Certified Cloud Practitioner Flashcards

1
Q

Region

A

Physical location/geographic location with 2+ AZ.

Minimize latency by deploying to 2+ regions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AZ

A

Physically/logically isolated data centers
Data provisioned across AZs
Not all zones offer all services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data Center

A

1+ per AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Edge Location

A

Host CloudFront (CDN) for faster delivery of static content with low latency/high transfer speeds
More edge locations than AZs
Catches data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Basics on Pricing

A

Usually no charge for inbound data or data within AWS region
Pay for CPU, data storage, outbound data transfer
The more you use, the less it costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

On demand

A

Pay as you
Most services pay per second of use
good for short term, spiky or unpredictable use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Reservations

A
Up to 75% less
1-3 year commitment
Pay none/partial/all up front
The more you pay up front the less it costs
Good for steady state usage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Spot

A

Up to 90% less
Pay for unused capacity
unpredictable when runs
ends when complete or price goes above bid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dedicated instance

A

Pay set hourly price
dedicated hardware for VPC
can use existing software licenses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Free tier

A

Some services free forver: VPC, Elastic BeanStalk, CloudFormation, IAM, AutoScaling, Opsworks, DynamoDB, Glacier, Lambda, Glue, Cognito, SNS, SES, SQS, SWF, Cloudwatch, Xray, Storage Gateway, etc
Some services free 12 months: EC2, S3, RDS, CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Basic Support

A

7 trusted advisor checks, personal health dashboard, docs/support forms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Developer Support

A

Basic + email support
1 contact
Response time 24 hrs for general, 12 hrs for impaired system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Business

A

Developer + full trusted advisor checks, phone support
unlimited contacts
response time 1 hour for prod down

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Enterprise

A

Business + senior cloud support engineers
Response time 12 minutes for business critical systems
Includes Wall Architected Review by AWS Solutions Architects, self packed labs, concierge support team, dedicated technical account manager (TAM).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Support Forms for

A
Encountering Abuse (sent to the abuse team)
Increasing limits beyond a point
penetration testing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Acceptable Use Policy

A

Don’t do bad things

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

EC2 (Elastic Compute Cloud) COMPUTE

A
Virtual server
proper name is EC2 instances
pay as you, pay for time running
maintain control
Don't have to provision/maintain server
assigned both public/private IP
has instance metadata
responsible for patch OS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

VPC (virtual private cloud) COMPUTE

A

isolate computer resources
control network config, access, what expose, etc
can span AZs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

ECS (elastic container service) COMPUTE

A

supports docker containers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

AMI COMPUTE

A

Amazon Machine Image
can use variety of preconfigured ones or create own
specifies type of hardware
bootable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Lamba COMPUTE

A

Serverless
pay only for compute by fraction of millisecond
ideal for variable/intermittent workloads
autoscales
supports many programming languages
limited disk space/memory
must run less than 5 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

IGW (Internet Gateway) NETWORKING

A

Allows access to internet from VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Subnet NETWORKING

A

Divides VPC
public subnets can access internet
private subnets cannot (by default)
VPC can have multiple subnets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Route tables NETWORKING

A

Register traffic leaving subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
NAT Gateway NETWORKING
allows private subnet to access the internet
26
CIDR (classless interdomain routing) NETWORKING
Internal IP address look like 10.0.0.0/16
27
Direct Connect
On premises to VPC connectivity or VPC TO VPC connectivity
28
PrivateLink
Connects to VPCs through endpoints
29
VPC Peering
Connects to VPCs privately
30
Route 53
``` DNS Geolocation routing latency based routng defaults to up to 50 domain names global services ```
31
elastic IP
static IPv4 address up to 5 per region pay if have more than one and not associated with running instance
32
Elastic Beanstalk
PaaS (platform as a service) application server | supplies all infrastructure so can just deploy app
33
CloudFormation
Manage/Provision collections of servers
34
application load balancer
http/https level includes https and websockets can route by path or hosts
35
Network Load Balancer
TCP level
36
ELB (elastic load balancer) - classic load balancer
Older loader balancer supports both http/tcp levels can mix with internal load balancers supports single region
37
Auto Scaling
Adds more EC2 instances as needed specify conditions/policy for when add/remove instances create launch config (what create if need new instance), group (constraints on what to create) and policy (when the scale) limit to 20 EC2 instances per region
38
Listener
Checks for connection requests to load balancer
39
Target
destination for traffic based on rules
40
Target groups
1+ targets target can be in multiple groups can do health check by target group
41
S3 (Simple Storage Service)
Object data up to 5TB can access by URL API to get data, not associated with specific server Can access via HTTP/HTTPS objects grouped into S3 buckets. Can have u[ to 100, can set policies on buckets. can replicate across regions durability is always 11 nines. Means probability of losing an object. Availability is 4 nines for standard and 3 nines for SIA (standard infrequent access)
42
EBS (elastic block store)
block storage storage for ec2 persistent data general purpose (SSD), provisioned IOPS (SSD), magnetic Automatically replicated with AZ. Can copy to other region for recovery Snapshots are backups
43
EFS (Elastic File System)
File storage for EC2
44
Aurora
Managed database service 5x faster than MySQL/Postgres faster version of MySQL Defaults to replicating twice in each of 3 AZs
45
RDS (relational database service)
Supports Aurora, MySQL, PostgresSQL, oracle, MS SQL Server, and MariaDB. Set up own IP, subnet, access control, etc Automatically generates standby database in another AZ Can create read replicas in different region for all but Oracle and MS SQL server
46
DynamoDB
Managed NoSQL service | Access by query (key) or scan (non-key attribute)
47
RedShift
managed data warehouse services Uses SQL supports petabytes of data OLAP (online analytical processing)
48
Snowball Edge
Physically transport 100TB of data
49
Snowball
Physically transport petabytes of data
50
Snowmobile
Physically transport up to 100 petabytes of data
51
Glacier
Data archiving each archive up to 40 TB infrequent access data encrypted by default archive - document stored vault - container for sorting archives. has access policy and lock policy ( can't alter when locked) data comes from S3(via lifecycle policies), SDK, CLI, or snowball/snowmobile import takes minutes or hours to retrieve data depending on cost bulk/standard/expedited
52
Transfer Accleration
transfer files over the internet across long distances with S3 bucket
53
DMS (data migration service)
migrate non-aws database to cloud
54
EMR (elastic map reduce)
hadoop
55
Glue
ETL(extract,transform,load)
56
Storage Gateway
Links to on premises data environment
57
Athena
serverless queries
58
Kinesis
streaming data
59
Kinesis Firehose
data load
60
Neptune
Graph database
61
SES (simple email service)
email
62
SNS (simple notification service)
publish messages | supports http/s, email, email JSON, SMS, SQS
63
SQS (simple queue service)
hosted queue | visible for 12 hours by default
64
SWF (simple workflow)
workflow | activity worker implements task
65
NACL (network access control list)
``` Statless Like passport control checks access each time on entry/exit optional at subnet level ```
66
Security Groups
built in firewall for virtual servers set up rules can control by protocol/port/ip by default, controls inbound (blocks all) and outbound traffic (allows all)
67
WAF (web application firewall)
blocks common attacks ex: XSS | global service
68
shared responsibility model
amazon - "of the cloud" | customer - "in the cloud"
69
Guard Duty
Threat Detection
70
IAM (identity and access management)
control access can't recover lost credentials allows each user up to two active keys global service
71
identities
people/processes/services | unit of authentication
72
groups
collections of users
73
root user
``` initial user created unrestricted access only use to create inital other users required to use CLI reccommended to delete access keys ```
74
role
identity with permission policies does not have own credentials used for apps used for SSO where authenticated at company
75
temporary credentials
credentials with restricted permission for a specific task
76
policy
applied to user/role/group to grant permissions
77
access types
programmatic access | management console access
78
TCO (total cost of ownership) Calculator
Determine costs before using don't need to be AWS customer yet compares on-prem and collocation to pure AWS
79
Trusted Advisor
Check security, fault tolerance, performance, cost savings for existing customers red (immediate action), yellow(investigate), green(good)
80
Cost Explorer
Billing visibility for current customers can see last 13 months data forecasts costs for next three months
81
Budgets
Alerts when costs exceed plan
82
Cost and Usage Report
Shows costs by category
83
CloudTrail
Records user activity/API calls
84
CloudWatch
``` Monitoring logs aggregates log can set billing alarm basic and detailed plans defaults to 5 minute granularity for basic and 1 minute for detailed ```
85
Inspector
find possible security issues focuses on s3 level automated compliance
86
artifact
view compliance reports
87
migration hub
track progress across AWS and partners
88
AWS SDKs
APIs
89
OpsWorks
DevOps platform | Uses Chef
90
CodeStar
UI for development
91
CodeCommit
Version Control
92
CodeDeploy
Automated deployment
93
CodePipeline
Continuous Delivery
94
Operational Excellence
``` Operations as code annotate documentation make frequent, small, reversible changes refine operations procedures frequently anticipate failure learn from operational failures ```
95
Security
``` implement a strong security foundation enable traceability apply security at all layers automate security at all layers automate security best practices protect data in transit and at rest prepare for security events ```
96
Reliability
``` Test recovery procedures Automatically recover from failure Scale horizontally to increase aggregate system availability Stop Guessing capacity manage change in automation ```
97
Performance Efficiency
``` Democratize advanced technologies Go global in minutes use serverless architectures experiment more often mechanical sympathy ```
98
Cost Optimization
Adopt a consumption model measure overall efficiency stop spending money on data center operation analyze and attribute expenditure use managed services to reduce cost of ownership
99
Pilot Light
Quick recovery option > minimal version always running
100
Slowest to Fastest Recovery
Backup & Restore > Pilot Light > Warm Standby > MultiSite
101
Fault tolerance
stays up even if parts fail | more strict than high availability
102
CloudFront
CDN (content delivery network) Can act as a cache to serve objects from S3 Global Service
103
Cognito
User sign up/access control
104
Config
Configuration history
105
Fargate
Run container
106
Macie
Machine learning about security
107
QuickSight
Business Analytics
108
Server Migration Service
Agentless migration from on-prem
109
Transcoder
Media conversion
110
Workspaces
Virtual Desktop
111
Xray
Distributed debugging/tracing
112
Assurance Programs
Include Certification/Attestation and Laws/Regulation/Privacy
113
Risk/Compliance Program
Risk Management, Control Environment and Information Security
114
Marketplace
Find software solution
115
Free pricing
Data in usually free | data transfer within a region usually free
116
EC2 Pricing
``` Server time used machine (type & config) # of instances load balancing and autoscaling monitoring level OS & Software packages ```
117
EBS Pricing
Volumes (data used) IO Operations per second Snapshots (backups) data transfer out
118
RDS pricing
``` server time used database (type, #) storage # of requests data transfer out ```
119
CloudFront
``` Traffic distribution (regions) requests (# and type) data transfer out ```