Week 11— Infrastructure Security · Data Protection
6 days- Study →
Infrastructure Security
Infrastructure Security is 20% of SCS-C02 and covers protecting AWS compute, network and edge resources. Expect scenario questions on VPC security groups versus NACLs, AWS WAF and Shield, Network Firewall, PrivateLink endpoints, EC2 instance access, Systems Manager Session Manager, and hardening with IAM, KMS and logging. Questions test choosing the correct control for a stated threat.
📅 Days 75–77🎯 ~5 questions/day⚖ 20% of exam- ✓Choosing security groups versus NACLs for stateful subnet and instance-level filtering
- ✓Configuring AWS Network Firewall, WAF rules and Shield Advanced for edge protection
- ✓Using VPC endpoints, PrivateLink and Gateway Endpoints to keep traffic off the internet
- Study →
Data Protection
Data Protection covers encryption at rest and in transit, KMS key policies and grants, ACM certificate management, S3 bucket policies and Object Lock, and Secrets Manager rotation. SCS-C02 tests these through scenario questions: choosing between SSE-KMS and SSE-S3, troubleshooting AccessDenied from key policies, enforcing TLS with aws:SecureTransport, and designing cross-account key access.
📅 Days 75–77🎯 ~21 questions/day⚖ 18% of exam- ✓Selecting SSE-S3, SSE-KMS, or DSSE-KMS for S3 objects based on audit and key control needs
- ✓Writing KMS key policies and grants that permit cross-account decrypt without wildcard principals
- ✓Enforcing TLS-only access using aws:SecureTransport conditions in S3 and IAM policies