By the end
What you'll build
- Read and write AWS IAM policy JSON fluently — Version, Statement, Effect, Action/NotAction, Resource/NotResource, Condition and (in resource policies) Principal.
- Apply IAM's evaluation logic by hand: default deny, explicit Allow, and explicit Deny that overrides any Allow.
- Use action and resource wildcards safely, avoiding the Get*-is-not-List* and object-ARN-vs-bucket-ARN traps.
- Constrain access with StringEquals, StringLike, IpAddress (prefix) and Bool conditions — including source-IP, tag-based, MFA and TLS-only rules.
- Design to the principle of least privilege and repair over-permissioned policies through error analysis.
- Distinguish identity-based from resource-based policies and lock down an S3 bucket (Block Public Access, HTTPS-only, scoped and tagged access).
- Compare network controls (stateful security groups vs stateless NACLs) and encryption choices (at rest vs in transit, SSE-S3/SSE-KMS, KMS decrypt separation).
- Choose the right secrets store (Secrets Manager vs Parameter Store) and never hardcode secrets.
- Investigate and respond to security incidents using CloudTrail, IAM Access Analyzer, and credential reports, framed by the Well-Architected Security Pillar.
- Practise on AWS's own free tier / AWS Educate using the IAM Policy Simulator and Access Analyzer, and honestly scope what a simulated course does and does not certify.
The shape of it
How this course works
Short lessons
35 lessons across 6 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
A certificate at the end
Finish the course and earn a certificate anyone can verify with a link.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
