General Terms Flashcards
Amazon EC2 Instance Types
Reserved, On-Demand, Spot
AWS Global infrastructure
AWS Regions, Availibility Zones
Define the benefits of the AWS Cloud
Security, Reliability, High Availability, Elasticity, Agility, Pay-as-you-go Pricing, Scalability, Global Reach, Economy of scale
Explain how the AWS cloud allows users to focus on business value
Shifting technical resources to revenue-generating activities as opposed to managing infrastructure
Which operations will reduce costs by moving to the cloud
Right Sized Infrastructure, Benefits of Automation, Reduce Compliance Scope, Managed Services
Explain the different cloud architecture design principles
Design for failure, Decouple components vs. Monolithic architecture, Implement Elasticity in the cloud vs. on-premises, Think Parallel
Define the AWS Shared Responsibility Model
(Recognize the elements of the Shared Responsibility Model, Describe the customer and AWS’s responsibilities and how they may shift depending on the service used)
Where to find AWS Compliance information
Locations of lists of recognized available compliance controls (for ex. hippa,socs), recognize that compliance requirements vary among AWS services
Describe how customers achieve compliance on AWS
Identify different encryption options on AWS (for ex. in transit, at rest)
Recognize there are services that will aid in auditing and reporting
Recognize that logs exist for auditing and monitoring, define amazon CloudWatch, AWS Config, and AWS CloudTrail
Identify AWS Access Management Capabilities
Understand the purpose of User and Identity Management including - Access Keys and Password Policies (rotation, complexity), MFA, AWS IAM (Groups/Users, Roles, Policies, managed policies vompared to custom policies), Tasks that require use of root accounts, protection of root accounts
Recognize there are different network security capabilities
Native AWS Services (for example, security groups, Network ACLs, AWS WAF), 3rd party security products from Marketplace
Recognize there is documentation and where to find it
AWS Knowledge Center, Security Center, Security Forum, and Security blogs, Partner Systems Integrators
Security Checks
A component of AWS Trusted advisor
Identify at a high level different ways of provisioning and operating in the AWS Cloud
Programatic access, APIs, SDKs, AWS Management Console, CLI, Infrastructure as Code