ANS-C01: AWS Advanced Networking, Part 7 of 9: Security Compliance and Optimization
with expert Zeal Vora
Course description
The AWS Certified Advanced Networking - Specialty is intended for individuals who perform complex networking tasks. The user will be able to Design, develop, and deploy cloud-based solutions using AWS as well as maintain Network Architecture across all AWS services.
The exam certification tests on 4 knowledge domains.
Domain 1: Network Design 30%
Domain 2: Network Implementation 26%
Domain 3: Network Management and Operation 20%
Domain 4: Network Security, Compliance, and Governance 24%
This course covers: IAC, CloudFormation, Penetration testing, DOS Attacks, AWS Configuration, Security Groups, Prefix lists and Regaining Access.
Prerequisites
AWS Cloud Practitioner or another Associate level AWS Certification
Minimum five years hands-on experience architecting and implementing network solutions
Meet the expert
Zeal works primarily as a Cloud Security Consultant guiding organizations to re-build their infrastructure with security in mind. Zeal also holds more then 13+ certifications ranging from RedHat Certified Architect to AWS Security.
Course outline
Module 12
IAC (38:27)
- Introduction (00:08)
- IAC (11:40)
- CloudFormation - Creating VPC (09:47)
- CloudFormation - Stack Depedencies (06:41)
- CloudFormation - DependsOn Attribute (10:01)
- Summary (00:08)
CloudFormation (34:19)
- Introduction (00:08)
- CloudFormation - Errors and Rollbacks (08:26)
- CloudFormation - Change Sets (06:16)
- CloudFormation - Parameters (04:50)
- CloudFormation - StackSets.mp4 (06:03)
- Elatic Beanstalk (08:27)
- Summary (00:08)
Module 13
Penetration Testing (34:58)
- Introduction (00:08)
- Penetration Testing in AWS (05:09)
- CloudTrail (07:49)
- CloudTrail Practical (06:55)
- CloudTrail Event Types (07:50)
- CloudTrail Log File Integrity Validation (06:56)
- Summary (00:08)
AWS Configuration (26:24)
- Introduction (00:08)
- AWS Config NE (12:01)
- AWS Config Practical NEW2 (14:07)
- Summary (00:08)
DOS Attack (41:06)
- Introduction (00:08)
- DOS attack demo (08:20)
- Mitigating DDOS (09:50)
- NACL (09:40)
- NACL Rule Ordering (13:00)
- Summary (00:08)
Module 14
Referencing Security Group (52:52)
- Introduction (00:08)
- Referencing Security Group (11:02)
- Stateful vs Stateless Firewalls (11:55)
- Network Firewall Overview (08:53)
- Network Firewall Practical (20:45)
- Summary (00:08)
AWS Guard Duty (39:28)
- Introduction (00:08)
- AWS Guard Duty (09:44)
- Central Guard Duty Findings (05:41)
- Active Directory - Integration (04:13)
- AWS Directory Service (08:41)
- Domain Join EC2 with Simple AD (10:51)
- Summary (00:08)
Module 15
Prefix Lists (44:57)
- Introduction (00:08)
- Prefix Lists (05:59)
- EC2 Instance Metadata (07:44)
- AWS KMS CP (05:37)
- S3 Encryption (13:11)
- S3 Bucket Policy (12:09)
- Summary (00:08)
Regaining Access (35:50)
- Introduction (00:08)
- Regaining Access to Locked S3 Bucket (05:08)
- Trusted Advisor (06:58)
- Federation (12:44)
- SAML (10:42)
- Summary (00:08)
Module 16
AWS SSO (14:39)
- Introduction (00:08)
- AWS SSO (06:17)
- Implementing AWS SSO (08:06)
- Summary (00:08)
Benchmarking and Optimizing (38:18)
- Introduction (00:08)
- Network Interface Card Basics (02:50)
- Elastic Network Interface (09:46)
- Enhanced Networking (14:18)
- Management Network (03:54)
- QoS (07:11)
- Summary (00:08)