AWS Cloud Infrastructure Management Training Course
| Course code | SD-CC-003 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
AWS infrastructure teams must provision secure, reliable environments while controlling spend, responding to incidents and meeting internal governance requirements. Many organisations have AWS accounts that grew through individual projects rather than consistent operational design, leaving inconsistent IAM permissions, manually created resources, weak tagging, limited monitoring and recovery procedures that have never been tested. This course prepares participants to manage AWS infrastructure systematically rather than treating the AWS Management Console as a collection of separate services.
Participants learn how to design and operate a multi-tier AWS workload using core services including IAM, Amazon VPC, EC2, Elastic Load Balancing, Auto Scaling, Amazon S3, RDS, CloudWatch and AWS CloudTrail. They build role-based access controls, configure network segmentation, select compute and storage options, implement infrastructure as code with AWS CloudFormation, establish monitoring and alerting, and apply cost allocation tags and AWS Budgets. The course also uses the AWS Well-Architected Framework to assess operational excellence, security, reliability, performance efficiency and cost optimisation.
Delivery combines instructor-led demonstrations with guided AWS console and AWS CLI labs in a controlled training environment. Participants work through a running case study: deploying and operating a customer-facing application across development and production environments. By the end of the week, each participant leaves with an AWS infrastructure operations pack containing a reference architecture, CloudFormation template, IAM access model, monitoring dashboard specification, backup and recovery runbook, and a prioritised Well-Architected improvement plan.
The programme suits technical professionals who need practical responsibility for AWS environments, as well as managers who need their teams to introduce repeatable controls before cloud usage expands further.
Course objectives
By the end of this course, participants will be able to:
- Configure IAM users, groups, roles, policies and MFA controls for least-privilege AWS access
- Design an Amazon VPC with public and private subnets, route tables, security groups and network ACLs
- Provision repeatable infrastructure using AWS CloudFormation templates and parameter sets
- Deploy resilient EC2 workloads using Application Load Balancers, Auto Scaling groups and Amazon RDS
- Implement Amazon CloudWatch metrics, alarms, logs and dashboards for infrastructure monitoring
- Create backup, restore and incident-response runbooks for Amazon EBS, S3 and RDS workloads
- Apply AWS tagging, Cost Explorer and AWS Budgets to allocate and control cloud expenditure
- Produce a prioritised AWS Well-Architected review and infrastructure operations improvement plan
Benefits of attending
For you
- Build evidence of practical AWS operations capability through a completed infrastructure operations pack
- Gain confidence explaining IAM, VPC, monitoring and resilience decisions to technical teams and managers
- Develop hands-on CloudFormation skills that support cloud engineer and DevOps role progression
- Learn to diagnose common AWS operational issues using CloudWatch, CloudTrail and console evidence
- Apply the AWS Well-Architected Framework when proposing improvements to existing cloud workloads
For your organisation
- Reduce configuration drift by equipping staff to provision standard environments with CloudFormation
- Lower security exposure through more consistent least-privilege IAM, MFA and network segmentation practices
- Improve service availability with documented monitoring, alerting, backup and recovery procedures
- Increase cloud cost accountability through tagging conventions, Cost Explorer analysis and AWS Budgets
- Create a common AWS operating vocabulary for infrastructure, development, security and management teams
Target competencies
Who should attend
- Cloud Engineers — who build and operate AWS environments for internal or customer-facing services
- Systems Administrators — who are moving server, storage and network administration responsibilities into AWS
- Infrastructure Engineers — who need repeatable methods for provisioning, monitoring and securing cloud resources
- DevOps Engineers — who require stronger AWS foundations for automated deployment and operational reliability
- IT Operations Analysts — who monitor cloud services, investigate alerts and maintain service runbooks
- Technical IT Managers — who oversee AWS adoption and need practical governance, resilience and cost controls
Requirements and prerequisites
Participants should be comfortable using a web browser, navigating folders and files, and working with basic command-line concepts such as running a command and reading output. Familiarity with servers, IP addresses, DNS, firewalls, storage and relational databases is helpful because these concepts are applied in AWS labs. Some exposure to AWS, Linux or PowerShell is useful but not essential. This is a foundation-to-intermediate course: complete beginners can attend, but should expect a technically demanding week and should review basic networking and operating-system terminology beforehand. No programming experience, prior AWS certification or existing AWS account is required.
Training methodology
The instructor introduces each AWS operational decision through short technical briefings, live configuration demonstrations and structured discussion of trade-offs. Participants then complete guided labs using the AWS Management Console, AWS CLI and CloudFormation, progressing from access control and networking to workload deployment, monitoring and recovery. Small groups review a flawed application environment against Well-Architected principles and defend their remediation priorities. The final session converts lab outputs into an individual application plan for a participant's own AWS estate, including owners, controls and immediate next actions.
Course outline
Day 1: AWS foundations, governance and identity
- AWS global infrastructure, Regions, Availability Zones and edge locations
- AWS account structure, organisational units and environment separation
- IAM users, groups, roles and policy evaluation logic
- Multi-factor authentication and root user protection
- Identity-based policies, resource-based policies and permission boundaries
- AWS resource tagging strategy and tag enforcement concepts
- AWS Well-Architected Framework pillars and review process
Workshop: Participants create an IAM access model and tagging standard for a fictional business unit, documenting roles, permissions and ownership rules.
Day 2: Networking and secure workload connectivity
- Amazon VPC address planning with CIDR blocks
- Public and private subnet design across Availability Zones
- Route tables, internet gateways and NAT gateways
- Security groups and network ACLs for layered traffic control
- Elastic IP addresses, VPC endpoints and private AWS service access
- DNS resolution and routing with Amazon Route 53
- VPC Flow Logs for network visibility and troubleshooting
Workshop: Participants build a two-tier VPC topology with segmented subnets, routing, security groups and a documented traffic-flow diagram.
Day 3: Compute, storage and resilient application services
- Amazon EC2 instance selection, AMIs, key pairs and user data
- Amazon EBS volume types, snapshots and encryption settings
- Amazon S3 storage classes, lifecycle rules, versioning and access controls
- Application Load Balancer listeners, target groups and health checks
- EC2 Auto Scaling groups and scaling policy design
- Amazon RDS deployment options, backups, Multi-AZ and maintenance windows
- High-availability design patterns across Availability Zones
Workshop: Participants deploy a resilient web application stack with EC2, an Application Load Balancer, Auto Scaling and an RDS database design.
Day 4: Automation, observability and operational response
- AWS CloudFormation stacks, templates, parameters and outputs
- CloudFormation change sets, drift detection and stack update controls
- AWS CLI profiles, credentials and repeatable resource commands
- Amazon CloudWatch metrics, namespaces and custom dashboard design
- CloudWatch Logs, metric filters and alarm configuration
- AWS CloudTrail event history and API activity investigation
- Incident triage, escalation paths and operational runbook structure
Workshop: Participants deploy a standard environment from a CloudFormation template and create a CloudWatch dashboard, alarms and first-response runbook.
Day 5: Cost control, resilience and infrastructure improvement
- AWS Cost Explorer analysis and cost allocation tag reporting
- AWS Budgets alerts and budget action design
- Rightsizing EC2 and EBS resources using utilisation evidence
- AWS Backup plans, retention policies and recovery point objectives
- RDS restore procedures and S3 recovery options
- Well-Architected workload review findings and remediation prioritisation
- AWS operations governance, change control and ownership matrices
Workshop: Participants complete a Well-Architected review and present an infrastructure operations pack with cost, resilience, monitoring and governance actions.
Tools & standards covered
AWS Management Console, AWS CLI, AWS CloudFormation, AWS Well-Architected Framework
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Dubai · USD 4,500 -
12 – 16 Oct 2026Book
Dar es Salaam · USD 3,500 -
12 – 16 Oct 2026Book
Mombasa · USD 3,200 -
02 – 06 Nov 2026Book
Cape Town · USD 4,200 -
02 – 06 Nov 2026Book
Kigali · USD 3,500 -
09 – 13 Nov 2026Book
Nairobi · USD 3,000 -
16 – 20 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
Cloud Security Controls for Cybersecurity Analysts Training Course
Cybersecurity analysts are increasingly expected to investigate alerts, validate cloud configurations, assess identity exposure and explain …
Microsoft Azure Administration Skills Training Course
Azure administrators are expected to provision services quickly while maintaining control over identity, spend, security, resilience and ope…
Pulumi Cloud Infrastructure Automation Training Course
Cloud teams often inherit manually created environments, inconsistent naming, undocumented access settings and deployment scripts that canno…
Cloud Computing for Healthcare IT Teams Training Course
Healthcare IT teams are under pressure to modernise clinical, administrative and data platforms without exposing protected health informatio…