Security Services and Resources
A tour of the AWS services that protect, detect, and advise: network protection like Shield and WAF, threat detection like GuardDuty and Inspector, and the official resources for security guidance.
Security Services and Resources is the last topic in the Security and Compliance domain, and it is the most service-heavy one. The earlier topics gave you the model: who is responsible for what, how compliance and governance work, and how IAM controls access. This topic covers the actual AWS services you turn on to protect your applications, spot threats, and get trustworthy guidance.
The topic has 3 lessons. The first covers the services that guard the network perimeter, the second covers the services that detect threats and find weaknesses inside your environment, and the third covers the official AWS resources you use to review your setup and stay informed.
What This Topic Covers
- network protection with AWS Shield (DDoS), AWS WAF (web exploits), AWS Network Firewall, and AWS Firewall Manager
- the difference between Shield Standard (free and automatic) and Shield Advanced (paid)
- threat detection with Amazon GuardDuty and vulnerability scanning with Amazon Inspector
- sensitive data discovery in Amazon S3 with Amazon Macie
- how AWS Security Hub aggregates findings and Amazon Detective investigates the root cause
- security guidance from AWS Trusted Advisor, the AWS Well-Architected Tool, and AWS Artifact
- where to stay informed: AWS Security Bulletins, documentation, and partner support
Why It Matters
The exam expects you to match a security need to the right service. A question rarely asks how a service works in depth. It describes a problem, like a DDoS flood, a public S3 bucket, or an unpatched server, and asks which AWS service handles it. If you can sort these services by their job, you can answer that whole family of questions quickly.
This topic also rounds out the rest of the domain. The model tells you what is yours to secure, and these services are the tools AWS gives you to actually do it.
