> For the complete documentation index, see [llms.txt](https://awsinpractice.itassist.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://awsinpractice.itassist.com/study-group/aws-certified-solutions-architect-associate/domain-1-design-secure-architectures/task-statement-1.2-design-secure-workloads-and-applications/hands-on-labs-and-final-challenge.md).

# Hands-on Labs & Final Challenge

#### **Scenario:**

SecureCart’s security team must **review and harden AWS security configurations** across **application workloads, network security, and threat monitoring**.

#### **Final Study Group Challenges:**

✅ **Scenario 1:** Secure Application Credentials Using AWS Secrets Manager\
✅ **Scenario 2:** Implement Network Segmentation for a Multi-Tier Application\
✅ **Scenario 3:** Protect a Web Application with AWS WAF & Shield\
✅ **Scenario 4:** Secure Hybrid Cloud Communication with AWS Direct Connect\
✅ **Scenario 5:** Detect Suspicious Activities Using Amazon GuardDuty

🔹 **Outcome:** Learners **demonstrate real-world AWS security skills** in **application & workload protection**.

***

### **📚 Recommended Study Resources**

✅ **AWS Well-Architected Framework – Security Pillar**\
✅ **AWS VPC Best Practices for Secure Networking**\
✅ **AWS Security Hub & AWS Config for Security Compliance**\
✅ **AWS Shield & WAF for Application Protection**\
✅ **AWS Secrets Manager & Parameter Store for Credential Security**
