EC2 Flashcards
What are Security Groups
Security groups are a virtual firewall that controls traffic to and from EC2 Instances. (operate at instance level)
Are security groups stateful or stateless? Describe what that means.
Security groups are STATEFUL. This means that if traffic is allowed inbound, then it is automatically allowed outbound.
Describe Security Group defaults
All inbound traffic is blocked by default. All outbound traffic is allowed by default. Each region has 2,500 security groups per region. Each SG has a default of 5 Elastic Elastic Network Interfaces (ENIs).
How many SGs can you have per region
10,000 (default is 2500)
How many SGs can be associated with an ENI?
16 max (default is 5)
How many inbound/outbound rules can be assigned to a Security Group?
60 each(inbound/outbound)
How many Security Groups can be associated with an EC2 instance (1 or many)
many
T/F - Security Groups can be assigned to multiple EC2 instances
true
What is EC2?
Elastic Cloud Compute -> A cloud computing service
What are the 5 main EC2 instance types?
General Purpose Compute Optimized Memory Optimized Accelerated Optimized Storage Optimized
Describe General Purpose EC2 Instances
balance of compute, memory, and networking resources. Uses resources in equal proportions.
Describe Compute Optimized EC2 Instance Type
- Ideal for compute bound applications that benefit from high performance processor.
- Batch processing loads.
- High performance web servers.
- Dedicated Gaming machine.
- Scientific modeling.
Describe Memory Optimized EC2 Instance Type
Ideal for workloads that process large datasets in memory.
Described Accelerated Optimized EC2 Type
Uses hardware accelerators and co-processors. Think Machine Learning. Floating point # calculations. Graphics processing.
Describe Storage Optimized EC2 Instance Type
High Sequential Read/Write access to large datasets on local storage. Use cases = NO-SQL DB, data warehouse, elasticSearch, Analytic workloads.
What are placement groups?
Allows you to specify the logical placement of your EC2 instances in order to optimize for communication, performance or durability.
What do placement groups cost?
They are free
What is the purpose of the UserData Section id the EC2 configuration?
This area allows you to upload a script that will automatically run when launching an EC2 instance.
What are the 4 pricing categories for EC2?
On-Demand SPOT Reserved Dedicated
Explain On-Demand EC2 pricing
Least commitment low cost and flexible pay per hour Good for short term, spikey or unpredictable workloads. Services can not be interuppted. Good for first time apps.
Explain the EC2 Reserved Price model
Best long term strategy. Good for steady state pr predictable usage. Commit from 1-3 years. Can resell unused reserved instances.
Explain Spot EC2 pricing
Provides the biggest savings User requests an instance at a specific price and if approved can use that instance until instance is needed by another user that is willing to pay a higher price. Instances can be terminated at anytime. If AWS terminates the instance you DO NOT pay for the partial hour usage. If you terminate the instance you DO pay partial hour usage.
What are the 3 types of reserved instances?
Standard RI Convertible RI Scheduled RI
What is a Standard Reserved Instance?
Up to 75% reduced pricing compared to On-Demand. Cannot change RI attributes.
What is a Convertible Reserved Instance?
Up to 54% reduced pricing compared to on-demand. Allows you to change RI Attributes if greater then or equal to current instance.
What is a Scheduled Reserved Instance (RI)?
You reserve an instance for specific time periods (i.e once a week for a few hours. Savings vary depending on schedule.
What is an Elastic IP Address and how is it different then a public IP Address in AWS?
An AWS Public IP can change if the instance is stopped and restarted. In order to maintain consistency, an Elastic IP can be assigned to an instance. This is a public IP that remains the same even when an instance stops.
What are Burstable Instances?
T2 Machines Can handle unexpected traffic by using “burst credits” If all credits are gone, the CPU becomes poor and user should consider moving to a large instance type. If a burstable machine does not need to “burst”, burst credits build up over time
How are EC2 instances billed?
By the second, with a minimum of 60 seconds
Do PRIVATE IPs change if the instances stops?
No but public does
What is the URL for EC2 Instance Metadata?
- http://169.254.169.254/latest/meta-data
- This is an internal URL to AWS.
- It will only work from inside your EC2 instance.
- It will NOT work from your computer.
What is EC2 Metadata?
Info about the EC2 Instance
Can you retrieve an EC2 IAM Policy from the EC2 metadata?
No, but you can retrieve the IAM Role name and use the AWS IAM Policy Simulator to test that Role.