All certifications / Solutions Architect Associate / Cheat sheet
Solutions Architect Associate SAA-C03 cheat sheet
Domain 1: Design Secure Architectures (30%)
Exam tips
- When a question asks why access is denied despite an Allow, look for an explicit Deny, an SCP or a permissions boundary. When it asks how to give an EC2 instance or Lambda function access, the answer is a role, never access keys stored on the instance.
- SCPs filter, they do not grant, and they do not apply to the management account. If the question wants centralized sign-in for people across many accounts, choose IAM Identity Center; if it wants an application in account A to act in account B, choose a cross-account role.
- If a mobile or web app needs its users to call AWS services directly, the answer involves a Cognito identity pool. If the question is only about sign-up and sign-in for app users, it is a user pool. Corporate users and SAML point to IAM Identity Center or AssumeRoleWithSAML.
- Stateful and allow-only means security group; stateless with deny rules and ordering means network ACL. When a question asks for shell access with no open inbound ports and no key management, choose Session Manager over a bastion host.
- S3 or DynamoDB, from inside the VPC, lowest cost: gateway endpoint. Any other service, or access from on-premises, or sharing a service with other VPCs: interface endpoint (PrivateLink).
- SQL injection, cross-site scripting, rate limiting or geo blocking points to AWS WAF. Large DDoS with expert support and cost protection points to Shield Advanced. Keeping an S3 origin private behind CloudFront points to origin access control.
- Audit of key usage, control of the key policy or the ability to disable the key: SSE-KMS with a customer managed key. The customer must supply and hold the key themselves: SSE-C. Simplest with no key management: SSE-S3.
- A CloudFront certificate must be in us-east-1. Enforcing HTTPS on an S3 bucket is a bucket policy that denies requests where aws:SecureTransport is false, not a setting on the bucket.
- The keyword is rotation. Automatic rotation of database credentials points to Secrets Manager; low-cost storage of configuration and static secrets points to Parameter Store SecureString.
- Governance mode can be bypassed by users with special permission; compliance mode cannot be bypassed by anyone. To give temporary access to one object without creating IAM users, choose a presigned URL.
- API history: CloudTrail. Configuration history and compliance: Config. Threats: GuardDuty. Vulnerabilities: Inspector. Sensitive data in S3: Macie. Single pane of findings: Security Hub.
Key terms
- IAM role
- An identity with permissions but no long-term credentials, assumed by a trusted principal to receive temporary credentials.
- IAM group
- A collection of IAM users that share attached policies; it cannot sign in, be nested or be a policy principal.
- Identity-based policy
- A policy attached to a user, group or role that states what that identity may do.
- Resource-based policy
- A policy attached to a resource, such as an S3 bucket policy, that names the principals allowed to access it.
- Explicit deny
- A Deny statement that matches a request; it overrides any Allow in any policy.
- Permissions boundary
- A managed policy that sets the maximum permissions an IAM user or role can have, without granting any itself.
- Instance profile
- The container that passes an IAM role to an EC2 instance so software on it receives temporary credentials.
- AWS Organizations
- The service that groups AWS accounts for central management, policies and consolidated billing.
- Organizational unit (OU)
- A container of accounts inside AWS Organizations to which policies such as SCPs can be attached.
- Service control policy (SCP)
- An Organizations policy that sets the maximum permissions for identities in member accounts; it never grants access.
- Permission set
- An IAM Identity Center template of policies that becomes a role in each account it is assigned to.
- External ID
- A secret value required in a cross-account role's trust policy to protect against the confused deputy problem.
- AWS Control Tower
- A service that sets up and governs a multi-account landing zone with baseline accounts and controls.
- AWS STS
- The Security Token Service, which issues temporary, expiring credentials for roles and federated users.
- Federation
- Granting AWS access to identities managed outside IAM, such as a corporate IdP or web identity provider.
- SAML 2.0
- An XML-based standard for exchanging signed authentication assertions, commonly used for workforce federation.
- OpenID Connect (OIDC)
- An identity layer on OAuth 2.0 whose signed tokens can be exchanged for AWS role credentials.
- Cognito user pool
- A managed user directory that handles sign-up and sign-in and returns JWTs.
- Cognito identity pool
- A service that exchanges identity tokens for temporary AWS credentials mapped to IAM roles.
- Security group
- A stateful, allow-only virtual firewall attached to network interfaces.
- Network ACL
- A stateless subnet-level firewall with numbered allow and deny rules evaluated in order.
- Public subnet
- A subnet whose route table sends internet-bound traffic to an internet gateway.
- NAT gateway
- A managed service in a public subnet that lets private instances start outbound internet connections.
- Bastion host
- A hardened instance in a public subnet used as a jump point for SSH into private instances.
- Session Manager
- A Systems Manager feature that gives shell access to instances over an outbound agent connection, controlled by IAM.
- VPC endpoint
- A private connection from a VPC to a supported AWS or partner service without using the internet.
- Gateway endpoint
- A route-table target that gives private, free access to S3 or DynamoDB from within a VPC.
- Interface endpoint
- A PrivateLink network interface with private IPs in your subnets that fronts an AWS or partner service.
- AWS PrivateLink
- The technology that exposes a service through interface endpoints in consumer VPCs without peering.
- Endpoint policy
- A resource policy on a VPC endpoint that restricts which actions and resources can be reached through it.
- aws:SourceVpce
- A condition key that matches the ID of the VPC endpoint a request came through.
- AWS WAF
- A layer 7 web application firewall that filters HTTP(S) requests using rules in a web ACL.
- Web ACL
- The AWS WAF resource that holds rules and is associated with CloudFront, ALB, API Gateway and other supported resources.
- Rate-based rule
- A WAF rule that blocks source IPs exceeding a request count within a time window.
- Shield Standard
- Automatic, no-extra-cost protection for all AWS customers against common layer 3 and 4 DDoS attacks.
- Shield Advanced
- A paid DDoS protection tier with SRT support, advanced detection and DDoS cost protection.
- Origin access control (OAC)
- A CloudFront feature that signs requests to an S3 origin so the bucket can stay private and accept only that distribution.
- AWS KMS
- The managed service that creates, stores and controls encryption keys and logs their use in CloudTrail.
- AWS managed key
- A KMS key created in your account by an AWS service, auditable but with a key policy you cannot change.
- Customer managed key
- A KMS key you create and control, including its key policy, rotation, disabling and deletion.
- Key policy
- The resource-based policy on a KMS key that is the primary control over who can use and manage it.
- Envelope encryption
- Encrypting data with a data key, then encrypting that data key with a KMS key.
- SSE-KMS
- S3 server-side encryption using a KMS key, with auditable key use and key-policy control.
- S3 Bucket Key
- A bucket-level data key that reduces the number of KMS calls, and cost, for SSE-KMS.
- TLS
- Transport Layer Security, the protocol that encrypts and authenticates network connections such as HTTPS.
- AWS Certificate Manager (ACM)
- A service that issues, stores and automatically renews TLS certificates for integrated AWS services.
- TLS termination
- Decrypting TLS at a front-end component such as a load balancer before passing the request on.
- Server Name Indication (SNI)
- A TLS extension that lets one listener serve different certificates for different host names.
- Viewer protocol policy
- The CloudFront setting that controls whether viewers may use HTTP, are redirected to HTTPS or must use HTTPS.
- aws:SecureTransport
- A condition key that is true when the request was sent over TLS.
- Secrets Manager
- A managed service that stores, encrypts, audits and automatically rotates secrets.
- Parameter Store
- A Systems Manager feature for hierarchical configuration data and secrets, without built-in rotation.
- SecureString
- A Parameter Store parameter type whose value is encrypted with a KMS key.
- Rotation
- Periodically replacing a secret with a new value and updating every place that uses it.
- Managed rotation
- Secrets Manager rotation for supported databases that needs no custom Lambda code.
- Dynamic reference
- A CloudFormation template reference that resolves a parameter or secret value at deploy time.
- Block Public Access
- Account and bucket settings that override any ACL or policy that would make S3 data public.
- Presigned URL
- A time-limited URL signed with an authorized identity's credentials that grants one S3 operation on one object.
- Versioning
- An S3 bucket setting that keeps every version of an object so overwrites and deletes can be undone.
- MFA Delete
- A versioning option, enabled only by the root user, that requires MFA to permanently delete versions or change versioning.
- Object Lock compliance mode
- A WORM retention mode that nobody, including root, can shorten or remove before it expires.
- Object Lock governance mode
- A WORM retention mode that users with special bypass permission can override.
- Legal hold
- An Object Lock flag that prevents a version from being deleted until the hold is removed, with no expiry date.
- CloudTrail
- The service that records API activity in AWS accounts for auditing and investigation.
- Data events
- High-volume CloudTrail events, such as S3 object reads and writes, that must be enabled explicitly.
- AWS Config
- The service that records resource configuration history and evaluates compliance with rules.
- GuardDuty
- A managed threat detection service that analyzes logs to find malicious or unauthorized activity.
- Inspector
- A service that continuously scans EC2, container images and Lambda functions for known vulnerabilities.
- Macie
- A service that discovers and classifies sensitive data such as PII in Amazon S3.
- Security Hub
- A service that aggregates security findings and runs best-practice checks across accounts.
Domain 2: Design Resilient Architectures (26%)
Exam tips
- Path-based or host-based routing means ALB. Static IP, UDP or millions of requests per second with ultra-low latency means NLB. If an ASG is not replacing instances that the load balancer says are unhealthy, switch the ASG to the ELB health check type.
- Messages processed twice usually means the visibility timeout is shorter than processing time. Strict order and no duplicates means FIFO. One event delivered to several independent consumers means SNS fan-out to SQS.
- Watch for time limits: a job longer than 15 minutes rules out Lambda. Orchestrating multiple steps with retries points to Step Functions; routing events from AWS services or SaaS apps by content points to EventBridge.
- Existing Kubernetes skills or portability: EKS. Simplest AWS-native orchestration: ECS. No servers to manage: Fargate. Need GPUs, host-level control or Reserved pricing on hosts: EC2 launch type.
- Multi-AZ equals availability, not performance; the classic standby cannot serve reads. Read replicas equal read performance, with asynchronous replication. Cross-Region relational DR with RPO of seconds equals Aurora Global Database.
- Replication is not backup: global tables copy mistakes too. For recovering from accidental deletion or corruption to an exact moment, choose point-in-time recovery; restores always go to a new table.
- Content must be restricted or localized by country: geolocation, not latency. Best performance for users: latency. Canary or percentage split: weighted. Active-passive DR: failover. The zone apex pointing at an ALB: an alias record.
- Match wording to strategy: lowest cost and hours of RTO is backup and restore; core database running but servers off is pilot light; scaled-down but fully working copy is warm standby; near-zero RTO and RPO is multi-site active-active.
- Centralized, tag-based backup across services with cross-Region and cross-account copies: AWS Backup. Automatically copy new S3 objects to another Region: CRR (versioning required). Continuous block-level replication of whole servers for DR: Elastic Disaster Recovery.
- Need connectivity this week or at low cost: Site-to-Site VPN. Consistent, high-bandwidth private link: Direct Connect, which takes longer to provision. Cheapest resilient option for Direct Connect: add a VPN backup. Many VPCs plus on-premises: Transit Gateway.
- Deploy the same resources to many accounts or Regions: StackSets. Preview changes before updating: change set. DR plans must include quota increases in the recovery Region. Throttling errors are handled with retries using exponential backoff.
Key terms
- Availability Zone
- One or more isolated data centers in a Region with independent power and networking.
- Application Load Balancer
- A layer 7 load balancer that routes HTTP and HTTPS requests by content such as path and host.
- Network Load Balancer
- A layer 4 load balancer for TCP, UDP and TLS with static IPs per AZ and very high performance.
- Auto Scaling group
- A set of EC2 instances launched from a template that EC2 Auto Scaling keeps at a desired, healthy count.
- Target tracking policy
- A scaling policy that adjusts capacity to keep a chosen metric near a target value.
- ELB health check type
- An Auto Scaling group setting that replaces instances the load balancer reports as unhealthy.
- Standard queue
- An SQS queue type with very high throughput, at-least-once delivery and best-effort ordering.
- FIFO queue
- An SQS queue type that preserves order within a message group and prevents duplicates.
- Visibility timeout
- The period during which a received SQS message is hidden from other consumers while it is processed.
- Dead-letter queue
- A queue that receives messages that failed processing more times than the maxReceiveCount.
- Long polling
- An SQS receive mode that waits up to 20 seconds for messages, reducing empty responses.
- Fan-out
- Publishing a message once to an SNS topic so that many subscribers, often SQS queues, each receive a copy.
- Idempotent processing
- Handling a message so that processing it twice has the same effect as processing it once.
- AWS Lambda
- A serverless compute service that runs functions in response to events, for up to 15 minutes per invocation.
- Reserved concurrency
- A Lambda setting that guarantees and caps the number of concurrent executions for one function.
- Provisioned concurrency
- Pre-initialized Lambda execution environments that remove cold-start latency.
- Amazon API Gateway
- A managed service for creating, securing and throttling REST, HTTP and WebSocket APIs.
- Amazon EventBridge
- A serverless event bus that routes events to targets based on pattern-matching rules.
- AWS Step Functions
- A service that orchestrates workflows as state machines with retries, branches and error handling.
- Amazon ECR
- A private container image registry integrated with IAM that can scan images for vulnerabilities.
- Task definition
- The ECS blueprint describing a task's containers, resources, networking and IAM roles.
- ECS service
- An ECS construct that keeps a desired number of tasks running and integrates with load balancers.
- Amazon EKS
- A managed Kubernetes service that runs the control plane for you.
- AWS Fargate
- A serverless compute engine for containers that removes the need to manage EC2 hosts.
- ECS task role
- The IAM role whose permissions the application inside an ECS task uses.
- Task execution role
- The IAM role the ECS agent uses to pull images, fetch injected secrets and send logs.
- Multi-AZ deployment
- An RDS configuration with a synchronously replicated standby in another AZ and automatic failover.
- Read replica
- An asynchronously replicated copy of a database used to offload reads; can be promoted manually.
- Replica lag
- The delay between a write on the primary and its appearance on an asynchronous replica.
- Aurora Replica
- A reader instance sharing the Aurora cluster volume that serves reads and is an automatic failover target.
- Reader endpoint
- An Aurora endpoint that load-balances read connections across the cluster's replicas.
- Aurora Global Database
- An Aurora configuration that replicates a cluster to secondary Regions with typically sub-second lag.
- Global table
- A DynamoDB table replicated across multiple Regions, with every replica accepting reads and writes.
- Last writer wins
- The default conflict resolution rule in global tables where the most recent write to an item prevails.
- Point-in-time recovery (PITR)
- Continuous DynamoDB backups allowing restore to any second in the recovery window of up to 35 days.
- On-demand backup
- A full, manually created DynamoDB backup retained until you delete it.
- DynamoDB Streams
- A time-ordered log of item-level changes kept for 24 hours for processing by consumers such as Lambda.
- Time to Live (TTL)
- A DynamoDB feature that automatically deletes items after a timestamp attribute expires.
- Hosted zone
- A Route 53 container for the DNS records of a domain, either public or private to VPCs.
- Alias record
- A Route 53 record that points to an AWS resource, works at the zone apex and has no query charge for AWS targets.
- Failover routing
- An active-passive policy returning the secondary record only when the primary's health check fails.
- Weighted routing
- A policy that splits DNS answers among records in proportion to assigned weights.
- Latency-based routing
- A policy that returns the endpoint in the Region with the lowest latency for the user.
- Geolocation routing
- A policy that returns answers based on the user's geographic location.
- Multivalue answer routing
- A policy that returns up to eight healthy records chosen at random.
- Disaster recovery
- The strategy and processes for restoring a workload after a major event such as a Regional outage.
- RPO
- Recovery point objective: the maximum acceptable data loss, measured as time before the disaster.
- RTO
- Recovery time objective: the maximum acceptable time to restore service after a disaster.
- Backup and restore
- The lowest-cost DR strategy, which restores data and rebuilds infrastructure only after a disaster.
- Pilot light
- A DR strategy that keeps data replicated in the recovery Region with the application tier off until needed.
- Warm standby
- A DR strategy that runs a scaled-down but fully functional copy of the workload in the recovery Region.
- Multi-site active-active
- A DR strategy that serves production traffic from multiple Regions at full scale simultaneously.
- AWS Backup
- A central service that schedules, retains and copies backups across many AWS services.
- Backup plan
- An AWS Backup policy defining backup frequency, retention, lifecycle and copy rules for assigned resources.
- Vault Lock
- An AWS Backup feature that makes a backup vault's retention settings immutable.
- Cross-Region Replication
- Asynchronous copying of S3 objects to a bucket in another Region; requires versioning on both buckets.
- EBS snapshot
- An incremental, point-in-time backup of an EBS volume that can be copied across Regions and accounts.
- AMI
- An Amazon Machine Image: a Regional template of snapshots and launch settings used to launch instances.
- AWS Elastic Disaster Recovery
- A service that continuously replicates servers to AWS and launches recovery instances on demand.
- Site-to-Site VPN
- An AWS service providing two encrypted IPsec tunnels over the internet between on-premises and AWS.
- Customer gateway
- The on-premises VPN device, or its AWS representation, at your end of a Site-to-Site VPN.
- AWS Direct Connect
- A dedicated private network connection between on-premises networks and AWS.
- Virtual interface (VIF)
- A logical connection on Direct Connect: private, public or transit.
- BGP
- Border Gateway Protocol, the dynamic routing protocol that advertises routes and enables automatic failover between paths.
- Transit Gateway
- A regional network hub that connects VPCs and on-premises networks with centralized routing.
- Infrastructure as code (IaC)
- Defining infrastructure in versioned text files that tools deploy repeatably.
- CloudFormation stack
- A set of AWS resources created and managed together from one template.
- Change set
- A preview of the changes CloudFormation will make when updating a stack.
- StackSets
- A CloudFormation feature that deploys a template across multiple accounts and Regions.
- Service quota
- A per-account, per-Region limit on resources or request rates, some of which can be increased.
- Exponential backoff
- A retry strategy that waits progressively longer between attempts, usually with random jitter.
Domain 3: Design High-Performing Architectures (24%)
Exam tips
- Lowest latency between nodes: cluster. Maximum isolation for a few critical instances: spread (seven per AZ). Big replicated clusters like Kafka, Cassandra or HDFS: partition. MPI or OS bypass: EFA, not just ENA.
- Default or boot volume: gp3. Highest sustained IOPS for critical databases: io2 Block Express. Big sequential throughput at low cost: st1; coldest and cheapest: sc1. Fastest temporary scratch space that may be lost: instance store.
- Linux shared files: EFS. Windows or SMB with Active Directory: FSx for Windows File Server. HPC or ML throughput, especially with S3 data: FSx for Lustre. NetApp features or NFS plus SMB plus iSCSI together: FSx for NetApp ONTAP.
- Global users uploading to one bucket over long distances: Transfer Acceleration. Large files and unreliable networks: multipart upload. Faster parallel downloads or reading part of a file: byte-range fetches. Higher request rates: more prefixes.
- Leaderboards, pub/sub, persistence or high availability: Redis OSS or Valkey. Simplest multi-threaded key-value cache: Memcached. Microsecond reads for DynamoDB with minimal code change: DAX. Always-fresh cache at the cost of write latency: write-through.
- Caching and HTTP content means CloudFront. Static IP addresses, UDP or other non-HTTP traffic, or instant regional failover without relying on DNS means Global Accelerator.
- Match clues to engines: relationships and graph traversal is Neptune; MongoDB compatibility is DocumentDB; analytics or data warehouse is Redshift; key-value at any scale with serverless operation is DynamoDB; too many connections from Lambda is RDS Proxy.
- Throttling while total capacity is unused points to a hot partition and poor key design. Unknown or spiky traffic points to on-demand; steady, predictable traffic points to provisioned with auto scaling. Need a new query pattern after launch: add a GSI, because LSIs must be created with the table.
- Deliver to S3, Redshift or OpenSearch with no code and no capacity management: Firehose. Real-time custom consumers, ordering per key or replay: Kinesis Data Streams. Existing Kafka workloads or Kafka APIs: MSK.
- Ad hoc SQL on S3 with no servers: Athena. Discover schemas and ETL: Glue. Column or row-level permissions across analytics tools: Lake Formation. Hadoop or Spark clusters with control: EMR. Join Redshift tables with S3 data: Redshift Spectrum. Dashboards: QuickSight.
- Keep a metric at a value: target tracking. Known times: scheduled. Recurring daily or weekly patterns with slow-starting instances: predictive. Different responses for different breach sizes: step. SQS worker fleets: scale on backlog per instance.
- Online file migration: DataSync. Huge data and limited bandwidth: Snow Family. Ongoing on-premises access to cloud storage: Storage Gateway (file, volume or tape). SFTP for partners: Transfer Family. Database move with minimal downtime: DMS, plus SCT when engines differ.
Key terms
- Instance family
- A group of EC2 instance types optimized for a resource profile, such as general purpose, compute, memory, storage or accelerated computing.
- Cluster placement group
- Instances packed closely in one Availability Zone for low-latency, high-throughput networking between them.
- Spread placement group
- Each instance on distinct hardware, limited to seven running instances per AZ per group, to reduce correlated failures.
- Partition placement group
- Instances divided into partitions on separate racks, for large distributed and replicated systems.
- Elastic Network Adapter (ENA)
- The network interface that provides enhanced networking with high bandwidth and packet rates on current instance types.
- Elastic Fabric Adapter (EFA)
- A network interface with operating system bypass for tightly coupled HPC and machine learning workloads using MPI or NCCL.
- Burstable instance
- A T-family instance that accrues CPU credits when idle and spends them to burst above a baseline.
- gp3
- General purpose SSD with a baseline of 3,000 IOPS and 125 MB/s, where IOPS and throughput are provisioned independently of size.
- gp2
- The older general purpose SSD whose IOPS scale with volume size and use burst credits on small volumes.
- io2 Block Express
- The highest-performance EBS SSD for demanding databases, with sub-millisecond latency and higher durability.
- st1
- Throughput optimized HDD for large sequential workloads such as big data and logs; not bootable.
- sc1
- Cold HDD, the lowest-cost EBS volume, for infrequently accessed sequential data; not bootable.
- Instance store
- Temporary block storage physically attached to the host; data is lost on stop, hibernation, termination or disk failure.
- Multi-Attach
- An io1 and io2 feature that attaches one volume to several Nitro instances in the same AZ.
- Amazon EFS
- A managed, elastic NFS file system for Linux that many instances across AZs can mount simultaneously.
- Mount target
- An EFS network endpoint in a subnet of each AZ through which clients mount the file system.
- FSx for Windows File Server
- A managed Windows file server using SMB with Active Directory integration and NTFS permissions.
- FSx for Lustre
- A managed high-performance parallel file system for HPC and ML, with optional S3 data repository integration.
- FSx for NetApp ONTAP
- A managed NetApp ONTAP file system supporting NFS, SMB and iSCSI with ONTAP data management features.
- Server Message Block (SMB)
- The file sharing protocol used by Windows clients and servers.
- Scratch vs persistent (Lustre)
- Scratch file systems do not replicate data and suit temporary jobs; persistent file systems replicate within an AZ.
- Prefix
- The leading part of an S3 object key; request rate guidance applies per prefix.
- Multipart upload
- Uploading an object in independently transferred parts that S3 then assembles; required above 5 GB.
- Byte-range fetch
- Downloading a specific range of bytes of an object with the HTTP Range header, often in parallel.
- S3 Transfer Acceleration
- A bucket feature that routes transfers through CloudFront edge locations over the AWS backbone.
- 503 Slow Down
- An S3 response indicating the request rate temporarily exceeds what the prefix can handle; clients should retry with backoff.
- Exponential backoff
- A retry strategy that waits progressively longer between attempts to let a service recover.
- ElastiCache for Redis OSS
- A managed in-memory data store with rich data types, replication, persistence and Multi-AZ failover; Valkey is a compatible engine option.
- ElastiCache for Memcached
- A managed, multi-threaded key-value cache without replication or persistence.
- DAX
- DynamoDB Accelerator, an API-compatible in-memory cache for DynamoDB with microsecond read latency.
- Lazy loading
- A caching strategy that loads data into the cache only after a cache miss; also called cache-aside.
- Write-through
- A caching strategy that updates the cache whenever the database is written, keeping cached data current.
- Time to live (TTL)
- An expiry time on a cached item after which it is removed and reloaded on the next request.
- Cache hit ratio
- The share of requests served from the cache rather than the backing database.
- Edge location
- An AWS site close to users where CloudFront caches content and Global Accelerator accepts traffic.
- Cache key
- The combination of URL and selected headers, cookies and query strings that identifies a unique cached object.
- TTL
- Time to live: how long CloudFront keeps an object in cache before checking the origin again.
- Invalidation
- A CloudFront request to remove objects from edge caches before their TTL expires.
- Origin access control (OAC)
- A CloudFront feature that lets a distribution read a private S3 bucket so users cannot access the bucket directly.
- AWS Global Accelerator
- A service providing two static anycast IP addresses that route TCP and UDP traffic over the AWS backbone to healthy endpoints.
- Anycast IP
- An IP address announced from many locations at once, so each client reaches the nearest one.
- OLTP vs OLAP
- Online transaction processing handles many small reads and writes; online analytical processing runs large aggregate queries over historical data.
- Amazon Aurora
- A MySQL- and PostgreSQL-compatible relational engine with distributed storage across three AZs and up to 15 read replicas.
- Amazon DynamoDB
- A serverless key-value and document NoSQL database with consistent single-digit millisecond performance at any scale.
- Amazon Redshift
- A managed columnar data warehouse for analytics over large datasets.
- Amazon DocumentDB
- A managed JSON document database compatible with MongoDB APIs and drivers.
- Amazon Neptune
- A managed graph database for data defined by relationships between entities.
- RDS Proxy
- A managed database proxy that pools connections to RDS and Aurora and speeds failover.
- Partition key
- The key attribute DynamoDB hashes to distribute items across physical partitions.
- Sort key
- The second part of a composite primary key that orders items sharing a partition key.
- Hot partition
- A partition receiving a disproportionate share of traffic, causing throttling.
- Read capacity unit (RCU)
- One strongly consistent or two eventually consistent reads per second of an item up to 4 KB.
- Write capacity unit (WCU)
- One write per second of an item up to 1 KB.
- Global secondary index
- An index with a different partition key that can be added anytime and supports eventually consistent reads.
- On-demand capacity
- A DynamoDB billing mode charging per request with no capacity planning.
- Shard
- The unit of capacity in a provisioned Kinesis data stream, with fixed read and write throughput.
- Partition key (Kinesis)
- The value that determines which shard receives a record, preserving order per key.
- Retention period
- How long Kinesis Data Streams keeps records for reading and replay, 24 hours by default and extendable.
- Enhanced fan-out
- A Kinesis feature giving each registered consumer dedicated read throughput per shard.
- Amazon Data Firehose
- A fully managed service that buffers streaming data and delivers it to destinations like S3, Redshift and OpenSearch.
- Amazon MSK
- Amazon Managed Streaming for Apache Kafka, a managed Kafka service with a serverless option.
- Data lake
- A central repository, usually on S3, that stores raw and processed data of any format for many analytics tools.
- AWS Glue Data Catalog
- A central metadata store of table definitions shared by Athena, EMR, Redshift Spectrum and Glue.
- Glue crawler
- A Glue component that scans data sources, infers schemas and creates or updates Data Catalog tables.
- Amazon Athena
- A serverless SQL query service for data in S3, priced per data scanned.
- AWS Lake Formation
- A service to build data lakes and manage fine-grained table, column and row access to them centrally.
- Redshift Spectrum
- A Redshift feature that queries data in S3 directly and joins it with warehouse tables.
- Amazon QuickSight
- A serverless business intelligence service for dashboards and visualizations.
- Target tracking scaling
- A policy that adjusts capacity to keep a chosen metric near a target value.
- Step scaling
- A policy that makes larger adjustments for larger CloudWatch alarm breaches.
- Simple scaling
- A legacy policy making one adjustment per alarm, then waiting for a cooldown period.
- Scheduled scaling
- Changing Auto Scaling group capacity at set times for known load patterns.
- Predictive scaling
- Forecasting load from history with machine learning to add capacity before it is needed.
- Warm pool
- A set of pre-initialized instances kept ready to join an Auto Scaling group quickly.
- Lifecycle hook
- A pause during instance launch or termination that lets you run custom actions.
- AWS DataSync
- An online data transfer service for moving files between on-premises storage, other clouds and AWS storage.
- Snow Family
- Physical AWS devices used to move large amounts of data offline and to run compute at the edge.
- Storage Gateway
- A hybrid service giving on-premises applications file, volume or tape interfaces backed by AWS storage with local caching.
- Tape Gateway
- A Storage Gateway type that presents a virtual tape library to existing backup software, storing tapes in S3 and Glacier classes.
- AWS Transfer Family
- Managed SFTP, FTPS, FTP and AS2 endpoints that store files in S3 or EFS.
- Change data capture (CDC)
- Continuously replicating ongoing database changes from source to target after the initial load.
- AWS SCT
- The Schema Conversion Tool, which converts database schemas and code between different engines.
Domain 4: Design Cost-Optimized Architectures (20%)
Exam tips
- Steady and long-term: Savings Plans or RIs. Interruptible and flexible: Spot. Short, unpredictable and uninterruptible: On-Demand. Per-socket or per-core BYOL licensing: Dedicated Hosts, not Dedicated Instances. Flexibility across families, Regions or Fargate and Lambda: Compute Savings Plan.
- Reduce Spot interruptions by diversifying instance types and AZs and using price-capacity-optimized or capacity-optimized allocation. The warning is two minutes. Keep a small On-Demand base for capacity that must always exist.
- Get recommendations from utilization data: Compute Optimizer. Better price performance with recompile-free languages: Graviton. Idle or spiky workloads favor serverless; steady high utilization favors provisioned capacity with commitments. Right-size before committing.
- Unknown or changing access: Intelligent-Tiering. Rarely read but must be instant: Standard-IA or Glacier Instant Retrieval. Recreatable data: One Zone-IA. Archive with hours of retrieval acceptable at the lowest price: Deep Archive.
- Old versions filling a versioned bucket: add a noncurrent version expiration rule. Organization-wide storage visibility: Storage Lens. Others downloading your large dataset should pay transfer costs: Requester Pays, which requires authenticated requesters.
- gp2 to gp3 is a no-downtime change that usually saves money. Automating snapshot retention by tag: Data Lifecycle Manager. Long-term, rarely restored snapshots: Snapshots Archive. Unattached volumes still cost money.
- Unpredictable or spiky: DynamoDB on-demand or Aurora Serverless v2. Steady and predictable: provisioned capacity with reservations. A stopped RDS database restarts after seven days, so for long idle periods snapshot and delete it.
- High NAT gateway cost with S3 or DynamoDB traffic: add a gateway endpoint. High internet egress for static or cacheable content: put it behind CloudFront. Inbound data is free; cross-AZ and cross-Region traffic is not.
- Alert before overspending: Budgets. Analyze trends and get Savings Plans recommendations: Cost Explorer. Most granular data for custom reports: Cost and Usage Report. Costs per team or project: activate cost allocation tags. Best-practice checks: Trusted Advisor.
- Reserved Instance and Savings Plans discounts are shared across accounts in an organization by default. If one account must not share or receive them, turn off sharing for that account in the management account's billing preferences.
Key terms
- On-Demand Instance
- An instance billed per second or hour with no commitment.
- Reserved Instance
- A one- or three-year commitment to an instance configuration in exchange for a lower rate.
- Compute Savings Plan
- A dollars-per-hour commitment that discounts EC2 across families and Regions, plus Fargate and Lambda.
- EC2 Instance Savings Plan
- A deeper-discount commitment tied to one instance family in one Region, flexible on size, OS and AZ.
- Spot Instance
- Spare EC2 capacity at a large discount that AWS can reclaim with a two-minute notice.
- Dedicated Host
- A physical server dedicated to you, with socket and core visibility for per-core or per-socket licensing.
- On-Demand Capacity Reservation
- Reserved EC2 capacity in a specific AZ without a term commitment, billed whether used or not.
- Spot interruption notice
- A two-minute warning, via instance metadata and EventBridge, that EC2 will reclaim a Spot Instance.
- Rebalance recommendation
- An early signal that a Spot Instance is at elevated risk of interruption.
- Capacity Rebalancing
- An Auto Scaling feature that launches replacement Spot capacity when a rebalance recommendation arrives.
- Spot capacity pool
- The spare capacity for one instance type in one Availability Zone.
- Mixed instances policy
- An Auto Scaling group setting combining multiple instance types and On-Demand and Spot purchase options.
- Price-capacity-optimized
- A Spot allocation strategy that favors pools with high available capacity and then low price.
- On-Demand base capacity
- The number of instances in a mixed group that always run as On-Demand before Spot is used.
- Right-sizing
- Adjusting resource types and sizes to match actual utilization and performance needs.
- AWS Compute Optimizer
- A service that uses utilization metrics to recommend optimal EC2, EBS, Lambda, ECS and other configurations.
- AWS Graviton
- AWS-designed Arm-based processors offering strong price performance for compatible workloads.
- CloudWatch agent
- Software that publishes additional metrics such as memory utilization from instances to CloudWatch.
- Over-provisioned
- A resource whose capacity is well above what the workload uses, so it can be downsized.
- Instance Scheduler on AWS
- An AWS solution that starts and stops EC2 and RDS instances on defined schedules.
- S3 Standard
- The default class for frequently accessed data, with no retrieval fees or minimum duration.
- Standard-IA
- An S3 class for infrequently accessed data with millisecond access, retrieval fees and a 30-day minimum.
- One Zone-IA
- A lower-cost infrequent-access class that stores data in a single Availability Zone.
- Intelligent-Tiering
- An S3 class that automatically moves objects between access tiers based on their usage, with no retrieval fees.
- Glacier Instant Retrieval
- An archive class with millisecond access for data read about once a quarter, with a 90-day minimum.
- Glacier Flexible Retrieval
- An archive class whose objects must be restored first, taking minutes to hours, with a 90-day minimum.
- Glacier Deep Archive
- The lowest-cost S3 class, for long-term archives retrieved within hours, with a 180-day minimum.
- Lifecycle rule
- A bucket configuration that transitions or expires objects automatically based on age and filters.
- Transition action
- A lifecycle action that moves objects to a colder storage class after a set number of days.
- Expiration action
- A lifecycle action that deletes objects, or noncurrent versions, after a set period.
- Noncurrent version
- An older version of an object in a versioned bucket, which lifecycle rules can transition or expire separately.
- S3 Storage Lens
- An analytics dashboard providing organization-wide storage usage, activity and recommendations.
- Requester Pays
- A bucket setting that makes authenticated requesters pay for requests and data transfer.
- Elastic Volumes
- An EBS feature to change volume type, size, IOPS or throughput while the volume is in use.
- Incremental snapshot
- An EBS snapshot that stores only blocks changed since the previous snapshot.
- Data Lifecycle Manager
- A service that automates EBS snapshot and AMI creation, retention and cross-Region copies by tag-based policy.
- EBS Snapshots Archive
- A low-cost tier for rarely accessed snapshots with a 90-day minimum and restores taking up to 72 hours.
- Recycle Bin
- A feature that retains deleted snapshots and AMIs for a set period so they can be recovered.
- Unattached volume
- An EBS volume in the available state, not attached to any instance but still billed.
- On-demand mode (DynamoDB)
- A capacity mode that bills per read and write request with no capacity planning.
- Provisioned mode (DynamoDB)
- A capacity mode that bills hourly for configured RCUs and WCUs, optionally with auto scaling.
- Aurora capacity unit (ACU)
- The unit of Aurora Serverless v2 capacity, combining memory with corresponding CPU and networking.
- Aurora Serverless v2
- An Aurora configuration that scales capacity automatically in fine-grained ACU increments between set limits.
- Reserved DB Instance
- A one- or three-year RDS or Aurora commitment that lowers the hourly instance price.
- DynamoDB reserved capacity
- A commitment to provisioned DynamoDB capacity for a discounted rate.
- Stopped DB instance
- An RDS instance not billed for instance hours, which restarts automatically after seven days.
- Egress
- Data leaving AWS to the internet, charged per GB.
- Ingress
- Data entering AWS from the internet, generally free.
- Inter-AZ transfer
- Traffic between Availability Zones in one Region, charged per GB in each direction.
- NAT gateway data processing
- A per-GB charge on all traffic passing through a NAT gateway, in addition to its hourly charge.
- Gateway VPC endpoint
- A free route-table target that gives private subnets access to S3 or DynamoDB without a NAT gateway.
- Interface endpoint
- A PrivateLink network interface in your subnets for private access to AWS services, billed hourly and per GB.
- Price class
- A CloudFront setting that limits which edge locations serve content, trading reach for cost.
- Cost Explorer
- An interactive tool to analyze, visualize and forecast AWS costs and usage, with commitment recommendations.
- AWS Budgets
- A service that alerts, and can take actions, when costs or usage exceed or are forecast to exceed thresholds.
- Budget action
- An automatic or approved response to a budget threshold, such as applying a restrictive policy or stopping instances.
- Cost and Usage Report
- The most detailed AWS billing dataset, delivered to S3 for analysis with tools like Athena.
- Cost allocation tag
- A resource tag activated in billing so costs can be grouped and filtered by it.
- Cost Anomaly Detection
- A service that uses machine learning to detect and alert on unusual spending patterns.
- AWS Trusted Advisor
- A service that checks accounts against best practices for cost, performance, security, fault tolerance and limits.
- Consolidated billing
- An AWS Organizations feature that combines all member accounts' charges into one bill paid by the management account.
- Management account
- The account that creates the organization and pays for all member accounts; also called the payer account.
- Member account
- An AWS account in an organization whose charges roll up to the management account's bill.
- Volume pricing tier
- A lower per-unit price that applies once combined usage passes a threshold.
- Discount sharing
- Applying Reserved Instance and Savings Plans benefits across accounts in an organization.
- Linked account
- The billing term for a member account, used to filter and group costs in Cost Explorer and the CUR.
Study Solutions Architect Associate for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Solutions Architect Associate study planLessons, quizzes, exam simulations and hands-on labs.