Free knowledge base

AWS Certified SysOps Administrator – Associate — key terms, tricks & tips

Everything from the course in one searchable place: 316 entries. Use it to review before a practice test or look up a word you forgot.

316 results · showing first 300, refine your search

Key term

Content Domains

Categorized sections of exam topics with assigned weightings.

Getting Started: Exam Essentials

Key term

Multiple-Choice

Question type with one correct answer among several options.

Getting Started: Exam Essentials

Key term

Multiple-Response

Question type requiring selection of two or more correct answers.

Getting Started: Exam Essentials

Key term

Distractors

Incorrect answer options in a multiple-choice question.

Getting Started: Exam Essentials

Key term

Passing Score

The minimum score required to pass the certification exam (720).

Getting Started: Exam Essentials

Key term

Unscored Questions

Experimental questions that do not count towards your final score.

Getting Started: Exam Essentials

Key term

Time Management

Strategically allocating time to answer all exam questions efficiently.

Getting Started: Exam Essentials

Memory trick

Understanding the SOA-C02 Exam Format

To remember the exam's time and question count: 'Sixty-Five questions, One Thirty minutes, Seven Twenty to pass.' (65, 130, 720).

Getting Started: Exam Essentials

Exam tip

Understanding the SOA-C02 Exam Format

The SOA-C02 exam has 65 questions and a 130-minute time limit. The passing score is 720 out of 1000. Remember these exact numbers for potential direct recall questions.

Getting Started: Exam Essentials

Common mistake

Understanding the SOA-C02 Exam Format

Not reading the question carefully, especially for 'choose TWO' or 'choose the BEST' options.

Getting Started: Exam Essentials

Common mistake

Understanding the SOA-C02 Exam Format

Spending too much time on a single difficult question, leading to not finishing the exam.

Getting Started: Exam Essentials

Common mistake

Understanding the SOA-C02 Exam Format

Not utilizing the 'mark for review' feature to revisit challenging questions later.

Getting Started: Exam Essentials

Key term

Exam Blueprint

Official document outlining exam domains and topics.

Getting Started: Exam Essentials

Key term

Active Learning

Engaging directly with material, not just passively reading.

Getting Started: Exam Essentials

Key term

AWS Free Tier

Allows free usage of many AWS services within limits.

Getting Started: Exam Essentials

Key term

AWS Skill Builder

Official AWS platform for digital training and practice exams.

Getting Started: Exam Essentials

Key term

Well-Architected Framework

AWS guidance on building secure, high-performing, resilient, and efficient infrastructure.

Getting Started: Exam Essentials

Key term

Practice Exam

Simulated test to assess knowledge and identify gaps.

Getting Started: Exam Essentials

Key term

Study Plan

Structured schedule for learning and reviewing exam topics.

Getting Started: Exam Essentials

Key term

Hands-on Labs

Practical exercises using AWS services in a real environment.

Getting Started: Exam Essentials

Memory trick

Effective Study Strategies & Resources for SOA-C02

To remember the key study steps: 'BLUEPRINT Learning PRACTICES REVIEW Success'. (Blueprint, Learning, Practices, Review, Success)

Getting Started: Exam Essentials

Exam tip

Effective Study Strategies & Resources for SOA-C02

The SOA-C02 exam frequently tests your ability to choose the MOST cost-effective, secure, or highly available solution. Look for keywords like 'least cost,' 'most secure,' or 'highest availability' in scenarios. Memorize the core tenets of the AWS Well-Architected Framework.

Getting Started: Exam Essentials

Common mistake

Effective Study Strategies & Resources for SOA-C02

Relying solely on dumps or unofficial practice questions without understanding the underlying concepts.

Getting Started: Exam Essentials

Common mistake

Effective Study Strategies & Resources for SOA-C02

Neglecting hands-on practice; theoretical knowledge alone is insufficient for SysOps.

Getting Started: Exam Essentials

Common mistake

Effective Study Strategies & Resources for SOA-C02

Cramming at the last minute instead of consistent, spaced repetition.

Getting Started: Exam Essentials

Key term

Metric

A time-ordered set of data points representing a variable.

Monitoring & Logging Mastery

Key term

Namespace

A container for CloudWatch metrics, identifying the service.

Monitoring & Logging Mastery

Key term

Dimension

A key-value pair that uniquely identifies a metric.

Monitoring & Logging Mastery

Key term

Alarm

Monitors a metric and performs actions when a threshold is breached.

Monitoring & Logging Mastery

Key term

Dashboard

Customizable homepage for monitoring resources in a single view.

Monitoring & Logging Mastery

Key term

High-resolution metric

Metrics with a granularity as low as 1 second.

Monitoring & Logging Mastery

Key term

Metric Filter

Extracts metric data from log events in CloudWatch Logs.

Monitoring & Logging Mastery

Key term

SNS

Simple Notification Service, used for sending alarm notifications.

Monitoring & Logging Mastery

Memory trick

CloudWatch: Metrics, Alarms, and Dashboards

MAP for CloudWatch: Metrics are the data, Alarms react to data, Dashboards visualize data.

Monitoring & Logging Mastery

Exam tip

CloudWatch: Metrics, Alarms, and Dashboards

The exam frequently tests on the different states of a CloudWatch alarm (OK, ALARM, INSUFFICIENT_DATA) and the actions that can be triggered (SNS, Auto Scaling policies). Remember that metrics are stored for 15 months by default.

Monitoring & Logging Mastery

Common mistake

CloudWatch: Metrics, Alarms, and Dashboards

Not understanding the difference between a metric and a log. Metrics are numerical data points; logs are event records.

Monitoring & Logging Mastery

Common mistake

CloudWatch: Metrics, Alarms, and Dashboards

Setting alarm thresholds too low, leading to 'flapping' alarms and alert fatigue.

Monitoring & Logging Mastery

Common mistake

CloudWatch: Metrics, Alarms, and Dashboards

Forgetting that custom metrics require either the CloudWatch agent or API calls to publish.

Monitoring & Logging Mastery

Common mistake

CloudWatch: Metrics, Alarms, and Dashboards

Not configuring sufficient permissions for CloudWatch to access other services (e.g., SNS for notifications).

Monitoring & Logging Mastery

Key term

CloudTrail

AWS service for logging API calls and events in your account.

Monitoring & Logging Mastery

Key term

Event History

90-day view of management events in the CloudTrail console.

Monitoring & Logging Mastery

Key term

Trail

Configuration to deliver CloudTrail logs to an S3 bucket and CloudWatch Logs.

Monitoring & Logging Mastery

Key term

Management Events

Operations performed on resources in your AWS account (e.g., creating an EC2 instance).

Monitoring & Logging Mastery

Key term

Data Events

Resource operations performed on or within a resource (e.g., S3 object API activity).

Monitoring & Logging Mastery

Key term

CloudTrail Insights

Identifies unusual operational activity by analyzing management events.

Monitoring & Logging Mastery

Key term

S3 Bucket

Storage location for CloudTrail log files, often with encryption.

Monitoring & Logging Mastery

Key term

CloudWatch Logs

Destination for CloudTrail events for real-time monitoring and alarms.

Monitoring & Logging Mastery

Memory trick

CloudTrail: Auditing AWS API Calls

To remember CloudTrail's purpose, think 'C-T-R-L': Control, Track, Record, Log. It gives you control by tracking and recording all API calls, logging them for audit.

Monitoring & Logging Mastery

Exam tip

CloudTrail: Auditing AWS API Calls

The exam often tests the difference between management events and data events, and when to enable each. Remember that data events are more granular and generate significantly more logs, impacting cost. Also, know that Event History is limited to 90 days and management events only.

Monitoring & Logging Mastery

Common mistake

CloudTrail: Auditing AWS API Calls

Forgetting to enable data events when detailed S3 object access or Lambda invocations need to be audited.

Monitoring & Logging Mastery

Common mistake

CloudTrail: Auditing AWS API Calls

Not configuring log file integrity validation, which ensures logs haven't been tampered with.

Monitoring & Logging Mastery

Common mistake

CloudTrail: Auditing AWS API Calls

Failing to integrate CloudTrail with CloudWatch Logs for real-time alerting on critical security events.

Monitoring & Logging Mastery

Key term

VPC Flow Logs

Records of IP traffic in and out of network interfaces.

Monitoring & Logging Mastery

Key term

Elastic Network Interface (ENI)

A virtual network card for an EC2 instance.

Monitoring & Logging Mastery

Key term

S3 Access Logs

Detailed records of requests made to an S3 bucket.

Monitoring & Logging Mastery

Key term

CloudWatch Logs Insights

A powerful query language for CloudWatch Logs.

Monitoring & Logging Mastery

Key term

Amazon Athena

Interactive query service for data in S3 using SQL.

Monitoring & Logging Mastery

Key term

ACCEPT/REJECT

Action field in flow logs indicating traffic status.

Monitoring & Logging Mastery

Key term

Target Bucket

S3 bucket where access logs are stored.

Monitoring & Logging Mastery

Memory trick

VPC Flow Logs & S3 Access Logs

VPC Flow Logs are like a 'Traffic Cop' for your network, telling you who's coming and going. S3 Access Logs are like a 'Librarian' for your data, recording every time a book (object) is checked out.

Monitoring & Logging Mastery

Exam tip

VPC Flow Logs & S3 Access Logs

For VPC Flow Logs, remember the three possible destinations: CloudWatch Logs, S3, and Kinesis Data Firehose. For S3 Access Logs, logs are always delivered to an S3 bucket. The exam often asks about the *purpose* of each log type and *where* they can be stored.

Monitoring & Logging Mastery

Common mistake

VPC Flow Logs & S3 Access Logs

Forgetting to configure an IAM role with sufficient permissions when publishing VPC Flow Logs to S3 or Kinesis Data Firehose.

Monitoring & Logging Mastery

Common mistake

VPC Flow Logs & S3 Access Logs

Enabling S3 Access Logs to log to the *same* bucket, creating a recursive logging loop and potentially increasing costs.

Monitoring & Logging Mastery

Common mistake

VPC Flow Logs & S3 Access Logs

Not understanding the difference in granularity: VPC Flow Logs are network-level, S3 Access Logs are object-level.

Monitoring & Logging Mastery

Key term

Automated Remediation

Automatic resolution of issues without human intervention.

Monitoring & Logging Mastery

Key term

Amazon SNS

Messaging service for publishing messages to subscribers.

Monitoring & Logging Mastery

Key term

AWS Lambda

Serverless compute service for running code in response to events.

Monitoring & Logging Mastery

Key term

AWS Systems Manager (SSM)

Collection of tools for managing and automating operational tasks.

Monitoring & Logging Mastery

Key term

SSM Automation Document

Defines a series of steps for automated operational tasks.

Monitoring & Logging Mastery

Key term

Mean Time To Resolution (MTTR)

Average time to recover from a product or system failure.

Monitoring & Logging Mastery

Memory trick

Remediating Issues with SNS, Lambda & SSM

To remember the order: 'A Sassy Little Squirrel' (Alarm, SNS, Lambda, SSM) handles the problem!

Monitoring & Logging Mastery

Exam tip

Remediating Issues with SNS, Lambda & SSM

The exam often presents scenarios requiring you to choose the most efficient and automated solution. Look for keywords like 'self-healing,' 'reduce manual effort,' or 'proactive response.' Remember the specific roles: CloudWatch for detection, SNS for notification, Lambda for logic, and SSM for action.

Monitoring & Logging Mastery

Common mistake

Remediating Issues with SNS, Lambda & SSM

Over-automating trivial issues that might be better handled by a human with more context.

Monitoring & Logging Mastery

Common mistake

Remediating Issues with SNS, Lambda & SSM

Not testing remediation workflows thoroughly, leading to unintended consequences or 'fix-loops.'

Monitoring & Logging Mastery

Common mistake

Remediating Issues with SNS, Lambda & SSM

Granting overly permissive IAM roles to Lambda functions or SSM, creating security vulnerabilities.

Monitoring & Logging Mastery

Key term

High Availability (HA)

System design for continuous operation without failure.

Building Resilient Systems

Key term

EC2 Auto Scaling

Automatically adjusts EC2 instance count based on demand.

Building Resilient Systems

Key term

Auto Scaling Group

Collection of EC2 instances managed as a single unit.

Building Resilient Systems

Key term

Launch Template

Specifies instance configuration for Auto Scaling.

Building Resilient Systems

Key term

Elastic Load Balancing (ELB)

Distributes incoming traffic across multiple targets.

Building Resilient Systems

Key term

Application Load Balancer (ALB)

ELB type for HTTP/HTTPS traffic at Layer 7.

Building Resilient Systems

Key term

Network Load Balancer (NLB)

ELB type for high-performance TCP/UDP/TLS at Layer 4.

Building Resilient Systems

Key term

Target Group

Routes requests to one or more registered targets.

Building Resilient Systems

Memory trick

High Availability with EC2 Auto Scaling & ELB

ELB is like a 'Traffic Cop' directing cars (requests) to the best lanes (instances). Auto Scaling is the 'Parking Attendant' adding or removing cars (instances) as needed.

Building Resilient Systems

Exam tip

High Availability with EC2 Auto Scaling & ELB

The exam frequently tests the differences between ALB and NLB. Remember ALB operates at Layer 7 (HTTP/HTTPS) and supports path/host-based routing, while NLB operates at Layer 4 (TCP/UDP/TLS) for extreme performance and static IP addresses.

Building Resilient Systems

Common mistake

High Availability with EC2 Auto Scaling & ELB

Forgetting to configure health checks for both ELB and Auto Scaling, leading to traffic being sent to unhealthy instances or unhealthy instances not being replaced.

Building Resilient Systems

Common mistake

High Availability with EC2 Auto Scaling & ELB

Setting Auto Scaling group minimum capacity too low, causing performance issues during unexpected traffic spikes before scaling policies can react.

Building Resilient Systems

Common mistake

High Availability with EC2 Auto Scaling & ELB

Confusing the use cases for ALB vs. NLB. ALB is for web applications needing advanced routing, while NLB is for high-performance, low-latency, or static IP needs.

Building Resilient Systems

Key term

RTO

Recovery Time Objective: Max acceptable downtime after an incident.

Building Resilient Systems

Key term

RPO

Recovery Point Objective: Max acceptable data loss after an incident.

Building Resilient Systems

Key term

Disaster Recovery

Processes and policies to recover IT infrastructure after a disaster.

Building Resilient Systems

Key term

Pilot Light

DR strategy: Minimal core services running in a secondary region.

Building Resilient Systems

Key term

Warm Standby

DR strategy: Scaled-down but functional environment in secondary region.

Building Resilient Systems

Key term

Multi-Site Active/Active

DR strategy: Full production in multiple regions, serving traffic concurrently.

Building Resilient Systems

Key term

Backup and Restore

DR strategy: Data backed up, restored manually or automatically.

Building Resilient Systems

Memory trick

Disaster Recovery: RTO & RPO

RTO is 'Time' (how long to get back up). RPO is 'Point' (how much data lost up to that point).

Building Resilient Systems

Exam tip

Disaster Recovery: RTO & RPO

The exam frequently presents scenarios asking you to choose the best DR strategy. Look for keywords like 'minutes of downtime' (low RTO), 'no data loss' (low RPO), or 'cost-effective' (higher RTO/RPO). Remember the order of increasing complexity and cost: Backup & Restore -> Pilot Light -> Warm Standby -> Multi-Site Active/Active.

Building Resilient Systems

Common mistake

Disaster Recovery: RTO & RPO

Confusing RTO and RPO: RTO is about time to recover, RPO is about data loss.

Building Resilient Systems

Common mistake

Disaster Recovery: RTO & RPO

Underestimating the cost and complexity of achieving very low RTO/RPO.

Building Resilient Systems

Common mistake

Disaster Recovery: RTO & RPO

Not involving business stakeholders in defining RTO/RPO, leading to misaligned expectations.

Building Resilient Systems

Key term

EBS Snapshot

An incremental backup of an Amazon EBS volume stored in S3.

Building Resilient Systems

Key term

AMI

An Amazon Machine Image; a template for launching an EC2 instance.

Building Resilient Systems

Key term

Incremental Backup

Only backs up data blocks that have changed since the last backup.

Building Resilient Systems

Key term

Data Lifecycle Manager (DLM)

Automates the creation, retention, and deletion of EBS Snapshots.

Building Resilient Systems

Key term

Root Volume

The primary EBS volume that contains the operating system for an EC2 instance.

Building Resilient Systems

Key term

Block Device Mapping

Specifies the volumes to attach to an EC2 instance when it's launched.

Building Resilient Systems

Key term

Durable

Ability of data to resist corruption or loss over time.

Building Resilient Systems

Memory trick

Backup & Restore with EBS Snapshots & AMIs

Think of an AMI as a 'blueprint' for a house (the whole instance), and an EBS Snapshot as a 'photo' of just one room's furniture (the data on a volume).

Building Resilient Systems

Exam tip

Backup & Restore with EBS Snapshots & AMIs

The exam frequently asks about the differences and appropriate use cases for EBS Snapshots versus AMIs. Remember that snapshots are for volume data, while AMIs are for entire instance configurations.

Building Resilient Systems

Common mistake

Backup & Restore with EBS Snapshots & AMIs

Confusing EBS Snapshots with AMIs; remember snapshots are for volumes, AMIs for instances.

Building Resilient Systems

Common mistake

Backup & Restore with EBS Snapshots & AMIs

Forgetting to automate snapshot management with Amazon Data Lifecycle Manager, leading to excessive costs or insufficient backups.

Building Resilient Systems

Common mistake

Backup & Restore with EBS Snapshots & AMIs

Not testing recovery procedures regularly, which can lead to unexpected issues during an actual disaster.

Building Resilient Systems

Key term

S3 Versioning

Keeps multiple versions of an object in a bucket.

Building Resilient Systems

Key term

Delete Marker

A special object version indicating an object was deleted.

Building Resilient Systems

Key term

S3 Replication

Automatically copies objects between S3 buckets.

Building Resilient Systems

Key term

Same-Region Replication

Replicates objects between buckets in the same AWS Region.

Building Resilient Systems

Key term

Cross-Region Replication

Replicates objects between buckets in different AWS Regions.

Building Resilient Systems

Key term

Source Bucket

The S3 bucket where objects are originally uploaded.

Building Resilient Systems

Key term

Destination Bucket

The S3 bucket where replicated objects are stored.

Building Resilient Systems

Memory trick

Data Protection with S3 Versioning & Replication

V-R-D: Versioning for Reversal, Replication for Disaster. Versioning lets you go back, Replication moves it far.

Building Resilient Systems

Exam tip

Data Protection with S3 Versioning & Replication

For the exam, remember that S3 Versioning must be enabled on both source and destination buckets for replication to function. Replication does not replicate existing objects at the time of configuration, only new objects and updates.

Building Resilient Systems

Common mistake

Data Protection with S3 Versioning & Replication

Forgetting to enable versioning on both source and destination buckets for replication.

Building Resilient Systems

Common mistake

Data Protection with S3 Versioning & Replication

Assuming replication will copy existing objects automatically when first configured (it only copies new objects unless S3 Batch Replication is used).

Building Resilient Systems

Common mistake

Data Protection with S3 Versioning & Replication

Not understanding that a 'delete' operation on a versioned object creates a delete marker, rather than permanently removing the object, which can still be recovered.

Building Resilient Systems

Key term

Infrastructure as Code (IaC)

Managing infrastructure through code, not manual processes.

Automated Deployments & Provisioning

Key term

AWS CloudFormation

AWS service for defining and provisioning infrastructure as code.

Automated Deployments & Provisioning

Key term

Template

JSON/YAML file describing AWS resources and their properties.

Automated Deployments & Provisioning

Key term

Stack

A collection of AWS resources created and managed by CloudFormation.

Automated Deployments & Provisioning

Key term

Parameters

Input values for a CloudFormation template at deployment.

Automated Deployments & Provisioning

Key term

Outputs

Values returned by a stack, usable by other stacks/applications.

Automated Deployments & Provisioning

Key term

Change Set

A preview of proposed changes to a running CloudFormation stack.

Automated Deployments & Provisioning

Memory trick

Infrastructure as Code with CloudFormation

Think 'Cloud' for 'Code' and 'Formation' for 'Forming' your infrastructure. CloudFormation forms your cloud resources from code!

Automated Deployments & Provisioning

Exam tip

Infrastructure as Code with CloudFormation

The exam frequently asks about the benefits of CloudFormation (consistency, automation, repeatability, version control) and the core components of a template (Resources, Parameters, Outputs). Know that CloudFormation manages the lifecycle of resources within a stack.

Automated Deployments & Provisioning

Common mistake

Infrastructure as Code with CloudFormation

Forgetting to delete a stack after testing, leading to unexpected costs.

Automated Deployments & Provisioning

Common mistake

Infrastructure as Code with CloudFormation

Making manual changes to resources managed by CloudFormation, causing 'drift' and deployment failures.

Automated Deployments & Provisioning

Common mistake

Infrastructure as Code with CloudFormation

Not using Change Sets to preview updates, which can lead to unintended resource modifications or deletions.

Automated Deployments & Provisioning

Key term

Application

Logical grouping of CodeDeploy deployments.

Automated Deployments & Provisioning

Key term

Deployment Group

Set of target instances or Lambda functions.

Automated Deployments & Provisioning

Key term

AppSpec File

YAML file defining deployment actions and hooks.

Automated Deployments & Provisioning

Key term

Lifecycle Hooks

Scripts run at specific stages of a deployment.

Automated Deployments & Provisioning

Key term

In-place Deployment

Updates application on existing instances.

Automated Deployments & Provisioning

Key term

Blue/Green Deployment

Deploys to new instances, shifts traffic for zero downtime.

Automated Deployments & Provisioning

Key term

Deployment Configuration

Defines how CodeDeploy performs a deployment.

Automated Deployments & Provisioning

Memory trick

Automating Deployments with AWS CodeDeploy

An APPlication has a DEPLOYMENT GROUP, which uses an APPSPEC file for LIFECYCLE HOOKS, following a DEPLOYMENT CONFIGURATION. Think: 'App Group Specs Hooks Config'.

Automated Deployments & Provisioning

Exam tip

Automating Deployments with AWS CodeDeploy

The exam frequently tests your understanding of CodeDeploy's deployment types (In-place vs. Blue/Green) and their use cases, as well as the purpose of the AppSpec file and lifecycle hooks. Pay close attention to how CodeDeploy integrates with other services like EC2, Lambda, and load balancers.

Automated Deployments & Provisioning

Common mistake

Automating Deployments with AWS CodeDeploy

Forgetting to include or correctly format the AppSpec file, leading to failed deployments.

Automated Deployments & Provisioning

Common mistake

Automating Deployments with AWS CodeDeploy

Using 'AllAtOnce' for critical production deployments without proper testing or fallback mechanisms, causing significant downtime.

Automated Deployments & Provisioning

Common mistake

Automating Deployments with AWS CodeDeploy

Not understanding the difference between In-place and Blue/Green deployments and choosing the wrong strategy for the business requirement.

Automated Deployments & Provisioning

Key term

SSM Agent

Software installed on instances to enable SSM functionality.

Automated Deployments & Provisioning

Key term

SSM Document

JSON/YAML file defining actions for Systems Manager.

Automated Deployments & Provisioning

Key term

Run Command

Securely execute commands on fleets of instances.

Automated Deployments & Provisioning

Key term

State Manager

Maintain desired configuration on managed instances.

Automated Deployments & Provisioning

Key term

Patch Manager

Automate patching of operating systems and applications.

Automated Deployments & Provisioning

Key term

Session Manager

Secure and auditable browser-based shell access.

Automated Deployments & Provisioning

Key term

Parameter Store

Secure storage for configuration data and secrets.

Automated Deployments & Provisioning

Memory trick

Provisioning with AWS Systems Manager

SSM: 'S'ecure 'S'ystem 'M'anagement – it's all about managing your systems securely and at scale.

Automated Deployments & Provisioning

Exam tip

Provisioning with AWS Systems Manager

On the exam, look for keywords like 'remote execution', 'desired state', 'patching', or 'secure shell access without SSH keys' to identify Systems Manager as the solution. Remember SSM Agent must be installed on instances.

Automated Deployments & Provisioning

Common mistake

Provisioning with AWS Systems Manager

Forgetting to install the SSM Agent on instances you want to manage.

Automated Deployments & Provisioning

Common mistake

Provisioning with AWS Systems Manager

Not configuring appropriate IAM permissions for Systems Manager to perform actions.

Automated Deployments & Provisioning

Common mistake

Provisioning with AWS Systems Manager

Confusing the purpose of different SSM Document types (e.g., using a Command document for a complex workflow better suited for Automation documents).

Automated Deployments & Provisioning

Key term

Serverless

Cloud execution model where providers manage servers; users focus on code.

Automated Deployments & Provisioning

Key term

Event-driven

Architecture where components react to events, not continuous polling.

Automated Deployments & Provisioning

Key term

AWS Step Functions

Serverless workflow service to orchestrate distributed applications.

Automated Deployments & Provisioning

Key term

State Machine

A workflow defined in Step Functions, describing steps and transitions.

Automated Deployments & Provisioning

Key term

Task State

A step in a Step Functions workflow that performs work, e.g., invokes Lambda.

Automated Deployments & Provisioning

Key term

Input/Output

Data passed between states in a Step Functions workflow.

Automated Deployments & Provisioning

Memory trick

Scripting & Automation with Lambda & Step Functions

L-S-O: Lambda for Logic, Step Functions for Orchestration. Remember the order and purpose!

Automated Deployments & Provisioning

Exam tip

Scripting & Automation with Lambda & Step Functions

For the exam, understand that Lambda is for individual, stateless functions, while Step Functions orchestrates stateful, multi-step workflows. Look for keywords like 'event-driven compute' for Lambda and 'orchestrate complex workflows' or 'manage state' for Step Functions.

Automated Deployments & Provisioning

Common mistake

Scripting & Automation with Lambda & Step Functions

Trying to build complex, stateful workflows entirely within a single Lambda function, leading to unwieldy code and poor error handling.

Automated Deployments & Provisioning

Common mistake

Scripting & Automation with Lambda & Step Functions

Not implementing proper error handling and retry mechanisms in Step Functions, causing workflows to fail completely on transient issues.

Automated Deployments & Provisioning

Common mistake

Scripting & Automation with Lambda & Step Functions

Overlooking the cost implications of long-running or frequently invoked Lambda functions, especially without proper memory/duration optimization.

Automated Deployments & Provisioning

Key term

VPC

Logically isolated virtual network in AWS.

Networking & Content Delivery

Key term

Subnet

A range of IP addresses within a VPC.

Networking & Content Delivery

Key term

Public Subnet

Subnet with a route to an Internet Gateway.

Networking & Content Delivery

Key term

Private Subnet

Subnet without a direct route to an Internet Gateway.

Networking & Content Delivery

Key term

Route Table

Rules that determine where network traffic is directed.

Networking & Content Delivery

Key term

Internet Gateway

Connects your VPC to the internet.

Networking & Content Delivery

Key term

NACL

Stateless firewall for controlling subnet traffic.

Networking & Content Delivery

Key term

CIDR Block

Classless Inter-Domain Routing notation for IP address ranges.

Networking & Content Delivery

Memory trick

VPC Fundamentals: Subnets, Route Tables, NACLs

NACLs are 'Nasty' because they're 'Stateless' – you have to tell them everything twice (inbound and outbound).

Networking & Content Delivery

Exam tip

VPC Fundamentals: Subnets, Route Tables, NACLs

The exam often tests the difference between NACLs and Security Groups. Remember that NACLs are stateless and operate at the subnet level, while Security Groups are stateful and operate at the instance level. Pay attention to questions involving explicit DENY rules or the need to allow both inbound and outbound traffic for responses.

Networking & Content Delivery

Common mistake

VPC Fundamentals: Subnets, Route Tables, NACLs

Confusing NACLs (stateless, subnet-level) with Security Groups (stateful, instance-level).

Networking & Content Delivery

Common mistake

VPC Fundamentals: Subnets, Route Tables, NACLs

Forgetting to add an explicit outbound rule in a NACL for response traffic, leading to one-way communication.

Networking & Content Delivery

Common mistake

VPC Fundamentals: Subnets, Route Tables, NACLs

Not associating a subnet with a route table, causing it to implicitly use the main route table, which might not have the desired routes.

Networking & Content Delivery

Key term

Site-to-Site VPN

Encrypts traffic between on-premises networks and AWS VPCs over the internet.

Networking & Content Delivery

Key term

Client VPN

Managed service for secure remote user access to AWS and on-premises resources.

Networking & Content Delivery

Key term

Direct Connect

Dedicated, private network connection from on-premises to AWS, bypassing the internet.

Networking & Content Delivery

Key term

VPC Peering

Connects two VPCs directly using private IP addresses; non-transitive.

Networking & Content Delivery

Key term

Transit Gateway

Central hub for connecting multiple VPCs and on-premises networks; transitive.

Networking & Content Delivery

Key term

Customer Gateway

Represents your on-premises VPN device in an AWS Site-to-Site VPN setup.

Networking & Content Delivery

Key term

Virtual Private Gateway

AWS side of a Site-to-Site VPN connection, attached to a VPC.

Networking & Content Delivery

Memory trick

Connecting Networks: VPN, Direct Connect, Peering

VPN: Virtual Private Network. Direct Connect: Dedicated Connection. Peering: Point-to-point. Transit Gateway: Traffic Hub.

Networking & Content Delivery

Exam tip

Connecting Networks: VPN, Direct Connect, Peering

For the exam, distinguish between Site-to-Site VPN (network-to-network over internet) and Client VPN (user-to-network). Remember Direct Connect offers dedicated private connectivity, bypassing the internet, and Transit Gateway solves the non-transitive routing limitation of VPC Peering.

Networking & Content Delivery

Common mistake

Connecting Networks: VPN, Direct Connect, Peering

Confusing Site-to-Site VPN (network-to-network) with Client VPN (user-to-network).

Networking & Content Delivery

Common mistake

Connecting Networks: VPN, Direct Connect, Peering

Assuming VPC peering is transitive; it is not, necessitating Transit Gateway for complex mesh networks.

Networking & Content Delivery

Common mistake

Connecting Networks: VPN, Direct Connect, Peering

Underestimating the lead time for Direct Connect provisioning; it's not an instant setup like a VPN.

Networking & Content Delivery

Key term

DNS

Domain Name System; translates domain names to IP addresses.

Networking & Content Delivery

Key term

Route 53

AWS's highly available and scalable cloud DNS web service.

Networking & Content Delivery

Key term

Hosted Zone

Container for records that define how to route traffic for a domain.

Networking & Content Delivery

Key term

Record Set

Maps a domain/subdomain to an IP address or other resource.

Networking & Content Delivery

Key term

Alias Record

Special Route 53 record type pointing to AWS resources.

Networking & Content Delivery

Key term

Routing Policy

Determines how Route 53 responds to DNS queries (e.g., Failover, Latency).

Networking & Content Delivery

Key term

Health Check

Monitors the health of resources to enable failover or traffic shifting.

Networking & Content Delivery

Key term

TTL

Time To Live; duration DNS resolvers cache a record before querying again.

Networking & Content Delivery

Memory trick

Route 53: DNS Management & Traffic Routing

Remember '53' for Route 53: 'Five' types of routing (Failover, IP-based, View, Elastic, Simple) and 'Three' key features (Traffic management, Health checks, Resource records).

Networking & Content Delivery

Exam tip

Route 53: DNS Management & Traffic Routing

The exam often tests the differences between various Route 53 routing policies. Memorize the purpose of Simple, Failover, Latency-based, Geolocation, and Weighted routing. Understand that Alias records can point to AWS resources and are free for DNS queries.

Networking & Content Delivery

Common mistake

Route 53: DNS Management & Traffic Routing

Confusing CNAME records with Alias records: CNAMEs cannot be used for the root domain (e.g., example.com), but Alias records can.

Networking & Content Delivery

Common mistake

Route 53: DNS Management & Traffic Routing

Forgetting to update Name Servers: If you transfer a domain to Route 53, you must update the domain's name servers at your registrar to point to Route 53's name servers.

Networking & Content Delivery

Common mistake

Route 53: DNS Management & Traffic Routing

Incorrectly configuring health checks: Ensure health checks are configured correctly for the failover routing policy to work as expected.

Networking & Content Delivery

Key term

CloudFront

AWS CDN for fast, secure content delivery.

Networking & Content Delivery

Key term

Edge Location

Global data centers where CloudFront caches content.

Networking & Content Delivery

Key term

Origin

The source of content for CloudFront (e.g., S3 bucket).

Networking & Content Delivery

Key term

OAC (Origin Access Control)

Recommended method for CloudFront to securely access S3.

Networking & Content Delivery

Key term

OAI (Origin Access Identity)

Legacy method for CloudFront to securely access S3.

Networking & Content Delivery

Key term

Caching

Storing copies of content closer to users for faster delivery.

Networking & Content Delivery

Key term

Distribution

A CloudFront configuration that defines how content is delivered.

Networking & Content Delivery

Key term

Invalidation

Process to remove cached content from CloudFront edge locations.

Networking & Content Delivery

Memory trick

Content Delivery with CloudFront & S3

CloudFront is like a 'Global Fast Food Chain' for your data. Edge Locations are the local restaurants, caching popular items (your content) for quick delivery to nearby customers (users).

Networking & Content Delivery

Exam tip

Content Delivery with CloudFront & S3

The exam often tests the difference between OAI and OAC, emphasizing OAC as the current best practice for securing S3 origins. Be prepared for questions about cache hit ratio, TTL settings, and how CloudFront integrates with other AWS services like S3 and Route 53.

Networking & Content Delivery

Common mistake

Content Delivery with CloudFront & S3

Forgetting to update S3 bucket policies after configuring OAC/OAI, leading to 'Access Denied' errors.

Networking & Content Delivery

Common mistake

Content Delivery with CloudFront & S3

Not setting appropriate cache TTLs, causing users to see stale content or frequent origin fetches.

Networking & Content Delivery

Common mistake

Content Delivery with CloudFront & S3

Using OAI for new distributions instead of the more secure and feature-rich OAC.

Networking & Content Delivery

Key term

IAM User

An entity representing a person or service for AWS interaction.

Security & Compliance Deep Dive

Key term

IAM Role

An AWS identity with temporary permissions for services or users.

Security & Compliance Deep Dive

Key term

IAM Policy

A JSON document defining permissions for AWS resources.

Security & Compliance Deep Dive

Key term

Least Privilege

Security principle: grant only necessary permissions for a task.

Security & Compliance Deep Dive

Key term

MFA

Multi-Factor Authentication, adding a second verification step.

Security & Compliance Deep Dive

Key term

Trust Policy

Part of an IAM role, specifying who can assume the role.

Security & Compliance Deep Dive

Key term

Identity-based Policy

Policy attached to an IAM user, group, or role.

Security & Compliance Deep Dive

Memory trick

IAM: Users, Roles, Policies, & Best Practices

R-U-P-S: Roles for Services, Users for People, Policies for Permissions, Security is paramount!

Security & Compliance Deep Dive

Exam tip

IAM: Users, Roles, Policies, & Best Practices

The exam will often test your understanding of policy evaluation logic, especially explicit Deny vs. Allow. Remember: an explicit Deny always overrides any Allow.

Security & Compliance Deep Dive

Common mistake

IAM: Users, Roles, Policies, & Best Practices

Using the root user for daily operational tasks instead of dedicated IAM users.

Security & Compliance Deep Dive

Common mistake

IAM: Users, Roles, Policies, & Best Practices

Attaching broad administrative policies directly to individual users instead of using groups or specific roles.

Security & Compliance Deep Dive

Common mistake

IAM: Users, Roles, Policies, & Best Practices

Not enabling MFA for privileged IAM users, leaving accounts vulnerable.

Security & Compliance Deep Dive

Key term

Security Group

A virtual firewall for an EC2 instance, controlling inbound/outbound traffic.

Security & Compliance Deep Dive

Key term

Network ACL (NACL)

A stateless firewall for a subnet, controlling all traffic in/out.

Security & Compliance Deep Dive

Key term

Stateful

Return traffic is automatically allowed once initial traffic is permitted.

Security & Compliance Deep Dive

Key term

Stateless

Both inbound and outbound traffic must be explicitly allowed by rules.

Security & Compliance Deep Dive

Key term

Inbound Rule

Controls traffic coming INTO an instance or subnet.

Security & Compliance Deep Dive

Key term

Outbound Rule

Controls traffic leaving an instance or subnet.

Security & Compliance Deep Dive

Memory trick

Security Groups & Network ACLs in Depth

SGs are 'Smart Guardians' (stateful, instance-level), NACLs are 'Nasty Cops' (stateless, subnet-level, can deny).

Security & Compliance Deep Dive

Exam tip

Security Groups & Network ACLs in Depth

Remember that Security Groups are stateful and operate at the instance level, while Network ACLs are stateless and operate at the subnet level. This distinction is a frequent exam topic, especially when comparing their rule processing and default behaviors.

Security & Compliance Deep Dive

Common mistake

Security Groups & Network ACLs in Depth

Confusing stateful (Security Groups) with stateless (Network ACLs).

Security & Compliance Deep Dive

Common mistake

Security Groups & Network ACLs in Depth

Forgetting that Network ACLs process rules by number, and the first match wins, potentially overriding later rules.

Security & Compliance Deep Dive

Common mistake

Security Groups & Network ACLs in Depth

Not explicitly allowing outbound traffic in Network ACLs when inbound is allowed (due to their stateless nature).

Security & Compliance Deep Dive

Key term

Encryption at Rest

Encrypting data when it is stored persistently on a storage device.

Security & Compliance Deep Dive

Key term

Encryption in Transit

Encrypting data as it moves between systems over a network.

Security & Compliance Deep Dive

Key term

AWS KMS

Managed service for creating and controlling encryption keys for AWS services.

Security & Compliance Deep Dive

Key term

AWS CloudHSM

Dedicated, single-tenant hardware security modules for stringent compliance.

Security & Compliance Deep Dive

Key term

TLS (Transport Layer Security)

Cryptographic protocol securing network communications, successor to SSL.

Security & Compliance Deep Dive

Key term

CMK (Customer-Managed Key)

Encryption key in KMS where you control key policies and lifecycle.

Security & Compliance Deep Dive

Key term

SSE-KMS

Server-side encryption for S3 using AWS KMS-managed keys.

Security & Compliance Deep Dive

Key term

FIPS 140-2

US government computer security standard for cryptographic modules.

Security & Compliance Deep Dive

Memory trick

Data Encryption: At Rest & In Transit

To remember the difference: 'KMS is for 'Keys Managed Simply,' CloudHSM is for 'Compliance's Hardcore Security Modules.'

Security & Compliance Deep Dive

Exam tip

Data Encryption: At Rest & In Transit

The exam often tests your understanding of when to use KMS versus CloudHSM. Remember KMS is for general-purpose, managed key encryption, while CloudHSM is for dedicated, single-tenant hardware for strict compliance needs. Look for keywords like 'dedicated HSM' or 'FIPS 140-2 Level 3' for CloudHSM.

Security & Compliance Deep Dive

Common mistake

Data Encryption: At Rest & In Transit

Forgetting to encrypt both at rest and in transit, leaving a vulnerability.

Security & Compliance Deep Dive

Common mistake

Data Encryption: At Rest & In Transit

Using AWS-managed keys when compliance requires more control (CMKs or CloudHSM).

Security & Compliance Deep Dive

Common mistake

Data Encryption: At Rest & In Transit

Not enabling default encryption for services like S3 buckets or EBS volumes.

Security & Compliance Deep Dive

Key term

AWS Config

Monitors and records AWS resource configurations.

Security & Compliance Deep Dive

Key term

Config Rule

Evaluates AWS resource configurations for compliance.

Security & Compliance Deep Dive

Key term

AWS Security Hub

Aggregates and prioritizes security findings.

Security & Compliance Deep Dive

Key term

Amazon GuardDuty

Intelligent threat detection service for AWS accounts.

Security & Compliance Deep Dive

Key term

Finding

A security alert or non-compliance event.

Security & Compliance Deep Dive

Key term

CloudTrail Logs

Records API calls and events in your AWS account.

Security & Compliance Deep Dive

Memory trick

Compliance Services: Config, Security Hub, GuardDuty

To CONFIGURE compliance, GUARD for threats, and HUB all your findings together!

Security & Compliance Deep Dive

Exam tip

Compliance Services: Config, Security Hub, GuardDuty

Memorize the primary purpose of each service: Config for configuration compliance, GuardDuty for threat detection, and Security Hub for aggregating security findings. The exam often presents scenarios where you must choose the best service for a specific problem.

Security & Compliance Deep Dive

Common mistake

Compliance Services: Config, Security Hub, GuardDuty

Confusing Config's role (configuration compliance) with GuardDuty's role (threat detection).

Security & Compliance Deep Dive

Common mistake

Compliance Services: Config, Security Hub, GuardDuty

Assuming Security Hub performs its own detection instead of aggregating findings from other services.

Security & Compliance Deep Dive

Common mistake

Compliance Services: Config, Security Hub, GuardDuty

Not understanding that these services often work best when integrated, not in isolation.

Security & Compliance Deep Dive

Key term

On-Demand Instances

Pay-as-you-go, flexible, highest cost EC2 option.

Optimizing Costs & Performance

Key term

Reserved Instances (RIs)

Commitment for 1 or 3 years, significant discount for steady workloads.

Optimizing Costs & Performance

Key term

Savings Plans

Flexible commitment for consistent compute usage across services.

Optimizing Costs & Performance

Key term

Spot Instances

Bid on unused EC2 capacity, up to 90% discount, interruptible.

Optimizing Costs & Performance

Key term

Right-sizing

Matching resource capacity to actual workload requirements.

Optimizing Costs & Performance

Key term

S3 Intelligent-Tiering

Automatically moves data between access tiers based on patterns.

Optimizing Costs & Performance

Key term

S3 Lifecycle Policy

Automates transitions or expiration of S3 objects.

Optimizing Costs & Performance

Key term

Aurora Serverless

On-demand, auto-scaling configuration for Amazon Aurora.

Optimizing Costs & Performance

Memory trick

Cost Optimization: EC2, S3, RDS Strategies

Think 'R-S-S' for EC2 savings: Reserved, Spot, Savings. Each offers a different way to save big!

Optimizing Costs & Performance

Exam tip

Cost Optimization: EC2, S3, RDS Strategies

The exam often tests your ability to choose the MOST cost-effective option for a given scenario. Pay close attention to keywords like 'interruptible,' 'steady-state,' 'unpredictable,' 'archival,' and 'infrequent access' to guide your choice of EC2 purchasing model or S3 storage class.

Optimizing Costs & Performance

Common mistake

Cost Optimization: EC2, S3, RDS Strategies

Using On-Demand instances for predictable, long-running workloads instead of Reserved Instances or Savings Plans.

Optimizing Costs & Performance

Common mistake

Cost Optimization: EC2, S3, RDS Strategies

Storing rarely accessed data in S3 Standard instead of a lower-cost S3 Infrequent Access or Glacier class.

Optimizing Costs & Performance

Common mistake

Cost Optimization: EC2, S3, RDS Strategies

Not deleting idle or unused EC2 instances, RDS databases, or old S3 snapshots, which continue to incur charges.

Optimizing Costs & Performance

Key term

Scaling Up

Increasing the resources (CPU, memory) of an existing instance.

Optimizing Costs & Performance

Key term

Scaling Out

Adding more instances to distribute workload.

Optimizing Costs & Performance

Key term

Provisioned IOPS (PIOPS)

An EBS/RDS storage type guaranteeing consistent I/O performance.

Optimizing Costs & Performance

Key term

Read Replica

A copy of an RDS database used to offload read traffic.

Optimizing Costs & Performance

Key term

Performance Insights

An RDS tool for monitoring and analyzing database performance.

Optimizing Costs & Performance

Key term

CloudWatch Metrics

Data points representing resource utilization and application performance.

Optimizing Costs & Performance

Key term

I/O Bottleneck

A performance limitation caused by slow disk or network input/output.

Optimizing Costs & Performance

Memory trick

Performance Tuning EC2 & RDS Instances

To remember EC2/RDS tuning, think 'MONITOR, DIAGNOSE, OPTIMIZE, SCALE'. It's a cycle, not a one-time fix!

Optimizing Costs & Performance

Exam tip

Performance Tuning EC2 & RDS Instances

The exam often tests your ability to choose the most cost-effective and appropriate scaling strategy. Look for keywords like 'read-heavy workload' (suggests Read Replicas), 'intermittent spikes' (Auto Scaling), or 'consistent high CPU' (scale up or optimize).

Optimizing Costs & Performance

Common mistake

Performance Tuning EC2 & RDS Instances

Immediately scaling up without first investigating and optimizing application or database queries, leading to unnecessary cost increases.

Optimizing Costs & Performance

Common mistake

Performance Tuning EC2 & RDS Instances

Ignoring disk I/O metrics for I/O-intensive applications, assuming CPU or memory is always the bottleneck.

Optimizing Costs & Performance

Common mistake

Performance Tuning EC2 & RDS Instances

Not using Read Replicas for read-heavy RDS workloads, causing the primary instance to become overloaded.

Optimizing Costs & Performance

Key term

CloudWatch Alarms

Monitors metrics against thresholds, triggers actions on state change.

Optimizing Costs & Performance

Key term

CloudWatch Events

Near real-time stream of system events for automation.

Optimizing Costs & Performance

Key term

CloudWatch Dashboards

Customizable visual interface for monitoring resources.

Optimizing Costs & Performance

Key term

EventBridge

AWS service for building event-driven applications, supersedes CloudWatch Events.

Optimizing Costs & Performance

Memory trick

Monitoring Performance with CloudWatch

MALED: Metrics, Alarms, Logs, Events, Dashboards – the core CloudWatch components.

Optimizing Costs & Performance

Exam tip

Monitoring Performance with CloudWatch

The exam often tests your understanding of which CloudWatch component is best suited for a specific task: metrics for raw data, alarms for proactive alerts, logs for centralized logging and analysis, and events for automation. Remember the 15-month metric retention.

Optimizing Costs & Performance