Cloud Security
AWS Security Essentials
Secure an AWS account from empty to audited baseline.
- 10 modules
- 16 labs
- ~18 hours
- Beginner

- Hands-on Labs
- Certificate
- Beginner Friendly
Course overview
A beginner-friendly but hands-on AWS security course. You start with a fresh account and progressively apply identity, network, logging, encryption and detection controls.
Every lab is free-tier conscious and ends with cleanup so you never leave billable resources running.
What you will be able to do
- Secure the AWS account root and set up organisational guardrails
- Write least-privilege IAM policies with confidence
- Design secure VPC networking
- Enable and use CloudTrail, Config and GuardDuty
- Encrypt data with KMS and manage secrets properly
Curriculum
- 1
Account & Root Security
The first hour of a new AWS account.
- Root account hardening
- Billing alarms
- Organisations and SCP basics
- 2
IAM in Depth
Policies, roles and boundaries.
- Policy evaluation logic
- Roles vs users
- Permission boundaries
- Access Analyzer
- 3
VPC & Network Security
Private by default.
- Subnet design
- Security groups vs NACLs
- VPC endpoints
- Flow logs
- 4
Logging & Detection
Know what happened.
- CloudTrail configuration
- AWS Config rules
- GuardDuty findings
- Security Hub
- 5
Data Protection
Encryption and secrets.
- KMS keys and policies
- S3 encryption and Block Public Access
- Secrets Manager
- 6
Baseline & Cleanup
Codify it, then tear it down.
- Baseline checklist
- Automating checks
- Cost-safe teardown
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Harden a new AWS account and enable billing alarms
- Write and test a least-privilege IAM policy
- Build a two-tier VPC with private subnets
- Enable CloudTrail and query the logs
- Trigger and investigate a GuardDuty finding
- Encrypt an S3 bucket with a customer-managed key
- Full account teardown verification
Portfolio projects
- An AWS security baseline document with screenshots
- An IAM policy library for common roles
- A detection and response runbook for GuardDuty findings
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
AWS Security Essentials is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
Related courses
Cybersecurity
SOC Analyst Level 1: Blue Team Fundamentals
Beginner · 12 modules · 18 labs
Cloud Security
Cloud Security Engineer Bootcamp
Intermediate · 14 modules · 22 labs
Network Security
Network Security Essentials
Beginner · 8 modules · 12 labs
