AWS WAF, Shield, and Amazon Inspector — Edge Protection and Vulnerability Scanning
SCS-C03 Domain 3 — WAF rule groups, managed rules, rate-based rules, Shield Advanced, and Inspector EC2/ECR/Lambda vulnerability scanning
SCS-C03 Domain 3 — WAF rule groups, managed rules, rate-based rules, Shield Advanced, and Inspector EC2/ECR/Lambda vulnerability scanning
SCS-C03 Domain 2 — Cloud IR phases, EC2 forensics and containment, automated response with SSM and Step Functions, and Amazon Detective graph-based investigation
SCS-C03 Domain 1 — Security Hub finding aggregation, security standards, ASFF, Macie sensitive data discovery, and multi-account setup

A full review connecting all four weeks — drawing the complete security architecture, identifying your weakest areas, and writing a personal threat model for your home lab and blog infrastructure.

A personal lab index — hands-on exercises mapped to each week of the DevSecOps study plan. Each lab has a clear objective, tools needed, and success criteria.
SCS-C03 Domain 1 — CloudTrail organisation trails, log integrity validation, Athena analysis, Config rules, conformance packs, and automated remediation

A full walkthrough of CIS AWS Foundations Benchmark — understanding the key controls, running automated checks via Security Hub, remediating failures, and mapping controls to broader compliance frameworks.

A full walkthrough of threat modeling using STRIDE — drawing data flow diagrams, identifying threats, rating risk, and applying the methodology to a real cloud-native application.
SCS-C03 Domain 1 — GuardDuty finding types, data sources, multi-account setup, trusted IP lists, suppression rules, and EventBridge automation

A full walkthrough of cloud incident response on AWS — the IR lifecycle, detecting and investigating a compromised IAM key or EC2 instance, containment steps, and building a runbook.