3 Network, System Hardening

one short security - aws security - last min rev

Note

NACL works at subnet level
security groups works at ec2 level

Network Hardening

Q1. What is difference between AWS systems manager, cloud watch ,cloud trail ?

Feature AWS Systems Manager Amazon CloudWatch AWS CloudTrail
Purpose Manage and configure AWS resources securely. Monitor resource performance and logs. Audit and log API calls and account activity.
Focus Operational management (inventory, patching, secure access). Metrics, alarms, logs, dashboards for monitoring. Governance, compliance, and security auditing.
Use Cases Inventory, patching, automation, secure EC2 access. Monitor CPU, memory, application logs, and set alerts. Track API calls, detect unauthorized changes.
Scope Instance-level management (EC2 and hybrid resources). Resource performance and health metrics. Logs activity for AWS account actions.
Data Tracked Instance configuration, patches, applications. Performance metrics, system logs, custom metrics. API calls, user actions, and resource changes.
Integration Patch Manager, Session Manager, Run Command. Alarms, SNS, Lambda, dashboards. S3, CloudWatch Logs, EventBridge.
Retention Depends on configuration (for inventory and logs). Configurable for logs and metrics. 90 days default for event history, extendable.
Example Use Case Automatically patch EC2 instances. Monitor EC2 instance CPU usage. Identify who deleted an S3 bucket.

Network Discovery Threats & Prevention

Network Architecture Hardening

AWS Security Layers

Key Takeaways

System Hardening

Hardening Methods

Server & Application Hardening

Key Takeaways


notebooklm summarized data (EXTRA THEORY)

Network hardening

Core Concepts

Network Discovery Threats & Prevention

Network Architecture Hardening

AWS Specifics

Key Takeaways

By implementing these techniques, networks can be made significantly more robust against both internal and external threats.


System hardening

Core Concept: Systems Hardening

Systems Hardening in the Security Lifecycle

Key Security Facets

Physical Security

Types of Systems to Harden

Security Baselines

How to Harden Systems

Patching

Systems Hardening Recommendations

Software Application Hardening

Server Hardening (Specific Examples)

Mobile Device Management (MDM)

Training and Education

Systems Hardening Tools (AWS)

Checkpoint Questions

Key Takeaways