The post AWS Security and Compliance Services appeared first on awsnewbies.com.
]]>AWS Artifact helps you obtain audit reports, certifications, and legal agreements related to AWS services. It is an on-demand service for security and compliance documentation to make sure your organization can meet compliance requirements.
>> Learn more about AWS Artifact.
AWS Audit Manager helps you… you know it… audit your AWS usage. It helps you evaluate whether your policies, procedures, and activities are operating as you intended, helping you simplify how you manage your organization’s risk and compliance against regulations and standards.
>> Learn more about AWS Audit Manager.
AWS Config monitors and manages your AWS infrastructure configurations by continuously monitoring and recording your AWS resource and service configurations. AWS Config helps you assess, audit, and evaluate resource configurations to make sure you’re aligned with your best practices.
>> Learn more about AWS Config.
AWS CloudTrail tracks user, role, and AWS services activity and API usage 24/7 and leaves an event log, providing visibility into who (or what) is doing what. You can search and download account activity and analyze and respond to events using AWS CloudTrail.
>> Learn more about AWS CloudTail.
Amazon CloudWatch collects and tracks metrics of your AWS infrastructure in real time to enhance observability. It collects monitoring data (logs), metrics, and events to detect unusual activities, set alarms, and troubleshoot issues that arise. You can look at the data on its homepage, or a custom dashboard.
>> Learn more about Amazon CloudWatch.
If your organization has multiple AWS accounts, but want to simplify maintaining and administrating these accounts, you may want to look into AWS Firewall Manager. AWS Firewall Manager helps you administer and perform maintenance tasks across multiple accounts and resources for variety of AWS protections like AWS WAF, AWS Shield, Amazon VPC security groups and network ACLS, AWS Network Firewall, and Amazon Route 53 Resolver DNS firewall. Just set it up once, and it’ll automatically apply the same protections across all of your accounts and resources.
>> Learn more about AWS Firewall Manager.
Amazon GuardDuty utilizes machine learning, anomaly detection, and integrated threat intelligence to monitor your AWS resources for malicious activity and unauthorized behavior.
>> Learn more about Amazon GuardDuty.
AWS Identity and Access Management, or AWS IAM, helps you specify who or what accesses which services or resources with granularity. You can utilize IAM Policies set policies that utilize the Principle of Least Privilege. IAM allows you to define who (workforce users, workloads) can access (permissions with IAM policies) what (resources).
>> Learn more about AWS IAM.
Amazon Inspector automatically “inspects” your AWS resources for software vulnerabilities and potential network exposures, by proactively identifying potential issues that misalign with your best practices and policies. Once the assessments are completed, it sends you detailed reports so you can review them for security vulnerabilities.
>> Learn more about Amazon Inspector.
AWS Security Hub collects security data from all of your AWS accounts and services to help you identify and prioritize security issues. AWS Security Hub will help you compare your cloud environment against industry standards and best practices to help you identify critical risks.
>> Learn more about AWS Security Hub.
AWS Shield protects your applications from DDoS (Distributed Denial-of-Service) attacks, acting as a… you guessed it… shield! DDoS attacks are cybercrimes where the attacker floods your server with a huge amount of internet traffic in an attempt to make it inaccessible for legitimate users.
>> Learn more about AWS Shield.
AWS Trusted Advisor acts as AWS’s automated “auditor,” helping you look at different ways to optimize your IT infrastructure so that they align with AWS’s best practices. Once the checks are completed, it provides recommendations to better align your infrastructure to best practices.
The categories of checks offered by this services are:
>> Learn more about AWS Trusted Advisor.
AWS Web Application Firewall, or AWS WAF, is, as the name suggests, a firewall service for your web applications hosted on AWS Cloud. It provides protection from malicious web exploits and your resources, which could potentially compromise security or availability of your web apps, as well as run you up a hefty bill by consuming excessive resources.
>> Learn more about AWS WAF.
The post AWS Security and Compliance Services appeared first on awsnewbies.com.
]]>The post AWS CLF-C02 Domain 4: Billing, Pricing, and Support appeared first on awsnewbies.com.
]]>If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the course here: LinkedIn Learning.
Don’t forget to download my unofficial study guide, as well as AWS’s official study guide!
In this domain, you will learn about the way AWS prices their services, different ways your resources are billed, and how to access support when necessary.
Learn about the fundamental ways AWS charges for your resource usage:
Tools to help larger organizations manage multiple AWS accounts and their billing:
There are many free and paid resources and support available for you and your organization when you are utilizing AWS.
The support plans and what the subscription comes with keeps on changing, so check out the official documentation for the most up-to-date info at “Compare AWS Support Plans.“
For pricing of the AWS Support Plans, there is a lot of granularity, so I recommend you check out the AWS Support Plan Pricing page.
Tools to manage and monitor AWS environments for cost optimization:
Go back to the AWS CLF-C02 Exam Guide
The post AWS CLF-C02 Domain 4: Billing, Pricing, and Support appeared first on awsnewbies.com.
]]>The post AWS CLF-C02 Domain 3: Cloud Technology and Services appeared first on awsnewbies.com.
]]>If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the course here: LinkedIn Learning.
Don’t forget to download my unofficial study guide, as well as AWS’s official study guide!
Next Domain: Billing, Pricing, and Support
Go back to AWS CLF-C02 Exam Guide
The post AWS CLF-C02 Domain 3: Cloud Technology and Services appeared first on awsnewbies.com.
]]>The post AWS CLF-C02 Domain 2: Security and Compliance appeared first on awsnewbies.com.
]]>If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the course here: LinkedIn Learning.
Don’t forget to download my unofficial study guide, as well as AWS’s official study guide!
As you might imagine, security and compliance are important pillars to creating and maintaining a well-secured, safe, and functional IT infrastructure. The rules change a little bit when you have resources hosted on cloud computing platforms instead of on-site, which makes the security and compliance domain of the exam an important area to understand.
The AWS Shared Responsibility Model asserts that security and compliance on the AWS Cloud is a shared responsibility between AWS and the customer. “Who’s responsible for this part of your AWS infrastructure’s security?” is one of the common questions on the exam.
Security in the Cloud consists of concepts in the Security Pillar of the Well-Architected Framework that we learned about in Domain 1.
Identity and Access Management (IAM) and IAM Identity Center provide granular control over permissions for identities, generally dealing with defining WHO has access to WHAT.
There are multiple ways to authenticate users/resources/etc. in AWS, such as:
When you create an AWS account, that account is a root user account. This account should not be utilized unless absolutely necessary. Make sure you secure it with MFA, and learn what specific tasks you need the root account for.
The Principle of Least Privilege asserts that you should only give the least amount of access for an entity to perform its tasks for maximum security. Basically, any bot, resource, or human should only be able to access what is absolutely necessary to complete their work, and no more or no less.
In AWS, you can utilize groups, users, custom policies, and manage policies in compliance with the Principle of Least Privilege.
You can find AWS’s security-related information and documentation at:
AWS has many security services to help you protect your infstructure on the AWS Cloud.
You can get started on learning about the security and compliance services on the AWS Security and Compliance Services page!
Next Domain: Cloud Technology and Services
Go back to AWS CLF-C02 Exam Guide
The post AWS CLF-C02 Domain 2: Security and Compliance appeared first on awsnewbies.com.
]]>The post AWS Cloud Practitioner Exam Study Mnemonics appeared first on awsnewbies.com.
]]>Were any of these helpful? Or do you have any of your own you’d like to share with the world to help others ace the exam? Share with us on LinkedIn or Twitter (tag me! @hirokonishimura or /in/hirokonishimura)
I couldn’t come up with a mnemonic for these, but I’ve come up with shortened words/phrases to jog your memory.
Learn about the 6 Advantages of Cloud Computing in Domain 1.
Before they added the 6th pillar, we had a good thing going, but here we are, with 2 S’s at the end now… Maybe think of a snake sssss-ing…?
Learn about the Well-Architected Framework in Domain 1.
The “Up” are things that improve/grow/increase. “Down” should reduce.
Alternatively, ROBE
Learn about the AWS Cloud Adoption Framework in Domain 1.
AWS security services and tools are difficult to differentiate, especially for newbies. Here are some one-word ways you can remember them:
The post AWS Cloud Practitioner Exam Study Mnemonics appeared first on awsnewbies.com.
]]>The post AWS CLF-C02 Domain 1: Cloud Concepts appeared first on awsnewbies.com.
]]>If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the course here: LinkedIn Learning.
Don’t forget to download my unofficial study guide, as well as AWS’s official study guide!
“Cloud Concepts” points understanding to the overall value proposition of “What is the Cloud, and why do we use it?”
There are 6 “benefits” or “advantages” to utilizing Cloud Computing over legacy infrastructure (think: server rooms in your office or data centers owned, managed, and serviced by your company’s staff) that AWS Cloud wants you to know about. They are referred to as the 6 Advantages of Cloud Computing. These will come up in various forms on the exam, so it’s best to know them in and out.
The basic premise is: what benefits do you get by letting the big cloud computing platforms manage the physical aspects of managing your data/infrastructure so that your company can focus on your business?
(Try out a study aide to help you memorize these!)
The AWS Well-Architected Framework encompasses key concepts, design principles, and architectural best practices for architecting and running workloads in the Cloud
The AWS Well-Architected Framework is also known as the 6 Pillars of a Well-Architected Framework (used to be 5, but they added Sustainability a few years ago). These are “pillars,” or building blocks of creating a best-practices based resilient, reliable, cost effective, and sustainable IT infrastructure on the Cloud.
(Try out a mnemonic to help you memorize these!)
Learn about adopting the cloud for your organization’s IT infrastructure based on best practices, and how you can utilize different AWS tools and features to migrate to the cloud.
AWS CAF describes best practices to help facilitate successful IT migrations into the Cloud, with recommendations for implementing, adapting, configuring, and maintaining effective workflows in the Cloud
(Try out a mnemonic to help you memorize these!)
Cloud migration strategies are ways to migrate your resources to and from the cloud
Basically, how you can save money by moving your infrastructure to the cloud (yes, there are obviously ways it can cost wayyy more – I also hate having Adobe subscriptions, but humor AWS for the sake of passing the exam!).
Managed AWS services are “fully managed” by AWS, which means that the underlying infrastructure, server management, patching, operations, etc. are all managed by AWS. This allows organizations and users to focus on building and business rather than the management and administration of these resources.
Examples of managed AWS Services:
Next Domain: Security and Compliance
Go back to AWS CLF-C02 Exam Guide
The post AWS CLF-C02 Domain 1: Cloud Concepts appeared first on awsnewbies.com.
]]>The post Amazon Lightsail appeared first on awsnewbies.com.
]]>Amazon Lightsail is an Amazon Web Service (AWS) service that helps you create and launch web applications or websites with just a few steps. You can get as basic or complicated with your website or project’s setup as you’d like, with “pre-packaged” applications (“images”) that launch with a click of a button, or managed databases and load balancers for more granular control.
Amazon Lightsail is effective for quickly setting up blogs, personal websites, databases, or e-commerce stores with low, predictable monthly prices. You can learn more about the service on the AWS Knowledge Base.
Amazon Lightsail utilizes a “fixed-cost pricing model,” which should prevent unwanted surprise bills.
The post Amazon Lightsail appeared first on awsnewbies.com.
]]>The post Transferring a domain to Amazon Route 53 appeared first on awsnewbies.com.
]]>In this tutorial, I will teach you how to transfer your registered domain name from your current registrar to Amazon Route 53. In my case, I will be transferring a .com domain from Namecheap.com to Amazon Route 53. Though steps may differ slightly, most registrars should follow similar patterns and steps.
You don’t need any previous Amazon Web Services (AWS) knowledge to execute this tutorial, but you do need:
This process can take up to a week and a half, so make sure you are not trying to do this last minute (the manual steps do not take very long, but processing on the domain registrars’ part can take up to 10 days).
This tutorial assumes that your domain name is currently unused (not connected to any websites/resources that cannot accept downtime). There are more steps to make sure there are no/minimal service interruptions for domain names that are attached to resources. If you are attempting to transfer a domain name that have active resources attached, please follow AWS’s official documentation.
Let’s get started!
There are a few things you need to do before we begin the process of transferring your domain from your current registrar to Amazon Route 53.
Once you obtained the authorization code, make sure you have access to it as we go through this tutorial. You can read more in-depth about the steps in this checklist on AWS’s official documentation: Pre-transfer checklist for domain transfers.
Now, we sit back and wait. You will receive some emails once the process completes. One of them is an authorization email to authorize the transfer. You MUST click on the link and complete the authorization, or the transfer will not complete (refer to this KB article for more information).
Expect the process to take at least a few days. You can check back on the progress on your Route 53 dashboard.
The dashboard status will tell you what step it is on in the domain transfer sequence.
If the transfer fails, you may have one of few reasons, such as:
Once the process is complete, you’ll see a screen like this:
Once the domain is residing in Route 53, you’re ready to get started on your next project!
The post Transferring a domain to Amazon Route 53 appeared first on awsnewbies.com.
]]>The post WordPress (Lightsail) on Amazon Lightsail for Newbies appeared first on awsnewbies.com.
]]>You will need a domain name registered at Amazon Route 53 and an AWS account to get started!
For this tutorial, we will be using:
You will find yourself at your WordPress instance’s dashboard!
Amazon Lightsail has provided us with a guided workflow for setting up our WordPress website, which will help us set up:
This is very cool, because you would generally have to do these manually (and be a little stressed out that you didn’t miss any steps). Let’s try it out!
And we’re done with creating your WordPress instance on Amazon Lightsail! How cool was that!
Once you complete the 5 steps, you may encounter an error like the one below, which says:
"We encountered an error while configuring the Let's Encrypt SSL/LC certificate on your instance WordPress-1 in the us-east-1 Region. Try again later. We are having trouble location your DNS records. If the DNS records were recently created, wait a few minutes and try again."
If you receive this error, it is likely that your DNS records need to be updated to provide domain control to Amazon Lightsail. You will go to your domain registrar (where your domain is registered: in this case, Amazon Route 53), and update your domain’s DNS records. Once the process is complete and your domain’s DNS records match what your Lightsail instance’s DNS records say, the setup should complete.
Here is documentation on how to create DNS entry from AWS’s official Knowledge Base.
Once you’re ready to move on, you should see this on your Lightsail instance’s dashboard:
Click on the button, “Go to website,” and visit your new WordPress website, secured with SSL/TLS certificate, and mapped to your custom domain name!
When you set up a WordPress website, you have a default user name and a password for the administration dashboard. We will need to retrieve these so that you can log into your dashboard and start publishing posts and editing the layout.
cat <<'E0T'.~ $ on the terminal. Click enter to let the command run.~ $ AWS_REGION=us-east-1 ~/lightsail_connect WordPress-1 tail -n 1 application_credentials, with a line of text underneath. That is your default password. Copy it.And viola! You’re logged into your WordPress instance, hosted in Amazon Lightsail!
If you are going to utilize this WordPress website, I recommend that you go into Users, create a new Administrator account, re-log in with the new Administrator account and delete the default “user.”
Done with your test, or want to get rid of your Lightsail instance? It’s very easy to delete your Amazon Lightsail instance!
You will need to delete your DNS zone and static IP as well. If you want to just pause the instance so it’s not active, you can choose “Stop.”
And that’s it! I hope this tutorial post has helped you get started with working in Amazon Web Services and creating your first Amazon Lightsail project! Congratulations!
The post WordPress (Lightsail) on Amazon Lightsail for Newbies appeared first on awsnewbies.com.
]]>The post OpenClaw on Amazon Lightsail for Newbies appeared first on awsnewbies.com.
]]>In this tutorial, we’ll learn how to:
You do not need to have any prior knowledge with Amazon Web Services to follow this tutorial!
OpenClaw is an AI-powered chat agent that provides a private, self-hosted (this means that it can technically also run on your computer) AI assistant to perform many tasks autonomously on your behalf.
You can “chat” with your assistant in many ways, including your browser, Telegram, and WhatsApp (you can check out all of the applications it can integrate with here).
Most “chatbots” we are familiar with can “talk to you.” But this chat agent has “eyes and hands,” which means it can read and write files, browse the Internet, run commands, fill out forms, and execute scripts. In a nutshell, it can actually do things.
Be careful, as it is powerful, but may not have the “human logic” of what’s right and wrong that you and I may have as humans (Twitter was full of funny- and sometimes cringe-worthy- ways OpenClaw agents wrecked havoc on people’s systems/life while executing tasks in very “technical” ways).
Used correctly, OpenClaw could be that personal assistant we all dreamed of!
Today, we will be setting it up and hosting it on Amazon Lightsail using a click-to-launch application. Their official website is at: openclaw.ai.
Congratulations! You now have OpenClaw running on Amazon Lightsail!
Now, we need to create secure connection between your brand new OpenClaw instance and your browser by “pairing” your browser with OpenClaw.
No worries though. This is all copy and paste and a few yes/no prompts!
Continue with browser device pairing? (y = pair now, n = skip):
Pending device request: [numbers and letters] Action? (a=approve, r=reject, s=skip all):
Huzzah! Your OpenClaw agent is alive! (Alive?) If you need to pair additional browsers, you can do these steps again!
If you go to “Chat” on your new OpenClaw gateway dashboard and type “Hello,” you won’t get a response. That’s because the AI capabilities aren’t available to you yet. To actually begin using your chat agent, you need to enable API access for Amazon Bedrock.
We will do this through the AWS CloudShell terminal by running a script. Don’t worry! This is all built-in to the Lightsail dashboard as well!
~$, paste in the script, and click enter, and confirm that in one of the last lines, it says DoneThe script:
If this is your first time using Anthropic models with Amazon Bedrock, you will need to complete “First Time Use (FTU) form” to gain access. Please refer to this documentation to learn more: request access to models.
To access the form, go to Amazon Bedrock console, navigate to “Model catalog,” and select Claude Sonnet 4.6 and fill out the form.
Go to the “Chat” window in your OpenClaw dashboard, and start a conversation with your OpenClaw assistant!
With the many ways running OpenClaw can charge you on AWS, it’s very important that you are mindful of your usage and stop or delete the instance when you are done with it.
Thankfully, it’s very quick an easy: go to the OpenClaw dashboard, and click Delete.
If you want to keep your data, create a snapshot of the instance before deletion.
Looking for an in-depth introduction and tutorial on setting up OpenClaw on Lightsail (especially the technical specifications)?
Check out the official documentation and Frequently Asked Questions on AWS’s KB.
AWS’s official documentation provides information on costs associated with running OpenClaw on Lightsail. There are a few ways you will be charged. (Information pulled from: here.)
- Lightsail instance — You pay for the instance plan you selected (e.g. the 4 GB plan). Lightsail plans are billed on an on-demand hourly rate, so you pay only for what you use. For every Lightsail plan you use, we charge you the fixed hourly price, up to the maximum monthly plan cost.
- AI model usage (tokens) — Every message sent to and received from the OpenClaw assistant is processed through Amazon Bedrock using a token-based pricing model. Costs vary by model — some models are more expensive per token than others.
- Third-party model subscriptions — If you select a third-party model distributed through AWS Marketplace (such as Anthropic Claude or Cohere), there may be additional software fees on top of the per-token cost. These appear as separate line items under AWS Marketplace in your bill.
- Data transfer overages — Each Lightsail plan includes a monthly data transfer allowance. If your OpenClaw instance sends or receives more data than your plan includes, overage charges apply for data transfer out.
- Snapshots — Manual and automatic snapshots of your Lightsail instance are billed based on the amount of storage used.
One thing you need to be cognizant of is that your charge to use Amazon Lightsail to run OpenClaw is separate from your usage charge to use the AI assistant capabilities through Amazon Bedrock. So each interaction you have with your assistant will be costing you tokens (which, in turn, is money).
You can also connect your OpenClaw to “talk” to you via messaging applications like Telegram and WhatsApp. You can follow the instructions on AWS’s official documentation to set this up: Connect a messaging channel.
The post OpenClaw on Amazon Lightsail for Newbies appeared first on awsnewbies.com.
]]>