AWS 419: Security and compliance automation
Purpose and exam boundary
This checkpoint assesses DOP-C02 Domain 6 Security and Compliance, weighted at 17 percent of scored content in the current guide. Security must be integrated through source, build, artifact, deployment, runtime, organization governance and response rather than added as one scanner near production.
Scenario and evidence
A regulated company has 25 accounts. Pipelines store long-term keys, deployment roles are shared, images use mutable tags, secrets rarely rotate, Inspector and Config coverage is incomplete, findings are suppressed without expiry, CloudTrail data selectors are unknown and a production emergency change bypassed source control.
| Evidence supplied | Learner decision |
|---|---|
| Trust/permission/SCP/resource/key policies | Effective access and escalation paths |
| Build manifests, SBOM, signatures and scans | Artifact identity and admission trust |
| Secret versions/rotation/application errors | Safe credential lifecycle and consumption |
| Inspector/GuardDuty/Security Hub findings | Coverage, priority, workflow and response |
| Config rules/remediation histories | Compliance truth and safe correction |
| CloudTrail logs/digests/emergency record | Custody, identity and change reconstruction |
Assessment tasks
- Replace static pipeline keys with federated temporary sessions; design trust claims, duration, source identity and revocation.
- Separate build, signer, artifact, deployment, stack execution and runtime roles; prove constrained PassRole and denied escalation.
- Create a digest/signature/SBOM/provenance admission policy for ECR and Lambda artifacts, including stale/failed scan behavior.
- Design Secrets Manager ownership, KMS/resource policies, single versus alternating-user rotation, caching, failure recovery and pipeline use.
- Prove Inspector coverage before prioritizing findings; write risk tiers, remediation SLOs, suppression/exception expiry and rescan closure.
- Design GuardDuty/Security Hub organization/Regional aggregation, idempotent routing, enrichment, authorized containment and workflow-state policy.
- Build a Config conformance pack/remediation classification with recorder proof, canary rollout, fresh reevaluation and exceptions.
- Trace effective authorization across identity/resource/key/session/boundary/SCP layers for ten requests, including service-linked-role limits.
- Design organization CloudTrail management/data selectors, S3/KMS custody, delivery reconciliation and digest validation.
- Reconstruct the emergency change, remove access, codify desired state, verify outcomes and create corrective controls.
Threat and failure analysis
Create a threat model for source contributor, compromised runner, artifact substitution, malicious approver, overprivileged deployer, compromised workload, member-account administrator and evidence-store administrator. For each state preventive, detective, responsive and recovery controls plus residual risk.
Diagnose eight cases: OIDC wildcard trusts forks, build can pass arbitrary role, signature belongs to another digest, rotation leaves AWSPENDING and stale clients, ECR zero findings with failed coverage, Security Hub suppression hides recurrence, Config automation reports success while rule stays noncompliant, and a CloudTrail digest chain has a delivery gap. Use evidence, not service slogans.
Quantitative and governance work
Calculate credential/session exposure windows, vulnerability/compliance SLO age, event/DLQ reconciliation, rotation overlap, audit retention/storage and remediation concurrency/error thresholds. State how cost changes with Inspector coverage, Config evaluations, CloudTrail data events, retained versions and centralized logs.
Write five policy decisions with alternatives: OIDC trust boundary, artifact signing authority, automated containment class, SCP invariant and emergency access. Include owner, rollout, negative tests, rollback and exception method. A guardrail that prevents recovery or can be bypassed by its operator is incomplete.
Cross-control proof
For three protected actions, build an end-to-end proof rather than listing controls. Example: a production deployment begins with a reviewed source identity, exchanges an OIDC token for a bounded session, reads an approved signed digest, passes a narrow execution role, mutates only declared resources, emits CloudTrail and Config evidence, and is admitted only while security findings and exceptions satisfy policy. Show where each control can fail open, fail closed or become unavailable.
Then test control independence. The same principal must not change the pipeline, signing policy, security gate, evidence store and production target. Central security aggregation must not be the only local response path. KMS, DNS, identity and logging dependencies need degraded-mode behavior. For each automatic response state the precondition, idempotency key, maximum blast radius, timeout, verification, compensation and human escalation.
Scoring and remediation
| Area | Points | Automatic failure condition |
|---|---|---|
| Identity/authorization | 20 | Long-term key or privilege-escalation path retained |
| Artifact/secret trust | 20 | Mutable identity or secret disclosed in artifact/log |
| Detection/compliance | 20 | Coverage gaps interpreted as compliant/safe |
| Organization/audit evidence | 20 | Audit custody or SCP semantics incorrect |
| Response/governance | 20 | Destructive unapproved automation or permanent exception |
Pass at 80/100, no automatic failure and at least 60 percent in each area. Remediate each miss by citing the earlier lesson, correcting the design, running a changed negative case and attaching evidence. Memorizing managed-service names does not pass.
Submission acceptance
Submit ten task answers, policy evaluation matrix, threat model, eight incident analyses, calculations, five decisions, audit reconstruction and personal remediation map. Acceptance requires temporary least-privilege identity, immutable admission, proven coverage, expiring exceptions, reversible response and protected verifiable evidence.