← AWS CloudOps Engineer: operations and recovery
06 / 7 · 30 MIN

Security in operations and recovery

Check effective permissions, renewal, and demonstrated remediation.

Concept and mechanism

Operations implements defined security requirements and gathers working evidence. An SCP restricts possible permissions in a member account but does not grant actions to a role. In KMS, possessing encrypted data and an IAM Allow may be insufficient when the key policy does not support that path and no applicable grant exists. Rehearsing recovery with the contingency identity avoids relying on the preparer’s personal session. For secrets, define actions and resources required by the task; metadata may support diagnosis without reading the value. Keep access attributable and revocable.

Guided application

Certificates also have a lifecycle. A certificate imported into ACM does not automatically receive managed renewal intended for eligible certificates. Plan renewal, reimport, and verification of the certificate actually served. In AWS Config remediation, the evaluation triggering action may precede current state; check before changing and tolerate already compliant resources. In Security Hub, marking a finding RESOLVED updates workflow but does not itself change vulnerable configuration. Tie resolution to correction and reevaluation evidence, with ownership and follow-up for approved exceptions.

IN PRACTICE

In a DR rehearsal, use the designated role to read encrypted data. A test performed only by the key-creating administrator does not validate contingency-team access.

Common pitfalls

SCP treated as a grant; backup without key access; visible certificate treated as guaranteed renewal; closed finding treated as corrected resource.

Related topics: Networking, DNS, and content delivery · Signals, alarms, and missing telemetry

Take this idea with you

Administrative state should match demonstrated technical control.

Create account

Reference: AWS Config remediation · SOA-C03; exam guide 1.1