Revision 1 Flashcards
easy-to-use service for deploying and scaling web applications and services developed with Java, .NET, PHP, Node.js, Python, Ruby, Go, and Docker on familiar servers such as Apache, Nginx, Passenger, and IIS.
imply upload your code and Elastic Beanstalk automatically handles the deployment, from capacity provisioning, load balancing, auto-scaling to application health monitoring.
can access the underlying resources at any time.
AWS Elastic Beanstalk
To gain greater discounts, which services can be reserved?
-EC2
-Amazon DynamoDB
-Amazon RedShift
-RDS
-ElastiCache
-OpenSearch Service,
-Serverless
-Fully managed NoSQL database
-Supports key-value and document data models.
-Replicates the data across multiple availability zones (AZs)
DynamoDB
attached to a VPC and allows inbound traffic from the internet to access the VPC. It is also used as a target in route tables for outbound internet traffic.
Internet gateway
Generate reports that break down AWS Cloud compute costs by duration, resource, or tags
AWS Cost & Usage Report.
Used for querying data in Amazon S3 using SQL.
Amazon Athena
connects your Amazon Virtual Private Clouds (VPCs) and on-premises networks through a central hub. This simplifies your network and puts an end to complex peering relationships. It acts as a cloud router – each new connection is only made once.
AWS Transit Gateway
Estimate a monthly bill for the AWS Cloud resources that will be used
Pricing Calculator
Types of flow logs
-VPC Flow Logs
-Subnet Flow Logs
-Elastic Network Interface FLow logsELastic
Help to troubleshoot connectivity issues
automated vulnerability management service that continually scans Amazon Elastic Compute Cloud (EC2), AWS Lambda functions, and container workloads for software vulnerabilities and unintended network exposure.
Amazon Inspector
enables you to easily generate and use your own encryption keys on the AWS Cloud.
helps you meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated Hardware Security Module
AWS CloudHSM
is a hybrid cloud storage service that gives you on-premises access to virtually unlimited cloud storage.
AWS Storage Gateway
lets you add user sign-up, sign-in, and access control to your web and mobile apps quickly and easily.
Amazon Cognito.
Key pairs are used for authenticating to
EC2 instances.
-Estimate savings when comparing the AWS Cloud to an on-premises environment
AWS Total Cost of Ownership (TCO) Calculator
AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?
-Amazon EMR Elastic Map Reduce
software licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted.
Software as a Service (SaaS)
AWS Trusted Advisor offers a rich set of best practice checks and recommendations across five categories:
-cost optimization
-security
-fault tolerance
-performance
-service limits
plan provides access to architectural and operational reviews, as well as 24/7 access to Cloud Support Engineers through email, online chat, and phone
enterprise
-NoSQL database that supports document data structures.
-Fully managed
-Flexible schema that allows for the data model to evolve
-MongoDB
-Automatically replicates six copies of your data across 3 availability zones to offer a 99.99% availability.
Amazon DocumentDB
A VGW is used for IPSec VPN connections to access a VPC
Virtual Private Gateway
group of protocols that are used together to set up encrypted connections between devices. It helps keep data sent over public networks secure.
IPSec
intelligent threat detection service
Amazon GuardDuty
is an Extract, Transform, and Load (ETL) service.
AWS Glue
you visibility and control of your infrastructure on AWS. provides a unified user interface so you can view operational data from multiple AWS services and allows you to automate operational tasks across your AWS resources.
AWS Systems Manager
Controls traffic to and from an EC2
Security Group
-Allow only
-IP or other security groups
-stateful: return traffic automatically allowed
-evaluate rules before deciding if allow
-must be specified at launch or associated