AWS Security Arsenal Explained | GuardDuty, Inspector, Macie, WAF & Shield | Day 16 — Transcript
Full transcript
- 0:00Hey everyone, welcome to day 16.
- 0:02Yesterday we learned how different parts
- 0:04of an application talk to each other
- 0:05using SQS, SNS, and EventBridge. Today
- 0:08we are switching gears completely and
- 0:10stepping into one of the most important
- 0:12and honestly one of the most heavily
- 0:13tested topics in the entire AWS Cloud
- 0:15Practitioner exam.
- 0:17That is security.
- 0:19Today's theme is what I like to call the
- 0:21AWS security arsenal.
- 0:23Think of it like a toolbox full of
- 0:25specialized weapons where each tool has
- 0:27one very specific job. Some detect
- 0:29threats, some protect your resources,
- 0:30and some help you respond when something
- 0:32goes wrong.
- 0:33Here's something important. This topic
- 0:35falls under domain two, that is security
- 0:37and compliance, and this domain is worth
- 0:3930% of your entire exam. And that's
- 0:42nearly one out of every three questions
- 0:44you will face.
- 0:45So if you only need to deeply understand
- 0:48one domain before
- 0:49your exam, honestly this would be the
- 0:51one of the top priorities, your top
- 0:53contenders.
- 0:55Now here's the thing about security
- 0:56services on this exam. AWS has a lot of
- 0:59them, and if you try to memorize them
- 1:00randomly, you will mix them up in
- 1:01seconds.
- 1:03GuardDuty, Inspector, Macie, Config,
- 1:06WAF, Shield, KMS, Secret Manager,
- 1:09Security Hub.
- 1:11That's nine services in one day.
- 1:14Sounds scary, right? But don't worry,
- 1:17there's a simple trick to master all of
- 1:18them.
- 1:19The exam almost never asks you to
- 1:21explain a service in detail. It gives
- 1:23you a one-line scenario and asks you to
- 1:25match it to the correct service.
- 1:27So today instead of just throwing
- 1:29definitions at you, I'm going to teach
- 1:31you exactly how to pattern match
- 1:32keywords in a question to the right
- 1:34service. Because that's the real skill
- 1:36that gets you marks in the exam.
- 1:38By the end of today's session, you will
- 1:39be able to clearly distinguish between
- 1:42GuardDuty,
- 1:44Inspector,
- 1:47Macie,
- 1:49and Config.
- 1:52Knowing exactly what each one detects.
- 1:55We will also compare AWS WAF
- 1:59and AWS
- 2:01Shield
- 2:02standard or advanced.
- 2:04And we will know when each applies.
- 2:07We will also explain how AWS KMS and AWS
- 2:11Secrets Manager work together for
- 2:14encryption and secrets.
- 2:17We will understand how uh AWS Security
- 2:20Hub brings everything together in one
- 2:23unified dashboard.
- 2:24And at the end we have got a real
- 2:26hands-on lab where you will enable
- 2:28GuardDuty in your own AWS account and
- 2:30generate uh sample security finding and
- 2:33we will explore what a real threat
- 2:35detection dashboard actually looks like.
- 2:37Let's dive in.
- 2:38Before we go service by service, let's
- 2:40zoom out and look at the big picture.
- 2:42Because once you see how these seven
- 2:44areas are organized, the whole day will
- 2:46feel much easier to follow.
- 2:48Think of AWS security like protecting a
- 2:50house. You need different types of
- 2:52protection for different types of
- 2:53threats.
- 2:54A camera to detect intruders, a lock to
- 2:56prevent break-ins, a fireproof safe for
- 2:59your valuables maybe, and maybe a
- 3:00security company that watches everything
- 3:02from one central control room.
- 3:05AWS security services work exactly the
- 3:07same way. So, let's map them out.
- 3:10The first one is threat detection,
- 3:12GuardDuty. This is like your security
- 3:14camera with AI built in. It constantly
- 3:16watches over your AWS account for
- 3:18suspicious behavior.
- 3:20Number two, vulnerability assessment,
- 3:23that is Inspector.
- 3:25This is like a home inspector who checks
- 3:27your home for weak locks, cracked
- 3:29windows, or outdated security systems.
- 3:32Except here it's scanning your servers
- 3:34and code for known weaknesses.
- 3:36We have third one that is sensitive data
- 3:38discovery, that is Macie.
- 3:40Think of this as someone going through
- 3:42your house and specifically searching
- 3:44for your most valuable, most sensitive
- 3:46documents like passport, bank details,
- 3:49and flagging if they are lying around
- 3:50unprotected.
- 3:52We have the fourth one, configuration
- 3:53compliance, that is config.
- 3:56This is your detailed history logbook.
- 3:57It remembers every single change made to
- 4:00your house setting, so you can always
- 4:01answer, "Was this door locked last
- 4:04Tuesday?"
- 4:06We have fifth one, that is network and
- 4:07application protection. WAF and Shield.
- 4:12These are your actual logs and
- 4:13reinforced walls, like stopping
- 4:15attackers from breaking in.
- 4:17Whether they are trying to sneak through
- 4:18the front door, that is application
- 4:20attacks, or trying to flood your entire
- 4:22state with traffic.
- 4:23We call it DDoS attack.
- 4:26Uh the sixth one we have, encryption and
- 4:28secrets. We have KMS and secrets
- 4:31manager. This is your safe and vault,
- 4:33protecting your most sensitive keys,
- 4:35passwords, and secrets.
- 4:37The seventh one we have, centralized
- 4:39visibility, that is security hub.
- 4:42This is your central security room, one
- 4:44dashboard, where every alarm, every
- 4:46camera feed, every alert from all other
- 4:48tools show up in one place.
- 4:50That's the entire landscape for today.
- 4:52Seven categories, nine services.
- 4:55Once we go through each one with
- 4:57example, this will all click together
- 4:59beautifully. Let's start with the first
- 5:01four, the detect, assess,
- 5:04classify,
- 5:05comply framework.
- 5:07This slide right here is probably the
- 5:08single most important slide of the
- 5:10entire day, because these four services
- 5:12get confused with each other constantly
- 5:14by beginners, and the exam knows that.
- 5:16So, it loves testing this exact
- 5:18confusion.
- 5:19Let's break each one down carefully and
- 5:21one at a time using a clear framework,
- 5:23that is detect, assess, classify, and
- 5:27comply.
- 5:29All right, so first one is detect
- 5:30threats, that is Amazon GuardDuty.
- 5:33GuardDuty is AWS' intelligent threat
- 5:35detection service. Think of it as a
- 5:37security guard powered by machine
- 5:38learning who never sleeps. It
- 5:40continuously and automatically analyzes
- 5:42three sources of information across your
- 5:44account.
- 5:45What are these three sources?
- 5:47The first one is
- 5:48CloudTrail logs.
- 5:51That is a records of every action taken
- 5:53in your AWS account.
- 5:56The next one is VPC flow logs, records
- 5:58of network traffic flowing in and out of
- 6:00your servers. The another source of
- 6:02information is DNS logs.
- 6:05That is a records of your domain name
- 6:07lookups.
- 6:08GuardDuty uses machine learning to spot
- 6:10pattern that looks suspicious.
- 6:12Patterns a human might completely miss.
- 6:14For example,
- 6:16imagine someone is suddenly making an
- 6:17API calls to your AWS account from a Tor
- 6:19exit node.
- 6:21That's a part of the dark web network
- 6:23people use to hide their identity. A
- 6:25normal human admin has no any reason to
- 6:27be logging in through Tor. GuardDuty
- 6:29would immediately flag this as an
- 6:31unusual API calls finding, warning you
- 6:33that your account might be compromised.
- 6:36Here the keyword to remember is whenever
- 6:38you see a phrase unusual activity,
- 6:40suspicious API calls, ML-based threat
- 6:43detection, and or compromised instance.
- 6:45The answer is GuardDuty.
- 6:48Remember that, and we have another
- 6:51assess vulnerabilities. That is Amazon
- 6:54Inspector.
- 6:56Now, GuardDuty watches for behavior
- 6:57things happening in the real time.
- 6:59Inspector is completely different.
- 7:01It does automated vulnerability
- 7:03scanning, meaning it checks your actual
- 7:05software and system for known
- 7:06weaknesses, even if nothing suspicious
- 7:08is currently happening.
- 7:10Inspector automatically scans your EC2
- 7:12instances, Lambda functions, and
- 7:14container images looking for known CVs,
- 7:17which stands for common vulnerabilities
- 7:19and exposures.
- 7:20These are publicly documented security
- 7:22flaws found in popular software.
- 7:25Let us take a real example. Remember the
- 7:27massive Log4j vulnerability that
- 7:29affected thousands of companies
- 7:30worldwide a few years back?
- 7:32If you might have heard about this
- 7:33vulnerability,
- 7:35if a vulnerable version of that Log4j
- 7:37software was sitting on one of your EC2
- 7:39instances, Inspector would automatically
- 7:42detect it and flag it even though no
- 7:44attacker has actually exploited it yet.
- 7:46It's proactive, not reactive.
- 7:48Keyword to remember here,
- 7:50whenever you see vulnerability
- 7:51assessment, CVE scanning, that is common
- 7:54vulnerabilities and exposures scanning,
- 7:57outdated software packages or known
- 7:59software vulnerabilities, the answer is
- 8:02Inspector.
- 8:03Remember that. So, we have detected and
- 8:06assessed. Now, it's time for classify,
- 8:09that is classify sensitive data.
- 8:11That is Amazon Macie.
- 8:14Uh so, let's talk about it. It has a
- 8:16very specific and narrow job. It uses
- 8:18machine learning to automatically
- 8:20discover and classify and protect
- 8:23sensitive data specifically inside the
- 8:25Amazon S3 buckets.
- 8:27So, what kind of sensitive data are we
- 8:29talking about?
- 8:30Things like credit card numbers, social
- 8:32security number, passport numbers, and
- 8:35other types of personally identifiable
- 8:36information commonly abbreviated as PII.
- 8:40Imagine a careless developer
- 8:42accidentally uploads a spreadsheet full
- 8:44of customer credit card numbers to an S3
- 8:46bucket and forgets to encrypt it.
- 8:49Macie's ML models will scan through that
- 8:51bucket, recognize the pattern of the
- 8:52data. It knows what a credit card
- 8:55typically looks like, and it raises an
- 8:57alert saying something like S3 bucket
- 8:59contains unencrypted credit card
- 9:01numbers.
- 9:03Whenever you see PII discovery,
- 9:06sensitive data in S3, credit card
- 9:08numbers, classified data, the answer is
- 9:11always Macie. Remember this simple link,
- 9:15Macie equal to S3 plus PII.
- 9:18Finally, Config.
- 9:20This one is completely different from
- 9:21the other three. It's not about
- 9:23detecting threats or scanning for
- 9:25vulnerabilities.
- 9:26Config's job is to record and track
- 9:28every single configuration change made
- 9:30to your AWS resources over time, and it
- 9:33lets you check whether your resources
- 9:34comply with the rules you have set.
- 9:37Imagine your security team ask was
- 9:38multi-factor authentication turned off
- 9:40for this IAM user last Tuesday?
- 9:42GuardDuty can't answer that. It's not
- 9:44tracking configuration history.
- 9:46Inspector can't answer it either. It's
- 9:48scanning for vulnerabilities, not
- 9:50settings history.
- 9:51But Config can answer this instantly
- 9:53because it keeps a full historical
- 9:55timeline of every configuration change
- 9:57ever made.
- 9:59Whenever you see configuration history,
- 10:01complies auditing, drift detection, or
- 10:03was this setting changed? The answer is
- 10:05always Config.
- 10:07Let's lock in the full exam pattern
- 10:08together.
- 10:09PII in S3, that is Macie.
- 10:12Unusual activity, suspicious behavior,
- 10:14that is GuardDuty.
- 10:16Software vulnerabilities or CV,
- 10:19Inspector.
- 10:21Configuration compliance or change
- 10:23history,
- 10:24Config.
- 10:26So, we have done four aspect, that is
- 10:28detect, assess, classify, and comply.
- 10:32Say these four mappings out loud a few
- 10:34times. Seriously, this single pattern
- 10:35alone will help you answer a huge chunk
- 10:37of domain two questions correctly.
- 10:39Now, let's move from detection services
- 10:41to active protection services.
- 10:43This slide covers two services that
- 10:45people confuse constantly, that is AWS
- 10:47WAF and AWS Shield.
- 10:50The trick to telling them apart is
- 10:52understanding which layer of the network
- 10:54each one protects.
- 10:57Think of network traffic like layers of
- 10:59onions. You must have seen onion?
- 11:01The deepest layer handle the raw network
- 11:04connections and the outer layer handle
- 11:05the actual content of a web request.
- 11:08Like a login form or search box.
- 11:11WAF and Shield each guard a different
- 11:13layer.
- 11:14WAF operates at layer seven, which is
- 11:16the application layer.
- 11:18Basically, the layer where actual web
- 11:20request like someone submitting a login
- 11:22form or a search query happen.
- 11:24WAF is designed to catch web specific
- 11:27attacks, including SQL injections. It is
- 11:30a way an attacker tries to sneak
- 11:32malicious database commands into a web
- 11:34form tricking your database into leaking
- 11:36or destroying data.
- 11:38We you must have heard about XSS or that
- 11:40is or cross-site scripting.
- 11:43In this attacker injects malicious
- 11:45scripts into a web page that then runs
- 11:47in the others users browser.
- 11:50We have geographic restrictions that is
- 11:52blocking traffic from a specific
- 11:54countries entirely.
- 11:56The next is IP rate limiting and bot
- 11:58control.
- 12:00That is stopping a single IP address
- 12:01from hammering your website with
- 12:02thousands of requests per second or
- 12:05blocking automated bots.
- 12:07WAF directly plugs into services like
- 12:09Amazon CloudFront, application load
- 12:11balancer, API Gateway, and AWS AppSync
- 12:14and basically anywhere your web traffic
- 12:16passes through.
- 12:18Whenever you see protect against SQL
- 12:21injection, block XSS attacks, or web
- 12:24application firewall, the answer is AWS
- 12:26WAF and WAF stands for web application
- 12:30firewall. We have another service that
- 12:33is AWS Shield. Shield operates one level
- 12:35deeper at a layer three and four, the
- 12:37network and transport layer.
- 12:39Its entire job is protecting you from
- 12:41DDoS attacks. DDoS means distributed
- 12:44denial of service attacks where
- 12:45attackers try to overwhelm your servers
- 12:47with a massive flood of junk traffic
- 12:49like SYN floods or UDP reflection
- 12:50attacks hoping to knock your service
- 12:53fully offline.
- 12:54Shield actually comes in two tiers.
- 12:56This distinction is favorite exam trap.
- 12:59Shield standard and Shield advanced. The
- 13:01Shield standard is completely free and
- 13:03it's automatically active for every
- 13:05single AWS customer with zero setup
- 13:06required. It protects against the most
- 13:09common layer three and layer four DDoS
- 13:10attacks right out of the box. The
- 13:12another one is AWS advanced. This is a
- 13:14paid tier starting at a minimum of
- 13:17$3,000 per month. For that price you get
- 13:19access to AWS 24/7 DDoS response team
- 13:22often abbreviated as the DRT, a team of
- 13:25real security expert who actively help
- 13:27you during a live attack.
- 13:29You also get financial protection,
- 13:30meaning if a DDoS attack causes your
- 13:32bill to spike and due to extra traffic
- 13:34and scaling, AWS will credit you back
- 13:37for those unexpected cost. Plus, you get
- 13:39an SLA guarantee for on protection.
- 13:42And here are some exam patterns to
- 13:43remember.
- 13:44Protect web application from SQL
- 13:46injection attacks. AWS WAF.
- 13:50DDoS protection with a dedicated expert
- 13:52response team.
- 13:54That is AWS Shield Advanced.
- 13:57Free automatic DDoS protection for all
- 13:59customers. We have AWS Shield Standard.
- 14:02Now, let's move into our third category.
- 14:05Encryption, secrets, and centralized
- 14:07visibility.
- 14:09This slide covers four services
- 14:10actually. Even though the title only
- 14:12mentions three, we will also touch on
- 14:14AWS Certificate Manager.
- 14:16Let's discuss about AWS KMS, Key
- 14:18Management Service.
- 14:22KMS lets you centrally create, manage,
- 14:24and control the graphic keys used to
- 14:27encrypt your data across AWS. Here's the
- 14:29most important part beginners often
- 14:31miss. You rarely interact with KMS
- 14:33directly and obviously. Instead, it
- 14:35works quietly behind the scenes. When
- 14:37you flip on encryption for services like
- 14:39S3, EBS, that is EBS is EC2 storage
- 14:42volumes, RDS, or DynamoDB, AWS is
- 14:46actually using KMS customer managed
- 14:47keys, often abbreviated as CMKs
- 14:52to perform that encryption under the
- 14:53hood. KMS also keeps a full audit trail
- 14:56meaning every single time a key is used
- 14:59to encrypt or decrypt something, that
- 15:01action gets logged, so you always know
- 15:03what exactly who used which key and
- 15:05when. Here are some keywords to
- 15:07remember. Encryption key management,
- 15:10customer managed key, CMKs envelope
- 15:13encryption
- 15:14that is KMS.
- 15:16Now, let's discuss about AWS Secrets
- 15:18Manager, the service with a very
- 15:19specific, very memorable job, securely
- 15:22storing secrets.
- 15:24Things like database passwords, API
- 15:26keys, and OAuth tokens. So, they are
- 15:28never hard-coded directly into your
- 15:30application source code, which by the
- 15:31way is the huge security risk many
- 15:33beginner developers accidentally make.
- 15:35But, here's the star feature that makes
- 15:37Secret Manager stand out on the exam.
- 15:39Automatic rotation.
- 15:41Secret Manager can automatically rotate
- 15:43your RDS database credentials on a
- 15:44schedule you configure. Let's say you
- 15:46configured every 30 days.
- 15:48Completely on its own without any human
- 15:51manually typing a new password. And this
- 15:53dramatically reduces the risk of leaked
- 15:55password being useful to any attacker
- 15:56for a long time.
- 15:58So, what are the keywords to remember
- 15:59here?
- 16:00Automatic secret rotation, database
- 16:02credential management, API key storage.
- 16:06Select Secret Manager.
- 16:08Just a quick mention here. Since it's
- 16:10related to security, too, ACM provides
- 16:12free SSL TLS certificates for AWS
- 16:14services like CloudFront and Application
- 16:16Load Balancer.
- 16:18These certificates are what make your
- 16:19website secure. That little padlock icon
- 16:21in the browser confirming your
- 16:22connection is encrypted. ACM's best
- 16:24feature is automatic certificate
- 16:26renewal.
- 16:27No more scrambling to manually renew an
- 16:29expiring certificate before your website
- 16:31breaks.
- 16:32And the final we have AWS Security Hub.
- 16:36Finally, the service that ties
- 16:37everything together. This is what's
- 16:39called a CSPM tool that stands for
- 16:42cloud
- 16:44security
- 16:45posture
- 16:48management. Its job is simple,
- 16:51but incredibly valuable. It takes all
- 16:53the security findings generated by
- 16:55GuardDuty, Inspector, Macie, and Config
- 16:58and aggregates them into a single
- 17:00unified dashboard.
- 17:02Instead of jumping between four or five
- 17:04different service consoles every morning
- 17:05to check for security issues, a security
- 17:08team can just open the Security Hub and
- 17:10see everything in one place. This is
- 17:12often described as a single pane of
- 17:14glass.
- 17:15Security Hub also comes with built-in
- 17:17compliance against well-known industry
- 17:19standards like CIS, PCI DSS, and NIST,
- 17:22automatically telling you how well your
- 17:24AWS environment aligns with these
- 17:25frameworks. So, what are the keywords to
- 17:27remember for this?
- 17:29Centralized security findings,
- 17:31single pane of glass,
- 17:33aggregates GuardDuty, Inspector, and
- 17:35Macie findings, that is Security Hub.
- 17:40All right, time to get hands-on. Today's
- 17:42lab is all about GuardDuty. We are going
- 17:44to enable it in your real AWS account,
- 17:46generate some sample security findings.
- 17:49Don't worry, these are just safe example
- 17:51findings, not the real threats, and we
- 17:52will learn how to read and interpret a
- 17:54real security dashboard.
- 17:56I want you to give a one important
- 17:58heads-up before we start. At the very
- 18:01end of this lab, we are going to disable
- 18:03GuardDuty.
- 18:04I will explain exactly why when we get
- 18:07there. Please don't skip that step.
- 18:10So, in the AWS console,
- 18:12you need to search for GuardDuty. As I
- 18:14can see GuardDuty over here, I will
- 18:16simply open it.
- 18:18And once you open it,
- 18:20as I currently I can see this screen,
- 18:22but if you are new to this GuardDuty,
- 18:25you will see a welcome screen, where the
- 18:27button says get started.
- 18:29What you need to do is click on get
- 18:31started, and you need to enable
- 18:33GuardDuty.
- 18:34All right. I guess there was a first
- 18:37option that says activate all the
- 18:39services. You need to select that, and
- 18:41enable GuardDuty.
- 18:43So, GuardDuty will actually what it will
- 18:45do is it will automatically create
- 18:47something called service-linked role.
- 18:49This is simply a special permission role
- 18:51that allows GuardDuty to read your
- 18:53CloudTrail, VPC flow,
- 18:55and DNS logs on your behalf. So, go
- 18:57ahead and accept these permission, and
- 18:59then the moment you enable it, your
- 19:0130-day free trial begins immediately.
- 19:03Meaning GuardDuty starts analyzing your
- 19:05account logs right away, at absolutely
- 19:08no cost for the first 30 days.
- 19:10You will land on this findings dashboard
- 19:14and it will likely show zero findings in
- 19:16your case.
- 19:17And yeah, that means it is 100% correct.
- 19:20It's because
- 19:21as you have a brand new account, it's so
- 19:23there is no suspicious activity so it
- 19:25will show zero. It means nothing bad has
- 19:27been detected yet and which is a good
- 19:29thing.
- 19:30And since we don't have any real
- 19:32threats,
- 19:33so what I will do is let me generate
- 19:37some sample finding.
- 19:41Go to this sample finding tab and I will
- 19:43click on generate finding.
- 19:46All right.
- 19:48So wait for 1 to 2 minutes and then head
- 19:50back to the finding section using the
- 19:51left hand menu.
- 19:53And yes, we are here. And then let's go
- 19:55to the findings menu. You will see a
- 19:57whole list of sample finding pop up
- 19:59representing different types of threat
- 20:01GuardDuty is designed to catch such as
- 20:04we have unauthorized access, we have EC2
- 20:07instance,
- 20:08user fault FD uses usage detected.
- 20:12Kubeflow dashboard was exposed to the
- 20:13internet, you can see. And container was
- 20:16mounted to the host directory. Yes, we
- 20:17have a lot of things.
- 20:19You can click on any of these. Let's
- 20:21say, let me click on this. And you can
- 20:23see
- 20:24the type of severity it is medium. You
- 20:27can see the reason, count, account ID.
- 20:31You will see each and everything like
- 20:32finding type, security level, affected
- 20:35resource, which is specific I am user
- 20:37EC2 instance or other resource finding
- 20:39relates to the reason, the source IP and
- 20:41the recommended action as well.
- 20:43GuardDuty doesn't just alert you, it
- 20:45actually suggest what you should do
- 20:47about it.
- 20:49A useful trick here.
- 20:51So you will find
- 20:52this
- 20:54section. Let me show you this.
- 20:56I will close this and we have this
- 20:58severity tab. Use this severity filter
- 21:01so only high and critical findings. In a
- 21:04real production environment, these are
- 21:06findings your security team needs to
- 21:07jump on immediately. All right, so you
- 21:10can see there are many critical, high,
- 21:13these type of alerts.
- 21:15So, these things are the things that I
- 21:18need to resolve immediately. Now, here's
- 21:20the step I promised to circle back to.
- 21:22Head back to setting in the navigation
- 21:25bar
- 21:26and scroll all the way to the bottom and
- 21:28click on suspend GuardDuty or you can
- 21:33delete it. Since I am I have already
- 21:35suspended, you can click on suspend and
- 21:37it suspends or you can disable the
- 21:39GuardDuty as well.
- 21:41All right, as you can see yeah, this is
- 21:43the page you will see when you are
- 21:46as you open the GuardDuty for the first
- 21:49time. I don't know why it is showing me
- 21:51this now.
- 21:52Some error has been occurred. All right,
- 21:54yeah.
- 21:55So, this is the page you will see.
- 21:58You can click on get it started and you
- 22:00can click on enable
- 22:02GuardDuty if you are a new account.
- 22:05Why does this matter so much?
- 22:07GuardDuty gives you a generous 30-day
- 22:08free trial, but after that period ends,
- 22:10AWS start charging you based on the
- 22:12volume events analyzed. Meaning the more
- 22:14CloudTrail events, VPC flow log entries,
- 22:17DNS queries your account generates, the
- 22:20more it costs.
- 22:21If you forget about this lab account and
- 22:23leave GuardDuty running indefinitely
- 22:26without realizing it, it could end up
- 22:28with an unexpected bill down the line.
- 22:31So, if you want to do it, you can do it.
- 22:33You can try this lab. Or if you don't
- 22:36want to do it, yeah. But But if you do
- 22:39it, remember to disable this GuardDuty.
- 22:42One very important real-world note, uh
- 22:45though in an actual production
- 22:47environment like a real company AWS
- 22:49account handling real customer data, you
- 22:51should almost always keep GuardDuty
- 22:54permanently enabled.
- 22:55The cost of running it is genuinely
- 22:58small compared to the massive value of
- 23:00catching a real security breach early.
- 23:02We are only disabling it because this is
- 23:05a practice lab account and not a real
- 23:07life production system.
- 23:09Also, keep a note of that to not show
- 23:12any real security findings in the
- 23:14LinkedIn or anywhere that exists in your
- 23:16personal AWS account. Only show the
- 23:19sample findings we generated together in
- 23:21the lab if you want to post anything in
- 23:23the LinkedIn or anywhere.
- 23:24All right. Fantastic work today. That
- 23:27was a lot of services actually.
- 23:29So, let's bring it all together with one
- 23:31final recap.
- 23:33Uh detection and assessment, we have
- 23:35GuardDuty, Inspector, Macie, Config.
- 23:38GuardDuty
- 23:39threat detection It is ML-powered and it
- 23:41watches for unusual and suspicious
- 23:43activity.
- 23:45Inspector is used for vulnerability
- 23:47scanning. It finds known CVs in your EC2
- 23:49instances, Lambda functions, and
- 23:51containers.
- 23:52Talking about Macie
- 23:54PII discovery in S3. It finds sensitive
- 23:56data like credit card numbers or SSNs.
- 24:00Config
- 24:02uh it tracks your compliance in history.
- 24:04It tracks every configuration change
- 24:06over the time.
- 24:07And talking about network defense, we
- 24:09have WAF
- 24:12Shield Standard, Shield Advanced.
- 24:15WAF is layer 7 web attack protection. It
- 24:18blocks SQL injection, XSS, and bad bots.
- 24:22Shield Standard, it is free automatic
- 24:24DDoS protection for everyone.
- 24:26And talking about Shield Advanced, it is
- 24:28a paid tier with a 24/7 DDoS response
- 24:31team and financial protection, as well.
- 24:34And we also discussed about encryption
- 24:36and invisibility thing. Encryption and
- 24:38invisibility, we have three services:
- 24:40KMS, Secrets Manager, and Security Hub.
- 24:43KMS is encryption key management, the
- 24:44engine behind encryption on S3, EBS,
- 24:47RDS, and more.
- 24:49Secrets Manager, it is automatically
- 24:51rotating secure storage for password and
- 24:53API keys.
- 24:54And we have Security Hub that is a
- 24:56centralized aggregator that pulls all
- 24:59these finding into one dashboard.
- 25:02So your homework for tonight, go
- 25:04complete 10 practice questions focus
- 25:05specifically on identifying the correct
- 25:07security service from the scenario.
- 25:10As you go through them, actively
- 25:11practice the keyword matching skill we
- 25:13built today. Look for the words like
- 25:15PII, unusual activity, vulnerability,
- 25:17SQL injection, DDoS rotation, and
- 25:20aggregated dashboard. These all things.
- 25:22Recognizing these trigger word instantly
- 25:24is what separates the confident exam day
- 25:26pass from a stressful guessing game.
- 25:28And take a look ahead to tomorrow.
- 25:31Day 17 takes us into the monitoring and
- 25:33infrastructure as code. We will be
- 25:34covering CloudWatch, CloudTrail, and
- 25:37CloudFormation.
- 25:38This is another AWS topic where
- 25:40beginners often confuse two very
- 25:43similarly named service, CloudWatch vs.
- 25:45CloudTrail.
- 25:46So we will make sure that distinction is
- 25:48also clear to
- 25:49Uh so that's a wrap for day 16. You now
- 25:52have a genuinely solid mental map of AWS
- 25:55entire security toolkit. You know
- 25:57exactly which tool detects what and
- 25:59which tool protects what. And also which
- 26:01tool ties it all together. And that's a
- 26:03huge exam critical skill you just built
- 26:05today. Great effort. Go get those
- 26:08practice question done and I will see
- 26:09you tomorrow for day 17. Keep pushing.
- 26:11You're doing brilliantly.
About this transcript
This page contains the full transcript of AWS Security Arsenal Explained | GuardDuty, Inspector, Macie, WAF & Shield | Day 16 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 4,097 words across 743 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.