SAA-CO2 Flashcards
AWS Organizations (units)
Consolidated Billing, Root -> OU (organizational unit) -> Accounts
SAML
Security Assertion Markup Language
Storage Gateway
Hybrid cloud storage service
File Gateway
(NFS/SMB) on premise backs up to cloud, low latency access for on premises applications to in cloud data
Tape Gateway
replace physical tapes with virtual tapes
volume gateway
cloud backed block storage volumes
Macie
machine learning & NLP to discover, classify, protect sensitive data
NAT Gateway
connect to the internet from instances within a private subnet. prevents internet from initiating a connection. do not support ipv6 connections
Max number of Internet Gateways per VPC
1
Internet Gateway
VPC and internet connection
egress only igw
like NAT gateway but for ipv6, outbound traffic only
elastic IP address
static ipv4 address
direct connect
direct connection to AWS using colocation
global accelerator
directs customer traffic to optimal endpoints over the global network. provided two static IP addresses
privatelink
private connectivity between VPCs, aws services, on prem networks
ENI
elastic network interface: networking component in a VPC
gp2
general purpose ssd EBS storage
Io1
provisioned IOPS EBS storage (databases)
St1
throughput optimized HDD (big data and Warehouses)
Sc1
cold hdd (file servers)
Standard
ebs magnetic (hdd for infrequent access)
ebs backed ami
ebs storage backed ami, by default root volume is deleted on termination (can set to not do this)
instance store backed ami
ephemeral storage, lost on stop
ec2 hypervisors
zen -> nitro
customer gateway
customer side vpn to allow connection to vpc
vpc endpoints
allows privately connect VPC to supported services
interface endpoint: private endpoint to many services
gateway endpoints: nat gateway for s3 and dynamodb
customer gateway
customer side connection to private vpc through vpn
cluster placement group
place ec2 near another in a datacenter, can’t span availability zones