Lesson 419 · AWS Learning Path

AWS 419: Security and compliance automation

· Published · 4 min read

Labelled process diagram for AWS 419: Original security and compliance scenarios to Identity, artifact and finding evidence to Block, correction or governed exception to Effective-control proof and changed retest...

Purpose and exam boundary

This checkpoint assesses DOP-C02 Domain 6 Security and Compliance, weighted at 17 percent of scored content in the current guide. Security must be integrated through source, build, artifact, deployment, runtime, organization governance and response rather than added as one scanner near production.

Scenario and evidence

A regulated company has 25 accounts. Pipelines store long-term keys, deployment roles are shared, images use mutable tags, secrets rarely rotate, Inspector and Config coverage is incomplete, findings are suppressed without expiry, CloudTrail data selectors are unknown and a production emergency change bypassed source control.

Evidence suppliedLearner decision
Trust/permission/SCP/resource/key policiesEffective access and escalation paths
Build manifests, SBOM, signatures and scansArtifact identity and admission trust
Secret versions/rotation/application errorsSafe credential lifecycle and consumption
Inspector/GuardDuty/Security Hub findingsCoverage, priority, workflow and response
Config rules/remediation historiesCompliance truth and safe correction
CloudTrail logs/digests/emergency recordCustody, identity and change reconstruction

Assessment tasks

  1. Replace static pipeline keys with federated temporary sessions; design trust claims, duration, source identity and revocation.
  2. Separate build, signer, artifact, deployment, stack execution and runtime roles; prove constrained PassRole and denied escalation.
  3. Create a digest/signature/SBOM/provenance admission policy for ECR and Lambda artifacts, including stale/failed scan behavior.
  4. Design Secrets Manager ownership, KMS/resource policies, single versus alternating-user rotation, caching, failure recovery and pipeline use.
  5. Prove Inspector coverage before prioritizing findings; write risk tiers, remediation SLOs, suppression/exception expiry and rescan closure.
  6. Design GuardDuty/Security Hub organization/Regional aggregation, idempotent routing, enrichment, authorized containment and workflow-state policy.
  7. Build a Config conformance pack/remediation classification with recorder proof, canary rollout, fresh reevaluation and exceptions.
  8. Trace effective authorization across identity/resource/key/session/boundary/SCP layers for ten requests, including service-linked-role limits.
  9. Design organization CloudTrail management/data selectors, S3/KMS custody, delivery reconciliation and digest validation.
  10. Reconstruct the emergency change, remove access, codify desired state, verify outcomes and create corrective controls.

Threat and failure analysis

Create a threat model for source contributor, compromised runner, artifact substitution, malicious approver, overprivileged deployer, compromised workload, member-account administrator and evidence-store administrator. For each state preventive, detective, responsive and recovery controls plus residual risk.

Diagnose eight cases: OIDC wildcard trusts forks, build can pass arbitrary role, signature belongs to another digest, rotation leaves AWSPENDING and stale clients, ECR zero findings with failed coverage, Security Hub suppression hides recurrence, Config automation reports success while rule stays noncompliant, and a CloudTrail digest chain has a delivery gap. Use evidence, not service slogans.

Quantitative and governance work

Calculate credential/session exposure windows, vulnerability/compliance SLO age, event/DLQ reconciliation, rotation overlap, audit retention/storage and remediation concurrency/error thresholds. State how cost changes with Inspector coverage, Config evaluations, CloudTrail data events, retained versions and centralized logs.

Write five policy decisions with alternatives: OIDC trust boundary, artifact signing authority, automated containment class, SCP invariant and emergency access. Include owner, rollout, negative tests, rollback and exception method. A guardrail that prevents recovery or can be bypassed by its operator is incomplete.

Cross-control proof

For three protected actions, build an end-to-end proof rather than listing controls. Example: a production deployment begins with a reviewed source identity, exchanges an OIDC token for a bounded session, reads an approved signed digest, passes a narrow execution role, mutates only declared resources, emits CloudTrail and Config evidence, and is admitted only while security findings and exceptions satisfy policy. Show where each control can fail open, fail closed or become unavailable.

Then test control independence. The same principal must not change the pipeline, signing policy, security gate, evidence store and production target. Central security aggregation must not be the only local response path. KMS, DNS, identity and logging dependencies need degraded-mode behavior. For each automatic response state the precondition, idempotency key, maximum blast radius, timeout, verification, compensation and human escalation.

Scoring and remediation

AreaPointsAutomatic failure condition
Identity/authorization20Long-term key or privilege-escalation path retained
Artifact/secret trust20Mutable identity or secret disclosed in artifact/log
Detection/compliance20Coverage gaps interpreted as compliant/safe
Organization/audit evidence20Audit custody or SCP semantics incorrect
Response/governance20Destructive unapproved automation or permanent exception

Pass at 80/100, no automatic failure and at least 60 percent in each area. Remediate each miss by citing the earlier lesson, correcting the design, running a changed negative case and attaching evidence. Memorizing managed-service names does not pass.

Submission acceptance

Submit ten task answers, policy evaluation matrix, threat model, eight incident analyses, calculations, five decisions, audit reconstruction and personal remediation map. Acceptance requires temporary least-privilege identity, immutable admission, proven coverage, expiring exceptions, reversible response and protected verifiable evidence.

Official sources

Advertisement