Category: Cloud Accounts & External Services
Overview
Some EC-Council training labs require learners to use an Amazon Web Services (AWS) account to complete hands-on exercises.
These labs are designed to provide practical experience using AWS services in a real cloud environment. Working directly with AWS helps learners develop practical skills using the same tools and interfaces found in enterprise environments.
This article explains what to expect when using an AWS account in the lab environment and provides guidance for completing AWS-based lab activities.
Why is an AWS account required?
Certain cybersecurity concepts require interaction with live AWS services rather than a simulated environment.
Depending on the course, you may work with services such as:
- Identity and Access Management (IAM)
- Amazon EC2
- Amazon S3
- AWS Key Management Service (KMS)
- Virtual Private Cloud (VPC)
- Security Groups
- Network Access Control Lists (NACLs)
- Logging and monitoring services
The AWS services used vary by course and lab module.
Will I need to create an AWS account?
Some EC-Council training labs require learners to create or use an AWS account.
Your course guide will provide the specific account requirements for your lab module.
If account creation is required, follow the instructions provided in the lab guide.
Why do some labs require the AWS root account?
Some lab modules require signing in with the AWS root account to ensure all required AWS services and administrative functions are available during the exercises.
Although AWS generally recommends using IAM users for routine administrative tasks, certain training activities require permissions or functionality that may not be available to IAM users, even when administrative permissions have been assigned.
If your lab guide instructs you to use the AWS root account, follow the documented workflow to complete the exercises successfully.
Will I incur AWS charges?
AWS may charge for resources created outside of the AWS Free Tier or for services that are not covered by free usage limits.
If your lab creates AWS resources that could incur charges, the course guide will typically provide cleanup instructions for removing those resources after completing the exercises.
To help avoid unnecessary charges:
- Follow all cleanup instructions in the lab guide.
- Delete AWS resources when instructed.
- Review your AWS account after completing the lab to confirm resources are no longer running.
Best Practices
When using AWS during a lab:
- Follow the instructions provided in the course guide.
- Create only the resources required for the lab exercises.
- Remove cloud resources when instructed.
- Review your AWS account after completing the lab to ensure resources have been deleted.
- Follow AWS security recommendations for protecting your account.
Privacy and Security
Some learners have questions about entering AWS credentials while working in the lab environment.
For information about:
- instructor observation,
- remote assistance,
- password masking,
- session privacy,
- and how lab data is handled,
see Privacy and Security When Using External Accounts in the Lab Environment.
Frequently Asked Questions
Can I use an existing AWS account?
Follow the instructions provided in your course guide. Some courses allow an existing account, while others may recommend creating a new account specifically for training purposes.
Can I use an AWS account provided by my employer?
Unless your organization has approved its use, a personal AWS account is generally recommended. Organizational security policies or permission restrictions may prevent some lab activities from functioning as expected.
Why doesn't EC-Council provide AWS accounts?
Course requirements vary. Some EC-Council training labs are designed to provide learners with practical experience managing resources within their own AWS environment.
The required workflow for your course will always be described in the lab guide.
Comments