Domain 6 · Security foundations and governance
14% of the exam. Building the account structure, deployment guardrails and compliance checks that every other security control sits on.
Domain 6 questions are about scale. One account with a handful of resources is easy to secure by hand. Two hundred accounts across four business units are not. The right answer sets a rule once, in a central place, and lets AWS apply it to every account that exists today and every account created tomorrow.
| Task | What it's really asking | Pages |
|---|---|---|
| 6.1 Centrally deploy and manage accounts | OU layout, Control Tower, organization policies, delegated administrators, root user control | Multi-account strategy, Organization policies |
| 6.2 Secure and consistent deployment | Hardened IaC, StackSets, policy as code, tags, Firewall Manager, Service Catalog and RAM | Secure deployment |
| 6.3 Evaluate compliance | Config rules and conformance packs, Security Hub CSPM standards, audit evidence, Well-Architected reviews | Compliance evaluation |
How to read a Domain 6 question
- "All accounts, including new ones" means an organization-level feature: an SCP or RCP on an OU, an organization Config rule or conformance pack, a Firewall Manager policy, or StackSets with automatic deployment.
- "Before it is deployed" means a preventive or proactive control: an SCP, a CloudFormation Hook, a Control Tower proactive control, or Guard in the pipeline. "Detect and report" means Config or Security Hub CSPM.
- "Least operational overhead" usually beats a custom Lambda. Look for the managed rule, managed standard or built-in control first.
- "Security team runs it, not the management account" means a delegated administrator in a security tooling account.
Doing it in the management account
Options that run security tooling, workloads or day-to-day administration from the Organizations management account are almost always wrong. SCPs don't apply to that account, so it's the least governed place you have. Keep it for billing and organization-level settings only.
Exam signal
Many questions in this domain have two technically valid answers. The winner is the one that is central, automatic for new accounts and managed by AWS. A per-account script that "runs every night" is the classic distractor.
Sensitive data
Finding sensitive data in S3 with Macie, masking it in CloudWatch Logs with data protection policies, SNS message data protection and S3 Object Lambda redaction (and their replacements), and choosing between masking, redaction, tokenization and encryption.
Multi-account strategy
Designing an AWS Organizations OU structure for security, running Control Tower controls, delegating security services and centrally managing root access for member accounts.