Mục tiêu bài học
Tập trung vào identity, shared responsibility, security services và compliance evidence.
Khái niệm cốt lõi
Identity/quyền → IAM, Identity Center, role. Key → KMS. Secret → Secrets Manager. DDoS → Shield. HTTP → WAF. Threat → GuardDuty. Vulnerability → Inspector. Audit event → CloudTrail. AWS compliance report → Artifact. App user identity → Cognito.
Thực hành có kiểm soát
Với mỗi scenario, xác định principal, action, resource và mục tiêu. Nếu mục tiêu là prevent, tìm control chặn; detect thì tìm dịch vụ phát hiện; prove/audit thì tìm log hoặc report.
Bẫy đề thi và cách tự kiểm tra
Một service có thể hỗ trợ security nhưng không giải quyết toàn bộ lớp. Shared Responsibility luôn phải đọc theo dịch vụ và phần khách hàng kiểm soát.