Topical Cards from Digital Cloud AWS Cert Exam Flashcards

1
Q

Kinesis Data Analytics

A
  • used for processing and analyzing real-time streaming data from either Firehose or Data streams
  • can only output data to S3, RedShift, Elasticsearch and Kinesis Data Streams
  • Autoscaling and Managed (no servers)
  • Real Time
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Kinesis Data Firehose

A
  • the easiest way to deliver data directly to AWS services or servicers like Splunk
  • data is NOT stored
  • serverless data transforms with lambda functions
  • Kinesis Data Streams can be used as the source(s) to Kinesis Data Firehose
  • near real-time (1 minute latency)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Kinesis Data Streams

A
  • enables real-time processing of streaming big data
  • stores data for later processing by applications (key difference with Firehose which delivers data directly to AWS services)
  • partition keys can guarentee ordering
  • records accessible from 24 hours (default) to 7 days
  • does not deliver it to destinations such as Splunk
  • must manage to scaling
  • will have to develop code (producer/consumer) to use
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Default IAM User Permissions

A
  • By default IAM users are created with no permissions

- an IAM policy must be attached to the user before they can do anything (even view their own access keys)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

EBS Encryption

A
  • Data in transit between an instance and an encrypted volume is encrypted
  • There is no direct way to change the encryption state of a volume
  • All EBS types support encryption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Amazon Glacier Resilience

A
  • 99.999999999% durability of archives
  • Data is resilient in the event of one entire AZ destruction
  • Data is NOT replicated globally
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

EBS Instance Store Configuration

A
  • Can only specify the instance store volumes for your instance when you launch the instance
  • Cannot add EBS volumes after launch
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Default Security Group Settings for a VPC

A
  • Inbound rule that allows all traffic from the security group itself
  • Outbound rule that allows all traffic to all addresses
  • Custom security groups do not have inbound rules by default (blocking all inbound traffic) and allow all outbound traffic by default
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RDS Database Restore

A
  • Can restore up to the last 5 minutes

- default DB security group is applied to the new DB instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Monitoring ELB Traffic

A
  • Use VPC Flow Logs

- To set up, create a VPC flow log for each network interface associated with an ELB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Network ACL

A
  • tied to subnets
  • stateless rules (rules applied to incoming traffic will not be applied to outgoing traffic
  • support allow and deny rules
  • rules applied in order
  • by default inbound rule denying all traffic and outbound rule denying all traffic
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Enhanced Networking

A

-provides higher bandwidth, pakcet-per-second, and lower inter-instance latencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DynamoDB Auto Scaling

A
  • uses AWS Application Auto Scaling Service to adjust provisted throughput capacity to traffic patterns
  • most efficient and cost-effective solution to optimizing cost
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CodeDeploy

A

-automates application deployment to EC2 instances, on-premises instances, serverless lambda.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

OpsWorks

A

-mangaged instances of Chef and Puppet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Beanstalk

A
  • used to quickly deploy and mange applications in the cloud

- beanstalk handles deployment details for applications in Go, Java, Python, Ruby, Node.js, and PHP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Run Command

A
  • designed to support a wide ranbe of enterprise configuration needs on windws machines
  • can install software, run scripts, or powershell commnads
  • accessible in the AWS Managment Console
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

AWS Config

A

-services that lets you assess, audit, and evaluate the configuration of your AWS Resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

POSIX Permissions

A

-allow you to restrict access from host by user group for EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

EFS Security Groups

A

-can act as a fire wall to restrict network traffic for EFS

21
Q

Direct Connect Gateway

A
  • transitive peering connections for VPC, VPN, and Direct Connect
  • can be assoicated with transit gateway when you have mutiple vpcs in the same region
  • can be associated with a virtural private gateway
22
Q

Direct Connect

A
  • establish private connectivity between AWS and your datacenter
  • set up a virtual private gateway on vpn and configured hardware connection to datacenter
23
Q

VPN CloudHub

A

-hub-and-spoke VPN model to connect your sites

24
Q

Transit Gateway

A

-transitive peering connections for VPC, VPN, and Direct Connect

25
Q

Private Link

A
  • connect services privately form your service VPC to customers VPC
  • eliminates the exposure of data to the public Internet
  • dosen’t need vpc peering, public internet, NAT gateway, ect
  • Must be used with NLB and Elastic Network Interface
26
Q

VPC Endpoints

A

-provide private access to aws services within a vpc

27
Q

Internet Gateway

A

-provide internet access at VPC level via ipv4 & ipv6

28
Q

Route Tables

A

-connect subnets to Interne Gateway, VPC Peering Connections, VPC Endpoints, ect

29
Q

Nat Instances

A
  • provides internet access to private instances on private subnet
  • Managed by user and requires additional set up like disabling source/destination check on the ec2
30
Q

Network ACL

A

-Statless, subnet allow and deny rules

31
Q

Securty Groups

A

-Stateful, operate at ec2 level

32
Q

Site to Site VPN

A

-connect datacenter to vpc over public internet, set up a virtual private gateway on vpn, customer gateway on the DC

33
Q

AWS DataSync

A
  • Used to move large amounts of data online between on-premises storage and Amazon S3 or Amazon Elastic File System (Amazon EFS
  • source datastore can be Server Message Block (SMB) file servers
34
Q

S3 Standard-IA

A
  • objects are available for millisecond access
  • charges a retrieval fee for these objects
  • stores the object data redundantly across multiple geographically separated Availability Zone
  • resilient to the loss of an Availability Zone
35
Q

S3 One Zone-IA

A
  • objects are available for millisecond access
  • charges a retrieval fee for these objects
  • object data in only one Availability Zone
  • data is not resilient to the physical loss of the Availability Zone resulting from disasters
36
Q

Service Control Policy (SCP)

A
  • used to apply restrictions across multiple member accounts in an OU
  • use deny rule to block a resource type (ec2 instance type for example) in member accounts
37
Q

Global Accelerator

A
  • improves the availability and performance of your applications with local or global users
  • uses the congestion-free AWS global network to route TCP and UDP traffic to a healthy application endpoint in the closest AWS Region to the user.
  • provides static IP addresses that act as a fixed entry point to your application endpoints in a single or multiple AWS Regions to your ALB or NLB
38
Q

FSx for Windows File Server

A
  • provides fully managed, highly reliable file storage accessible over SMB protocol
  • provides a rich set of administrative features that include end-user file restore, user quotas, and Access Control Lists
  • supports Distributed File System Replication (DFSR) in both Single-AZ and Multi-AZ deployments
39
Q

EFS

A
  • file storage for EC2 instances

- only available for Linux instances

40
Q

Target Tracking AutoScaling

A

-allows you to specify a target value for a metric to scale off of (CPU for instances)

41
Q

RedShift

A
  • columnar data warehouse DB that is ideal for running long complex queries.
  • RedShift can also improve performance for repeat queries by caching the result and returning the cached result when queries are re-run.
42
Q

AWS Batch Multi-node parallel jobs

A
  • enable you to run single jobs that span multiple Amazon EC2 instances (model training)
  • does not require you to launch, configure, and manage Amazon EC2 resources directly
  • supports IP-based, internode communication, such as Apache MXNet, TensorFlow, Caffe2, or Message Passing Interface (MPI)
43
Q

Scaling Process

A
  • There are two primary process types: Launch and Terminate
  • other process are Scheduled Actions, Replace Unhealthy, AZ Rebalance, ect.
  • Autoscaling groups can have multiple scaling processes
  • Process can be suspened and resumed
44
Q

EC2 Standby State AutoScaling

A
  • used for performing updates/changes/troubleshooting etc. without health checks being performed or replacement instances being launched
  • instance still managed by Auto Scaling
  • do not count towards available EC2 instance for workload/application
  • health checks are not performe
45
Q

Aazon DynamoDB Streams

A
  • captures a time-ordered sequence of item-level modifications in DynamoDB table
  • stores this information in a log for up to 24 hours
  • logs can be accessed in near-real time
46
Q

Troubleshooting ECS Containers

A
  • Verify that the Docker daemon is running on the container instance.
  • Verify that the Docker Container daemon is running on the container instance.
  • Verify that the container agent is running on the container instance.
  • Verify that the IAM instance profile has the necessary permissions.
47
Q

Cognito Identity Pools

A
  • provide temporary AWS credentials for users who are guests (unauthenticated) and for users who have been authenticated and received a token.
  • used to obtain temporary AWS credentials to access AWS services, such as Amazon S3 and DynamoDB.
48
Q

Cognito User Pools

A
  • A user pool is a user directory in Amazon Cognito

- Used to provide access to an application (think web app log in via facebook)