Reverse AWS CCP Flashcards
helps provision resources following AWS best practices
Trusted Advisor
Monitoring tool for applications, performance changes , optimize resource utilization and view operational health
CloudWatch
Assess, audit and evaluate the configurations of AWS resources
AWS Config
security assessment service for EC2 instances
Amazon Inspector
Read only copy databases that are sync’d with the RDS master database used to increase read performance and scalability
Read Replication Configuraiton
provides alerts and remediation guidance when AWS is experiencing issues.
AWS Personal Health Dashboard
Marketplace for vendors / consultants to sell AWS services (professional) or list their custom software(s)
AWS Marketplace
provide users with single sign-on access to all their assigned accounts and applications from one place (usually a website).
AWS Single Sign-On
A service to enable sign-up, sign-in and access control for web and mobile apps.
AWS Cognito
A service to provision users, securely control access to AWS services and resources for users
AWS Identity and Access Management (IAM)
helps ensure you have the correct number of EC2 instances to handle the application load
Auto Scaling
An application deployment that supports automatic failover between availability zones (AZ)
Multi AZ Deployment
distributes traffic (TCP, UDP, TLS) and does not scale resources
Network Load Balancer
Distribute traffic between EC2 instances (can be multiple Azs). Does not scale resources.
Application Load Balancer
AWS is responsible for the security “of” the cloud. The customer is responsible for security “in” the cloud.
AWS Shared Responsibility Model
PaaS, automatically handles the deployment details, capacity provisioning, load balancing, auto-scaling, and application health monitoring
AWS Elastic Beanstalk
IaaS, Model and provision resources needed for an application (Done through a UI tool!)
AWS CloudFormation
Apply permissions to IAM users and roles
Service Control Policies (SCP)
A service to monitor activity on all accounts for governance, compliance, risk, and auditing purposes.
CloudTrail
A service to automate the creation of users and groups and the security policies applied to them
AWS Organizations
Proprietary Amazon relational database
Amazon Aurora
A service for hosting 3rd party relational databases like mySQL, MS SQL Server, Oracle, etc..
Amazon RDS
High performance, multi-region, key-value and document database that is fully managed
Amazon DynamoDB
Datawarehouse DB for large scale data storage and analysis
Amazon RedShift
Yes but customers are excluded from pen testing the AWS infrastructure and AWS Services
Pen tests allowed on AWS?
Protect secrets needed to access applications, services and IT resources
AWS Secrets Manager
Describes key concepts, design principles and architectural best practices
Well-Architected Framework
operational excellence, security, reliability, performance efficiency, and cost optimization
5 pillars of the Well-Architected framework
Service and resource limits in AWS
AWS Service Quotas
Serverless compute engine that will spin up resources based on the containers application specifications.
AWS Fargate
Build, train and deploy machine learning (ML) models
Amazon SageMaker
Publication and subscription service
Amazon Simple Notificaiton Service (SNS)
AWS Well-Architected Framework pillar that recommends maintaining infrastructure as code
Operational Excellence