General Flashcards

1
Q

6 advantages of cloud

A
  • Trade capital expense for variable expense
  • Benefit from massive economies of scale
  • Stop guessing about capacity
  • Increase speed and agility
  • Stop spending money running and maintaining data centers
  • Go global in minutes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

3 types of cloud computing

A
  • IAAS
  • PAAS
  • SAAS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

3 types of Cloud Computing deployments

A
  • Public Cloud (AWS, Azure)
  • Private Cloud (Your own datacenter
  • Hybrid (Mix of both)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Availability Zone

A

One or more closely-located data centers, each with redundant power, networking, connectivity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Region

A

A geographical area

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A region always has at least _____ AZs

A

2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Edge Location

A

Endpoint for caching content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Factors for choosing the right Region

A
  • Data sovereignty laws (data needs to be physically stored in a certain location)
  • Latency to end-users
  • AWS Services (us-east-1 has the most services available)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

4 Support Plans (Names)

A
  • Basic
  • Developer
  • Business
  • Enterprise
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Basic Support Plan (not including response times)

A
  • Free
  • No tech support
  • No TAM
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Developer Support Plan (not including response times)

A
  • $29/month
  • Tech support via email during business hours
  • No TAM
  • 1 person can open unlimited support cases
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Business Support Plan (not including response times)

A
  • $100/month (at least)
  • 24 x 7 tech support via email, chat, phone
  • No TAM
  • Unlimited people can open unlimited support cases
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Enterprise Support Plan (not including response times)

A
  • $15,000/month
  • 24 x 7 tech support via email, chat, phone
  • Includes TAM
  • Unlimited people can open unlimited support cases
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What support level includes a TAM

A

Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Basic Support Plan response times

A

None

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Developer Support Plan response times

A
  • General guidance: < 24 business hrs

- System impaired: < 12 business hrs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Business Support Plan response times

A
  • General guidance: < 24 hrs
  • System impaired: < 12 hrs
  • Prod system impaired: < 4 hrs
  • Prod system down: < 1 hr
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Enterprise Support Plan response times

A
  • General guidance: < 24 hrs
  • System impaired: < 12 hrs
  • Prod system impaired: < 4 hrs
  • Prod system down: < 1 hr
  • Business-critical system down: < 15 min
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Root account

A

Email address account used to set up AWS account. Always has admin access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

How are permissions given to users in a group

A

Policies are associated to the group, and users inherit the permissions in these policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Credential Report

A

IAM report that lists all users in your account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

7 S3 Storage Classes (names)

A
  • Standard
  • Infrequently Accessed (IA)
  • One Zone IA
  • Intelligent Tiering
  • Glacier
  • Glacier Deep Archive
  • Outposts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

“Standard” S3 storage class

A

99.99% available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

“Infrequently Accessed (IA)” S3 storage class

A

Accessed less frequently, but still need rapid access. Charged retrieval fee.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

“One Zone IA” S3 storage class

A

Same as IA but without multiple AZ resilience

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

“Intelligent Tiering” S3 storage class

A

Auto move data to most cost-effective tier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

“Glacier” S3 storage class

A

Retrieval times from minutes to hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

“Glacier Deep Archive” S3 storage class

A

12 hour retrieval time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

“Outposts” S3 storage class

A

For on-prem Outpost environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

S3 file size range

A

0B to 5TB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

S3 storage limit

A

Unlimited

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Timing for S3 operations (Write/Read, Update, Delete)

A
  • New files are readable instantly

- Update/Delete takes up to a second to propagate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

S3 Cross-region replication

A

Replicating contents of a bucket into another region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

3 ways to restrict bucket access

A
  • Bucket policy
  • Object policy
  • IAM policies to users/groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What is the advantage of static websites in S3

A

S3 scales to meet demand, so many concurrent visitors will be handled automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Default TTL for CloudFront

A

Greater of the two: 24 hrs or configured minimum TTL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

3 components of CloudFront

A
  • Edge location (caching location)
  • Origin (orig file source)
  • Distribution (name of cdn)
38
Q

2 types of CloudFront distributions

A
  • Web

- RTMP (Adobe’s flash protocol)

39
Q

EC2 pricing models (names)

A
  • On Demand
  • Reserved
  • Spot
  • Dedicated Hosts
40
Q

“On Demand” EC2 pricing model

A

Fixed rate by hour/second, no up-front cost

41
Q

“Reserved” EC2 pricing model

A

Pay up front; discounted hourly rate but you must lock into 1 or 3 year contract

42
Q

“Spot” EC2 pricing model

A

You set desired cost, and instanced is auto-provisioned when current price hits that bid; Instance is terminated if price changes from bid

43
Q

“Dedicated Hosts” EC2 pricing model

A

Physical EC2 servers for software licenses that require dedicated hosts

44
Q

What happens if a Spot EC2 instance is terminated by AWS?

A

You will not be charged for the partial hour of usage

45
Q

EC2 Reserved Instance pricing types (names)

A
  • Standard
  • Convertible
  • Scheduled
46
Q

“Standard” EC2 Reserved Instance pricing type

A

Up to 75% off on-demand pricing

47
Q

“Convertible” EC2 Reserved Instance pricing type

A

Up to 54% off on-demand pricing, but can change attributes of instance as long as it results in an instance of equal or greater value; Can’t revert

48
Q

“Scheduled” EC2 Reserved Instance pricing type

A

Can launch within time windows you reserve

49
Q

EC2 Instance Type Mnemonic

A

Fight Dr. McPxz Australia

FIGHTDRMCPXZAU

50
Q

EBS

A
  • Elastic Block Storage
  • Installing Operating Systems or Databases
  • Virtual storage volumes used by EC2 instances
51
Q

4 Types of EBS volumes

A
  • General Purpose SSD
  • Provisioned IOPS SSD
  • Throughput Optimized HDD
  • Cold HDD
52
Q

Security Groups

A
  • Virtual firewalls in the cloud

- You must open ports to use them

53
Q

Ports for 4 common protocols when using Security Groups

A
  • 22 (SSH)
  • 80 (HTTP)
  • 443 (HTTPS)
  • 3389 (RDP)
54
Q

3 ways to interact with AWS

A
  • Console
  • CLI
  • SDK
55
Q

Which is more secure: roles or access keys?

A

Roles

56
Q

3 types of Load Balancers

A
  • Application (ALB) - has access to code
  • Network (NLB) - extreme performance; static IPs
  • Classic - Test/Dev; keeps costs low
57
Q

Amazon Macie

A

Fully managed data security/privacy service that uses machine learning to discover and protect sensitive data in AWS

58
Q

VPC Peering

A

Allows access between two VPCs

59
Q

Internet Gateway

A

Horizontally scaled, highly-available VPC component that allows communication from a VPC to the internet

60
Q

How to design EC2 for failure

A

Put one instance in each AZ

61
Q

6 RDS DB Engines

A
  • SQL Server
  • Oracle
  • MySQL Server
  • PostgreSQL
  • Aurora
  • MariaDB
62
Q

Red Shift

A

Data warehouse for OLAP (Online Analytics Processing)

63
Q

RDS 2 key features

A
  • multi-AZ (for disaster recovery)

- read replicas (for performance)

64
Q

Read Replicas (RDS)

A

Auto-replicated database used only for reading

65
Q

ElastiCache

A
  • Web service for deploying/operating/scaling in-memory caches in the cloud
  • Place to store most frequently used queries
66
Q

2 caching engines supported by ElastiCache

A
  • Memcached

- Redis

67
Q

3 Compute Services

A
  • EC2
  • Lambda
  • Elastic Beanstalk
68
Q

Elastic Beanstalk

A
  • A way of deploying web apps to the cloud

- Automatically handles capacity provisioning, load balancing, scaling, health monitoring

69
Q

Elastic Beanstalk vs. CloudFormation

A
  • Both auto-provision resources

- Elastic beanstalk is not programmable, CF is

70
Q

Benefits of Cloud Computing vs Traditional Computing

A
  • IT Assets as provisioned resources
  • Global, available, and scalable capacity
  • Higher level managed services
  • Built-in security
  • Architecting for cost
  • Operations on AWS (refactoring, rearchitecting)
71
Q

Pillars of AWS Well-Architected Framework

A
  • Operational Excellence
  • Security
  • Reliability
  • Performance Efficiency
  • Cost Optimization
72
Q

AWS Graph DB

A

Amazon Neptune

73
Q

Global AWS Services

A
  • IAM
  • Route53
  • CloudFront
  • SNS
  • SES (not all regions)
74
Q

AWS Services that can be used on-prem

A
  • Snowball
  • Snowball Edge
  • Storage Gateway
  • CodeDeploy
  • Opsworks
  • IoT Greengrass
75
Q

CloudWatch EC2 default monitoring interval

A

5 minutes

76
Q

How to increase CloudWatch EC2 monitoring interval

A

Turn on detailed monitoring (1 minute)

77
Q

Opsworks

A

Uses Chef to deploy app code to EC2 or OnPrem Opsworks env

78
Q

Snowball

A

Disk shipped to data center to migrate data (80TB), then shipped back to AWS

79
Q

Storage Gateway

A

Similar to Snowball, but never leaves your datacenter

80
Q

AWS Systems Manager

A
  • Connects to EC2 instances or VMs via installed agent
  • In AWS or on-prem
  • Run commands, apply patches
81
Q

Service Health Dashboard

A

Monitor health of entire services (not resources)

82
Q

Personal Health Dashboard

A

Monitor health of services you actually use

83
Q

EFS

A
  • Elastic File System

- File storage for EC2 instances

84
Q

Difference between EBS and EFS

A

EFS is elastic (size is adjusted automatically)

85
Q

Global Accelerator

A

Create accelerators to improve availability and PERFORMANCE of your apps for users where internet is ingested

86
Q

Load Balancer vs Autoscaling Group

A

Autoscaling group spins up new instances, Load Balancer redirects traffic to already running instances

87
Q

AWS Trusted Advisor

A

A tool that provides you real time guidance to help you provision your resources following AWS best practices

88
Q

AWS Certificates Manager

A

A service that lets you manage public and private SSL/TLS certificates for use with AWS services and your internal connected resources

89
Q

AWS Artifact

A

A service that provides on-demand access to AWS’ security and compliance reports and select online agreements

90
Q

Customer-inherited controls

A

Physical and Environmental controls

91
Q

Shared Controls

A
  • Patch management
  • Configuration management
  • Awareness and training
92
Q

Customer Specific Controls

A

Service and Communications Protection or Zone Security