This hands-on lab provides an introduction to AWS Security Hub and how it can be used to analyze the security of an AWS account. You can view this hands-on lab as a Security Hub quick start guide.
Learning Objectives
Successfully complete this lab by achieving the following learning objectives:
- Enable AWS Security Hub
- Enable AWS Config
- Then, enable AWS Security Hub
- Create a VPC
- From the VPC console, select Create VPC
- Select VPC and More
- From the VPC console, select Create VPC
- Create a Security Group
- Create an EC2 Security Hub
- Set the ingress on port 22 to 0.0.0.0/0 (This will create a critical finding in Security Hub.)
- Create an EC2 Security Hub
- Create an S3 Bucket
- Create an S3 bucket with open read access
- Turn off the checkbox (the default), which restricts open read access (This will create a Security Hub finding.)
- Create an S3 bucket with open read access