In this lab project, students
are challenged to use AWS services to secure various resources in the AWS
Cloud. The lab project is divided into four phases, which are independent of
each other. The architecture must reflect the principles of the AWS Well-Architected
Framework and the principle of least privilege. Specific sections of the
assignment are meant to challenge students on skills that they have acquired
throughout the learning process.
Learning objectives
Upon completion
of this project, students will be able to do the following:
Secure
access to objects in an Amazon Simple Storage Service (Amazon S3) bucket.
Secure
network access to your virtual network.
Encrypt
data at rest by using AWS Key Management Service (AWS KMS) on an Amazon Elastic
Block Store (Amazon EBS) volume.
Manage
encryption keys by using AWS KMS.
Create
a monitoring and incident response system by using Amazon CloudWatch and AWS
Config.