Key AWS Security Services at a Glance
The AIF-C01 exam asks a simple question about security: "Which service solves this problem?" Pair each service with the problem it solves and scenario questions become straightforward.
---
IAM — Identity and Access Management
IAM controls who can access AWS resources, like an access-card system for a building.
| Component | Plain Explanation | |-----------|-------------------| | Users | Individual people with unique credentials | | Groups | Collections of users sharing similar permissions | | Roles | Temporary permissions for services or apps (e.g., EC2 accessing S3) | | Policies | JSON documents defining allow/deny rules |
Least Privilege Principle: grant only the permissions actually needed — nothing more.
---
Amazon S3 — Object Storage
S3 stores any type of file with 99.999999999% durability (11 nines) — same across all storage classes.
Storage classes by access frequency: Standard: frequent access, highest cost Standard-IA: infrequent access, retrieval fee applies Glacier Instant/Flexible/Deep Archive: archival tiers, increasing retrieval time Intelligent-Tiering: auto-moves data based on access patterns
---
EC2 vs Lambda
| Feature | EC2 | Lambda | |---------|-----|--------| | Server management | Manual | None needed | | Execution | Always running | Event-triggered only | | Scaling | Manual or auto-configured | Fully automatic | | Billing | Per hour running | Per execution time |
---
5 Security Monitoring Services
Macie: detects PII and sensitive data in S3 using ML Config: tracks configuration changes and evaluates compliance Inspector: scans EC2, containers, Lambda for known vulnerabilities CloudTrail: records every API call — first place to check after a security incident Artifact: provides compliance reports and certifications for download
---
VPC and Private Connectivity
VPC creates an isolated private network inside AWS. Key components: public subnet, private subnet, Internet Gateway, NAT Gateway. Use VPC Endpoints and PrivateLink to connect to AWS services without going over the public internet.
---
Exam Quick Reference
IAM = access control + least privilege S3 = object storage, 11 nines durability for all classes Macie → PII detection; Config → config change tracking; Inspector → vulnerability scanning CloudTrail → audit all API calls (check first in security incidents) Security flow: "Who accessed?" (IAM) → "What did they do?" (CloudTrail) → "Is config safe?" (Config) → "Any vulnerabilities?" (Inspector)