AWS Certified Developer – Associate (DVA-C02) flashcards
135 free flashcards. Tap a card to flip it.
S3 Access Control & Private Access
Flip cardS3 bucket policies control access permissions, while S3 Gateway VPC Endpoints provide private, secure access to S3 from within a VPC, avoiding the public internet.
- Bucket policies define who can access S3 resources and what actions they can perform.
- Gateway VPC Endpoints route S3 traffic over AWS's private network.
- Endpoints are free of charge.
Memory trick: Bucket policies guard the gate, Gateway Endpoints keep it private.
Amazon S3
Flip cardAn object storage service that offers industry-leading scalability, data availability, security, and performance.
- Stores data as objects in buckets.
- Highly durable (11 nines) and available.
- Supports various storage classes for cost optimization.
- Accessed via HTTP/HTTPS endpoints.
Memory trick: S3 is the simple, scalable solution for storing all your stuff.
AWS Systems Manager Parameter Store
Flip cardA capability of AWS Systems Manager that provides secure, hierarchical storage for configuration data management and secrets. It allows you to store data such as passwords, database strings, and license codes as parameter values.
- Secure storage for configuration and secrets
- Supports encryption with KMS
- Provides versioning and hierarchical organization
Memory trick: Parameter Store keeps config secure and versioned.
CloudWatch Alarm Statistics
Flip cardCloudWatch alarms evaluate metrics based on a chosen statistic (e.g., `Average`, `Sum`, `Minimum`, `Maximum`, `SampleCount`). Selecting the correct statistic is crucial for an alarm to accurately reflect the desired behavior of a metric and trigger reliably.
- `Sum` is often used for count-based metrics (e.g., `NumberOfMessagesSent`, `Errors`).
- `Average` is used for rate or duration metrics (e.g., `Latency`, `CPUUtilization`).
- Incorrect statistic can lead to alarms not triggering or triggering falsely.
Memory trick: CloudWatch Alarm Silent: Check the Statistic, Period, and Threshold, or it's a fright.
ECS Task IAM Roles
Flip cardECS Task IAM Roles allow you to specify an IAM role that a task can use to make API requests to authorized AWS services. This provides temporary, frequently rotated credentials to the container, eliminating the need to embed or distribute static credentials.
- Provides temporary credentials to individual tasks.
- Eliminates static credential management.
- Adheres to the principle of least privilege.
- Configured in the ECS task definition.
Memory trick: Fargate Tasks get their own Role, no keys in the container's soul.
SSM get_parameter (WithDecryption)
Flip cardThe `get_parameter` API call with `WithDecryption=True` in AWS Systems Manager Parameter Store automatically decrypts encrypted parameters using AWS KMS.
- Requires the calling IAM role to have `kms:Decrypt` permissions.
- Simplifies retrieval of sensitive, encrypted configuration data.
- Parameter Store handles the KMS interaction transparently.
Memory trick: To 'get' a 'parameter' that's a 'secret', remember to ask for 'Decryption' to complete the feat.
SQS Visibility Timeout
Flip cardThe SQS visibility timeout is the period during which a message is hidden from other consumers after it has been received by one consumer. If the consumer fails to delete the message before the timeout expires, the message becomes visible again and can be received by another consumer.
- Prevents multiple consumers from processing the same message simultaneously.
- Must be longer than the message processing time to avoid duplicate processing.
- Can be extended via ChangeMessageVisibility API call if processing takes longer than expected.
Memory trick: SQS Duplicates: Visibility Timeout is the key; if too short, messages flee (back to queue).
Principle of Least Privilege
Flip cardA security best practice that states that any user, program, or process should be given only the minimum privileges necessary to perform its task.
- Reduces the attack surface.
- Limits the impact of security breaches.
- Essential for secure application development in AWS.
Memory trick: Least Privilege: Only the keys you need for the doors you open.
Lambda Static Egress IP
Flip cardTo provide a static, known outbound IP address for AWS Lambda functions running in a VPC, configure them in a private subnet and route their outbound traffic through a NAT Gateway with an associated Elastic IP address.
- Lambda in VPC gets private IP; needs NAT Gateway for internet access.
- NAT Gateway's Elastic IP provides the static public egress IP.
- Required for whitelisting with external services.
Memory trick: NAT Gateway's EIP is Lambda's Exit Point.
Lambda IAM Role
Flip cardAn IAM role associated with an AWS Lambda function that grants it the necessary permissions to interact with other AWS services.
- Provides secure access without embedding credentials.
- Adheres to the principle of least privilege.
- Managed by IAM policies attached to the role.
Memory trick: Roles are the key to secure Lambda access, protecting your functions from unauthorized calls.
DynamoDB Fine-Grained Access with Cognito
Flip cardAmazon DynamoDB can enforce fine-grained access control for user-specific data by combining IAM policies with attributes provided by Amazon Cognito Identity Pools, such as the authenticated user's ID.
- Cognito Identity Pools provide temporary AWS credentials.
- IAM policies attached to the Identity Pool role can use conditions.
- Conditions can restrict DynamoDB item access based on user ID or other attributes.
Memory trick: Cognito with IAM Secures DynamoDB Data.
SQS Server-Side Encryption (SSE-SQS)
Flip cardSSE-SQS encrypts messages at rest in Amazon SQS queues using SQS-managed encryption keys. These keys are automatically rotated by AWS and offer a fully managed encryption solution.
- Uses SQS-managed keys.
- Keys are automatically rotated by AWS.
- Transparent encryption and decryption for applications.
Memory trick: SQS-Managed Keys Keep Messages Quietly Secure.
EC2 Instance Profiles & IAM Roles
Flip cardAn EC2 instance profile is a container for an IAM role that allows EC2 instances to obtain temporary, programmatic access to AWS services using the instance metadata service.
- Provides temporary, auto-rotated credentials.
- Eliminates the need to store long-term credentials on the instance.
- Credentials are retrieved via the Instance Metadata Service (IMDS).
Memory trick: Instance Roles give temporary keys via IMDS.
DynamoDB On-demand Scaling Limits
Flip cardWhile DynamoDB On-demand capacity mode automatically adjusts to accommodate workload, it isn't instantaneous. It has an initial burst capacity and scales up by doubling the previous peak throughput. A sudden, sustained spike significantly exceeding this scaling rate can still lead to `ProvisionedThroughputExceededException`.
- Scales automatically, but not infinitely fast or without limits.
- Initial burst capacity is available.
- Scaling rate is based on previous peak traffic (doubles the highest previous peak within 30 minutes).
- Sudden, large, sustained increases can still cause throttling.
Memory trick: On-demand Throttling: Even auto-scaling has a Burst Limit, especially if traffic's a sudden hit.
S3 Server-Side Encryption with KMS (SSE-KMS)
Flip cardEncrypts S3 objects using keys stored and managed in AWS Key Management Service (KMS). This allows customers to have control over the encryption keys and audit their usage.
- Uses AWS KMS Customer Master Keys (CMKs)
- Keys are customer-managed within KMS
- Key usage is auditable via CloudTrail
Memory trick: S3 encryption has key options: S3, KMS, or Customer.
Amazon SQS FIFO Queue
Flip cardAmazon SQS FIFO (First-In, First-Out) queues guarantee that messages are processed exactly once, in the exact order that they are sent and received.
- Exactly-once processing.
- Strict message ordering.
- Message deduplication.
Memory trick: For ordered and exactly once, FIFO is the SQS dance.
SQS Server-Side Encryption (SSE)
Flip cardAmazon SQS Server-Side Encryption (SSE) uses AWS Key Management Service (KMS) to encrypt messages at rest within SQS queues.
- Encrypts message bodies stored in SQS queues.
- Uses AWS KMS customer master keys (CMKs).
- Transparent to the client application.
Memory trick: SQS SSE with KMS keeps your messages safe at rest.
Amazon Simple Email Service (SES)
Flip cardA flexible, scalable, and cost-effective email platform that enables developers to send email from any application.
- Transactional, marketing, and bulk email.
- High deliverability rates.
- Supports dynamic content.
Memory trick: For application emails, SES is the best choice, it entails.
Amazon SQS Standard Queue
Flip cardA highly scalable, fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications. It offers at-least-once delivery and message retention.
- Decouples producers and consumers.
- At-least-once message delivery.
- Messages retained for up to 14 days.
- Scales automatically with demand.
Memory trick: SQS 'Saves' your messages for 'Scalable' processing.
Amazon DynamoDB for Session Data
Flip cardAmazon DynamoDB is a fully managed NoSQL database service that delivers single-digit millisecond performance at any scale, making it ideal for storing transient or persistent user session data due to its low-latency, high availability, and automatic scaling capabilities.
- Single-digit millisecond latency.
- Scales to millions of requests/second.
- Fully managed, serverless.
- Highly available and durable.
Memory trick: DynamoDB 'Drives' sessions 'Directly' with speed.
RDS In-Transit Encryption (SSL/TLS)
Flip cardTo encrypt data in transit between an application and an Amazon RDS database, the application must be configured to establish an SSL/TLS connection to the database endpoint.
- RDS supports SSL/TLS for all database engines.
- Application's database driver needs to be configured for SSL/TLS.
- Protects data from eavesdropping during network transmission.
Memory trick: SSL/TLS Secures RDS Traffic.
Amazon DynamoDB
Flip cardA fully managed, serverless NoSQL database service that supports key-value and document data models, offering single-digit millisecond performance at any scale.
- NoSQL database (key-value and document)
- Serverless and scales automatically
- Single-digit millisecond latency
Memory trick: NoSQL for JSON needs, DynamoDB's the speed.
ElastiCache for Session Data
Flip cardAmazon ElastiCache, particularly with Redis, is a managed in-memory data store service used for caching, session management, and real-time analytics.
- Provides high performance and low latency.
- Supports encryption at rest and in transit (TLS).
- Ideal for temporary, session-specific data that requires fast access and expiration.
Memory trick: ElastiCache Redefines Speedy Sessions Securely.
EBS Encryption with KMS CMKs
Flip cardEncrypting Amazon EBS volumes using Customer Managed Keys (CMKs) in AWS Key Management Service (KMS) provides granular control over encryption keys, including policies, audit trails, and rotation.
- Customer manages key policies and usage permissions.
- Supports automatic key rotation for CMKs.
- Provides a detailed audit trail via CloudTrail.
Memory trick: CMK gives you C-ontrol over M-y K-eys for EBS.
S3 Bucket Policy for Public Read, Restricted Write
Flip cardAn S3 bucket policy is an access policy language used to grant or deny permissions to specific AWS principals for a bucket and its objects. It's ideal for setting public read access while restricting administrative actions.
- Centrally manages permissions for the entire bucket.
- Can grant public read access (e.g., `s3:GetObject`).
- Can explicitly deny write/delete actions for unauthorized users.
Memory trick: Bucket Policy Protects Public Content Prudently.
AWS Secrets Manager for DB Credentials
Flip cardAWS Secrets Manager helps you protect secrets needed to access your applications, services, and IT resources. The service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Automated secret rotation for RDS, Redshift, DocumentDB.
- Integration with Lambda for secure retrieval.
- Fine-grained access control using IAM.
Memory trick: Secrets Manager Rotates Credentials Safely.
SQS Server-Side Encryption (SSE-KMS)
Flip cardEncrypts messages at rest within Amazon SQS queues using AWS Key Management Service (KMS) customer master keys (CMKs). This provides central management and auditing capabilities for the encryption keys.
- Encrypts messages at rest in SQS
- Uses AWS KMS CMKs for encryption
- Provides auditable key usage via CloudTrail
Memory trick: SQS talks securely with KMS keys.
Cognito User Pools & Identity Pools (Federated Identities)
Flip cardAmazon Cognito User Pools manage user directories for sign-up and sign-in. Amazon Cognito Identity Pools (Federated Identities) enable you to grant authenticated (or unauthenticated) users access to your AWS resources.
- User Pools handle authentication and social logins.
- Identity Pools provide temporary AWS credentials.
- Allows mobile/web apps to directly access AWS services securely.
Memory trick: User Pools Authenticate, Identity Pools Permit.
Amazon Cognito Identity Pools
Flip cardAmazon Cognito Identity Pools (Federated Identities) enable you to grant your users (authenticated by User Pools or third-party identity providers) temporary, limited-privilege AWS credentials to access AWS resources directly, such as Amazon S3 or DynamoDB.
- Authorizes users to access AWS services.
- Provides temporary, limited-privilege AWS credentials.
- Integrates with Cognito User Pools and social IDPs (Google, Facebook).
- Supports unauthenticated access for guest users.
Memory trick: Identity 'Pools' 'Provide' 'Permissions' for 'Private' access.
S3 Default Encryption with KMS CMK
Flip cardAmazon S3 default encryption allows you to configure a bucket to automatically encrypt all new objects uploaded to it using a specified server-side encryption method, including AWS KMS with a Customer Managed Key (CMK), ensuring data-at-rest compliance without requiring client-side configuration.
- Automatically encrypts new objects on upload.
- Can specify AWS KMS CMK for encryption.
- Simplifies client-side code (no need for `x-amz-server-side-encryption` header).
- Can be combined with bucket policies for strict enforcement.
Memory trick: Default 'Encryption' with KMS 'Ensures' S3 'Security'.
Lambda VPC Connectivity
Flip cardWhen a Lambda function is configured to run inside a VPC, it gets an Elastic Network Interface (ENI) in the specified subnets. Its network access is then governed by the security groups attached to that ENI and the network configuration of the VPC.
- Lambda ENIs have their own security groups.
- Communication with resources in the same VPC is via private IP addresses.
- Requires a NAT Gateway in private subnets for outbound internet access.
Memory trick: Lambda's VPC woes: Security Groups are the gatekeepers, both ways.
Kinesis IteratorAgeMilliseconds
Flip cardThe `IteratorAgeMilliseconds` metric for an Amazon Kinesis Data Stream consumer (like Lambda) indicates how far behind the consumer is from the tip of the stream. A steadily increasing value means the consumer is falling behind the data producers.
- Measures the age of the last record successfully processed by the consumer.
- High values indicate bottlenecks in consumer processing.
- Can be caused by insufficient consumer concurrency, processing errors, or inefficient batching.
Memory trick: Kinesis Age: If the Iterator is old, the consumer's too slow, or not enough shards to go.
Cognito Identity Pools (Federated Identities)
Flip cardAmazon Cognito Identity Pools provide temporary AWS credentials to users who have been authenticated by various identity providers (e.g., Cognito User Pools, Facebook, Google, SAML, or custom IdPs), allowing them to access AWS services.
- Facilitates federation from external IdPs to AWS.
- Exchanges IdP tokens for temporary AWS credentials.
- Allows authenticated users to assume IAM roles for AWS resource access.
- Supports both authenticated and unauthenticated (guest) access.
Memory trick: Custom IdP users need Identity Pools to get their AWS access keys.
AWS Batch
Flip cardA fully managed service that allows you to run batch computing workloads of any scale efficiently on AWS, provisioning and managing compute resources automatically.
- Manages compute resources, job scheduling, and queues.
- Supports Docker containers.
- Ideal for long-running, resource-intensive batch jobs.
Memory trick: Batch handles big jobs, Lambda for quick tasks.
Lambda Provisioned Concurrency
Flip cardA feature that keeps function execution environments initialized and ready to respond to requests, reducing cold start latency for critical serverless applications.
- Pre-initializes a specified number of execution environments.
- Eliminates cold start latency for provisioned environments.
- You pay for the configured concurrency even when idle.
Memory trick: Provisioned Concurrency gets Lambda ready before the call.
Lambda Global Initialization
Flip cardIn AWS Lambda, initializing resources like AWS SDK clients, database connections, or common variables outside the main handler function allows them to persist and be reused across multiple invocations of the same execution environment, reducing 'warm start' latency and improving performance.
- Code outside handler runs once per execution environment spin-up.
- Reduces 'warm start' latency.
- Optimizes resource utilization.
- Avoids redundant setup for subsequent invocations.
Memory trick: Global client 'Gets' Lambda 'Going' 'Faster'.
Container Memory Troubleshooting
Flip cardTroubleshooting container crashes related to memory often involves distinguishing between insufficient allocated resources and inefficient application memory usage (e.g., memory leaks). Profiling tools are key for diagnosing application-specific memory issues.
- High memory spikes followed by OOM (Out Of Memory) errors are indicative of application-level issues.
- Container orchestration platforms (like Fargate/ECS) terminate tasks that exceed their memory limits.
- Memory profiling helps identify leaks, inefficient data structures, or excessive allocations within the application.
Memory trick: Fargate Crash: Memory spikes hint at a leak; Profile to find the source and make it sleek.
DynamoDB Accelerator (DAX)
Flip cardA fully managed, highly available, in-memory cache for Amazon DynamoDB that delivers up to a 10x performance improvement for read-heavy workloads.
- Reduces read latency from milliseconds to microseconds.
- Compatible with existing DynamoDB API calls.
- Automatically scales to meet demand.
Memory trick: DAX gives DynamoDB a speed boost for rapid reads.
DynamoDB for Session Data
Flip cardAmazon DynamoDB is an ideal choice for storing user session data due to its high performance, scalability, low latency, and managed nature.
- Supports high-volume, low-latency key-value access.
- Automatically scales to handle millions of users and requests.
- Provides high availability and durability.
- Supports secondary indexes for flexible query patterns.
Memory trick: When 'Dynamic' sessions need 'DB' storage, 'DynamoDB' is the clear choice.
S3 SSE-C
Flip cardServer-Side Encryption with Customer-Provided Keys (SSE-C) for Amazon S3 allows customers to provide their own encryption keys for S3 to use during object operations.
- Customer manages and provides encryption keys.
- Key must be provided with every PUT and GET request.
- S3 does not store the customer-provided key.
Memory trick: C for Customer-Provided Keys, K for KMS, S3 for AWS-Managed.
DynamoDB GetItem
Flip cardThe GetItem operation in Amazon DynamoDB retrieves a single item from a table using its primary key.
- Retrieves a single item.
- Requires the full primary key.
- Most efficient way to retrieve specific items.
Memory trick: For a single DynamoDB item, GetItem is the secure rhythm.
Amazon S3 Server-Side Encryption with Customer-Provided Keys (SSE-C)
Flip cardSSE-C allows you to encrypt S3 objects using an encryption key that you provide. Amazon S3 manages the encryption and decryption process, but you manage the encryption key. AWS does not store your key.
- You manage the encryption key.
- Key must be provided with every PUT and GET request.
- AWS encrypts/decrypts but does not store the key.
- Requires HTTP headers: `x-amz-server-side-encryption-customer-key` and `x-amz-server-side-encryption-customer-key-MD5`.
Memory trick: SSE-C: Your Key, Your Rules, Every Request.
S3 Encryption with Customer-Managed Keys (SSE-KMS)
Flip cardServer-Side Encryption with AWS KMS Managed Keys (SSE-KMS) uses AWS KMS to manage the encryption keys for Amazon S3 objects, allowing customers to control key usage policies.
- Encryption keys are managed within AWS KMS.
- Provides an audit trail of key usage in CloudTrail.
- Suitable for compliance requirements needing customer control over keys.
Memory trick: KMS Keys Keep S3 Compliance.
S3 ETag for Data Integrity
Flip cardThe ETag (entity tag) returned by Amazon S3 for an object can be used to verify the integrity of the object. For single-part uploads, the ETag is the MD5 hash of the object data.
- Returned in the response headers of `PutObject`.
- For single-part uploads, ETag is the MD5 hash.
- For multi-part uploads, ETag is not a simple MD5 hash.
- Can be used by clients to verify data integrity.
Memory trick: The ETag is S3's stamp of integrity for your single-part upload.
Amazon Cognito Sync
Flip cardAn AWS service that enables you to synchronize user profile data and application-specific settings across mobile devices and the web.
- Synchronizes user data across multiple devices and platforms.
- Supports offline data access with automatic synchronization.
- Integrates with Amazon Cognito Identity Pools for user identity.
Memory trick: When user data needs to 'Sync' across 'Cognito' devices, 'Cognito Sync' is the specialized service.
DynamoDB Encryption at Rest
Flip cardAmazon DynamoDB provides encryption at rest for all tables, protecting sensitive data. You can choose different encryption key types, including AWS owned keys, AWS managed keys, and customer managed keys (CMKs) from AWS KMS.
- Always encrypted at rest by default.
- Supports AWS owned, AWS managed, and customer managed KMS keys.
- Choosing a CMK provides granular control and auditability over the encryption key.
Memory trick: DynamoDB's data rests encrypted, KMS keys its secret keeper.
Amazon RDS Proxy
Flip cardAmazon RDS Proxy is a fully managed, highly available database proxy for Amazon RDS that improves application scalability, resilience, and security by pooling and sharing database connections, handling failovers, and integrating with AWS Secrets Manager for credential rotation.
- Connection pooling and multiplexing.
- Reduces database load and improves scalability.
- Enhances resilience during database failovers.
- Integrates with AWS Secrets Manager for secure credential management.
Memory trick: RDS 'Proxy' 'Pools' 'Private' 'Paths' for 'Performance'.
Cognito for Enterprise & Social Federation
Flip cardAmazon Cognito User Pools manage user authentication for web and mobile apps, supporting SAML for enterprise and social IDPs. Amazon Cognito Identity Pools provide federated access to AWS resources for these authenticated users.
- User Pools support SAML, OpenID Connect, social IDPs.
- Identity Pools provide temporary AWS credentials.
- Ideal for consumer-facing applications with diverse user populations.
Memory trick: Cognito Unites Users and Identity for Global Access.
Amazon API Gateway
Flip cardA fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale.
- Acts as a 'front door' for applications to access backend services.
- Supports REST, HTTP, and WebSocket APIs.
- Integrates natively with AWS Lambda and other AWS services.
- Handles traffic management, authorization, access control, monitoring, and API version management.
Memory trick: API Gateway is the grand entrance for Lambda's serverless show.
S3 Multipart Upload Part Size
Flip cardWhen using Amazon S3 Multipart Upload, each part of the object, except the last part, must be at least 5 MB in size. The maximum number of parts is 10,000, and the maximum overall object size is 5 TB.
- Minimum part size (except last): 5 MB.
- Maximum part size: 5 GB.
- Maximum number of parts: 10,000.
- Maximum object size (assembled): 5 TB.
Memory trick: Five 'Mega' parts make a 'Multi' upload.
S3 Presigned URL Header Matching
Flip cardWhen generating an S3 presigned URL, if you include specific HTTP headers (such as `Content-Type`, `Content-Disposition`, `x-amz-meta-*`) in the signing process, the client must include those *exact* headers with their *exact* values in the subsequent actual HTTP request to S3. Any mismatch will result in an 'Access Denied' error.
- Ensures the signed request matches the actual request.
- Crucial for security and integrity of the signed operation.
- Content-Type mismatch is a very common pitfall.
Memory trick: Presigned URL's 'Access Denied': Check the Headers first, then Expiration.
CodeDeploy AppSpec Hook Timeout
Flip cardIn AWS CodeDeploy, each lifecycle event hook (e.g., `ApplicationStop`, `BeforeInstall`) defined in the `appspec.yml` file has an associated `timeout` setting. If a script executed during a hook exceeds this timeout, CodeDeploy terminates the script and marks the deployment as failed with a 'Script timed out' error.
- Configurable per hook in `appspec.yml`.
- Default timeout is 300 seconds (5 minutes) for most hooks.
- Essential to match the timeout with the expected execution time of the script.
Memory trick: CodeDeploy Timeout: The `appspec.yml` hook's patience is thin, just extend its `timeout` to win.
API Gateway Integration Timeout
Flip cardThe API Gateway integration timeout defines the maximum amount of time API Gateway will wait for a backend integration (e.g., Lambda function, HTTP endpoint) to respond. If the backend does not respond within this period, API Gateway returns a 504 Gateway Timeout error to the client.
- Default is 29 seconds for Lambda proxy integrations.
- Can be configured up to 29 seconds for most integrations.
- Must be carefully balanced with the backend service's expected response time.
Memory trick: API Gateway's 5XX: If the Integration Timeout is too short, the backend's too slow.
SQS Redrive Policy
Flip cardA configuration on an Amazon SQS queue that specifies how messages that fail to be processed by consumers should be handled, including automatic retries and moving to a Dead-Letter Queue (DLQ).
- Automatically retries messages that fail processing.
- Utilizes an exponential backoff delay before redelivering messages.
- Moves messages to a DLQ after a specified number of retries (`maxReceiveCount`).
Memory trick: SQS RedrivePolicy is the reliable road for retries.
Amazon SES
Flip cardA highly scalable, flexible, and cost-effective email service that enables developers to send mail from within any application.
- Supports sending various types of emails (transactional, marketing, notification).
- Requires sender identity verification (email address or domain).
- Provides features for email templates and sending metrics.
Memory trick: SES is the best choice when your app needs to 'Express' itself through email.
AWS Key Management Service (KMS)
Flip cardA managed service that makes it easy for you to create and control the encryption keys used to encrypt your data, providing centralized key management and strong security controls.
- Integrates with many AWS services for encryption.
- Provides auditable usage of encryption keys.
- Offers customer master keys (CMKs) for strong control.
Memory trick: KMS keeps keys safe, S3 holds secrets, together they secure data.
X-Ray Trace Context Propagation
Flip cardX-Ray trace context propagation ensures that a single trace ID follows a request across multiple services, including asynchronous communication patterns. This is achieved by passing trace headers (e.g., X-Amzn-Trace-Id) between services.
- Essential for end-to-end visibility in distributed systems.
- Often requires explicit configuration for asynchronous services like SQS or SNS.
- Prevents different parts of a request from appearing as separate traces.
Memory trick: X-Ray's Missing Piece: Trace Context is the glue, especially for async queues.
EC2 Instance Profiles and IAM Roles
Flip cardAn EC2 instance profile is a container for an IAM role that you can attach to an EC2 instance. This allows applications running on the instance to assume the role and gain temporary credentials for accessing other AWS services.
- Provides temporary, automatically rotated credentials.
- Eliminates the need to store static AWS credentials on the instance.
- Enforces the principle of least privilege.
Memory trick: Roles on Profiles Provide EC2 Power.
SNS and SQS Integration
Flip cardA common AWS pattern where Amazon SNS topics publish messages, and Amazon SQS queues subscribe to these topics to receive and durably store messages for processing by consumers.
- SNS provides fan-out capabilities.
- SQS provides message durability and decoupling for consumers.
- Enables asynchronous, event-driven architectures.
Memory trick: The Speaker (SNS) broadcasts, and Queues (SQS) reliably catch the messages.
Fargate Ephemeral Storage Encryption with CMK
Flip cardAWS Fargate tasks use ephemeral local storage that is not directly configurable for customer-managed key (CMK) encryption. To encrypt data on this storage with a CMK, the application must perform client-side encryption using AWS KMS.
- Fargate ephemeral storage is deleted when the task stops.
- Default Fargate encryption uses AWS-managed keys.
- Client-side encryption is necessary for CMK use on ephemeral storage.
Memory trick: Client-Side Code Secures Fargate's Ephemeral Cache with CMK.