Domain

Security and Compliance

Control who can do what, and prove it: IAM policies and roles, access troubleshooting, Organizations and SCPs, compliance with AWS Config and Trusted Advisor, encryption with KMS and ACM, secrets management, and threat detection with GuardDuty and Security Hub.

A developer cannot write to an S3 bucket and nobody can say why. The role's IAM policy looks correct, so the answer sits somewhere else: a permissions boundary, an SCP at the organization level, a bucket policy, or a KMS key policy that never granted decrypt. Knowing where an authorization decision actually gets made, and proving afterward that it was the right one, is what this domain builds.

It carries 16% of SOA-C03, the smallest weight of the five domains and the easiest to underestimate. Security failures do not stay in their own lane: an instance that cannot reach S3, a Lambda function that fails on a KMS call, and a stack that rolls back on AccessDenied all look like problems in other domains until you follow the policy path.

What This Domain Covers

  • IAM users, groups, roles, and policy types, including when a role replaces a long-lived access key
  • How AWS evaluates a request: explicit deny, allow, permissions boundaries, SCPs, and condition keys
  • MFA, identity federation, root account protection, and credential hygiene
  • Diagnosing a denied action with IAM Access Analyzer, the policy simulator, last-accessed data, and CloudTrail
  • AWS Organizations and service control policies, plus centralized workforce access with IAM Identity Center
  • Continuous compliance with AWS Config rules and conformance packs, and acting on Trusted Advisor checks
  • Data classification with Macie, encryption at rest with KMS, TLS certificates with ACM, and secrets in Secrets Manager and Parameter Store
  • Threat detection with GuardDuty and Inspector, and finding aggregation with automated response in Security Hub

Why It Matters

Exam questions here rarely ask what IAM is. They hand you a denied API call with four plausible causes, or a compliance requirement that several services could satisfy, and ask which one fits. Answering means holding the boundaries: Config records configuration drift while GuardDuty watches behavior, and Inspector scans for vulnerabilities while Security Hub aggregates what the others find.

On the job the asymmetry is what makes this domain matter. A permission that is too narrow costs you an outage and an annoyed team. One that is too broad costs you the account, and you often find out months later from a GuardDuty finding.

Topics in this domain

Send us a message

Have a question about a course, a partnership, or the product? Drop us a line, we reply by email.

We reply within 2 business days.

© 2026 Syllaro Academy. All rights reserved.