0PricingLogin
AWS Security Academy · Lesson

Designing Layered Defense Scenarios

Combine controls into the end-to-end architectures the exam favors.

Defense in Depth

The exam favors defense in depth: multiple independent layers so that if one fails, others still protect the workload.

No single control is enough. The best answer usually combines identity, network, data, and detection controls rather than relying on one.

Layering at the Edge

At the network edge, stack protections:

  • Shield absorbs DDoS floods.
  • WAF filters malicious web requests.
  • CloudFront terminates TLS and shrinks the origin's exposure.

Each layer handles a different threat class.

All lessons in this course

  1. Connecting the Six Exam Domains
  2. Designing Layered Defense Scenarios
  3. Decoding Tricky Scenario Questions
  4. Your Final Study Plan and Checklist
← Back to AWS Security Academy