Cloud Security on Azure and AWS
Professional-level course
Cloud security on Azure and AWS - identity and access, networking, encryption, security posture and detection on both clouds. You leave able to build a secure cloud environment, audit an existing one against the vendor's recommendations and fix what the audit finds.
- Registration
- Waiting list
- Duration
- 30 academic hours
- Format
- In personHybrid
- Level
- Professional
- Certification
- Toward Microsoft SC-500 (Cloud and AI Security Engineer Associate) and AWS Certified Security - Specialty (SCS-C03)
- Language
- Hebrew, course materials in English
- For organisations
- By arrangement - at the academy or hybrid
What you will be able to do
- Set up identity and access properly - Microsoft Entra ID with Conditional Access and RBAC, and AWS IAM with least-privilege policies
- Segment cloud networks - VNet and VPC, NSGs and security groups, Azure Firewall and WAF, and a secure link to the site
- Encrypt data at rest and in transit with Key Vault and KMS, and manage keys, secrets and certificates
- Measure security posture with Microsoft Defender for Cloud and CSPM tooling, and close findings by priority
- Collect logs and detect incidents in the cloud - Microsoft Sentinel and Microsoft Defender XDR on Azure, CloudTrail and GuardDuty on AWS
- Secure AI workloads in the cloud - model access, data and keys - as SC-500 requires
The syllabus
8 modules over 30 academic hours. Open a module for its topics.
- Service models, regions and availability, the shared responsibility model
- Azure and AWS building blocks: subscriptions and accounts, resource groups, tags
- Governance: Azure Policy and management groups, AWS Organizations
- Where AZ-900 and AWS Certified Cloud Practitioner (CLF-C02) sit on the path
- Microsoft Entra ID: users, groups, roles, Conditional Access, MFA
- Azure RBAC, Privileged Identity Management and managed identities
- AWS IAM: users, roles, policies, permission boundaries, IAM Identity Center
- Federation and single sign-on across both clouds
- VNet and VPC design, subnets, routing and peering
- NSGs and security groups, network ACLs
- Azure Firewall and WAF; firewall rules on AWS
- Private endpoints, site-to-site VPN and private connectivity to the site
- Encryption at rest and in transit; key management with Key Vault and KMS
- Storage security: Azure Storage and S3 access control, blocking public access
- Database security: authentication, network isolation, encryption, auditing
- Secrets, certificates and rotation
- Hardening virtual machines, images and patching
- Containers and Kubernetes clusters: registries, cluster access, workload identity
- Serverless and app services: identities, secrets, network restrictions
- Securing AI workloads - model access, data and keys (SC-500)
- Microsoft Defender for Cloud: secure score, recommendations, regulatory standards
- CSPM across both clouds, misconfiguration findings and remediation
- Compliance evidence with Microsoft Purview and AWS governance tooling
- Policy as code and drift detection
- Log sources: activity and sign-in logs, CloudTrail, flow logs
- Microsoft Sentinel and Microsoft Defender XDR: analytics rules, incidents, KQL
- AWS detection and response: GuardDuty findings and response playbooks
- The incident response life cycle of NIST SP 800-61r3, in a cloud context
- Securing a two-cloud landing zone end to end
- Auditing an existing environment and writing the findings report
- Mapping the material to SC-900, AZ-900, CLF-C02, SC-500 and SCS-C03
- Exam booking, timing and what each exam measures
Who it is for
Who takes this course, and what you need before the first session.
IT and infrastructure staff moving services to Azure or AWS and responsible for securing them
Security staff and SOC analysts whose logs and incidents now come from the cloud too
Developers and DevOps engineers who stand up environments and want them secure from day one
Prerequisites
Experience in systems or network administration and basic familiarity with one of the two clouds; Linux and command-line familiarity helps.
The exam and the certification
The course follows Microsoft's and AWS's published exam outlines. On the Microsoft side: SC-900 and AZ-900 (45 minutes each, passing score 700) as the base, and Exam SC-500, Implementing End-to-End Security Controls for Cloud and AI Workloads - 120 minutes, in English - which earns Microsoft Certified: Cloud and AI Security Engineer Associate; it replaced AZ-500, retired on August 31, 2026. On the AWS side: AWS Certified Cloud Practitioner (CLF-C02, 90 minutes, 65 questions, valid 3 years) as the base, and AWS Certified Security - Specialty (SCS-C03, 170 minutes, 65 questions) as the advanced target - AWS describes its target candidate as having 3-5 years of experience securing cloud solutions. Microsoft's fundamentals exams are scheduled through Pearson VUE. The academy issues its own certificate of completion at the end of the course.
The certification
Toward Microsoft SC-500 (Cloud and AI Security Engineer Associate) and AWS Certified Security - Specialty (SCS-C03)
Microsoft
SC-900 and AZ-900 are 45 minutes each; SC-200 is 100 minutes; SC-500 - Cloud and AI Security Engineer Associate - is 120 minutes, in English. Passing score 700.
AWS
AWS Certified Cloud Practitioner (CLF-C02): 90 minutes, 65 questions, valid three years. AWS Certified Security - Specialty (SCS-C03): 170 minutes, 65 questions.
Renewal
SC-200 is renewed every twelve months with a free online assessment; SC-900 and AZ-900 do not expire. AZ-500 retired on August 31, 2026, and SC-500 is its replacement.
The labs
The work is done in the academy's Azure and AWS lab environments. In them you build the environment from nothing: identities and Conditional Access in Microsoft Entra ID, IAM policies on AWS, segmented networks with NSGs and security groups, Key Vault and KMS, and then connect all of it to Microsoft Defender for Cloud and Microsoft Sentinel and watch the findings and incidents arrive. The closing exercise hands you an environment built wrong on purpose, to bring back to a sound state from the audit's findings.
Two ways to take the course
The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.
The next cohort
The next cohort is in planning - 30 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.
For your team
An intensive format, by arrangement - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.
Related courses
Linux Administration
Linux administration from the first shell prompt to a running server - the command line, users and permissions, storage, services, networking and shell scripts - on Linux servers of your own in the lab. You leave able to build a Linux server, maintain it and troubleshoot it, with the material of the LPIC-1 and CompTIA Linux+ exams covered.
ExplorePalo Alto Networks Firewall Administration
Building and operating a Palo Alto Networks next-generation firewall - zones and security policy, NAT, App-ID, User-ID, security profiles, URL filtering, WildFire and decryption, following the topics the vendor publishes for its Firewall Essentials: Configuration and Management (EDU-210) outline and the Next-Generation Firewall Engineer exam blueprint. Participants leave able to put a firewall into a production network, write its policy and read its logs.
Explore