Security, Identity & Compliance
Encrypting data with KMS, managing customer identities with Cognito, protecting web applications with WAF and Shield, and governing multi-account environments with Organizations.
AWS KMS & Encryption
intermediate~2hAWS's managed key management service — how encryption keys are created, controlled, and used across AWS services without you handling raw key material yourself.
Amazon Cognito
intermediate~2hManaged user authentication and identity for your applications — sign-up, sign-in, and temporary AWS credentials for end users, without building auth infrastructure yourself.
AWS WAF & Shield
intermediate~1.5hFiltering malicious web requests before they reach your application, and protecting against DDoS attacks at the network and application layers.
AWS Organizations & Service Control Policies
advanced~2hManaging many AWS accounts as one organization — centralized billing, and Service Control Policies that set permission guardrails no IAM policy within a member account can override.
ACM, STS & CloudHSM
advanced~2hThree security services that round out the AWS security toolkit: ACM for managed TLS certificates, STS for temporary credential vending, and CloudHSM for dedicated, single-tenant hardware security modules.
Advanced Threat Detection: GuardDuty, Macie & Security Hub
intermediate~3hThe three services that turn raw AWS activity logs and stored data into actionable security findings — continuous threat detection, sensitive-data discovery, and a single aggregated dashboard for both.