Designing Secure Workloads

Design secure workloads with VPC architecture, Security Groups, NACLs, WAF, and GuardDuty.

VPC security architecture is the foundation for nearly every SAA-C03 scenario. Understanding how to isolate networks and control traffic gets you halfway through most exam questions.

 

What Is a VPC?

Think of city planning. A VPC (Virtual Private Cloud) is a virtual city you build inside the AWS cloud. The city has different neighborhoods (subnets), each with its own entry rules.

The public subnet is like a commercial district — accessible from the outside. You place load balancers (ALB), NAT Gateways, and Bastion Hosts here.

The private subnet is like a residential neighborhood — not directly reachable from the internet. Your application servers (EC2) live here.

The isolated private subnet is the city vault — maximum security, no one enters without authorization. Your databases (RDS) go here.

This three-tier separation is the standard architecture pattern for SAA-C03.

 

Security Groups vs NACLs — Two Types of Firewalls

AWS gives you two traffic control tools. You must know the difference cold.

| Feature | Security Group | NACL | |---------|---------------|------| | Applied at | Instance (ENI) level | Subnet level | | State tracking | Stateful (responses auto-allowed) | Stateless (inbound and outbound set separately) | | Rule types | Allow rules only | Allow + Deny rules | | Rule evaluation | All rules evaluated together | Evaluated in numeric order, first match wins |

A common exam pattern: "block traffic from a specific IP address" — Security Groups have no Deny rules, so you must use a NACL.

The Stateful vs Stateless difference also matters. A Security Group (Stateful) automatically allows response traffic when you allow a request. A NACL (Stateless) requires you to configure inbound and outbound rules separately.

!Security Group versus NACL

Safely Accessing Private Servers

Private subnet EC2 instances cannot be reached directly from the internet via SSH. Two approaches exist.

The Bastion Host approach places a "jump server" in the public subnet. An administrator SSHs into the Bastion Host first, then hops from there to the private server. It is like requiring visitors to check in at the front desk before being escorted into the building.

AWS Systems Manager Session Manager is the modern approach. You do not need to open SSH port 22 at all. It uses IAM authentication to connect directly from the browser. Every session is automatically logged to CloudTrail for audit purposes.

Exam hint: "access EC2 without opening ports" or "EC2 access with audit trail" — choose Session Manager.

 

Threat Detection and Defense Services

AWS provides several services to detect and block attacks.

| Service | Role | Analogy | |---------|------|---------| | AWS WAF | Block web attacks like SQL injection and XSS | Security scanner at the building entrance | | AWS Shield Standard | Automatic DDoS protection (free) | Bulletproof exterior walls | | AWS Shield Advanced | Advanced DDoS protection plus AWS support (paid) | Professional security team | | Amazon GuardDuty | Automatically detects threats by analyzing VPC Flow Logs and CloudTrail | 24-hour AI-powered CCTV analysis | | Amazon Inspector | Automatically scans EC2 and Lambda for vulnerabilities | Building safety inspection service |

GuardDuty activates with a single click and analyzes logs automatically to detect suspicious activity. No agent installation is needed.

 

VPC Endpoints — Access AWS Services Without the Internet

A private subnet EC2 instance normally needs to go through the internet to reach S3. VPC endpoints let it stay on the AWS internal network the entire time.

Gateway endpoints work only with S3 and DynamoDB. They add an entry to your route table and are free of charge.

Interface endpoints (PrivateLink) work with other AWS services like EC2 API, Kinesis, and SQS. They create an ENI (Elastic Network Interface) inside your VPC and do incur a cost.

Exam hint: "access S3 without internet gateway" — Gateway endpoint. "access other AWS services without internet" — Interface endpoint (PrivateLink).

 

Exam Key Points

"Block a specific IP address" — NACL (Security Groups have no Deny rules)

"Access EC2 without opening SSH port, with audit trail" — Session Manager

"Jump server in the public subnet" — Bastion Host

"Block SQL injection and XSS for web application" — AWS WAF (placed in front of CloudFront or ALB)

"Automatic threat detection from VPC logs" — Amazon GuardDuty

"Automatic vulnerability scanning for EC2 and Lambda" — Amazon Inspector

"Access S3 without internet" — VPC Gateway Endpoint (free)

"Access other AWS services without internet" — VPC Interface Endpoint (PrivateLink)

"Private subnet needs outbound internet access" — NAT Gateway (placed in the public subnet)

Back to blog list