Skip to content

Runbook 02 Enterprise Network Protection Assessment

Module: 08 – Network Protection

Enterprise Lab: 02

Estimated Time: 4–5 Hours

Difficulty: ⭐⭐⭐⭐☆

Estimated Cost: Free Tier (No additional AWS charges)


As a Cloud Security Engineer at CloudNova Technologies, you have been assigned to perform a comprehensive assessment of the organization’s AWS network protection controls.

By completing this runbook, you will learn how to:

  • Review AWS Network Firewall
  • Review Firewall Policies
  • Review Stateless Rule Groups
  • Review Stateful Rule Groups
  • Review AWS WAF
  • Review Web ACLs
  • Review AWS Managed Rule Groups
  • Review Custom WAF Rules
  • Review AWS Shield
  • Review Amazon Route 53 security
  • Review VPC Endpoints
  • Review AWS PrivateLink
  • Review Network Firewall Logging
  • Identify network security gaps
  • Recommend remediation actions
  • Produce an executive network protection assessment report

CloudNova Technologies hosts several customer-facing applications, APIs, and internal business systems on AWS.

Over the years, different engineering teams have independently implemented firewalls, WAF rules, endpoint policies, and network protections.

Following a recent penetration test, management is concerned that network security controls may not be consistently configured across environments.

The Chief Information Security Officer (CISO) has requested a complete review of the organization’s network protection architecture before the next security audit.

Your responsibility is to assess the environment, identify weaknesses, prioritise risks, and recommend improvements.


Complete:

  • Enterprise Runbook 01 — Build Enterprise AWS Network Protection

Required:

  • AWS Account
  • Administrator Access
  • AWS CLI Installed
  • Visual Studio Code

CloudNova AWS Environment
Internet
AWS Shield
Amazon Route 53
AWS WAF
Application Load Balancer
AWS Network Firewall
Production VPC
├── Public Subnets
├── Private Application Subnets
├── Private Database Subnets
Supporting Services
├── VPC Endpoints
├── AWS PrivateLink
├── CloudWatch Logs
├── AWS Config
└── Security Hub

Your objective is to determine whether the environment follows AWS and enterprise network security best practices.


Navigate to:

AWS Console
AWS Network Firewall
Firewalls

Review:

  • Firewall Status
  • Deployment Model
  • Firewall Endpoints
  • Availability Zones
  • Associated VPC

Questions:

  • Is the firewall deployed in all required Availability Zones?
  • Is the firewall protecting all production traffic?
  • Are firewall endpoints healthy?

Terminal window
aws network-firewall list-firewalls

Navigate to:

AWS Network Firewall
Firewall Policies

Review:

  • Stateless Default Actions
  • Stateful Default Actions
  • Rule Group Associations
  • Policy Order

Questions:

  • Are default actions secure?
  • Are rule groups applied correctly?
  • Are policies consistently implemented?

Terminal window
aws network-firewall list-firewall-policies

Review:

  • Allowed Ports
  • Allowed Protocols
  • Rule Priority
  • Default Actions

Questions:

  • Are unnecessary ports allowed?
  • Are rule priorities configured correctly?

Terminal window
aws network-firewall list-rule-groups

Review:

  • Domain Blocking
  • Malicious IP Blocking
  • Outbound Restrictions
  • Database Access Rules
  • Administrative Access Rules

Questions:

  • Are outbound connections restricted?
  • Are known malicious destinations blocked?

Navigate to:

AWS WAF
Web ACLs

Review:

  • Web ACL Associations
  • Protected Resources
  • Logging
  • Rule Priorities

Questions:

  • Are all Internet-facing applications protected?
  • Is logging enabled?

Terminal window
aws wafv2 list-web-acls \
--scope REGIONAL

Verify that the following are enabled:

  • AWS Core Rule Set
  • Known Bad Inputs
  • SQL Injection
  • Linux Rule Set
  • Anonymous IP List
  • Amazon IP Reputation List

Questions:

  • Are all managed protections enabled?
  • Have unnecessary exclusions been configured?

Review:

  • Rate Limiting
  • Geo Restrictions
  • IP Allow Lists
  • IP Block Lists
  • User-Agent Filtering
  • URI Restrictions

Questions:

  • Are rate limits appropriate?
  • Are blocked countries aligned with business requirements?

Navigate to:

AWS Shield

Review:

  • Shield Standard
  • Protected Resources
  • DDoS Events
  • Health Dashboard

Questions:

  • Are all public resources protected?
  • Have any DDoS events occurred?

Navigate to:

Amazon Route 53

Review:

  • Hosted Zones
  • DNSSEC Configuration
  • Health Checks
  • Routing Policies

Questions:

  • Is DNSSEC enabled where required?
  • Are health checks configured?
  • Are failover policies implemented?

Terminal window
aws route53 list-hosted-zones

Navigate to:

VPC
Endpoints

Review:

  • Gateway Endpoints
  • Interface Endpoints
  • Endpoint Policies
  • Private DNS

Questions:

  • Are AWS services accessed privately?
  • Are endpoint policies restrictive?

Terminal window
aws ec2 describe-vpc-endpoints

Review:

  • Endpoint Services
  • Interface Endpoints
  • Service Consumers
  • Security Groups

Questions:

  • Are private services exposed securely?
  • Is unnecessary Internet traffic eliminated?

Review:

  • Network Firewall Logs
  • AWS WAF Logs
  • CloudWatch Logs
  • AWS Config
  • Security Hub Findings

Questions:

  • Are blocked requests logged?
  • Are firewall events retained?
  • Are alerts investigated?

Document findings.

Finding Risk Severity Recommendation
AWS WAF not enabled High Critical Deploy Web ACL for all public applications
SQL Injection rule disabled High Critical Enable AWS Managed SQLi protection
No rate limiting Medium High Configure rate-based rules
Network Firewall not inspecting outbound traffic High High Update firewall policy
Missing VPC Endpoints Medium Medium Deploy Gateway and Interface Endpoints
DNSSEC not configured Medium High Enable DNSSEC for hosted zones
WAF logging disabled Medium High Enable logging to CloudWatch or S3

  • Enable missing WAF protections
  • Enable logging
  • Apply firewall policies
  • Configure rate limiting
  • Restrict public access

  • Review all firewall policies
  • Standardise WAF configurations
  • Deploy missing VPC Endpoints
  • Enable DNSSEC
  • Review endpoint policies

  • Enterprise Firewall Governance
  • Centralised WAF Management
  • Automated Rule Deployment
  • Threat Intelligence Integration
  • Continuous Network Security Assessments

Verify:

  • AWS Network Firewall Reviewed
  • Firewall Policies Reviewed
  • Stateless Rules Reviewed
  • Stateful Rules Reviewed
  • AWS WAF Reviewed
  • Managed Rule Groups Reviewed
  • Custom Rules Reviewed
  • AWS Shield Reviewed
  • Route 53 Reviewed
  • VPC Endpoints Reviewed
  • AWS PrivateLink Reviewed
  • Logging Reviewed
  • Risks Documented
  • Remediation Plan Completed

CloudNova Technologies has experienced a coordinated attack against its public e-commerce platform.

Security monitoring identified:

  • Thousands of requests from suspicious IP addresses
  • SQL Injection attempts against the login page
  • Cross-Site Scripting (XSS) payloads
  • Excessive requests from a single IP address
  • DNS reconnaissance activity
  • Attempts to access internal AWS services through public endpoints
  • Firewall logs showing unexpected outbound traffic

Your task is to:

  • Review AWS WAF logs
  • Review Network Firewall logs
  • Review Route 53 health checks
  • Validate AWS Shield protections
  • Review VPC Endpoint configuration
  • Identify attack vectors
  • Determine the effectiveness of existing controls
  • Produce a remediation roadmap
  • Prepare an executive summary for the CISO

Capture screenshots of:

  • AWS Network Firewall
  • Firewall Policies
  • Rule Groups
  • AWS WAF
  • Web ACL
  • Managed Rule Groups
  • AWS Shield
  • Route 53
  • VPC Endpoints
  • AWS PrivateLink
  • Network Firewall Logs
  • WAF Logs

Submit:

  • Enterprise Network Protection Assessment Report
  • Risk Register
  • Remediation Roadmap
  • Updated Network Architecture
  • Executive Summary

This is primarily an assessment runbook.

Do NOT delete:

  • AWS Network Firewall
  • Firewall Policies
  • Rule Groups
  • AWS WAF
  • AWS Shield
  • Route 53 Hosted Zones
  • VPC Endpoints
  • AWS PrivateLink
  • CloudWatch Logs

Delete only:

  • Temporary test rules
  • Test Web ACLs
  • Experimental firewall policies
  • Temporary endpoint resources

  • AWS Network Firewall Reviewed
  • Firewall Policies Reviewed
  • Stateless Rules Reviewed
  • Stateful Rules Reviewed
  • AWS WAF Reviewed
  • Managed Rule Groups Reviewed
  • Custom Rules Reviewed
  • AWS Shield Reviewed
  • Route 53 Reviewed
  • VPC Endpoints Reviewed
  • AWS PrivateLink Reviewed
  • Logging Reviewed
  • Risks Documented
  • Remediation Plan Completed

What network protection weaknesses were identified?

Section titled “What network protection weaknesses were identified?”

How do AWS Network Firewall, AWS WAF, and AWS Shield provide defence in depth?

Section titled “How do AWS Network Firewall, AWS WAF, and AWS Shield provide defence in depth?”
Section titled “Why are VPC Endpoints and AWS PrivateLink important for reducing the attack surface?”

How do firewall logs and WAF logs support incident investigations?

Section titled “How do firewall logs and WAF logs support incident investigations?”

How would you improve the network protection architecture for a global enterprise deployment?

Section titled “How would you improve the network protection architecture for a global enterprise deployment?”

09 — Vulnerability & Compliance Management

In the next module, you will implement enterprise vulnerability management and continuous compliance monitoring using Amazon Inspector, AWS Config, AWS Security Hub, AWS Audit Manager, AWS Trusted Advisor, and AWS Systems Manager Patch Manager to identify vulnerabilities, maintain compliance, and strengthen the security posture of AWS workloads.