Ravindra BagaleCourses & study guides

30. Cloud and AWS Security

Chala mitrano, Chapter 12 te 16 madhe tumhi AWS var EC2, S3, RDS vaprun purna app chalavla. Aata prashna asa: te surakshit aahe ka? Cloud madhe sarvat jast breaches hack mule nahi, tar chukichya settings mule hotat – public S3 bucket, GitHub var takleli access key, sagalyasathi open security group. Ya chapter madhe AWS cha "Shared Responsibility Model" samjun ghevu, ani tumchya account la step-by-step lock karu. Ghabru naka, he sagle console madhe kahi clicks che kaam aahe. Samjla ka? Chala!

What you will learn in this chapter

  • The Shared Responsibility Model: what AWS secures and what you secure
  • IAM done right: root account, MFA, least privilege, roles instead of keys
  • Network security: security groups, NACLs, private subnets
  • Data protection: S3 Block Public Access, encryption with KMS, secrets
  • Detection: CloudTrail, GuardDuty, AWS Config and Security Hub
  • EC2 metadata (IMDSv2) and SSRF, plus an incident checklist for leaked keys

Scope for this chapter

Work only in your own AWS account. Testing someone else's cloud account, bucket or instance without written permission is illegal. Watch the Free Tier: turn off paid services (GuardDuty, Config, Security Hub trials) after the lab if you do not need them, and keep a billing alarm on (Chapter 12).

Concepts in this chapter

  1. 30.1The Shared Responsibility Model
  2. 30.2IAM Done Right
  3. 30.3Network Security in AWS
  4. 30.4Protecting Data: S3, Encryption and Secrets
  5. 30.5Detection: CloudTrail, GuardDuty, Config and Security Hub
  6. 30.6EC2 Metadata, SSRF and a Leaked-Key Incident Checklist
  7. 30.7Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.