Home About For organisations The labs Gallery FAQ Contact

Cloud Security on Azure and AWS
Professional-level course

Cloud security on Azure and AWS - identity and access, networking, encryption, security posture and detection on both clouds. You leave able to build a secure cloud environment, audit an existing one against the vendor's recommendations and fix what the audit finds.

Registration
Waiting list
Duration
30 academic hours
Format
In personHybrid
Level
Professional
Certification
Toward Microsoft SC-500 (Cloud and AI Security Engineer Associate) and AWS Certified Security - Specialty (SCS-C03)
Language
Hebrew, course materials in English
For organisations
By arrangement - at the academy or hybrid

What you will be able to do

  • Set up identity and access properly - Microsoft Entra ID with Conditional Access and RBAC, and AWS IAM with least-privilege policies
  • Segment cloud networks - VNet and VPC, NSGs and security groups, Azure Firewall and WAF, and a secure link to the site
  • Encrypt data at rest and in transit with Key Vault and KMS, and manage keys, secrets and certificates
  • Measure security posture with Microsoft Defender for Cloud and CSPM tooling, and close findings by priority
  • Collect logs and detect incidents in the cloud - Microsoft Sentinel and Microsoft Defender XDR on Azure, CloudTrail and GuardDuty on AWS
  • Secure AI workloads in the cloud - model access, data and keys - as SC-500 requires

The syllabus

8 modules over 30 academic hours. Open a module for its topics.

  • Service models, regions and availability, the shared responsibility model
  • Azure and AWS building blocks: subscriptions and accounts, resource groups, tags
  • Governance: Azure Policy and management groups, AWS Organizations
  • Where AZ-900 and AWS Certified Cloud Practitioner (CLF-C02) sit on the path

  • Microsoft Entra ID: users, groups, roles, Conditional Access, MFA
  • Azure RBAC, Privileged Identity Management and managed identities
  • AWS IAM: users, roles, policies, permission boundaries, IAM Identity Center
  • Federation and single sign-on across both clouds

  • VNet and VPC design, subnets, routing and peering
  • NSGs and security groups, network ACLs
  • Azure Firewall and WAF; firewall rules on AWS
  • Private endpoints, site-to-site VPN and private connectivity to the site

  • Encryption at rest and in transit; key management with Key Vault and KMS
  • Storage security: Azure Storage and S3 access control, blocking public access
  • Database security: authentication, network isolation, encryption, auditing
  • Secrets, certificates and rotation

  • Hardening virtual machines, images and patching
  • Containers and Kubernetes clusters: registries, cluster access, workload identity
  • Serverless and app services: identities, secrets, network restrictions
  • Securing AI workloads - model access, data and keys (SC-500)

  • Microsoft Defender for Cloud: secure score, recommendations, regulatory standards
  • CSPM across both clouds, misconfiguration findings and remediation
  • Compliance evidence with Microsoft Purview and AWS governance tooling
  • Policy as code and drift detection

  • Log sources: activity and sign-in logs, CloudTrail, flow logs
  • Microsoft Sentinel and Microsoft Defender XDR: analytics rules, incidents, KQL
  • AWS detection and response: GuardDuty findings and response playbooks
  • The incident response life cycle of NIST SP 800-61r3, in a cloud context

  • Securing a two-cloud landing zone end to end
  • Auditing an existing environment and writing the findings report
  • Mapping the material to SC-900, AZ-900, CLF-C02, SC-500 and SCS-C03
  • Exam booking, timing and what each exam measures
Cloud Security on Azure and AWS Opening soon +972 8-669-8400

Who it is for

Who takes this course, and what you need before the first session.

IT and infrastructure staff moving services to Azure or AWS and responsible for securing them

Security staff and SOC analysts whose logs and incidents now come from the cloud too

Developers and DevOps engineers who stand up environments and want them secure from day one

Prerequisites

Experience in systems or network administration and basic familiarity with one of the two clouds; Linux and command-line familiarity helps.

The exam and the certification

The course follows Microsoft's and AWS's published exam outlines. On the Microsoft side: SC-900 and AZ-900 (45 minutes each, passing score 700) as the base, and Exam SC-500, Implementing End-to-End Security Controls for Cloud and AI Workloads - 120 minutes, in English - which earns Microsoft Certified: Cloud and AI Security Engineer Associate; it replaced AZ-500, retired on August 31, 2026. On the AWS side: AWS Certified Cloud Practitioner (CLF-C02, 90 minutes, 65 questions, valid 3 years) as the base, and AWS Certified Security - Specialty (SCS-C03, 170 minutes, 65 questions) as the advanced target - AWS describes its target candidate as having 3-5 years of experience securing cloud solutions. Microsoft's fundamentals exams are scheduled through Pearson VUE. The academy issues its own certificate of completion at the end of the course.

Toward Microsoft SC-500 (Cloud and AI Security Engineer Associate) and AWS Certified Security - Specialty (SCS-C03)

The certification

Toward Microsoft SC-500 (Cloud and AI Security Engineer Associate) and AWS Certified Security - Specialty (SCS-C03)

Microsoft

SC-900 and AZ-900 are 45 minutes each; SC-200 is 100 minutes; SC-500 - Cloud and AI Security Engineer Associate - is 120 minutes, in English. Passing score 700.

AWS

AWS Certified Cloud Practitioner (CLF-C02): 90 minutes, 65 questions, valid three years. AWS Certified Security - Specialty (SCS-C03): 170 minutes, 65 questions.

Renewal

SC-200 is renewed every twelve months with a free online assessment; SC-900 and AZ-900 do not expire. AZ-500 retired on August 31, 2026, and SC-500 is its replacement.

The labs

The work is done in the academy's Azure and AWS lab environments. In them you build the environment from nothing: identities and Conditional Access in Microsoft Entra ID, IAM policies on AWS, segmented networks with NSGs and security groups, Key Vault and KMS, and then connect all of it to Microsoft Defender for Cloud and Microsoft Sentinel and watch the findings and incidents arrive. The closing exercise hands you an environment built wrong on purpose, to bring back to a sound state from the audit's findings.

The SpotAcademy classroom in Shoham - rows of workstations, and the equipment rack behind them
The classroom in Shoham. The sessions run here, and the lab environment is reached from the workstations and from home.

Two ways to take the course

The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.

The next cohort

The next cohort is in planning - 30 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.

For your team

An intensive format, by arrangement - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.

Leave us your details

A few lines about what you are after - a course for yourself or training for a team - are enough. The message reaches the academy team directly.

Who is this for