Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 29 more to the end of certification prep.
The exam prep reading list names a whitepaper called AWS Security Best Practices. When I went looking for it (2026-09-21), what surfaced were archived PDFs — July 2018 and July 2020 versions carrying AWS's historical-reference notice.
AWS's current, maintained document for this material is the Security Pillar of the Well-Architected Framework, publication date November 6, 2024. That is what this lesson is built on.
⚠️ I could not verify that a current standalone whitepaper titled "AWS Security Best Practices" exists. If your copy of the reading list links to a PDF, check its date before you study from it — several of the archived versions predate IAM Identity Center's current name, resource control policies, and the S3 default-encryption change, all of which are examinable now.
Security is 30% of the scored exam — the largest domain. So the Security Pillar isn't one whitepaper among six; it's the reading for nearly a third of the paper.
What the pillar is, verbatim from Security (verified 2026-09-21):
"The Security pillar encompasses the ability to protect data, systems, and assets to take advantage of cloud technologies to improve your security."
And the whitepaper's own statement of purpose:
"This will help you meet your business and regulatory requirements by following current AWS recommendations. … After reading this paper, you will understand AWS current recommendations and strategies to use when designing cloud architectures with security in mind."
Note who it says it's for: "chief technology officers (CTOs), chief information security officers (CSOs/CISOs), architects, developers, and operations team members." And note what it explicitly is not: "This paper doesn't provide implementation details or architectural patterns."
That last point is the honest framing for how to use it. The Security Pillar tells you what good looks like and why. It does not tell you which service to click. Module SAA1 does that.
Verbatim from Design principles, verified 2026-09-21. These are worth memorising — not for a recall question, but because they are the reasons that make a design defensible in an exam answer or an interview.
1. Implement a strong identity foundation
"Implement the principle of least privilege and enforce separation of duties with appropriate authorization for each interaction with your AWS resources. Centralize identity management, and aim to eliminate reliance on long-term static credentials."
Three commitments in one principle, and the third is the sharp one: eliminate reliance on long-term static credentials. That is AWS telling you, in the framework document, that an IAM user with access keys is the wrong answer. Roles, instance profiles, IAM Identity Center.
2. Maintain traceability
"Monitor, alert, and audit actions and changes to your environment in real time. Integrate log and metric collection with systems to automatically investigate and take action."
"Automatically investigate and take action" — not just collect. Which is why EventBridge-driven remediation is the framework-aligned answer, not a dashboard someone checks.
3. Apply security at all layers
"Apply a defense in depth approach with multiple security controls. Apply to all layers (for example, edge of network, VPC, load balancing, every instance and compute service, operating system, application, and code)."
The bracketed list is the layer stack from SAA1 lesson 3, in AWS's own words. It's also the reason a single control is rarely the complete answer.
4. Automate security best practices
"Automated software-based security mechanisms improve your ability to securely scale more rapidly and cost-effectively. Create secure architectures, including the implementation of controls that are defined and managed as code in version-controlled templates."
5. Protect data in transit and at rest
"Classify your data into sensitivity levels and use mechanisms, such as encryption, tokenization, and access control where appropriate."
⚠️ Read the order: classify first, then apply mechanisms. Encryption is not the first step in this principle — classification is. That's why Macie exists, and it's why "encrypt everything" is a weaker answer than "classify, then protect according to sensitivity".
6. Keep people away from data
"Use mechanisms and tools to reduce or eliminate the need for direct access or manual processing of data. This reduces the risk of mishandling or modification and human error when handling sensitive data."
This is the most under-used principle on the exam and it's a tie-breaker. Between "engineers SSH in to run a script" and "an automated job with no human access", the second wins on this principle and on operational excellence. Systems Manager Session Manager and Run Command exist for exactly this.
7. Prepare for security events
"Prepare for an incident by having incident management and investigation policy and processes that align to your organizational requirements. Run incident response simulations and use tools with automation to increase your speed for detection, investigation, and recovery."
"Run incident response simulations" — the game-days principle from lesson 1, applied to security. Having a plan is not preparation; rehearsing it is.
Verbatim from Best practices, verified 2026-09-21:
| # | Area |
|---|---|
| 1 | Security foundations |
| 2 | Identity and access management |
| 3 | Detection |
| 4 | Infrastructure protection |
| 5 | Data protection |
| 6 | Incident response |
| 7 | Application security |
Seven principles, seven areas — they are not the same seven, and they don't pair off. The principles are why; the areas are where the questions live.
Here's the useful part: those seven areas map cleanly onto SAA-C03 Domain 1's three task statements and the SAA1 module's lessons, which is a good way to check your coverage.
| Best practice area | SAA-C03 task statement | SAA1 lesson |
|---|---|---|
| Security foundations | 1.1 | 2 — multi-account guardrails |
| Identity and access management | 1.1 | 1 — policy evaluation |
| Detection | 1.2 | 4 — GuardDuty, Macie, Security Hub |
| Infrastructure protection | 1.2 | 3 — SGs, NACLs, endpoints |
| Data protection | 1.3 | 5 and 6 — KMS, Object Lock, backup |
| Incident response | (not directly weighted) | — |
| Application security | 1.2 | 4 — WAF, Shield, Cognito |
⚠️ Incident response has no direct SAA-C03 task statement. It's in the pillar and it matters professionally, but don't over-invest in it for this exam. This is the kind of thing that only becomes visible when you read the pillar and the exam guide side by side — which is why you should.
The principles are how you turn "I think it's B" into "it's B because…". Four worked mappings:
| Question shape | Principle that decides it | Answer direction |
|---|---|---|
| "Application needs to read a secret. Options include an env var, a config file, Secrets Manager." | 1 — eliminate long-term static credentials | Role + Secrets Manager with managed rotation |
| "How do we know if a bucket becomes public?" | 2 — maintain traceability, automatically take action | Config / Macie finding → EventBridge → remediation |
| "We have a WAF, so we're protected." | 3 — security at all layers | A WAF only sees the path it's on; add the other layers |
| "Engineers need to debug production." | 6 — keep people away from data | Session Manager, not SSH keys and a bastion |
And the meta-point: in this exam, "why" is the answer. Two options can both be secure; the one the Framework's principles endorse is the one AWS scored as correct.