[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloud-practitioner-security-and-compliance-security-services-and-resources-network-protection-services-en":4,"prev-aws-certified-cloud-practitioner-security-and-compliance-security-services-and-resources-network-protection-services-en":293,"next-aws-certified-cloud-practitioner-security-and-compliance-security-services-and-resources-network-protection-services-en":304},null,{"locked":5,"reason":3,"meta":6,"item":17},false,{"title":7,"description":8,"isFree":9,"estimatedMinutes":10,"difficulty":11,"learningObjectives":12},"AWS Network Protection Services","Learn how AWS Shield, AWS WAF, AWS Network Firewall, and AWS Firewall Manager protect your applications from DDoS attacks, web exploits, and unwanted network traffic.",true,16,"beginner",[13,14,15,16],"Explain how AWS Shield Standard and Shield Advanced protect against DDoS attacks","Describe what AWS WAF filters and which resources it can protect","Identify the role of AWS Network Firewall inside a VPC","Explain how AWS Firewall Manager centralizes protection across many accounts",{"id":18,"title":7,"body":19,"description":8,"difficulty":11,"estimatedMinutes":10,"extension":235,"infographics":236,"isFree":9,"learningObjectives":246,"meta":247,"navigation":9,"path":248,"quiz":249,"seo":290,"stem":291,"__hash__":292},"courses/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/04-security-services-and-resources/01-network-protection-services.md",{"type":20,"value":21,"toc":220},"minimark",[22,27,31,34,39,43,46,51,54,58,61,64,68,71,74,77,81,84,87,91,94,97,101,197,200,204],[23,24,26],"h2",{"id":25},"protecting-the-network-perimeter","Protecting the network perimeter",[28,29,30],"p",{},"Every application that accepts traffic from the internet has a perimeter, the point where outside requests first reach your resources. That perimeter is where attackers probe first, so AWS offers several services that filter and absorb unwanted traffic before it can hurt your application.",[28,32,33],{},"These services work at different layers. Some absorb floods of traffic aimed at knocking your site offline. Some read individual web requests and block the malicious ones. Some inspect traffic moving inside your private network. You often use more than one at the same time, because each one stops a different kind of threat.",[35,36],"infographic",{"alt":37,"slug":38},"A diagram showing AWS Shield absorbing DDoS traffic at the edge, AWS WAF filtering web requests at the application layer, AWS Network Firewall inspecting traffic inside the VPC, and AWS Firewall Manager managing all of them across accounts.","network-protection-layers",[23,40,42],{"id":41},"aws-shield-ddos-protection","AWS Shield: DDoS protection",[28,44,45],{},"A Distributed Denial of Service (DDoS) attack tries to overwhelm your application with a flood of traffic from many sources at once, so real users can no longer reach it. AWS Shield is the managed service that defends against these attacks.",[47,48,50],"h3",{"id":49},"shield-standard","Shield Standard",[28,52,53],{},"Shield Standard is automatic and free for every AWS customer. You do not enable it or pay for it. It defends against the most common network and transport layer attacks, known as Layer 3 and Layer 4 attacks, that target your website or applications. When you use it with Amazon CloudFront and Amazon Route 53, you get strong protection against all known infrastructure-layer attacks.",[47,55,57],{"id":56},"shield-advanced","Shield Advanced",[28,59,60],{},"Shield Advanced is a paid subscription for applications that need more. It adds detection and mitigation for large and sophisticated DDoS attacks, including attacks at the application layer (Layer 7). It protects resources such as Amazon EC2, Elastic Load Balancing, CloudFront, Route 53, and AWS Global Accelerator.",[28,62,63],{},"Shield Advanced also gives you near real-time visibility into attacks, 24x7 access to the AWS Shield Response Team, and protection against the cost spikes that an attack can cause on protected resources. If your site is a frequent target or downtime would be expensive, Shield Advanced is worth the cost.",[23,65,67],{"id":66},"aws-waf-filtering-web-traffic","AWS WAF: filtering web traffic",[28,69,70],{},"AWS WAF is a web application firewall. While Shield absorbs traffic floods, WAF looks at individual HTTP and HTTPS requests and decides whether to allow, block, or count each one based on rules you set.",[28,72,73],{},"WAF defends against common web exploits such as SQL injection and cross-site scripting (XSS). You can write rules based on the IP address a request comes from, the country of origin, values in request headers, the length of a request, or strings in the request body. You can also start fast with managed rule groups from AWS, including sets that address the OWASP Top 10 risks and rules that block bad bots.",[28,75,76],{},"WAF protects resources that serve web traffic, including Amazon CloudFront distributions, Application Load Balancers, Amazon API Gateway REST APIs, and AWS AppSync GraphQL APIs. A blocked request gets an HTTP 403 (Forbidden) response instead of your content.",[23,78,80],{"id":79},"aws-network-firewall-protecting-your-vpc","AWS Network Firewall: protecting your VPC",[28,82,83],{},"AWS Network Firewall is a managed service that filters network traffic for the subnets in your Amazon VPCs. While WAF works on web requests reaching public-facing resources, Network Firewall sits inside your private network and controls traffic flowing in and out of it.",[28,85,86],{},"It gives you fine-grained control with a flexible rules engine. You can block outbound requests to known bad domains, run an intrusion prevention system that inspects traffic for known exploits, and filter web traffic by URL or domain name. It scales automatically with your traffic, so you do not manage any firewall infrastructure yourself.",[23,88,90],{"id":89},"aws-firewall-manager-managing-protection-at-scale","AWS Firewall Manager: managing protection at scale",[28,92,93],{},"Setting up Shield Advanced, WAF, and security groups one account at a time does not scale when a company runs dozens of AWS accounts. AWS Firewall Manager solves that problem. It is a central management service that lets you configure firewall rules once and apply them across every account and resource in your AWS Organization.",[28,95,96],{},"Firewall Manager can manage AWS WAF rules, Shield Advanced protections, Amazon VPC security groups and network ACLs, AWS Network Firewall, and Amazon Route 53 Resolver DNS Firewall. When someone creates a new account or resource, Firewall Manager automatically brings it under the same security policies, so nothing slips through unprotected.",[23,98,100],{"id":99},"how-these-services-fit-together","How these services fit together",[102,103,104,123],"table",{},[105,106,107],"thead",{},[108,109,110,114,117,120],"tr",{},[111,112,113],"th",{},"Service",[111,115,116],{},"What it protects against",[111,118,119],{},"Where it works",[111,121,122],{},"Cost",[124,125,126,141,155,169,183],"tbody",{},[108,127,128,132,135,138],{},[129,130,131],"td",{},"AWS Shield Standard",[129,133,134],{},"Common DDoS attacks (Layer 3 and 4)",[129,136,137],{},"Edge, all AWS resources",[129,139,140],{},"Free, automatic",[108,142,143,146,149,152],{},[129,144,145],{},"AWS Shield Advanced",[129,147,148],{},"Large and sophisticated DDoS (Layer 3, 4, and 7)",[129,150,151],{},"EC2, ELB, CloudFront, Route 53, Global Accelerator",[129,153,154],{},"Paid subscription",[108,156,157,160,163,166],{},[129,158,159],{},"AWS WAF",[129,161,162],{},"Web exploits like SQL injection and XSS",[129,164,165],{},"CloudFront, ALB, API Gateway, AppSync",[129,167,168],{},"Pay per rule and request",[108,170,171,174,177,180],{},[129,172,173],{},"AWS Network Firewall",[129,175,176],{},"Unwanted traffic inside your network",[129,178,179],{},"Amazon VPC subnets",[129,181,182],{},"Pay per firewall and traffic",[108,184,185,188,191,194],{},[129,186,187],{},"AWS Firewall Manager",[129,189,190],{},"Inconsistent protection across accounts",[129,192,193],{},"Central, across AWS Organizations",[129,195,196],{},"Pay per policy",[28,198,199],{},"The pattern is layered defense. Shield absorbs the flood, WAF blocks the bad request, Network Firewall controls traffic inside your VPC, and Firewall Manager keeps all of it consistent across your accounts.",[23,201,203],{"id":202},"exam-tips","Exam tips",[205,206,207,211,214,217],"ul",{},[208,209,210],"li",{},"Shield Standard is free and automatic for everyone, and it covers common Layer 3 and 4 DDoS attacks. Shield Advanced is paid and adds Layer 7 protection, the Shield Response Team, and cost protection.",[208,212,213],{},"AWS WAF filters web requests and blocks exploits like SQL injection and cross-site scripting. If a question mentions HTTP requests, web exploits, or the OWASP Top 10, the answer is WAF.",[208,215,216],{},"AWS Network Firewall protects traffic at the VPC level, not individual web requests.",[208,218,219],{},"AWS Firewall Manager is about central management across many accounts in AWS Organizations. If a question asks how to enforce the same rules across all accounts, the answer is Firewall Manager.",{"title":221,"searchDepth":222,"depth":222,"links":223},"",3,[224,226,230,231,232,233,234],{"id":25,"depth":225,"text":26},2,{"id":41,"depth":225,"text":42,"children":227},[228,229],{"id":49,"depth":222,"text":50},{"id":56,"depth":222,"text":57},{"id":66,"depth":225,"text":67},{"id":79,"depth":225,"text":80},{"id":89,"depth":225,"text":90},{"id":99,"depth":225,"text":100},{"id":202,"depth":225,"text":203},"md",[237],{"slug":38,"concept":238,"style":239,"aspectRatio":240,"labels":241},"AWS network protection services placed along the path incoming traffic travels: Shield absorbs DDoS floods at the edge first, WAF inspects individual HTTP requests at Layer 7 next, and Network Firewall filters traffic once it is inside the VPC, while Firewall Manager sits above the whole path enforcing the same rules across every account in an AWS Organization. Firewall Manager carries the orange accent to set the central overseer apart from the three in-path filters. The takeaway is layered defense: each service stops a different kind of threat at a different point, and you often run them together.","diagram","16:9",[242,243,244,245],"Shield: absorbs DDoS at the edge","WAF: blocks web exploits at Layer 7","Network Firewall: filters traffic inside the VPC","Firewall Manager: same rules across every account",[13,14,15,16],{},"/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/04-security-services-and-resources/01-network-protection-services",{"passingScore":250,"questions":251},70,[252,261,266,272,282],{"question":253,"type":254,"options":255,"correctAnswer":256,"explanation":260},"Which statement about AWS Shield Standard is correct?","single",[256,257,258,259],"It is automatically enabled for all AWS customers at no extra cost","It must be purchased separately before it protects your resources","It only protects on-premises data centers, not AWS resources","It blocks SQL injection and cross-site scripting attacks","Shield Standard is on by default for every AWS account and costs nothing extra. It defends against the most common network and transport layer (Layer 3 and 4) DDoS attacks. Filtering SQL injection and cross-site scripting is the job of AWS WAF, not Shield.",{"question":262,"type":254,"options":263,"correctAnswer":159,"explanation":265},"A team needs to block SQL injection and cross-site scripting attempts against a public web application running behind CloudFront. Which service should they use?",[131,159,173,264],"Amazon Inspector","AWS WAF is a web application firewall that inspects HTTP and HTTPS requests and blocks common web exploits like SQL injection and cross-site scripting. Shield handles DDoS attacks, and Network Firewall filters traffic inside a VPC rather than web requests at the application layer.",{"question":267,"type":254,"options":268,"correctAnswer":270,"explanation":271},"AWS Shield Advanced is included automatically with every AWS account at no additional charge.",[269,270],"True","False","Shield Advanced is a paid subscription that adds protection against larger and more sophisticated DDoS attacks, near real-time attack visibility, and 24x7 access to the Shield Response Team. Only Shield Standard is free and automatic.",{"question":273,"type":274,"options":275,"correctAnswers":280,"explanation":281},"Which protections can AWS Firewall Manager centrally configure and enforce across multiple accounts? (Select all that apply.)","multiple",[276,277,278,279],"AWS WAF rules","AWS Shield Advanced protections","Amazon VPC security groups and network ACLs","The monthly AWS bill for each account",[276,277,278],"Firewall Manager applies a common set of protections across accounts in AWS Organizations, including AWS WAF, Shield Advanced, security groups, network ACLs, and AWS Network Firewall. It manages security policies, not billing.",{"question":283,"type":254,"options":284,"correctAnswer":286,"explanation":289},"What does AWS Network Firewall protect?",[285,286,287,288],"It manages SSL/TLS certificates for load balancers","It filters network traffic for the subnets in your Amazon VPCs","It scans EC2 instances for software vulnerabilities","It stores and rotates database passwords","AWS Network Firewall is a managed service that filters traffic at the VPC level, with stateful inspection, an intrusion prevention system, and web filtering. Certificate management is AWS Certificate Manager, vulnerability scanning is Amazon Inspector, and secret storage is AWS Secrets Manager.",{"title":7,"description":8},"courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/04-security-services-and-resources/01-network-protection-services","9sUGis0RTLT758zci4AfgicRcMpKKZHQJwIcebH0Srs",{"locked":9,"reason":294,"meta":295,"item":3},"paywall",{"title":296,"description":297,"isFree":5,"estimatedMinutes":298,"difficulty":11,"learningObjectives":299},"IAM Identity Center and Federation","See how AWS gives your workforce single sign-on across many accounts with IAM Identity Center, and how federation lets people use an existing identity provider to access AWS with temporary credentials.",15,[300,301,302,303],"Explain why IAM users do not scale well for human access across many accounts","Describe what AWS IAM Identity Center is and the access it provides","Identify the identity sources IAM Identity Center can use","Explain what identity federation is and how it grants temporary access",{"locked":9,"reason":294,"meta":305,"item":3},{"title":306,"description":307,"isFree":5,"estimatedMinutes":308,"difficulty":309,"learningObjectives":310},"AWS Threat Detection and Monitoring Services","Understand how Amazon GuardDuty, Amazon Inspector, Amazon Macie, AWS Security Hub, and Amazon Detective detect threats, find vulnerabilities, and investigate security findings.",18,"intermediate",[311,312,313,314,315],"Explain what Amazon GuardDuty monitors and the data sources it analyzes","Describe how Amazon Inspector finds software vulnerabilities","Identify what Amazon Macie discovers and protects","Compare the roles of AWS Security Hub and Amazon Detective","Match a security need to the right AWS detection service"]