Topic module

Network Security, Logging and Monitoring

This area covers VPC security basics, security groups, network ACLs, public and private access, CloudTrail, CloudWatch, logs, and monitoring.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AWS Cloud Practitioner

Treat each question as a service-selection or responsibility decision: identify the business need, AWS responsibility, customer configuration, and best-fit service.

Core concepts

Concept 1

Network security in AWS uses layered controls such as security groups, network ACLs, routing, private subnets, and endpoints.

Exam cue: Use security groups and NACLs for network access control questions.

Concept 2

Monitoring and logging help detect, investigate, and respond to account, application, and infrastructure activity.

Exam cue: Use CloudTrail for who-did-what API activity.

Concept 3

CloudTrail records AWS API activity, while CloudWatch monitors metrics, logs, alarms, and events.

Exam cue: Use CloudWatch for metrics, logs, alarms, and operational monitoring.

Risk pitfalls and guardrails

Using CloudWatch metrics to answer API audit questions.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Opening broad inbound access to make troubleshooting easier.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Confusing security groups and network ACL behavior.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Memory anchors

VPC

A virtual private cloud is a logically isolated network in AWS.

Security Group

A security group is a stateful virtual firewall for supported resources.

Network ACL

A network ACL is a stateless subnet-level network control.

Public Subnet

A public subnet has routing that can reach the internet through an internet gateway.

Private Subnet

A private subnet is not directly reachable from the internet by default.

VPC Endpoint

A VPC endpoint privately connects a VPC to supported AWS services.

CloudTrail

AWS CloudTrail records account API activity and helps with auditing.

CloudWatch

Amazon CloudWatch collects metrics, logs, alarms, and operational events.

CloudWatch Alarm

A CloudWatch alarm watches a metric and takes configured action when thresholds are met.

Flow Logs

VPC Flow Logs capture metadata about accepted and rejected IP traffic.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company wants an isolated virtual network in AWS with its own IP address range, subnets, and route tables. Which service provides it?

A web server must accept HTTPS traffic from the internet but reject direct SSH access from the internet. Which control is most appropriate at the instance level?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.