
AWS Certified Advanced Networking – Specialty (ANS-C01) Certification Guide
By :

In this chapter, you learned about the cloud shared responsibility model and how AWS implements it. Of particular importance is that the customer is always responsible for IAM and data, regardless of the service model. You learned about using network segmentation to divide the network into zones as a way of enhancing security. You also learned about threat modeling along with common attacks and their corresponding countermeasures, which will give security-focused engineers a playbook to start tackling threats in their own networks. You learned some of the most common categories of threats, which will help you organize the security features that AWS offers into a more understandable framework. On the exam, you will be better able to identify the appropriate security services to employ based on the threats mentioned. You learned about the mechanisms available to secure application flows and encrypt data in transit. Lastly, you reviewed DNSSEC and split DNS as methods for securing...