AWS Certified SysOps Administrator – Associate flashcards
146 free flashcards. Tap a card to flip it.
SQS FIFO Queues & Message Group ID
Flip cardAmazon SQS FIFO (First-In, First-Out) queues guarantee processing of messages in the exact order they are sent and exactly once. A Message Group ID ensures that messages with the same group ID are processed in order, even if there are multiple consumers.
- Guarantees message ordering and exactly-once processing.
- Supports message group IDs for ordered processing of related messages.
- Throughput is lower than Standard queues (up to 3,000 messages/second with batching).
- Used for critical applications where order and uniqueness are paramount.
Memory trick: FIFO for order, Group ID for the flow, Content Dedupe for no repeat show!
VPC Gateway Endpoint for S3
Flip cardA VPC endpoint that allows private connectivity from instances in your VPC to Amazon S3, routing traffic through the AWS network instead of the internet or a NAT Gateway.
- Eliminates NAT Gateway data processing charges for S3 traffic.
- Enhances security by keeping traffic within the AWS network.
- Gateway endpoints are specifically for S3 and DynamoDB.
- Configured via route tables to direct S3 traffic to the endpoint.
Memory trick: NAT Gateway costs? VPC Endpoint for S3 is the boss!
Default EBS Encryption
Flip cardA regional setting that automatically encrypts all newly created EBS volumes and snapshot copies in that AWS Region, using a default KMS key or a specified custom KMS key.
- Applies to all new volumes and snapshot copies.
- Uses AWS managed key or customer managed key (CMK).
- Simplifies compliance with encryption-at-rest requirements.
- Does not affect existing unencrypted volumes.
Memory trick: Default encryption: Set it and forget it, for new volumes!
Amazon RDS Read Replicas
Flip cardAsynchronous copies of a primary Amazon RDS database instance, used to offload read traffic, improve database availability, and serve as disaster recovery targets.
- Enhance read scalability and performance.
- Can be created within the same region or cross-region.
- Do not automatically fail over to become the primary instance.
- Requires application to direct read queries to the replica endpoint.
Memory trick: Reads are slow? Replicas help them grow!
S3 Versioning & Object Lock
Flip cardS3 Versioning retains multiple versions of an object, allowing recovery from accidental deletion or modification. S3 Object Lock prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely.
- Versioning is crucial for point-in-time recovery.
- Object Lock has two modes: Governance (most users can't delete, root can) and Compliance (no one, not even root, can delete).
- Together, they provide robust data protection and immutability.
Memory trick: Versioning saves your history, Object Lock guards your treasure.
Global Accelerator for Data Residency
Flip cardAWS Global Accelerator, combined with regional deployments, can route user traffic to the nearest healthy regional endpoint where data is stored locally, satisfying data residency requirements while providing a global application footprint.
- Provides static IP addresses and intelligent routing for global performance.
- Allows data to remain within specific geographic boundaries.
- Requires separate, independent deployments in each required region.
- Addresses both global user experience and data residency.
Memory trick: Global Accelerator routes your requests, local data residency for your guests!
S3 Performance Optimization (Prefixes)
Flip cardAmazon S3 automatically scales request rates based on object prefixes. To avoid '503 Slow Down' errors during high demand, it's crucial to design object keys with sufficient randomness in their prefixes to distribute I/O requests across S3's underlying partitions.
- S3 performance scales with the number of prefixes.
- Using randomized prefixes (e.g., UUID, hash) helps distribute I/O.
- Avoid sequential naming (e.g., timestamps) for high-volume writes to the same prefix.
- S3 can handle thousands of requests per second per prefix.
Memory trick: 503 Slow Down? Randomize prefixes, speed up your S3 town!
Pilot Light DR Strategy
Flip cardA disaster recovery strategy where a minimal operational version of an application is always running in a DR region, ready to be scaled up quickly in case of a disaster.
- Core services (e.g., database) are replicated and running.
- Compute resources (e.g., EC2) are scaled down or off.
- Offers better RTO/RPO than Backup and Restore, but less than Warm Standby or Multi-site.
- Cost-effective compared to active-active solutions.
Memory trick: RTO/RPO: How fast, how fresh? Pilot Light's a cost-effective guess!
EBS Volume Types for Performance
Flip cardDifferent Amazon EBS volume types offer varying levels of performance (IOPS, throughput) and cost. gp2/gp3 are general purpose, while io1/io2 are Provisioned IOPS for high-performance, I/O-intensive workloads.
- gp2: General purpose, scales 3 IOPS/GiB, up to 16,000 IOPS, burstable.
- io1/io2: Provisioned IOPS, guarantees consistent performance, much higher IOPS (up to 64,000 for io2, 256,000 for io2 Block Express).
- io2 is the latest generation of Provisioned IOPS, offering higher durability and IOPS/GiB than io1.
- Choosing the right volume type is critical for performance-sensitive applications.
Memory trick: gp2's good, but for max speed, io2's the EBS type you need!
AWS Backup Vault Lock
Flip cardA feature of AWS Backup vaults that enforces an immutable policy on backups stored within the vault. It prevents changes to backup retention periods or deletion of backups for a specified duration.
- Can be configured in Governance mode (allows authorized users to change/delete) or Compliance mode (no one can change/delete).
- Compliance mode provides the strongest immutability for regulatory compliance or ransomware protection.
- Applied at the vault level, affecting all backups within it.
- Once locked in Compliance mode, the policy cannot be changed or deleted until the lock duration expires.
Memory trick: 7-year retention, 3-month lock in compliance, that's the backup dance!
S3 Glacier Flexible Retrieval
Flip cardS3 Glacier Flexible Retrieval is a low-cost Amazon S3 storage class designed for archiving data that is rarely accessed, with retrieval options ranging from minutes to hours.
- Extremely low storage costs.
- Retrieval options: Expedited (minutes), Standard (3-5 hours), Bulk (5-12 hours).
- Suitable for long-term archives with flexible retrieval time needs.
- Formerly known as S3 Glacier.
Memory trick: Instant for fast, Flexible for medium, Deep for slow and cheap.
RDS Cross-Region DR
Flip cardFor standard Amazon RDS, cross-region disaster recovery with low RTO/RPO is best achieved by combining Cross-Region Automated Backups with a Read Replica in the disaster recovery region.
- Cross-Region Automated Backups enable PITR to another region.
- Read Replica in DR region provides near real-time data copy.
- Read Replica can be quickly promoted to primary (low RTO).
- Asynchronous replication means RPO is typically minutes.
Memory trick: RDS Cross-Region DR: Backup + Read Replica = Fast Recovery, Minimal Loss.
AWS Backup for EC2/EBS
Flip cardAWS Backup automates the creation of crash-consistent snapshots for all EBS volumes attached to an EC2 instance, providing a centralized and efficient backup solution without requiring instance downtime.
- Centralized backup service.
- Automates snapshot creation for EC2 instances and attached EBS volumes.
- Achieves crash-consistency (application-consistency with VSS for Windows).
- No instance downtime required.
Memory trick: AWS Backup: Your one-stop shop for consistent EBS snapshots without stopping your EC2.
S3 Lifecycle for Cost Optimization
Flip cardS3 Lifecycle policies automate the transition of objects between storage classes or their expiration, allowing for cost optimization based on access patterns and retention requirements.
- Define rules based on object age or prefixes.
- Transition to less expensive storage classes (e.g., Standard-IA, Glacier).
- Can also be used to expire (delete) objects.
- Helps meet compliance and cost reduction goals.
Memory trick: Standard -> Infrequent -> Glacier: Follow the access, save the money.
EBS Volume Types for High IOPS
Flip cardFor applications requiring the highest IOPS and throughput, especially with small, random I/O, Provisioned IOPS SSD (io1/io2/io2 Block Express) volume types are designed to deliver consistent, high performance.
- io2 Block Express offers the highest IOPS and throughput.
- Suitable for I/O-intensive databases and enterprise applications.
- Designed for consistent, low-latency performance.
- Ideal for workloads with frequent small, random I/O.
Memory trick: SSD for speed, HDD for bulk, io2 for ultimate power.
Warm Standby DR Strategy
Flip cardWarm Standby is a disaster recovery strategy where a scaled-down but fully functional copy of your application is continuously running in a separate region, ready for rapid failover.
- Lower RTO/RPO than Backup & Restore or Pilot Light.
- Higher cost and complexity than Pilot Light.
- Data is continuously replicated to the standby region.
- Infrastructure is provisioned and running, but often at reduced capacity.
Memory trick: Faster recovery costs more, slower costs less.
SQS Dead-Letter Queue (DLQ)
Flip cardAn Amazon SQS Dead-Letter Queue stores messages that an application fails to process successfully after a specified number of attempts, preventing processing loops and isolating problematic messages.
- Isolates unprocessable messages.
- Prevents messages from re-entering the main queue indefinitely.
- Allows for later inspection and debugging.
- Configured with a `maxReceiveCount` threshold.
Memory trick: DLQ: The 'reject' bin for SQS messages that just won't behave.
Multi-AZ Application with EFS
Flip cardDeploying an application across multiple Availability Zones with an Auto Scaling group and using Amazon EFS for shared, persistent state ensures high availability and resilience.
- Auto Scaling Group distributes instances across AZs.
- EFS provides shared, highly available, and durable file storage.
- Decouples application state from individual instances.
- Enables seamless instance replacement without data loss.
Memory trick: Spread the servers, share the files, stay alive.
S3 Cross-Region Replication (CRR)
Flip cardS3 Cross-Region Replication (CRR) automatically and asynchronously copies objects across S3 buckets in different AWS Regions or accounts, enabling disaster recovery and compliance.
- Requires S3 Versioning enabled on both source and destination buckets.
- Replicates new objects, object updates, and object deletions (optional).
- Supports encryption at rest and in transit.
- Can replicate to different accounts and regions for DR.
Memory trick: CRR: Copy, Replicate, Recover.
DynamoDB On-demand Capacity
Flip cardDynamoDB On-demand capacity mode allows you to pay for read and write requests as they occur, providing automatic scaling for unpredictable workloads without requiring capacity planning.
- Pay-per-request pricing.
- Automatically scales up and down.
- Ideal for unpredictable traffic patterns.
- Can handle sudden spikes efficiently.
Memory trick: On-Demand is like a taxi, Provisioned is like a bus route.
Amazon EFS for Shared File Systems
Flip cardAmazon EFS provides a scalable, fully managed, highly available, and durable NFS file system that can be shared concurrently by EC2 instances across multiple Availability Zones within a region.
- Elastic and scales automatically.
- Accessible from multiple EC2 instances simultaneously.
- Supports NFSv4 protocol.
- High-bandwidth and low-latency for distributed workloads.
Memory trick: EFS: Everyone Files Share.
Aurora Global Database DR
Flip cardAmazon Aurora Global Database enables fast, low-RPO disaster recovery across AWS Regions by replicating data with minimal latency, making it ideal for critical applications needing quick regional failover.
- Replicates Aurora data across up to five AWS Regions.
- Achieves RPO typically < 1 second and RTO < 1 minute.
- Uses dedicated infrastructure for replication, minimizing impact on primary.
- Complements Warm Standby or Multi-site strategies for compute layer.
Memory trick: Global DB for data, Warm Standby for compute, quick recovery guaranteed.
Aurora Global Database
Flip cardAurora Global Database provides low-latency, cross-region replication for Aurora clusters, enabling fast disaster recovery with RPO of seconds and RTO of minutes.
- Designed for cross-region disaster recovery.
- RPO (Recovery Point Objective) of seconds.
- RTO (Recovery Time Objective) of minutes.
- Uses dedicated replication infrastructure.
Memory trick: Aurora Global Database: Your express train for DR across regions, fast RPO/RTO.
AWS Global Accelerator for DR
Flip cardAWS Global Accelerator uses static IP addresses and intelligent routing to direct user traffic to the nearest healthy application endpoint across multiple AWS regions, enhancing availability and performance.
- Provides static IP addresses as fixed entry points.
- Continuously monitors health of application endpoints.
- Automatically reroutes traffic away from unhealthy endpoints.
- Ideal for active-passive multi-region disaster recovery.
Memory trick: Global Accelerator: The traffic cop for your global apps, always finding a healthy route.
RDS PITR & Long-Term Backup
Flip cardAchieving point-in-time recovery (PITR) for a short window and long-term regulatory backup for RDS databases typically involves combining RDS automated backups with AWS Backup.
- RDS automated backups enable PITR for up to 35 days.
- AWS Backup centralizes backup management for many AWS services.
- AWS Backup can create snapshots and enforce long-term retention policies.
- Ensures compliance with minimal operational overhead.
Memory trick: Automated for now, AWS Backup for later.
Highly Available NAT Gateway
Flip cardTo ensure highly available outbound internet access for instances in private subnets, deploy a NAT Gateway in each Availability Zone with a route table entry pointing to it from the private subnets in that AZ.
- NAT Gateways allow private instances to initiate outbound connections.
- A single NAT Gateway is an AZ-level resource and can be a single point of failure.
- Deploying multiple NAT Gateways across AZs improves resilience.
- Each NAT Gateway requires a public subnet and an Elastic IP.
Memory trick: Many doors to the internet, never get stuck inside.