AWS Certified Solutions Architect – Professional flashcards
132 free flashcards. Tap a card to flip it.
AWS Batch + Step Functions
Flip cardAWS Batch allows developers, scientists, and engineers to easily run hundreds of thousands of batch computing jobs on AWS. AWS Step Functions is a serverless workflow service that makes it easy to coordinate multiple AWS services into serverless workflows.
- AWS Batch manages compute for long-running jobs.
- Step Functions orchestrates complex, distributed workflows.
- Step Functions provides built-in error handling and retries.
- Combined, they offer robust, scalable, and reliable batch processing.
Memory trick: Batch is the 'Cook' for heavy jobs, and Step Functions is the 'Recipe Book' ensuring every step is followed.
Amazon ElastiCache for Redis
Flip cardA fully managed, in-memory caching service compatible with Redis, providing high performance and low latency for applications requiring fast data access.
- Supports Redis data structures and APIs.
- Offers replication for high availability and read scaling.
- Automates common administrative tasks like patching and backups.
Memory trick: ElastiCache: Elastic for speed, Cache for memory.
AWS Network Firewall
Flip cardA managed service that makes it easy to deploy, set up, and scale network security across all of your Amazon VPCs. It provides stateful inspection, intrusion prevention, and web filtering.
- Centralized network traffic inspection and filtering.
- Supports Suricata-compatible rules for deep packet inspection.
- Enforces fine-grained ingress and egress traffic policies.
Memory trick: Network Firewall is the bouncer for your VPC, checking every packet in and out.
Service Control Policies (SCPs)
Flip cardService Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Preventative guardrails that deny actions.
- Apply to all IAM users and roles, including the root user.
- Applied at the OU or root level and inherited by child accounts.
Memory trick: SCPs Secure Strict Standards.
Amazon Cognito User Pools
Flip cardA fully managed, scalable user directory service that handles user registration, authentication, and account recovery for web and mobile applications.
- Supports millions of users.
- Integrates with social identity providers (e.g., Google, Facebook).
- Provides secure user directories and authentication.
Memory trick: Cognito handles countless consumers securely.
Amazon MQ
Flip cardA managed message broker service for RabbitMQ and ActiveMQ that makes it easy to migrate message brokers to AWS.
- Supports industry-standard APIs and protocols (e.g., JMS, AMQP, MQTT).
- Ideal for lift-and-shift of applications using traditional message brokers.
- Provides high availability and durability.
Memory trick: MQ maintains message integrity for legacy links.
Amazon EMR for Spark Workloads
Flip cardAmazon EMR is a managed cluster platform that simplifies running big data frameworks like Apache Spark, Hadoop, and Presto on AWS.
- Provides scalable and flexible clusters for big data processing.
- Reduces operational overhead compared to self-managed clusters.
- Supports various instance types and auto-scaling for cost optimization.
Memory trick: EMR is like a managed ranch for your Spark horses, letting them run free and fast.
Amazon CloudFront
Flip cardA fast content delivery network (CDN) service that securely delivers data, video, applications, and APIs globally with low latency.
- Caches content at edge locations worldwide.
- Reduces latency and improves transfer speeds.
- Integrates with AWS services like S3, EC2, Lambda@Edge.
- Supports HTTP/HTTPS and streaming protocols.
Memory trick: CloudFront is the 'Express Lane' for your content, reaching everyone, everywhere, fast.
Asynchronous Microservices Communication
Flip cardA pattern where microservices communicate without waiting for an immediate response, typically using message queues or event buses to improve resilience and scalability.
- Decouples services, reducing dependencies.
- Prevents cascading failures.
- Improves system resilience, scalability, and responsiveness.
Memory trick: SQS is like a post office, holding messages until the recipient is ready.
AWS CodePipeline, CodeBuild, CodeDeploy, CodeCommit
Flip cardA suite of fully managed AWS services that automate the software release process. CodeCommit for source control, CodeBuild for compiling/testing, CodeDeploy for deploying, and CodePipeline for orchestrating the workflow.
- Provides end-to-end CI/CD automation.
- Integrates with other AWS services.
- CodeBuild supports custom build environments (Docker).
Memory trick: CodePipeline orchestrates the 'Code' family: Commit, Build, Deploy.
AWS Batch
Flip cardA fully managed service that enables developers, scientists, and engineers to easily and efficiently run hundreds of thousands of batch computing jobs on AWS.
- Dynamically provisions compute resources.
- Manages job queueing, scheduling, and execution.
- Integrates with other AWS services like S3 and EC2.
Memory trick: Batch processing is like a factory assembly line, AWS Batch manages the flow.
Real-time Streaming Analytics with Kinesis
Flip cardA fully managed AWS solution for ingesting, processing, and analyzing high-volume streaming data with low latency to derive immediate insights.
- Amazon Kinesis Data Streams for high-throughput data ingestion.
- Amazon Kinesis Data Analytics for Apache Flink for real-time processing and analysis.
- Suitable for immediate decision-making like fraud detection.
Memory trick: Kinesis Streams the data, Flink Analyzes it instantly, Redshift stores the results.
Amazon Relational Database Service (RDS)
Flip cardA managed service that makes it easy to set up, operate, and scale a relational database in the cloud. It supports several popular database engines.
- Supports MySQL, PostgreSQL, Oracle, SQL Server, MariaDB, and Amazon Aurora.
- Automates administrative tasks like patching, backups, and replication.
- Provides high availability, scalability, and security features.
Memory trick: RDS for Relational, DynamoDB for NoSQL, Redshift for Warehouse.
AWS Step Functions
Flip cardA serverless workflow service that allows you to define, orchestrate, and track multi-step application workflows as state machines.
- Visually define workflows as state machines.
- Manages state, retries, and error handling automatically.
- Integrates with over 200 AWS services.
- Suitable for long-running and complex processes.
Memory trick: Step Functions Steps Up Complex Flows
Amazon S3 Inventory
Flip cardAmazon S3 Inventory provides a scheduled, flat-file list of objects in an S3 bucket or a shared prefix. It helps you manage your storage by auditing and reporting on the replication and encryption status of your objects.
- Generates daily or weekly reports of object metadata.
- Supports CSV, ORC, or Parquet output formats.
- Useful for auditing, compliance, and cost optimization at scale.
Memory trick: Inventory Inspects In-depth.
Strangler Fig Pattern
Flip cardA technique for incrementally transforming a monolithic application into a microservices architecture by gradually replacing specific functionalities with new services, while the old system continues to operate.
- Enables modernization without a complete rewrite.
- Reduces risk by allowing phased migration.
- Traffic redirection is key to cut over to new services.
Memory trick: Imagine a strangler fig slowly engulfing a monolithic tree, replacing it bit by bit.
Elastic Fabric Adapter (EFA)
Flip cardA network interface for Amazon EC2 instances that enables customers to run applications requiring high levels of inter-node communications at scale on AWS, like HPC and machine learning.
- Provides lower and more consistent latency than traditional TCP.
- Supports OS-bypass capabilities for MPI and NCCL.
- Similar performance to on-premises InfiniBand networks.
Memory trick: EFA gives your HPC apps 'Extra Fast' networking, like InfiniBand.
Amazon Kinesis Data Analytics for Apache Flink
Flip cardA fully managed service that allows you to process and analyze streaming data in real time using Apache Flink, supporting continuous SQL queries.
- Serverless and fully managed service.
- Supports continuous SQL queries or Apache Flink applications.
- Processes data from Kinesis Data Streams and Firehose.
- Used for real-time analytics, dashboards, and anomaly detection.
Memory trick: Kinesis Data Analytics is the 'Stream Detective', constantly watching and reporting on your data flow.
The 6 R's of Migration
Flip cardA framework outlining different strategies an organization can adopt when migrating applications to the cloud, each with varying levels of effort, cost, and cloud benefits.
- Developed by AWS to categorize migration approaches.
- Helps organizations choose the most appropriate strategy for each application.
- Impacts cost, complexity, and time-to-value for cloud adoption.
Memory trick: Remember the Six Rs: Rehost, Replatform, Refactor, Repurchase, Retain, Retire.
AWS Content Delivery Network (CDN)
Flip cardA system of distributed servers (network of PoPs) that delivers web content and static assets to users based on their geographic location, providing high availability and performance.
- Reduces latency by caching content closer to users.
- Offloads origin servers, reducing load and costs.
- Enhances security with DDoS protection and WAF integration.
Memory trick: CloudFront accelerates global content from S3 with Global Accelerator's aid.
AWS Glue
Flip cardA serverless data integration service that makes it easy to discover, prepare, and combine data for analytics, machine learning, and application development, supporting Apache Spark.
- Fully managed, serverless Spark environment.
- Includes a Data Catalog for metadata management.
- Supports ETL (Extract, Transform, Load) operations.
- Pay-as-you-go pricing, scales automatically.
Memory trick: Glue 'sticks' your Spark jobs to a serverless cloud, no more server headaches!
Amazon EMR for Apache Spark
Flip cardAmazon EMR is a managed cluster platform that simplifies running big data frameworks, such as Apache Hadoop and Apache Spark, on AWS to process vast amounts of data.
- Fully managed service for big data frameworks.
- Provides elastic scalability for Spark clusters.
- Reduces operational overhead compared to self-managed clusters.
Memory trick: EMR is like having a managed elephant (Hadoop/Spark) that can grow and shrink on demand.
AWS Directory Service for Microsoft Active Directory (Managed AD) with Route 53 Resolver
Flip cardAWS Managed Microsoft AD provides a fully managed, highly available Active Directory. Route 53 Resolver enables hybrid DNS resolution between on-premises DNS and AWS DNS, allowing resources in both environments to resolve hostnames.
- Extends or creates Active Directory in AWS.
- Manages DNS for AD-joined instances.
- Route 53 Resolver bridges on-premises and AWS DNS for seamless name resolution.
Memory trick: AD Service + Route 53 Resolver = Your old names, new cloud home, all resolved.
Amazon Redshift
Flip cardA fully managed, petabyte-scale data warehouse service in the cloud, optimized for fast analytical queries on large datasets.
- Columnar storage for efficient analytical processing.
- Massively Parallel Processing (MPP) architecture.
- Integrates with other AWS services like S3, Kinesis, EMR.
- Cost-effective for large-scale data analytics.
Memory trick: Redshift turns your 'data mountain' into a 'query sprint'.
Re-host (Lift and Shift) Migration
Flip cardMoving an application and its components to the cloud with minimal or no changes. It's often the fastest migration strategy, preserving existing architecture and operational models.
- Minimal application changes required.
- Faster migration time.
- Leverages existing licenses and operational processes.
Memory trick: The 7 Rs of migration: Re-host, Re-platform, Re-factor, Re-purchase, Retire, Retain, Relocate.
Amazon ElastiCache
Flip cardA fully managed in-memory data store and caching service that supports Redis and Memcached, designed to accelerate application performance by retrieving data from fast, managed in-memory caches.
- Supports both Redis and Memcached engines.
- Provides high availability with replication and failover.
- Offers automatic scaling, patching, and backups, reducing operational burden.
Memory trick: ElastiCache for speed, Dynamo for NoSQL, S3 for objects.
Database Migration Service (DMS) with CDC
Flip cardAWS Database Migration Service (DMS) can migrate databases to AWS with Change Data Capture (CDC) to keep source and target databases synchronized during migration.
- Supports homogeneous and heterogeneous database migrations.
- CDC enables continuous replication, minimizing downtime during cutover.
- Ideal for migrating critical applications requiring high availability.
Memory trick: DMS with CDC is like a real-time mirror, reflecting changes during migration.
AWS End-of-Life Extended Support
Flip cardAWS provides options, such as Extended Security Updates (ESU) for Windows Server and SQL Server, to allow customers to continue running applications on unsupported operating systems in EC2.
- Enables migration of legacy workloads to AWS without immediate OS upgrades.
- Helps bridge the gap for applications with strict OS dependencies.
- Reduces immediate re-architecture costs but is a temporary solution.
Memory trick: When old OS is due, AWS helps you 'renew'.
AWS Elemental MediaConvert
Flip cardAWS Elemental MediaConvert is a file-based video transcoding service that allows you to create video-on-demand (VOD) content for broadcast and multiscreen delivery at scale.
- Fully managed and highly scalable.
- Supports a wide range of video codecs and formats.
- Integrates seamlessly with S3.
- Pay-per-minute pricing, reducing costs compared to owned infrastructure.
Memory trick: MediaConvert is the 'Magic Mixer' for videos, letting SQS 'line up' jobs for S3 storage.
AWS Database Migration Service (DMS)
Flip cardA cloud service that helps migrate relational databases, data warehouses, NoSQL databases, and other types of data stores to AWS quickly and securely. It supports both homogeneous and heterogeneous migrations.
- Supports continuous data replication with Change Data Capture (CDC).
- Minimizes downtime during database migrations.
- Can migrate to and from various database engines including Oracle, SQL Server, MySQL, PostgreSQL, MongoDB, etc.
Memory trick: DMS for Databases, DataSync for Files, Snowball for Bulk.
KMS Customer Managed Keys (CMKs)
Flip cardEncryption keys created and managed by an AWS customer within AWS Key Management Service (KMS), offering full control over key lifecycle, usage, and auditing.
- Customer retains full control over the key.
- Integrates with most AWS services for encryption.
- Supports automatic annual key rotation.
- Key usage can be audited via AWS CloudTrail.
Memory trick: KMS CMKs are your 'Personal Vault Keys' for AWS, giving you the master control.
Kinesis Data Analytics for Apache Flink
Flip cardA fully managed service for processing streaming data in real time with Apache Flink, enabling powerful analytics with low latency.
- Processes data from Kinesis Data Streams or Firehose.
- Supports SQL, Java, Scala, and Python for stream processing.
- Ideal for real-time dashboards, anomaly detection, and machine learning.
Memory trick: Flink is the lightning-fast river current, processing data as it flows.
Amazon Elastic MapReduce (EMR)
Flip cardA managed cluster platform that simplifies running big data frameworks like Apache Hadoop and Apache Spark on AWS to process and analyze vast amounts of data.
- Automates provisioning, managing, and scaling of big data clusters.
- Supports various big data frameworks and analytic tools.
- Integrates with other AWS services like S3 and EC2.
Memory trick: Hadoop to EMR, easy as can be.
Serverless Modernization
Flip cardA modernization strategy that involves re-architecting applications to use serverless services, eliminating the need to provision, scale, and manage servers.
- Achieves high scalability and elasticity automatically.
- Offers a 'pay-per-execution' cost model, reducing idle costs.
- Significantly reduces operational overhead for infrastructure management.
Memory trick: Scalability, Cost Efficiency, Operational Ease: SCOPE.
AWS Storage Gateway (Tape Gateway) and S3 Glacier Deep Archive
Flip cardTape Gateway virtualizes physical tape libraries for existing backup software, sending data to S3 Glacier storage classes. S3 Glacier Deep Archive is the lowest-cost storage class for long-term data archiving with retrieval times of 12 hours or more.
- Tape Gateway replaces physical tapes with virtual tapes in AWS.
- S3 Glacier Deep Archive offers sub-dollar per TB per month storage.
- Ideal for regulatory compliance, disaster recovery, and long-term retention.
Memory trick: Tape Gateway tapes into Glacier Deep Archive for the cheapest long-term cold storage.
AWS Batch with Spot Instances
Flip cardA combination of AWS Batch for managing batch computing workloads and EC2 Spot Instances for cost-effective, interruptible compute capacity.
- AWS Batch handles job scheduling, resource provisioning, and scaling.
- Spot Instances offer significant cost savings (up to 90% off On-Demand price).
- Ideal for fault-tolerant, flexible batch jobs.
Memory trick: Batch + Spot = Best for Batch Cost
Managed Application & Database on AWS
Flip cardLeveraging fully managed AWS services like Elastic Beanstalk for applications and Amazon RDS for databases significantly reduces operational overhead, enhances availability, and simplifies compliance efforts by offloading infrastructure management to AWS.
- Elastic Beanstalk automates application deployment, scaling, and health monitoring.
- Amazon RDS offers managed relational databases with Multi-AZ for high availability.
- AWS KMS and ACM provide robust encryption for data at rest and in transit.
- Managed services help meet compliance requirements through built-in features and shared responsibility model.
Memory trick: Elastic Beanstalk is the 'Beanstalk' growing your app, while RDS Multi-AZ is the 'Red Dragon' guarding your data.
Amazon RDS for SQL Server
Flip cardA fully managed service that makes it easy to set up, operate, and scale Microsoft SQL Server deployments in the cloud.
- Supports native SQL Server features (stored procedures, triggers).
- Automates backups, patching, and high availability.
- Minimizes code changes for SQL Server migrations.
- Offers various SQL Server editions and versions.
Memory trick: RDS SQL Server, Same SQL, Simple Shift
AWS Storage Gateway (File Gateway)
Flip cardA hybrid storage service that provides on-premises applications with file-based access to cloud storage (Amazon S3) using standard file protocols like NFS and SMB.
- Presents S3 as NFS/SMB shares to on-premises apps.
- Caches frequently accessed data locally for low latency.
- Manages data transfer to S3, including versioning and lifecycle policies.
- Ideal for hybrid cloud file storage and migration to S3.
Memory trick: File Gateway Gets Files to S3
AWS Managed Microsoft AD with Two-Way Trust
Flip cardA fully managed AWS service that hosts Microsoft Active Directory, enabling seamless integration with on-premises AD via a two-way forest trust.
- Reduces operational burden of managing AD servers.
- Provides a single identity plane across on-premises and AWS.
- Supports standard AD features like Group Policy and DNS.
Memory trick: Managed AD, Two-Way Trust, Total Ease
Strangler Fig Pattern with SQS
Flip cardThe Strangler Fig Pattern is an incremental refactoring technique where new services gradually replace specific functionalities of a monolithic application. Integrating Amazon SQS enables asynchronous communication, decoupling services and improving resilience and scalability.
- Allows for gradual modernization of monolithic applications.
- Minimizes risk compared to a 'big bang' rewrite.
- Amazon SQS adds resilience through asynchronous processing and message queuing.
Memory trick: Strangler SQS Smoothly Scales.
Elastic Scalability
Flip cardThe ability of a system to automatically scale its resources up or down in response to changes in demand, ensuring optimal performance and cost efficiency.
- Matches capacity to demand.
- Prevents over-provisioning and under-provisioning.
- Often uses services like Auto Scaling Groups, SQS, and serverless compute.
Memory trick: Elasticity stretches and shrinks like a rubber band with demand.
AWS Snowball Edge
Flip cardA physical device from the AWS Snow Family that allows customers to transfer large amounts of data to and from AWS, or to perform edge computing workloads.
- Comes in Storage Optimized and Compute Optimized versions.
- Ideal for data transfers from tens of terabytes to petabytes.
- Provides secure data transfer using 256-bit encryption and tamper-evident enclosures.
Memory trick: Network for the fast, Snow for the vast.
Amazon S3 Glacier Deep Archive
Flip cardThe lowest-cost Amazon S3 storage class for long-term archival storage, designed for data accessed once or twice a year with retrieval times up to 12 hours.
- Lowest cost S3 storage class.
- Ideal for long-term archives (7-10+ years).
- Retrieval times typically 12 hours.
- High durability (11 nines).
Memory trick: Deep Archive, Deepest Savings
AWS Fargate with ECS
Flip cardAWS Fargate is a serverless compute engine for Amazon ECS that allows you to run containers without having to manage servers or clusters. ECS orchestrates the deployment and management of these containers.
- Eliminates server management (serverless containers).
- Scales rapidly based on demand.
- Pay-per-use for compute resources.
Memory trick: Fargate gives you a 'free gate' from server management for your ECS containers.
AWS CodePipeline, CodeBuild, CodeDeploy
Flip cardA suite of AWS services that together form a fully managed continuous integration and continuous delivery (CI/CD) pipeline.
- CodePipeline orchestrates the release process.
- CodeBuild compiles, tests, and packages code.
- CodeDeploy automates deployments to various compute services.
- Integrates with CodeCommit for source control.
Memory trick: Pipeline Builds and Deploys Code
Amazon SQS FIFO Queue
Flip cardA message queuing service that guarantees message ordering and exactly-once processing, ideal for applications where the order of operations and no duplication are critical.
- Guarantees message order (FIFO).
- Ensures exactly-once processing.
- Supports message groups for parallel processing of related messages.
Memory trick: FIFO Guarantees First-In, First-Out Order
Amazon Simple Queue Service (SQS)
Flip cardA fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications.
- Supports standard and FIFO queues.
- Eliminates the complexity of managing message-oriented middleware.
- Highly scalable and durable message storage.
Memory trick: SQS is like a 'Simple Queue' where messages wait their turn.
AWS Snow Family
Flip cardA collection of physical devices that help customers migrate large amounts of data to and from AWS, or perform computing in disconnected environments.
- Includes Snowcone, Snowball Edge, and Snowmobile.
- Designed for offline data transfer where network transfer is impractical or too slow.
- Provides physical security and encryption for data in transit.
Memory trick: Small to Big Snow: Cone, Ball, Mobile.
AWS Transit Gateway with Direct Connect
Flip cardA combination of AWS Transit Gateway as a central routing hub for VPCs and on-premises networks, and AWS Direct Connect for dedicated, high-bandwidth hybrid connectivity.
- Simplifies network topology, reduces peering complexity.
- Enables central management of routing policies.
- Scales to thousands of VPCs across accounts and regions.
- Direct Connect provides private, high-bandwidth, low-latency link to on-premises.
Memory trick: Transit Gateway is The Global Hub
AWS Step Functions with AWS Batch
Flip cardA powerful combination for building robust and scalable batch processing workflows. Step Functions orchestrates multi-step processes with built-in error handling and retries, while AWS Batch provides fully managed, elastic compute resources for executing the batch jobs.
- Step Functions for workflow orchestration, state management, and error handling.
- AWS Batch for managed, scalable compute resources (EC2, Fargate).
- Ideal for complex, long-running, and critical batch processing.
Memory trick: Step Functions orchestrates the dance, Batch does the heavy lifting, S3 holds the props.
Amazon Elastic File System (EFS)
Flip cardA scalable, elastic, cloud-native NFS file system for Linux-based workloads, designed to be used with AWS Cloud services and on-premises resources.
- Fully managed and highly available.
- Scales automatically from gigabytes to petabytes.
- Supports NFSv4 protocol, accessible from EC2, containers, and on-premises via AWS Direct Connect/VPN.
Memory trick: EBS for one, EFS for many, S3 for objects.
AWS Snowball Edge Storage Optimized
Flip cardA rugged, portable storage and compute device used for physically transferring petabyte-scale data into and out of AWS, especially when network bandwidth is limited.
- Designed for large data migrations (hundreds of TB to PBs).
- Includes local compute for edge processing.
- Secure (encryption, tamper-evident seals) and verifiable.
- Ideal for environments with limited or no internet connectivity.
Memory trick: Snowball Edge, Enormous Data, Easy Entry
Amazon S3 Glacier Storage Classes
Flip cardA family of Amazon S3 storage classes optimized for archiving data that is infrequently accessed, offering various retrieval times and cost points.
- Includes S3 Glacier Instant Retrieval, S3 Glacier Flexible Retrieval, and S3 Glacier Deep Archive.
- Designed for cost-effective long-term data retention.
- Different classes offer trade-offs between retrieval speed and cost.
Memory trick: Cost vs. Time: Standard, IA, Glacier, Deep Archive.
AWS Transit Gateway
Flip cardA network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks to a single gateway. It simplifies network management and creates a hub-and-spoke network topology.
- Enables transitive routing between attached VPCs and VPN/Direct Connect.
- Centralizes network connectivity and routing.
- Supports routing policies for network segmentation and traffic inspection.
Memory trick: Transit Gateway is the 'traffic cop' for your cross-VPC and on-prem networks.
Lift and Shift (Rehost)
Flip cardMigrating an application to the cloud without making significant changes to its architecture. Often involves moving applications from on-premises servers to AWS EC2 instances.
- Minimizes initial migration effort and risk.
- Good for legacy applications with complex dependencies.
- May not fully leverage cloud-native benefits immediately.
Memory trick: Lift and Shift is like moving a whole box without opening it.
Kinesis Data Streams + Kinesis Data Analytics for Flink
Flip cardAmazon Kinesis Data Streams is a highly scalable, durable real-time data streaming service. Amazon Kinesis Data Analytics for Apache Flink is a fully managed service that allows you to easily process and analyze streaming data in real time using Apache Flink.
- Kinesis Data Streams ingests data at high throughput.
- Kinesis Data Analytics for Flink provides serverless real-time processing.
- Reduces operational overhead and scales automatically.
Memory trick: Kinesis Keeps Kicking Knowledge.
KMS Customer Managed Keys (CMKs) for EBS Encryption
Flip cardAWS Key Management Service (KMS) allows creating and managing encryption keys. Customer Managed Keys (CMKs) are encryption keys that you own and control, providing granular control over their lifecycle, permissions, and auditing. These can be used to encrypt EBS volumes.
- CMKs provide full control over key rotation, permissions, and revocation.
- Encrypting EBS volumes ensures data at rest encryption for EC2 instances.
- Integrates with many AWS services for encryption.
Memory trick: KMS Keys Keep Kustomer Control.
AWS Key Management Service (KMS) with Customer Managed Keys (CMKs)
Flip cardAWS KMS is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. CMKs are encryption keys that you create, own, and manage in KMS, giving you full control over their lifecycle.
- You control key policies, rotation, and permissions.
- Integrated with many AWS services for encryption.
- All key usage is logged in AWS CloudTrail for auditing.
Memory trick: KMS CMKs: Your keys, your rules, your audit trail.
S3 Pre-signed URLs with Multi-Part Upload
Flip cardA method to securely allow users to directly upload or download objects to/from Amazon S3 without exposing AWS credentials, with Multi-Part Upload specifically optimizing large file uploads for efficiency and reliability.
- Pre-signed URLs grant temporary access to S3 objects.
- Multi-Part Upload breaks large files into smaller parts for parallel upload.
- Combining them allows secure, resumable, and efficient large file uploads directly to S3.
Memory trick: Pre-signed URLs are your temporary key, Multi-Part is how you break the big package into smaller, faster deliveries.