StudyToCert

All certifications / Solutions Architect Associate / Cheat sheet

Solutions Architect Associate SAA-C03 cheat sheet

Every exam tip and key term from the free Solutions Architect Associate lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Design Secure Architectures (30%)

Exam tips

Key terms

IAM role
An identity with permissions but no long-term credentials, assumed by a trusted principal to receive temporary credentials.
IAM group
A collection of IAM users that share attached policies; it cannot sign in, be nested or be a policy principal.
Identity-based policy
A policy attached to a user, group or role that states what that identity may do.
Resource-based policy
A policy attached to a resource, such as an S3 bucket policy, that names the principals allowed to access it.
Explicit deny
A Deny statement that matches a request; it overrides any Allow in any policy.
Permissions boundary
A managed policy that sets the maximum permissions an IAM user or role can have, without granting any itself.
Instance profile
The container that passes an IAM role to an EC2 instance so software on it receives temporary credentials.
AWS Organizations
The service that groups AWS accounts for central management, policies and consolidated billing.
Organizational unit (OU)
A container of accounts inside AWS Organizations to which policies such as SCPs can be attached.
Service control policy (SCP)
An Organizations policy that sets the maximum permissions for identities in member accounts; it never grants access.
Permission set
An IAM Identity Center template of policies that becomes a role in each account it is assigned to.
External ID
A secret value required in a cross-account role's trust policy to protect against the confused deputy problem.
AWS Control Tower
A service that sets up and governs a multi-account landing zone with baseline accounts and controls.
AWS STS
The Security Token Service, which issues temporary, expiring credentials for roles and federated users.
Federation
Granting AWS access to identities managed outside IAM, such as a corporate IdP or web identity provider.
SAML 2.0
An XML-based standard for exchanging signed authentication assertions, commonly used for workforce federation.
OpenID Connect (OIDC)
An identity layer on OAuth 2.0 whose signed tokens can be exchanged for AWS role credentials.
Cognito user pool
A managed user directory that handles sign-up and sign-in and returns JWTs.
Cognito identity pool
A service that exchanges identity tokens for temporary AWS credentials mapped to IAM roles.
Security group
A stateful, allow-only virtual firewall attached to network interfaces.
Network ACL
A stateless subnet-level firewall with numbered allow and deny rules evaluated in order.
Public subnet
A subnet whose route table sends internet-bound traffic to an internet gateway.
NAT gateway
A managed service in a public subnet that lets private instances start outbound internet connections.
Bastion host
A hardened instance in a public subnet used as a jump point for SSH into private instances.
Session Manager
A Systems Manager feature that gives shell access to instances over an outbound agent connection, controlled by IAM.
VPC endpoint
A private connection from a VPC to a supported AWS or partner service without using the internet.
Gateway endpoint
A route-table target that gives private, free access to S3 or DynamoDB from within a VPC.
Interface endpoint
A PrivateLink network interface with private IPs in your subnets that fronts an AWS or partner service.
AWS PrivateLink
The technology that exposes a service through interface endpoints in consumer VPCs without peering.
Endpoint policy
A resource policy on a VPC endpoint that restricts which actions and resources can be reached through it.
aws:SourceVpce
A condition key that matches the ID of the VPC endpoint a request came through.
AWS WAF
A layer 7 web application firewall that filters HTTP(S) requests using rules in a web ACL.
Web ACL
The AWS WAF resource that holds rules and is associated with CloudFront, ALB, API Gateway and other supported resources.
Rate-based rule
A WAF rule that blocks source IPs exceeding a request count within a time window.
Shield Standard
Automatic, no-extra-cost protection for all AWS customers against common layer 3 and 4 DDoS attacks.
Shield Advanced
A paid DDoS protection tier with SRT support, advanced detection and DDoS cost protection.
Origin access control (OAC)
A CloudFront feature that signs requests to an S3 origin so the bucket can stay private and accept only that distribution.
AWS KMS
The managed service that creates, stores and controls encryption keys and logs their use in CloudTrail.
AWS managed key
A KMS key created in your account by an AWS service, auditable but with a key policy you cannot change.
Customer managed key
A KMS key you create and control, including its key policy, rotation, disabling and deletion.
Key policy
The resource-based policy on a KMS key that is the primary control over who can use and manage it.
Envelope encryption
Encrypting data with a data key, then encrypting that data key with a KMS key.
SSE-KMS
S3 server-side encryption using a KMS key, with auditable key use and key-policy control.
S3 Bucket Key
A bucket-level data key that reduces the number of KMS calls, and cost, for SSE-KMS.
TLS
Transport Layer Security, the protocol that encrypts and authenticates network connections such as HTTPS.
AWS Certificate Manager (ACM)
A service that issues, stores and automatically renews TLS certificates for integrated AWS services.
TLS termination
Decrypting TLS at a front-end component such as a load balancer before passing the request on.
Server Name Indication (SNI)
A TLS extension that lets one listener serve different certificates for different host names.
Viewer protocol policy
The CloudFront setting that controls whether viewers may use HTTP, are redirected to HTTPS or must use HTTPS.
aws:SecureTransport
A condition key that is true when the request was sent over TLS.
Secrets Manager
A managed service that stores, encrypts, audits and automatically rotates secrets.
Parameter Store
A Systems Manager feature for hierarchical configuration data and secrets, without built-in rotation.
SecureString
A Parameter Store parameter type whose value is encrypted with a KMS key.
Rotation
Periodically replacing a secret with a new value and updating every place that uses it.
Managed rotation
Secrets Manager rotation for supported databases that needs no custom Lambda code.
Dynamic reference
A CloudFormation template reference that resolves a parameter or secret value at deploy time.
Block Public Access
Account and bucket settings that override any ACL or policy that would make S3 data public.
Presigned URL
A time-limited URL signed with an authorized identity's credentials that grants one S3 operation on one object.
Versioning
An S3 bucket setting that keeps every version of an object so overwrites and deletes can be undone.
MFA Delete
A versioning option, enabled only by the root user, that requires MFA to permanently delete versions or change versioning.
Object Lock compliance mode
A WORM retention mode that nobody, including root, can shorten or remove before it expires.
Object Lock governance mode
A WORM retention mode that users with special bypass permission can override.
Legal hold
An Object Lock flag that prevents a version from being deleted until the hold is removed, with no expiry date.
CloudTrail
The service that records API activity in AWS accounts for auditing and investigation.
Data events
High-volume CloudTrail events, such as S3 object reads and writes, that must be enabled explicitly.
AWS Config
The service that records resource configuration history and evaluates compliance with rules.
GuardDuty
A managed threat detection service that analyzes logs to find malicious or unauthorized activity.
Inspector
A service that continuously scans EC2, container images and Lambda functions for known vulnerabilities.
Macie
A service that discovers and classifies sensitive data such as PII in Amazon S3.
Security Hub
A service that aggregates security findings and runs best-practice checks across accounts.

Domain 2: Design Resilient Architectures (26%)

Exam tips

Key terms

Availability Zone
One or more isolated data centers in a Region with independent power and networking.
Application Load Balancer
A layer 7 load balancer that routes HTTP and HTTPS requests by content such as path and host.
Network Load Balancer
A layer 4 load balancer for TCP, UDP and TLS with static IPs per AZ and very high performance.
Auto Scaling group
A set of EC2 instances launched from a template that EC2 Auto Scaling keeps at a desired, healthy count.
Target tracking policy
A scaling policy that adjusts capacity to keep a chosen metric near a target value.
ELB health check type
An Auto Scaling group setting that replaces instances the load balancer reports as unhealthy.
Standard queue
An SQS queue type with very high throughput, at-least-once delivery and best-effort ordering.
FIFO queue
An SQS queue type that preserves order within a message group and prevents duplicates.
Visibility timeout
The period during which a received SQS message is hidden from other consumers while it is processed.
Dead-letter queue
A queue that receives messages that failed processing more times than the maxReceiveCount.
Long polling
An SQS receive mode that waits up to 20 seconds for messages, reducing empty responses.
Fan-out
Publishing a message once to an SNS topic so that many subscribers, often SQS queues, each receive a copy.
Idempotent processing
Handling a message so that processing it twice has the same effect as processing it once.
AWS Lambda
A serverless compute service that runs functions in response to events, for up to 15 minutes per invocation.
Reserved concurrency
A Lambda setting that guarantees and caps the number of concurrent executions for one function.
Provisioned concurrency
Pre-initialized Lambda execution environments that remove cold-start latency.
Amazon API Gateway
A managed service for creating, securing and throttling REST, HTTP and WebSocket APIs.
Amazon EventBridge
A serverless event bus that routes events to targets based on pattern-matching rules.
AWS Step Functions
A service that orchestrates workflows as state machines with retries, branches and error handling.
Amazon ECR
A private container image registry integrated with IAM that can scan images for vulnerabilities.
Task definition
The ECS blueprint describing a task's containers, resources, networking and IAM roles.
ECS service
An ECS construct that keeps a desired number of tasks running and integrates with load balancers.
Amazon EKS
A managed Kubernetes service that runs the control plane for you.
AWS Fargate
A serverless compute engine for containers that removes the need to manage EC2 hosts.
ECS task role
The IAM role whose permissions the application inside an ECS task uses.
Task execution role
The IAM role the ECS agent uses to pull images, fetch injected secrets and send logs.
Multi-AZ deployment
An RDS configuration with a synchronously replicated standby in another AZ and automatic failover.
Read replica
An asynchronously replicated copy of a database used to offload reads; can be promoted manually.
Replica lag
The delay between a write on the primary and its appearance on an asynchronous replica.
Aurora Replica
A reader instance sharing the Aurora cluster volume that serves reads and is an automatic failover target.
Reader endpoint
An Aurora endpoint that load-balances read connections across the cluster's replicas.
Aurora Global Database
An Aurora configuration that replicates a cluster to secondary Regions with typically sub-second lag.
Global table
A DynamoDB table replicated across multiple Regions, with every replica accepting reads and writes.
Last writer wins
The default conflict resolution rule in global tables where the most recent write to an item prevails.
Point-in-time recovery (PITR)
Continuous DynamoDB backups allowing restore to any second in the recovery window of up to 35 days.
On-demand backup
A full, manually created DynamoDB backup retained until you delete it.
DynamoDB Streams
A time-ordered log of item-level changes kept for 24 hours for processing by consumers such as Lambda.
Time to Live (TTL)
A DynamoDB feature that automatically deletes items after a timestamp attribute expires.
Hosted zone
A Route 53 container for the DNS records of a domain, either public or private to VPCs.
Alias record
A Route 53 record that points to an AWS resource, works at the zone apex and has no query charge for AWS targets.
Failover routing
An active-passive policy returning the secondary record only when the primary's health check fails.
Weighted routing
A policy that splits DNS answers among records in proportion to assigned weights.
Latency-based routing
A policy that returns the endpoint in the Region with the lowest latency for the user.
Geolocation routing
A policy that returns answers based on the user's geographic location.
Multivalue answer routing
A policy that returns up to eight healthy records chosen at random.
Disaster recovery
The strategy and processes for restoring a workload after a major event such as a Regional outage.
RPO
Recovery point objective: the maximum acceptable data loss, measured as time before the disaster.
RTO
Recovery time objective: the maximum acceptable time to restore service after a disaster.
Backup and restore
The lowest-cost DR strategy, which restores data and rebuilds infrastructure only after a disaster.
Pilot light
A DR strategy that keeps data replicated in the recovery Region with the application tier off until needed.
Warm standby
A DR strategy that runs a scaled-down but fully functional copy of the workload in the recovery Region.
Multi-site active-active
A DR strategy that serves production traffic from multiple Regions at full scale simultaneously.
AWS Backup
A central service that schedules, retains and copies backups across many AWS services.
Backup plan
An AWS Backup policy defining backup frequency, retention, lifecycle and copy rules for assigned resources.
Vault Lock
An AWS Backup feature that makes a backup vault's retention settings immutable.
Cross-Region Replication
Asynchronous copying of S3 objects to a bucket in another Region; requires versioning on both buckets.
EBS snapshot
An incremental, point-in-time backup of an EBS volume that can be copied across Regions and accounts.
AMI
An Amazon Machine Image: a Regional template of snapshots and launch settings used to launch instances.
AWS Elastic Disaster Recovery
A service that continuously replicates servers to AWS and launches recovery instances on demand.
Site-to-Site VPN
An AWS service providing two encrypted IPsec tunnels over the internet between on-premises and AWS.
Customer gateway
The on-premises VPN device, or its AWS representation, at your end of a Site-to-Site VPN.
AWS Direct Connect
A dedicated private network connection between on-premises networks and AWS.
Virtual interface (VIF)
A logical connection on Direct Connect: private, public or transit.
BGP
Border Gateway Protocol, the dynamic routing protocol that advertises routes and enables automatic failover between paths.
Transit Gateway
A regional network hub that connects VPCs and on-premises networks with centralized routing.
Infrastructure as code (IaC)
Defining infrastructure in versioned text files that tools deploy repeatably.
CloudFormation stack
A set of AWS resources created and managed together from one template.
Change set
A preview of the changes CloudFormation will make when updating a stack.
StackSets
A CloudFormation feature that deploys a template across multiple accounts and Regions.
Service quota
A per-account, per-Region limit on resources or request rates, some of which can be increased.
Exponential backoff
A retry strategy that waits progressively longer between attempts, usually with random jitter.

Domain 3: Design High-Performing Architectures (24%)

Exam tips

Key terms

Instance family
A group of EC2 instance types optimized for a resource profile, such as general purpose, compute, memory, storage or accelerated computing.
Cluster placement group
Instances packed closely in one Availability Zone for low-latency, high-throughput networking between them.
Spread placement group
Each instance on distinct hardware, limited to seven running instances per AZ per group, to reduce correlated failures.
Partition placement group
Instances divided into partitions on separate racks, for large distributed and replicated systems.
Elastic Network Adapter (ENA)
The network interface that provides enhanced networking with high bandwidth and packet rates on current instance types.
Elastic Fabric Adapter (EFA)
A network interface with operating system bypass for tightly coupled HPC and machine learning workloads using MPI or NCCL.
Burstable instance
A T-family instance that accrues CPU credits when idle and spends them to burst above a baseline.
gp3
General purpose SSD with a baseline of 3,000 IOPS and 125 MB/s, where IOPS and throughput are provisioned independently of size.
gp2
The older general purpose SSD whose IOPS scale with volume size and use burst credits on small volumes.
io2 Block Express
The highest-performance EBS SSD for demanding databases, with sub-millisecond latency and higher durability.
st1
Throughput optimized HDD for large sequential workloads such as big data and logs; not bootable.
sc1
Cold HDD, the lowest-cost EBS volume, for infrequently accessed sequential data; not bootable.
Instance store
Temporary block storage physically attached to the host; data is lost on stop, hibernation, termination or disk failure.
Multi-Attach
An io1 and io2 feature that attaches one volume to several Nitro instances in the same AZ.
Amazon EFS
A managed, elastic NFS file system for Linux that many instances across AZs can mount simultaneously.
Mount target
An EFS network endpoint in a subnet of each AZ through which clients mount the file system.
FSx for Windows File Server
A managed Windows file server using SMB with Active Directory integration and NTFS permissions.
FSx for Lustre
A managed high-performance parallel file system for HPC and ML, with optional S3 data repository integration.
FSx for NetApp ONTAP
A managed NetApp ONTAP file system supporting NFS, SMB and iSCSI with ONTAP data management features.
Server Message Block (SMB)
The file sharing protocol used by Windows clients and servers.
Scratch vs persistent (Lustre)
Scratch file systems do not replicate data and suit temporary jobs; persistent file systems replicate within an AZ.
Prefix
The leading part of an S3 object key; request rate guidance applies per prefix.
Multipart upload
Uploading an object in independently transferred parts that S3 then assembles; required above 5 GB.
Byte-range fetch
Downloading a specific range of bytes of an object with the HTTP Range header, often in parallel.
S3 Transfer Acceleration
A bucket feature that routes transfers through CloudFront edge locations over the AWS backbone.
503 Slow Down
An S3 response indicating the request rate temporarily exceeds what the prefix can handle; clients should retry with backoff.
Exponential backoff
A retry strategy that waits progressively longer between attempts to let a service recover.
ElastiCache for Redis OSS
A managed in-memory data store with rich data types, replication, persistence and Multi-AZ failover; Valkey is a compatible engine option.
ElastiCache for Memcached
A managed, multi-threaded key-value cache without replication or persistence.
DAX
DynamoDB Accelerator, an API-compatible in-memory cache for DynamoDB with microsecond read latency.
Lazy loading
A caching strategy that loads data into the cache only after a cache miss; also called cache-aside.
Write-through
A caching strategy that updates the cache whenever the database is written, keeping cached data current.
Time to live (TTL)
An expiry time on a cached item after which it is removed and reloaded on the next request.
Cache hit ratio
The share of requests served from the cache rather than the backing database.
Edge location
An AWS site close to users where CloudFront caches content and Global Accelerator accepts traffic.
Cache key
The combination of URL and selected headers, cookies and query strings that identifies a unique cached object.
TTL
Time to live: how long CloudFront keeps an object in cache before checking the origin again.
Invalidation
A CloudFront request to remove objects from edge caches before their TTL expires.
Origin access control (OAC)
A CloudFront feature that lets a distribution read a private S3 bucket so users cannot access the bucket directly.
AWS Global Accelerator
A service providing two static anycast IP addresses that route TCP and UDP traffic over the AWS backbone to healthy endpoints.
Anycast IP
An IP address announced from many locations at once, so each client reaches the nearest one.
OLTP vs OLAP
Online transaction processing handles many small reads and writes; online analytical processing runs large aggregate queries over historical data.
Amazon Aurora
A MySQL- and PostgreSQL-compatible relational engine with distributed storage across three AZs and up to 15 read replicas.
Amazon DynamoDB
A serverless key-value and document NoSQL database with consistent single-digit millisecond performance at any scale.
Amazon Redshift
A managed columnar data warehouse for analytics over large datasets.
Amazon DocumentDB
A managed JSON document database compatible with MongoDB APIs and drivers.
Amazon Neptune
A managed graph database for data defined by relationships between entities.
RDS Proxy
A managed database proxy that pools connections to RDS and Aurora and speeds failover.
Partition key
The key attribute DynamoDB hashes to distribute items across physical partitions.
Sort key
The second part of a composite primary key that orders items sharing a partition key.
Hot partition
A partition receiving a disproportionate share of traffic, causing throttling.
Read capacity unit (RCU)
One strongly consistent or two eventually consistent reads per second of an item up to 4 KB.
Write capacity unit (WCU)
One write per second of an item up to 1 KB.
Global secondary index
An index with a different partition key that can be added anytime and supports eventually consistent reads.
On-demand capacity
A DynamoDB billing mode charging per request with no capacity planning.
Shard
The unit of capacity in a provisioned Kinesis data stream, with fixed read and write throughput.
Partition key (Kinesis)
The value that determines which shard receives a record, preserving order per key.
Retention period
How long Kinesis Data Streams keeps records for reading and replay, 24 hours by default and extendable.
Enhanced fan-out
A Kinesis feature giving each registered consumer dedicated read throughput per shard.
Amazon Data Firehose
A fully managed service that buffers streaming data and delivers it to destinations like S3, Redshift and OpenSearch.
Amazon MSK
Amazon Managed Streaming for Apache Kafka, a managed Kafka service with a serverless option.
Data lake
A central repository, usually on S3, that stores raw and processed data of any format for many analytics tools.
AWS Glue Data Catalog
A central metadata store of table definitions shared by Athena, EMR, Redshift Spectrum and Glue.
Glue crawler
A Glue component that scans data sources, infers schemas and creates or updates Data Catalog tables.
Amazon Athena
A serverless SQL query service for data in S3, priced per data scanned.
AWS Lake Formation
A service to build data lakes and manage fine-grained table, column and row access to them centrally.
Redshift Spectrum
A Redshift feature that queries data in S3 directly and joins it with warehouse tables.
Amazon QuickSight
A serverless business intelligence service for dashboards and visualizations.
Target tracking scaling
A policy that adjusts capacity to keep a chosen metric near a target value.
Step scaling
A policy that makes larger adjustments for larger CloudWatch alarm breaches.
Simple scaling
A legacy policy making one adjustment per alarm, then waiting for a cooldown period.
Scheduled scaling
Changing Auto Scaling group capacity at set times for known load patterns.
Predictive scaling
Forecasting load from history with machine learning to add capacity before it is needed.
Warm pool
A set of pre-initialized instances kept ready to join an Auto Scaling group quickly.
Lifecycle hook
A pause during instance launch or termination that lets you run custom actions.
AWS DataSync
An online data transfer service for moving files between on-premises storage, other clouds and AWS storage.
Snow Family
Physical AWS devices used to move large amounts of data offline and to run compute at the edge.
Storage Gateway
A hybrid service giving on-premises applications file, volume or tape interfaces backed by AWS storage with local caching.
Tape Gateway
A Storage Gateway type that presents a virtual tape library to existing backup software, storing tapes in S3 and Glacier classes.
AWS Transfer Family
Managed SFTP, FTPS, FTP and AS2 endpoints that store files in S3 or EFS.
Change data capture (CDC)
Continuously replicating ongoing database changes from source to target after the initial load.
AWS SCT
The Schema Conversion Tool, which converts database schemas and code between different engines.

Domain 4: Design Cost-Optimized Architectures (20%)

Exam tips

Key terms

On-Demand Instance
An instance billed per second or hour with no commitment.
Reserved Instance
A one- or three-year commitment to an instance configuration in exchange for a lower rate.
Compute Savings Plan
A dollars-per-hour commitment that discounts EC2 across families and Regions, plus Fargate and Lambda.
EC2 Instance Savings Plan
A deeper-discount commitment tied to one instance family in one Region, flexible on size, OS and AZ.
Spot Instance
Spare EC2 capacity at a large discount that AWS can reclaim with a two-minute notice.
Dedicated Host
A physical server dedicated to you, with socket and core visibility for per-core or per-socket licensing.
On-Demand Capacity Reservation
Reserved EC2 capacity in a specific AZ without a term commitment, billed whether used or not.
Spot interruption notice
A two-minute warning, via instance metadata and EventBridge, that EC2 will reclaim a Spot Instance.
Rebalance recommendation
An early signal that a Spot Instance is at elevated risk of interruption.
Capacity Rebalancing
An Auto Scaling feature that launches replacement Spot capacity when a rebalance recommendation arrives.
Spot capacity pool
The spare capacity for one instance type in one Availability Zone.
Mixed instances policy
An Auto Scaling group setting combining multiple instance types and On-Demand and Spot purchase options.
Price-capacity-optimized
A Spot allocation strategy that favors pools with high available capacity and then low price.
On-Demand base capacity
The number of instances in a mixed group that always run as On-Demand before Spot is used.
Right-sizing
Adjusting resource types and sizes to match actual utilization and performance needs.
AWS Compute Optimizer
A service that uses utilization metrics to recommend optimal EC2, EBS, Lambda, ECS and other configurations.
AWS Graviton
AWS-designed Arm-based processors offering strong price performance for compatible workloads.
CloudWatch agent
Software that publishes additional metrics such as memory utilization from instances to CloudWatch.
Over-provisioned
A resource whose capacity is well above what the workload uses, so it can be downsized.
Instance Scheduler on AWS
An AWS solution that starts and stops EC2 and RDS instances on defined schedules.
S3 Standard
The default class for frequently accessed data, with no retrieval fees or minimum duration.
Standard-IA
An S3 class for infrequently accessed data with millisecond access, retrieval fees and a 30-day minimum.
One Zone-IA
A lower-cost infrequent-access class that stores data in a single Availability Zone.
Intelligent-Tiering
An S3 class that automatically moves objects between access tiers based on their usage, with no retrieval fees.
Glacier Instant Retrieval
An archive class with millisecond access for data read about once a quarter, with a 90-day minimum.
Glacier Flexible Retrieval
An archive class whose objects must be restored first, taking minutes to hours, with a 90-day minimum.
Glacier Deep Archive
The lowest-cost S3 class, for long-term archives retrieved within hours, with a 180-day minimum.
Lifecycle rule
A bucket configuration that transitions or expires objects automatically based on age and filters.
Transition action
A lifecycle action that moves objects to a colder storage class after a set number of days.
Expiration action
A lifecycle action that deletes objects, or noncurrent versions, after a set period.
Noncurrent version
An older version of an object in a versioned bucket, which lifecycle rules can transition or expire separately.
S3 Storage Lens
An analytics dashboard providing organization-wide storage usage, activity and recommendations.
Requester Pays
A bucket setting that makes authenticated requesters pay for requests and data transfer.
Elastic Volumes
An EBS feature to change volume type, size, IOPS or throughput while the volume is in use.
Incremental snapshot
An EBS snapshot that stores only blocks changed since the previous snapshot.
Data Lifecycle Manager
A service that automates EBS snapshot and AMI creation, retention and cross-Region copies by tag-based policy.
EBS Snapshots Archive
A low-cost tier for rarely accessed snapshots with a 90-day minimum and restores taking up to 72 hours.
Recycle Bin
A feature that retains deleted snapshots and AMIs for a set period so they can be recovered.
Unattached volume
An EBS volume in the available state, not attached to any instance but still billed.
On-demand mode (DynamoDB)
A capacity mode that bills per read and write request with no capacity planning.
Provisioned mode (DynamoDB)
A capacity mode that bills hourly for configured RCUs and WCUs, optionally with auto scaling.
Aurora capacity unit (ACU)
The unit of Aurora Serverless v2 capacity, combining memory with corresponding CPU and networking.
Aurora Serverless v2
An Aurora configuration that scales capacity automatically in fine-grained ACU increments between set limits.
Reserved DB Instance
A one- or three-year RDS or Aurora commitment that lowers the hourly instance price.
DynamoDB reserved capacity
A commitment to provisioned DynamoDB capacity for a discounted rate.
Stopped DB instance
An RDS instance not billed for instance hours, which restarts automatically after seven days.
Egress
Data leaving AWS to the internet, charged per GB.
Ingress
Data entering AWS from the internet, generally free.
Inter-AZ transfer
Traffic between Availability Zones in one Region, charged per GB in each direction.
NAT gateway data processing
A per-GB charge on all traffic passing through a NAT gateway, in addition to its hourly charge.
Gateway VPC endpoint
A free route-table target that gives private subnets access to S3 or DynamoDB without a NAT gateway.
Interface endpoint
A PrivateLink network interface in your subnets for private access to AWS services, billed hourly and per GB.
Price class
A CloudFront setting that limits which edge locations serve content, trading reach for cost.
Cost Explorer
An interactive tool to analyze, visualize and forecast AWS costs and usage, with commitment recommendations.
AWS Budgets
A service that alerts, and can take actions, when costs or usage exceed or are forecast to exceed thresholds.
Budget action
An automatic or approved response to a budget threshold, such as applying a restrictive policy or stopping instances.
Cost and Usage Report
The most detailed AWS billing dataset, delivered to S3 for analysis with tools like Athena.
Cost allocation tag
A resource tag activated in billing so costs can be grouped and filtered by it.
Cost Anomaly Detection
A service that uses machine learning to detect and alert on unusual spending patterns.
AWS Trusted Advisor
A service that checks accounts against best practices for cost, performance, security, fault tolerance and limits.
Consolidated billing
An AWS Organizations feature that combines all member accounts' charges into one bill paid by the management account.
Management account
The account that creates the organization and pays for all member accounts; also called the payer account.
Member account
An AWS account in an organization whose charges roll up to the management account's bill.
Volume pricing tier
A lower per-unit price that applies once combined usage passes a threshold.
Discount sharing
Applying Reserved Instance and Savings Plans benefits across accounts in an organization.
Linked account
The billing term for a member account, used to filter and group costs in Cost Explorer and the CUR.
Study Solutions Architect Associate for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Solutions Architect Associate study plan