Lesson 184 · AWS Learning Path

AWS 184: Encrypt data, protect secrets, terminate TLS, and review findings

· Published · 9 min read

Labelled process diagram for AWS 184: Fake secret and TLS requirement to Encrypted parameter and validated certificate to Authorized workload and protected endpoint to Finding review and cleanup evidence, with...

Why this lesson matters

Prove encryption, secure parameter handling, TLS certificate state, and finding review using free or near-free controls and supplied evidence for paid services.

What you will be able to do

By the end, you can:

  • explain encrypt data, protect secrets, terminate tls, and review findings in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This lesson has an optional live path. Check current prices, obtain the account owner's approval, set a hard timer, use course tags, and complete the stated cleanup. The evidence path is a complete alternative.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposeProve encryption, secure parameter handling, TLS certificate state, and finding review using free or near-free controls and supplied evidence for paid services.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Security controls lab.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Security controls lab.
Cost modelStandard parameters can be no-additional-charge within limits, while advanced parameters, API interactions, Secrets Manager, customer KMS keys, certificates, findings services, and logs may charge.
Safe rejection ruleAvoid real credentials, customer-managed key creation, CloudHSM, public secrets, shared screenshots of values, or unvalidated cleanup.

How the request flows

+-----------------------------------+
|  Fake secret and TLS requirement  |
+-----------------------------------+
                 |
                 v
+-------------------------------------------------+
|  Encrypted parameter and validated certificate  |
+-------------------------------------------------+
                        |
                        v
+----------------------------------------------+
|  Authorized workload and protected endpoint  |
+----------------------------------------------+
                       |
                       v
+---------------------------------------+
|  Finding review and cleanup evidence  |
+---------------------------------------+

Architecture decision table

SituationDirectionReason
Requirement matchesUse the live parameter exercise only with scoped permission and fake data; use supplied evidence for certificates and findings when no owned domain or service exists.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid real credentials, customer-managed key creation, CloudHSM, public secrets, shared screenshots of values, or unvalidated cleanup.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open KMS aliases, Systems Manager Parameter Store, ACM certificates, and supplied security findings; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws kms list-aliases --query 'Aliases[?starts_with(AliasName, `alias/aws/`)].AliasName' --output table
aws ssm describe-parameters --parameter-filters Key=Name,Option=BeginsWith,Values=/nw/p05/ --output table
aws acm list-certificates --query 'CertificateSummaryList[].{Domain:DomainName,Status:Status}' --output table
aws securityhub get-findings --max-results 10 --query 'Findings[].{Title:Title,Severity:Severity.Label,Status:Workflow.Status}' --output table

Expected interpretation

The pass records encrypted-at-rest configuration, value redaction, least-privilege retrieval evidence, certificate validation and attachment state, finding triage, and zero temporary parameters or certificates.

Practical work

Create one temporary SecureString parameter with a fake value only, retrieve it without displaying the value in shared evidence, delete it, then analyze supplied TLS and finding captures. Use no customer-managed KMS key or CloudHSM.

Safe live exercise

Use fake text only. The command below creates one temporary SecureString through the AWS-managed Parameter Store key path. Do not print its value into screenshots, transcripts, or logs.

aws ssm put-parameter --name /nw/p05/lab/fake-api-token   --type SecureString --value 'training-value-not-a-real-secret'   --description 'Temporary AWS 184 training value'   --tags Key=Project,Value=NitWings-P05
aws ssm get-parameter --name /nw/p05/lab/fake-api-token   --query 'Parameter.{Name:Name,Type:Type,Version:Version}' --output table
aws ssm delete-parameter --name /nw/p05/lab/fake-api-token
aws ssm describe-parameters   --parameter-filters Key=Name,Option=BeginsWith,Values=/nw/p05/lab/ --output table

The final result must be empty. Use supplied evidence for ACM, GuardDuty, Inspector, Macie, Security Hub, or CloudHSM unless the account already has an owner-approved service state. Never enable a paid security service simply to make this lesson look practical.

Lab runbook: produce four independent proofs

1. Preflight and ownership

Record caller ARN, account alias (not account ID in shared work), Region, start time and approved resource prefix. Check current Parameter Store pricing/tier and create a cleanup trap before mutation:

set -euo pipefail
export AWS_DEFAULT_REGION="ap-south-1"
parameter_name="/nw/p05/lab/fake-api-token"
cleanup() { aws ssm delete-parameter --name "$parameter_name" >/dev/null 2>&1 || true; }
trap cleanup EXIT
aws sts get-caller-identity --query Arn --output text
if aws ssm get-parameter --name "$parameter_name" >/dev/null 2>&1; then
  echo "Stop: owned test parameter already exists" >&2
  exit 1
fi

The last check distinguishes not-found from every other error imperfectly; if it reports anything unexpected, inspect manually before proceeding. Never overwrite an existing name with --overwrite in this lab.

2. SecureString metadata and audit proof

Create fake data, then inspect metadata without --with-decryption or a value query:

aws ssm put-parameter \
  --name "$parameter_name" \
  --type SecureString \
  --value 'training-value-not-a-real-secret' \
  --description 'Temporary AWS184 training value' \
  --tier Standard \
  --tags Key=Project,Value=NitWings-P05 Key=Owner,Value=student

aws ssm get-parameter --name "$parameter_name" \
  --query 'Parameter.{Name:Name,Type:Type,Version:Version,Modified:LastModifiedDate}' --output table
aws ssm describe-parameters \
  --parameter-filters "Key=Name,Option=Equals,Values=${parameter_name}" \
  --query 'Parameters[0].{Name:Name,Type:Type,Tier:Tier,KeyId:KeyId}' --output table
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=EventName,AttributeValue=PutParameter \
  --max-results 10 --query 'Events[].{Time:EventTime,User:Username,Event:EventName}' --output table

Evidence proves name, type, version, tier, KMS-key reference and actor/time. It must not contain Parameter.Value, the fake value, account number or full ARN. Explain why SSM permission and KMS decrypt permission are separate on a customer-managed-key path.

3. TLS proof from the client and AWS control plane

For an instructor-provided hostname, prove DNS target and the certificate actually served:

host="replace-with-approved-hostname"
dig +short "$host"
openssl s_client -connect "${host}:443" -servername "$host" -showcerts </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -issuer -serial -dates -ext subjectAltName
curl --fail --show-error --verbose "https://${host}/" -o /dev/null

Then, only if the account already owns the certificate, correlate its ACM ARN, status, renewal eligibility and InUseBy associations with aws acm describe-certificate. Client proof catches wrong SNI/default certificates; ACM proof catches validation/renewal/association state. Do not use curl -k.

4. Finding triage without enabling a paid service

Use an instructor-supplied redacted ASFF finding, or an existing owner-approved Security Hub state. Record finding/product IDs, account/Region, resource, created/updated/processed times, severity, record/workflow state and remediation. Correlate one source event. Mark RESOLVED only after new source/control evidence proves the underlying correction; a workflow update is not remediation.

Mandatory cleanup and evidence gate

cleanup
trap - EXIT
if aws ssm get-parameter --name "$parameter_name" >/dev/null 2>&1; then
  echo "FAIL: temporary parameter still exists" >&2
  exit 1
fi
echo "PASS: temporary parameter absent"

The submission contains preflight, metadata-only encryption proof, CloudTrail actor/time, TLS client/control-plane correlation, redacted finding timeline, cleanup proof and a cost statement. It contains no secret value, private key, account ID, full ARN or customer data.

Diagnose this topic from its own evidence

  • AccessDenied on create/read: identify whether SSM, KMS, boundary/SCP or endpoint policy denied; do not add administrator access.
  • SecureString exists but metadata lacks expected key: distinguish AWS managed alias/aws/ssm from an explicitly selected customer key.
  • TLS hostname mismatch: compare requested SNI, SANs, DNS target and listener default/additional certificates.
  • ACM ISSUED but client still serves old certificate: inspect actual association and distribution/listener deployment.
  • Finding changed to resolved without resource evidence: reopen workflow and obtain a fresh detector/control result.

Cost and cleanup

Standard parameters can be no-additional-charge within limits, while advanced parameters, API interactions, Secrets Manager, customer KMS keys, certificates, findings services, and logs may charge.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Prove encryption, secure parameter handling, TLS certificate state, and finding review using free or near-free controls and supplied evidence for paid services.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for Security controls lab.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for Security controls lab.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid real credentials, customer-managed key creation, CloudHSM, public secrets, shared screenshots of values, or unvalidated cleanup.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: Standard parameters can be no-additional-charge within limits, while advanced parameters, API interactions, Secrets Manager, customer KMS keys, certificates, findings services, and logs may charge.

Lesson acceptance

  • All four proof tracks are present and redacted.
  • SecureString was never printed or placed in evidence, and IAM/KMS boundaries are explained.
  • TLS hostname, chain, validity and actual service association agree.
  • Finding closure includes root remediation and fresh source evidence.
  • Cleanup inventory proves the parameter is absent; no security service, certificate, KMS key or HSM was created.

Official sources

Advertisement