Cloud Practitioner
Security, identity and compliance
The shared responsibility model, IAM, MFA, KMS, WAF, Shield, GuardDuty, Artifact and the compliance vocabulary CLF-C02 expects.
Foundational notes for AWS Certified Cloud Practitioner (CLF-C02). Read them in order the first time through, then use them as a revision sweep before you book.
15 study points. Everything here is exam-oriented: each point is a fact or a distinction that CLF-C02 items are built on. Test yourself against the practice exam once you can explain a section without re-reading it.
Security
AWS Identity and Access Management (IAM) is a global service, meaning it is not tied to any specific Region. When you create a user, group, role, or policy in IAM, it is available across all AWS Regions automatically. IAM is the first service you interact with when setting up your AWS account, and understanding it deeply is critical. Every action you take in AWS is governed by IAM permissions, making it the foundation of your entire security posture.
The Shared Responsibility Model is one of the most important concepts in AWS security. AWS is responsible for the security “of” the cloud, meaning the physical infrastructure, networking, and hypervisor. You, the customer, are responsible for security “in” the cloud, meaning your data, applications, IAM configurations, and operating system patches. For IaaS services like EC2 and VPC, you are entirely responsible for security from the operating system level up. For managed services like RDS, AWS handles more of the stack.
The Principle of Least Privilege states that every user, role, and application should have only the minimum permissions necessary to perform their job. For example, a developer who only needs to read logs from CloudWatch should not have permission to delete EC2 instances. In IAM, you implement this by creating granular policies and assigning them to groups rather than individual users. Starting with zero permissions and adding only what is needed is far safer than starting with broad access and trying to restrict it later.
IAM Policies are written in JSON format and define what actions are allowed or denied on which AWS resources. A policy consists of statements, each containing an Effect (Allow or Deny), an Action (like s3
), and a Resource (like a specific S3 bucket). You attach policies to users, groups, or roles. Understanding how to read and write IAM policies is essential because misconfigured policies are one of the most common causes of security incidents in the cloud.It is always safer to use IAM Roles than access keys. Access keys are long-term credentials that, if leaked, can be used to access your AWS resources indefinitely. IAM Roles, on the other hand, provide temporary credentials that automatically expire. For example, instead of embedding access keys in an EC2 instance to call S3, you assign an IAM Role to the instance. The instance receives temporary credentials that rotate automatically. You should never store access keys in your application code.
To secure your root account, follow these best practices: enable Multi-Factor Authentication (MFA), delete the root access keys, create individual IAM users for daily operations, use groups to assign permissions, and apply a strong IAM password policy. The root user has unrestricted access to everything in your AWS account and should never be used for routine tasks. Even the account owner should create a separate IAM user for day-to-day work and reserve the root account for rare administrative actions.
AWS WAF (Web Application Firewall) protects your web applications from common exploits like SQL injection and cross-site scripting. It operates at Layer 7 of the OSI model, meaning it inspects HTTP and HTTPS traffic. AWS Shield is a separate service that provides managed DDoS (Distributed Denial of Service) protection. Shield Standard is free and protects against common network-layer attacks, while Shield Advanced offers additional protection, automated application-layer (Layer 7) monitoring, and 24/7 access to the AWS DDoS Response Team.
The Security pillar of the AWS Well-Architected Framework includes five key areas: IAM (identity and access management), Detective Controls (monitoring and alerting on security events), Infrastructure Protection (securing your network and compute resources), Data Protection (encrypting data at rest and in transit), and Incident Response (planning for and responding to security events). Together, these areas form a comprehensive approach to cloud security.
To restrict access to an entire S3 bucket, use Bucket Policies. To restrict access to an individual object within a bucket, use Access Control Lists (ACLs). For example, if you want to make your entire static website bucket publicly readable, a bucket policy is the right tool. But if you need to grant a specific user access to one particular file, an ACL is more appropriate. In practice, AWS now recommends disabling ACLs and using bucket policies and IAM policies for all access control.
AWS Inspector is a security assessment service that automatically analyzes EC2 instances against predefined security templates and best practices. It checks for common vulnerabilities, unintended network exposure, and deviations from security benchmarks like CIS. After a scan, Inspector produces a detailed findings report with prioritized recommendations. This is a detective control that helps you identify and remediate security issues before they are exploited.
Authentication and authorization are two distinct steps in the security process. Authentication verifies who you are (for example, by checking your username and password or MFA token). Authorization determines what you are allowed to do (for example, whether you can read from an S3 bucket or launch an EC2 instance). In AWS, authentication happens first through IAM credentials, and then IAM policies determine your authorization. Understanding this sequence helps you troubleshoot access denied errors.
AWS compliance programs help you meet regulatory requirements. PCI DSS Level 1 certification is required for organizations processing credit card transactions. HIPAA compliance is essential for handling protected health information (medical records) in the United States. AWS services are already PCI DSS compliant at the infrastructure level, but you are still responsible for configuring your applications to meet compliance standards. The AWS Risk and Compliance Program covers risk management, control environment, and information security.
By default, all subnets within a VPC can communicate with each other. Security Groups act as virtual firewalls at the instance level, controlling inbound and outbound traffic. Network ACLs operate at the subnet level and provide an additional layer of defense. Security Groups are stateful (if you allow inbound traffic, the response is automatically allowed out), while Network ACLs are stateless (you must explicitly allow both inbound and outbound). Layering both provides defense in depth.
Amazon S3 Glacier automatically encrypts all data at rest using AES-256 encryption. This means your archived data is protected without any additional configuration on your part. For other services, you can enable encryption using AWS Key Management Service (KMS), which lets you create and manage encryption keys. Encrypting data at rest and in transit is a best practice that protects sensitive information even if physical storage media is compromised.
Decoupling is a design principle that reduces inter-dependencies between components of your application. Instead of having services call each other directly, you place a message queue (like SQS) or an event bus (like EventBridge) between them. If one component fails or slows down, the others continue operating independently. This makes your architecture more resilient, easier to scale, and simpler to maintain. Decoupling is a core principle of well-architected cloud applications.
Where to go next
- Back to the AWS Cloud Practitioner overview.
- Look up any service you could not name in the AWS services glossary.
- Sit the 80-item practice exam once two or three note pages are solid.
Last updated Sep 18, 2026