Strengthen hands-on knowledge of AWS Identity & Security:
Work with AWS Security Hub to aggregate security information and evaluate compliance standards.
Understand advanced IAM mechanisms, including Roles, Condition Keys, and Permission Boundaries, to control and limit access.
Analyze compute options and optimize costs by comparing EC2 and Lambda for different use cases.
Improve skills in reading, analyzing, and translating AWS technical documentation for internal knowledge sharing.
| Day | Tasks | Start Date | Completion Date | Reference Material |
|---|---|---|---|---|
| 2 | - Explore AWS Identity & Security services: + Experiment with Amazon Cognito: User Pools (signup/sign-in) and Identity Pools (access to other AWS services). + Study AWS Organizations: manage multi-account setups, Organizational Units (OUs), Service Control Policies (SCPs), and consolidated billing. + Understand AWS Identity Center (SSO) for cross-account and external application access. + Practice AWS KMS: encrypt data at rest using CMKs and Data Keys. - Hands-on labs: IAM Roles, Permission Boundaries, resource tagging, Security Hub, KMS workflows. | 29/09/2025 | 29/09/2025 | AWS Study Group YouTube Playlist |
| 3 | - Explore AWS Security Hub: enable the service, integrate with GuardDuty, Config, and Inspector, review compliance frameworks, analyze findings, and respond to alerts. - Compare EC2 vs Lambda costs across usage patterns and determine the most cost-effective solution. - Apply tag-based IAM policies to control EC2 access and validate effectiveness. | 30/09/2025 | 30/09/2025 | AWS Security Hub Overview EC2 vs Lambda Cost Optimization |
| 4 | - Study IAM Roles and Condition Keys: attach roles to EC2/Lambda, differentiate Trust Policies vs Permission Policies, and practice conditional access based on IP, region, or tags. - Practice encrypting data at rest using AWS KMS and compare with encryption in transit. | 01/10/2025 | 01/10/2025 | IAM Role Documentation AWS KMS Overview |
| 5 | - Learn Permission Boundaries: define maximum permission limits for users or roles, compare with standard IAM policies. - Lab: create a user with a permission boundary restricting EC2 creation to a specific region; verify effectiveness via CLI and Console. | 02/10/2025 | 02/10/2025 | IAM Permission Boundaries |
| 6 | - Explore AWS monitoring and auditing services: + Review AWS CloudTrail to track API activity across AWS accounts. + Use AWS Config to observe resource compliance and configuration changes. + Use Amazon CloudWatch to monitor metrics, create dashboards, and set alarms for key resources. - Practice creating alerts and analyzing logs to understand system activity and potential security issues. | 03/10/2025 | 03/10/2025 | AWS CloudTrail Overview AWS Config Overview Amazon CloudWatch Overview |
Improved knowledge and hands-on skills with AWS Identity & Security:
Completed labs reinforcing key concepts: IAM Roles & Conditions, Permission Boundaries, Security Hub, tag-based EC2 access control, KMS encryption.
Applied advanced IAM concepts: Trust Policies, Permission Policies, and Condition Keys to implement fine-grained access control.
Analyzed cost-effectiveness of compute services, determining appropriate workloads for EC2 vs Lambda.
Strengthened ability to read, synthesize, and present AWS technical information for internal knowledge sharing.