AWS Training
Modules Listen All tracks

← Design Secure Architectures

SAA1 Cheat sheet — Design Secure Architectures (Domain 1, 30%)

Every figure verified 2026-09-21 against the pages cited in the lessons. Re-verify before the exam — quotas and defaults move.

Policy evaluation

Explicit Deny anywhere  ──▶  DENIED. Nothing overrides it.

CEILINGS (all must allow):   SCP/RCP  ∩  permissions boundary  ∩  session policy
GRANTS   (any one enough):   identity policy  ∪  resource policy

One union, three intersections.

Combination Operator
identity + resource (same account) union
identity + permissions boundary intersection
identity + SCP / RCP intersection
role policy + session policy intersection

STS / session numbers

Thing Value
DurationSeconds range 900 – 43200 (15 min – 12 h)
DurationSeconds default 3600
Role chaining ceiling 1 hour — request more and the call fails
Session policy size (inline + all ARNs) 2,048 chars
Managed policy ARNs per session 10
Session tags 50 (key 128 / value 256)
ExternalId 2 – 1,224 chars
STS requests 600/sec per account per Region
Current size field SessionTokenUtilization (PackedPolicySize deprecated)

IAM limits

Adjustable Default → Max
Roles per account 1,000 → 10,000
Customer managed policies/account 1,500 → 10,000
Managed policies per role 20 → 25
Managed policies per user 10 → 20
Role trust policy length 2,048 → 8,192 chars
Not adjustable Limit
Inline policy per user / group / role 2,048 / 5,120 / 10,240 chars
Each customer managed policy 6,144 chars
Role name 64 chars

White space isn't counted. Hitting inline limits → move to managed policies, don't request an increase.

Organizations / SCPs

Quota Value Adjustable
Accounts per org 10 default (→ 50,000) ✅ mgmt account only
SCP max size 10,240 chars ❌
RCP max size 5,120 chars ❌
SCPs per root / OU / account 10 each (hard) ❌
Minimum SCPs on an entity 1 — can't remove the last —
OU nesting 5 levels ❌
Roots per org 1 ❌

SCPs cannot restrict: ① the management account ② service-linked roles ③ Enterprise support registration as root ④ CloudFront trusted signer ⑤ reverse DNS for Lightsail/EC2 as root. → Run no workloads in the management account.

Allow = AND down every level. Deny = OR at any level. ⚠️ Detach FullAWSAccess with no replacement → all member-account actions fail.

Console strips white space from policies; CLI/SDK do not. Same policy can pass in console, fail in CI.

Security groups vs NACLs

Security group Network ACL
Level instance subnet
Rules allow only allow + deny
Evaluation all rules ascending order, first match
Return traffic automatic (stateful) must be explicit (stateless)

NAT & endpoints

Reaches EIP
Public NAT GW internet via IGW; or TGW/VGW required
Private NAT GW other VPCs / on-prem via TGW/VGW not allowed
Endpoint Shape Reach
Interface ENI + private IP + DNS in-VPC and on-prem via DX/VPN
Gateway route table entry, S3 + DynamoDB only, not PrivateLink that VPC only
GatewayLoadBalancer route to appliance fleet inline inspection

WAF / Shield / Firewall Manager

Service Job
WAF inspect layer-7 requests (SQLi, XSS, IP, country, headers, regex, length, rate)
Shield Standard automatically included, no extra cost — nothing to enable
Shield Advanced paid; L3/4 + L7; EC2, ELB, CloudFront, Route 53 hosted zones, Global Accelerator standard accelerators; SRT access
Firewall Manager applies WAF/Shield/SGs/NACLs/Network Firewall/DNS Firewall across accounts, "even as new resources are added"

WAF attaches to: CloudFront, API Gateway REST API, ALB, AppSync, Cognito user pool, App Runner, Bedrock AgentCore Gateway, Verified Access, Amplify. ⚠️ Not NLB. Not bare EC2.

Deploy new rules in Count first, then Block. Managed rule groups = low-overhead answer. Shield Advanced covers standard WAF costs up to 1,500 WCUs; auto L7 mitigation adds 150 WCUs.

Cognito

User pool Identity pool
Is user directory + OIDC IdP credentials broker
Returns JWTs temporary AWS credentials (STS)
Guest access — ✅ unauthenticated identities

Calling an AWS API directly from the client → identity pool. Neither requires the other. Identity pools support RBAC and ABAC via principal tags.

Detection

Need Service
Compromised creds, cryptomining, C2 GuardDuty — auto-ingests CloudTrail mgmt events, VPC flow logs, DNS logs
PII in S3 / public bucket finding Macie (S3 general purpose buckets)
Findings vs industry standards, multi-account Security Hub CSPM
Root-cause across log data Detective
Automated response EventBridge → Lambda / SNS

Secrets

KMS

Customer managed AWS managed AWS owned
In your account yes yes no
Key policy you control service controls, you view invisible
CloudTrail audit ✅ ✅ ❌ cannot audit
Auto rotation optional required, ~365 days service's choice
Cost monthly + per-use per-use free

⚠️ Cross-account sharing requires a customer managed key — "You cannot share resources encrypted under an AWS managed key with other accounts." ⚠️ AWS managed keys are legacy (none created for new services since 2021).

Key policy is mandatory and primary:

Rotation:

Encryption at rest / in transit

Retention & immutability

Object Lock — requires S3 Versioning. Assessed for SEC 17a-4, CFTC, FINRA.

Mode Who can delete
Governance holders of s3:BypassGovernanceRetention + header x-amz-bypass-governance-retention:true (⚠️ the console sends it by default)
Compliance nobody, including root. "The only way to delete … is to delete the associated AWS account."
Legal hold anyone with s3:PutObjectLegalHold; no expiry; independent of retention

Delete behaviour: permanent DELETE (version ID) → 403. Simple DELETE → 200 OK + delete marker.

⚠️⚠️ THE BIG ONE: "even if your bucket policy denies all actions for all principals, your S3 Lifecycle configuration still functions as normal." → A Deny does not prevent deletion. Only Object Lock does. Permissions ≠ immutability.

Retroactive or not?

Change Applies to existing data?
Lifecycle rule ✅ yes — queues existing eligible objects immediately
Bucket default encryption ❌ no → S3 Batch Operations
Live replication ❌ no → S3 Batch Replication
KMS key rotation ❌ no re-encryption ever

Replication

RTC CRR SRR
Timing 99.99% in 15 min, SLA-backed¹ 24–48 h, no SLA 24–48 h, no SLA
Cross-account ✅ ✅ ✅

¹ The user guide states 99.99% in prose and 99.9% in its own table — read the S3 SLA for the contractual figure.

AWS Backup

Exam mechanics

65 questions (50 scored, 15 unscored and unmarked) · 130 min · scaled 100–1,000 · pass = 720 · compensatory scoring — you only need to pass overall, not each domain.

The four things to carry in

  1. Explicit deny beats everything — for principals. One union, three intersections.
  2. A control only works on the path it sits on.
  3. In KMS the key policy opens the door; rotation never re-encrypts.
  4. Permissions are not immutability. "Cannot be deleted" → Object Lock / Vault Lock.