architect Associate · Domain 1 035
Intellectual Point Amazon Web Services
S3 security

Amazon S3: Encryption in Transit (SSL/TLS)

  • Encryption in flight is also called SSL/TLS
  • Amazon S3 exposes two endpoints
    • HTTP: not encrypted
    • HTTPS: encryption in flight
  • HTTPS is recommended, and mandatory for SSE-C
  • Most clients use the HTTPS endpoint by default
HTTP endpointHTTPS endpointClientNot encryptedEncrypted in flight
AWS Solutions Architect Associate · Domain 1 036
Intellectual Point Amazon Web Services
S3 security

Amazon S3: Force Encryption in Transit

UserUserhttpshttpmy-bucketBucket policy

Deny any request where aws:SecureTransport is false. HTTP calls are refused.

Bucket policy
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "Bool": { "aws:SecureTransport": "false" }
      }
    }
  ]
}
AWS Solutions Architect Associate · Domain 1 037
Intellectual Point Amazon Web Services
S3 security

Amazon S3: Default Encryption vs. Bucket Policies

SSE-S3 is applied automatically to new objects. To force a specific method, a bucket policy can deny s3:PutObject calls on my-bucket/* that lack the right headers:

// Require SSE-KMS
"Condition": {
  "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" }
}
// Require SSE-C
"Condition": {
  "Null": { "s3:x-amz-server-side-encryption-customer-algorithm": "true" }
}

Bucket policies are evaluated before default encryption.

AWS Solutions Architect Associate · Domain 1 038
Intellectual Point Amazon Web Services
S3 security

What is CORS?

  • Cross-Origin Resource Sharing: a web browser mechanism that allows requests to other origins while visiting the main origin
  • Same origin: http://example.com/app1 and http://example.com/app2
  • Different origins: http://www.example.com and http://other.example.com
  • Requests are refused unless the other origin allows them with CORS headers, such as Access-Control-Allow-Origin

Origin = scheme + host + port

https://schemewww.example.comhost:443port

The implied port is 443 for HTTPS and 80 for HTTP.

AWS Solutions Architect Associate · Domain 1 039
Intellectual Point Amazon Web Services
S3 security

How CORS Works

Web serverwww.example.comOriginWeb browserWeb serverwww.other.comCross-origin1 HTTPS request for the page2 Preflight: OPTIONS /Origin: https://www.example.com3 Access-Control-Allow-Origin: https://www.example.comAccess-Control-Allow-Methods: GET, PUT, DELETE4 GET / with the Origin header
AWS Solutions Architect Associate · Domain 1 040
Intellectual Point Amazon Web Services
S3 security

Amazon S3: CORS

  • A cross-origin request to your bucket needs the right CORS headers on that bucket
  • Allow a specific origin, or * for all origins. A popular exam question
Web browserGET /index.htmlGET /images/coffee.jpg + Origin headermy-bucket-htmlstatic website, serves index.htmlmy-bucket-assetsstatic website, CORS enabledAccess-Control-Allow-Origin: http://my-bucket-html.s3-website...
AWS Solutions Architect Associate · Domain 1 041
Intellectual Point Amazon Web Services
S3 security

Amazon S3: MFA Delete

  • Users must enter an MFA code before important S3 operations
  • Versioning must be enabled on the bucket
  • Only the bucket owner (root account) can enable or disable MFA Delete

MFA required to

  • Permanently delete an object version
  • Suspend versioning on the bucket

MFA not required to

  • Enable versioning
  • List deleted versions
MFA devicesGoogle AuthenticatorHardware device
AWS Solutions Architect Associate · Domain 1 042
Intellectual Point Amazon Web Services
S3 security

S3 Access Logs

  • For audits, log all access to an S3 bucket
  • Every request, from any account, authorized or denied, is logged to another S3 bucket
  • Analyze the logs with data analysis tools
  • The logging bucket must be in the same AWS Region
RequestsMy-bucketLog all requestsLogging bucket
AWS Solutions Architect Associate · Domain 1 043
Intellectual Point Amazon Web Services
S3 security

S3 Access Logs: Warning

  • Never set your logging bucket to be the monitored bucket
  • It creates a logging loop, and the bucket grows exponentially

Do not try this at home.

App bucket = logging bucketPutObjectLogging loop
AWS Solutions Architect Associate · Domain 1 044
Intellectual Point Amazon Web Services
S3 security

Amazon S3: Pre-Signed URLs

  • Generate pre-signed URLs with the S3 Console, AWS CLI, or SDK
  • Users with the URL inherit the permissions of the user who generated it, for GET and PUT
Tool
URL expiration
S3 Console
1 min to 720 min (12 hours)
AWS CLI
--expires-in seconds. Default 3600, max 604800 (~168 hours)
OwnerS3 bucketprivateUsergenerate URLshare URLuse URL
AWS Solutions Architect Associate · Domain 1 045
Intellectual Point Amazon Web Services
S3 security

Pre-Signed URLs: Examples

Premium downloads

Let only logged-in users download a premium video from your S3 bucket.

Dynamic access

Let an ever-changing list of users download files by generating URLs on the fly.

Temporary uploads

Let a user upload a file to one precise location in your bucket, for a limited time.

AWS Solutions Architect Associate · Domain 1 046
Intellectual Point Amazon Web Services
S3 security

S3 Glacier Vault Lock

  • Adopt a WORM model: Write Once, Read Many
  • Create a Vault Lock policy
  • Lock the policy against future edits. It can no longer be changed or deleted
  • Helpful for compliance and data retention
ObjectGlacier vaultVault Lock policyObject can't be deleted
AWS Solutions Architect Associate · Domain 1 047
Intellectual Point Amazon Web Services
S3 security

S3 Object Lock

WORM for individual object versions: block deletion for a set time. Versioning must be enabled.

Compliance mode

No user, not even root, can overwrite or delete a version. Modes can't change and periods can't shorten.

Governance mode

Most users can't overwrite, delete, or change lock settings. Users with special permissions can.

Retention period

Protects the object for a fixed period. The period can be extended.

Legal hold

Protects the object indefinitely. Placed and removed with s3:PutObjectLegalHold.

AWS Solutions Architect Associate · Domain 1 048
Intellectual Point Amazon Web Services
S3 security

S3 Access Points

  • Access points simplify security management for S3 buckets
  • Each has its own DNS name (internet or VPC origin) and an access point policy
FinanceFinance access pointPolicy: R/W /finance/SalesSales access pointPolicy: R/W /sales/AnalyticsAnalytics access pointPolicy: Read whole bucketS3 bucketsimple bucket policy/finance/sales
AWS Solutions Architect Associate · Domain 1 049
Intellectual Point Amazon Web Services
S3 security

S3 Access Points: VPC Origin

  • Make an access point reachable only from within a VPC
  • Create a VPC endpoint (gateway or interface) to reach it
  • The VPC endpoint policy must allow the target bucket and access point
VPCEC2 instanceVPC endpointEndpoint policyAccess pointVPC originAccess point policyS3 bucketBucket policy
AWS Solutions Architect Associate · Domain 1 050
Intellectual Point Amazon Web Services
S3 security

S3 Object Lambda

  • Use Lambda functions to change an object before the caller gets it
  • One bucket, with an S3 access point and Object Lambda access points on top
  • Redact personal data for analytics or non-production
  • Convert formats, such as XML to JSON
  • Resize and watermark images per caller
E-commerce appAnalytics appMarketing appS3 bucketSupportingaccess pointoriginal objectObject Lambdaaccess pointRedactingLambda functionObject Lambdaaccess pointEnrichingLambda functionCustomer loyalty DB
AWS Solutions Architect Associate · Domain 1 051
Intellectual Point Amazon Web Services
Section 4

Advanced Identity in AWS

Organizations, SCPs, IAM conditions, permission boundaries, Identity Center, and Control Tower

AWS Solutions Architect Associate · Domain 1 052
Intellectual Point Amazon Web Services
Advanced identity

AWS Organizations

  • A global service to manage multiple AWS accounts
  • The main account is the management account. The others are member accounts
  • A member account belongs to one organization only
  • An API automates AWS account creation

Billing benefits

  • Consolidated billing: one payment method for all accounts
  • Volume discounts from aggregated usage (EC2, S3...)
  • Reserved Instance and Savings Plans discounts shared across accounts
AWS Solutions Architect Associate · Domain 1 053
Intellectual Point Amazon Web Services
Advanced identity

Organization Structure

Root organizational unit (OU)OU (Dev)OU (Prod)OU (HR)OU (Finance)Management accountMember accounts
AWS Solutions Architect Associate · Domain 1 054
Intellectual Point Amazon Web Services
Advanced identity

Organizational Units (OU): Examples

By business unit

  • Management account
  • Sales OU: account 1, account 2
  • Retail OU: account 1, account 2
  • Finance OU: account 1, account 2

By environment lifecycle

  • Management account
  • Prod OU: account 1, account 2
  • Dev OU: account 1, account 2
  • Test OU: account 1, account 2

By project

  • Management account
  • Project 1 OU: account 1, account 2
  • Project 2 OU: account 1, account 2
  • Project 3 OU: account 1, account 2
AWS Solutions Architect Associate · Domain 1 055
Intellectual Point Amazon Web Services
Advanced identity

AWS Organizations: Advantages and SCPs

Advantages

  • Multi-account instead of one account with many VPCs
  • Tagging standards for billing
  • CloudTrail on all accounts, logs sent to a central S3 account
  • CloudWatch Logs sent to a central logging account
  • Cross-account roles for admin work

Security: Service Control Policies (SCP)

  • IAM policies applied to OUs or accounts to restrict users and roles
  • They do not apply to the management account (full admin power)
  • Need an explicit allow from the root through every OU on the path to the account. Nothing is allowed by default
AWS Solutions Architect Associate · Domain 1 056
Intellectual Point Amazon Web Services
Advanced identity

SCP Hierarchy

OU (Root)OU (Sandbox)OU (Workloads)OU (Test)OU (Prod)FullAWSAccessManagement accountDeny Athena (ignored)FullAWSAccess + Deny S3Account AFullAWSAccess + Deny EC2Account BAccount CFullAWSAccessFullAWSAccessAllow EC2Account DFullAWSAccessAccount EAccount F
Account
Effective access
Management
Anything. SCPs never apply
Account A
Anything except S3 and EC2
Accounts B, C
Anything except S3
Account D
EC2 only
Accounts E, F
Anything
AWS Solutions Architect Associate · Domain 1 057
Intellectual Point Amazon Web Services
Advanced identity

SCP Examples: Blocklist and Allowlist

Blocklist: allow everything, then deny specific services

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowsAllActions",
      "Effect": "Allow",
      "Action": "*",
      "Resource": "*"
    },
    {
      "Sid": "DenyDynamoDB",
      "Effect": "Deny",
      "Action": "dynamodb:*",
      "Resource": "*"
    }
  ]
}

Allowlist: allow only the services you list

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:*",
        "cloudwatch:*"
      ],
      "Resource": "*"
    }
  ]
}

More examples: docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_example-scps.html

AWS Solutions Architect Associate · Domain 1 058
Intellectual Point Amazon Web Services
Advanced identity

AWS Organizations: Tag Policies

  • Standardize tags across resources in an organization
  • Define tag keys and their allowed values
  • Supports Cost Allocation Tags and attribute-based access control
  • Block non-compliant tagging on chosen services (untagged resources are unaffected)
  • Report non-compliant resources. Monitor with EventBridge
{
  "tags": {
    "costcenter": {
      "tag_key": { "@@assign": "CostCenter" },
      "tag_value": { "@@assign": ["100", "200"] },
      "enforced_for": { "@@assign": ["secretsmanager:*"] }
    }
  }
}
AWS Solutions Architect Associate · Domain 1 059
Intellectual Point Amazon Web Services
Advanced identity

IAM Conditions: Source IP and Region

aws:SourceIp restricts the client IP that API calls come from

{
  "Effect": "Deny",
  "Action": "*",
  "Resource": "*",
  "Condition": {
    "NotIpAddress": {
      "aws:SourceIp": [
        "192.0.2.0/24",
        "203.0.113.0/24"
      ]
    }
  }
}

aws:RequestedRegion restricts the Region API calls go to

{
  "Effect": "Deny",
  "Action": ["ec2:*", "rds:*", "dynamodb:*"],
  "Resource": "*",
  "Condition": {
    "StringEquals": {
      "aws:RequestedRegion": [
        "eu-central-1",
        "eu-west-1"
      ]
    }
  }
}
AWS Solutions Architect Associate · Domain 1 060
Intellectual Point Amazon Web Services
Advanced identity

IAM Conditions: Tags and MFA

ec2:ResourceTag restricts actions based on tags

{
  "Effect": "Allow",
  "Action": ["ec2:StartInstances", "ec2:StopInstances"],
  "Resource": "arn:aws:ec2:*:*:instance/*",
  "Condition": {
    "StringEquals": {
      "ec2:ResourceTag/Project": "DataAnalytics",
      "aws:PrincipalTag/Department": "Data"
    }
  }
}

aws:MultiFactorAuthPresent forces MFA

{
  "Effect": "Deny",
  "Action": ["ec2:StopInstances", "ec2:TerminateInstances"],
  "Resource": "*",
  "Condition": {
    "BoolIfExists": {
      "aws:MultiFactorAuthPresent": false
    }
  }
}
AWS Solutions Architect Associate · Domain 1 061
Intellectual Point Amazon Web Services
Advanced identity

IAM for S3

arn:aws:s3:::test

Bucket level

s3:ListBucket applies to the bucket ARN

arn:aws:s3:::test/*

Object level

s3:GetObject, s3:PutObject, s3:DeleteObject apply to objects

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:ListBucket"],
      "Resource": "arn:aws:s3:::test"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:PutObject",
        "s3:GetObject",
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::test/*"
    }
  ]
}
AWS Solutions Architect Associate · Domain 1 062
Intellectual Point Amazon Web Services
Advanced identity

Resource Policies & aws:PrincipalOrgID

Use aws:PrincipalOrgID in any resource policy to allow only accounts that are members of your AWS Organization.

AWS Organizationo-yyyyyyyyyyMember accountsS3 bucket2022-financial-dataUser outside the org
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": ["s3:PutObject", "s3:GetObject"],
      "Resource": "arn:aws:s3:::2022-financial-data/*",
      "Condition": {
        "StringEquals": {
          "aws:PrincipalOrgID": ["o-yyyyyyyyyy"]
        }
      }
    }
  ]
}
AWS Solutions Architect Associate · Domain 1 063
Intellectual Point Amazon Web Services
Advanced identity

IAM Roles vs. Resource-Based Policies

Cross-account access: attach a resource-based policy to the resource (such as an S3 bucket policy), or use a role as a proxy.

Account AAccount BAccount AAccount BRole as a proxy UserRoleAmazon S3assumeResource-based policy UserS3 bucketBucket policy
AWS Solutions Architect Associate · Domain 1 064
Intellectual Point Amazon Web Services
Advanced identity

Roles vs. Resource-Based Policies: The Difference

Assume a role

A user, application, or service gives up its original permissions and takes the role's permissions.

Resource-based policy

The principal keeps its own permissions. Supported by S3 buckets, SNS topics, SQS queues, and more.

Example: a user in account A scans a DynamoDB table in account A and writes the dump to an S3 bucket in account B. With a role, they would lose access to the table. A bucket policy lets them keep both.

AWS Solutions Architect Associate · Domain 1 065
Intellectual Point Amazon Web Services
Advanced identity

Amazon EventBridge: Security

  • When a rule runs, it needs permissions on the target
  • Resource-based policy
    • Lambda, SNS, SQS, S3 buckets, API Gateway...
  • IAM role
    • EC2 Auto Scaling, Systems Manager Run Command, ECS tasks...
EventBridgeruleLambdaResource-based policy: allow EventBridgeEventBridgeruleEC2 Auto ScalingIAM role
AWS Solutions Architect Associate · Domain 1 066
Intellectual Point Amazon Web Services
Advanced identity

IAM Permission Boundaries

  • Supported for users and roles, not groups
  • A managed policy that sets the maximum permissions an IAM entity can get

Permission boundary

{
  "Effect": "Allow",
  "Action": [
    "s3:*",
    "cloudwatch:*",
    "ec2:*"
  ],
  "Resource": "*"
}

+

IAM policy

{
  "Effect": "Allow",
  "Action": "iam:CreateUser",
  "Resource": "*"
}

=

No permissions

iam:CreateUser is outside the boundary

AWS Solutions Architect Associate · Domain 1 067
Intellectual Point Amazon Web Services
Advanced identity

Permission Boundaries: Use Cases

  • Combine with AWS Organizations SCPs
  • Delegate work to non-admins within boundaries, such as creating IAM users
  • Let developers self-assign policies without escalating their privileges
  • Restrict one user instead of a whole account
OrganizationsSCPPermissionsboundaryIdentity-basedpolicyEffective permissions = the overlap
AWS Solutions Architect Associate · Domain 1 068
Intellectual Point Amazon Web Services
Advanced identity

IAM Policy Evaluation Logic

Explicit denyanywhere?YesDenySCPs allowthe action?NoDenyResource-basedpolicy allows?YesAllowIdentity-basedpolicy allows?NoDenyPermissionboundary allows?NoDenySession policyallows?NoDenyEvery check passed: the request is allowed

docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html

AWS Solutions Architect Associate · Domain 1 069
Intellectual Point Amazon Web Services
Advanced identity

Example IAM Policy

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": "sqs:*",
      "Effect": "Deny",
      "Resource": "*"
    },
    {
      "Action": [
        "sqs:DeleteQueue"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}

No

Can you perform sqs:CreateQueue?

The explicit deny on sqs:* blocks it.

No

Can you perform sqs:DeleteQueue?

An explicit deny always beats an allow.

No

Can you perform ec2:DescribeInstances?

Nothing allows it, so it is implicitly denied.

AWS Solutions Architect Associate · Domain 1 070
Intellectual Point Amazon Web Services
Advanced identity

AWS IAM Identity Center

  • One login (single sign-on) for
    • AWS accounts in AWS Organizations
    • Business cloud apps (Salesforce, Box, Microsoft 365...)
    • SAML 2.0-enabled applications
    • EC2 Windows instances
  • Identity providers
    • Built-in identity store in IAM Identity Center
    • Third party: Active Directory (AD), OneLogin, Okta...

Successor to AWS Single Sign-On

One place to manage workforce access to every AWS account and business app.

AWS Solutions Architect Associate · Domain 1 071
Intellectual Point Amazon Web Services
Advanced identity

AWS IAM Identity Center: Login Flow

1 Sign in

Users sign in once to the AWS access portal.

2 Pick an account

The portal lists every account the user can reach.

3 Choose a role

A permission set opens the console with the right access.

AWS Solutions Architect Associate · Domain 1 072
Intellectual Point Amazon Web Services
Advanced identity

AWS IAM Identity Center: How It Fits

AWS IAM Identity CenterAWS CloudBusiness cloud appsCustom SAML 2.0 appsBrowserloginPermission setsSSOOrganizationEC2 WindowsBox · SlackMicrosoft 365 · Dropboxstore / retrieve identitiesActive DirectoryBuilt-in identity store
AWS Solutions Architect Associate · Domain 1 073
Intellectual Point Amazon Web Services
Advanced identity

IAM Identity Center: Permission Sets

AWS OrganizationOU (Development)OU (Production)IAM Identity Center (management account)Group: DevelopersManagement accountDev account ADev account BProd account AProd account B Bob AlicePermission setReadOnlyAccessPermission setFullAccessassign
AWS Solutions Architect Associate · Domain 1 074
Intellectual Point Amazon Web Services
Advanced identity

Identity Center: Fine-Grained Permissions

Multi-account permissions

  • Manage access across accounts in your organization
  • Permission sets: one or more IAM policies assigned to users and groups

Application assignments

  • SSO to many SAML 2.0 business apps (Salesforce, Box, Microsoft 365...)
  • Provide the required URLs, certificates, and metadata

Attribute-based access control

  • Permissions based on user attributes (cost center, title, locale...)
  • Define permissions once, then change access by changing attributes
AWS Solutions Architect Associate · Domain 1 075
Intellectual Point Amazon Web Services
Advanced identity

What is Microsoft Active Directory (AD)?

  • Found on any Windows Server with AD Domain Services
  • A database of objects: users, computers, printers, file shares, security groups
  • Centralized security management: create accounts, assign permissions
  • Objects are organized in trees. A group of trees is a forest
Domain controllerComputerComputer John Printer
AWS Solutions Architect Associate · Domain 1 076
Intellectual Point Amazon Web Services
Advanced identity

AWS Directory Services

AWS Managed Microsoft AD

  • Create your own AD in AWS and manage users locally
  • Supports MFA
  • Set up trust with your on-premises AD

AD Connector

  • Directory gateway (proxy) to your on-premises AD
  • Supports MFA
  • Users stay managed on-premises

Simple AD

  • AD-compatible managed directory on AWS
  • Cannot join an on-premises AD
AWS Solutions Architect Associate · Domain 1 077
Intellectual Point Amazon Web Services
Advanced identity

IAM Identity Center: Active Directory Setup

  • Connect to AWS Managed Microsoft AD: works out of the box
  • Self-managed directory: a two-way trust with AWS Managed Microsoft AD, or an AD Connector
AWS Managed Microsoft ADIAM Identity CenterconnectAWS Managed MS ADSelf-managed directoryIAM Identity CenterconnectAWS Managed MS ADtwo-way trustAD ConnectorproxyOn-premises AD
AWS Solutions Architect Associate · Domain 1 078
Intellectual Point Amazon Web Services
Advanced identity

AWS Control Tower

  • Set up and govern a secure, compliant multi-account environment based on best practices
  • Uses AWS Organizations to create accounts

Benefits

  • Set up your environment in a few clicks
  • Automate policy management with guardrails
  • Detect policy violations and remediate them
  • Monitor compliance in an interactive dashboard
AWS Solutions Architect Associate · Domain 1 079
Intellectual Point Amazon Web Services
Advanced identity

AWS Control Tower: Guardrails

Ongoing governance for every account in your Control Tower environment

Uses SCPs

Preventive guardrail

Example: restrict Regions across all accounts

Uses AWS Config

Detective guardrail

Example: find untagged resources

Control TowerDetective guardrailAWS Configmonitor untaggedMember accountsNON_COMPLIANTSNSnotify AdmininvokeLambda adds tags
AWS Solutions Architect Associate · Domain 1 080
Intellectual Point Amazon Web Services
Section 5

AWS Security and Encryption

KMS, Parameter Store, Secrets Manager, ACM, CloudHSM, WAF, Shield, GuardDuty, Inspector, and Macie

AWS Solutions Architect Associate · Domain 1 081
Intellectual Point Amazon Web Services
Security and encryption

Why Encryption? Encryption in Flight (TLS/SSL)

  • Data is encrypted before sending and decrypted after receiving
  • TLS certificates enable encryption (HTTPS)
  • Encryption in flight prevents man-in-the-middle (MITM) attacks
ClientUsername: adminPassword: supersecretTLS encryptionaGVsbG8gd29ybGQ...TLS decryptionHTTPS website
AWS Solutions Architect Associate · Domain 1 082
Intellectual Point Amazon Web Services
Security and encryption

Why Encryption? Server-Side Encryption at Rest

  • Data is encrypted after the server receives it and decrypted before it is sent
  • It is stored encrypted with a key, usually a data key
  • Keys must be managed somewhere, and the server must have access to them
AWS service (e.g., S3)ObjectHTTP(S)Data key+EncryptionStored encryptedDecryption+HTTP(S)Object
AWS Solutions Architect Associate · Domain 1 083
Intellectual Point Amazon Web Services
Security and encryption

Why Encryption? Client-Side Encryption

  • Data is encrypted by the client and never decrypted by the server
  • A receiving client decrypts it. The server should not be able to
  • Can use envelope encryption
ClientAny storage serviceObject+Data keyEncryptObjectDecryptstoreretrieveFTP, S3, ...Server never decrypts
AWS Solutions Architect Associate · Domain 1 084
Intellectual Point Amazon Web Services
Security and encryption

AWS KMS (Key Management Service)

  • "Encryption" on an AWS service almost always means KMS
  • AWS manages the encryption keys for you
  • Fully integrated with IAM for authorization
  • Audit key usage with CloudTrail
  • Built into most services: EBS, S3, RDS, SSM...

Never store secrets in plaintext, especially in your code.

Use KMS through the API

  • Encrypt with the SDK or CLI
  • Store encrypted secrets in code or environment variables
AWS Solutions Architect Associate · Domain 1 085
Intellectual Point Amazon Web Services
Security and encryption

KMS Key Types

KMS keys are the new name for KMS customer master keys (CMK).

AES-256

Symmetric

  • One key encrypts and decrypts
  • AWS services integrated with KMS use symmetric keys
  • You never see the key unencrypted. Call the KMS API to use it

RSA and ECC key pairs

Asymmetric

  • Public key encrypts, private key decrypts
  • Encrypt/decrypt or sign/verify
  • Public key is downloadable. The private key never leaves KMS unencrypted
  • Use case: encryption outside AWS by users who can't call the KMS API
AWS Solutions Architect Associate · Domain 1 086
Intellectual Point Amazon Web Services
Security and encryption

KMS Key Ownership, Cost, and Rotation

Key type
Cost
AWS owned
Free. SSE-S3, SSE-SQS, SSE-DDB default keys
AWS managed
Free. aws/service-name, such as aws/rds
Customer managed, created in KMS
$1 / month
Customer managed, imported
$1 / month
API calls
$0.03 per 10,000 calls

Automatic rotation

  • AWS managed key: automatic, every year
  • Customer managed key: enable it. Automatic and on demand
  • Imported key: manual only, using an alias
AWS Solutions Architect Associate · Domain 1 087
Intellectual Point Amazon Web Services
Security and encryption

Copying Snapshots Across Regions

Region eu-west-2Region ap-southeast-2EBS volumeencrypted with KMS key AEBS snapshotencrypted with KMS key AKMS key AEBS volumeencrypted with KMS key BEBS snapshotencrypted with KMS key BKMS key BKMS ReEncrypt with key B
AWS Solutions Architect Associate · Domain 1 088
Intellectual Point Amazon Web Services
Security and encryption

KMS Key Policies

  • Control access to KMS keys, much like S3 bucket policies
  • The difference: without a key policy, nobody can access the key

Default key policy

  • Created when you don't provide one
  • Gives the root user, meaning the entire account, complete access

Custom key policy

  • Define the users and roles that can use the key
  • Define who can administer it
  • Useful for cross-account access
AWS Solutions Architect Associate · Domain 1 089
Intellectual Point Amazon Web Services
Security and encryption

Copying Snapshots Across Accounts

1

Create a snapshot encrypted with your customer managed key

2

Attach a key policy that allows cross-account access

3

Share the encrypted snapshot

4

In the target account, copy the snapshot and encrypt it with a key there

5

Create a volume from the snapshot

KMS key policy
{
  "Sid": "AllowUseByDestinationAccount",
  "Effect": "Allow",
  "Principal": {
    "AWS": "arn:aws:iam::TARGET-ACCOUNT-ID:role/ROLENAME"
  },
  "Action": ["kms:Decrypt", "kms:CreateGrant"],
  "Resource": "*",
  "Condition": {
    "StringEquals": {
      "kms:ViaService": "ec2.REGION.amazonaws.com",
      "kms:CallerAccount": "TARGET-ACCOUNT-ID"
    }
  }
}
AWS Solutions Architect Associate · Domain 1 090
Intellectual Point Amazon Web Services
Security and encryption

KMS Multi-Region Keys

AWS KMSPrimary keyus-east-1Replica key · us-west-2arn:aws:kms:us-west-2:111122223333:key/mrk-1234abcd...syncReplica key · eu-west-1arn:aws:kms:eu-west-1:111122223333:key/mrk-1234abcd...Replica key · ap-southeast-2arn:aws:kms:ap-southeast-2:111122223333:key/mrk-1234abcd...key/mrk-1234abcd...
AWS Solutions Architect Associate · Domain 1 091
Intellectual Point Amazon Web Services
Security and encryption

KMS Multi-Region Keys: How They Work

  • Identical KMS keys in different Regions, usable interchangeably
  • Same key ID, key material, automatic rotation...
  • Encrypt in one Region, decrypt in another, with no re-encryption or cross-Region calls
  • Not global: one primary plus replicas
  • Each multi-Region key is managed independently
  • Use cases: global client-side encryption, DynamoDB global tables, Global Aurora
AWS Solutions Architect Associate · Domain 1 092
Intellectual Point Amazon Web Services
Security and encryption

Multi-Region Keys with Global Databases

  • Encrypt specific attributes client-side with the DynamoDB Encryption Client or the AWS Encryption SDK (Aurora)
  • Global Tables / Global Aurora replicate the encrypted data to other Regions
  • A replica key in each Region gives clients low-latency KMS calls to decrypt locally
  • Protects specific fields, even from database admins
us-east-1ap-southeast-2Client appTablePrimary MRK1 Encrypt attribute (SSN)2 Put encrypted attributeClient appTableReplica MRK4 Get encrypted attribute5 Decrypt with replica MRK3 Global replication
AWS Solutions Architect Associate · Domain 1 093
Intellectual Point Amazon Web Services
Security and encryption

S3 Replication: Encryption Considerations

Replicated by default

Unencrypted objects and objects encrypted with SSE-S3

Can be replicated

Objects encrypted with SSE-C (customer-provided key)

SSE-KMS: enable the option

  • Choose the target KMS key and adapt its policy
  • IAM role with kms:Decrypt (source) and kms:Encrypt (target)
  • Throttled? Request a quota increase

Multi-Region KMS keys work, but S3 treats them as independent keys: objects are still decrypted and re-encrypted.

AWS Solutions Architect Associate · Domain 1 094
Intellectual Point Amazon Web Services
Security and encryption

AMI Sharing Encrypted via KMS

1

The AMI in the source account is encrypted with a KMS key from that account

2

Modify the image attribute: add a launch permission for the target account

3

Share the KMS key used for the AMI's snapshots with the target account or role

4

The target role or user needs DescribeKey, ReEncrypt*, CreateGrant, Decrypt

5

At launch, the target can re-encrypt the volumes with its own KMS key

Account AAccount BAMIKMS keyAMIEC2 instancesharesharelaunch
AWS Solutions Architect Associate · Domain 1 095
Intellectual Point Amazon Web Services
Security and encryption

SSM Parameter Store

  • Secure storage for configuration and secrets
  • Optional seamless encryption with KMS
  • Serverless, scalable, durable, easy SDK
  • Version tracking of configurations and secrets
  • Security through IAM. Notifications with EventBridge
  • Integrates with CloudFormation
ApplicationsParameter Storeplaintext configencrypted configCheck IAMpermissionsAWS KMSdecryption
AWS Solutions Architect Associate · Domain 1 096
Intellectual Point Amazon Web Services
Security and encryption

SSM Parameter Store Hierarchy

/my-department/my-app/dev/db-urldb-passwordprod/db-urldb-passwordother-app//other-department/Dev LambdaProd LambdaGetParameters orGetParametersByPath

Organize parameters in paths. Some paths are special:

  • /aws/reference/secretsmanager/<secret_ID> reads a Secrets Manager secret
  • /aws/service/ami-amazon-linux-latest/... returns the latest public AMI
AWS Solutions Architect Associate · Domain 1 097
Intellectual Point Amazon Web Services
Security and encryption

Standard and Advanced Parameter Tiers

Standard
Advanced
Parameters per account and Region
10,000
100,000
Maximum value size
4 KB
8 KB
Parameter policies
No
Yes
Cost
No additional charge
Charges apply
Storage pricing
Free
$0.05 per advanced parameter per month
AWS Solutions Architect Associate · Domain 1 098
Intellectual Point Amazon Web Services
Security and encryption

Parameter Policies (Advanced Parameters)

  • Assign a TTL (expiration date) to force updating or deleting sensitive data such as passwords
  • Assign multiple policies at once

Expiration: delete the parameter

{
  "Type": "Expiration",
  "Version": "1.0",
  "Attributes": {
    "Timestamp": "2020-12-02T21:34:33Z"
  }
}

ExpirationNotification (EventBridge)

{
  "Type": "ExpirationNotification",
  "Version": "1.0",
  "Attributes": {
    "Before": "15",
    "Unit": "Days"
  }
}

NoChangeNotification (EventBridge)

{
  "Type": "NoChangeNotification",
  "Version": "1.0",
  "Attributes": {
    "After": "20",
    "Unit": "Days"
  }
}
AWS Solutions Architect Associate · Domain 1 099
Intellectual Point Amazon Web Services
Security and encryption

AWS Secrets Manager

  • A newer service, built for storing secrets
  • Force rotation of secrets every X days
  • Generate secrets automatically on rotation (uses Lambda)
  • Integrates with Amazon RDS (MySQL, PostgreSQL, Aurora)
  • Secrets are encrypted with KMS

Mostly meant for RDS integration.

AWS Solutions Architect Associate · Domain 1 100
Intellectual Point Amazon Web Services
Security and encryption

Secrets Manager: Multi-Region Secrets

  • Replicate secrets across Regions. Read replicas stay in sync with the primary
  • Promote a read replica to a standalone secret
  • Use cases: multi-Region apps, disaster recovery, multi-Region databases
us-east-1 (primary)us-west-2 (secondary)Secrets ManagerMySecret-AprimarySecrets ManagerMySecret-Areplicareplicate
AWS Solutions Architect Associate · Domain 1 101
Intellectual Point Amazon Web Services
Security and encryption

AWS Certificate Manager (ACM)

  • Provision, manage, and deploy TLS certificates
  • In-flight encryption for websites (HTTPS)
  • Public and private certificates. Public ones are free
  • Automatic renewal
  • Load certificates on
    • Elastic Load Balancers (CLB, ALB, NLB)
    • CloudFront distributions
    • APIs on API Gateway
Auto Scaling groupUsersHTTPSLoad balancerACMprovisions andmaintains TLS certsHTTPEC2 instanceEC2 instance
AWS Solutions Architect Associate · Domain 1 102
Intellectual Point Amazon Web Services
Security and encryption

ACM: Requesting Public Certificates

1

List the domain names

FQDN such as corp.example.com, or a wildcard such as *.example.com

2

Choose a validation method

DNS validation (preferred for automation, a CNAME record in Route 53) or email validation (WHOIS contacts)

3

Wait a few hours for verification

4

The certificate is enrolled for automatic renewal

ACM renews its own certificates 60 days before expiry

AWS Solutions Architect Associate · Domain 1 103
Intellectual Point Amazon Web Services
Security and encryption

ACM: Importing Public Certificates

  • Generate a certificate outside ACM, then import it
  • No automatic renewal: import a new one before expiry
  • ACM sends daily expiration events to EventBridge, starting 45 days before (configurable)
  • AWS Config managed rule acm-certificate-expiration-check flags expiring certificates
ACMdaily expiry eventsAWS Configexpiration checknon-complianceEventBridgeLambdaSNSSQS
AWS Solutions Architect Associate · Domain 1 104
Intellectual Point Amazon Web Services
Security and encryption

ACM: Integration with ALB

Auto Scaling groupUsersHTTPredirect to HTTPSHTTPSApplication Load BalancerHTTP to HTTPS redirect ruleACM provisions and maintains TLS certsHTTPEC2 instanceEC2 instance
AWS Solutions Architect Associate · Domain 1 105
Intellectual Point Amazon Web Services
Security and encryption

API Gateway: Endpoint Types

Default · global clients

Edge-optimized

  • Requests route through CloudFront edge locations
  • The API still lives in one Region

Clients in the same Region

Regional

  • Can be combined with your own CloudFront distribution for more caching control

Inside your VPC

Private

  • Reachable only through an interface VPC endpoint (ENI)
  • A resource policy defines access
AWS Solutions Architect Associate · Domain 1 106
Intellectual Point Amazon Web Services
Security and encryption

ACM: Integration with API Gateway

Create a custom domain name in API Gateway.

Edge-optimized

  • TLS certificate in us-east-1, with CloudFront

Regional

  • Certificate in the same Region as the API stage

Then point a CNAME or, better, an A-Alias record in Route 53 at it.

us-east-1 · Edge-optimizedap-southeast-2 · RegionalAPI GatewayCloudFrontACMcertificateAPI GatewayACMcertificate
AWS Solutions Architect Associate · Domain 1 107
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM

  • KMS: AWS manages the software. CloudHSM: AWS provisions the hardware
  • Dedicated Hardware Security Module. You manage the keys entirely
  • Tamper resistant, FIPS 140-2 Level 3
  • Symmetric and asymmetric encryption (SSL/TLS keys)
  • No free tier
  • Requires the CloudHSM client software
  • Redshift supports CloudHSM for database encryption
  • A good fit with SSE-C
AWS Solutions Architect Associate · Domain 1 108
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM: Who Manages What

CloudHSM clientSSL connectionAWS CloudHSMAWS manages the hardwareYou manage the keys

IAM permissions cover creating, reading, updating, and deleting an HSM cluster. The CloudHSM software manages the keys and the users.

AWS Solutions Architect Associate · Domain 1 109
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM: High Availability

  • CloudHSM clusters span multiple AZs
  • Great for availability and durability
Availability Zone 1Availability Zone 2CloudHSM clientCloudHSM 1CloudHSM 2
AWS Solutions Architect Associate · Domain 1 110
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM: Integration with AWS Services

  • Integrates through AWS KMS
  • Configure a KMS custom key store backed by CloudHSM
  • Works with EBS, S3, RDS...
RDS DB instanceEBS volumeAWS KMScustom key storeKMS encryptionCloudHSMCloudTrailkey usage logs
AWS Solutions Architect Associate · Domain 1 111
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM vs. KMS (1/2)

Feature
AWS KMS
AWS CloudHSM
Tenancy
Multi-tenant
Single-tenant
Standard
FIPS 140-2 Level 3
FIPS 140-2 Level 3
Master keys
AWS owned, AWS managed, customer managed
Customer managed
Key types
Symmetric, asymmetric, digital signing
Symmetric, asymmetric, digital signing and hashing
Key accessibility
Multiple Regions (keys can't leave their Region)
Deployed in a VPC. Shareable across VPCs with peering
AWS Solutions Architect Associate · Domain 1 112
Intellectual Point Amazon Web Services
Security and encryption

CloudHSM vs. KMS (2/2)

Feature
AWS KMS
AWS CloudHSM
Cryptographic acceleration
None
SSL/TLS acceleration, Oracle TDE acceleration
Access and authentication
AWS IAM
You create users and manage their permissions
High availability
AWS managed service
Add HSMs across AZs
Audit
CloudTrail, CloudWatch
CloudTrail, CloudWatch, MFA support
Free tier
Yes
No
AWS Solutions Architect Associate · Domain 1 113
Intellectual Point Amazon Web Services
Security and encryption

AWS WAF: Web Application Firewall

  • Protects web apps from common exploits at Layer 7
  • Layer 7 is HTTP. Layer 4 is TCP/UDP

Deploy on

  • Application Load Balancer
  • API Gateway
  • CloudFront
  • AppSync GraphQL API
  • Cognito user pool
AWS Solutions Architect Associate · Domain 1 114
Intellectual Point Amazon Web Services
Security and encryption

AWS WAF: Web ACL Rules

  • IP set: up to 10,000 IP addresses. Use more rules for more IPs
  • Match headers, body, or URI: blocks SQL injection and cross-site scripting (XSS)
  • Size constraints and geo-match (block countries)
  • Rate-based rules count events, for DDoS protection

Web ACLs are Regional, except for CloudFront.

A rule group is a reusable set of rules you add to a web ACL.

AWS Solutions Architect Associate · Domain 1 115
Intellectual Point Amazon Web Services
Security and encryption

WAF: Fixed IP with a Load Balancer

  • WAF does not support the Network Load Balancer (Layer 4)
  • Use Global Accelerator for a fixed IP and WAF on the ALB
us-east-1UsersGlobal Acceleratorfixed IPv4: 1.2.3.4Application Load BalancerWebACL (same Region as the ALB)EC2 instances
AWS Solutions Architect Associate · Domain 1 116
Intellectual Point Amazon Web Services
Security and encryption

AWS Shield: Protect from DDoS Attacks

DDoS: Distributed Denial of Service, many requests at the same time.

Free · on for every customer

Shield Standard

  • Protects against SYN/UDP floods, reflection attacks, and other Layer 3/4 attacks

$3,000 per month per organization

Shield Advanced

  • Sophisticated attacks on EC2, ELB, CloudFront, Global Accelerator, Route 53
  • 24/7 access to the AWS DDoS response team
  • Protection against higher fees from DDoS usage spikes
  • Automatically creates and deploys WAF rules for Layer 7 attacks
AWS Solutions Architect Associate · Domain 1 117
Intellectual Point Amazon Web Services
Security and encryption

AWS Firewall Manager

  • Manage rules in all accounts of an AWS Organization
  • Rules apply to new resources as they are created, across all current and future accounts
  • Policies are created per Region

Security policy: a common set of rules

  • WAF rules (ALB, API Gateway, CloudFront)
  • Shield Advanced (ALB, CLB, NLB, Elastic IP, CloudFront)
  • Security groups for EC2, ALB, and ENIs in a VPC
  • AWS Network Firewall (VPC level)
  • Route 53 Resolver DNS Firewall
AWS Solutions Architect Associate · Domain 1 118
Intellectual Point Amazon Web Services
Security and encryption

WAF vs. Firewall Manager vs. Shield

AWS WAF

Define your web ACL rules. For granular protection of individual resources, WAF alone is the right choice.

AWS Firewall Manager

Use WAF across accounts, speed up configuration, and protect new resources automatically.

AWS Shield Advanced

Adds the Shield Response Team and advanced reporting on top of WAF. Worth it if you face frequent DDoS attacks.

They work together for comprehensive protection.

AWS Solutions Architect Associate · Domain 1 119
Intellectual Point Amazon Web Services
Security and encryption

DDoS Resiliency: Reference Architecture

AWS CloudAWS edge servicesRegionVPC Public subnet Private subnetAuto Scaling groupCorporate data centerBP8BP5BP7UsersGlobal AcceleratorBP1Route 53BP3AWS WAFBP2CloudFrontBP1AWS WAFBP2Load BalancingBP6API GatewayBP4EC2 instancesTransit GatewayCustomer gatewayInternetDX / VPN
AWS Solutions Architect Associate · Domain 1 120
Intellectual Point Amazon Web Services
Security and encryption

DDoS Resiliency: Edge Location Mitigation

BP1

CloudFront

  • Web application delivery at the edge
  • Protects from common attacks (SYN floods, UDP reflection)

BP1

Global Accelerator

  • Access your application from the edge
  • Integrates with Shield
  • Helpful when the backend isn't compatible with CloudFront

BP3

Route 53

  • Domain name resolution at the edge
  • Built-in DDoS protection
AWS Solutions Architect Associate · Domain 1 121
Intellectual Point Amazon Web Services
Security and encryption

DDoS Resiliency: Mitigation Best Practices

BP1, BP3, BP6

Infrastructure layer defense

  • Protect EC2 against high traffic
  • Use Global Accelerator, Route 53, CloudFront, Elastic Load Balancing

BP7

EC2 with Auto Scaling

  • Scale for sudden surges, including flash crowds or a DDoS attack

BP6

Elastic Load Balancing

  • Scales with traffic and spreads it across many EC2 instances
AWS Solutions Architect Associate · Domain 1 122
Intellectual Point Amazon Web Services
Security and encryption

DDoS Resiliency: Application Layer Defense

BP1, BP2

Detect and filter malicious requests

  • CloudFront caches static content at the edge, protecting the backend
  • WAF on CloudFront and ALB filters requests by signature
  • WAF rate-based rules block bad actors' IPs automatically
  • Managed WAF rules block by IP reputation or anonymous IPs
  • CloudFront can block specific geographies

BP1, BP2, BP6

Shield Advanced

  • Automatic application layer mitigation creates, evaluates, and deploys WAF rules for Layer 7 attacks
AWS Solutions Architect Associate · Domain 1 123
Intellectual Point Amazon Web Services
Security and encryption

DDoS Resiliency: Attack Surface Reduction

BP1, BP4, BP6

Obfuscate AWS resources

  • CloudFront, API Gateway, and load balancers hide your backend (Lambda, EC2)

BP5

Security groups and NACLs

  • Filter traffic by IP at the subnet or ENI level
  • Elastic IPs are protected by Shield Advanced

BP4

Protect API endpoints

  • Hide EC2 and Lambda behind API Gateway
  • Edge-optimized mode, or CloudFront + Regional mode
  • WAF + API Gateway: burst limits, header filtering, API keys
AWS Solutions Architect Associate · Domain 1 124
Intellectual Point Amazon Web Services
Security and encryption

Amazon GuardDuty

  • Intelligent threat discovery for your AWS account
  • Machine learning, anomaly detection, third-party data
  • One click to enable (30-day trial). No software to install
  • EventBridge rules notify you of findings, targeting Lambda or SNS
  • A dedicated finding for cryptocurrency attacks

Input data

  • CloudTrail logs: unusual API calls, unauthorized deployments (management and S3 data events)
  • VPC Flow Logs: unusual internal traffic or IPs
  • DNS logs: compromised EC2 instances sending encoded data in DNS queries
  • Optional: EKS audit logs, RDS and Aurora, EBS, Lambda, S3 data events
AWS Solutions Architect Associate · Domain 1 125
Intellectual Point Amazon Web Services
Security and encryption

Amazon GuardDuty: How It Works

Optional featuresVPC Flow LogsCloudTrail logsDNS logsEKS audit logs · RDS and AuroraEBS volumes · Lambda · S3 data eventsGuardDutyfindingsEventBridgeSNSLambda
AWS Solutions Architect Associate · Domain 1 126
Intellectual Point Amazon Web Services
Security and encryption

Amazon Inspector

Automated security assessments for:

  • EC2 instances: uses the SSM agent. Checks network accessibility and the running OS for known vulnerabilities
  • Container images in ECR: assessed as they are pushed
  • Lambda functions: code and package dependencies, assessed as they deploy

Reports to Security Hub and sends findings to EventBridge.

EC2 + SSM agentECR container imageLambda functionInspectorSecurity HubEventBridge
AWS Solutions Architect Associate · Domain 1 127
Intellectual Point Amazon Web Services
Security and encryption

What Does Amazon Inspector Evaluate?

  • Only EC2 instances, container images, and Lambda functions
  • Continuous scanning, only when needed
  • Package vulnerabilities (EC2, ECR, Lambda) against the CVE database
  • Network reachability (EC2)
  • A risk score on every vulnerability for prioritization

Remember

Inspector is for EC2, container images, and Lambda only.

AWS Solutions Architect Associate · Domain 1 128
Intellectual Point Amazon Web Services
Security and encryption

Amazon Macie

  • A fully managed data security and privacy service
  • Uses machine learning and pattern matching to discover and protect sensitive data
  • Identifies and alerts you to sensitive data such as personally identifiable information (PII)
S3 bucketsanalyzeMaciediscovers sensitive data (PII)notifyEventBridge Integrations
AWS Solutions Architect Associate · Domain 1 129
Intellectual Point Amazon Web Services
Section 6

Amazon VPC

Subnets, gateways, NAT, NACLs, peering, endpoints, VPN, Direct Connect, and Transit Gateway

AWS Solutions Architect Associate · Domain 1 130
Intellectual Point Amazon Web Services
Amazon VPC

VPC Components Overview

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupCorporate DCInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peeringVPCendpointS3DynamoDBFlowlogsCloudWatchServerVPNgatewayCustomergatewayS2S VPNDirect Connect
AWS Solutions Architect Associate · Domain 1 131
Intellectual Point Amazon Web Services
Amazon VPC

Understanding CIDR: IPv4

  • Classless Inter-Domain Routing: a method for allocating IP addresses
  • Used in security group rules and AWS networking in general
  • CIDRs define an IP address range
    • WW.XX.YY.ZZ/32 is one IP
    • 0.0.0.0/0 is all IPs
    • 192.168.0.0/26 is 192.168.0.0 to 192.168.0.63 (64 addresses)
IP version
Type
Protocol
Port range
Source
IPv4
SSH
TCP
22
122.149.196.85/32
IPv4
HTTP
TCP
80
0.0.0.0/0
AWS Solutions Architect Associate · Domain 1 132
Intellectual Point Amazon Web Services
Amazon VPC

Understanding CIDR: Two Components

Base IP

  • An IP contained in the range (XX.XX.XX.XX)
  • Examples: 10.0.0.0, 192.168.0.0

Subnet mask

  • How many bits can change in the IP
  • Examples: /0, /24, /32
  • Two forms: /8 = 255.0.0.0, /16 = 255.255.0.0, /24 = 255.255.255.0, /32 = 255.255.255.255
AWS Solutions Architect Associate · Domain 1 133
Intellectual Point Amazon Web Services
Amazon VPC

Understanding CIDR: Subnet Mask

Mask
IPs
Range
/32
1
192.168.0.0
/31
2
192.168.0.0 - .0.1
/30
4
192.168.0.0 - .0.3
/29
8
192.168.0.0 - .0.7
/28
16
192.168.0.0 - .0.15
/27
32
192.168.0.0 - .0.31
Mask
IPs
Range
/26
64
192.168.0.0 - .0.63
/25
128
192.168.0.0 - .0.127
/24
256
192.168.0.0 - .0.255
/16
65,536
192.168.0.0 - .255.255
/0
All
0.0.0.0 - 255.255.255.255

Quick memo

  • /32: no octet changes
  • /24: last octet changes
  • /16: last 2 octets
  • /8: last 3 octets
  • /0: all octets
AWS Solutions Architect Associate · Domain 1 134
Intellectual Point Amazon Web Services
Amazon VPC

Understanding CIDR: Quick Exercise

192.168.0.0/24

192.168.0.0 to 192.168.0.255 (256 IPs)

192.168.0.0/16

192.168.0.0 to 192.168.255.255 (65,536 IPs)

134.56.78.123/32

Just 134.56.78.123

0.0.0.0/0

All IPs

When in doubt, use ipaddressguide.com/cidr.

AWS Solutions Architect Associate · Domain 1 135
Intellectual Point Amazon Web Services
Amazon VPC

Public vs. Private IP (IPv4)

The Internet Assigned Numbers Authority (IANA) set aside blocks of IPv4 addresses for private (LAN) use. Everything else on the internet is public.

Private range
CIDR
Typical use
10.0.0.0 - 10.255.255.255
10.0.0.0/8
Big networks
172.16.0.0 - 172.31.255.255
172.16.0.0/12
The AWS default VPC
192.168.0.0 - 192.168.255.255
192.168.0.0/16
Home networks
AWS Solutions Architect Associate · Domain 1 136
Intellectual Point Amazon Web Services
Amazon VPC

Default VPC Walkthrough

  • Every new AWS account has a default VPC
  • New EC2 instances launch into it when no subnet is specified
  • It has internet connectivity, and every instance in it gets a public IPv4 address
  • Instances also get a public and a private IPv4 DNS name
RegionDefault VPC 172.31.0.0/16 Public subnet Public subnet Public subnetInternet gateway172.31.0.0/20Public IPv4AZ a172.31.16.0/20Public IPv4AZ b172.31.32.0/20Public IPv4AZ cMain route table: 0.0.0.0/0 to the internet gateway
AWS Solutions Architect Associate · Domain 1 137
Intellectual Point Amazon Web Services
Amazon VPC

VPC in AWS: IPv4

  • VPC = Virtual Private Cloud
  • Up to 5 VPCs per Region (soft limit)
  • Up to 5 CIDRs per VPC. For each CIDR
    • Minimum /28 (16 IPs)
    • Maximum /16 (65,536 IPs)
  • Your VPC CIDR must not overlap your other networks, such as corporate

Private ranges only

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16
AWS Solutions Architect Associate · Domain 1 138
Intellectual Point Amazon Web Services
Amazon VPC

Hands-On: Start with a VPC

RegionVPC

We start with an empty VPC in a Region.

AWS Solutions Architect Associate · Domain 1 139
Intellectual Point Amazon Web Services
Amazon VPC

Hands-On: Add Subnets

RegionVPCAvailability Zone Public subnet Private subnet

Add a public and a private subnet in one Availability Zone.

AWS Solutions Architect Associate · Domain 1 140
Intellectual Point Amazon Web Services
Amazon VPC

VPC: Subnet (IPv4)

AWS reserves 5 IP addresses in every subnet: the first 4 and the last 1. For 10.0.0.0/24:

10.0.0.0
Network address
10.0.0.1
VPC router
10.0.0.2
Amazon-provided DNS
10.0.0.3
Reserved for future use
10.0.0.255
Broadcast address (unsupported, so reserved)

Exam tip: you need 29 IPs

  • /27 gives 32 - 5 = 27. Too few
  • /26 gives 64 - 5 = 59. Choose this
AWS Solutions Architect Associate · Domain 1 141
Intellectual Point Amazon Web Services
Amazon VPC

Internet Gateway (IGW)

  • Lets resources in a VPC, such as EC2 instances, connect to the internet
  • Scales horizontally. Highly available and redundant
  • Created separately from a VPC
  • One VPC attaches to one IGW, and vice versa
VPC Public subnetInternetInternet gateway0.0.0.0/0 to igw

An IGW alone does not give internet access. You must also edit the route tables.

AWS Solutions Architect Associate · Domain 1 142
Intellectual Point Amazon Web Services
Amazon VPC

Hands-On: Add an Internet Gateway

RegionVPCAvailability Zone Public subnet Private subnetInternetgateway

Attach an internet gateway to the VPC.

AWS Solutions Architect Associate · Domain 1 143
Intellectual Point Amazon Web Services
Amazon VPC

Hands-On: Edit Route Tables

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2

Route the public subnet to the internet gateway, then launch a public instance.

AWS Solutions Architect Associate · Domain 1 144
Intellectual Point Amazon Web Services
Amazon VPC

Bastion Hosts

  • SSH into private EC2 instances through a bastion host
  • The bastion sits in the public subnet, connected to all private subnets
  • Bastion SG: allow inbound port 22 from a restricted CIDR, such as your corporate public CIDR
  • Private instances' SG: allow the bastion's SG or its private IP
VPC Public subnetBastionHost-SG Private subnetLinuxInstance-SGUsersBastion hostSSHSSH
AWS Solutions Architect Associate · Domain 1 145
Intellectual Point Amazon Web Services
Amazon VPC

NAT Instance (Outdated, Still on the Exam)

  • NAT = Network Address Translation
  • Lets instances in private subnets reach the internet
  • Launch it in a public subnet
  • Disable the EC2 source / destination check
  • Attach an Elastic IP
  • Route private subnets' traffic to the NAT instance
VPC Public subnetNATInstance-SG Private subnetServer 50.60.4.10NAT instanceEIP 12.34.56.7810.0.0.1010.0.0.20src 10.0.0.20dst 50.60.4.10src 12.34.56.78dst 50.60.4.10
AWS Solutions Architect Associate · Domain 1 146
Intellectual Point Amazon Web Services
Amazon VPC

NAT Instance in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT instanceRoute tablePrivate EC2

Private instances reach the internet through the NAT instance in the public subnet.

AWS Solutions Architect Associate · Domain 1 147
Intellectual Point Amazon Web Services
Amazon VPC

NAT Instance: Comments

  • A pre-configured Amazon Linux AMI exists. Standard support ended December 31, 2020
  • Not highly available out of the box: build an ASG across AZs with a resilient user-data script
  • Internet bandwidth depends on the instance type

You manage the security groups

  • Inbound: HTTP / HTTPS from private subnets
  • Inbound: SSH from your home network (through the IGW)
  • Outbound: HTTP / HTTPS to the internet
AWS Solutions Architect Associate · Domain 1 148
Intellectual Point Amazon Web Services
Amazon VPC

NAT Gateway

  • AWS-managed NAT: higher bandwidth, high availability, no administration
  • Pay per hour and for bandwidth
  • Created in one AZ, with an Elastic IP
  • Can't be used by instances in the same subnet
  • Requires an IGW: private subnet → NAT gateway → IGW

5 Gbps

with automatic scaling up to 100 Gbps

No security groups

nothing to manage

AWS Solutions Architect Associate · Domain 1 149
Intellectual Point Amazon Web Services
Amazon VPC

NAT Gateway in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2

The NAT gateway lives in the public subnet and sends private traffic out through the IGW.

AWS Solutions Architect Associate · Domain 1 150
Intellectual Point Amazon Web Services
Amazon VPC

NAT Gateway with High Availability

  • A NAT gateway is resilient within one AZ
  • Create one per AZ for fault tolerance
  • No cross-AZ failover needed: if an AZ goes down, it doesn't need NAT
RegionVPCAZ A Public subnet Private subnetAZ B Public subnet Private subnetInternet gatewayNAT gatewayEC2NAT gatewayEC2
AWS Solutions Architect Associate · Domain 1 151
Intellectual Point Amazon Web Services
Amazon VPC

NAT Gateway vs. NAT Instance

NAT gateway
NAT instance
Availability
Highly available in its AZ (add one per AZ)
A script manages failover between instances
Bandwidth
Up to 100 Gbps
Depends on the instance type
Maintenance
Managed by AWS
Managed by you (software, OS patches...)
Cost
Per hour and per GB transferred
Per hour, instance type and size, plus network
Public and private IPv4
Yes
Yes
Security groups
No
Yes
Use as a bastion host?
No
Yes
AWS Solutions Architect Associate · Domain 1 152
Intellectual Point Amazon Web Services
Amazon VPC

Regional NAT Gateway (RNAT)

  • A highly available NAT gateway associated with the VPC
  • Has its own route tables
  • Shared across AZs: no per-AZ deployments
  • No public subnets needed to host it
  • Detects resources in a new AZ and expands to it
Destination
Target
10.0.0.0/16
local
0.0.0.0/0
igw-1234

RNAT route table

Destination
Target
10.0.0.0/16
local
0.0.0.0/0
nat-1234

Private subnet route table (AZ A and AZ B)

AWS Solutions Architect Associate · Domain 1 153
Intellectual Point Amazon Web Services
Amazon VPC

Security Groups & NACLs

Incoming requestClientNACL inboundrules · statelessSG inboundrules · statefulEC2SG outboundallowed automaticallyNACL outboundrules · statelessOutgoing requestEC2SG outboundrules · statefulNACL outboundrules · statelessServerNACL inboundrules · statelessSG inboundallowed automatically

NACLs check every packet in both directions. Security groups remember allowed connections, so the reply is allowed automatically.

AWS Solutions Architect Associate · Domain 1 154
Intellectual Point Amazon Web Services
Amazon VPC

Network Access Control List (NACL)

  • A firewall that controls traffic to and from subnets
  • One NACL per subnet. New subnets get the default NACL
  • Newly created NACLs deny everything
  • A great way to block a specific IP at the subnet level

NACL rules

  • Numbered 1 to 32766. Lower number wins
  • The first matching rule decides
  • #100 ALLOW 10.0.0.10/32 beats #200 DENY 10.0.0.10/32
  • The last rule, *, denies anything unmatched
  • AWS recommends steps of 100
AWS Solutions Architect Associate · Domain 1 155
Intellectual Point Amazon Web Services
Amazon VPC

NACLs in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACL

Each subnet gets a NACL that filters traffic at the subnet boundary.

AWS Solutions Architect Associate · Domain 1 156
Intellectual Point Amazon Web Services
Amazon VPC

Default NACL

Accepts everything inbound and outbound for its subnets. Don't modify it: create custom NACLs instead.

Inbound rules

Rule #
Type
Source
Allow/Deny
100
All IPv4 traffic
0.0.0.0/0
ALLOW
*
All IPv4 traffic
0.0.0.0/0
DENY

Outbound rules

Rule #
Type
Destination
Allow/Deny
100
All IPv4 traffic
0.0.0.0/0
ALLOW
*
All IPv4 traffic
0.0.0.0/0
DENY
AWS Solutions Architect Associate · Domain 1 157
Intellectual Point Amazon Web Services
Amazon VPC

Ephemeral Ports

  • Two endpoints need ports to connect
  • Clients connect to a defined port and expect the response on an ephemeral port
  • Ranges differ by OS: IANA and Windows 10 use 49152-65535, many Linux kernels 32768-60999
ClientIP 11.22.33.44Ephemeral port 50105Web serverIP 55.66.77.88Fixed port 443RequestResponseSrc IP11.22.33.44Src port50105Dest IP55.66.77.88Dest port443Src IP55.66.77.88Src port443Dest IP11.22.33.44Dest port50105
AWS Solutions Architect Associate · Domain 1 158
Intellectual Point Amazon Web Services
Amazon VPC

NACL with Ephemeral Ports

VPC Web subnet (public) DB subnet (private)Client (web tier)DB instanceWeb-NACL outboundTCP 3306to DB subnet CIDRWeb-NACL inboundTCP 1024-65535from DB subnet CIDRDB-NACL inboundTCP 3306from web subnet CIDRDB-NACL outboundTCP 1024-65535to web subnet CIDRport 3306ephemeral port

docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html#nacl-ephemeral-ports

AWS Solutions Architect Associate · Domain 1 159
Intellectual Point Amazon Web Services
Amazon VPC

Create NACL Rules for Each Target Subnet CIDR

VPC Web subnet A (public) DB subnet A (private) Web subnet B (public) DB subnet B (private)Web tierDatabase tierWeb-NACLDB-NACLOne rule per target subnet CIDR
AWS Solutions Architect Associate · Domain 1 160
Intellectual Point Amazon Web Services
Amazon VPC

Security Group vs. NACL

Security group
NACL
Operates at the instance level
Operates at the subnet level
Allow rules only
Allow and deny rules
Stateful: return traffic is allowed automatically
Stateless: return traffic must be allowed by rules (ephemeral ports)
All rules are evaluated before deciding
Rules are evaluated in order, lowest number first. First match wins
Applies to an EC2 instance when someone assigns it
Applies to every instance in its subnets automatically
AWS Solutions Architect Associate · Domain 1 161
Intellectual Point Amazon Web Services
Amazon VPC

VPC Peering

  • Privately connect two VPCs over the AWS network
  • They behave as if they were in the same network
  • CIDRs must not overlap
  • Peering is not transitive: connect every pair that needs to talk
  • Update the route tables in each VPC's subnets
VPC AVPC BVPC CA-BA-CB-C
AWS Solutions Architect Associate · Domain 1 162
Intellectual Point Amazon Web Services
Amazon VPC

VPC Peering: Good to Know

  • Peer VPCs across AWS accounts and Regions
  • Reference a security group in a peered VPC: works across accounts in the same Region
Type
Protocol
Port range
Source
HTTP
TCP
80
sg-04991f9af3473b939 / default
HTTP
TCP
80
606412510120 / sg-027ad1f7865d4be76

The second rule references a security group in another account by account ID.

AWS Solutions Architect Associate · Domain 1 163
Intellectual Point Amazon Web Services
Amazon VPC

VPC Peering in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peering

Peering connections link this VPC to others.

AWS Solutions Architect Associate · Domain 1 164
Intellectual Point Amazon Web Services
Amazon VPC

VPC Endpoints in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peeringVPCendpointS3DynamoDB

VPC endpoints reach S3 and DynamoDB without leaving the AWS network.

AWS Solutions Architect Associate · Domain 1 165
Intellectual Point Amazon Web Services
Amazon VPC

VPC Endpoints (AWS PrivateLink)

  • Every AWS service has a public URL
  • VPC endpoints (PrivateLink) reach AWS services over a private network
  • Redundant and scale horizontally
  • No IGW or NAT gateway needed to reach AWS services
  • Having issues? Check
    • DNS resolution settings in your VPC
    • Route tables
RegionVPC Public subnet Private subnetNATOption 1Option 2VPC endpointAmazon SNSAmazon SNSpublic internetprivate
AWS Solutions Architect Associate · Domain 1 166
Intellectual Point Amazon Web Services
Amazon VPC

Types of Endpoints

PrivateLink

Interface endpoint

  • An ENI (private IP) entry point with a security group
  • Most AWS services. $ per hour + $ per GB

Route table target

Gateway endpoint

  • A route table target. No security groups
  • S3 and DynamoDB only. Free
VPC endpoint (Interface) Private subnetVPC endpoint (Gateway) Private subnetENI (PrivateLink)Amazon SNSS3 or DynamoDB
AWS Solutions Architect Associate · Domain 1 167
Intellectual Point Amazon Web Services
Amazon VPC

Gateway or Interface Endpoint for S3?

  • The gateway endpoint is almost always the exam answer
  • Cost: gateway is free, interface costs money
  • Choose an interface endpoint for access from on-premises (Site-to-Site VPN or Direct Connect), another VPC, or another Region
AWS CloudVPCOn-premises usersInterface endpointIn-VPC appsGatewayAmazon S3DX / S2S VPNPrivateLink
AWS Solutions Architect Associate · Domain 1 168
Intellectual Point Amazon Web Services
Amazon VPC

Lambda in a VPC Accessing DynamoDB

  • DynamoDB is a public AWS service
  • Option 1: over the public internet
    • Lambda in a VPC needs a NAT gateway in a public subnet and an IGW
  • Option 2 (better and free): over the private network
    • Deploy a VPC gateway endpoint for DynamoDB
    • Update the route tables
AWS Cloud Public subnet Private subnetNATIGWLambdaGateway endpointDynamoDBoption 1option 2
AWS Solutions Architect Associate · Domain 1 169
Intellectual Point Amazon Web Services
Amazon VPC

VPC Flow Logs

  • Capture information about IP traffic going into your interfaces
    • VPC, subnet, or ENI flow logs
  • Monitor and troubleshoot connectivity issues
  • Send flow log data to S3, CloudWatch Logs, or Data Firehose
  • Also captures AWS managed interfaces: ELB, RDS, ElastiCache, Redshift, WorkSpaces, NAT gateway, Transit Gateway
Capture atSend toVPCSubnetENIFlow logsAmazon S3CloudWatch Logs Data Firehose
AWS Solutions Architect Associate · Domain 1 170
Intellectual Point Amazon Web Services
Amazon VPC

VPC Flow Logs in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peeringVPCendpointS3DynamoDBFlowlogsCloudWatch

Flow logs record traffic metadata for the VPC and send it to CloudWatch Logs or S3.

AWS Solutions Architect Associate · Domain 1 171
Intellectual Point Amazon Web Services
Amazon VPC

VPC Flow Logs Syntax

Each flow log record is one line with these fields, in order. The bold fields matter most for troubleshooting.

Field
Example
version
2
account-id
123456789010
interface-id
eni-1235b8ca123456789
srcaddr
172.31.16.139
dstaddr
172.31.16.21
srcport
20641
dstport
22
Field
Example
protocol
6 (TCP)
packets
20
bytes
4249
start
1418530010
end
1418530070
action
ACCEPT
log-status
OK
AWS Solutions Architect Associate · Domain 1 172
Intellectual Point Amazon Web Services
Amazon VPC

Reading Flow Logs

  • srcaddr and dstaddr identify problematic IP addresses
  • srcport and dstport identify problematic ports
  • action shows success or failure caused by a security group or NACL
  • Use them for usage analytics or to spot malicious behavior
  • Query flow logs with Athena on S3 or CloudWatch Logs Insights
Example records: SSH accepted, RDP rejected
2 123456789010 eni-1235b8ca123456789 172.31.16.139 172.31.16.21 20641 22 6 20 4249 1418530010 1418530070 ACCEPT OK
2 123456789010 eni-1235b8ca123456789 172.31.9.69 172.31.9.12 49761 3389 6 20 4249 1418530010 1418530070 REJECT OK
AWS Solutions Architect Associate · Domain 1 173
Intellectual Point Amazon Web Services
Amazon VPC

Flow Logs: Troubleshoot SG and NACL Issues

Look at the action field for the request and its response:

What you see
Likely cause
Inbound REJECT
NACL or security group
Outbound REJECT
NACL or security group
Inbound ACCEPT, outbound REJECT
NACL
Outbound ACCEPT, inbound REJECT
NACL

Security groups are stateful: once a request is accepted, its response is allowed. A rejected response points to the stateless NACL.

AWS Solutions Architect Associate · Domain 1 174
Intellectual Point Amazon Web Services
Amazon VPC

VPC Flow Logs: Architectures

VPC Flow LogsCloudWatch LogsContributor InsightsTop-10 IP addressesVPC Flow LogsCloudWatch LogsMetric filterCloudWatch alarmAmazon SNSSSH, RDP...VPC Flow LogsS3 bucketAmazon AthenaAmazon QuickSight

Find top talkers, alert on SSH or RDP attempts, or run SQL analytics and dashboards.

AWS Solutions Architect Associate · Domain 1 175
Intellectual Point Amazon Web Services
Amazon VPC

VPC Flow Logs: CloudWatch Permissions

  • The IAM service role used by VPC Flow Logs needs permission to publish to CloudWatch Logs
  • At minimum: logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents
VPC Flow LogsIAM service roleCloudWatch Logslogs:*
Role permissions policy
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "logs:DescribeLogGroups",
      "logs:DescribeLogStreams"
    ],
    "Resource": "*"
  }]
}
AWS Solutions Architect Associate · Domain 1 176
Intellectual Point Amazon Web Services
Amazon VPC

Site-to-Site VPN in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupCorporate DCInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peeringVPCendpointS3DynamoDBFlowlogsCloudWatchServerVPNgatewayCustomergatewayS2S VPN

A Site-to-Site VPN links the VPC to your corporate data center over the public internet.

AWS Solutions Architect Associate · Domain 1 177
Intellectual Point Amazon Web Services
Amazon VPC

AWS Site-to-Site VPN

Virtual private gateway (VGW)

  • VPN concentrator on the AWS side
  • Created and attached to the VPC
  • Customizable ASN (Autonomous System Number)

Customer gateway (CGW)

  • Software or physical device on the customer side
  • AWS publishes a list of tested devices
VPC Private subnetCorporate data centerEC2VGWCGWServersVPNover the public internet
AWS Solutions Architect Associate · Domain 1 178
Intellectual Point Amazon Web Services
Amazon VPC

Site-to-Site VPN Connections

  • Which IP does the customer gateway use?
    • Its public, internet-routable IP
    • Behind a NAT with NAT-T? Use the NAT device's public IP
  • Enable route propagation for the VGW in your subnets' route tables
  • Need to ping EC2 from on-premises? Allow ICMP inbound in the security group
VPC Private subnetCorporate data centerVGWCustomer gateway(public IP)ORNAT device (public IP)CGW (private IP)VPN
AWS Solutions Architect Associate · Domain 1 179
Intellectual Point Amazon Web Services
Amazon VPC

AWS VPN CloudHub

  • Secure communication between multiple sites with multiple VPN connections
  • Low-cost hub-and-spoke model for primary or backup connectivity
  • It is a VPN, so traffic goes over the public internet
  • Set up: connect several VPNs to the same VGW, use dynamic routing, configure route tables
VPC Private subnet Private subnetCustomer networkCustomer networkCustomer networkVGWVPN
AWS Solutions Architect Associate · Domain 1 180
Intellectual Point Amazon Web Services
Amazon VPC

AWS Direct Connect (DX)

  • A dedicated private connection from your network to your VPC
  • Set up between your data center and an AWS Direct Connect location
  • Needs a virtual private gateway on your VPC
  • Reach public (S3) and private (EC2) resources on the same connection
  • Supports IPv4 and IPv6

More bandwidth

Large data sets at lower cost

Consistent network

Apps with real-time data feeds

Hybrid environments

On-premises plus cloud

AWS Solutions Architect Associate · Domain 1 181
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect in the VPC

RegionVPCAvailability Zone Public subnet Private subnetSecurity groupSecurity groupCorporate DCInternetgatewaywwwRouterRoute tablePublic EC2NAT gatewayRoute tablePrivate EC2NACLNACLVPC peeringVPCendpointS3DynamoDBFlowlogsCloudWatchServerVPNgatewayCustomergatewayS2S VPNDirect Connect

Direct Connect adds a private, dedicated link alongside (or instead of) the VPN.

AWS Solutions Architect Associate · Domain 1 182
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect Diagram

Region (us-east-1)VPC Private subnetAWS Direct Connect locationAWS cageCustomer or partner cageCustomer networkEC2 instancesVirtual privategatewayAmazon S3S3 GlacierDX endpointPartner routerRouter / firewallVLAN 1 · private virtual interface (VPC)VLAN 2 · public virtual interface (S3, Glacier)
AWS Solutions Architect Associate · Domain 1 183
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect Gateway

  • Connect to one or more VPCs in different Regions (same account)
  • You must use a Direct Connect gateway for this
  • Each VPC attaches with a private virtual interface
Region (us-east-1)VPCRegion (us-west-1)VPC10.0.0.0/16172.16.0.0/16private VIFprivate VIFDirect Connect gatewayDX connectionCustomer network
AWS Solutions Architect Associate · Domain 1 184
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect: Connection Types

1 Gbps to 400 Gbps

Dedicated connections

  • Physical ethernet port dedicated to one customer
  • Request to AWS first, then completed by AWS Direct Connect Partners

50 Mbps to 25 Gbps

Hosted connections

  • Requested through AWS Direct Connect Partners
  • Add or remove capacity on demand

Lead times are often longer than 1 month to establish a new connection.

AWS Solutions Architect Associate · Domain 1 185
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect: Encryption

  • Data in transit is not encrypted, but it is private
  • Direct Connect + VPN gives an IPsec-encrypted private connection
  • Extra security, but slightly more complex to set up
VPC Private subnet Private subnetDX locationCorporate DCClientsDirect ConnectIPsec VPN tunnel
AWS Solutions Architect Associate · Domain 1 186
Intellectual Point Amazon Web Services
Amazon VPC

Direct Connect: Resiliency

High resiliency for critical workloads

RegionDX location 1Corporate DCDX location 2Corporate DC

One connection at multiple locations

Maximum resiliency for critical workloads

RegionDX location 1Corporate DCDX location 2Corporate DC

Separate connections on separate devices in more than one location

AWS Solutions Architect Associate · Domain 1 187
Intellectual Point Amazon Web Services
Amazon VPC

Site-to-Site VPN as a Backup

If Direct Connect fails, fail over to a second DX connection (expensive) or a Site-to-Site VPN.

Corporate DCAWS CloudVPCDirect Connect · primarySite-to-Site VPN · backup
AWS Solutions Architect Associate · Domain 1 188
Intellectual Point Amazon Web Services
Amazon VPC

Network Topologies Can Become Complicated

Amazon VPCAmazon VPCAmazon VPCAmazon VPCCorporate DCCustomer gatewayCustomer gatewayDirect Connect gatewayVPC peeringVPN connectionDirect Connect

Peering is not transitive, so every new VPC adds more peering, VPN, and DX links.

AWS Solutions Architect Associate · Domain 1 189
Intellectual Point Amazon Web Services
Amazon VPC

Transit Gateway

  • Transitive peering between thousands of VPCs and on-premises: hub and spoke
  • Regional resource that works cross-Region (peer Transit Gateways)
  • Share cross-account with Resource Access Manager (RAM)
  • Route tables limit which VPCs can talk to each other
  • Works with Direct Connect gateway and VPN connections
  • Supports IP multicast (no other AWS service does)
Amazon VPCAmazon VPCAmazon VPCAmazon VPCTransit GatewayDX gatewayVPN + customer gateway
AWS Solutions Architect Associate · Domain 1 190
Intellectual Point Amazon Web Services
Amazon VPC

Transit Gateway: Site-to-Site VPN ECMP

  • ECMP = equal-cost multi-path routing
  • Forwards packets over multiple best paths
  • Use case: create multiple Site-to-Site VPN connections to increase bandwidth to AWS
Corporate DCVPC attachmentsTransit GatewayVPNattachments
AWS Solutions Architect Associate · Domain 1 191
Intellectual Point Amazon Web Services
Amazon VPC

Transit Gateway: Throughput with ECMP

VPN to virtual private gateway1 VPN connection, 2 tunnels:only 1 tunnel is used at a time1x1.25 GbpsVPN to Transit Gateway (ECMP)1x2.5 Gbps2 tunnels used2x5.0 Gbps3x7.5 Gbps$ per GB of data processed by the Transit Gateway

Each VPN connection has 2 tunnels. With ECMP, the Transit Gateway uses both and scales as you add connections.

AWS Solutions Architect Associate · Domain 1 192
Intellectual Point Amazon Web Services
Amazon VPC

Transit Gateway: Share Direct Connect

AWS RegionAccount 1Account 2DX locationCorporate DCClientsVPCServersVPCTransitGatewayDirect ConnectgatewayDX endpointCustomerrouterTransit VIF

Share the Transit Gateway with other accounts using AWS Resource Access Manager (RAM).

AWS Solutions Architect Associate · Domain 1 193
Intellectual Point Amazon Web Services
Amazon VPC

VPC Traffic Mirroring

  • Capture and inspect network traffic in your VPC
  • Route it to security appliances you manage
  • Capture traffic
    • From (source): ENIs
    • To (target): an ENI or a Network Load Balancer
  • Capture all packets or only those you care about (optionally truncate)
  • Source and target can be in the same VPC or peered VPCs
  • Use cases: content inspection, threat monitoring, troubleshooting
Auto Scaling groupSource ASource Binbound andoutbound trafficTraffic Mirroring(optional filter)Network LoadBalancerSecurity appliances
AWS Solutions Architect Associate · Domain 1 194
Intellectual Point Amazon Web Services
Amazon VPC

What Is IPv6?

  • IPv4 provides about 4.3 billion addresses, which will run out soon
  • IPv6 is its successor, with 3.4 × 10³⁸ unique addresses
  • Every IPv6 address in AWS is public and internet-routable (no private range)
  • Format: x:x:x:x:x:x:x:x, where each x is hexadecimal from 0000 to ffff
Example
Meaning
2001:db8:3333:4444:5555:6666:7777:8888
All 8 segments written out
::
All 8 segments are zero
2001:db8::
The last 6 segments are zero
::1234:5678
The first 6 segments are zero
2001:db8::1234:5678
The middle 4 segments are zero
AWS Solutions Architect Associate · Domain 1 195
Intellectual Point Amazon Web Services
Amazon VPC

IPv6 in a VPC

  • IPv4 cannot be disabled for your VPC and subnets
  • Enable IPv6 (public addresses) to run in dual-stack mode
  • EC2 instances get at least a private IPv4 and a public IPv6
  • They reach the internet over IPv4 or IPv6 through an internet gateway
VPCInternetInternet gatewayEC2 instancePrivate IPv4: 10.0.0.5IPv6: 2001:db8::ff00:42:8329IPv4 & IPv6
AWS Solutions Architect Associate · Domain 1 196
Intellectual Point Amazon Web Services
Amazon VPC

IPv4 Troubleshooting

  • IPv4 cannot be disabled for your VPC and subnets
  • Can't launch an EC2 instance in your subnet?
    • Not because it can't get an IPv6 (the space is huge)
    • Because there are no available IPv4 addresses left
  • Fix: add a new IPv4 CIDR to the subnet
VPCUserIPv4 192.168.0.0/24 (full).10.15...IPv6 2001:db8:1234:5678::/56New IPv4 CIDR 10.0.0.0/2410.0.0.35create
AWS Solutions Architect Associate · Domain 1 197
Intellectual Point Amazon Web Services
Amazon VPC

Egress-Only Internet Gateway

  • For IPv6 only: like a NAT gateway, but for IPv6
  • Instances make outbound IPv6 connections, while the internet can't initiate connections to them
  • You must update the route tables
VPC Public subnet Private subnetInternetInternet gatewayEgress-only IGW2001:db8::b1c22001:db8::e1c3both sidescan initiateinternet can't initiate
AWS Solutions Architect Associate · Domain 1 198
Intellectual Point Amazon Web Services
Amazon VPC

IPv6 Routing

VPC 10.0.0.0/16 · 2001:db8:1234:1a00::/56 Public subnet Private subnetInternetWeb serverIPv4 & IPv6NAT gatewayServerIGWEgress-onlyIGWIPv4IPv6
Public subnet destination
Target
10.0.0.0/16
local
2001:db8:1234:1a00::/56
local
0.0.0.0/0
igw-id
::/0
igw-id
Private subnet destination
Target
10.0.0.0/16
local
2001:db8:1234:1a00::/56
local
0.0.0.0/0
nat-gateway-id
::/0
eigw-id
AWS Solutions Architect Associate · Domain 1 199
Intellectual Point Amazon Web Services
Amazon VPC

VPC Section Summary (1 of 3)

Term
What to remember
VPC
Virtual private cloud with IPv4 and IPv6 CIDRs (IP ranges)
Subnets
Tied to one AZ, each with its own CIDR
Internet gateway
VPC-level IPv4 and IPv6 internet access
Route tables
Route subnets to the IGW, peering connections, and endpoints
Bastion host
Public EC2 instance to SSH into private instances
NAT instance
Old way. Public subnet, source/destination check off
NAT gateway
AWS managed, scalable IPv4 internet for private instances
AWS Solutions Architect Associate · Domain 1 200
Intellectual Point Amazon Web Services
Amazon VPC

VPC Section Summary (2 of 3)

Term
What to remember
NACL
Stateless subnet rules for inbound and outbound. Remember ephemeral ports
Security groups
Stateful, at the EC2 instance level
VPC peering
Connect two VPCs with non-overlapping CIDRs. Not transitive
VPC endpoints
Private access to AWS services (S3, DynamoDB, CloudFormation, SSM) from a VPC
VPC Flow Logs
VPC, subnet, or ENI level. ACCEPT and REJECT traffic. Analyze with Athena or CloudWatch Logs Insights
Site-to-Site VPN
Customer gateway on premises, VGW on the VPC, VPN over the public internet
AWS VPN CloudHub
Hub-and-spoke VPN model to connect your sites
AWS Solutions Architect Associate · Domain 1 201
Intellectual Point Amazon Web Services
Amazon VPC

VPC Section Summary (3 of 3)

Term
What to remember
Direct Connect
VGW on the VPC plus a private link to an AWS Direct Connect location
Direct Connect gateway
Direct Connect to many VPCs in different Regions
PrivateLink (endpoint services)
Expose a service privately to customer VPCs. No peering, internet, NAT, or route tables. Uses an NLB and ENIs
ClassicLink
Connect EC2-Classic instances privately to your VPC
Transit Gateway
Transitive peering for VPCs, VPN, and DX
Traffic Mirroring
Copy network traffic from ENIs for analysis
Egress-only IGW
Like a NAT gateway, but for IPv6
AWS Solutions Architect Associate · Domain 1 202
Intellectual Point Amazon Web Services
Amazon VPC

Networking Costs in AWS per GB

  • Use private IPs instead of public IPs for savings and better network performance
  • Use the same AZ for maximum savings, at the cost of high availability
RegionAvailability Zone 1Availability Zone 2Another RegionFree · private IP$0.01 · private IP$0.02 · public or Elastic IP$0.02 · inter-RegionPrices are per GB, simplified
AWS Solutions Architect Associate · Domain 1 203
Intellectual Point Amazon Web Services
Amazon VPC

Minimizing Egress Traffic Cost

  • Egress: outbound traffic from AWS to outside
  • Ingress: inbound traffic to AWS (typically free)
  • Keep as much traffic inside AWS as possible
  • Direct Connect locations in the same Region lower egress cost
AWS CloudCorporate DCEgress cost is highDatabaseApplication50 KB query100 MB results
AWS CloudCorporate DCEgress cost is minimizedApplicationDatabase100 MBUser50 KB results
AWS Solutions Architect Associate · Domain 1 204
Intellectual Point Amazon Web Services
Amazon VPC

S3 Data Transfer Pricing (USA)

Transfer
Price
S3 ingress
Free
S3 to internet
$0.09 per GB
Transfer Acceleration
+$0.04 to $0.08 per GB, 50 to 500% faster
S3 to CloudFront
$0.00 per GB
CloudFront to internet
$0.085 per GB, caching, 7x cheaper requests
Cross-Region Replication
$0.02 per GB
S3 bucket$0.09Internet+$0.04$0.09Internet$0.00$0.085Internet$0.02Other RegionEdge locationCloudFront
AWS Solutions Architect Associate · Domain 1 205
Intellectual Point Amazon Web Services
Amazon VPC

Pricing: NAT Gateway vs. Gateway VPC Endpoint

Region (us-east-1) · VPC 10.0.0.0/16 Private subnet 1 Public subnet Private subnet 2EC2NAT gatewayIGWEC2Gateway endpointAmazon S3$0.045 per hour (NAT gateway)$0.045 per GB processed$0.00 same Region$0.09 cross-RegionNo cost for the gateway endpoint$0.01 per GB in/out (same Region)

Private subnet 1 routes 0.0.0.0/0 to the NAT gateway. Private subnet 2 routes the S3 prefix list to the endpoint.

AWS Solutions Architect Associate · Domain 1 206
Intellectual Point Amazon Web Services
Amazon VPC

Network Protection on AWS

So far, you have seen these ways to protect your network:

NACLs

Subnet-level rules

Security groups

Instance-level rules

AWS WAF

Block malicious requests

AWS Shield

DDoS protection (and Advanced)

Firewall Manager

Manage them across accounts

What if you want to protect your entire VPC in a sophisticated way?

AWS Solutions Architect Associate · Domain 1 207
Intellectual Point Amazon Web Services
Amazon VPC

AWS Network Firewall

  • Protects your entire Amazon VPC
  • Layer 3 to Layer 7 protection
  • Inspect any direction
    • VPC to VPC
    • Outbound to and inbound from the internet
    • To and from Direct Connect and Site-to-Site VPN
  • Uses the Gateway Load Balancer internally
  • Manage rules cross-account with Firewall Manager
VPC Private subnetInternetNetwork FirewallPeered VPCCorporate DCVPNDX
AWS Solutions Architect Associate · Domain 1 208
Intellectual Point Amazon Web Services
Amazon VPC

Network Firewall: Fine-Grained Controls

IP and port

Filter 10,000s of IPs

Protocol

Block SMB for outbound traffic

Domain lists

Only allow *.mycorp.com or a software repo

Pattern matching

General matching with regex

  • Supports 1000s of rules
  • Traffic filtering: allow, drop, or alert on matches
  • Active flow inspection with intrusion prevention, fully managed by AWS
  • Send rule-match logs to S3, CloudWatch Logs, or Data Firehose
AWS Solutions Architect Associate · Domain 1 209
1 / 1