SOA-C03 / Domain 4 / 16%

Security and Compliance

Security controls, compliance operations, and identity troubleshooting.

Official Task Statements

TaskWhat to prove
SOA-4.1Implement and manage security and compliance tools and policies.
SOA-4.2Implement strategies to protect data and infrastructure.

Concepts You Need to Understand

  • Security operations, compliance tools, encryption, access troubleshooting, patching, vulnerability findings, and audit evidence.

AWS services involved

  • IAM
  • KMS
  • CloudTrail
  • Config
  • GuardDuty
  • Inspector
  • Security Hub
  • Organizations

Important configurations

  • SCPs.
  • Key policies.
  • Trail protection.
  • Config rules.
  • Finding aggregation.

Exam Decision Patterns

Least operational overhead

Prefer managed and serverless services when they satisfy the requirement. Exceptions appear when the scenario needs host control, unsupported runtimes, specialized network behavior, or exact migration compatibility.

Highly available

Identify the failure boundary. One instance is not HA. Multiple instances in one AZ help capacity but not AZ failure. Multi-AZ handles regional AZ faults. Multi-Region handles regional events but adds complexity and cost.

Durable

Durability is about preserving data. Use replication, versioning, backups, point-in-time recovery, and tested restore plans. A durable backup does not guarantee a low RTO.

Decouple the application

Use SQS for buffering work, SNS for fanout, EventBridge for event routing, and Step Functions for visible workflow state. Add retries, DLQs, and idempotent consumers.

Least privilege

Prefer roles and temporary credentials, scope actions/resources/conditions, watch explicit denies, and remember that resource policies may also be required.

Most cost-effective

Read usage pattern, duration, access frequency, scaling behavior, data transfer, and operations. Cheapest unit price is not always lowest total cost.

Lowest latency

Move content or compute closer to users, cache aggressively, choose the right database access pattern, and avoid unnecessary cross-Region or NAT paths.

Private connectivity

Use private subnets, VPC endpoints, PrivateLink, VPN, Direct Connect, Transit Gateway, and tight DNS/routing design instead of public exposure.

Minimum downtime

Separate deployment downtime, failure recovery, and data restore time. Use blue/green, canary, Multi-AZ, replication, and tested rollback where appropriate.

Automatic remediation

Pair a reliable signal with EventBridge or CloudWatch, a scoped Systems Manager Automation or Lambda action, and a validation step.

Common Mistakes

  • Treating detective controls as preventive controls.
  • Missing explicit deny in policy evaluation.

Example Architecture

Private Subnet Architecture Internet-facing load balancers stay public while application and database resources stay private with controlled egress and private AWS service access. Private Subnet Architecture Public ALB SubnetsPrivate App SubnetsPrivate DB SubnetsNAT GatewayVPC Endpoints
Internet-facing load balancers stay public while application and database resources stay private with controlled egress and private AWS service access.

Hands-On Activity

Trace an access denied event from CloudTrail to IAM policy, SCP, and resource policy.

For an AWS-account lab, use one of the linked mini labs and keep cleanup steps visible before you start.

Task-by-Task Study Notes

SOA-4.1 - Implement and manage security and compliance tools and policies.

This task statement is asking whether you can turn a scenario into a decision. Start by identifying the workload requirement, the control or service family involved, and the tradeoff AWS is testing in this domain.

  • Translate the wording into requirements: security, operations, cost, availability, latency, governance, or data behavior.
  • Choose the service or configuration that directly satisfies those requirements with the least unnecessary complexity.
  • Reject options that are technically possible but miss the domain goal or increase risk without a requirement.

Practice SOA-4.1 style questions in this domain

SOA-4.2 - Implement strategies to protect data and infrastructure.

This task statement is asking whether you can turn a scenario into a decision. Start by identifying the workload requirement, the control or service family involved, and the tradeoff AWS is testing in this domain.

  • Translate the wording into requirements: security, operations, cost, availability, latency, governance, or data behavior.
  • Choose the service or configuration that directly satisfies those requirements with the least unnecessary complexity.
  • Reject options that are technically possible but miss the domain goal or increase risk without a requirement.

Practice SOA-4.2 style questions in this domain

Review Checklist

Sources and Review Metadata

This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.