Flashcards
Click a card to flip it. Try to answer out loud before flipping.
What is the relationship between an AWS Region and an Availability Zone (AZ)?
Cloud Concepts · click to flip
A Region is a geographic area (e.g. us-east-1) containing multiple isolated, physically separate Availability Zones, each with independent power/networking, connected by low-latency links.
click to flip back
What problem does an Auto Scaling group solve?
Cloud Technology and Services · click to flip
It automatically adds or removes EC2 instances based on demand (e.g., CPU thresholds), maintaining availability and controlling cost by not over- or under-provisioning.
click to flip back
Name the 6 advantages of cloud computing AWS cites.
Cloud Concepts · click to flip
Trade capital expense for variable expense; benefit from massive economies of scale; stop guessing capacity; increase speed and agility; stop spending on data centers; go global in minutes.
click to flip back
How do you remember the difference between CloudTrail and CloudWatch?
Cloud Technology and Services · click to flip
CloudTrail = Trail of who did WHAT (API/account activity audit log). CloudWatch = WATCHing performance/health (metrics, logs, alarms, dashboards).
click to flip back
Does using AWS automatically make your application compliant (e.g., HIPAA, PCI-DSS)?
Security and Compliance · click to flip
No. AWS provides compliant infrastructure and certifications (see AWS Artifact), but you must configure your own workload correctly to meet the specific compliance requirement.
click to flip back
Given a workload, how do you choose between EC2, Lambda, and ECS/Fargate?
Cloud Technology and Services · click to flip
Need full OS control / long-running, stateful process → EC2. Short, event-driven, stateless function → Lambda. Already containerized, needs more control/duration than Lambda but not full server management → ECS/Fargate.
click to flip back
What is the benefit of consolidated billing under AWS Organizations?
Billing, Pricing, and Support · click to flip
One bill across all linked accounts, and usage from all accounts can combine to reach volume pricing tiers/discounts faster than any single account alone.
click to flip back
Name the main EC2 purchasing options and when to use each.
Cloud Technology and Services · click to flip
On-Demand: pay per second/hour, no commitment, for unpredictable workloads. Reserved/Savings Plans: discount for 1-3 year commitment, for steady-state workloads. Spot: deep discount using spare capacity, for fault-tolerant/interruptible workloads.
click to flip back
What is an AWS edge location used for?
Cloud Concepts · click to flip
A site used by CloudFront (and other services) to cache content physically closer to end users, reducing latency — distinct from Regions/AZs which run full AWS services.
click to flip back
What is the difference between elasticity and scalability?
Cloud Concepts · click to flip
Scalability is the ability to increase resources to handle load. Elasticity is scaling automatically up AND down to match demand in near real time, so you only pay for what you use.
click to flip back
What is the difference between encryption at rest and encryption in transit?
Security and Compliance · click to flip
At rest protects stored data (e.g., KMS-encrypted S3/EBS/RDS). In transit protects data moving over a network (e.g., TLS/SSL, handled by services like ACM for certificates).
click to flip back
What are the three types of AWS Free Tier offers?
Billing, Pricing, and Support · click to flip
Always Free (e.g., limited Lambda requests every month), 12 Months Free (e.g., limited EC2/S3 usage starting from account creation), and Trials (short-term free access to a specific service).
click to flip back
Distinguish high availability from fault tolerance.
Cloud Concepts · click to flip
High availability minimizes downtime by running across multiple resources/AZs. Fault tolerance goes further: the system keeps operating correctly even if a component fails, with no perceivable impact.
click to flip back
When should you use an IAM role instead of an IAM user?
Security and Compliance · click to flip
Use a role for temporary, assumable permissions — e.g., an EC2 instance or Lambda function needing AWS access, or federating an external identity — rather than long-lived credentials tied to a specific user.
click to flip back
What problem does an Elastic Load Balancer solve?
Cloud Technology and Services · click to flip
Distributes incoming traffic across multiple targets (EC2 instances, containers) in one or more AZs, improving fault tolerance and enabling horizontal scaling.
click to flip back
What problem does MFA solve?
Security and Compliance · click to flip
It requires a second verification factor beyond a password (e.g., a one-time code), so a compromised password alone is not enough to access an account.
click to flip back
What does "least privilege" mean in AWS security?
Security and Compliance · click to flip
Grant only the minimum permissions required to perform a task — nothing more — to reduce the impact if credentials are compromised.
click to flip back
What makes a subnet "public" versus "private" in a VPC?
Cloud Technology and Services · click to flip
A public subnet has a route to an internet gateway, allowing direct internet access. A private subnet has no such route — resources like databases typically live here, reaching the internet (if needed) only via a NAT gateway.
click to flip back
How do you decide between RDS and DynamoDB for a new application?
Cloud Technology and Services · click to flip
Structured data with relationships needing SQL joins/transactions → RDS. Flexible schema, key-value/document access pattern, and need for massive horizontal scale with low, predictable latency → DynamoDB.
click to flip back
What is the recommended first security step after creating a new AWS account?
Security and Compliance · click to flip
Enable MFA on the root user, avoid using it for daily tasks, and create an individual IAM (or IAM Identity Center) user with only the permissions needed.
click to flip back
Why would you use S3 Glacier instead of S3 Standard?
Cloud Technology and Services · click to flip
Glacier is far cheaper per GB for data accessed rarely (archival, compliance retention) in exchange for slower retrieval times; Standard is for frequently accessed data needing millisecond access.
click to flip back
What does "serverless" mean in the context of Lambda?
Cloud Technology and Services · click to flip
You never provision or manage servers — AWS runs your code on demand and automatically handles scaling; you're billed only for actual compute time used.
click to flip back
In the AWS Shared Responsibility Model, what is AWS responsible for vs. the customer?
Security and Compliance · click to flip
AWS is responsible for security "of" the cloud (hardware, software, networking, facilities running AWS services). The customer is responsible for security "in" the cloud (data, IAM configuration, OS patching on EC2, network/firewall config, encryption).
click to flip back
How do you choose between S3, EBS, and EFS?
Cloud Technology and Services · click to flip
Object storage accessed via API/URL, not mounted as a drive → S3. Block storage attached to a single EC2 instance → EBS. Shared file storage mounted concurrently by multiple instances → EFS.
click to flip back
Which AWS Support plan is the minimum generally recommended for production workloads?
Billing, Pricing, and Support · click to flip
Business Support — it adds 24/7 access to Cloud Support Engineers, faster response times for production-down issues, and full Trusted Advisor checks, unlike Basic/Developer.
click to flip back
List the six pillars of the AWS Well-Architected Framework.
Cloud Concepts · click to flip
Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.
click to flip back