IMPORT FlashCards
AWS SA FLASHCARDS
AUDIT AWS RESOURCES
AWS CONFIG
API MONITORING SERVICES
AWS CLOUD TRAIL
EVERY TIME A RESOURCE A CHANGED, WHERE DOES CONFIG RECORD THE CHANGE?
S3 BUCKET
LOGGING SERVICE THAT RECORDS ALL API CALLS TO ANY AWS SERVICE
AWS CLOUD TRAIL
RECORDS DETAILS OF A CALL, LIKE WHICH USER OR APPLICATION MADE THE CALL, WHEN IT WAS MADE AND WHAT IP ADDRESS IT WAS MADE FROM
AWS CLOUD TRAIL
REPORTS ON WHAT HAS CHANGED
AWS CONFIG
REPORTS ON WHO MADE THE CHANGE, WHEN AND FROM WHICH LOCATION
AWS CLOUD TRAIL
[TERM LINK] RESOURCE AUDIT
CLOUDTRAIL
[TERM LINK] API CALL AUDIT
CLOUDWATCH
TYPICALLY USED FOR AUDITING AND COMPLIANCE PURPOSES ACROSS ORGANIZATIONS
AWS CONFIG
WHAT ARE THE TWO DELETEONTERMINATION VALUES?
TRUE/FALSE
IF A DELETEONTERMINATION IS SET TO FALSE, WHAT HAPPENS WHEN AN INSTANCE IS TERMINATED?
IT PRESERVES THE ROOT VOLUME AND ENSURES IT REMAINS INTACT
YOUR DB INSTANCE MUST BE IN THE ______ STATE FOR AUTOMATED BACKUPS TO OCCUR
ACTIVE STATE
YOU CREATE A SNAPSHOT AND THEN YOU HAVE TO
COPY IT TO ANOTHER REGION
SNS TOPICS ARE USED FOR
NOTIFICATION PURPOSES
UNDERLYING STORAGE FOR A DB INSTANCE, AUTOMATED BACKUPS, READ REPLICAS, AND SNAPSHOTS ARE ALL ….
DATA THAT IS ENCRYPTED AT REST
_____ CAN BE CONFIGURED TO USE SERVICE AUTO SCALING TO ADJUST ITS DESIRED COUNT UP OR DOWN IN RESPONSE TO CLOUDWATCH ALARMS
AMAZON ECS
_______ FOR LAMBDA FUNCTIONS ENABLE YOU TO DYNAMICALLY PASS SETTINGS TO YOUR FUNCTION CODE AND LIBRARIES, WITHOUT MAKING CHANGES TO YOUR CODE
ENVIRONMENT VARIABLES
YOU CAN USE _____ TO HELP LIBRARIES KNOW WHAT DIRECTORY TO INSTALL FILES IN, WHERE TO STORE OUTPUTS, STORE CONNECTION AND LOGGING SETTINGS, AND MORE
ENVIRONMENT VARIABLES
______POWERED BY AWS PRIVATELINK, AN AWS TECHNOLOGY THAT ENABLES PRIVATE COMMUNICATION BETWEEN AWS SERVICES USING AN ELASTIC NETWORK
VPC ENDPOINTS
WHEN YOU CREATE A TRAIL THAT APPLIES TO ____ _____ CLOUDTRAIL RECORDS EVENTS IN EACH REGIION AND DELIVERS THE CLOUDTRAIL EVENT LOG FILES TO AN S3 BUCKET THAT YOU SPECIFY
ALL REGIONS
IF A REGION IS ADDED AFTER YOU CREATE A TRAIL THAT APPLIES TO ALL REGIONS, THAT NEW REGION IS _____
AUTOMATICALLY INCLUDED AND EVENTS IN THAT REGION IS LOGGED
YOU CAN CONFIGURE AMAZON REDSHIFT TO AUTOMATICALLY _____
COPY SNAPSHOTS TO ANOTHER REGION
BASTION HOSTS NEED TO BE IN A _____ SUBNET
PUBLIC
BASTION HOST PURPOSE IS TO
PROVIDE ACCESS TO A PRIVATE NETWORK FROM AN EXTERNAL NETWORK
VPC ENDPOINT INTERFACES HAVE TO BE
IN THE SAME REGION
______ IS A CLOUD SERVICE SOLUTION THAT MAKES IT EASY TO ESTABLISH A DEDICATED NETWORK CONNECTION FROM YOUR PREMISES TO AWS
AWS DIRECT CONNECT
____ IS A WEB SERVICE THAT YOU CAN USE TO AUTOMATE THE MOVEMENT AND TRANSFORMATION OF DATA
AWS DATA PIPELINE
COMMONLY USED TO TAKE METADATA AND STORE THE METADATA IN DYNAMODB
AWS LAMBDA
YOU CAN USE _____ TO DELEGATE ACCESS TO USERS, APPLICATIONS, OR SERVICES THAT DON’T NORMALLY HAVE ACCESS TO YOUR AWS RESOURCES
IAM ROLES
DATA IN DYNAMODB IS STORED IN _____ FORMAT
JSON
WHEN AN EC2-CLASSIC INSTANCE IS STOPPED, AWS ______ ANY ELASTIC IP ADDRESS THATS ASSOCIATED WITH INSTANCE
DISASSOCIATES
WHEN AN EC2-CLASSIC INSTANCE IS STOPPED, AWS RELEASES THE
PUBLIC AND PRIVATE IPV4 ADDRESSES
IF YOU USE PuTTY TO CONNECT TO YOUR INSTANCE VIA SSH YOU NEED TO VERIFY THAT YOUR PRIVATE KEY (.pem) HAS BEEN CORRECTLY CONVERTED TO
.ppk (PuTTY FORMAT)
EC2 BASIC DATA AVAILABLE AFTER
5 MINS
EC2 DETAILED MONITORING DATA AVAILABLE AFTER
1 MIN
_____ LAUNCHES A NUMBER OF EC2 INSTANCES FOR ITS HADOOP DATA PROCESSING ENGINE, IS MANAGED BY THE CUSTOMER AND IS USED TO PROCESS VAST AMOUNTS OF DATA
EMR
AVAILABLE AMAZON EC2 METRICS
CPU UTILIZATION, NETWORK UTILIZATION, DISK PERFORMANCE AND DISK READ/WRITES
[TERM LINK] OBJECT BASED
S3
S3 FILE SIZE
0 BT - 5 TB
minimal replical lag, usually less than 100 millisecods
AWS AURORA
___ ____ component can be used to create web server environments and work environments
ELASTIC BEANSTALK
_____ provides scalable file storage
EFS
[TERM LINK]
EPHEMERAL
INSTANCE STORES
_______ HELPS TO ENSURE THAT YOUR AUTO SCALING GROUP DOESN’T LAUNCH OR TERMINATE ADDITIONAL INSTANCES BEFORE THE PREVIOUS SCALING ACTIVITY TAKES EFFECT
AWS SCALING COOLING PERIOD
IAM ROLES IS USED TO DELEGATE ACCESS TO..
USERS, APPLICATIONS OR SERVICES
USED FOR ISSUING TOKENS WHILE USING THE API GATEWAY FOR TRAFFIC IN TRANSIT
API GATEWAY WITH STS
REDSHIFT WILL NOT BE ABLE TO ACCESS THE S3 VPC ENDPOINTS WITHOUT
ENHANCED VPC ROUTING
IF LANGUAGE IS SPECIFIED IN THE QUERY STRING PARAMETERS THEN
CLOUDFRONT SHOULD BE CONFIGURED
AWS KINESES DATA FIREHOSE CAN CAPTURE, TRANSFORM AND LOAD STREAMING DATA INTO
- AMAZON REDSHIFT (NOT REDSHIFT SPECTRUM)
- AMAZON ELASTICSEARCH SERVICE
- SPLUNK
AN INSTANCE STORE-BACKED INSTANCE IS EITHER
RUNNING OR TERMINATED , CAN NOT BE STOPPED !
AWS REDSHIFT USES TWO FORMS OF ENCRYPTION
AWS KMS OR AWS HSM
ON PREMISE —-> AWS RESOURCES
VPN CONNECTION
PRIVATE RESOURCES REQUIRED TO ACCESS THE INTERNET?
UTILIZE NAT INSTANCE OR NAT GATEWAY
BOTTLENECK
NAT INSTANCE
ONCE YOU CONVERT FROM NAT INSTANCE TO NAT GATEWAY YOUR NEXT STEP IS TO
MOVE NAT GATEWAY TO PUBLIC SUBNET
SERVICE WHERE YOU ONLY PAY FOR THE TIME THE FUNCTION RUNS AND NOT THE INFRASTRUCTURE, ALSO SAME SERVICE WHEN THE CUSTOMER HAS OWNERSHIP OF THE API
AWS LAMBDA
MONITOR API ACTIVITY
CLOUD TRAIL
CLOUD TRAIL MONITORS _____ ACTIVITY
API
[TERM LINK] API ACTIVITY
CLOUD TRAIL
[TERM LINK] CLOUD TRAIL
MONITOR API ACTIVITY
YOU CAN TURN ON A _____ACROSS ALL REGIONS
CLOUD TRAIL
CLOUDTRAIL DELIVERS LOG FILES TO
S3 BUCKET AND OPTIONAL CLOUDWATCH LOG FILES
OFFLOAD DATABASE READS
READ REPLICAS
READ REPLICAS
OFFLOAD DB READS
HIGH AVAILABILITY
MULTI AZ
MULTI AZ MEANS
HIGH AVAILABILITY
RDS HIGH AVAILABILITY
MULTI AZ
RDS READ REPLICAS
OFFLOAD DB READS
BATCH PROCESSING
SPOT INSTANCES
SPOT INSTANCES
BATCH PROCESSING
AMIS ARE NOT ______ AT REST
ENCRYPTED AT REST
ROUTE 53 ROUTES USER TRAFFIC TO RANDOM WEB SERVERS
MULTIVALUE ANSWER
MULTIVALUE ANSWER
ROUTE 53 ROUTES USER TRAFFIC TO RANDOM WEB SERVERS
RANDOM WEB SERVERS
MULTIVALUE ANSWER
INCREASE WRITE PERFORMANCE OF DB HOSTED ON EC2
INCREASE EC2 INSTANCE AND OR USE STANDARD RAID CONFIGURATION
NO COST FOR TRANSFERRING DATA FROM
EC2 INSTANCE TO AN S3 BUCKET
____ PROVIDES MULTIPLE WAYS TO USE AMAZON CLOUD DIRECTORY AND MICROSOFT ACTIVE DIRECTORY
AWS DIRECTORY SERVICE
AWS DIRECTORY SERVICE
LINK BETWEEN CLOUD DIRECTORY AND MICROSOFT AD
SNS SENDS NOTIFICATIONS OVER
HTTP, HTTPS, EMAIL, EMAIL-JSON, SQS AND SMS
HTTP, HTTPS, EMAIL, EMAIL-JSON, SQS AND SMS
WHAT IS SENT OVER FROM SNS
STORE SESSION DATA ON BOTH
DYNAMO DB AND ELASTICACHE
IF AN INSTANCE IS STOPPED
DATA IS DELETED
DATA IS DELETED WHEN
AN INSTANCE IS STOPPED
TO IMPLEMENT STICKY SESSION YOU NEED TWO THINGS
- HTTP/HTTPS LOAD BALANCER
- AT LEAST ONE HEALTHY INSTANCE
instance metadata provides
instance ID, public keys, public IP address
how to you find instance meta data
fire a URL command
S3 Standard IA storage class is designed for
data that is accessed less frequently, but requires rapid access when needed
managed cloud service that lets devices (IoT) easily and securely interact with cloud applications and other devices
AWS IoT Core
perfect forward secrecy is provided to two aws services
CLOUDFRONT AND ELB
AWS MANAGES SECURITY OF:
- FACILITIES
- PHYSICAL SECURITY OF HARDWARE
- NETWORK INFRASTRUCTURE
- VIRTUALIZATION INFRASTRUCTURE
THE DATA IN_____ IS STORED IN JSON FORMAT FOR
DYNAMODB
DYNAMODB STORES DATA IN _____ FORMAT
JSON
SINCE DYNAMODB WORKS WITH IoTs, gaming, ad tech and mobile applications IT IS USED TO STORE
SESSION DATA
THIS AWS FEATURE IS REALLY GOOD BECAUSE IT IS DURABLE, ACID COMPLIANT AND ALLOWS SCHEMA CHANGES
AURORA
REDSHIFT CLUSTER DISASTER RECOVERY ???
CROSS-REGION SNAPSHOT
REDSHIFT HAS TWO FORMS OF ENCRYPTION
AWS KMS AND HSM
IN ORDER TO HOST A STATIC WEBSITE IN S3 YOU NEED TO NEED TO ____________ IN THE DOMAIN REGRISTAR
ENTER THE NS RECORDS
CLOUD TRAIL MONITORS
API ACTIVITY