[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"lesson-aws-certified-cloud-practitioner-security-and-compliance-en":3,"cheat-sheet---en":3,"topic-info----en":3,"prev-aws-certified-cloud-practitioner-security-and-compliance-en":3,"next-aws-certified-cloud-practitioner-security-and-compliance-en":3,"domain-info-aws-certified-cloud-practitioner-security-and-compliance-en":4},null,{"meta":5,"body":8},{"title":6,"description":7},"Security and Compliance","An overview of the second AWS Cloud Practitioner domain: the shared responsibility model, compliance and governance, identity and access management with IAM, and the AWS services that protect your resources.",{"type":9,"value":10,"toc":55},"minimark",[11,15,18,23,45,49,52],[12,13,14],"p",{},"Security and Compliance is the second domain of the AWS Certified Cloud Practitioner course, and it carries the most weight on the exam. Cloud Concepts gave you the vocabulary; this domain shows you how AWS keeps workloads safe and who is responsible for what. It all builds on one idea: in the cloud, security is a shared job between AWS and you.",[12,16,17],{},"Security and Compliance is 30% of the CLF-C02 exam, the largest share of any single domain. The concepts here are practical, and most of them map to controls you would actually configure in a real AWS account.",[19,20,22],"h2",{"id":21},"what-this-domain-covers","What This Domain Covers",[24,25,26,30,33,36,39,42],"ul",{},[27,28,29],"li",{},"the AWS Shared Responsibility Model, and how the split between AWS and customer duties shifts by service type",[27,31,32],{},"compliance and governance: AWS Artifact, encryption on AWS, and monitoring and auditing your account",[27,34,35],{},"identity and access management with IAM: users, groups, roles, and policies",[27,37,38],{},"account security fundamentals: the root user, least privilege, and multi-factor authentication (MFA)",[27,40,41],{},"federated and centralized access with IAM Identity Center",[27,43,44],{},"the AWS security services that protect your network and detect threats, plus the official resources for staying current",[19,46,48],{"id":47},"why-it-matters","Why It Matters",[12,50,51],{},"Security comes up everywhere on the exam, and the Shared Responsibility Model is the idea behind a large share of those questions. Once you can say what AWS secures, what you secure, and how that line moves between EC2, a managed database, and a serverless function, you can reason through most security scenarios instead of memorizing them.",[12,53,54],{},"This domain is also the most hands-on part of the course. IAM, MFA, and least privilege are among the first things you set up in a real AWS account, so the time you spend here pays off well beyond the exam.",{"title":56,"searchDepth":57,"depth":57,"links":58},"",3,[59,61],{"id":21,"depth":60,"text":22},2,{"id":47,"depth":60,"text":48}]