AWS Certified Solutions Architect – Associate (SAA-C03) flashcards
115 free flashcards. Tap a card to flip it.
Reserved Instances on Dedicated Hosts
Flip cardReserved Instances can be purchased for Dedicated Hosts, providing significant cost savings for long-term, predictable usage of dedicated physical servers.
- Combines benefits of Dedicated Hosts (physical isolation) with RI cost savings.
- Ideal for licensing requirements that mandate dedicated hardware.
- Requires a 1-year or 3-year commitment.
- Offers substantial discounts compared to On-Demand Dedicated Hosts.
Memory trick: Reserved for Dedication, Reduces the Bill's Temptation.
AWS Same-Region Data Transfer Cost
Flip cardData transfer between AWS services within the same AWS Region is generally free of charge, or significantly cheaper than cross-region or internet data transfer.
- Inter-AZ data transfer within the same region is charged.
- Data transfer between services (e.g., S3 to EC2) within the same region is often free.
- Cross-region data transfer incurs charges.
- Design for same-region placement to minimize costs.
Memory trick: Keep your data 'home' in the same region to avoid travel fees.
S3 Lifecycle Policies
Flip cardS3 Lifecycle Policies define rules to automatically transition objects between different S3 storage classes or expire objects after a specified time.
- Automate cost optimization by moving data to cheaper storage tiers.
- Can transition objects based on age or access patterns.
- Can expire objects after a set period.
- Helps meet compliance requirements for data retention.
Memory trick: Standard to Infrequent, then to Glacier's Deep Sleep.
S3 Lifecycle Policies for Cost Optimization
Flip cardAmazon S3 Lifecycle policies automate the transition or expiration of objects based on defined rules. This allows for significant cost savings by moving data to lower-cost storage classes (e.g., S3 Standard-IA, Glacier) as it ages or becomes less frequently accessed, or by deleting it when no longer needed.
- Automates object transitions between S3 storage classes.
- Automates object expiration (deletion).
- Key tool for optimizing S3 storage costs and meeting retention policies.
Memory trick: Lifecycle rules: Data's journey, cost's reduction.
Amazon EC2 Spot Instances
Flip cardAmazon EC2 Spot Instances let you take advantage of unused EC2 capacity in the AWS cloud, available at steep discounts compared to On-Demand prices.
- Up to 90% savings compared to On-Demand.
- Workloads can be interrupted with a two-minute warning.
- Ideal for fault-tolerant, flexible, non-time-critical tasks.
- Good for batch processing, big data analytics, and CI/CD.
Memory trick: Think of EC2 options like different ways to rent a car: hourly, long-term, or bidding for a spare.
AWS Transit Gateway Inter-Region Peering
Flip cardAWS Transit Gateway inter-region peering allows you to connect Transit Gateways in different AWS Regions, enabling network traffic to route between them.
- Extends Transit Gateway's capabilities across AWS Regions.
- Uses the highly available, low-latency AWS global network.
- Simplifies complex multi-region network architectures.
- Can reduce inter-region data transfer costs compared to other methods.
Memory trick: Transit Gateways Peer, Costs Disappear.
Amazon RDS Read Replicas
Flip cardCopies of your primary Amazon RDS database instance that are used to offload read traffic, improving read performance and scalability for read-heavy workloads.
- Asynchronous replication from primary to replicas.
- Can be promoted to standalone database instances if needed.
- Supports cross-Region and cross-AZ replication.
- Ideal for read-heavy applications and reporting queries.
Memory trick: Read Replicas are like having multiple copies of a book to share, so everyone can read at once.
Amazon S3 Intelligent-Tiering
Flip cardAn S3 storage class that automatically optimizes storage costs by moving data between two access tiers (frequent and infrequent access) based on changing access patterns.
- Automatically moves data to the most cost-effective access tier.
- Ideal for data with unknown or changing access patterns.
- No performance impact due to tiering.
Memory trick: Intelligent-Tiering: Smart savings, auto-sorted data.
EC2 Spot Instances (Max Savings)
Flip cardAmazon EC2 Spot Instances allow you to bid on unused EC2 capacity, providing the largest potential cost savings (up to 90% off On-Demand prices). They are ideal for flexible, fault-tolerant workloads that can withstand interruptions, such as batch processing, big data analytics, and continuous integration/delivery (CI/CD).
- Up to 90% cost savings compared to On-Demand.
- Can be interrupted with a two-minute warning.
- Best for fault-tolerant, flexible, and stateless workloads.
Memory trick: Spot: The deepest discount, if you don't mind a little bounce.
AWS Key Management Service (KMS) CMKs
Flip cardAWS Key Management Service (KMS) is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. Customer Managed Keys (CMKs) give you full control over key policies and rotation.
- Creates and manages cryptographic keys.
- Integrates with most other AWS services.
- Supports automatic key rotation for CMKs.
- Highly available and secure hardware security modules (HSMs).
Memory trick: KMS is the master locksmith of your cloud, keeping your keys safe and turning them regularly.
EC2 Enhanced Networking (ENA)
Flip cardEnhanced Networking provides significantly higher packet per second (PPS) performance, lower network latency, and lower jitter using specialized network interfaces like Elastic Network Adapter (ENA) or Intel 82599 Virtual Function (VF) interface.
- Boosts network performance (PPS, latency, jitter).
- Uses ENA on most modern instance types.
- Essential for performance-sensitive applications like gaming or HPC.
Memory trick: ENA: Your network's turbo boost for a smooth game host.
AWS Tagging for Cost Allocation
Flip cardAWS Tags are key-value pairs that can be assigned to AWS resources. They are crucial for cost governance, enabling organizations to categorize resources for billing, reporting, and automation, allowing for accurate cost allocation to departments, projects, or applications.
- Key-value pairs for resource metadata.
- Enables granular cost allocation in Cost Explorer and CUR.
- Essential for organizing and managing resources at scale.
Memory trick: Tag your assets, trace your spending, stay on track with your budget's ending.
Lambda Provisioned Concurrency
Flip cardProvisioned Concurrency initializes a specified number of execution environments for a Lambda function, ensuring that they are ready to respond to invocations with minimal latency.
- Eliminates cold starts for a defined number of invocations.
- You pay for the configured concurrency even when the function is idle.
- Ideal for latency-sensitive applications with predictable traffic.
- Balances cost (for pre-warmed environments) with performance.
Memory trick: Provisioned Concurrency: Prepare, Perform, Pay Less Per Start.
EC2 Spot Instances for EMR
Flip cardLeveraging EC2 Spot Instances for Amazon EMR clusters, particularly for worker nodes, can significantly reduce compute costs. This is effective because EMR is designed to be fault-tolerant, allowing for worker nodes to be interrupted and replaced without failing the entire job, especially suitable for batch processing.
- Significant cost savings (up to 90%) for worker nodes.
- EMR's fault tolerance handles Spot interruptions.
- Master nodes typically use On-Demand for stability.
Memory trick: EMR's Spot-on strategy: cheap workers, stable master.
EC2 On-Demand Instances
Flip cardEC2 On-Demand Instances allow you to pay for compute capacity by the hour or second with no long-term commitments.
- No upfront payment or long-term commitment.
- Pay for compute capacity by the hour or second.
- Ideal for unpredictable, short-term, or spiky workloads.
- Highest cost per hour compared to other options but offers maximum flexibility.
Memory trick: On-Demand: Only pay for what you need, when you need it.
AWS Lambda Cost Optimization
Flip cardAWS Lambda is a serverless compute service that automatically manages underlying infrastructure and charges only for the compute time consumed when a function is invoked. This 'pay-per-use' model is highly cost-efficient for event-driven, intermittent, or frequently invoked small workloads.
- Pay only for code execution time, not idle time.
- Automatic scaling, no server management.
- Cost-effective for event-driven and microservices architectures.
Memory trick: Lambda's pay-per-play saves cash every day.
AWS Same-Region Data Transfer
Flip cardData transfer between AWS services within the same AWS Region is generally free or significantly cheaper than inter-region data transfer.
- Most data transfer between services within the same region is free.
- Applies to services like EC2, S3, RDS, Lambda, EMR, etc.
- Helps minimize operational costs.
- A key consideration for cost-optimized architecture design.
Memory trick: Regional Harmony Saves Your Money.
DynamoDB Encryption with CMK
Flip cardEncrypts DynamoDB data at rest using customer managed keys (CMK) stored in AWS Key Management Service (KMS).
- Customer has full control over key policies and rotation.
- Leverages AWS KMS for secure key storage and management.
- Key usage can be audited via AWS CloudTrail.
Memory trick: CMKs give you the master key to DynamoDB's secrets.
NAT Gateway
Flip cardA Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Enables outbound internet access from private subnets.
- Prevents inbound internet connections from the internet.
- Requires deployment in a public subnet and a route table entry from the private subnet.
Memory trick: NAT Gateway: No Inbound, All Outbound for Private Zones.
CloudFront Secure Content Delivery
Flip cardCloudFront delivers content globally, providing in-transit encryption, and integrates with signed URLs/cookies for authenticated access and Origin Access Control (OAC) for secure, private S3 origin access.
- CloudFront for global distribution and HTTPS.
- Signed URLs/cookies for authenticated, time-limited access.
- Origin Access Control (OAC) securely connects CloudFront to private S3.
- Prevents direct access to the S3 origin bucket.
Memory trick: CloudFront: Caching Content Securely
SSE-KMS
Flip cardServer-Side Encryption with AWS Key Management Service (SSE-KMS) allows S3 objects to be encrypted using customer master keys (CMKs) stored and managed in AWS KMS.
- Uses AWS KMS to manage encryption keys (CMKs).
- Provides an audit trail of key usage through AWS CloudTrail.
- Offers more control over key rotation and permissions than SSE-S3.
Memory trick: KMS Keys Keep S3 Secure and Auditable.
IAM Least Privilege
Flip cardGranting only the permissions required to perform a specific task, and no more.
- Crucial for security in AWS.
- Achieved through granular IAM policies.
- Limits the blast radius in case of compromise.
Memory trick: Lambda's Role: Only What It Needs to Get.
S3 Secure Partner Access
Flip cardSecurely sharing S3 data with partners involves enforcing HTTPS, restricting access by IP range, and granting granular access to specific prefixes using bucket policies.
- HTTPS ensures data encryption in transit.
- Bucket policies with `aws:SourceIp` restrict access to specific IP ranges.
- Bucket policies with `s3:prefix` limit access to designated object prefixes.
- IAM policies can grant partner roles/users access to the bucket.
Memory trick: HTTPS, IP, and Prefix: 'H'ow 'I' 'P'rotect 'S'3.
S3 SSE-C
Flip cardServer-Side Encryption with Customer-Provided Keys (SSE-C) allows customers to manage their own encryption keys and provide them to Amazon S3 as part of API requests.
- Customer provides and manages the encryption key.
- Key is passed with each S3 API request (PUT, GET).
- S3 performs the encryption/decryption using the provided key.
- Allows enforcement via bucket policies to require SSE-C for uploads.
Memory trick: SSE-C: 'S'3 'S'ecurity 'E'xternally 'C'ontrolled.
Multi-Tier VPC Architecture
Flip cardA common AWS architecture pattern that segregates application components into different network tiers (subnets) based on their public accessibility and security requirements.
- Public subnets for internet-facing resources (e.g., load balancers, web servers).
- Private subnets for internal resources (e.g., application servers, databases).
- Security groups and Network ACLs control traffic flow between tiers and to/from the internet.
Memory trick: Public for Front, Private for Back, NACLs Block, SGs Track.
AWS Organizations SCPs
Flip cardService Control Policies (SCPs) are a type of policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Applied to OUs or the root of an organization.
- Acts as a 'guardrail' or maximum permission boundary.
- Does not grant permissions, only restricts them.
Memory trick: SCPs Securely Control Permissions for Organizational Purity.
AWS Secrets Manager
Flip cardAWS Secrets Manager helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Automates rotation of secrets (e.g., database credentials).
- Provides fine-grained access control through IAM.
- Integrates with other AWS services (e.g., Lambda, RDS).
Memory trick: Secrets Manager: Rotate, Retrieve, Restrict, Repeat.
AWS CloudTrail
Flip cardA service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by logging actions taken by a user, role, or an AWS service.
- Records all AWS API calls and events.
- Logs who, what, when, and from where.
- Delivers logs to S3 for secure, immutable storage.
- Essential for auditing and compliance.
Memory trick: CloudTrail: Track All Actions
RDS Encryption & Access Control
Flip cardAmazon RDS allows encryption of data at rest using AWS KMS and uses security groups to control network access to database instances.
- Encrypts data at rest using AWS KMS.
- Security Groups control network access.
- Managed relational database service.
Memory trick: RDS: Restrict Data Securely
S3 Pre-signed URLs
Flip cardAn Amazon S3 pre-signed URL is a URL that you can share with others to grant them temporary access to a specific S3 object or prefix, without requiring them to have AWS credentials.
- Grants temporary access to objects/prefixes.
- Does not require AWS credentials for the recipient.
- Expiration time can be set, enhancing security.
Memory trick: Pre-signed URLs: Perfect for Partners, Precise and Temporary.
AWS WAF with CloudFront
Flip cardAWS WAF (Web Application Firewall) helps protect web applications from common web exploits and unwanted bots. When deployed with CloudFront, it provides edge protection for global applications.
- WAF protects against common web exploits (SQLi, XSS).
- WAF can create custom rules (e.g., IP blacklists).
- CloudFront distributes content globally and integrates WAF at the edge.
- Provides Layer 7 protection for web applications.
Memory trick: WAF: Web App Firewall
ALB & EC2 Private Subnet
Flip cardA common secure architecture where an Application Load Balancer (ALB) is deployed in public subnets to face the internet, while backend EC2 instances are deployed in private subnets to protect them from direct internet access.
- ALB in public subnets for internet-facing access.
- EC2 instances in private subnets for isolation.
- Security groups control traffic flow between ALB and EC2 instances.
Memory trick: ALB Public Front, EC2 Private Back, Keep Internet Track.
AWS Organizations CloudTrail Integration
Flip cardA feature of AWS Organizations that allows creating an 'organization trail' from the management account, which automatically logs all events for all accounts in the organization to a single S3 bucket.
- Centralizes CloudTrail logs from all member accounts.
- Member accounts cannot disable or modify the organization trail.
- Created and managed from the AWS Organizations management account.
- Ensures mandatory logging across the entire organization.
Memory trick: Org Trail: The 'O'rganization's 'R'equired 'G'uardian 'T'rail.
S3 Multi-Tenant Access Control
Flip cardFor multi-tenant applications storing data in S3, use IAM policies with role assumption and object key prefixes (e.g., tenant ID) to enforce logical data isolation.
- IAM policies are preferred for granular control.
- Object key prefixes (e.g., tenant ID) enable logical isolation.
- IAM roles allow applications to assume specific permissions.
Memory trick: IAM: Isolate Access Multi-tenant
S3 Encryption with Customer Control
Flip cardUsing S3 encryption options that provide the highest level of control over encryption keys and auditability for sensitive data.
- SSE-S3: AWS manages keys fully.
- SSE-KMS: AWS KMS manages keys, some customer control over policy.
- SSE-C: Customer provides key, S3 encrypts.
- Client-Side Encryption with CMK: Customer encrypts data with their KMS CMK before upload, full key control and auditability.
Memory trick: Client-Side KMS CMK: Control Your Own Key.
AWS WAF
Flip cardA web application firewall that helps protect your web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources.
- Protects against common web exploits like SQL injection and XSS.
- Integrates with Amazon CloudFront, Application Load Balancer, and API Gateway.
- Allows creation of custom rules to block or allow traffic.
Memory trick: WAF guards your web apps from common 'W'icked 'A'ttack 'F'ailures.
Security Group Referencing
Flip cardA method to allow traffic between AWS resources by specifying a source or destination security group, rather than IP addresses.
- Simplifies network access control between AWS services.
- Dynamically updates as instances are added or removed from the referenced security group.
- Enhances security by avoiding hardcoded IP addresses.
Memory trick: Security Groups Talk, RDS Unlocks.
CodeCommit Secure Workflow
Flip cardA secure workflow in AWS CodeCommit combines IAM for access control, CodePipeline for enforcing code review and approval, and CloudTrail for auditing.
- IAM policies grant/deny repository access.
- CodePipeline enforces pull request and approval workflows.
- Protected branches prevent direct pushes without review.
- AWS CloudTrail logs all CodeCommit API calls for auditing.
Memory trick: IAM, Pipeline, and CloudTrail: The 'IPC' of secure code.
S3 Cross-Region Replication (CRR)
Flip cardAn S3 feature that automatically and asynchronously replicates objects across S3 buckets in different AWS Regions.
- Provides disaster recovery and reduces latency for globally distributed users.
- Maintains object metadata, version IDs (if versioning is enabled), and object ACLs.
- Requires versioning to be enabled on both source and destination buckets.
Memory trick: CRR: Critical Regions Replicate Reliably.
AWS Managed Microsoft AD
Flip cardA fully managed, highly available Microsoft Active Directory service in the AWS Cloud, offering full compatibility with Windows applications and SSO.
- Fully managed Microsoft AD.
- Compatible with Windows applications.
- Supports single sign-on (SSO).
- Can establish trusts with on-premises AD.
Memory trick: AD: All Directories Done
Centralized CloudTrail Logging
Flip cardConsolidating AWS CloudTrail logs from multiple accounts into a single, secure location for centralized auditing and compliance.
- AWS Organizations enables organization trails.
- Delegated administrator account manages the organization trail.
- S3 Object Lock provides WORM (Write Once, Read Many) for log immutability.
- S3 lifecycle policies manage retention periods.
Memory trick: Org Trail with Object Lock Locks Logs.
CloudTrail Organization Trails
Flip cardAn AWS CloudTrail organization trail is a trail created in the management account of an AWS Organization that logs all events from all member accounts in that organization to a specified Amazon S3 bucket.
- Created by the management account in AWS Organizations.
- Logs events from all member accounts (current and future).
- Ensures consistent and centralized audit logging.
Memory trick: Org Trail: One Trail to Rule All Accounts' Logs.
DynamoDB Encryption at Rest
Flip cardDynamoDB tables are encrypted at rest by default, protecting data stored on disk.
- DynamoDB tables are encrypted by default using AWS owned keys.
- Users can choose AWS owned keys, AWS managed keys, or customer managed keys (CMKs).
- AWS owned keys offer the lowest operational overhead.
Memory trick: DynamoDB's Default Key Does the Job.
Isolated VPC Design
Flip cardA VPC design that completely restricts internet access for instances by using private subnets, no Internet Gateway, no NAT Gateway, and leveraging VPC Endpoints for AWS service access.
- Instances deployed in private subnets.
- No Internet Gateway attached to the VPC.
- No NAT Gateway configured.
- VPC Endpoints provide private connectivity to AWS services.
Memory trick: No Gateway, Private Subnets, VPC Endpoints: The 'NGPVE' of isolation.
S3 Access Log Auditing
Flip cardS3 server access logs record all requests to an S3 bucket. When combined with S3 Object Lock and Amazon Athena, they provide immutable, auditable, and queryable access records.
- S3 server access logs capture all requests (who, what, when).
- S3 Object Lock (Compliance Mode) ensures log immutability.
- Logs should be stored in a separate S3 bucket.
- Amazon Athena allows SQL-based querying of logs in S3.
Memory trick: Logs: Lock, Query, Audit
AWS IoT Core Security
Flip cardAWS IoT Core secures device communication and data with mechanisms like X.509 certificates and mutual TLS.
- X.509 certificates authenticate devices.
- Mutual TLS encrypts data in transit and verifies both ends of the connection.
- IoT Core policies authorize device actions.
Memory trick: IoT's X.509 and mTLS Seal the Deal.
S3 Data in Transit Encryption
Flip cardEnsuring data is encrypted while it moves between an application and Amazon S3.
- S3 supports HTTPS/TLS for all data transfers by default.
- Bucket policies can enforce HTTPS/TLS to ensure secure connections.
- This method encrypts data as it travels over the network.
Memory trick: Secure S3 with Simple TLS Tactics.
Secure Isolated AWS Network
Flip cardCreating a highly secure and isolated network environment in AWS, often involving private subnets, Direct Connect, and VPC Endpoints.
- Private subnets host resources isolated from public internet.
- AWS Direct Connect provides dedicated, private network link to AWS.
- VPC Endpoints enable private access to AWS services without internet exposure.
Memory trick: VPC's Private Endpoints Directly Connect.
CodeCommit Access Control
Flip cardAWS CodeCommit uses IAM users with Git credentials (HTTPS or SSH) for authentication and IAM policies for authorization to control access to repositories.
- IAM users manage developer identities.
- Git credentials (HTTPS or SSH) authenticate to CodeCommit.
- IAM policies define granular permissions (e.g., push, pull).
- Policies can be attached to users or groups.
Memory trick: IAM: Identify And Manage Code
SQS Encryption
Flip cardAmazon SQS supports Server-Side Encryption (SSE) for data at rest and relies on HTTPS for encryption of data in transit.
- SSE for SQS encrypts messages at rest using KMS.
- HTTPS ensures data is encrypted in transit.
- SQS is a fully managed message queuing service.
Memory trick: SQS: Secure Queues System
AWS Bot Control for WAF
Flip cardA managed rule group for AWS WAF that provides intelligent, real-time protection against common and sophisticated bot traffic.
- Uses machine learning and threat intelligence.
- Distinguishes between legitimate and malicious bot traffic.
- Integrates directly with AWS WAF.
Memory trick: WAF's Bot Control Blocks Sneaky Bots.
S3 SSE-KMS
Flip cardServer-Side Encryption using AWS Key Management Service (KMS) managed keys, offering customer control over key policies and auditing.
- Uses AWS KMS to manage encryption keys.
- Customer retains full control over key policies, including rotation.
- Integrates with AWS CloudTrail for auditing key usage.
Memory trick: KMS keys give you the reins for S3 security.
AWS Managed Microsoft AD Features
Flip cardAWS Directory Service offers managed Microsoft Active Directory, providing features like Kerberos, LDAP, and trust relationships.
- Enterprise Edition supports multi-region deployments and trust relationships.
- Standard Edition is for smaller workloads and does not support trusts.
- Provides a fully managed experience, reducing operational overhead.
Memory trick: Directory Decisions: Enterprise for On-Prem.
ALB & EC2 Private Subnet Security Groups
Flip cardTo secure EC2 instances behind an ALB in private subnets, the ALB's security group allows public inbound traffic, while the EC2 instances' security group only allows inbound traffic from the ALB's security group.
- ALB resides in public subnets, EC2 in private.
- ALB security group allows inbound from 0.0.0.0/0 on application ports.
- EC2 security group allows inbound from ALB's security group on application ports.
- Ensures EC2 instances are not directly exposed to the internet.
Memory trick: ALB Accepts All, EC2 Accepts ALB Only.
S3 Object Lock & Lifecycle
Flip cardAmazon S3 Object Lock provides WORM (Write Once, Read Many) protection for objects, making them immutable. S3 Lifecycle policies automate the transition of objects between different storage classes based on age or access patterns.
- Ensures data immutability (WORM)
- Compliance mode protects against root user deletion
- Retention periods configurable
- Lifecycle policies automate cost optimization
Memory trick: Lock your objects for compliance, then lifecycle them to save cash.