2025-09-19 21:02:28
๋ฐ˜์‘ํ˜•

๐Ÿ“˜ AWS Certified SysOps Administrator - Associate (SOA-C02)

Domain 4: ๋ณด์•ˆ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜ (Security & Compliance)

> ์ด ๋„๋ฉ”์ธ์€ ์‹œํ—˜ ์ ์ˆ˜์˜ **16%**๋ฅผ ์ฐจ์ง€ํ•˜๋ฉฐ, AWS ๋ณด์•ˆ๊ณผ ๊ทœ์ • ์ค€์ˆ˜ ์ •์ฑ…์„ ์ดํ•ดํ•˜๊ณ  ๊ตฌํ˜„ํ•˜๋Š” ๋Šฅ๋ ฅ์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
> ํ•ต์‹ฌ์€ **๋น„๋ฐ€ ์œ ์ง€(Secrets)** ์™€ **๋ณด์•ˆ ์œ ์ง€(Security)** ์ž…๋‹ˆ๋‹ค.

---

๐Ÿ”‘ ์ฃผ์š” ํ•™์Šต ์ฃผ์ œ

1. ๋ณด์•ˆ ์ •์ฑ… ๋ฐ ๊ทœ์ • ์ค€์ˆ˜ ์ •์ฑ… ๊ตฌํ˜„

- **IAM ๊ด€๋ฆฌ**

  • ์‚ฌ์šฉ์ž(User), ๊ทธ๋ฃน(Group), ์—ญํ• (Role)์˜ ์ฐจ์ด ์ดํ•ด
  • ์•”ํ˜ธ ์ •์ฑ…(Password Policy), MFA ์ ์šฉ
  • IAM ์ •์ฑ… JSON ํ•ด์„ ๋Šฅ๋ ฅ
  • IAM Access Analyzer, Policy Simulator ํ™œ์šฉ

- **๊ฐ์‚ฌ & ๋ชจ๋‹ˆํ„ฐ๋ง**

  • AWS CloudTrail: ๋ชจ๋“  API ํ˜ธ์ถœ ๊ธฐ๋ก
  • AWS Trusted Advisor: ๋ณด์•ˆ ๊ถŒ์žฅ ์‚ฌํ•ญ ํ™•์ธ
  • ๋‹ค์ค‘ ๊ณ„์ • ์ „๋žต: AWS Organizations, Control Tower
  • ๋ฆฌ์ „ ์„ ํƒ ์‹œ ๊ทœ์ • ์ค€์ˆ˜ ๊ณ ๋ ค (GDPR, PCI DSS ๋“ฑ)

---

2. ๋ฐ์ดํ„ฐ ๋ฐ ์ธํ”„๋ผ ๋ณดํ˜ธ ์ „๋žต

- **๋ฐ์ดํ„ฐ ๋ณดํ˜ธ & ๋ถ„๋ฅ˜**

  • ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ vs ๊ณต๊ฐœ ๋ฐ์ดํ„ฐ ๊ตฌ๋ถ„
  • ๋ณด๊ด€ ์œ„์น˜ ๋ฐ ์•”ํ˜ธํ™” ์˜๋ฌดํ™”

- **์•”ํ˜ธํ™” & ํ‚ค ๊ด€๋ฆฌ**

  • S3 ์•”ํ˜ธํ™” ์˜ต์…˜ (SSE-S3, SSE-KMS, SSE-C)
  • AWS KMS, CloudHSM ํ‚ค ๊ด€๋ฆฌ
  • ์ „์†ก ์ค‘ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™” (VPN, TLS, ACM ์ธ์ฆ์„œ)

- **๋น„๋ฐ€ ๊ด€๋ฆฌ & ๋ณด์•ˆ ์„œ๋น„์Šค**

  • AWS Secrets Manager → DB ๋น„๋ฐ€๋ฒˆํ˜ธ, API ํ‚ค ์ €์žฅ
  • SSM Parameter Store → ์„ค์ •๊ฐ’ ์•ˆ์ „ ๊ด€๋ฆฌ
  • AWS Config, GuardDuty, Security Hub, Inspector, Macie → ๋ณด์•ˆ ์ƒํƒœ ์ ๊ฒ€

---

{
  "Version": "2012-10-17", // ์ •์ฑ… ๋ฒ„์ „ (ํ•ญ์ƒ ์ด ๋‚ ์งœ ํ˜•์‹ ๊ณ ์ •)
  "Statement": [           // ๊ถŒํ•œ์„ ์ •์˜ํ•˜๋Š” ๋ธ”๋ก
    {
      "Effect": "Allow",   // ํ—ˆ์šฉ(Allow) ๋˜๋Š” ๊ฑฐ๋ถ€(Deny)
      "Action": "s3:*",    // S3 ์„œ๋น„์Šค์—์„œ ๋ชจ๋“  ๋™์ž‘ ํ—ˆ์šฉ
      "Resource": "*"      // ๋ชจ๋“  S3 ๋ฆฌ์†Œ์Šค์— ์ ์šฉ
    }
  ]
}

๐Ÿ”Ž ๋ผ์ธ๋ณ„ ์„ค๋ช…

  • "Version": "2012-10-17" → AWS ์ •์ฑ… ๋ฌธ์„œ ํ‘œ์ค€ ๋ฒ„์ „
  • "Statement" → ์‹ค์ œ ๊ถŒํ•œ ์ •์˜ํ•˜๋Š” ๋ฐฐ์—ด
  • "Effect": "Allow" → ๋™์ž‘์„ ํ—ˆ์šฉํ•œ๋‹ค๋Š” ์˜๋ฏธ
  • "Action": "s3:*" → S3์—์„œ ๊ฐ€๋Šฅํ•œ ๋ชจ๋“  API ํ˜ธ์ถœ ํ—ˆ์šฉ (GetObject, PutObject ๋“ฑ)
  • "Resource": "*" → ๋ชจ๋“  S3 ๋ฒ„ํ‚ท ๋ฐ ๊ฐ์ฒด์— ์ ์šฉ

๐Ÿ‘‰ ์‹ค์ œ ํ˜„์—…์—์„œ๋Š” Resource ๋ฅผ "arn:aws:s3:::my-bucket/*" ๊ฐ™์ด ํŠน์ • ๋ฆฌ์†Œ์Šค๋กœ ์ œํ•œํ•˜๋Š” ๊ฒƒ์ด ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€์ž…๋‹ˆ๋‹ค.


๐Ÿ’ผ ํ˜„์—… ์ ์šฉ ์‚ฌ๋ก€

  1. IAM & MFA
    • ์‚ฌ๋‚ด ์ง์› ๊ณ„์ •์— MFA๋ฅผ ํ•„์ˆ˜ ์ ์šฉํ•˜์—ฌ ๊ณ„์ • ํƒˆ์ทจ ์œ„ํ—˜ ๋ฐฉ์ง€
  2. CloudTrail & GuardDuty
    • ๋ชจ๋“  API ํ˜ธ์ถœ์„ ๊ธฐ๋ก → ๋น„์ •์ƒ ๋กœ๊ทธ์ธ ์‹œ๋„ ํƒ์ง€ ๊ฐ€๋Šฅ
  3. ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”
    • ๊ณ ๊ฐ์˜ ๊ธˆ์œต/์˜๋ฃŒ ๋ฐ์ดํ„ฐ๋Š” ๋ฐ˜๋“œ์‹œ KMS๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•”ํ˜ธํ™”
    • GDPR ๋“ฑ ๊ทœ์ •์— ๋”ฐ๋ผ ํŠน์ • ๋ฆฌ์ „(EU) ๋‚ด ๋ฐ์ดํ„ฐ ์ €์žฅ
  4. Secrets Manager
    • RDS ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ง์ ‘ ์ฝ”๋“œ์— ๋„ฃ์ง€ ์•Š๊ณ  Secrets Manager์— ์ €์žฅ → ์•ฑ์ด ๋™์ ์œผ๋กœ ๋ถˆ๋Ÿฌ์™€ ์‚ฌ์šฉ
  5. Security Hub & Inspector
    • ๋ณด์•ˆ ์ทจ์•ฝ์  ์ž๋™ ํƒ์ง€ → ํŒจ์น˜ ๋ฏธ์ ์šฉ ์„œ๋ฒ„๋ฅผ ์•Œ๋ฆผ์œผ๋กœ ํ™•์ธ ๊ฐ€๋Šฅ

๐Ÿ“Œ ํ•ต์‹ฌ ํ‚ค์›Œ๋“œ ์š”์•ฝ

  • IAM, MFA, JSON ์ •์ฑ…, Access Analyzer
  • CloudTrail, Trusted Advisor, AWS Organizations
  • ๋ฐ์ดํ„ฐ ๋ถ„๋ฅ˜, ์•”ํ˜ธํ™” (KMS, CloudHSM, ACM, VPN)
  • Secrets Manager, Parameter Store
  • Config, GuardDuty, Security Hub, Inspector, Macie

๐Ÿ” AWS Certified SysOps Administrator - Associate (SOA-C02)

Domain 4: ๋ณด์•ˆ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜์— ๋Œ€ํ•œ ์ดํ•ด


๐Ÿ“Œ ํ•ต์‹ฌ ์š”์•ฝ

  • ๋ณด์•ˆ์€ AWS ์ธํ”„๋ผ์˜ ๋ชจ๋“  ๋‹จ๊ณ„(๊ณ„ํš → ๊ตฌ์ถ• → ์šด์˜) ์— ๊ฑธ์ณ ๋ฐ˜๋“œ์‹œ ๊ณ ๋ คํ•ด์•ผ ํ•จ
  • IAM ์€ AWS ์•ก์„ธ์Šค ๊ด€๋ฆฌ์˜ ์ค‘์‹ฌ → ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์ ์šฉ ํ•„์ˆ˜
  • CloudTrail, CloudWatch ๋ฅผ ํ†ตํ•œ ๊ฐ์‚ฌ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง์œผ๋กœ ๊ทœ์ • ์ค€์ˆ˜ ์œ ์ง€
  • ์‹œํ—˜์—์„œ๋Š” “๋ณด์•ˆ์„ฑ์ด ๋” ๋†’์€ ์„ ํƒ์ง€๊ฐ€ ์žˆ์œผ๋ฉด ๊ทธ๊ฒƒ์ด ์ •๋‹ต”์ธ ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ

๐Ÿ›ก๏ธ ์ฃผ์š” ํ•™์Šต ํฌ์ธํŠธ

1. IAM (Identity & Access Management)

  • ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ (Least Privilege)
    • ์‚ฌ์šฉ์ž์—๊ฒŒ ๊ผญ ํ•„์š”ํ•œ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌ
    • Production ๊ณ„์ • ์ง์ ‘ ์•ก์„ธ์Šค๋Š” ๊ทนํžˆ ์ œํ•œ
  • MFA(๋ฉ€ํ‹ฐ ํŒฉํ„ฐ ์ธ์ฆ)
    • ์ฝ˜์†” ๋กœ๊ทธ์ธ ์‹œ ์ถ”๊ฐ€ ์ธ์ฆ ๋‹จ๊ณ„ ์š”๊ตฌ
  • ์—ญํ• (Role)๊ณผ ํŽ˜๋”๋ ˆ์ด์…˜(Federation)
    • ์ž„์‹œ ๊ถŒํ•œ ๋ถ€์—ฌ / ์™ธ๋ถ€ IdP ์—ฐ๋™

2. ๋ณ€๊ฒฝ ๊ด€๋ฆฌ & ์ž๋™ํ™”

  • ๋ฆฌ์†Œ์Šค ์‹œ์ž‘·์ข…๋ฃŒ ๊ถŒํ•œ์€ ๊ฐœ์ธ์ด ์•„๋‹Œ ์ž๋™ํ™” ๋„๊ตฌ๋ฅผ ํ†ตํ•ด ์ˆ˜ํ–‰
  • ๋ณ€๊ฒฝ ๊ด€๋ฆฌ ํ”„๋กœ์„ธ์Šค๋ฅผ ํ†ตํ•ด ์‹ค์ˆ˜·์˜ค๋ฅ˜๋ฅผ ์ตœ์†Œํ™”

3. ๊ฐ์‚ฌ & ์ถ”์ 

  • AWS CloudTrail
    • ๋ชจ๋“  API ํ˜ธ์ถœ ๋ฐ ์ด๋ฒคํŠธ ๋กœ๊น…
    • “๋ˆ„๊ฐ€, ์–ธ์ œ, ๋ฌด์—‡์„” ํ–ˆ๋Š”์ง€ ์ถ”์  ๊ฐ€๋Šฅ
  • Amazon CloudWatch
    • CloudTrail ์ด๋ฒคํŠธ์™€ ์—ฐ๋™ → ์•Œ๋žŒ·๊ฒฝ๋ณด ์ƒ์„ฑ
  • ๊ทœ์ • ์ค€์ˆ˜ ๋ฏธ์ค€์ˆ˜ ํ™œ๋™ ํƒ์ง€ ๋ฐ ์•Œ๋ฆผ ์ž๋™ํ™” ๊ฐ€๋Šฅ

๐Ÿ“Š ๋ณด์•ˆ & ๊ทœ์ • ์ค€์ˆ˜ ํ๋ฆ„ (Mermaid)

flowchart TD
    A["๋ณด์•ˆ & ๊ทœ์ • ์ค€์ˆ˜ ๊ณ ๋ ค"] --> B["IAM ๊ด€๋ฆฌ"]
    A --> C["๋ณ€๊ฒฝ ๊ด€๋ฆฌ & ์ž๋™ํ™”"]
    A --> D["๊ฐ์‚ฌ & ์ถ”์ "]

    B --> B1["์ตœ์†Œ ๊ถŒํ•œ ์›์น™"]
    B --> B2["MFA ์ ์šฉ"]
    B --> B3["Role / Federation ํ™œ์šฉ"]

    C --> C1["์ž๋™ํ™” ๋„๊ตฌ๋ฅผ ํ†ตํ•œ ๋ฆฌ์†Œ์Šค ์ œ์–ด"]
    C --> C2["ํ”„๋กœ๋•์…˜ ๊ณ„์ • ์ง์ ‘ ์•ก์„ธ์Šค ์ตœ์†Œํ™”"]

    D --> D1["CloudTrail ๋กœ๊ทธ"]
    D --> D2["CloudWatch ์•Œ๋žŒ"]
    D --> D3["๊ทœ์ • ์ค€์ˆ˜ ์ƒํƒœ ์ ๊ฒ€"]


๐Ÿ“ ์˜ˆ์‹œ IAM ์ •์ฑ… JSON

{
"Version": "2012-10-17", // ์ •์ฑ… ๋ฒ„์ „ (๊ณ ์ •๋œ ํ‘œ์ค€)
"Statement": [
{
"Effect": "Allow", // ํ—ˆ์šฉ ๊ทœ์น™
"Action": [ // ํ—ˆ์šฉํ•  ์•ก์…˜ ๋ชฉ๋ก
"ec2:StartInstances",
"ec2:StopInstances"
],
"Resource": "arn:aws:ec2:ap-northeast-2:123456789012:instance/*"
// ํŠน์ • ๊ณ„์ •์˜ ๋ชจ๋“  EC2 ์ธ์Šคํ„ด์Šค
}
]
}

```

๐Ÿ‘‰ ์‹ค๋ฌด ํฌ์ธํŠธ

  • Production ํ™˜๊ฒฝ์—์„œ๋Š” ec2:TerminateInstances ๊ถŒํ•œ์€ ์ ˆ๋Œ€ ์ง์ ‘ ๋ถ€์—ฌ ๊ธˆ์ง€
  • Terraform, CloudFormation ๊ฐ™์€ IaC ๋„๊ตฌ๋ฅผ ํ†ตํ•ด ๊ด€๋ฆฌํ•˜๋Š” ๊ฒƒ์ด ์•ˆ์ „

๐Ÿ’ผ ํ˜„์—… ์ ์šฉ ์‚ฌ๋ก€

  1. ๊ธˆ์œตํšŒ์‚ฌ: ๊ณ ๊ฐ ๋ฐ์ดํ„ฐ ์ €์žฅ ์‹œ ๋ฐ˜๋“œ์‹œ KMS ํ‚ค๋กœ ์•”ํ˜ธํ™”
  2. ๊ฒŒ์ž„์‚ฌ: ์šด์˜์ž๊ฐ€ ์‹ค์ˆ˜๋กœ ์„œ๋ฒ„๋ฅผ ์ข…๋ฃŒํ•˜์ง€ ์•Š๋„๋ก EC2 ์ข…๋ฃŒ ๊ถŒํ•œ์€ ์ž๋™ํ™” ๋„๊ตฌ์—๋งŒ ๋ถ€์—ฌ
  3. ์˜๋ฃŒ๊ธฐ๊ด€: CloudTrail + GuardDuty๋กœ ์˜์‹ฌ์Šค๋Ÿฌ์šด API ํ˜ธ์ถœ ํƒ์ง€
  4. ์Šคํƒ€ํŠธ์—…: Secrets Manager๋กœ DB ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ → ์ฝ”๋“œ์— ํ•˜๋“œ์ฝ”๋”ฉ ๊ธˆ์ง€

๐Ÿ“Œ ์‹œํ—˜ ๋Œ€๋น„ ํŒ

  • “๋‘ ์˜ต์…˜ ์ค‘ ํ•˜๋‚˜๊ฐ€ ๋ณด์•ˆ์„ฑ์ด ๋” ๋†’๋‹ค” → ๋ณด์•ˆ ๊ฐ•ํ™”๋œ ์˜ต์…˜ ์„ ํƒ
  • IAM, CloudTrail, CloudWatch, Config, GuardDuty, Security Hub ๋“ฑ ๋ณด์•ˆ ์„œ๋น„์Šค์˜ ๋ชฉ์ ๊ณผ ์ฐจ์ด์  ์ˆ™์ง€
  • Least Privilege ๋Š” ํ•ญ์ƒ ๋‹ต์•ˆ์—์„œ ํ•ต์‹ฌ ํ‚ค์›Œ๋“œ

โœ… ๊ฒฐ๋ก : ๋ณด์•ˆ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜๋Š” AWS ์ธํ”„๋ผ์˜ ๊ธฐ์ดˆ ์ฒด๋ ฅ
์‹œํ—˜๋ฟ ์•„๋‹ˆ๋ผ ์‹ค๋ฌด์—์„œ๋„ IAM, ๊ฐ์‚ฌ, ์•”ํ˜ธํ™”๋Š” ๋ฐ˜๋“œ์‹œ ์ˆ™์ง€ํ•ด์•ผ ํ•˜๋Š” ํ•ต์‹ฌ์ž…๋‹ˆ๋‹ค.

๋ฐ˜์‘ํ˜•

'AWS > Skill Builder_AWS SOA-C02' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

AWS SOA-C02 Domain 6 Review  (0) 2025.09.19
AWS SOA-C02 Domain 5 Review  (0) 2025.09.19
AWS SOA-C02 Domain 3 Review  (0) 2025.09.18
AWS SOA-C02 Domain 1 Review  (0) 2025.09.18