Design Secure Architectures

AWS Certified Solutions Architect - Associate SAA-C03 - Domain 1

:

A collection of cheat sheet posts related to the 'Design Secure Architectures' domain, which is a part of the content for the AWS Certified Solutions Architect - Associate certification exam.

The 'Design Secure Architectures' domain is the first area in the content scope of the AWS Certified Solutions Architect - Associate certification exam. 

 

It encompasses 30% of the exam's scored content, making it the most significant domain from a scoring perspective. This domain consists of three Task Statements, which group knowledge and skills into distinct concepts and AWS services.

 

Many questions in the exam from this domain are derived from the Security Pillar of the AWS Well-Architected Framework, which is extensive and often challenging for many learners to fully understand. The tagged posts will significantly aid you in effectively comprehending and retaining the material.

 

 

Task Statement 1.1: Design secure access to AWS resources 

 

The task is primarily related to the way human users access and communicate with AWS resources and services.

 

 

What AWS services does Task 1.1 include?

 

ServiceReference
Identity and Access Management (IAM)Access controls and management across multiple accounts in AWS

AWS federated access and identity services
AWS OrganizationsAccess controls and management across multiple accounts in AWS
Resource Access Manager (RAM)Access controls and management across multiple accounts in AWS
AWS IAM Identity Center

Access controls and management across multiple accounts in AWS

 

AWS federated access and identity services

AWS Control TowerAccess controls and management across multiple accounts in AWS
AWS Directory ServiceAWS federated access and identity services
Amazon CognitoAWS federated access and identity services
AWS GuardDutyAccess controls and management across multiple accounts in AWS
AWS Security HubAccess controls and management across multiple accounts in AWS
CloudWatchAccess controls and management across multiple accounts in AWS
CloudTrailAccess controls and management across multiple accounts in AWS
AWS Service CatalogAccess controls and management across multiple accounts in AWS
AWS ConfigAccess controls and management across multiple accounts in AWS

 

 

What are key concepts inlcuded in Task 1.1?

 

ConceptReference
AWS RegionsAWS global infrastructure
Global and regional servicesAWS global infrastructure
AWS Availability Zones and High AvailabilityAWS global infrastructure
Edge LocationsAWS global infrastructure
Local ZonesAWS global infrastructure
Wavelength ZonesAWS global infrastructure
AWS Outposts FamilyAWS global infrastructure
Federated AccessAWS federated access and identity services
Multiple accounts benefitsAccess controls and management across multiple accounts in AWS
The AWS shared responsibility modelThe AWS shared responsibility model
AWS security best practices, especially those related to Security foundations and Identity and access management areas.AWS security best practices