Design secure architectures — 30%
IAM users, roles, and policies and when each is the right answer; federated access; VPC design, security groups, and network ACLs; encryption at rest and in transit; secrets handling; and the difference between what is secure and what merely looks it on a diagram.