Runbook 02 Enterprise Network Protection Assessment
Module: 08 – Network Protection
Enterprise Lab: 02
Estimated Time: 4–5 Hours
Difficulty: ⭐⭐⭐⭐☆
Estimated Cost: Free Tier (No additional AWS charges)
🎯 Objective
Section titled “🎯 Objective”As a Cloud Security Engineer at CloudNova Technologies, you have been assigned to perform a comprehensive assessment of the organization’s AWS network protection controls.
By completing this runbook, you will learn how to:
- Review AWS Network Firewall
- Review Firewall Policies
- Review Stateless Rule Groups
- Review Stateful Rule Groups
- Review AWS WAF
- Review Web ACLs
- Review AWS Managed Rule Groups
- Review Custom WAF Rules
- Review AWS Shield
- Review Amazon Route 53 security
- Review VPC Endpoints
- Review AWS PrivateLink
- Review Network Firewall Logging
- Identify network security gaps
- Recommend remediation actions
- Produce an executive network protection assessment report
🏢 Business Scenario
Section titled “🏢 Business Scenario”CloudNova Technologies hosts several customer-facing applications, APIs, and internal business systems on AWS.
Over the years, different engineering teams have independently implemented firewalls, WAF rules, endpoint policies, and network protections.
Following a recent penetration test, management is concerned that network security controls may not be consistently configured across environments.
The Chief Information Security Officer (CISO) has requested a complete review of the organization’s network protection architecture before the next security audit.
Your responsibility is to assess the environment, identify weaknesses, prioritise risks, and recommend improvements.
📋 Prerequisites
Section titled “📋 Prerequisites”Complete:
- Enterprise Runbook 01 — Build Enterprise AWS Network Protection
Required:
- AWS Account
- Administrator Access
- AWS CLI Installed
- Visual Studio Code
🏗 Existing Enterprise Environment
Section titled “🏗 Existing Enterprise Environment”CloudNova AWS Environment
Internet │AWS Shield │Amazon Route 53 │AWS WAF │Application Load Balancer │AWS Network Firewall │Production VPC │├── Public Subnets├── Private Application Subnets├── Private Database Subnets│Supporting Services
├── VPC Endpoints├── AWS PrivateLink├── CloudWatch Logs├── AWS Config└── Security HubYour objective is to determine whether the environment follows AWS and enterprise network security best practices.
Step 1 — Review AWS Network Firewall
Section titled “Step 1 — Review AWS Network Firewall”Navigate to:
AWS Console
↓
AWS Network Firewall
↓
FirewallsReview:
- Firewall Status
- Deployment Model
- Firewall Endpoints
- Availability Zones
- Associated VPC
Questions:
- Is the firewall deployed in all required Availability Zones?
- Is the firewall protecting all production traffic?
- Are firewall endpoints healthy?
AWS CLI
Section titled “AWS CLI”aws network-firewall list-firewallsStep 2 — Review Firewall Policies
Section titled “Step 2 — Review Firewall Policies”Navigate to:
AWS Network Firewall
↓
Firewall PoliciesReview:
- Stateless Default Actions
- Stateful Default Actions
- Rule Group Associations
- Policy Order
Questions:
- Are default actions secure?
- Are rule groups applied correctly?
- Are policies consistently implemented?
AWS CLI
Section titled “AWS CLI”aws network-firewall list-firewall-policiesStep 3 — Review Stateless Rule Groups
Section titled “Step 3 — Review Stateless Rule Groups”Review:
- Allowed Ports
- Allowed Protocols
- Rule Priority
- Default Actions
Questions:
- Are unnecessary ports allowed?
- Are rule priorities configured correctly?
AWS CLI
Section titled “AWS CLI”aws network-firewall list-rule-groupsStep 4 — Review Stateful Rule Groups
Section titled “Step 4 — Review Stateful Rule Groups”Review:
- Domain Blocking
- Malicious IP Blocking
- Outbound Restrictions
- Database Access Rules
- Administrative Access Rules
Questions:
- Are outbound connections restricted?
- Are known malicious destinations blocked?
Step 5 — Review AWS WAF
Section titled “Step 5 — Review AWS WAF”Navigate to:
AWS WAF
↓
Web ACLsReview:
- Web ACL Associations
- Protected Resources
- Logging
- Rule Priorities
Questions:
- Are all Internet-facing applications protected?
- Is logging enabled?
AWS CLI
Section titled “AWS CLI”aws wafv2 list-web-acls \--scope REGIONALStep 6 — Review Managed Rule Groups
Section titled “Step 6 — Review Managed Rule Groups”Verify that the following are enabled:
- AWS Core Rule Set
- Known Bad Inputs
- SQL Injection
- Linux Rule Set
- Anonymous IP List
- Amazon IP Reputation List
Questions:
- Are all managed protections enabled?
- Have unnecessary exclusions been configured?
Step 7 — Review Custom WAF Rules
Section titled “Step 7 — Review Custom WAF Rules”Review:
- Rate Limiting
- Geo Restrictions
- IP Allow Lists
- IP Block Lists
- User-Agent Filtering
- URI Restrictions
Questions:
- Are rate limits appropriate?
- Are blocked countries aligned with business requirements?
Step 8 — Review AWS Shield
Section titled “Step 8 — Review AWS Shield”Navigate to:
AWS ShieldReview:
- Shield Standard
- Protected Resources
- DDoS Events
- Health Dashboard
Questions:
- Are all public resources protected?
- Have any DDoS events occurred?
Step 9 — Review Route 53 Security
Section titled “Step 9 — Review Route 53 Security”Navigate to:
Amazon Route 53Review:
- Hosted Zones
- DNSSEC Configuration
- Health Checks
- Routing Policies
Questions:
- Is DNSSEC enabled where required?
- Are health checks configured?
- Are failover policies implemented?
AWS CLI
Section titled “AWS CLI”aws route53 list-hosted-zonesStep 10 — Review VPC Endpoints
Section titled “Step 10 — Review VPC Endpoints”Navigate to:
VPC
↓
EndpointsReview:
- Gateway Endpoints
- Interface Endpoints
- Endpoint Policies
- Private DNS
Questions:
- Are AWS services accessed privately?
- Are endpoint policies restrictive?
AWS CLI
Section titled “AWS CLI”aws ec2 describe-vpc-endpointsStep 11 — Review AWS PrivateLink
Section titled “Step 11 — Review AWS PrivateLink”Review:
- Endpoint Services
- Interface Endpoints
- Service Consumers
- Security Groups
Questions:
- Are private services exposed securely?
- Is unnecessary Internet traffic eliminated?
Step 12 — Review Logging & Monitoring
Section titled “Step 12 — Review Logging & Monitoring”Review:
- Network Firewall Logs
- AWS WAF Logs
- CloudWatch Logs
- AWS Config
- Security Hub Findings
Questions:
- Are blocked requests logged?
- Are firewall events retained?
- Are alerts investigated?
Step 13 — Identify Security Findings
Section titled “Step 13 — Identify Security Findings”Document findings.
| Finding | Risk | Severity | Recommendation |
|---|---|---|---|
| AWS WAF not enabled | High | Critical | Deploy Web ACL for all public applications |
| SQL Injection rule disabled | High | Critical | Enable AWS Managed SQLi protection |
| No rate limiting | Medium | High | Configure rate-based rules |
| Network Firewall not inspecting outbound traffic | High | High | Update firewall policy |
| Missing VPC Endpoints | Medium | Medium | Deploy Gateway and Interface Endpoints |
| DNSSEC not configured | Medium | High | Enable DNSSEC for hosted zones |
| WAF logging disabled | Medium | High | Enable logging to CloudWatch or S3 |
Step 14 — Prepare Remediation Plan
Section titled “Step 14 — Prepare Remediation Plan”Immediate (Within 24 Hours)
Section titled “Immediate (Within 24 Hours)”- Enable missing WAF protections
- Enable logging
- Apply firewall policies
- Configure rate limiting
- Restrict public access
Short Term (30 Days)
Section titled “Short Term (30 Days)”- Review all firewall policies
- Standardise WAF configurations
- Deploy missing VPC Endpoints
- Enable DNSSEC
- Review endpoint policies
Long Term (90 Days)
Section titled “Long Term (90 Days)”- Enterprise Firewall Governance
- Centralised WAF Management
- Automated Rule Deployment
- Threat Intelligence Integration
- Continuous Network Security Assessments
Step 15 — Validation
Section titled “Step 15 — Validation”Verify:
- AWS Network Firewall Reviewed
- Firewall Policies Reviewed
- Stateless Rules Reviewed
- Stateful Rules Reviewed
- AWS WAF Reviewed
- Managed Rule Groups Reviewed
- Custom Rules Reviewed
- AWS Shield Reviewed
- Route 53 Reviewed
- VPC Endpoints Reviewed
- AWS PrivateLink Reviewed
- Logging Reviewed
- Risks Documented
- Remediation Plan Completed
🧪 Enterprise Challenge
Section titled “🧪 Enterprise Challenge”CloudNova Technologies has experienced a coordinated attack against its public e-commerce platform.
Security monitoring identified:
- Thousands of requests from suspicious IP addresses
- SQL Injection attempts against the login page
- Cross-Site Scripting (XSS) payloads
- Excessive requests from a single IP address
- DNS reconnaissance activity
- Attempts to access internal AWS services through public endpoints
- Firewall logs showing unexpected outbound traffic
Your task is to:
- Review AWS WAF logs
- Review Network Firewall logs
- Review Route 53 health checks
- Validate AWS Shield protections
- Review VPC Endpoint configuration
- Identify attack vectors
- Determine the effectiveness of existing controls
- Produce a remediation roadmap
- Prepare an executive summary for the CISO
📄 Deliverables
Section titled “📄 Deliverables”Capture screenshots of:
- AWS Network Firewall
- Firewall Policies
- Rule Groups
- AWS WAF
- Web ACL
- Managed Rule Groups
- AWS Shield
- Route 53
- VPC Endpoints
- AWS PrivateLink
- Network Firewall Logs
- WAF Logs
Submit:
- Enterprise Network Protection Assessment Report
- Risk Register
- Remediation Roadmap
- Updated Network Architecture
- Executive Summary
🧹 Cleanup
Section titled “🧹 Cleanup”This is primarily an assessment runbook.
Do NOT delete:
- AWS Network Firewall
- Firewall Policies
- Rule Groups
- AWS WAF
- AWS Shield
- Route 53 Hosted Zones
- VPC Endpoints
- AWS PrivateLink
- CloudWatch Logs
Delete only:
- Temporary test rules
- Test Web ACLs
- Experimental firewall policies
- Temporary endpoint resources
✅ Runbook Checklist
Section titled “✅ Runbook Checklist”- AWS Network Firewall Reviewed
- Firewall Policies Reviewed
- Stateless Rules Reviewed
- Stateful Rules Reviewed
- AWS WAF Reviewed
- Managed Rule Groups Reviewed
- Custom Rules Reviewed
- AWS Shield Reviewed
- Route 53 Reviewed
- VPC Endpoints Reviewed
- AWS PrivateLink Reviewed
- Logging Reviewed
- Risks Documented
- Remediation Plan Completed
💡 Lessons Learned
Section titled “💡 Lessons Learned”What network protection weaknesses were identified?
Section titled “What network protection weaknesses were identified?”How do AWS Network Firewall, AWS WAF, and AWS Shield provide defence in depth?
Section titled “How do AWS Network Firewall, AWS WAF, and AWS Shield provide defence in depth?”Why are VPC Endpoints and AWS PrivateLink important for reducing the attack surface?
Section titled “Why are VPC Endpoints and AWS PrivateLink important for reducing the attack surface?”How do firewall logs and WAF logs support incident investigations?
Section titled “How do firewall logs and WAF logs support incident investigations?”How would you improve the network protection architecture for a global enterprise deployment?
Section titled “How would you improve the network protection architecture for a global enterprise deployment?”🚀 Next Module
Section titled “🚀 Next Module”09 — Vulnerability & Compliance Management
In the next module, you will implement enterprise vulnerability management and continuous compliance monitoring using Amazon Inspector, AWS Config, AWS Security Hub, AWS Audit Manager, AWS Trusted Advisor, and AWS Systems Manager Patch Manager to identify vulnerabilities, maintain compliance, and strengthen the security posture of AWS workloads.