The security domain of DOP-C02 carries the highest weight across the exam. Rather than memorizing service features, you must be able to design "which security control to apply at which layer of this architecture." This is the essence of defense-in-depth.
IAM at Scale
CodeBuild Service Role and Least Privilege
Consider a CodeBuild project that retrieves artifacts from S3 and pushes images to ECR. The CodeBuild Service Role should only receive the minimum necessary permissions: , , , , and others that are strictly required.
Common exam trap: any answer suggesting AdministratorAccess for CodeBuild is obviously wrong. The principle of least privilege is the core security mindset for DOP-C02.
S3 Mountpoint Cross-Account IAM
When mounting a cross-account S3 bucket to an EC2 instance using S3 Mountpoint, two configurations are both required. First, the IAM role attached to the EC2 instance must have a policy allowing cross-account S3 access. Second, the S3 bucket policy in the other account must explicitly allow the IAM role from your account.
Both the S3 bucket policy and the IAM policy must Allow access. If either has an explicit Deny, access is blocked.
IAM Identity Center and Organization Security
Running dozens of member accounts in an AWS Organizations environment and creating IAM users in each account is a management nightmare. IAM Identity Center (formerly SSO) provides centralized integrated authentication with a single entry point to access multiple accounts and applications.
| Aspect | IAM Users | IAM Identity Center | |--------|-----------|---------------------| | Management location | Distributed per account | Centralized | | Authentication | Username/password + MFA | IdP federation (SAML 2.0) | | Permission assignment | Per-account policies | Permission Sets | | Audit | CloudTrail per account | Centralized CloudTrail |
SCPs (Service Control Policies) restrict the maximum scope of permissions at the root or OU level of the organization. The critical point is that SCPs do not grant permissions; they set the upper bound of permissible permissions. Even if an IAM policy in a member account allows access, if the SCP denies it, access is blocked.
Permission Boundaries limit the maximum permissions that can be granted to an IAM role. You can delegate role creation to development teams while using Permission Boundaries as guardrails to ensure certain permissions (such as IAM management access or production S3 bucket access) can never be granted.
Secrets Manager Automatic Credential Rotation
You stored RDS credentials in Secrets Manager and enabled 30-day automatic rotation. Now some applications are experiencing intermittent DB connection errors. What is the cause?
The problem is that the application queries Secrets Manager only once at startup, caches credentials in memory, and never refreshes them. When new credentials are rotated after 30 days, the cached old credentials become invalid.
The solution: implement logic to call again on connection failure or at regular intervals to obtain the latest credentials. Using the AWS SDK caching library enables TTL-based automatic refresh with minimal code changes.
Security Controls and Data Protection
S3 + CloudFront + WAF Architecture
How do you host a static frontend web application while defending against SQL injection and XSS attacks, with no EC2 server management, and delivering low latency to global users?
S3 static website hosting + CloudFront + AWS WAF is the answer. S3 hosts static files serverlessly, CloudFront caches content at 400+ edge locations for low-latency global delivery, and AWS WAF integrates with CloudFront to block SQL injection and XSS at every edge location.
When do you use ALB + WAF + ACM? For dynamic web applications with EC2 instances when you want to terminate TLS without EC2 CPU overhead, block L7 attacks with WAF, and automate certificate renewal with ACM.
CloudFront Custom Origin HTTPS Requirements
When CloudFront is configured with an on-premises server as a custom origin and 502 errors appear, the first thing to suspect is the certificate. CloudFront validates that the origin's certificate was issued by a public CA when making HTTPS connections to custom origins. Self-signed certificates fail this validation.
ACM certificates are exclusive to AWS services and cannot be installed directly on on-premises servers. Install a certificate from a public CA like Let's Encrypt or DigiCert on the origin server. Set the origin protocol policy to HTTPS Only to maintain end-to-end encryption.
CloudFront end-to-end HTTPS certificate configuration summary:
| Segment | Certificate Location | Requirement | |---------|---------------------|-------------| | Viewer to CloudFront | us-east-1 ACM certificate | Must be us-east-1 region | | CloudFront to ALB | ALB region ACM certificate | Same region as ALB | | CloudFront to on-premises | Public CA cert installed on server | Self-signed not allowed |
WAF Rule Combination — Country Block + IP Allowlist + Web Attack Defense
Blocking a specific country while allowing an internal team IP from that country, plus defending against SQL injection, can all be implemented in a single WAF Web ACL.
WAF rule priority (lower number = evaluated first): (Lower number) IP Set Allow — ALLOW the internal IP range first (Higher number) Geo Match Block — BLOCK the specific country AWS Managed Rules — Block SQL injection and XSS
Because rule 1 is evaluated before rule 2, even users from the blocked country pass through if their IP is on the allowlist.
AWS Firewall Manager automatically applies WAF policies across the entire organization and auto-connects WAF Web ACLs to newly created ALBs and API Gateways within minutes. The difference from Config auto-remediation: Config detects non-compliance then remediates, while Firewall Manager attaches instantly on creation, leaving no security gap.
Egress-Only Internet Gateway — IPv6 Outbound Only
Sometimes a private subnet EC2 instance needs to communicate with an IPv6-only external API, but inbound IPv6 connections from the internet must not be allowed.
This is exactly what Egress-Only Internet Gateway is for. It is the IPv6 equivalent of NAT Gateway. It allows only the responses to outbound connections initiated by the instance and blocks inbound connections statefully.
Prerequisites: enable an IPv6 CIDR block on the VPC, assign IPv6 addresses on the subnet, add to the routing table.
Security Monitoring and Auditing
EventBridge + CloudTrail AssumeRole Detection
Monitoring cross-account role assumption (AssumeRole) in a multi-account environment is the foundation of privilege escalation detection. Configure an architecture where EventBridge detects CloudTrail events and triggers notifications. This is particularly useful for detecting role assumptions from unexpected accounts or identifying abnormal patterns.
Amazon Inspector v2 — SSM Agent-Based CVE Scanning
Amazon Inspector v2 automatically evaluates OS package vulnerabilities (CVEs) and network accessibility on EC2 instances. Inspector v2 supports agentless scanning through SSM Agent without installing additional agents. Once enabled, it continuously and automatically evaluates all EC2 instances and ECR images.
Inspector vs GuardDuty distinction:
| Service | What it monitors | Event Source | What it detects | |---------|-----------------|-------------|----------------| | Amazon Inspector | EC2, Lambda, ECR | Vulnerability DB (CVE) | Software vulnerabilities, network exposure | | Amazon GuardDuty | Account, VPC, IAM | VPC Flow Logs, CloudTrail, DNS | Malicious behavior, abnormal API calls | | Amazon Macie | S3 buckets | ML + pattern matching | Sensitive data (PII) classification, anomalous access |
GuardDuty — Automated Threat Response
When a GuardDuty Finding is generated, EventBridge detects it immediately. You can design automated responses for each finding type.
Example scenario: cryptocurrency mining pattern detected on EC2 instance → EventBridge → Lambda → configure the instance's security group to isolate it (block all inbound/outbound).
Exposed IAM access key detected → EventBridge → Lambda → call → SNS notification.
AWS Config + SSM Automation — Continuous Compliance Auto-Remediation
The combination of Config rules + SSM Automation Runbook implements "auto-remediation immediately on detection."
Usage examples: Automatically terminate instances running unapproved AMIs ( managed rule) Automatically make public S3 buckets private Automatically remove SSH 0.0.0.0/0 security group rules
The role distinction between Macie and Config must be clear. Macie analyzes the content of data stored in S3, classifying sensitive data like PII and detecting anomalous access patterns. Config evaluates whether the configuration settings of resources comply with policies. Config handles public S3 bucket detection; Macie handles locating sensitive data inside S3.