3.4.2.5. Combining Security Controls for Defense in Depth (ACM, WAF, Config, Security Hub, GuardDuty, Detective, Network Firewall)
3.4.2.5. Combining Security Controls for Defense in Depth (ACM, WAF, Shield)
Defense in depth means no single security control failure exposes the system. Each layer catches what the previous layer missed.
Security layers from edge to data:
- Edge (CloudFront + Shield + WAF): DDoS protection, web application firewall, geo-blocking
- Network (VPC + NACLs + Security Groups): Network segmentation, port filtering
- Compute (EC2/ECS + Inspector + SSM): Vulnerability scanning, patching, hardening
- Application (Cognito + API Gateway): Authentication, authorization, rate limiting
- Data (KMS + Macie + S3 policies): Encryption, data classification, access control
- Audit (CloudTrail + Config + Security Hub): Logging, compliance, finding aggregation
AWS Shield:
- Shield Standard: Free, automatic DDoS protection for all AWS resources (L3/L4)
- Shield Advanced: $3,000/month — L7 DDoS protection, DRT (DDoS Response Team) access, cost protection during attacks, WAF credits
Combining WAF + Shield + CloudFront:
Internet → CloudFront (Shield + WAF) → ALB (Security Group) → EC2 (Inspector patched)
↓
RDS (KMS encrypted, private subnet)
AWS PrivateLink exposes a service to other accounts through an endpoint service without peering whole VPCs: only principals on the service's allowed principals list can create interface endpoints to it, and consumer-side security groups narrow access further. That is identity-scoped, unlike CIDR rules over VPC peering.
AWS Network Firewall provides stateful inspection for VPC traffic — IDS/IPS capabilities that security groups and NACLs can't provide. Use for compliance environments requiring deep packet inspection.
Exam Trap: Shield Standard protects against network-layer DDoS (SYN floods, UDP reflection). Application-layer attacks (HTTP floods) require WAF rate-limiting rules. If the exam describes an application-layer DDoS (millions of legitimate-looking HTTP requests), Shield alone isn't enough — you need WAF with rate-based rules.