Security Services & Compliance

AWS Config rules, GuardDuty threat detection, KMS encryption, and Security Hub explained with real-life analogies for beginners.

This guide explains AWS security services from the ground up, with everyday analogies to help absolute beginners understand not just what each service does, but why it exists and how it works. The Security & Compliance domain is the largest on the SOA-C03 exam with 63 questions.

 

AWS Config — The Security Camera System for Your AWS Account

Imagine you manage a convenience store. You need every shelf arrangement, safe lock status, and refrigerator temperature to always follow company rules. If someone changes something they shouldn't, you need to know immediately.

AWS Config does exactly this for your AWS resources. Every time a resource configuration changes — an S3 bucket becomes public, a security group gets a new rule, an RDS instance loses its encryption — AWS Config records it and alerts you if it violates your defined rules.

Here is what Config tracks in practice. If an S3 bucket suddenly becomes publicly accessible, Config detects it instantly. If someone adds a 0.0.0.0/0 inbound rule to a security group, Config flags it. You can view a complete timeline showing who changed what and when for every resource.

 

Config Rules — Automated Compliance Checking

Config Rules are like automated quality inspectors that continuously check whether your resources follow the rules you define. There are two types.

| Rule Type | Description | Example | |-----------|-------------|---------| | AWS Managed Rules | Pre-built rules from AWS | s3-bucket-public-read-prohibited | | Custom Rules | Rules you write using Lambda | EC2 instances must have an "Owner" tag |

Here is a real scenario to make this concrete. You run an online shopping platform and your security policy requires all databases to be encrypted. You create a Config rule called rds-storage-encrypted. Every time a new RDS instance is created, Config automatically checks whether encryption is enabled. If it is not, the resource immediately shows as Non-Compliant and you receive an alert.

 

Conformance Packs — Compliance Template Bundles

Companies in finance, healthcare, or retail must comply with regulations like PCI-DSS, HIPAA, or CIS Benchmark. Each regulation has dozens of security requirements. Creating Config rules for each one individually would be tedious.

A Conformance Pack bundles many related Config rules into a single deployment package. Think of it as an employee onboarding checklist that activates all required rules at once. AWS provides pre-built conformance packs for PCI-DSS, HIPAA, and CIS Benchmark so you do not have to build them from scratch.

 

Auto Remediation — Automatic Self-Healing

Auto Remediation takes Config one step further. When a rule violation is detected, AWS automatically fixes the problem without any human intervention. Internally, it uses AWS Systems Manager Automation documents to carry out the fix.

Practical examples of what this looks like in action. A public S3 bucket is detected and Config automatically applies the block-public-access setting. An unencrypted EBS volume is found and encryption is automatically enabled. A dangerous security group rule appears and it is automatically deleted.

This is especially valuable at 3am when no one is monitoring the console. Security issues get resolved automatically even while your team sleeps.

 

AWS Security Hub — The Mission Control Center

When you use multiple AWS security services, you need to check GuardDuty, Inspector, and Config consoles separately. Security Hub solves this by aggregating all security findings into a single unified dashboard.

Think of it as a city-wide surveillance center where feeds from every CCTV camera (GuardDuty), building inspection reports (Inspector), and compliance dashboards (Config) all appear on one screen.

Security Hub consolidates findings from these services: GuardDuty threat detections, Inspector vulnerability scan results, AWS Config compliance status, Firewall Manager policy findings, and IAM Access Analyzer permission findings.

It also automatically scores your environment against security standards like CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices, giving you a clear picture of your overall security posture.

 

Amazon GuardDuty — The Always-On Security Guard

GuardDuty automatically detects malicious activity in your AWS environment. Think of it as a security guard who watches your apartment complex 24 hours a day, seven days a week, without ever taking a break.

The biggest advantage of GuardDuty is that you just enable it and it starts working immediately. No agents to install, no complex configuration needed. It analyzes three data sources automatically.

VPC Flow Logs analysis catches abnormal network traffic patterns. For example, if an EC2 instance suddenly starts sending large amounts of data to an unknown external IP address at 2am, GuardDuty raises an alert. This pattern suggests a compromised instance leaking data to a hacker's server.

CloudTrail event analysis detects unusual API call patterns. If a particular IAM user suddenly tries to create hundreds of EC2 instances in the middle of the night, that is a red flag. Hackers who steal credentials often do this to run cryptocurrency mining operations at the victim's expense.

DNS log analysis catches communication with malicious domains. If an EC2 instance tries to contact a known malware command-and-control server, GuardDuty immediately raises an alert and can trigger an automated response.

 

Amazon Inspector — Regular Health Checkups for Your Infrastructure

Inspector automatically scans EC2 instances, Lambda functions, and ECR container images for software vulnerabilities and unintended network exposure. Just as you go for annual health checkups to catch problems before they become serious, Inspector finds weaknesses in your infrastructure before attackers exploit them.

If your server runs an old version of OpenSSL with a known vulnerability, hackers can use that weakness to break in. Inspector continuously compares your software against the CVE (Common Vulnerabilities and Exposures) database and alerts you to any matches.

Remember the key difference between GuardDuty and Inspector. GuardDuty detects active threats happening right now, like an attacker who is currently probing your systems. Inspector finds potential vulnerabilities that could be exploited in the future, like outdated software that has not been patched yet.

 

AWS Trusted Advisor — Your Personal AWS Consultant

Trusted Advisor is like having an AWS expert continuously review your environment and suggest improvements. It checks five areas.

| Area | Example Recommendation | |------|----------------------| | Cost Optimization | Terminate EC2 instances that have been idle for over 14 days | | Performance | EBS throughput approaching its limit — consider upgrading | | Security | Root account has no MFA enabled — enable immediately | | Fault Tolerance | EC2 instances deployed in only one AZ — add multi-AZ | | Service Limits | EC2 instance count is approaching your account limit |

The free tier provides only basic checks. Business or Enterprise Support plans unlock the full set of Trusted Advisor checks.

 

AWS KMS — The Key Vault for Your Data

KMS (Key Management Service) manages the cryptographic keys used to encrypt your data. Think of it as a high-security vault that stores your master keys. The vault itself has multiple locks, alarms, and security guards, so your keys are far safer here than anywhere else.

Why is this necessary? Suppose you store customer personal information in S3. If someone gains unauthorized access to the S3 bucket, what happens? If the data is encrypted with a KMS key, they see only meaningless gibberish. Without the key, the data is worthless.

Key concepts to understand. A CMK (Customer Master Key) is your primary encryption key in KMS. You can use AWS Managed Keys (AWS handles everything automatically) or Customer Managed Keys (you create and control them yourself). Enabling automatic key rotation causes the key material to be replaced every year, like periodically changing locks to improve security. KMS integrates with S3 (SSE-KMS), EBS volumes, RDS, Secrets Manager, and many other services.

 

AWS Certificate Manager (ACM) — Free Padlocks for Your Website

You have probably noticed that some websites start with https:// and show a padlock icon. That padlock means the connection is encrypted using SSL/TLS, so data travels securely between your browser and the server. ACM provides these SSL/TLS certificates for free and manages them automatically.

When you do online banking, your account information is encrypted as it travels across the internet. Even if someone intercepts the transmission, they cannot read the contents. This is encryption in transit.

ACM certificates integrate with ALB (Application Load Balancer), CloudFront, and API Gateway. Certificate renewal happens automatically, so you never worry about expiration causing downtime.

 

Encryption at Rest vs Encryption in Transit

You must clearly understand these two encryption concepts.

| Type | Encryption at Rest | Encryption in Transit | |------|-------------------|----------------------| | What it protects | Data stored on disk | Data moving over a network | | Services | KMS, S3 SSE, EBS encryption, RDS encryption | ACM, TLS/SSL, HTTPS | | Analogy | Documents locked in a safe | A sealed envelope in the mail | | When it matters | If physical storage is stolen or accessed without authorization | Defending against eavesdropping and man-in-the-middle attacks |

!Encryption at rest versus in transit

AWS CloudTrail — The Complete Audit Log

CloudTrail records every API call made in your AWS account. Who did it, when they did it, what resource they touched, and where the request came from — all of it is logged.

Back to blog list