Phase 89 modules

Security & Compliance

Security is a lens applied at every layer. KMS encryption, secrets management, WAF, Shield, GuardDuty, CloudTrail, and Config.

Modules in This Phase

Module 52

Module 52: AWS Organizations & Control Tower

A single AWS account is a single blast radius. If an attacker compromises credentials in that account, every resource is reachable. If a developer accidentally deletes a production database, nothing prevented it. If a runaway process spins up expensive instances, the same billing boundary absorbs th

Lesson Lab Quiz Resources
Module 53

Module 53: Encryption with AWS KMS

Encryption transforms readable data (plaintext) into unreadable data (ciphertext) using a cryptographic key. Without the corresponding decryption key, the ciphertext is computationally infeasible to reverse.

Lesson Lab Quiz Resources
Module 54

Module 54: Secrets Management

Every application needs credentials to access external systems: database passwords, API keys, OAuth tokens, SSH keys, TLS private keys. The question is where those credentials live at runtime.

Lesson Lab Quiz Resources
Module 55

Module 55: Certificate Management with ACM

Transport Layer Security (TLS, the successor to SSL) encrypts data in transit between a client and a server. Without TLS, all data including credentials, personal information, and session tokens travels across the network in plaintext. Any intermediary (ISP, network operator, attacker on the same Wi

Lesson Lab Quiz Resources
Module 56

Module 56: AWS WAF

Your web applications face a constant barrage of automated attacks. SQL injection bots probe your login forms. Credential stuffing tools replay stolen username/password pairs against your authentication endpoints. Scrapers consume your API rate limits. Reconnaissance scanners map your attack surface

Lesson Lab Quiz Resources
Module 57

Module 57: AWS Shield

A Distributed Denial of Service (DDoS) attack is not a sophisticated exploit. It is brute force. An attacker coordinates thousands or millions of compromised machines to send traffic to your application simultaneously, overwhelming your infrastructure's capacity to respond to legitimate requests.

Lesson Lab Quiz Resources
Module 58

Module 58: Threat Detection: GuardDuty & Inspector

Prevention fails. No matter how rigorous your security controls, eventually someone will misconfigure an IAM policy, a credential will leak into a public repository, or a zero-day vulnerability will be exploited before a patch is available. The question is not whether a security incident will happen

Lesson Lab Quiz Resources
Module 59

Module 59: Audit & Compliance: CloudTrail & Config

Two questions dominate every security investigation and compliance audit:

Lesson Lab Quiz Resources
Module 60

Module 60: Security Hub & Governance

Individual security services generate findings in isolation. GuardDuty detects threats. Inspector finds vulnerabilities. Config identifies misconfigurations. Firewall Manager reports policy violations. Each service has its own console, its own finding format, and its own severity scale.

Lesson Lab Quiz Resources

Phase 8 Exam

Test your knowledge of all 9 modules in this phase. 25 questions, 70% required to pass.

60–90 minutes25 questions70% passing
Take the Exam