IAM
Who can log in, and what they can do
Root account use, MFA, unused access keys, and users or roles with far more permission than they need.
S3
Whether any storage is public
Public buckets, open bucket policies, missing encryption, and missing access logging.
CloudTrail
Whether activity is recorded
If something goes wrong, can you see who did what? Logging coverage, retention, and integrity.
Networking
What's reachable from the internet
Security group rules that expose SSH, remote desktop, or databases to the whole internet.