AWS Certified Solutions Architect – Professional flashcards
132 free flashcards. Tap a card to flip it.
AWS Snowball Edge
Flip cardA physical device from the AWS Snow Family that allows customers to transfer large amounts of data to and from AWS, or to perform edge computing workloads.
- Comes in Storage Optimized and Compute Optimized versions.
- Ideal for data transfers from tens of terabytes to petabytes.
- Provides secure data transfer using 256-bit encryption and tamper-evident enclosures.
Memory trick: Network for the fast, Snow for the vast.
Asynchronous Microservices Communication (SQS)
Flip cardAsynchronous communication decouples microservices, allowing them to send messages without waiting for an immediate response. Amazon SQS acts as a message queue, buffering messages and enabling services to process them independently, improving resilience and scalability.
- Decouples services, preventing cascading failures.
- Buffers requests during traffic spikes.
- Improves scalability and resilience of distributed systems.
Memory trick: SQS Secures Spiky Systems.
Database Migration with Minimal Reporting Tool Refactoring
Flip cardMigrating an operational data store (DB2) to a compatible AWS managed relational database service (e.g., RDS for MySQL) and using AWS DMS for replication from the primary application database (e.g., Aurora MySQL) to minimize changes to legacy reporting tools.
- Choose a target database engine compatible with the original for reporting tools to avoid refactoring.
- AWS DMS provides continuous data replication for consistency between databases.
- Leverages managed database services for high availability and scalability.
- Aids in phased migration strategies for complex applications.
Memory trick: Same SQL engine in RDS, DMS keeps the reports consistent.
Amazon FSx for NetApp ONTAP
Flip cardA fully managed service that provides highly reliable, scalable, and high-performance file storage built on NetApp ONTAP file systems.
- Supports NFS, SMB, and iSCSI protocols.
- Offers advanced data management features like snapshots, replication, and data deduplication.
- Ideal for enterprise workloads such as ERP, SAP, and media processing.
Memory trick: ERP needs ONTAP for consistent shared files.
Re-hosting (Lift and Shift)
Flip cardRe-hosting, or 'Lift and Shift,' is a migration strategy where applications and databases are moved to a cloud environment with minimal or no changes to their architecture. This approach is often used for quick migrations and to gain immediate cloud benefits.
- Minimal architectural changes
- Fastest migration path
- Good for gaining initial cloud experience
- Can be a first step towards future modernization
Memory trick: 7 Rs of Migration: Right Move for the Right App.
AWS KMS
Flip cardA managed service that makes it easy for you to create and control the encryption keys used to encrypt your data.
- Integrates with many AWS services for encryption.
- Provides centralized key management.
- Supports customer managed keys (CMKs) and AWS managed keys.
Memory trick: KMS encrypts, IAM controls, CloudTrail audits.
AWS Direct Connect with Direct Connect Gateway
Flip cardA service providing a dedicated network connection from an on-premises network to AWS, combined with a gateway to connect to multiple VPCs across different AWS Regions.
- Offers consistent network performance and reduced latency.
- Provides a private, secure connection, bypassing the public internet.
- Direct Connect Gateway enables connectivity to VPCs in any AWS Region (except China) via a single connection.
Memory trick: Direct Connect is the dedicated highway for hybrid networks.
Replatforming (Database)
Flip cardMigrating a database to a different platform, often a managed service, with minimal application code changes, while retaining the same database engine type (e.g., Oracle to RDS for Oracle).
- Reduces operational overhead by using managed services.
- Minimizes application code changes compared to re-architecting.
- Leverages cloud features like scalability and high availability.
Memory trick: Keep the core, upgrade the bed, then lift the rest.
AWS Direct Connect
Flip cardAWS Direct Connect establishes a dedicated network connection from your premises to AWS, offering reduced network costs, increased bandwidth throughput, and a more consistent network experience than Internet-based connections.
- Private, dedicated network connection
- Bypasses the public internet
- Offers consistent network performance and reduced latency
- Supports multiple virtual interfaces (VIFs) for different services
Memory trick: Directly Connect for a Smooth Hybrid Path.
Amazon CloudHSM
Flip cardA cloud-based hardware security module (HSM) service that enables you to easily generate and use your own encryption keys on the AWS Cloud.
- Provides FIPS 140-2 Level 3 validated hardware for key storage.
- Offers single-tenant HSMs for dedicated key isolation.
- Gives customers exclusive control over their cryptographic keys.
Memory trick: CloudHSM: Hardware Security, Highest FIPS Level.
S3 for Medical Imaging with Compliance
Flip cardUtilizing Amazon S3 Standard with features like Transfer Acceleration and Object Lock to store, ingest, and manage petabytes of medical imaging data while meeting compliance requirements.
- S3 offers extreme durability, scalability, and low-latency access for unstructured data.
- S3 Transfer Acceleration speeds up data transfers over long distances.
- S3 Object Lock provides WORM (Write Once, Read Many) functionality for immutability and regulatory compliance (e.g., HIPAA, SEC Rule 17a-4).
Memory trick: S3 is the secure, scalable vault for medical images.
Amazon SQS (Simple Queue Service)
Flip cardA fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications.
- Supports asynchronous communication between components.
- Offers standard queues (at-least-once delivery) and FIFO queues (exactly-once processing, message ordering).
- Eliminates the need to manage message broker infrastructure.
Memory trick: SQS: Simple Queues for Seamless System Sync.
Amazon ECS Fargate for Batch Processing
Flip cardA serverless compute engine for Amazon Elastic Container Service (ECS) that allows running containers without provisioning or managing servers, suitable for batch jobs and asynchronous processing.
- Eliminates server management overhead.
- Provides flexible resource allocation for CPU and memory.
- Scales automatically based on demand, ideal for variable workloads.
- Integrates well with messaging services like SQS for asynchronous task execution.
Memory trick: Fargate containers are the flexible, serverless workhorses for big reports.
Strangler Fig Pattern with Messaging
Flip cardThe Strangler Fig Pattern facilitates gradual migration from a monolithic application to microservices by incrementally replacing components. Integrating messaging queues (like Amazon SQS) enables asynchronous communication between the old and new services, helping manage eventual consistency and decoupling during the transition.
- Gradual, low-risk refactoring of monoliths
- Messaging queues (SQS) enable asynchronous communication
- Helps achieve eventual consistency in distributed systems
- Allows for concurrent operation of old and new components
Memory trick: Strangler Fig + SQS: Smoothly break apart the monolith.
Hybrid Messaging with Amazon MQ
Flip cardAmazon MQ is a managed message broker service for Apache ActiveMQ and RabbitMQ that makes it easy to set up and operate message brokers on AWS. It supports industry-standard APIs and protocols, simplifying migration of existing applications that use message-oriented middleware.
- Supports industry-standard protocols (JMS, NMS, AMQP, STOMP, MQTT, WebSocket).
- Managed service, reducing operational overhead.
- High availability and scalability built-in.
- Facilitates migration of legacy applications with minimal code changes to messaging logic.
Memory trick: Migrate Old Queues to AWS with MQ's Familiar Tune.
Amazon MQ for Hybrid Messaging
Flip cardA fully managed message broker service for Apache ActiveMQ and RabbitMQ that makes it easy to set up and operate message brokers in the cloud, facilitating hybrid messaging with on-premises systems.
- Supports industry-standard messaging protocols (e.g., AMQP, MQTT, OpenWire, STOMP).
- Offers high availability, message ordering, and guaranteed delivery.
- Reduces operational overhead by managing the broker infrastructure.
- Ideal for bridging existing on-premises messaging systems to AWS.
Memory trick: MQ bridges the old and new, keeping messages in order.
AWS Observability Suite
Flip cardA combination of AWS services (CloudWatch, X-Ray, CloudTrail) that provide monitoring, logging, and tracing capabilities for applications and infrastructure.
- CloudWatch for metrics, logs, and alarms.
- X-Ray for distributed tracing.
- CloudTrail for API call logging and auditing.
Memory trick: X-Ray traces, CloudWatch watches, Logs record.
AWS Key Management Service (KMS)
Flip cardA managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. KMS is integrated with most other AWS services.
- Manages encryption keys used by AWS services and applications.
- Supports customer-managed keys (CMKs) for granular control.
- Provides audit logs via AWS CloudTrail for key usage.
Memory trick: KMS: Your central key master for AWS security.
Re-hosting for Legacy Applications
Flip cardRe-hosting, or 'Lift and Shift,' is a migration strategy particularly suitable for legacy applications with complex dependencies or specific software versions that are difficult to update. It involves moving the application to cloud virtual machines (e.g., EC2) and often migrating databases to compatible managed services (e.g., RDS for the same engine) with minimal code changes.
- Minimal application code changes
- Fastest path to cloud for legacy apps
- Leverages existing application architecture
- Can be combined with managed database services for operational benefits
Memory trick: Lift and Shift: Old dogs, new cloud tricks.
AWS Direct Connect Gateway
Flip cardA global service that allows you to connect your on-premises network to one or more Amazon Virtual Private Clouds (VPCs) in any AWS Region using a single AWS Direct Connect connection.
- Enables global network connectivity over Direct Connect.
- Provides high bandwidth and low latency.
- Supports redundant connections for business continuity.
Memory trick: Direct Connect Gateway: Your global, fast lane to the cloud.
Re-platforming to Amazon RDS for Oracle
Flip cardMigrating an on-premises Oracle database to a fully managed Amazon Relational Database Service (RDS) for Oracle instance in AWS.
- Minimizes changes to application code and database schema as the database engine remains the same.
- Provides managed database services including backups, patching, and scaling.
- Offers high availability and performance improvements over self-managed on-premises databases.
Memory trick: Same Oracle, just Managed and Scaled in RDS.
Hybrid Messaging with AWS MQ
Flip cardIntegrating on-premises messaging systems with AWS cloud applications using AWS Managed Message Queue (MQ) services like RabbitMQ or ActiveMQ.
- Provides managed, highly available message brokers compatible with popular open-source engines.
- Enables reliable, asynchronous communication between hybrid environments.
- Supports standard protocols, facilitating integration with existing enterprise systems.
Memory trick: Mainframe needs a managed MQ bridge for smooth cloud talks.
Replatforming
Flip cardMigrating an application to the cloud with minimal changes to leverage cloud-native features, often involving containerization or managed databases.
- Also known as 'lift-and-tinker'.
- Balances effort with cloud benefits.
- Commonly uses managed services like RDS, ECS, EKS.
Memory trick: Choose your 'R' wisely: Rehost, Replatform, Refactor, Repurchase, Retire.
AWS Application Discovery Service
Flip cardAWS Application Discovery Service helps customers plan migration projects by gathering information about their on-premises data centers. It collects configuration, usage, and behavior data from servers to help identify application dependencies and create migration strategies.
- Automates data collection from on-premises servers
- Collects inventory, configuration, and performance data
- Maps application dependencies
- Helps identify suitable migration strategies
Memory trick: Discover your apps before you leap.
Hybrid Integration with AWS Managed AD
Flip cardIntegrating on-premises applications with AWS involves extending existing services like Active Directory to the cloud. AWS Directory Service for Microsoft Active Directory (Managed AD) can establish a trust relationship with an on-premises AD, allowing AWS resources and migrated applications to authenticate against the existing directory.
- Extends on-premises AD to AWS
- Enables seamless authentication for cloud resources
- Supports trust relationships for hybrid identity management
- Managed service, reduces operational burden
Memory trick: Managed AD: Your bridge for seamless hybrid auth.
Amazon FSx for Lustre
Flip cardA fully managed file system optimized for compute-intensive workloads, such as high-performance computing (HPC), machine learning, media processing, and financial simulations.
- Provides very high throughput and low-latency access.
- Designed for shared access across thousands of compute instances.
- Integrates with Amazon S3 for data persistence and cost-effectiveness.
Memory trick: Lustre is for lightning-fast, shared storage needs.
Hybrid Data Migration and Analytics with AWS
Flip cardA strategy combining AWS Snowball Edge for initial bulk data transfer, AWS Direct Connect for ongoing incremental updates, Amazon S3 for scalable storage, and Amazon EMR for big data analytics and machine learning.
- Snowball Edge accelerates migration of petabytes of data without internet bandwidth constraints.
- Direct Connect provides a private, consistent, and cost-effective link for continuous data flow.
- Amazon S3 offers highly durable, scalable, and cost-effective object storage.
- Amazon EMR is a managed cluster platform for running big data frameworks like Apache Spark and Hadoop, ideal for ML analytics.
Memory trick: Snowball starts the move, Direct Connect keeps it flowing, S3 stores it, EMR analyzes it.
Amazon ECS Fargate for Multi-Region Deployments
Flip cardLeveraging Amazon ECS with the Fargate launch type to deploy and manage containerized applications across multiple AWS Regions without managing underlying EC2 instances.
- Offers a serverless experience for running containers, reducing operational overhead.
- Provides high availability and automatic scaling capabilities.
- Simplifies multi-region deployments by standardizing container orchestration across regions.
Memory trick: Fargate is the serverless way to scale containers globally.
AWS Directory Service AD Connector
Flip cardA proxy service that allows AWS applications to use an existing on-premises Microsoft Active Directory without deploying a managed AD in AWS or establishing complex trusts.
- Acts as a gateway to forward authentication requests to on-premises AD.
- No synchronization or replication of AD data to AWS is required.
- Simplifies hybrid AD integration, especially with multiple distinct on-premises AD forests.
- Requires network connectivity (VPN or Direct Connect) to on-premises AD.
Memory trick: AD Connector is the direct, trusting bridge to multiple on-prem forests, no copies needed.
Amazon Aurora
Flip cardA MySQL and PostgreSQL-compatible relational database built for the cloud, combining the performance and availability of traditional enterprise databases with the simplicity and cost-effectiveness of open-source databases.
- Up to 5x faster than MySQL and 3x faster than PostgreSQL.
- Scales automatically, up to 128TB of storage.
- Highly available with up to 15 read replicas across multiple AZs.
Memory trick: Aurora shines for speed and scales for reads.
Scalable Web Application Architecture
Flip cardA scalable web application architecture on AWS typically involves using auto-scaling compute (EC2 Auto Scaling, ECS/Fargate), a highly available and scalable database (Aurora Multi-AZ), and a distributed caching layer (ElastiCache) to handle variable traffic loads and ensure optimal performance and cost efficiency.
- Decouples components for independent scaling
- Utilizes managed services for operational efficiency
- Employs caching to reduce database load and improve response times
- Designed for high availability and fault tolerance
Memory trick: Auto-scale, Aurora, ElastiCache: The Triple-A for E-commerce.
AWS Route 53 Resolver Endpoints for Hybrid DNS
Flip cardA feature of Amazon Route 53 that enables seamless DNS query resolution between VPCs and on-premises networks without direct exposure of entire networks.
- Inbound endpoints allow on-premises DNS to resolve AWS DNS names.
- Outbound endpoints allow AWS resources to resolve on-premises DNS names.
- Supports conditional forwarding rules for specific domain resolution.
- Provides highly available and scalable hybrid DNS resolution.
Memory trick: Route 53 Resolver is the smart traffic cop for hybrid DNS queries.
Amazon FSx for Windows File Server
Flip cardA fully managed native Microsoft Windows file system that provides highly reliable, scalable, and secure file storage accessible via the Server Message Block (SMB) protocol.
- Native SMB support for Windows-based applications.
- Fully managed service, reducing operational overhead.
- Integrates with Active Directory and supports data residency.
Memory trick: FSx for Windows is the native bridge for your legacy file shares.
Pilot Light Disaster Recovery
Flip cardA DR strategy where a minimal set of core infrastructure is always running in the recovery region, and data is continuously replicated. Full capacity is provisioned during a disaster.
- Balances cost and recovery time.
- Data continuously replicated (low RPO).
- Applications scaled up on demand (moderate RTO).
Memory trick: Backup, Pilot, Warm, Hot: Know your recovery temperature.
AWS FSx for Lustre
Flip cardAWS FSx for Lustre is a fully managed file system that is optimized for compute-intensive workloads, such as high-performance computing (HPC), machine learning, and media processing. It provides high-performance, POSIX-compliant file storage that integrates with Amazon S3.
- Optimized for HPC workloads (ultra-low latency, high throughput)
- POSIX-compliant file system
- Integrates with Amazon S3 for durable data storage
- Fully managed service, reduces operational overhead
Memory trick: FSx for Lustre: Your HPC's lightning-fast file system.
AWS Data Lake on S3
Flip cardA centralized, curated, and secured repository that stores all your data, both structured and unstructured, at any scale, typically built on Amazon S3.
- Scalable and cost-effective for petabyte-scale data storage.
- Supports various data formats (structured, semi-structured, unstructured).
- Integrates with serverless analytics services like Athena, Glue, and Redshift Spectrum.
Memory trick: From Hadoop's past to S3's lake, serverless queries we make.
Hybrid Messaging
Flip cardAn architecture where messaging components exist both on-premises and in the cloud, allowing applications in both environments to communicate.
- Enables phased migration of applications.
- Requires robust network connectivity (e.g., Direct Connect).
- Can use message brokers like AWS MQ or self-managed solutions.
Memory trick: Direct Connect bridges, Hybrid MQ speaks both languages.
AWS Data Lake
Flip cardA centralized repository that allows you to store all your structured and unstructured data at any scale, making it accessible for analytics.
- Typically built on Amazon S3.
- Uses services like AWS Glue for ETL and cataloging.
- Analyzed with services like Athena, Redshift Spectrum, EMR.
Memory trick: S3 lake, Glue transforms, Athena queries.
AWS Control Tower
Flip cardA service that sets up and governs a secure, multi-account AWS environment, enforcing best practices and compliance.
- Automates setting up a landing zone.
- Provides guardrails for compliance.
- Centralizes identity and access management.
Memory trick: Control your Tower, Identity your Center, Region your Data.
Real-time Analytics Pipeline
Flip cardA real-time analytics pipeline on AWS typically involves services for high-throughput data ingestion (e.g., Kinesis), serverless or stream-processing compute (e.g., Lambda, Kinesis Analytics), and cost-effective, scalable storage for historical data (e.g., S3) with query capabilities (e.g., Athena).
- Handles high-volume, high-velocity data
- Enables immediate processing and insights
- Decouples components for scalability and resilience
- Leverages managed services for operational efficiency
Memory trick: Kinesis, Lambda, S3, Athena: The K.L.S.A. pipeline.
HIPAA Compliance on AWS
Flip cardAdhering to the Health Insurance Portability and Accountability Act (HIPAA) regulations when handling Protected Health Information (PHI) on AWS, requiring specific security and privacy controls.
- Requires encryption at rest and in transit.
- Strict access controls and auditing.
- Business Associate Addendum (BAA) with AWS.
Memory trick: Multi-AZ for uptime, Encrypt for PHI, Audit for compliance, Guard for threats.
Video Streaming Architecture on AWS
Flip cardA solution for ingesting, processing, storing, and delivering live and video-on-demand (VOD) content using specialized AWS Media Services and a global CDN.
- Uses MediaLive for live ingestion and encoding.
- Employs MediaConvert for VOD transcoding.
- Leverages S3 for scalable storage and CloudFront for global delivery.
Memory trick: MediaLive streams, MediaConvert transforms, S3 stores, CloudFront delivers.
Aurora Global Database for Gaming
Flip cardLeveraging Amazon Aurora Global Database to provide a scalable, low-latency, globally distributed relational database backend for multiplayer online games.
- Globally distributed relational database.
- Fast cross-Region replication (sub-second latency).
- High availability and resilience to regional failures.
- Supports complex relational data models and SQL queries.
Memory trick: Relational global game, use Aurora Global's power and speed.
DynamoDB Global Tables
Flip cardDynamoDB Global Tables provide a fully managed, multi-region, multi-master database that enables you to build globally distributed applications with low-latency data access for users worldwide.
- Automatic replication of data across multiple AWS regions.
- Provides fast, local read and write performance.
- Designed for internet-scale applications requiring high availability and global reach.
Memory trick: DynamoDB's Global Reach Ensures Instant Data Everywhere.
DynamoDB for MMO Games
Flip cardUtilizing Amazon DynamoDB Global Tables to provide a highly scalable, low-latency, and globally distributed NoSQL database for massively multiplayer online (MMO) game data such as player profiles, game state, and leaderboards, supporting millions of concurrent users.
- Multi-region active-active replication.
- Extremely low-latency (single-digit ms) reads/writes.
- Massive scalability for millions of concurrent users.
- Eventual consistency suitable for game state.
Memory trick: DynamoDB Global Tables: the ultimate power-up for global gaming data.
Aurora Global Database
Flip cardA feature of Amazon Aurora that allows a single Aurora database to span multiple AWS Regions, enabling fast local reads, rapid disaster recovery, and global active-active read scaling with low replication lag.
- Cross-Region replication with typical latencies under one second.
- Designed for global applications requiring low latency and high availability.
- Supports planned failover to a secondary region in under a minute.
- Scales to millions of transactions per second.
Memory trick: Globally spread your data, keep it snappy and safe.
Siloed Multi-Tenancy
Flip cardA multi-tenancy model where each tenant has completely separate, dedicated instances of the application and underlying infrastructure, often in separate AWS accounts.
- Provides the highest level of isolation and security.
- Eliminates the 'noisy neighbor' problem.
- Ideal for strict compliance and tenant-specific customization.
Memory trick: For ultimate isolation, silo each tenant in their own AWS home.
Real-time Fraud Detection on AWS
Flip cardAn architecture leveraging AWS services for ingesting, processing, and analyzing high-volume transactional data in real-time to identify and prevent fraudulent activities with low latency.
- Requires real-time data ingestion and processing.
- Needs low-latency decision storage and retrieval.
- Must be highly scalable and available.
Memory trick: Fraudsters Flee Fast, Kinesis Keeps Kicking.
AWS Media Workflow for Live & VOD
Flip cardAn integrated architecture using AWS Elemental services and S3/CloudFront to ingest, process, store, and deliver both live and on-demand video content globally with high quality and low latency.
- MediaConnect for reliable live ingest.
- MediaLive/MediaPackage for live encoding and packaging.
- MediaConvert for VOD transcoding.
- S3 for VOD storage, CloudFront for global delivery.
Memory trick: Connect, Live, Package, Convert, S3, CloudFront — The Full Stream Dream.
HPC Storage on AWS
Flip cardAWS solutions for storing and accessing large datasets for High-Performance Computing (HPC) workloads, focusing on throughput, latency, cost-effectiveness, and scalability.
- Uses S3 for object storage and data lakes.
- FSx for Lustre provides high-performance file systems for HPC.
- Intelligent-Tiering optimizes S3 costs.
- S3 Replication for global data sharing.
Memory trick: S3 Intelligent Lustre for Global Genomic Gold.
IoT Time-Series Data Platform
Flip cardAn architecture for ingesting, processing, and analyzing high-volume, real-time time-series data from IoT devices, often utilizing specialized databases and tiered storage.
- Leverages IoT Core and Kinesis for ingestion.
- Uses Timestream for hot time-series data.
- Combines S3 and Athena for cost-effective cold data analysis.
Memory trick: IoT Core streams to Kinesis, Lambda processes, Timestream holds hot, S3/Athena cools.
DynamoDB for Gaming
Flip cardAmazon DynamoDB's capabilities, especially Global Tables, make it a strong choice for game backends requiring high scale, low latency, and global availability for player data and game state.
- Handles millions of requests per second.
- Provides single-digit millisecond latency.
- Global Tables enable multi-region, multi-active replication.
Memory trick: DynamoDB Global Tables powers your game with worldwide speed and scale.
AWS Live Streaming Architecture
Flip cardA set of AWS services designed for ingesting, processing, packaging, and delivering live video content with low latency and high scalability.
- Uses MediaLive for encoding and MediaPackage for packaging live streams.
- MediaConnect ensures high-quality, reliable transport of live video.
- CloudFront delivers the content globally with low latency.
Memory trick: MediaLive, Connect, Package, and CloudFront Deliver the Stream.
VPC Endpoints (AWS PrivateLink)
Flip cardVPC Endpoints allow you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Traffic between your VPC and the service stays within the Amazon network.
- Enhances security by eliminating internet exposure.
- Supports both interface endpoints (ENIs) and gateway endpoints (for S3 and DynamoDB).
Memory trick: VPC Endpoints Keep Data Inside, Safe and Sound.
IoT Predictive Maintenance Architecture
Flip cardAn AWS architecture for ingesting, processing, and analyzing IoT sensor data in real-time to predict equipment failures and optimize maintenance schedules.
- AWS IoT Core for secure device connectivity and data ingestion.
- AWS Lambda for serverless real-time data processing and anomaly detection.
- Amazon S3 for cost-effective, scalable raw data storage (data lake).
- Amazon Redshift for historical analysis, aggregation, and ML model training.
Memory trick: Connect with IoT, process with Lambda, store in S3, analyze with Redshift.
IoT Data Ingestion and Processing Pipeline
Flip cardAn architecture designed to collect, process, and store high volumes of real-time data from IoT devices using serverless and managed AWS services.
- Uses IoT Core for device connectivity.
- Leverages Kinesis for high-throughput streaming ingestion.
- Employs Lambda for real-time event-driven processing.
Memory trick: IoT Core connects, Kinesis streams, Lambda processes, S3 stores.
HIPAA-Compliant Data Storage on AWS
Flip cardDesigning data storage on AWS to meet HIPAA requirements for Protected Health Information (PHI), emphasizing encryption, access control, and auditability.
- Encrypt data at rest (e.g., RDS SLE, S3 SSE-KMS).
- Encrypt data in transit (e.g., SSL/TLS, VPC Endpoints).
- Implement strong access controls (e.g., IAM, database authentication).
- Maintain detailed audit logs (e.g., CloudTrail, database logs).
Memory trick: PHI Needs Protection: Encrypt, Access Control, Audit, and Transit Secure.
AWS Live & VOD Streaming Architecture
Flip cardAn AWS solution for building scalable, highly available video streaming platforms that can ingest live feeds, transcode content, store media assets, and deliver both live and video-on-demand content globally with low latency.
- Supports both live streaming and VOD.
- Includes ingestion, transcoding, storage, and global distribution.
- Requires low latency and high availability.
Memory trick: MediaLive and MediaConvert stream to S3, then CloudFront delivers the global show.
VPC Endpoints
Flip cardA feature that enables private connectivity to supported AWS services and VPC endpoint services powered by AWS PrivateLink, ensuring that network traffic does not leave the Amazon network.
- Connects VPC to AWS services privately.
- Traffic stays within the Amazon network.
- No internet gateway, NAT device, VPN, or Direct Connect needed.
- Enhances security and compliance for sensitive data.
Memory trick: VPC Endpoints are private tunnels, keeping sensitive data off the public roads.
DynamoDB Global Tables for E-commerce
Flip cardLeveraging Amazon DynamoDB Global Tables to provide a highly scalable, low-latency, and globally distributed database solution for e-commerce product catalogs, supporting millions of requests per second with high availability and eventual consistency.
- Multi-region active-active replication.
- Extremely low-latency global reads and writes.
- Scales to millions of requests per second.
- Supports eventual consistency for updates.
Memory trick: DynamoDB Global Tables: products appear instantly worldwide, like magic.