Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Every figure verified 2026-09-21 against the pages cited in the lessons. Re-verify before the exam — quotas and defaults move.
Explicit Deny anywhere ──▶ DENIED. Nothing overrides it.
CEILINGS (all must allow): SCP/RCP ∩ permissions boundary ∩ session policy
GRANTS (any one enough): identity policy ∪ resource policy
One union, three intersections.
| Combination | Operator |
|---|---|
| identity + resource (same account) | union |
| identity + permissions boundary | intersection |
| identity + SCP / RCP | intersection |
| role policy + session policy | intersection |
| Thing | Value |
|---|---|
DurationSeconds range |
900 – 43200 (15 min – 12 h) |
DurationSeconds default |
3600 |
| Role chaining ceiling | 1 hour — request more and the call fails |
| Session policy size (inline + all ARNs) | 2,048 chars |
| Managed policy ARNs per session | 10 |
| Session tags | 50 (key 128 / value 256) |
ExternalId |
2 – 1,224 chars |
| STS requests | 600/sec per account per Region |
| Current size field | SessionTokenUtilization (PackedPolicySize deprecated) |
| Adjustable | Default → Max |
|---|---|
| Roles per account | 1,000 → 10,000 |
| Customer managed policies/account | 1,500 → 10,000 |
| Managed policies per role | 20 → 25 |
| Managed policies per user | 10 → 20 |
| Role trust policy length | 2,048 → 8,192 chars |
| Not adjustable | Limit |
|---|---|
| Inline policy per user / group / role | 2,048 / 5,120 / 10,240 chars |
| Each customer managed policy | 6,144 chars |
| Role name | 64 chars |
White space isn't counted. Hitting inline limits → move to managed policies, don't request an increase.
| Quota | Value | Adjustable |
|---|---|---|
| Accounts per org | 10 default (→ 50,000) | ✅ mgmt account only |
| SCP max size | 10,240 chars | ❌ |
| RCP max size | 5,120 chars | ❌ |
| SCPs per root / OU / account | 10 each (hard) | ❌ |
| Minimum SCPs on an entity | 1 — can't remove the last | — |
| OU nesting | 5 levels | ❌ |
| Roots per org | 1 | ❌ |
SCPs cannot restrict: ① the management account ② service-linked roles ③ Enterprise support registration as root ④ CloudFront trusted signer ⑤ reverse DNS for Lightsail/EC2 as root. → Run no workloads in the management account.
Allow = AND down every level. Deny = OR at any level.
⚠️ Detach FullAWSAccess with no replacement → all member-account actions fail.
Console strips white space from policies; CLI/SDK do not. Same policy can pass in console, fail in CI.
| Security group | Network ACL | |
|---|---|---|
| Level | instance | subnet |
| Rules | allow only | allow + deny |
| Evaluation | all rules | ascending order, first match |
| Return traffic | automatic (stateful) | must be explicit (stateless) |
| Reaches | EIP | |
|---|---|---|
| Public NAT GW | internet via IGW; or TGW/VGW | required |
| Private NAT GW | other VPCs / on-prem via TGW/VGW | not allowed |
| Endpoint | Shape | Reach |
|---|---|---|
| Interface | ENI + private IP + DNS | in-VPC and on-prem via DX/VPN |
| Gateway | route table entry, S3 + DynamoDB only, not PrivateLink | that VPC only |
| GatewayLoadBalancer | route to appliance fleet | inline inspection |
| Service | Job |
|---|---|
| WAF | inspect layer-7 requests (SQLi, XSS, IP, country, headers, regex, length, rate) |
| Shield Standard | automatically included, no extra cost — nothing to enable |
| Shield Advanced | paid; L3/4 + L7; EC2, ELB, CloudFront, Route 53 hosted zones, Global Accelerator standard accelerators; SRT access |
| Firewall Manager | applies WAF/Shield/SGs/NACLs/Network Firewall/DNS Firewall across accounts, "even as new resources are added" |
WAF attaches to: CloudFront, API Gateway REST API, ALB, AppSync, Cognito user pool, App Runner, Bedrock AgentCore Gateway, Verified Access, Amplify. ⚠️ Not NLB. Not bare EC2.
Deploy new rules in Count first, then Block. Managed rule groups = low-overhead answer.
Shield Advanced covers standard WAF costs up to 1,500 WCUs; auto L7 mitigation adds 150 WCUs.
| User pool | Identity pool | |
|---|---|---|
| Is | user directory + OIDC IdP | credentials broker |
| Returns | JWTs | temporary AWS credentials (STS) |
| Guest access | — | ✅ unauthenticated identities |
Calling an AWS API directly from the client → identity pool. Neither requires the other. Identity pools support RBAC and ABAC via principal tags.
| Need | Service |
|---|---|
| Compromised creds, cryptomining, C2 | GuardDuty — auto-ingests CloudTrail mgmt events, VPC flow logs, DNS logs |
| PII in S3 / public bucket finding | Macie (S3 general purpose buckets) |
| Findings vs industry standards, multi-account | Security Hub CSPM |
| Root-cause across log data | Detective |
| Automated response | EventBridge → Lambda / SNS |
| Customer managed | AWS managed | AWS owned | |
|---|---|---|---|
| In your account | yes | yes | no |
| Key policy | you control | service controls, you view | invisible |
| CloudTrail audit | ✅ | ✅ | ❌ cannot audit |
| Auto rotation | optional | required, ~365 days | service's choice |
| Cost | monthly + per-use | per-use | free |
⚠️ Cross-account sharing requires a customer managed key — "You cannot share resources encrypted under an AWS managed key with other accounts." ⚠️ AWS managed keys are legacy (none created for new services since 2021).
Key policy is mandatory and primary:
Rotation:
RotationPeriodInDays = 365; rotation date is based on when rotation was enabled.AWS_KMS origin only. On-demand: also EXTERNAL.
Manual only for asymmetric, HMAC, custom key store keys.KMS CMK Rotation (EventBridge), RotateKey (CloudTrail), ListKeyRotations.us-east-1. Import third-party certs supported; wildcards cover unlimited
subdomains.Object Lock — requires S3 Versioning. Assessed for SEC 17a-4, CFTC, FINRA.
| Mode | Who can delete |
|---|---|
| Governance | holders of s3:BypassGovernanceRetention + header x-amz-bypass-governance-retention:true (⚠️ the console sends it by default) |
| Compliance | nobody, including root. "The only way to delete … is to delete the associated AWS account." |
| Legal hold | anyone with s3:PutObjectLegalHold; no expiry; independent of retention |
Delete behaviour: permanent DELETE (version ID) → 403. Simple DELETE → 200 OK + delete marker.
⚠️⚠️ THE BIG ONE: "even if your bucket policy denies all actions for all principals, your S3
Lifecycle configuration still functions as normal."
→ A Deny does not prevent deletion. Only Object Lock does. Permissions ≠ immutability.
| Change | Applies to existing data? |
|---|---|
| Lifecycle rule | ✅ yes — queues existing eligible objects immediately |
| Bucket default encryption | ❌ no → S3 Batch Operations |
| Live replication | ❌ no → S3 Batch Replication |
| KMS key rotation | ❌ no re-encryption ever |
| RTC | CRR | SRR | |
|---|---|---|---|
| Timing | 99.99% in 15 min, SLA-backed¹ | 24–48 h, no SLA | 24–48 h, no SLA |
| Cross-account | ✅ | ✅ | ✅ |
¹ The user guide states 99.99% in prose and 99.9% in its own table — read the S3 SLA for the contractual figure.
arn:aws:backup ARNs for backup-specific policies.65 questions (50 scored, 15 unscored and unmarked) · 130 min · scaled 100–1,000 · pass = 720 · compensatory scoring — you only need to pass overall, not each domain.