Domain 3 · Infrastructure security
18% of the exam. Putting the right control at each layer, from the edge through the network to the workload, without opening more access than the requirement needs.
Domain 3 questions give you a workload and a threat (a bot swarm, an exposed port, an unpatched AMI, a prompt injection) and ask which control stops it at the right layer with the least operational effort. Most wrong answers are real controls placed at the wrong layer: a security group asked to inspect HTTP, or WAF asked to filter egress.
| Task | What it's really asking | Pages |
|---|---|---|
| 3.1 Network edge services | Filter and absorb bad traffic before it reaches the origin: WAF, Shield, CloudFront, CORS, IoT policies | Edge protection |
| 3.2 Compute workloads | Harden images, give workloads the right role, find and patch vulnerabilities, remove SSH, scan in the pipeline, guard GenAI apps | Compute hardening, Vulnerability and patch management, Generative AI guardrails |
| 3.3 Network security controls | Permit or block flows, connect hybrid networks securely, segment, and prove there's no unintended path | Network controls, Hybrid and private access, Segmentation and analysis |
Layers and their controls
- Edge stops volumetric and layer 7 abuse closest to the attacker, where capacity is largest.
- Network decides which flows may exist at all, both north/south (in and out of the VPC) and east/west (between workloads).
- Compute assumes something will get through, so it limits what an attacker can do on the host and how long a known flaw stays unpatched.
Exam signal
Look for the layer word in the question. "SQL injection", "User-Agent", "requests per IP" point at WAF. "Domain allow list for outbound traffic" points at Network Firewall or DNS Firewall. "No inbound ports, no bastion" points at Session Manager or EC2 Instance Connect Endpoint. "Unintended network path across many VPCs" points at Network Access Analyzer.
Detection is not prevention
GuardDuty, Inspector and Network Access Analyzer find problems. They don't block anything by themselves. If the question asks to prevent or block, the answer is a control (WAF rule, firewall rule, security group, SCP) or an automated response wired to the finding. See Automated response.
Compromised workloads
Containing and investigating compromised EC2 instances, EKS pods and Lambda functions, capturing memory and disk evidence, storing it immutably with S3 Object Lock, and automating forensics.
Edge protection
AWS WAF rules, managed rule groups, rate limiting, Bot Control and Fraud Control, Shield Standard and Advanced, CloudFront security headers and origin protection, S3 CORS, Firewall Manager, OCSF integrations and AWS IoT policies.