Course Title: AWS Secure Builder Micro-Credential (SANS) Training Course
Executive Summary
This two-week intensive course equips participants with the skills to build and secure applications and infrastructure on Amazon Web Services (AWS). Focused on the SANS Institute’s Secure Builder curriculum, the course covers foundational AWS security concepts, secure coding practices, infrastructure-as-code security, and incident response techniques. Through hands-on labs and real-world scenarios, attendees will learn to identify and mitigate common security vulnerabilities in AWS environments. The program emphasizes a ‘security-first’ approach, providing practical guidance on integrating security into every stage of the software development lifecycle. Participants will gain expertise in utilizing AWS security services and tools to build resilient and compliant systems. This course prepares individuals for the AWS Certified Security – Specialty certification and enhances their ability to develop and deploy secure solutions in the cloud.
Introduction
In today’s cloud-centric world, security is paramount, especially when building and deploying applications and infrastructure on platforms like Amazon Web Services (AWS). Organizations face an ever-evolving threat landscape, demanding skilled professionals who can proactively identify and mitigate security risks within their cloud environments. This two-week AWS Secure Builder Micro-Credential training course, based on the renowned SANS Institute’s curriculum, provides a comprehensive and hands-on approach to AWS security. Participants will learn to build secure applications and infrastructure from the ground up, utilizing AWS’s robust suite of security services and tools. The course emphasizes practical skills and real-world scenarios, empowering attendees to effectively address security challenges in their own AWS deployments. By focusing on secure coding practices, infrastructure-as-code security, and incident response, this training prepares individuals to build resilient, compliant, and secure solutions in the cloud. Participants will also gain a deep understanding of AWS security best practices and develop the skills necessary to achieve the AWS Certified Security – Specialty certification, demonstrating their expertise in securing AWS environments.
Course Outcomes
- Understand foundational AWS security concepts and best practices.
- Implement secure coding practices for applications deployed on AWS.
- Automate security using Infrastructure-as-Code (IaC) on AWS.
- Configure and manage AWS security services such as IAM, KMS, and CloudTrail.
- Identify and mitigate common security vulnerabilities in AWS environments.
- Respond effectively to security incidents in AWS.
- Prepare for the AWS Certified Security – Specialty certification exam.
Training Methodologies
- Expert-led lectures and interactive discussions.
- Hands-on labs and practical exercises using AWS Management Console and CLI.
- Real-world case studies and scenario-based learning.
- Group projects and collaborative problem-solving.
- Security code reviews and vulnerability assessments.
- Incident response simulations.
- Quizzes and assessments to reinforce learning.
Benefits to Participants
- Gain in-demand skills in AWS security, making you a valuable asset to any organization.
- Develop a deep understanding of AWS security best practices and how to implement them.
- Learn to build secure applications and infrastructure from the ground up.
- Master the use of AWS security services and tools.
- Improve your ability to identify and mitigate security vulnerabilities.
- Prepare for the AWS Certified Security – Specialty certification exam.
- Enhance your career prospects in the cloud security field.
Benefits to Sending Organization
- Reduce the risk of security breaches and data loss in your AWS environment.
- Improve compliance with industry regulations and standards.
- Increase the security posture of your applications and infrastructure.
- Enhance the skills of your security team and development teams.
- Automate security tasks and reduce manual effort.
- Gain a competitive advantage by demonstrating a commitment to security.
- Improve the efficiency and effectiveness of your incident response process.
Target Participants
- Security Engineers
- Cloud Architects
- DevOps Engineers
- Software Developers
- System Administrators
- Security Auditors
- IT Professionals responsible for AWS security
WEEK 1: AWS Security Fundamentals and Secure Development
Module 1: Introduction to AWS Security
- Overview of AWS security pillars.
- AWS Shared Responsibility Model.
- Identity and Access Management (IAM) fundamentals.
- IAM roles, policies, and best practices.
- Multi-Factor Authentication (MFA) implementation.
- Securing AWS accounts and root credentials.
- AWS Organizations and Service Control Policies (SCPs).
Module 2: Network Security in AWS
- Virtual Private Cloud (VPC) design and configuration.
- Security Groups and Network Access Control Lists (NACLs).
- AWS Direct Connect and VPN connectivity.
- AWS Shield for DDoS protection.
- Web Application Firewall (WAF) configuration.
- Intrusion Detection and Prevention Systems (IDS/IPS) in AWS.
- Network traffic monitoring and analysis.
Module 3: Data Protection and Encryption
- AWS Key Management Service (KMS) overview.
- Encryption at rest and in transit.
- S3 bucket security and access control.
- AWS CloudHSM for hardware security modules.
- Data masking and tokenization techniques.
- AWS Secrets Manager for managing secrets.
- Compliance with data privacy regulations (e.g., GDPR, HIPAA).
Module 4: Secure Coding Practices
- Common web application vulnerabilities (OWASP Top 10).
- Secure coding principles for AWS Lambda functions.
- Input validation and output encoding.
- Authentication and authorization techniques.
- Cross-Site Scripting (XSS) and SQL Injection prevention.
- Secure API development with API Gateway.
- Static code analysis and vulnerability scanning tools.
Module 5: Infrastructure-as-Code (IaC) Security
- Introduction to AWS CloudFormation and Terraform.
- Secure IaC development practices.
- Automated security checks for IaC templates.
- Managing secrets in IaC.
- Version control and code review for IaC.
- Compliance as Code.
- Using AWS Config for infrastructure governance.
WEEK 2: Security Automation, Monitoring, and Incident Response
Module 6: Security Automation and Orchestration
- AWS Systems Manager Automation.
- Automated patching and configuration management.
- Automated security remediation.
- Event-driven security automation with AWS CloudWatch Events.
- Continuous Compliance with AWS Security Hub.
- Automated vulnerability scanning.
- Integrating security into the CI/CD pipeline.
Module 7: Security Monitoring and Logging
- AWS CloudTrail for auditing AWS API calls.
- AWS CloudWatch Logs for application and system logging.
- AWS GuardDuty for threat detection.
- Amazon Inspector for vulnerability assessments.
- Security Information and Event Management (SIEM) integration.
- Log analysis and correlation techniques.
- Creating custom dashboards for security monitoring.
Module 8: Incident Response in AWS
- Incident response planning and preparation.
- Identifying and classifying security incidents.
- Containment, eradication, and recovery steps.
- Incident communication and reporting.
- Forensic analysis in AWS.
- Post-incident review and lessons learned.
- Using AWS services for incident response (e.g., Lambda, Step Functions).
Module 9: Compliance and Governance
- AWS compliance programs (e.g., SOC, PCI DSS, HIPAA).
- AWS Artifact for accessing compliance reports.
- Compliance automation with AWS Config Rules.
- Security best practices for specific industries.
- Implementing a security governance framework.
- Risk management and security assessments.
- Staying up-to-date with AWS security updates and announcements.
Module 10: AWS Certified Security – Specialty Exam Preparation
- Review of key exam topics.
- Practice exam questions and answers.
- Exam tips and strategies.
- Identifying areas for improvement.
- Study resources and materials.
- Hands-on exercises to reinforce knowledge.
- Final Q&A session.
Action Plan for Implementation
- Conduct a security assessment of your current AWS environment.
- Develop a security roadmap based on the assessment findings.
- Implement security best practices and controls.
- Automate security tasks using AWS services and tools.
- Establish a security monitoring and alerting system.
- Create an incident response plan.
- Continuously review and improve your security posture.
Course Features
- Lecture 0
- Quiz 0
- Skill level All levels
- Students 0
- Certificate No
- Assessments Self





