Domain 4: Security and Compliance (16% of the exam content) - AWS Certification

Domain 4: Security and Compliance (16% of the exam content)

This domain accounts for 16% of the exam content.

Task 4.1: Implement and manage security and compliance policies

  • Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, SAML, federated identity, resource policies, policy conditions).

  • Troubleshoot and audit access issues by using services (for example, CloudTrail, IAM Access Analyzer, IAM policy simulator).

  • Validate service control policies (SCPs) and permissions boundaries.

  • Review Trusted Advisor security checks.

  • Validate Region and service selections based on compliance requirements.

  • Implement secure multi-account strategies (for example, Control Tower, Organizations).

Task 4.2: Implement data and infrastructure protection strategies

  • Enforce a data classification scheme.

  • Create, manage, and protect encryption keys.

  • Implement encryption at rest (for example, Key Management Service [ KMS]).

  • Implement encryption in transit (for example, Certificate Manager [ACM], VPN).

  • Securely store secrets by using services (for example, Secrets Manager, Systems Manager Parameter Store).

  • Review reports or findings (for example, Security Hub, Amazon GuardDuty, Config, Amazon Inspector).