The Beginner Problem
One of the most common mistakes new AWS users make is launching resources before understanding three foundational concepts:
- Who is allowed to do something? → IAM
- Where are resources running? → Regions and Availability Zones
- Who is responsible for security? → Shared Responsibility Model
A beginner might create an EC2 instance, upload files to Amazon S3, and then realize:
- They accidentally used administrator permissions everywhere.
- They deployed resources in the wrong Region.
- They assumed AWS automatically backs up or secures everything.
- They cannot find a resource because they're viewing a different Region.
These mistakes appear simple, but they are exactly the type of concepts tested heavily in:
- AWS Certified Solutions Architect – Associate (SAA)
- AWS Certified Machine Learning Engineer – Associate (MLA-C02)
- AWS Professional-level architecture and security domains
In this hands-on article, you'll build foundational AWS knowledge through practical implementation instead of memorization.
Learning Objectives
By the end of this exercise you should understand:
- IAM users, groups, permissions, and policies
- Least privilege access
- AWS Regions and Availability Zones (AZs)
- High availability fundamentals
- AWS Shared Responsibility Model
- AWS account security best practices
- How these concepts fit into real cloud architectures
Where These Concepts Fit in Real Architecture
Before opening the console, it helps to understand where these concepts fit.
A simple AWS application may look like this:
User
|
v
IAM Authentication & Authorization
|
v
VPC
|
+---- EC2 Instance (AZ-A)
|
+---- EC2 Instance (AZ-B)
|
+---- Amazon S3 Bucket
|
+---- RDS Database
Architecture Diagram Description
Create an architecture image containing:
- One AWS Region
- Two Availability Zones within that Region
- One EC2 instance in each Availability Zone
- One Amazon S3 bucket shared across the Region
- One IAM user accessing AWS services
- Labels showing:
- IAM controls access
- AZs improve availability
- Regions determine geographic placement
- AWS and customer share security responsibilities
Understanding IAM
What Is IAM?
AWS Identity and Access Management (IAM) is the AWS service used to control who can access AWS resources and what actions they can perform.
Think of IAM as the security guard for your AWS account.
IAM answers three questions:
- Who are you?
- What resources can you access?
- What actions are you allowed to perform?
Without IAM, every user would effectively have administrator permissions, which creates major security risks.
Real-World Example
Imagine a startup team:
| Team Member | Access Needed |
|---|---|
| Developer | Amazon EC2 |
| Data Analyst | Amazon S3 |
| Security Engineer | IAM |
| Intern | Read-only access |
Giving all of them AdministratorAccess would violate AWS security best practices.
Instead, IAM allows organizations to grant only the permissions required for each role. This principle is known as least privilege.
Understanding Regions and Availability Zones
AWS infrastructure is organized into Regions and Availability Zones.
These concepts are frequently tested in AWS certification exams because they directly affect:
- Availability
- Resilience
- Disaster recovery
- Compliance
- Cost management
What Is a Region?
A Region is a geographic AWS location.
Examples include:
- US East (N. Virginia)
- US East (Ohio)
- Europe (Frankfurt)
- Asia Pacific (Mumbai)
When selecting a Region, consider:
- User location
- Regulatory requirements
- Available AWS services
- Latency requirements
Example
If your customers are primarily in Pakistan and India, you may choose:
ap-south-1 (Mumbai)
to reduce latency compared to a North American Region.
What Is an Availability Zone?
An Availability Zone (AZ) is an isolated AWS facility within a Region.
Examples:
us-east-1a
us-east-1b
us-east-1c
Each Availability Zone is designed to operate independently.
If one Availability Zone experiences problems:
- Applications running in another AZ may continue operating.
- High availability architectures remain functional.
Why Multiple Availability Zones Matter
Single-AZ deployment:
EC2
|
AZ-A
If AZ-A fails:
Application Unavailable
Multi-AZ deployment:
EC2 (AZ-A)
|
Load Balancer
|
EC2 (AZ-B)
If one AZ fails:
Traffic continues through surviving AZ
This is a core AWS high-availability pattern.
Understanding the Shared Responsibility Model
One of the most important AWS concepts is understanding who is responsible for what.
Many beginners incorrectly assume:
“AWS manages security, so I'm automatically protected.”
This is false.
AWS security follows a Shared Responsibility Model.
AWS Responsibilities
AWS is responsible for security OF the cloud, including:
- Physical data centers
- Physical network infrastructure
- Power systems
- Cooling systems
- Hardware
- Virtualization infrastructure
AWS manages and protects the underlying cloud infrastructure.
Customer Responsibilities
Customers are responsible for security IN the cloud, including:
- IAM permissions
- User management
- Data protection
- Application security
- Operating system patching on EC2
- Security Groups
- Encryption configuration
Certification Exam Example
Question:
An EC2 instance is compromised because security updates were never installed.
Who is responsible?
Answer: Customer
Reason:
For Amazon EC2, customers are responsible for managing and patching the guest operating system.
Prerequisites
Before beginning:
- AWS account
- Access to AWS Management Console
- MFA enabled on the root account (recommended)
- Modern web browser
- Basic cloud computing familiarity
Important: AWS updates the console regularly. If your interface differs from the screenshots or instructions shown here, verify the latest workflow using the official AWS documentation.
Hands-On Lab
Part 1: Create an IAM User
Certification Concepts
SAA
- Identity and Access Management
- Security Best Practices
- Least Privilege
MLA-C02
- Secure access to machine learning resources
Step 1: Open IAM
Navigate to:
AWS Console
→ IAM
→ Users
Why This Step Matters
Users represent individual human identities.
AWS recommends avoiding daily use of the root account.
Step 2: Create a New User
Select:
Create User
Example username:
student-user
Enable:
Provide user access to AWS Management Console
Why This Option Matters
This creates a separate identity rather than sharing root credentials.
This follows AWS security best practices.
Step 3: Assign Permissions
Choose:
Attach policies directly
Select:
ReadOnlyAccess
Why This Policy?
ReadOnlyAccess allows a user to:
- View resources
- Explore the account
- Learn AWS safely
It prevents:
- Resource deletion
- Infrastructure modification
- Administrative changes
This demonstrates least privilege access.
Step 4: Review and Create
Review:
- Username
- Console access
- Attached permissions
Click:
Create User
Save:
- Sign-in URL
- Username
You will use them later for testing.
Part 2: Explore AWS Regions
Certification Concepts
SAA
- Global Infrastructure
- Regional Design
- Workload Placement
Step 1: Locate the Region Selector
In the AWS Console, locate the Region selector in the upper-right corner.
Examples:
us-east-1
us-west-2
eu-west-1
ap-south-1
Step 2: Switch Between Regions
Move from one Region to another.
Observe:
- EC2 instance lists change
- VPC configurations change
- Resource inventories change
Key Lesson
Most AWS resources are Regional.
Resources created in one Region do not automatically appear in another Region.
Part 3: Explore Availability Zones
Certification Concepts
SAA
- Fault Tolerance
- Availability
- Resilience Design
Step 1: Open EC2
Navigate to:
EC2
→ Launch Instance
You do not need to launch an instance.
You are only exploring the configuration options.
Step 2: Review Network Placement
Locate:
Availability Zone
Examples:
us-east-1a
us-east-1b
us-east-1c
Why This Matters
Workloads distributed across multiple Availability Zones are more resilient than workloads running in a single AZ.
This principle is used heavily in production architectures.
Part 4: Apply the Shared Responsibility Model
Certification Concepts
SAA
- Security Design
- Operational Excellence
Professional Certifications
- Governance
- Risk Management
- Compliance
Scenario
You launch:
Amazon EC2
Now ask:
Who secures what?
AWS Secures
- Physical servers
- Network facilities
- Storage hardware
- Data center operations
You Secure
- Application code
- IAM permissions
- Operating system updates
- Security Groups
- Credentials
- Data access controls
Validation and Testing
Test 1: IAM Login
Log in using the newly created IAM user.
Expected Result:
Login succeeds
Test 2: Attempt Administrative Actions
Attempt:
Create a new IAM policy
Expected Result:
Access Denied
Reason:
ReadOnlyAccess does not permit administrative changes.
Test 3: Switch Regions
Move between Regions.
Expected Result:
Different resources appear
Test 4: Identify Availability Zones
Locate at least two AZs within your selected Region.
Expected Result:
Multiple AZs available
Test 5: Shared Responsibility Review
For an EC2 deployment, identify customer responsibilities.
Expected Answers:
- IAM configuration
- Operating system patching
- Security Group configuration
Troubleshooting
Case 1: Resources Cannot Be Found
Cause
Wrong Region selected.
Fix
Verify the Region selector.
Case 2: Access Denied Errors
Cause
IAM policy lacks required permissions.
Fix
Review attached policies and permissions.
Case 3: User Cannot Sign In
Cause
Console access was not enabled during user creation.
Fix
Edit the user settings and enable console access.
Case 4: Using Root Account for Everything
Cause
Common beginner mistake.
Fix
Create IAM users for daily activities.
Enable MFA on the root account.
Case 5: Assuming AWS Configures Security Automatically
Cause
Misunderstanding Shared Responsibility.
Fix
Review which responsibilities belong to AWS and which belong to customers.
Security Considerations
Follow these security practices:
- Enable MFA on privileged accounts.
- Avoid using the root user for routine work.
- Apply least privilege permissions.
- Remove unused users.
- Review permissions regularly.
- Use IAM roles where possible.
- Protect access keys.
- Monitor account activity.
Cost and Free Tier Awareness
This exercise primarily uses informational console activities.
However, always remember:
- AWS pricing changes over time.
- Free Tier eligibility changes.
- Different Regions may have different pricing.
Before launching resources:
- Review AWS Pricing
- Review AWS Free Tier documentation
- Confirm current pricing directly in AWS documentation
Never assume a resource is free because a tutorial says so.
Cleanup
Delete Test IAM User
Navigate to:
IAM
→ Users
→ student-user
→ Delete
Verify Deletion
Confirm:
User no longer exists
Delete Additional Resources
If you launched resources while experimenting, remove:
- EC2 Instances
- EBS Volumes
- Elastic IP Addresses
- Load Balancers
Review each service manually to ensure cleanup is complete.
Intermediate Extension Challenge
Create:
Developers Group
Attach:
ReadOnlyAccess
Then:
- Create multiple users.
- Add users to the group.
- Test permissions.
Skills Developed
- IAM Groups
- Permission Management
- Least Privilege at Scale
Advanced / Professional Discussion
At the professional architect level, these concepts become organizational design decisions rather than basic AWS features.
Multi-Account Strategy
Many organizations separate:
Development
Testing
Production
into different AWS accounts.
Benefits:
- Better security boundaries
- Easier auditing
- Reduced operational risk
Multi-Region Architectures
Mission-critical applications often deploy across multiple Regions.
Benefits:
- Disaster recovery
- Geographic redundancy
- Improved global user experience
Advanced IAM
Large organizations frequently adopt:
- IAM Roles
- Federation
- AWS IAM Identity Center
- Attribute-Based Access Control (ABAC)
to manage access at scale.
Compliance Considerations
Region selection may be driven by:
- Data residency requirements
- Regulatory obligations
- Customer contracts
- Disaster recovery requirements
These considerations commonly appear in AWS architecture certification exams.
References
AWS IAM Documentation: https://docs.aws.amazon.com/iam/
Getting Started with IAM: https://docs.aws.amazon.com/IAM/latest/UserGuide/getting-started.html
AWS Regions and Availability Zones: https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions-availability-zones.html
AWS Regions Documentation: https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions.html
AWS Shared Responsibility Model: https://aws.amazon.com/compliance/shared-responsibility-model/





Top comments (0)