How Domain 1 questions are built
| Pattern | Typical stem | What decides it |
|---|---|---|
| Who can do what | “Developers must be able to X but must never be able to Y” | Policy type and evaluation order |
| Cross-account access | “An application in account A must read a bucket or key in account B” | Both sides must allow |
| Guardrail | “No account in the organization may use Regions outside the EU” | SCP (limits, never grants) |
| Private path | “Traffic must not traverse the internet” | Endpoints, PrivateLink, DX/VPN |
| Pick the service | “Detect cryptocurrency mining” / “find PII in S3” | Service-to-job mapping |
| Encryption choice | “The company must control and audit key usage” | KMS key type and policy |
Decision rules: access (task 1.1)
Policy evaluation, in order
- An explicit deny anywhere wins. This includes identity policies, resource policies, SCPs, RCPs, permissions boundaries and session policies.
- Guardrails must allow. SCPs (on principals) and RCPs (on resources) in the organization, the permissions boundary and the session policy only limit permissions. An action must be inside all of them.
- Something must grant. An identity-based or resource-based policy must allow the action.
- Otherwise the request is implicitly denied.
Cross-account access
- Resource-based policy (S3, KMS, SQS, SNS, Lambda): the resource policy names the other account, and the caller’s IAM policy must allow the action. For KMS, the key policy must allow the external account, and the external account’s IAM policy must allow the key usage.
- Cross-account role: the trust policy in account B allows account A to assume the role, and account A’s policy allows
sts:AssumeRole. For a third party, add an external ID condition to prevent the confused-deputy problem. - Organization-wide sharing: a resource policy with the
aws:PrincipalOrgIDcondition beats listing account IDs one by one.
Identity triggers
| Requirement | Answer |
|---|---|
| App on EC2, ECS or Lambda needs AWS access | Instance profile, task role or execution role. Never access keys in code |
| Workforce single sign-on to many accounts | IAM Identity Center |
| Sign-in with the on-premises Active Directory | Identity Center with AD Connector or AWS Managed Microsoft AD |
| Mobile or web app users sign up and sign in | Cognito user pool |
| Those users need temporary AWS credentials (for example to upload to S3) | Cognito identity pool |
| Restrict Regions, services or root actions across accounts | SCP on an OU |
| Governed multi-account setup with guardrails out of the box | Control Tower |
| Share subnets or a Transit Gateway with other accounts | AWS RAM |
Decision rules: workloads and networks (task 1.2)
Network layers
| Need | Use | Not |
|---|---|---|
| Allow app-tier traffic only from the web tier | Security group rule that references the web tier’s SG | IP ranges that change |
| Block one malicious IP range | Network ACL deny rule (or WAF IP set for HTTP) | Security group (allow rules only) |
| Stop SQL injection, XSS or bad bots | AWS WAF on CloudFront, ALB, API Gateway or AppSync | NACL or Shield |
| Rate-limit abusive clients | WAF rate-based rule | Security group |
| Layer 3/4 DDoS protection | Shield Standard (automatic, free) | Anything extra |
| DDoS response team, cost protection, advanced L7 visibility | Shield Advanced | Shield Standard |
| Stateful inspection and domain filtering for VPC traffic | AWS Network Firewall | WAF (HTTP only) |
| Same WAF and SG policies in every account | Firewall Manager | Per-account manual rules |
| Admin shell access with no open port 22 or 3389 | Systems Manager Session Manager | Bastion host |
| Private access to S3 or DynamoDB | Gateway endpoint | NAT gateway |
| Private access to other AWS services | Interface endpoint (PrivateLink) | Public endpoint |
| Expose a service privately to other VPCs or accounts | Endpoint service backed by an NLB | VPC peering to every consumer |
Security services
| Job | Service |
|---|---|
| Detect threats from logs (compromised credentials, crypto mining, unusual API calls) | GuardDuty |
| Scan EC2, container images and Lambda for vulnerabilities | Inspector |
| Discover PII and sensitive data in S3 | Macie |
| Investigate the root cause of a finding | Detective |
| Aggregate findings and check against security standards | Security Hub |
| Record configuration history and check compliance rules | AWS Config |
| Record who called which API | CloudTrail |
Automated response is the same pattern each time: finding → EventBridge rule → Lambda or Systems Manager Automation.
Secrets
Use Secrets Manager when credentials must rotate automatically or be replicated across Regions. Use Parameter Store for configuration and low-cost secrets without native rotation.
Decision rules: data protection (task 1.3)
KMS and encryption at rest
| Requirement | Answer |
|---|---|
| Encrypt with no key management at all | SSE-S3 (the default for new objects) |
| Control the key policy, audit every use in CloudTrail, rotate on a schedule | SSE-KMS with a customer managed key |
| High request rates with SSE-KMS at lower KMS cost | S3 Bucket Keys |
| Company supplies its own key with every request | SSE-C |
| Single-tenant HSM under the company’s exclusive control | CloudHSM (or a KMS custom key store backed by it) |
| Decrypt the same data in two Regions | KMS multi-Region keys |
| Encrypt an existing unencrypted EBS volume | Snapshot, copy the snapshot with encryption, create a new volume |
| Encrypt an existing unencrypted RDS instance | Snapshot, copy the snapshot with encryption, restore a new instance |
| New EBS volumes must always be encrypted | Turn on EBS encryption by default for the Region |
S3 protection
- WORM that nobody can override, including root: Object Lock in compliance mode. Governance mode can be bypassed by users with special permission. A legal hold has no expiry date.
- Protect against accidental deletion: versioning, plus MFA Delete for extra protection.
- Temporary access to one object: a presigned URL.
- Private bucket served through CloudFront: origin access control (OAC).
- Force HTTPS: a bucket policy that denies requests where
aws:SecureTransportis false.
Transit and audit
- The ACM certificate for CloudFront must be in us-east-1. ACM auto-renews the certificates it issues but not imported certificates.
- For tamper-evident audit logs, use an organization CloudTrail trail with log file validation, delivered to a locked-down bucket in a log-archive account.
- Immutable backups: AWS Backup Vault Lock.
Common traps
Pacing in Domain 1
Most Domain 1 items take 60–90 seconds once you know the rules. Items with a JSON policy snippet take up to 2 minutes. Look for the Effect, the Condition block and whether the policy is identity-based or resource-based (a resource policy has a Principal). Do not work through every statement in order. Look for the one deny or missing allow that decides the answer.