Skill Introduction
Certification Information
Here's some information on the AWS Certified Security Specialty exam and blueprint.
As noted, many AWS services are not explicitly called out in the exam blueprint as being “in scope”. This, however, does not mean that they will not show up in exam questions. The (somewhat) good news is that the AWS security tools are more or less relatively consistent in their application and use across the board. The syntax for creating a Policy in JSON is the same whether we are creating an IAM policy or a Resource policy--all of which we will cover in later skills.
Knowledge Check
How many years of experience does AWS REQUIRE you to have before attempting the Security Specialty Certification exam?
Course Expectations
Now that we have taken a look at the exam blueprint, let's see how this course is put together.
Most people have heard of the Dunning-Kruger Effect, but it is sometimes misinterpreted. Psychologists David Dunning and Justin Kruger found, through their work, a form of cognitive bias that people can adopt where they overestimate their level of knowledge on a particular topic despite limited knowledge about that topic. It's not that we intentionally do this, but our brain desperately wants to make sense of things and sometimes leads us to draw hasty conclusions. Thus, we believe we understand more than that which is out there to understand.
I suppose the opposite of this bias is something we call Imposter Syndrome. Once we get to a certain level of knowledge on a topic, we realize how much we still don't know. That can inject self-doubt, causing us to question if we really are knowledgeable on a topic. If you've been around for any amount of time, you have most certainly felt each of these. Later in the course, we'll see how both of these can directly impact our performance on certification exams.
Knowledge Check
According to the course introduction, what is the primary focus of the learning approach in this AWS course?
Creating our AWS Account
Enough jibber jabber. Let's create our AWS account.
Although we breezed over it in this video, I would recommend taking a look at the AWS terms of service when you are signing up for an account. If you are signing up as part of a business, your legal team will most certainly want to review the TOS just as they usually do with any other vendor agreements.
Possibly relevant to InfoSec, the TOS explicitly says using your AWS account to scan other accounts or other websites is a big no-no. Furthermore, if you are having an external company run pen testing, you must first let AWS know that this will be going on. Otherwise, they may think it's a malicious attack and take their measures, wasting time and resources to respond to a perfectly valid test.
Knowledge Check
In the video, what is the minimum-recommended support level for an organization that intends on running several production workloads in AWS?
Applying MFA to our Root User
The first step in securing our account is to add MFA to our root user.
It might be worth reviewing the specific collection of best practices AWS has documented for the root user.
You might notice that AWS no longer offers the option of using SMS for OTP. I am not a big fan of SMS for MFA due to vulnerabilities along that chain. For example, SIM-swapping is when the attacker uses information collected from phishing and social media to initiate a fraudulent port of a phone number. Once the ownership of the phone number has been compromised, the attacker can access those SMS-protected accounts.
Knowledge Check
Which of the following are recommended for managing root accounts among multiple people or within a department? (Select Two)
Creating an IAM User
Just like in Unix systems with root accounts, we want to use those accounts very rarely because they are so powerful. For our daily access, we want to create an Identity and Access Management User. By granting that user Administrative Access, we can do almost everything that our root account can--and that's a good thing.
Exactly what sort of things must we use our root account for? AWS has documentation on this that you can read in the link below.
Knowledge Check
Which of the following are we only able to do as the root account?
Enabling CloudTrail
Like any good security professional, we know the value of a good log. Let's enable logging for our account activities.
In the video, we just used the "easy button" to create our CloudTrail logs and that applied all the default values, which includes logging just the Management Events and enabling server-side encryption on the S3 bucket using the S3 managed KMS key. In some cases, you may want or need to use a Customer KMS key which you can certainly do. (If you're not sure of the difference, we'll cover this in a later skill.)
There is a caution here, though. When using a KMS-managed key, by default, each write or read to that S3 bucket requires a call to the KMS API. We get a certain number of calls for free each month, but over a certain amount, we have to start paying. In the case of a heavily used AWS account or accounts with CloudTrail enabled using a KMS-managed key, this can quickly add up and end up as a surprise on your bill. To get around this, AWS implemented something called S3 Bucket Keys, which is sort of like a local key cache for the KMS-managed keys. Enabling this in the bucket properties can greatly reduce cost for KMS API calls.
Knowledge Check
Enabling CloudTrail logs with the default settings includes logging only Management Events and using server-side encryption with an S3 managed KMS key.
Set up a Budget Alert
Now, let's setup an alert to let us know if we are on track for spending more that we expect.
For the most part, the exercises we will be doing in this course will be within the Free Tier. There are some things, though, that we will not be able to show because they require a higher level of support. For example, some of the Trust Advisor recommendations that we will cover are only available to Business Support customers at $100/month. You are welcome to enroll in that support level, especially if your organization plans on running production workloads on your AWS accounts. However, that's certainly not required.
Knowledge Check
What is the purpose of setting up a budget alert in AWS Cost Management?
Validation: Course Introduction and Getting Started
Normally, for our Validation section, I will present several quiz questions that are written in the style of AWS exam questions. Doing well on the exam has just as much to do with how you interpret and process those questions as it does your level of AWS knowledge. There are some specific tricks and tips that can help you increase your odds of getting a question right, even if that particular area isn't very familiar to you.
After the questions, I will normally include a short optional video explaining how I might approach this question and my thought process when selecting the best answer. Since we're just getting started in this Skill, and we haven't covered much at all, these are lightweight questions that shouldn't need an explanation.
Knowledge Check
What two things must we do before we can set up a billing alert as our IAM user? (Choose TWO)
Knowledge Check
Which of the following is explicitly not permitted under the AWS terms of service?
Knowledge Check
At a minimum, which of the following should you do with a brand-new AWS account? (Choose THREE)
View Transcript
Skill Introduction
0:00Well hello there and welcome my name is Scott Fletcher and this is the AWS
0:04Certified Security
0:06Specialty course. If you've ever wanted a quick and easy way to break into the
0:10fast-paced and
0:11exciting career of cyber security, well my sweet sweet summer child you may
0:16want to look elsewhere.
0:18This course is not for you. No this course is for those who are already well
0:22versed in information
0:23security and have the calluses to prove it. Maybe your organization is
0:28migrating to AWS and you
0:29need to keep the auditors happy. Perhaps you have been saddled with the thank
0:33less task of trying to
0:34keep your developers reasonably crowd yet still frictionless or maybe you just
0:40don't want your
0:41company to end up posted on the data breach wall of shame. Yep you are in the
0:47right place.
0:48We're going to cover encryption, firewalls, identity management, intrusion
0:52detection,
0:52a stack of best practices for AWS workloads and lots more. And we're going to
0:57keep things
0:58practical and dare I say occasionally entertaining and I promise not to use the
1:04C word in this course
1:05again. Let's get started.
Certification Information
0:00Okay, so to get us started, I figured the logical place to start would be the
0:04exam blueprint.
0:05Let's take a look at the blueprint, see what's in the exam, what's not in the
0:09exam, which
0:10is just as important as knowing what is in the exam, how it's scored and so
0:15forth.
0:15And then next, I wanted to share a little bit about my learning philosophy and
0:20maybe
0:20some tips and tricks to help you get the most out of this course.
0:25Now, for the rest of this course, sometimes I'll be here talking to you like
0:30this.
0:31Sometimes I'll be in a little box down here at the bottom.
0:34And sometimes I'll just be lurking in the shadows, which is what I'm going to
0:39do right
0:39now.
0:40So here we have the AWS certifications and there's more cropping up every now
0:46and then.
0:47Sometimes they end of life.
0:49Some of these certifications, sometimes they create new ones or consolidate.
0:53So one of the things I wanted to point out here is here is the security
0:57specialty certification
0:59right here.
1:00And it is a higher level certification.
1:03It is a more advanced certification.
1:07It's not quite as large as the solutions architect, but it's pretty specialized
1:13.
1:13So you are expected to have components that are covered in these certifications
1:20down here
1:21and this certification here.
1:23Now, this does not mean that you must have these certifications in order to
1:28take this
1:28exam, but the knowledge learned in pursuing some of these certifications will
1:35help support
1:36this.
1:37So hopefully you have some AWS background and you're not coming in new because
1:42as I
1:42said, this is not really a course for somebody just getting started in cloud or
1:48just getting
1:49started in AWS.
1:51So right here in the blueprint AWS says you need to have three to five years
1:55experience
1:56with security solutions and a minimum of two years hands on with AWS.
2:03Now this is a little bit deceptive because as we all know, somebody can just
2:08play around
2:09with S3 buckets for a whole two years and that doesn't constitute what they're
2:13trying
2:14to say is two years of hands on with AWS.
2:19You should have a pretty broad level of knowledge and experience with using AWS
2:24.
2:25Know your way around the console.
2:26Know your way around the CLI.
2:29So that's what they are expecting here.
2:32So for example, if I say something like this, hey, can you go set up a VPC with
2:36one subnet
2:38and spin up an EC2 instance there with a 50 gig EBS volume.
2:42And we're also going to launch an RDS instance along with an EFS share.
2:47Now if I say something like this and you literally have no idea what I'm
2:52talking about, then
2:54this might not be the best starting point for you.
2:58You can learn all of this in one of my other courses, like the certified cloud
3:03practitioner.
3:04Now if you said to yourself, I know how to do all that stuff, then I think you
3:08'll be fine.
3:11Bonus points, if you started critiquing my design, if you said, hey, let's not
3:14use EC2,
3:16let's use some Lambda functions and Aurora serverless as the data store, then
3:20you're
3:20going to be doing just fine.
3:23So what is in this certification, the basics of AWS architectures, security
3:29controls and
3:30concepts, disaster recovery strategies, cryptographic and key management, data
3:35retention, lifecycle
3:36management, threat modeling and mitigation.
3:40So what's out?
3:41We're not going to be doing any software development.
3:43We're not going to be managing the SDLC lifecycle.
3:48We're not really going to be doing network design.
3:51However, we do have to build some networks because if we want to deploy, for
3:56instance,
3:57an EC2 instance to act as a honeypot, for example, we need to build a network
4:02such that
4:02we can deploy that resource.
4:05And also we're not going to be expected to architect whole deployments.
4:10Now here's one of the things that is a little bit deceptive about this security
4:16specialty.
4:17The amount of services, if you compare them to some of the other certifications
4:21, the amount
4:22of services is relatively small because AWS has a certain toolbox of security
4:29related
4:29tools.
4:30But the problem is those same security related tools apply to virtually every
4:36single one of
4:37the AWS services.
4:39So that's what AWS is saying here is that although we don't specifically call
4:45out services in
4:47the blueprint that are in scope, we might still have questions on those
4:52services on
4:52the exam because it relates to how we would use security principles and best
4:58practices
4:59with those services.
5:02So let's take a look at what the exam is like.
5:04It's still a multiple choice or multiple response and some of the more recent
5:09exams or some
5:10of the more recent certifications, AWS is starting to try to implement or
5:15incorporate
5:15some labs, which I think are a good thing.
5:18But as far as right now, this particular certification is still using the
5:22multiple choice
5:23or multiple response method.
5:26There are 50 scored questions and 15 unscored questions.
5:31Why in the world would there be unscored questions?
5:33Well, when the question writers write new questions to put into the question
5:40data bank,
5:41they need to test out those questions because maybe they have some sort of
5:45error in them
5:45or maybe they're ambiguous.
5:48And another reason why we have unscored questions is whenever a new service
5:52comes out, AWS is
5:53going to try to write questions for those new services and incorporate them
5:59into the
5:59test question data bank.
6:01Now, one thing to note and I get this question all the time is whenever a new
6:05service comes
6:06out, are we expected to know that new service?
6:09For example, if something is released last week, is it going to show up on the
6:14exam this
6:14week?
6:15Well, the answer is maybe, but most likely it's going to be an unscored
6:21question.
6:22So AWS has an internal policy that says that something has to be GA for at
6:32least six months
6:34before it can show up on an exam as a scored question.
6:39So don't worry too much about all the new services that get announced for
6:44reinvent,
6:45for example.
6:46And especially if they're in preview or beta, they have to become GA generally
6:51available.
6:52And then that has to be generally available for six months before it will show
6:56up as a
6:56scored question.
6:58So passing score is 750 out of 1000.
7:02And because everybody's test is different, it consists of a different
7:06collection of questions.
7:08The scoring is scaled, meaning that some questions are acknowledged to be more
7:14difficult than
7:15others, and AWS has some internal normalization that they try to apply to make
7:22sure everybody
7:23gets a fair shake.
7:25So that's a quick walkthrough of the exam itself in the blueprint.
7:29Let's keep going.
7:30[BLANK_AUDIO]
Course Expectations
0:00Everybody has different learning journeys.
0:03I fully understand that people are coming to this course
0:06for different reasons.
0:08And rarely are those learning journeys
0:11perfect linear blinds.
0:13As a matter of fact, in my case,
0:14there's a bunch of loopty loops and cutbacks and so forth,
0:18but here we are.
0:20So I wanted to take a few moments
0:22to explain some of my learning philosophy
0:24and also how you might be able to maximize the benefit
0:28out of this course using not only the resources
0:32inside the course, but also some resources
0:35that you have access to beyond this course as well.
0:40So for example, I know that there are people out there
0:43that have a love of learning.
0:46Something comes out new, they're early adopters,
0:48they just wanna learn all the things.
0:51I also realize that there's people taking this course
0:54who are focused on career advancement.
0:57And that is a perfectly valid thing
1:00because certifications are a very useful thing
1:04in building out your resume
1:06and building out your portfolio.
1:08There are also those who are coming to this course
1:11because maybe they're curious or skeptical.
1:15Maybe this idea that, oh, well,
1:17if I put something on the cloud,
1:18it's inherently insecure.
1:21They probably don't believe that.
1:23And I don't believe that either.
1:24I think there's ways to perfectly secure information
1:29on the cloud.
1:30And by saying that, it's like saying that my money
1:34is more secure if I stuff it under my mattress
1:36than it is if I put it in a bank.
1:38It just doesn't make sense.
1:40So I welcome those skeptics out there
1:43or the folks that are just curious in this course
1:46or gonna learn some of those best practices
1:49that will keep our data secure.
1:51And then I also understand that there is a segment of folks
1:56who have been volintold.
1:58Hey, we are moving to AWS.
2:01You need to go learn AWS security
2:04so you can keep us safe.
2:06I understand that.
2:08And I appreciate it.
2:10And I stand with you on your learning journey
2:13for all those who have been volintold.
2:16And I appreciate that you selected this course
2:19for your volintold assignment.
2:22Now I wanted to talk a bit about Bloom's taxonomy.
2:26Now this is a way to organize different levels of learning.
2:31And down here at the bottom,
2:33this is kind of considered the basic level of learning.
2:36This is the most simplistic or the most elemental.
2:40And it's just asking us to remember stuff
2:43and examples of this are like memorization.
2:46We had to memorize our multiplication tables, for example.
2:50And at least what we were told at that time is,
2:53oh, that's so important
2:54because that's going to help us understand stuff.
2:58So understanding is kind of the next level up
3:00in complexity of learning.
3:02And then once we understand the hows and whys of things,
3:06then we should be able to apply them.
3:09Now this is the important step here
3:12because down here,
3:14we're not really building any sort of value
3:17or contributing our value to an organization
3:20or a school or something like that.
3:23We're just building some of the building blocks
3:27of these higher level actions.
3:30And that's what organizations,
3:32if there's a hiring manager here, I'm more interested,
3:35how can you actually apply your knowledge
3:38or maybe use your knowledge to analyze a situation
3:42that we're in and build something that fixes that problem?
3:47So when we talk about developing knowledge,
3:50really what I want to focus on
3:52is everything above this layer right here.
3:56So we are not going to spend a lot of time memorizing stuff
4:00and maybe a little bit of time understanding
4:03just because it's sometimes necessary,
4:05but we want to focus as much as we can
4:08on the application of these things that we learn.
4:13So within every skill in this course,
4:16we're going to have a lab, a hands-on exercise
4:20that you need to do.
4:21And I want you to do those things
4:23rather than just kind of kicking back, watching me do them.
4:27In some cases, I'm going to have challenges
4:29where I'm going to lay out a scenario
4:31and I want you to try to complete that scenario
4:35or solve that problem or whatever.
4:37And this is going to help us develop this apply aspect,
4:42which is really what AWS wants us to be able to do.
4:45And that's what employers want us to be able to do.
4:48So if we go back to our certifications here,
4:52does getting one of these certifications
4:54really prove that we have knowledge?
4:58No, not at all.
5:00I think we all know somebody who has a ton of certifications
5:04and they couldn't architect their way out
5:06of a wet paper bag, for example.
5:08And conversely, I'm sure we know lots of brilliant people
5:14who, for one reason or another,
5:15whenever they sit down in an exam,
5:17they just kind of lose their mind
5:19and they don't test very well,
5:21they're still very, very capable
5:23and they have lots of knowledge,
5:24but they just don't have the little certification
5:27on their profile or hanging on their wall.
5:30And just so we're on the same page,
5:32I wanted to let you know that I do not believe
5:35that certifications are proof of knowledge.
5:38However, I do believe that certifications
5:41are a very useful framework for learning.
5:44And that's, at the end of the day,
5:45that's what we want to do, we want to learn.
5:48We just don't want to rack up certifications
5:50and still have that gap in our knowledge
5:54because if we go into an interview with that certification
5:56and we can't really walk the walk,
5:59then that's gonna be very embarrassing
6:01and very uncomfortable for us.
6:03So in this course, I'm going to focus heavily
6:06on the understand, apply and analyze
6:08and not so much on the memorize.
6:11And I really want you to look at this
6:13as something greater than just passing an exam.
6:17The intent here is that we build a knowledge set
6:20and sure we can use the exam to test that knowledge
6:23and evidence that, but just having that certification
6:27doesn't mean that we really know what we're talking about.
6:30I want you to focus on building that
6:32you know what you're talking about, confidence,
6:36that's so important.
6:37And along those same lines,
6:39I'm going to build scenarios within this course
6:43that is gonna help you try to apply that.
6:46And I'm gonna try to make these scenarios
6:47as realistic as possible within bounds and within reason,
6:52but still entertaining and still a bit fun to do.
6:57So within this course, we're gonna use
6:59a variety of different learning methods.
7:01We're gonna use of course, audio visual,
7:03which you are experiencing right now.
7:06We're gonna use text.
7:07Now inside the skills in between the videos,
7:11I include textual information a lot of times.
7:14Sometimes it's a link, sometimes it's a YouTube video
7:16that I suggest you watch, but that stuff is important.
7:19Do not skip that stuff because that stuff is just as important
7:23as the audio visual components.
7:25I will also sometimes direct you to AWS content.
7:29Maybe it's a white paper.
7:30Maybe it's a blog that does just a beautiful job
7:33of explaining something.
7:34And it doesn't really make sense for me to regurgitate
7:37that inside the context of the course.
7:40We're also gonna have quiz questions.
7:43So there are gonna be quiz questions as we go
7:46throughout the skill.
7:47And at the end of every skill,
7:49we're gonna have a validation section.
7:51And I'm going to include some questions
7:54that are written in the style of the AWS exam
7:59to help you get comfortable with some of the tricks
8:02they try to use to trip you up.
8:04Now sometimes we're gonna have hands-on follow-alongs.
8:07I'm gonna show you how to do something
8:09and I would really encourage you to actually follow along
8:12and do the same thing.
8:14So you start building that muscle memory
8:16and that familiarity with doing things
8:18either in the console or the CLI.
8:21And then we're also gonna have some challenges here and there.
8:24And these are the scenario based things
8:26that I was talking about,
8:27where I'm gonna build these scenarios
8:29and challenge you to solve them.
8:31And then afterwards, I'm gonna show you how I solved it.
8:35Not saying that that's the only way to solve it,
8:38but we can compare notes and see how you did
8:40versus how I managed to address the issue.
8:43Now beyond this course material,
8:46there are some other things that you can do
8:48to kind of enrich your learning.
8:49Maybe have a study group.
8:52I know there are folks that have a lunch and learn,
8:55for example, and they'll watch a skill during their lunch hour
8:59and kind of follow along as I go through these things.
9:03Flashcards, flashcards help as well
9:06if you're trying to learn or memorize.
9:09But again, I wouldn't focus too much on the memorization.
9:12AWS typically does not ask you to memorize
9:16what's the system spec for a T4G nano instance
9:20or something like that.
9:21That's not gonna show up on an exam.
9:23But sometimes if you're talking about concepts
9:26or vocabulary words or something like that,
9:28flashcards might help.
9:30There's also the AWS documentation.
9:32Do not discount this as a source of information,
9:37but also a source of test questions.
9:41I'm gonna point out some cases in the AWS documentation
9:45where they use certain little flags
9:47to kind of give you a hint that says,
9:49hey, we believe this is very important.
9:51You might wanna know this for the exam.
9:53And another way is just talk to folks.
9:55Talk to folks who have already been through this cycle
9:59who are well-versed in AWS security.
10:02If you happen to go to a conference,
10:03maybe sit in on some seminars or something like that.
10:07So there's a lot of different ways
10:09that you can really kind of enrich your learning
10:12beyond just the content offered in this course.
10:17And by the end of this course,
10:19I really want you to have this common understanding
10:23of AWS security strategies
10:25and why AWS does things the way they do
10:28and how it does things the way they do.
10:31And I want you to effectively apply those strategies.
10:34Remember, that's what employers care about.
10:36Can you actually turn that knowledge into value?
10:40And AWS has a host of best practices that they recommend.
10:45But also more importantly,
10:47that you are familiar with some of the potential dangers on.
10:50Some of the things that we don't wanna do
10:53with our AWS account.
10:54And of course, I want you to smash
10:56that certified security specialty exam.
11:00And another thing I want you to do
11:02after you've gone through this course
11:04is maybe help somebody else out.
11:07Help somebody either start or continue
11:10on their cloud journey, their cloud security journey.
11:13So that's that.
11:15Let's get our hands dirty and get out there in the console
11:18and actually start doing some stuff.
Creating our AWS Account
0:00For the rest of the skill, we are going to create an AWS account and apply some
0:05security best practices to it.
0:07Now you may be saying, "Hey, I already got an account. My employer gave me an
0:10account that I can play with."
0:12I would really recommend against that because in some cases we are going to be
0:16implementing some bad security practices
0:19to be able to test some of our audits and some of our tools.
0:23And you may inadvertently open up your organization to stuff that you don't
0:28want to open up.
0:30So I would really suggest that you just create a personal account. It's fairly
0:33easy.
0:34You're going to be in the free tier. All the stuff in this course tries to be
0:37in the free tier.
0:39Occasionally we have to venture off a little bit, but it's not going to cost
0:42you much at all.
0:44And it is well worth the potential exposure that you might inadvertently do,
0:49especially if you're just learning some of this security
0:52with AWS that you might inadvertently expose your organization to some
0:57additional risk that is not needed.
1:00So just create a personal account. So let's do that right now.
1:04And to do that, we just go out to aws.amazon.com. We'll come up here to says, "
1:09Create an AWS account."
1:10We click on that and it's going to take us to this other screen.
1:15And we're being asked to give a root user email address.
1:19Now, let me enlarge this a bit. Here we go.
1:22Now this is an email address for the root user. The root user is the most
1:26important and the most powerful user inside an AWS account.
1:32There's nothing that this user cannot do, which means that we need to really
1:37secure it.
1:38And ideally, just like in a regular Linux system, for example, you don't use
1:42root for your daily driver account.
1:45You use a user account. And then if you need to assume root, then you use a
1:50sudo or something like that.
1:52And we can do the same type of thing. So we don't want to use our root account
1:55for everything.
1:56But nonetheless, we still have to create a root account.
2:00So I'm just going to enter an email address here. Now we're being asked for an
2:04account name.
2:05And we can change this name later, but let's just say, "Plecher security."
2:10And I'm going to click verify email address. And it will send us some sort of
2:15email to this email address.
2:18Going out to my email, there's the code. I'm going to paste this code in here,
2:22verify it.
2:23Now we're being asked for a password. And it's really best practices to use a
2:28very complex password here.
2:30However, we're also going to enable MFA, but you really should have a
2:34relatively complex password.
2:36So I just entered my proposed password and it meets all the criteria here.
2:41And I'm going to continue to the next step.
2:44Now it is asking us whether this account is for business or personal use. It's
2:49for personal use.
2:50And I also have to enter some personal information here. So I'm going to do
2:53that and proceed on to the next step.
2:57Now in this next step, we have to enter a debit card or a credit card, some
3:00sort of payment card.
3:02I'm going to enter my details here and then proceed to the next step.
3:06Next, we're being asked to confirm our identity. And it wants to either send us
3:11an SMS or an automated voice call.
3:14I'm going to enter my mobile phone number here and proceed to the next step.
3:19So my code just arrived on my phone. I'm going to enter that there and proceed
3:22to the next step.
3:24Now it's going to ask us if we want to sign up for a support plan.
3:28And for our purposes, we're just going to keep it at basic support. That's a
3:32free tier.
3:33We can also, if we wanted to sign up for the developer support or the business
3:36support, if you are a professional organization,
3:39I would highly recommend at least sign up for the business support.
3:43But for our purposes, the basic is just fine. And we can complete the sign up
3:48process.
3:49And that's all we have to do. Now we can go login to the AWS Management Console
3:56.
3:56console, and that's where we're going to pick up the next video.
Applying MFA to our Root User
0:00Okay, in our last video, we just finished up creating our account. Now we can
0:03sign into our account.
0:05Just click this little box up here and it's going to give us this prompt. Now
0:08right now,
0:09they are testing a new UI experience. By the time you watch this video, your
0:13user interface may
0:14look a little like this and may look a little different. But nonetheless, it
0:19still has all the
0:20same parts and pieces. Now, by default, we are dropped here to an IAM user sign
0:27in. That's an
0:28identity and access management user sign in. And that is a best practice. We
0:31should be using
0:32an IAM user for 99.999% of our activity in our account. But because it's a
0:39brand new account,
0:40we only have our root user. So we're going to have to log in as our root user.
0:45But what we want to do
0:46is protect our root user with MFA. So let's go down here to click this button
0:52here sign in using
0:53root user email, going to enter the root email address that I used, and the
0:59password, and sign in.
1:02Now right off the bat, it's going to prompt us to enter an MFA device or
1:07register an MFA device.
1:09I'm partial to UB keys. I probably have about six or 70s things. And I use them
1:14whenever I
1:15possibly can for as many different things as I can. I also have this little
1:21hardware token here.
1:21It has a little button where it gives you a LCD readout of a number there. You
1:26can also use an
1:27application like LastPass or Bitwarden or something like that. I would really
1:32recommend
1:33at a minimum, you can set up keys, sure, hardware keys. But if you're sharing
1:38this account with
1:39other people, then you want those root credentials to be stored in some
1:44location that if you have
1:46to break the glass, you can get access to them. So maybe use LastPass or Bit
1:50warden where you can
1:52actually share that password and that account with some colleagues so that if
1:56they need to get in
1:57there and get access, they have that authentication code set up as well. So for
2:02our purposes, I'm going
2:04to create an entry for my UB key that I'm going to show you how we can also add
2:10an authenticator
2:11app called us UB key for Neo. And let me plug it in here. And then I'm going to
2:17click next.
2:18There we go. So that's as easy as it is to set up a multi factor authentication
2:27for our root user.
2:29I'm going to continue to the console. And I'm also going to show you how we can
2:33set up
2:34another alternative way to log in. So we can go up here to this little drop
2:38down here
2:39and go down to security credentials. So let's enlarge this a bit. So here's my
2:46account number.
2:47And if you didn't notice, here's my account number up here. Now for some reason
2:50, people are
2:51very sensitive around account numbers. AWS themselves does not consider AWS
2:56account numbers to be
2:57sensitive or any sort of private thing that needs to be kept private. So I don
3:03't keep them private.
3:05There's really if you secure your account properly, there's really nothing
3:09anybody can do with just
3:11knowing your AWS account ID plus I go through accounts so often that by the
3:17time this course
3:18actually gets published, this particular account is going to be long gone and
3:22closed out. But anyway,
3:24here are we're at the security credentials. It's telling us it's the root user
3:28here. If we go down
3:29here to multi factor authentication, we have our our past key that's already
3:33been set up. We can
3:34assign another device here. Let's call this bit warden. And I can scroll down
3:40here to
3:41authenticator app. And it's going to give me either a QR code or the secret key
3:47here. Now I am just
3:48going to use the secret key here. And I'm going to enter that into bit warden
3:52over here. And it
3:54requires me to enter my code or the codes that were generated down here. And I
3:59have to enter two
4:00codes in succession. Add the MFA device, there we go. So there, my virtual MFA
4:08device has been
4:09registered. So you can register up to eight of these. Again, I would really
4:14recommend that you use
4:15kind of a shared password vault for your root user. It's not so important for I
4:20am users. If you
4:21happen to lose your root credentials or unintentionally lock yourself out,
4:27there is a process to get
4:28back in, but it is a major hassle. So please do not do that. Okay, so there's
4:34one more thing that we
4:35have to do with our root user before we're ready to create our I am user. And
4:41that is enable some
4:43permissions for billing access. And this is something that has to be done under
4:48the root account. So
4:50to do that, we're going to go up here to this little dropdown, we're going to
4:52go to account.
4:54And then we are going to scroll all the way down. Scroll, scroll, scroll. And
5:02then we're going to get
5:03here, I am user and role access to billing information. So I'm going to click
5:08on edit, I'm going to
5:09click this little checkbox and click update. What this is going to do is allow
5:14us to assign permissions
5:17to our I am user to be able to look at billing information. In other words, our
5:22budgets, our costs,
5:24and stuff like that. So that's a good thing. Now in the next video, we are
5:28going to create our
5:29I am user. And from there on out, we are going to use that I am user instead of
5:34this root user.
Creating an IAM User
0:00Okay, here we are still logged in as our root user. We are going to create our
0:04IAM user.
0:05To get there, we type in IAM up here. And what does IAM stand for? Identity and
0:11Access Management.
0:12And this is the central tool for dealing with logins and users and permissions
0:18and whatnot.
0:19And we're going to do a very deep dive into this whole service later. But for
0:24now, I just want us
0:25to create an IAM user so that we can use so that we're outside of the danger
0:30zone of constantly
0:31using our root account. So I just click on users here. I'm going to click
0:36create user. Give it a name.
0:37Provide access to the AWS console. Yes, we want to do this. Now it is giving us
0:44a choice here.
0:45It is saying, do we want to create an identity center or do we want to create
0:49an IAM user?
0:50Now identity center is something that we are definitely going to cover. But for
0:54now, I want to
0:55try to keep it simple and do old school. So we're just going to create an IAM
0:59user.
1:00And I'm going to use a custom password here that I'm going to enter. And we can
1:04also have the user
1:05whenever they log in, reset the password themselves. I'm going to uncheck that
1:09because I'm me. And I
1:11know what my password is. I'm going to click on next, and it's going to ask me
1:16for what sort of
1:17permissions do I want to assign to this particular user? Now, we can assign
1:23permissions directly,
1:25or we can add the user to a group. I'm going to create a group. I'm going to
1:29name this group
1:30administrators. And now I can choose what sort of permissions do I want to
1:35assign to this group.
1:37So I'm definitely going to assign administrator access. And then I also want to
1:42assign something
1:43called billing down here. That's going to allow us to access the billing
1:48information inside this
1:50account from our IAM user. So I'm going to create that group. And it's asking
1:55us, okay, here's your
1:56group. Do you want to assign that user to this group? Yes, I do click next. And
2:02it's going to give
2:03me a little confirmation screen here. There we go. So it has a username, it has
2:08the password here,
2:09it's even given us a little URL that we can use as a shortcut to be able to
2:14sign in to our console.
2:16We can even email instructions to whoever we created this user for. So I'm just
2:22going to copy that.
2:23I'm going to return to the users list. And I'm done for the moment, I'm done
2:29using my root account.
2:31And generally speaking, I don't think in this whole course, we're even going to
2:35have to use
2:36this root account again. I think maybe we will when we set up AWS organizations
2:40. But for the most
2:42part, just put that password away, put that MFA away, lock it away. Don't use
2:47it. Use your IAM
2:48user from here on out.
Enabling CloudTrail
0:00Okay, so I use the URL that it prepared for so I'm going to bookmark that so I
0:04have it when I need it and
0:06I'm going to enter my IAM username here and
0:09my password and
0:12Then click sign in
0:14There we go now you'll notice that we were able to just sign in
0:18But what we need to do is add MFA to this account as well. Yes, that is correct
0:24This account as well needs MFA access
0:26so we're going to go down here to security credentials from this little drop
0:30down up here and
0:31Right off the bat here. It's saying hey, you don't have MFA assigned. Well, of
0:37course
0:37we're going to sign it and I'm going to register my same UV key and
0:41Pass keys fine next
0:44There we go, so now it is registered here if I wanted to I could add another
0:55device
0:56here
0:57But I'm okay with just the UV key for now. So now with MFA enabled on this
1:02account
1:03I'm reasonably confident that it's fairly secure at this moment
1:08But what we need to do is enable some other things for our account the first
1:12thing we want to enable is
1:14Something called a cloud trail and we're going to cover this in more detail
1:18later
1:18But think of cloud trail is kind of like an eye in the sky
1:22It's going to capture all the API activity going in and out of your account
1:26And if something bad happens then you're going to have this trail to be able to
1:31go back through and
1:33Evaluate what maybe happened
1:36so we're going to click on create a trail and I'm just going to call it
1:40management events and
1:41It's going to propose an s3 bucket name here that it's going to create
1:46So whenever something happens with our account
1:49It's going to log it into this trail name management events into this bucket.
1:54So I'm going to click create the trail
1:55That's it. That's all we have to do
1:59so we can go over here to this s3 bucket and
2:01We can see that we have a cloud trail folder here
2:04It's going to take a little bit of time for these entries to start showing up
2:09but later in this course we are going to analyze these entries and
2:13Set up notifications for whenever maybe somebody has an erroneous login or some
2:19sort of threat
2:20Maybe happening we can set up an alert to alert us
2:23So it's really important right now that you go ahead and turn this on so we can
2:26start building some history here
2:28Such that we can have access to it
2:31So that is creating cloud trail in the next video
2:35We want to do something that's also just as important and that's setting up a
2:39budget alert
Set up a Budget Alert
0:00Okay, the next best practice that I want to implement is to set up a budget
0:05alert so that if I spend too much, I get notified before I get this shocking
0:09bill at the end of the month that says, "Hey, I owe $600 because I forgot to
0:15turn off an instance or something like that."
0:17So to help prevent that, we are going to go to Building and Cost Management and
0:24we go down here to Budget Status. It says, "Set Up Required." We're going to
0:29click on that.
0:30And it's going to bring us to a page that we can select a budget. We can either
0:34use a custom budget or use a ready-made template.
0:38And we have a couple different options here. We have a zero-spin budget.
0:43Basically, if we go outside the free tier, it's going to alert us of that. That
0:48may be something you want to do.
0:49I am going to use a monthly cost budget. We are able to supply some sort of
0:54number that if it exceeds or if we're on the trending towards exceeding that
0:59number, it's going to notify us.
1:02Now, down here, these daily savings plan coverage, these daily reservation
1:07utilization budget, these are really outside the scope of this particular
1:10course. They have to do with savings plans and reservations for EC2 and other
1:17compute services just to make sure that we're trying to fully utilize those
1:21particular contracts, but we are not going to go into those.
1:25Down here, I'm just going to say 100 bucks a month, sure. I'll leave the budget
1:30name the same, and now we're going to enter the email address that we want to
1:35send these notifications.
1:37And you can see here, we are going to get a notification when our actual spend
1:43reaches 85%, or we reach 100%, or if we're forecasted to exceed or reach 100%.
1:51So I'm going to click on Create Budget. That's it.
1:53That's all you have to do. So turning on CloudTrail, enabling a budget,
1:58enabling MFA, that will cover you and get you pretty far.
2:02So I think we're in a good position to really get underway in this course.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year