Content Domains
Categorized sections of exam topics with assigned weightings.
Getting Started: Exam Essentials
Free knowledge base
Everything from the course in one searchable place: 316 entries. Use it to review before a practice test or look up a word you forgot.
316 results · showing first 300, refine your search
Categorized sections of exam topics with assigned weightings.
Getting Started: Exam Essentials
Question type with one correct answer among several options.
Getting Started: Exam Essentials
Question type requiring selection of two or more correct answers.
Getting Started: Exam Essentials
Incorrect answer options in a multiple-choice question.
Getting Started: Exam Essentials
The minimum score required to pass the certification exam (720).
Getting Started: Exam Essentials
Experimental questions that do not count towards your final score.
Getting Started: Exam Essentials
Strategically allocating time to answer all exam questions efficiently.
Getting Started: Exam Essentials
To remember the exam's time and question count: 'Sixty-Five questions, One Thirty minutes, Seven Twenty to pass.' (65, 130, 720).
Getting Started: Exam Essentials
The SOA-C02 exam has 65 questions and a 130-minute time limit. The passing score is 720 out of 1000. Remember these exact numbers for potential direct recall questions.
Getting Started: Exam Essentials
Not reading the question carefully, especially for 'choose TWO' or 'choose the BEST' options.
Getting Started: Exam Essentials
Spending too much time on a single difficult question, leading to not finishing the exam.
Getting Started: Exam Essentials
Not utilizing the 'mark for review' feature to revisit challenging questions later.
Getting Started: Exam Essentials
Official document outlining exam domains and topics.
Getting Started: Exam Essentials
Engaging directly with material, not just passively reading.
Getting Started: Exam Essentials
Allows free usage of many AWS services within limits.
Getting Started: Exam Essentials
Official AWS platform for digital training and practice exams.
Getting Started: Exam Essentials
AWS guidance on building secure, high-performing, resilient, and efficient infrastructure.
Getting Started: Exam Essentials
Simulated test to assess knowledge and identify gaps.
Getting Started: Exam Essentials
Structured schedule for learning and reviewing exam topics.
Getting Started: Exam Essentials
Practical exercises using AWS services in a real environment.
Getting Started: Exam Essentials
To remember the key study steps: 'BLUEPRINT Learning PRACTICES REVIEW Success'. (Blueprint, Learning, Practices, Review, Success)
Getting Started: Exam Essentials
The SOA-C02 exam frequently tests your ability to choose the MOST cost-effective, secure, or highly available solution. Look for keywords like 'least cost,' 'most secure,' or 'highest availability' in scenarios. Memorize the core tenets of the AWS Well-Architected Framework.
Getting Started: Exam Essentials
Relying solely on dumps or unofficial practice questions without understanding the underlying concepts.
Getting Started: Exam Essentials
Neglecting hands-on practice; theoretical knowledge alone is insufficient for SysOps.
Getting Started: Exam Essentials
Cramming at the last minute instead of consistent, spaced repetition.
Getting Started: Exam Essentials
A time-ordered set of data points representing a variable.
Monitoring & Logging Mastery
A container for CloudWatch metrics, identifying the service.
Monitoring & Logging Mastery
A key-value pair that uniquely identifies a metric.
Monitoring & Logging Mastery
Monitors a metric and performs actions when a threshold is breached.
Monitoring & Logging Mastery
Customizable homepage for monitoring resources in a single view.
Monitoring & Logging Mastery
Metrics with a granularity as low as 1 second.
Monitoring & Logging Mastery
Extracts metric data from log events in CloudWatch Logs.
Monitoring & Logging Mastery
Simple Notification Service, used for sending alarm notifications.
Monitoring & Logging Mastery
MAP for CloudWatch: Metrics are the data, Alarms react to data, Dashboards visualize data.
Monitoring & Logging Mastery
The exam frequently tests on the different states of a CloudWatch alarm (OK, ALARM, INSUFFICIENT_DATA) and the actions that can be triggered (SNS, Auto Scaling policies). Remember that metrics are stored for 15 months by default.
Monitoring & Logging Mastery
Not understanding the difference between a metric and a log. Metrics are numerical data points; logs are event records.
Monitoring & Logging Mastery
Setting alarm thresholds too low, leading to 'flapping' alarms and alert fatigue.
Monitoring & Logging Mastery
Forgetting that custom metrics require either the CloudWatch agent or API calls to publish.
Monitoring & Logging Mastery
Not configuring sufficient permissions for CloudWatch to access other services (e.g., SNS for notifications).
Monitoring & Logging Mastery
AWS service for logging API calls and events in your account.
Monitoring & Logging Mastery
90-day view of management events in the CloudTrail console.
Monitoring & Logging Mastery
Configuration to deliver CloudTrail logs to an S3 bucket and CloudWatch Logs.
Monitoring & Logging Mastery
Operations performed on resources in your AWS account (e.g., creating an EC2 instance).
Monitoring & Logging Mastery
Resource operations performed on or within a resource (e.g., S3 object API activity).
Monitoring & Logging Mastery
Identifies unusual operational activity by analyzing management events.
Monitoring & Logging Mastery
Storage location for CloudTrail log files, often with encryption.
Monitoring & Logging Mastery
Destination for CloudTrail events for real-time monitoring and alarms.
Monitoring & Logging Mastery
To remember CloudTrail's purpose, think 'C-T-R-L': Control, Track, Record, Log. It gives you control by tracking and recording all API calls, logging them for audit.
Monitoring & Logging Mastery
The exam often tests the difference between management events and data events, and when to enable each. Remember that data events are more granular and generate significantly more logs, impacting cost. Also, know that Event History is limited to 90 days and management events only.
Monitoring & Logging Mastery
Forgetting to enable data events when detailed S3 object access or Lambda invocations need to be audited.
Monitoring & Logging Mastery
Not configuring log file integrity validation, which ensures logs haven't been tampered with.
Monitoring & Logging Mastery
Failing to integrate CloudTrail with CloudWatch Logs for real-time alerting on critical security events.
Monitoring & Logging Mastery
Records of IP traffic in and out of network interfaces.
Monitoring & Logging Mastery
A virtual network card for an EC2 instance.
Monitoring & Logging Mastery
Detailed records of requests made to an S3 bucket.
Monitoring & Logging Mastery
A powerful query language for CloudWatch Logs.
Monitoring & Logging Mastery
Interactive query service for data in S3 using SQL.
Monitoring & Logging Mastery
Action field in flow logs indicating traffic status.
Monitoring & Logging Mastery
S3 bucket where access logs are stored.
Monitoring & Logging Mastery
VPC Flow Logs are like a 'Traffic Cop' for your network, telling you who's coming and going. S3 Access Logs are like a 'Librarian' for your data, recording every time a book (object) is checked out.
Monitoring & Logging Mastery
For VPC Flow Logs, remember the three possible destinations: CloudWatch Logs, S3, and Kinesis Data Firehose. For S3 Access Logs, logs are always delivered to an S3 bucket. The exam often asks about the *purpose* of each log type and *where* they can be stored.
Monitoring & Logging Mastery
Forgetting to configure an IAM role with sufficient permissions when publishing VPC Flow Logs to S3 or Kinesis Data Firehose.
Monitoring & Logging Mastery
Enabling S3 Access Logs to log to the *same* bucket, creating a recursive logging loop and potentially increasing costs.
Monitoring & Logging Mastery
Not understanding the difference in granularity: VPC Flow Logs are network-level, S3 Access Logs are object-level.
Monitoring & Logging Mastery
Automatic resolution of issues without human intervention.
Monitoring & Logging Mastery
Messaging service for publishing messages to subscribers.
Monitoring & Logging Mastery
Serverless compute service for running code in response to events.
Monitoring & Logging Mastery
Collection of tools for managing and automating operational tasks.
Monitoring & Logging Mastery
Defines a series of steps for automated operational tasks.
Monitoring & Logging Mastery
Average time to recover from a product or system failure.
Monitoring & Logging Mastery
To remember the order: 'A Sassy Little Squirrel' (Alarm, SNS, Lambda, SSM) handles the problem!
Monitoring & Logging Mastery
The exam often presents scenarios requiring you to choose the most efficient and automated solution. Look for keywords like 'self-healing,' 'reduce manual effort,' or 'proactive response.' Remember the specific roles: CloudWatch for detection, SNS for notification, Lambda for logic, and SSM for action.
Monitoring & Logging Mastery
Over-automating trivial issues that might be better handled by a human with more context.
Monitoring & Logging Mastery
Not testing remediation workflows thoroughly, leading to unintended consequences or 'fix-loops.'
Monitoring & Logging Mastery
Granting overly permissive IAM roles to Lambda functions or SSM, creating security vulnerabilities.
Monitoring & Logging Mastery
System design for continuous operation without failure.
Building Resilient Systems
Automatically adjusts EC2 instance count based on demand.
Building Resilient Systems
Collection of EC2 instances managed as a single unit.
Building Resilient Systems
Specifies instance configuration for Auto Scaling.
Building Resilient Systems
Distributes incoming traffic across multiple targets.
Building Resilient Systems
ELB type for HTTP/HTTPS traffic at Layer 7.
Building Resilient Systems
ELB type for high-performance TCP/UDP/TLS at Layer 4.
Building Resilient Systems
Routes requests to one or more registered targets.
Building Resilient Systems
ELB is like a 'Traffic Cop' directing cars (requests) to the best lanes (instances). Auto Scaling is the 'Parking Attendant' adding or removing cars (instances) as needed.
Building Resilient Systems
The exam frequently tests the differences between ALB and NLB. Remember ALB operates at Layer 7 (HTTP/HTTPS) and supports path/host-based routing, while NLB operates at Layer 4 (TCP/UDP/TLS) for extreme performance and static IP addresses.
Building Resilient Systems
Forgetting to configure health checks for both ELB and Auto Scaling, leading to traffic being sent to unhealthy instances or unhealthy instances not being replaced.
Building Resilient Systems
Setting Auto Scaling group minimum capacity too low, causing performance issues during unexpected traffic spikes before scaling policies can react.
Building Resilient Systems
Confusing the use cases for ALB vs. NLB. ALB is for web applications needing advanced routing, while NLB is for high-performance, low-latency, or static IP needs.
Building Resilient Systems
Recovery Time Objective: Max acceptable downtime after an incident.
Building Resilient Systems
Recovery Point Objective: Max acceptable data loss after an incident.
Building Resilient Systems
Processes and policies to recover IT infrastructure after a disaster.
Building Resilient Systems
DR strategy: Minimal core services running in a secondary region.
Building Resilient Systems
DR strategy: Scaled-down but functional environment in secondary region.
Building Resilient Systems
DR strategy: Full production in multiple regions, serving traffic concurrently.
Building Resilient Systems
DR strategy: Data backed up, restored manually or automatically.
Building Resilient Systems
RTO is 'Time' (how long to get back up). RPO is 'Point' (how much data lost up to that point).
Building Resilient Systems
The exam frequently presents scenarios asking you to choose the best DR strategy. Look for keywords like 'minutes of downtime' (low RTO), 'no data loss' (low RPO), or 'cost-effective' (higher RTO/RPO). Remember the order of increasing complexity and cost: Backup & Restore -> Pilot Light -> Warm Standby -> Multi-Site Active/Active.
Building Resilient Systems
Confusing RTO and RPO: RTO is about time to recover, RPO is about data loss.
Building Resilient Systems
Underestimating the cost and complexity of achieving very low RTO/RPO.
Building Resilient Systems
Not involving business stakeholders in defining RTO/RPO, leading to misaligned expectations.
Building Resilient Systems
An incremental backup of an Amazon EBS volume stored in S3.
Building Resilient Systems
An Amazon Machine Image; a template for launching an EC2 instance.
Building Resilient Systems
Only backs up data blocks that have changed since the last backup.
Building Resilient Systems
Automates the creation, retention, and deletion of EBS Snapshots.
Building Resilient Systems
The primary EBS volume that contains the operating system for an EC2 instance.
Building Resilient Systems
Specifies the volumes to attach to an EC2 instance when it's launched.
Building Resilient Systems
Ability of data to resist corruption or loss over time.
Building Resilient Systems
Think of an AMI as a 'blueprint' for a house (the whole instance), and an EBS Snapshot as a 'photo' of just one room's furniture (the data on a volume).
Building Resilient Systems
The exam frequently asks about the differences and appropriate use cases for EBS Snapshots versus AMIs. Remember that snapshots are for volume data, while AMIs are for entire instance configurations.
Building Resilient Systems
Confusing EBS Snapshots with AMIs; remember snapshots are for volumes, AMIs for instances.
Building Resilient Systems
Forgetting to automate snapshot management with Amazon Data Lifecycle Manager, leading to excessive costs or insufficient backups.
Building Resilient Systems
Not testing recovery procedures regularly, which can lead to unexpected issues during an actual disaster.
Building Resilient Systems
Keeps multiple versions of an object in a bucket.
Building Resilient Systems
A special object version indicating an object was deleted.
Building Resilient Systems
Automatically copies objects between S3 buckets.
Building Resilient Systems
Replicates objects between buckets in the same AWS Region.
Building Resilient Systems
Replicates objects between buckets in different AWS Regions.
Building Resilient Systems
The S3 bucket where objects are originally uploaded.
Building Resilient Systems
The S3 bucket where replicated objects are stored.
Building Resilient Systems
V-R-D: Versioning for Reversal, Replication for Disaster. Versioning lets you go back, Replication moves it far.
Building Resilient Systems
For the exam, remember that S3 Versioning must be enabled on both source and destination buckets for replication to function. Replication does not replicate existing objects at the time of configuration, only new objects and updates.
Building Resilient Systems
Forgetting to enable versioning on both source and destination buckets for replication.
Building Resilient Systems
Assuming replication will copy existing objects automatically when first configured (it only copies new objects unless S3 Batch Replication is used).
Building Resilient Systems
Not understanding that a 'delete' operation on a versioned object creates a delete marker, rather than permanently removing the object, which can still be recovered.
Building Resilient Systems
Managing infrastructure through code, not manual processes.
Automated Deployments & Provisioning
AWS service for defining and provisioning infrastructure as code.
Automated Deployments & Provisioning
JSON/YAML file describing AWS resources and their properties.
Automated Deployments & Provisioning
A collection of AWS resources created and managed by CloudFormation.
Automated Deployments & Provisioning
Input values for a CloudFormation template at deployment.
Automated Deployments & Provisioning
Values returned by a stack, usable by other stacks/applications.
Automated Deployments & Provisioning
A preview of proposed changes to a running CloudFormation stack.
Automated Deployments & Provisioning
Think 'Cloud' for 'Code' and 'Formation' for 'Forming' your infrastructure. CloudFormation forms your cloud resources from code!
Automated Deployments & Provisioning
The exam frequently asks about the benefits of CloudFormation (consistency, automation, repeatability, version control) and the core components of a template (Resources, Parameters, Outputs). Know that CloudFormation manages the lifecycle of resources within a stack.
Automated Deployments & Provisioning
Forgetting to delete a stack after testing, leading to unexpected costs.
Automated Deployments & Provisioning
Making manual changes to resources managed by CloudFormation, causing 'drift' and deployment failures.
Automated Deployments & Provisioning
Not using Change Sets to preview updates, which can lead to unintended resource modifications or deletions.
Automated Deployments & Provisioning
Logical grouping of CodeDeploy deployments.
Automated Deployments & Provisioning
Set of target instances or Lambda functions.
Automated Deployments & Provisioning
YAML file defining deployment actions and hooks.
Automated Deployments & Provisioning
Scripts run at specific stages of a deployment.
Automated Deployments & Provisioning
Updates application on existing instances.
Automated Deployments & Provisioning
Deploys to new instances, shifts traffic for zero downtime.
Automated Deployments & Provisioning
Defines how CodeDeploy performs a deployment.
Automated Deployments & Provisioning
An APPlication has a DEPLOYMENT GROUP, which uses an APPSPEC file for LIFECYCLE HOOKS, following a DEPLOYMENT CONFIGURATION. Think: 'App Group Specs Hooks Config'.
Automated Deployments & Provisioning
The exam frequently tests your understanding of CodeDeploy's deployment types (In-place vs. Blue/Green) and their use cases, as well as the purpose of the AppSpec file and lifecycle hooks. Pay close attention to how CodeDeploy integrates with other services like EC2, Lambda, and load balancers.
Automated Deployments & Provisioning
Forgetting to include or correctly format the AppSpec file, leading to failed deployments.
Automated Deployments & Provisioning
Using 'AllAtOnce' for critical production deployments without proper testing or fallback mechanisms, causing significant downtime.
Automated Deployments & Provisioning
Not understanding the difference between In-place and Blue/Green deployments and choosing the wrong strategy for the business requirement.
Automated Deployments & Provisioning
Software installed on instances to enable SSM functionality.
Automated Deployments & Provisioning
JSON/YAML file defining actions for Systems Manager.
Automated Deployments & Provisioning
Securely execute commands on fleets of instances.
Automated Deployments & Provisioning
Maintain desired configuration on managed instances.
Automated Deployments & Provisioning
Automate patching of operating systems and applications.
Automated Deployments & Provisioning
Secure and auditable browser-based shell access.
Automated Deployments & Provisioning
Secure storage for configuration data and secrets.
Automated Deployments & Provisioning
SSM: 'S'ecure 'S'ystem 'M'anagement – it's all about managing your systems securely and at scale.
Automated Deployments & Provisioning
On the exam, look for keywords like 'remote execution', 'desired state', 'patching', or 'secure shell access without SSH keys' to identify Systems Manager as the solution. Remember SSM Agent must be installed on instances.
Automated Deployments & Provisioning
Forgetting to install the SSM Agent on instances you want to manage.
Automated Deployments & Provisioning
Not configuring appropriate IAM permissions for Systems Manager to perform actions.
Automated Deployments & Provisioning
Confusing the purpose of different SSM Document types (e.g., using a Command document for a complex workflow better suited for Automation documents).
Automated Deployments & Provisioning
Cloud execution model where providers manage servers; users focus on code.
Automated Deployments & Provisioning
Architecture where components react to events, not continuous polling.
Automated Deployments & Provisioning
Serverless workflow service to orchestrate distributed applications.
Automated Deployments & Provisioning
A workflow defined in Step Functions, describing steps and transitions.
Automated Deployments & Provisioning
A step in a Step Functions workflow that performs work, e.g., invokes Lambda.
Automated Deployments & Provisioning
Data passed between states in a Step Functions workflow.
Automated Deployments & Provisioning
L-S-O: Lambda for Logic, Step Functions for Orchestration. Remember the order and purpose!
Automated Deployments & Provisioning
For the exam, understand that Lambda is for individual, stateless functions, while Step Functions orchestrates stateful, multi-step workflows. Look for keywords like 'event-driven compute' for Lambda and 'orchestrate complex workflows' or 'manage state' for Step Functions.
Automated Deployments & Provisioning
Trying to build complex, stateful workflows entirely within a single Lambda function, leading to unwieldy code and poor error handling.
Automated Deployments & Provisioning
Not implementing proper error handling and retry mechanisms in Step Functions, causing workflows to fail completely on transient issues.
Automated Deployments & Provisioning
Overlooking the cost implications of long-running or frequently invoked Lambda functions, especially without proper memory/duration optimization.
Automated Deployments & Provisioning
Logically isolated virtual network in AWS.
Networking & Content Delivery
A range of IP addresses within a VPC.
Networking & Content Delivery
Subnet with a route to an Internet Gateway.
Networking & Content Delivery
Subnet without a direct route to an Internet Gateway.
Networking & Content Delivery
Rules that determine where network traffic is directed.
Networking & Content Delivery
Connects your VPC to the internet.
Networking & Content Delivery
Stateless firewall for controlling subnet traffic.
Networking & Content Delivery
Classless Inter-Domain Routing notation for IP address ranges.
Networking & Content Delivery
NACLs are 'Nasty' because they're 'Stateless' – you have to tell them everything twice (inbound and outbound).
Networking & Content Delivery
The exam often tests the difference between NACLs and Security Groups. Remember that NACLs are stateless and operate at the subnet level, while Security Groups are stateful and operate at the instance level. Pay attention to questions involving explicit DENY rules or the need to allow both inbound and outbound traffic for responses.
Networking & Content Delivery
Confusing NACLs (stateless, subnet-level) with Security Groups (stateful, instance-level).
Networking & Content Delivery
Forgetting to add an explicit outbound rule in a NACL for response traffic, leading to one-way communication.
Networking & Content Delivery
Not associating a subnet with a route table, causing it to implicitly use the main route table, which might not have the desired routes.
Networking & Content Delivery
Encrypts traffic between on-premises networks and AWS VPCs over the internet.
Networking & Content Delivery
Managed service for secure remote user access to AWS and on-premises resources.
Networking & Content Delivery
Dedicated, private network connection from on-premises to AWS, bypassing the internet.
Networking & Content Delivery
Connects two VPCs directly using private IP addresses; non-transitive.
Networking & Content Delivery
Central hub for connecting multiple VPCs and on-premises networks; transitive.
Networking & Content Delivery
Represents your on-premises VPN device in an AWS Site-to-Site VPN setup.
Networking & Content Delivery
AWS side of a Site-to-Site VPN connection, attached to a VPC.
Networking & Content Delivery
VPN: Virtual Private Network. Direct Connect: Dedicated Connection. Peering: Point-to-point. Transit Gateway: Traffic Hub.
Networking & Content Delivery
For the exam, distinguish between Site-to-Site VPN (network-to-network over internet) and Client VPN (user-to-network). Remember Direct Connect offers dedicated private connectivity, bypassing the internet, and Transit Gateway solves the non-transitive routing limitation of VPC Peering.
Networking & Content Delivery
Confusing Site-to-Site VPN (network-to-network) with Client VPN (user-to-network).
Networking & Content Delivery
Assuming VPC peering is transitive; it is not, necessitating Transit Gateway for complex mesh networks.
Networking & Content Delivery
Underestimating the lead time for Direct Connect provisioning; it's not an instant setup like a VPN.
Networking & Content Delivery
Domain Name System; translates domain names to IP addresses.
Networking & Content Delivery
AWS's highly available and scalable cloud DNS web service.
Networking & Content Delivery
Container for records that define how to route traffic for a domain.
Networking & Content Delivery
Maps a domain/subdomain to an IP address or other resource.
Networking & Content Delivery
Special Route 53 record type pointing to AWS resources.
Networking & Content Delivery
Determines how Route 53 responds to DNS queries (e.g., Failover, Latency).
Networking & Content Delivery
Monitors the health of resources to enable failover or traffic shifting.
Networking & Content Delivery
Time To Live; duration DNS resolvers cache a record before querying again.
Networking & Content Delivery
Remember '53' for Route 53: 'Five' types of routing (Failover, IP-based, View, Elastic, Simple) and 'Three' key features (Traffic management, Health checks, Resource records).
Networking & Content Delivery
The exam often tests the differences between various Route 53 routing policies. Memorize the purpose of Simple, Failover, Latency-based, Geolocation, and Weighted routing. Understand that Alias records can point to AWS resources and are free for DNS queries.
Networking & Content Delivery
Confusing CNAME records with Alias records: CNAMEs cannot be used for the root domain (e.g., example.com), but Alias records can.
Networking & Content Delivery
Forgetting to update Name Servers: If you transfer a domain to Route 53, you must update the domain's name servers at your registrar to point to Route 53's name servers.
Networking & Content Delivery
Incorrectly configuring health checks: Ensure health checks are configured correctly for the failover routing policy to work as expected.
Networking & Content Delivery
AWS CDN for fast, secure content delivery.
Networking & Content Delivery
Global data centers where CloudFront caches content.
Networking & Content Delivery
The source of content for CloudFront (e.g., S3 bucket).
Networking & Content Delivery
Recommended method for CloudFront to securely access S3.
Networking & Content Delivery
Legacy method for CloudFront to securely access S3.
Networking & Content Delivery
Storing copies of content closer to users for faster delivery.
Networking & Content Delivery
A CloudFront configuration that defines how content is delivered.
Networking & Content Delivery
Process to remove cached content from CloudFront edge locations.
Networking & Content Delivery
CloudFront is like a 'Global Fast Food Chain' for your data. Edge Locations are the local restaurants, caching popular items (your content) for quick delivery to nearby customers (users).
Networking & Content Delivery
The exam often tests the difference between OAI and OAC, emphasizing OAC as the current best practice for securing S3 origins. Be prepared for questions about cache hit ratio, TTL settings, and how CloudFront integrates with other AWS services like S3 and Route 53.
Networking & Content Delivery
Forgetting to update S3 bucket policies after configuring OAC/OAI, leading to 'Access Denied' errors.
Networking & Content Delivery
Not setting appropriate cache TTLs, causing users to see stale content or frequent origin fetches.
Networking & Content Delivery
Using OAI for new distributions instead of the more secure and feature-rich OAC.
Networking & Content Delivery
An entity representing a person or service for AWS interaction.
Security & Compliance Deep Dive
An AWS identity with temporary permissions for services or users.
Security & Compliance Deep Dive
A JSON document defining permissions for AWS resources.
Security & Compliance Deep Dive
Security principle: grant only necessary permissions for a task.
Security & Compliance Deep Dive
Multi-Factor Authentication, adding a second verification step.
Security & Compliance Deep Dive
Part of an IAM role, specifying who can assume the role.
Security & Compliance Deep Dive
Policy attached to an IAM user, group, or role.
Security & Compliance Deep Dive
R-U-P-S: Roles for Services, Users for People, Policies for Permissions, Security is paramount!
Security & Compliance Deep Dive
The exam will often test your understanding of policy evaluation logic, especially explicit Deny vs. Allow. Remember: an explicit Deny always overrides any Allow.
Security & Compliance Deep Dive
Using the root user for daily operational tasks instead of dedicated IAM users.
Security & Compliance Deep Dive
Attaching broad administrative policies directly to individual users instead of using groups or specific roles.
Security & Compliance Deep Dive
Not enabling MFA for privileged IAM users, leaving accounts vulnerable.
Security & Compliance Deep Dive
A virtual firewall for an EC2 instance, controlling inbound/outbound traffic.
Security & Compliance Deep Dive
A stateless firewall for a subnet, controlling all traffic in/out.
Security & Compliance Deep Dive
Return traffic is automatically allowed once initial traffic is permitted.
Security & Compliance Deep Dive
Both inbound and outbound traffic must be explicitly allowed by rules.
Security & Compliance Deep Dive
Controls traffic coming INTO an instance or subnet.
Security & Compliance Deep Dive
Controls traffic leaving an instance or subnet.
Security & Compliance Deep Dive
SGs are 'Smart Guardians' (stateful, instance-level), NACLs are 'Nasty Cops' (stateless, subnet-level, can deny).
Security & Compliance Deep Dive
Remember that Security Groups are stateful and operate at the instance level, while Network ACLs are stateless and operate at the subnet level. This distinction is a frequent exam topic, especially when comparing their rule processing and default behaviors.
Security & Compliance Deep Dive
Confusing stateful (Security Groups) with stateless (Network ACLs).
Security & Compliance Deep Dive
Forgetting that Network ACLs process rules by number, and the first match wins, potentially overriding later rules.
Security & Compliance Deep Dive
Not explicitly allowing outbound traffic in Network ACLs when inbound is allowed (due to their stateless nature).
Security & Compliance Deep Dive
Encrypting data when it is stored persistently on a storage device.
Security & Compliance Deep Dive
Encrypting data as it moves between systems over a network.
Security & Compliance Deep Dive
Managed service for creating and controlling encryption keys for AWS services.
Security & Compliance Deep Dive
Dedicated, single-tenant hardware security modules for stringent compliance.
Security & Compliance Deep Dive
Cryptographic protocol securing network communications, successor to SSL.
Security & Compliance Deep Dive
Encryption key in KMS where you control key policies and lifecycle.
Security & Compliance Deep Dive
Server-side encryption for S3 using AWS KMS-managed keys.
Security & Compliance Deep Dive
US government computer security standard for cryptographic modules.
Security & Compliance Deep Dive
To remember the difference: 'KMS is for 'Keys Managed Simply,' CloudHSM is for 'Compliance's Hardcore Security Modules.'
Security & Compliance Deep Dive
The exam often tests your understanding of when to use KMS versus CloudHSM. Remember KMS is for general-purpose, managed key encryption, while CloudHSM is for dedicated, single-tenant hardware for strict compliance needs. Look for keywords like 'dedicated HSM' or 'FIPS 140-2 Level 3' for CloudHSM.
Security & Compliance Deep Dive
Forgetting to encrypt both at rest and in transit, leaving a vulnerability.
Security & Compliance Deep Dive
Using AWS-managed keys when compliance requires more control (CMKs or CloudHSM).
Security & Compliance Deep Dive
Not enabling default encryption for services like S3 buckets or EBS volumes.
Security & Compliance Deep Dive
Monitors and records AWS resource configurations.
Security & Compliance Deep Dive
Evaluates AWS resource configurations for compliance.
Security & Compliance Deep Dive
Aggregates and prioritizes security findings.
Security & Compliance Deep Dive
Intelligent threat detection service for AWS accounts.
Security & Compliance Deep Dive
A security alert or non-compliance event.
Security & Compliance Deep Dive
Records API calls and events in your AWS account.
Security & Compliance Deep Dive
To CONFIGURE compliance, GUARD for threats, and HUB all your findings together!
Security & Compliance Deep Dive
Memorize the primary purpose of each service: Config for configuration compliance, GuardDuty for threat detection, and Security Hub for aggregating security findings. The exam often presents scenarios where you must choose the best service for a specific problem.
Security & Compliance Deep Dive
Confusing Config's role (configuration compliance) with GuardDuty's role (threat detection).
Security & Compliance Deep Dive
Assuming Security Hub performs its own detection instead of aggregating findings from other services.
Security & Compliance Deep Dive
Not understanding that these services often work best when integrated, not in isolation.
Security & Compliance Deep Dive
Pay-as-you-go, flexible, highest cost EC2 option.
Optimizing Costs & Performance
Commitment for 1 or 3 years, significant discount for steady workloads.
Optimizing Costs & Performance
Flexible commitment for consistent compute usage across services.
Optimizing Costs & Performance
Bid on unused EC2 capacity, up to 90% discount, interruptible.
Optimizing Costs & Performance
Matching resource capacity to actual workload requirements.
Optimizing Costs & Performance
Automatically moves data between access tiers based on patterns.
Optimizing Costs & Performance
Automates transitions or expiration of S3 objects.
Optimizing Costs & Performance
On-demand, auto-scaling configuration for Amazon Aurora.
Optimizing Costs & Performance
Think 'R-S-S' for EC2 savings: Reserved, Spot, Savings. Each offers a different way to save big!
Optimizing Costs & Performance
The exam often tests your ability to choose the MOST cost-effective option for a given scenario. Pay close attention to keywords like 'interruptible,' 'steady-state,' 'unpredictable,' 'archival,' and 'infrequent access' to guide your choice of EC2 purchasing model or S3 storage class.
Optimizing Costs & Performance
Using On-Demand instances for predictable, long-running workloads instead of Reserved Instances or Savings Plans.
Optimizing Costs & Performance
Storing rarely accessed data in S3 Standard instead of a lower-cost S3 Infrequent Access or Glacier class.
Optimizing Costs & Performance
Not deleting idle or unused EC2 instances, RDS databases, or old S3 snapshots, which continue to incur charges.
Optimizing Costs & Performance
Increasing the resources (CPU, memory) of an existing instance.
Optimizing Costs & Performance
Adding more instances to distribute workload.
Optimizing Costs & Performance
An EBS/RDS storage type guaranteeing consistent I/O performance.
Optimizing Costs & Performance
A copy of an RDS database used to offload read traffic.
Optimizing Costs & Performance
An RDS tool for monitoring and analyzing database performance.
Optimizing Costs & Performance
Data points representing resource utilization and application performance.
Optimizing Costs & Performance
A performance limitation caused by slow disk or network input/output.
Optimizing Costs & Performance
To remember EC2/RDS tuning, think 'MONITOR, DIAGNOSE, OPTIMIZE, SCALE'. It's a cycle, not a one-time fix!
Optimizing Costs & Performance
The exam often tests your ability to choose the most cost-effective and appropriate scaling strategy. Look for keywords like 'read-heavy workload' (suggests Read Replicas), 'intermittent spikes' (Auto Scaling), or 'consistent high CPU' (scale up or optimize).
Optimizing Costs & Performance
Immediately scaling up without first investigating and optimizing application or database queries, leading to unnecessary cost increases.
Optimizing Costs & Performance
Ignoring disk I/O metrics for I/O-intensive applications, assuming CPU or memory is always the bottleneck.
Optimizing Costs & Performance
Not using Read Replicas for read-heavy RDS workloads, causing the primary instance to become overloaded.
Optimizing Costs & Performance
Monitors metrics against thresholds, triggers actions on state change.
Optimizing Costs & Performance
Near real-time stream of system events for automation.
Optimizing Costs & Performance
Customizable visual interface for monitoring resources.
Optimizing Costs & Performance
AWS service for building event-driven applications, supersedes CloudWatch Events.
Optimizing Costs & Performance
MALED: Metrics, Alarms, Logs, Events, Dashboards – the core CloudWatch components.
Optimizing Costs & Performance
The exam often tests your understanding of which CloudWatch component is best suited for a specific task: metrics for raw data, alarms for proactive alerts, logs for centralized logging and analysis, and events for automation. Remember the 15-month metric retention.
Optimizing Costs & Performance