AWS security for DevOps engineers
Not a certification course — the working subset: an IAM mental model that scales past ten engineers, roles and boundaries, OIDC from CI instead of access keys, SCP guardrails, network and KMS basics, CloudTrail/GuardDuty/Security Hub habits, SSM instead of SSH, and the IR runbook that makes incidents tractable.
01IAM mental modelPrincipals, policies, boundaries, and evaluation order.30 min02Roles, trust policies, and PassRoleWho may assume whom — and the quiet escalator.30 min03OIDC federation from CIGitHub/GitLab to AWS with zero stored keys.30 min04Permission boundaries in practiceDelegate admin without handing over the kingdom.25 min
01CloudTrail and GuardDuty baselineThe two services to turn on everywhere, today.30 min02Security Hub and Config rulesFindings in one place, drift as a signal.30 min03Instance roles and SSM Session ManagerKill standing SSH keys on bastions.25 min04Incident response in AWSKey compromise runbook, step by step.30 min
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
15 questions drawn from all 5 sections — every answer explained as you pick.