80% found this document useful (10 votes)
6K views879 pages

AWS Course - All Slides

AWS Course aws solutions archtecht certification- All Slides of www.dolfined.com cours

Uploaded by

iss yaz
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
80% found this document useful (10 votes)
6K views879 pages

AWS Course - All Slides

AWS Course aws solutions archtecht certification- All Slides of www.dolfined.com cours

Uploaded by

iss yaz
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 879

AWS CERTIFIED SOLUTIONS ARCHITECT ASSOCIATE

Student e-Notebook Version 1.0


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Table of Contents

Section 1 - Suggested Study Plan .......................................................................................................................... 9

Section 2 – Introduction to Cloud Computing ..................................................................................................... 12


Section Outline ....................................................................................................................................................... 13
On-Premises Data Centers vs. Cloud ...................................................................................................................... 14
Private, Public & Hybrid Cloud................................................................................................................................ 17
Cloud Services......................................................................................................................................................... 22

Section 3 – Introduction to AWS Services – Part 1............................................................................................... 25


Section Outline ....................................................................................................................................................... 25
AWS Global Infrastructure ..................................................................................................................................... 26
AWS Free Tier ......................................................................................................................................................... 29
AWS IAM 101 ......................................................................................................................................................... 30
Identity and Access Management 101 ................................................................................................................... 31
IAM Identities – Users & IAM Best Practices .......................................................................................................... 35
AWS Virtual Private Cloud (101)............................................................................................................................. 39
AWS Virtual Private Cloud (VPC) - Components ..................................................................................................... 40
VPC Components (cont.) ......................................................................................................................................... 46
VPC – Public vs. Private Subnets & Hybrid Connectivity 101 .................................................................................. 49
Knowledge In Action – Project 1 - 1........................................................................................................................ 52

Section 4 – Introduction to AWS Services – Part 2............................................................................................... 56


Section Outline ....................................................................................................................................................... 57
Elastic Compute Cloud (EC2) 101 ........................................................................................................................... 58
Using SSH to connect a Linux EC2 instance ............................................................................................................ 63
Private, Public, and Elastic IP Addresses ................................................................................................................ 67
Understanding Security Groups.............................................................................................................................. 71
Understanding Network Access Lists (NACLs) ........................................................................................................ 74
Encryption 101 ....................................................................................................................................................... 84
AWS Key Management Service (KMS) 101 ............................................................................................................. 89
Simple Storage Service (S3) 101 ............................................................................................................................. 96
IAM Access Keys for Programmatic Access to AWS ............................................................................................. 103
AWS IAM – Elements and Policies ........................................................................................................................ 106

© DolfinED All rights reserved www.dolfined.com 1


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 IAM Roles ...................................................................................................................................................... 110


Monolithic vs. Multi-Tier Applications.................................................................................................................. 112
Introduction to Messaging and Notification Services in AWS .............................................................................. 114
Knowledge In Action – Project 1 - 2...................................................................................................................... 117
Amazon CloudFront (Content Delivery Network – CDN) 101 ............................................................................... 120
Amazon Route 53 101 .......................................................................................................................................... 124
Knowledge In Action – Project 1 - 3...................................................................................................................... 127
Amazon Relational Database Service (RDS) 101 .................................................................................................. 131
Knowledge In Action – Project 1 - 4...................................................................................................................... 135

Section 5 – Key Architecture Pillars................................................................................................................... 141


Section Outline ..................................................................................................................................................... 142
Monolithic vs. Microservices Applications............................................................................................................ 143
High Availability, Fault Tolerance, Scalability & Elastic Load Balancing 101 ....................................................... 146
Elasticity and Auto Scaling ................................................................................................................................... 149
Knowledge In Action – Project 1 - 5...................................................................................................................... 153
Monitoring and Visibility – Amazon CloudWatch 101.......................................................................................... 159
Auditing in AWS – Amazon CloudTrail ................................................................................................................. 161
Disaster Recovery in AWS 101 .............................................................................................................................. 166

Section 6 – Virtual Private Cloud (VPC) – Deep Dive .......................................................................................... 171


NAT Instance & NAT Gateway.............................................................................................................................. 173
NAT Gateway ....................................................................................................................................................... 176
Bastion Host, Proxy & Reverse Proxy Servers ....................................................................................................... 182
Bastion Host ......................................................................................................................................................... 185
Knowledge In Action – Project 2 - 1...................................................................................................................... 188
VPC Peering .......................................................................................................................................................... 191
AWS Transit Gateway .......................................................................................................................................... 195
VPC Endpoints ...................................................................................................................................................... 201
Knowledge In Action – Project 2- 2....................................................................................................................... 208
AWS IPv6 Egress-Only Gateway ........................................................................................................................... 212
VPC Flow Logs ...................................................................................................................................................... 214
Hybrid Cloud Connectivity .................................................................................................................................... 218
AWS Managed Virtual Private Networks (VPN) ................................................................................................... 219
Direct Connect ...................................................................................................................................................... 223

Section 7 – EC2 and EBS (Deep Dive) ................................................................................................................. 229

© DolfinED All rights reserved www.dolfined.com 2


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline ..................................................................................................................................................... 230


Elastic Compute Cloud (EC2) ................................................................................................................................ 232
EC2 Instance Types & Instance Lifecycle .............................................................................................................. 233
EC2 Instance Metadata & User Data ................................................................................................................... 238
EC2 Purchasing/Launch Options .......................................................................................................................... 241
EC2 Spot Instances ............................................................................................................................................... 247
EC2 Placement Groups & Data Transfer Costs ..................................................................................................... 253
EC2 Monitoring .................................................................................................................................................... 259
Elastic Block Store (EBS) ....................................................................................................................................... 264
Elastic Block Store (EBS) ....................................................................................................................................... 265
EBS Snapshots ...................................................................................................................................................... 271
Creating and Sharing/Copying EC2 AMIs ............................................................................................................. 279
RAID and EBS Volumes, AWS Batch ..................................................................................................................... 283
AWS Batch ............................................................................................................................................................ 286

Section 8 - Elastic Load Balancing and Auto Scaling on AWS ............................................................................. 288
Section Outline ..................................................................................................................................................... 289
Elastic Load Balancing .......................................................................................................................................... 291
Target Groups, Listeners, and Health Checks ....................................................................................................... 292
Cross-Zone Load Balancing, Connection Draining & Subnet Design for HA ......................................................... 299
ELB Security Groups.............................................................................................................................................. 304
ELB and SSL Certificates ....................................................................................................................................... 308
Knowledge In Action – Project 3 ........................................................................................................................... 316
ELB – Client IP Address, Monitoring, Stickiness, and PFS ..................................................................................... 320
Application Load Balancer.................................................................................................................................... 325
Network Load Balancer ........................................................................................................................................ 329
ELB – Gateway Load Balancer (GWLB) ................................................................................................................. 333
Amazon Auto Scaling ........................................................................................................................................... 335
Auto Scaling ......................................................................................................................................................... 336
Amazon AutoScaling – Launch Templates and Scaling Policies ........................................................................... 342
Knowledge In Action – Project 4 ........................................................................................................................... 348

Section 9 – Amazon Relational Database Service (RDS) ..................................................................................... 357


Knowledge In Action – Project 5 ........................................................................................................................... 376
Amazon Aurora .................................................................................................................................................... 380
Amazon Aurora Serverless ................................................................................................................................... 392
Knowledge In Action – Project 6 ........................................................................................................................... 395

© DolfinED All rights reserved www.dolfined.com 3


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Redshift .................................................................................................................................................. 399


Amazon RedShift - Introduction ........................................................................................................................... 400

Section 10 - NoSQL Databases in AWS .............................................................................................................. 409


Section Outline ..................................................................................................................................................... 410
Amazon DynamoDB ............................................................................................................................................. 411
Amazon DynamoDB – Advanced Features ........................................................................................................... 419
Knowledge In Action – Project 7 ........................................................................................................................... 428
ElastiCache ........................................................................................................................................................... 431
Amazon DocumentDB and Amazon Neptune....................................................................................................... 440

Section 11 - Mid Course Assessment................................................................................................................. 443

Section 12 – Identity and Access Management (IAM) - Intermediate ................................................................ 444


IAM Identity-Based Policies .................................................................................................................................. 446
IAM Security Token Service (STS) & IAM Roles ..................................................................................................... 456
IAM Resource-based Policies, Permissions Boundary, and Policy Evaluation Logic ............................................. 463
Knowledge In Action – Project 8 ........................................................................................................................... 469

Section 13 – Simple Storage Service (S3) – Deep Dive ....................................................................................... 472


Section Outline ..................................................................................................................................................... 473
S3 Data Consistency, Tiered Storage Classes, and S3 Lifecycle Policies................................................................ 475
S3 Server Side Encryption and Multipart Upload ................................................................................................. 482
S3 Bucket Versioning and Cross-Region Replication ............................................................................................ 487
S3 Object Lock and Glacier Vault Lock.................................................................................................................. 494
S3 Static Website Hosting .................................................................................................................................... 498
S3 Pre-Signed URLS, Transfer Acceleration, and Requester Pays ......................................................................... 501
S3 Access Management and Bucket Policies ........................................................................................................ 505
S3 Cross-Origin Resource Sharing, Batch Operations, and Billing ........................................................................ 514
Knowledge In Action – Project 9 ........................................................................................................................... 518
S3 SELECT, Glacier SELECT, S3 Performance, and AWS Transfer Family............................................................... 521
Knowledge In Action – Project 10......................................................................................................................... 526
Knowledge In Action – Project 11......................................................................................................................... 529
S3 Monitoring, Event Notification, Server Access Logging, and S3 vs. DynamoDB .............................................. 532

Section 14 – CloudFront, Route53, and Global Accelerator ............................................................................... 536


Section Outline ..................................................................................................................................................... 537
Amazon CloudFront .............................................................................................................................................. 538
CloudFront – Additional Features......................................................................................................................... 546

© DolfinED All rights reserved www.dolfined.com 4


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Route 53 ................................................................................................................................................. 551


Route 53 Routing Policies (cont.) and Route 53 Resolver ..................................................................................... 560
Knowledge In Action – Project 12......................................................................................................................... 568
Global Accelerator ................................................................................................................................................ 572
Knowledge In Action – Project 13......................................................................................................................... 580

Section 15 – Serverless Computing in AWS ....................................................................................................... 583


Section Outline ..................................................................................................................................................... 584
AWS Lambda ........................................................................................................................................................ 585
Lambda@Edge ..................................................................................................................................................... 592
API Gateway ......................................................................................................................................................... 594
Knowledge In Action – Project 14......................................................................................................................... 605

Section 16 – Storage Services in AWS ............................................................................................................... 608


Section Outline ..................................................................................................................................................... 609
Elastic File System (EFS) ....................................................................................................................................... 610
Amazon FSx .......................................................................................................................................................... 617
Amazon FSx for Windows File Server ................................................................................................................... 618
Amazon FSx for Lustre .......................................................................................................................................... 622
Amazon Storage Gateway.................................................................................................................................... 627
Amazon Snow Family ........................................................................................................................................... 631
Knowledge In Action – Project 15......................................................................................................................... 636
AWS Backup and AWS DataSync .......................................................................................................................... 639
Knowledge In Action – Project 16......................................................................................................................... 645

Section 17 – Containers in AWS ........................................................................................................................ 648


Section Outline ..................................................................................................................................................... 649
Amazon Elastic Container Service (ECS) ............................................................................................................... 650
Containers and ECS .............................................................................................................................................. 651
Amazon ECS – Features and Use Cases ................................................................................................................ 659
Knowledge In Action – Project 17......................................................................................................................... 666
Elastic Kubernetes Service (EKS) ........................................................................................................................... 670

Section 18 – Notification, Messaging and Application Integration in AWS ........................................................ 674


Section Outline ..................................................................................................................................................... 675
Simple Queue Service (SQS) .................................................................................................................................. 676
Amazon Simple Notification Service (SNS) ........................................................................................................... 685
Amazon MQ ......................................................................................................................................................... 691

© DolfinED All rights reserved www.dolfined.com 5


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Step Functions ...................................................................................................................................................... 694


Knowledge In Action – Project 18......................................................................................................................... 696

Section 19 – Management, Monitoring, and Auditing in AWS ........................................................................... 699


Section Outline ..................................................................................................................................................... 700
Amazon CloudWatch ............................................................................................................................................ 701
Amazon CloudWatch Logs.................................................................................................................................... 706
Amazon CloudWatch Events ................................................................................................................................ 712

Section 20 – Governance, Deployment, and Operations in AWS ....................................................................... 716


Section Outline ..................................................................................................................................................... 717
AWS Organizations .............................................................................................................................................. 718
AWS CloudFormation ........................................................................................................................................... 727
AWS Elastic Beanstalk .......................................................................................................................................... 735
AWS OpsWorks 101.............................................................................................................................................. 742
Knowledge In Action – Project 19......................................................................................................................... 745
AWS Systems Manager ........................................................................................................................................ 748
Parameter Store ................................................................................................................................................... 751
AWS Secrets Manager .......................................................................................................................................... 755
AWS Config........................................................................................................................................................... 759
AWS Trusted Advisor ............................................................................................................................................ 765
Knowledge In Action – Project 20......................................................................................................................... 767

Section 21 – Security, Identity and Compliance Services in AWS ....................................................................... 770


Section Outline ..................................................................................................................................................... 771
AWS CloudHSM .................................................................................................................................................... 772
Amazon Shield ...................................................................................................................................................... 777
Web Application Firewall ..................................................................................................................................... 781
Knowledge In Action – Project 21......................................................................................................................... 785
Amazon GuardDuty .............................................................................................................................................. 788
Amazon Inspector ................................................................................................................................................ 792
Amazon Cognito ................................................................................................................................................... 796
Knowledge In Action – Project 22......................................................................................................................... 798
Amazon Cognito ................................................................................................................................................... 802
AWS Directory Services ........................................................................................................................................ 807
AWS Single Sign-On (SSO) .................................................................................................................................... 809
Knowledge In Action – Project 23......................................................................................................................... 812

© DolfinED All rights reserved www.dolfined.com 6


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 22 – Analytics Services in AWS ............................................................................................................. 815


Section Outline ..................................................................................................................................................... 816
Amazon Redshift Spectrum .................................................................................................................................. 817
Elastic MAP Reduce .............................................................................................................................................. 819
Amazon Athena .................................................................................................................................................... 824
Amazon Glue ........................................................................................................................................................ 828
Knowledge In Action – Project 23......................................................................................................................... 832
Amazon Kinesis .................................................................................................................................................... 835
Kinesis Data Streams ............................................................................................................................................ 836
Kinesis Data Firehose & Kinesis Data Analytics .................................................................................................... 844
Amazon QuickSight .............................................................................................................................................. 847
Data Pipeline ........................................................................................................................................................ 849
Knowledge In Action – Project 25......................................................................................................................... 851

Section 23 - Additional Services ........................................................................................................................ 854


Section Outline ..................................................................................................................................................... 855
Amazon Elasticsearch........................................................................................................................................... 856
Elastic Transcoder ................................................................................................................................................ 859
Amazon AppSync .................................................................................................................................................. 861
Amazon WorkSpaces ............................................................................................................................................ 863
Amazon WorkDocs ............................................................................................................................................... 865
Amazon X-Ray ...................................................................................................................................................... 866
AWS Database Migration Service (DMS).............................................................................................................. 869
AWS Resource Access Manager (RAM) ................................................................................................................ 873
AWS Cost Explorer ................................................................................................................................................ 876

© DolfinED All rights reserved www.dolfined.com 7


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The course is available on Udemy & DolfinED websites,


https://www.udemy.com/course/aws-certified-solutions-architect-associate-/

Visit DolfinED’s website to browse the available courses and enroll at a discounted
price.
www.dolfined.com/course-catalog

When you visit the above URL @ www.dolfined.com, Enroll in the free course,
TCP/IP Introduction and Cloud Pre-Requisite Knowledge

Which will teach you many topics required for Cloud and IT in general, including
TCP/IP, IP Routing, IP Subnetting, Containers, Virtualization, SSL and Digital
Certificates, Encryption, NAT, and PAT, among other topics.
The course is full of animation and graphics, high quality knowledge, audio, and
video. Definitely worth having a look at.

© DolfinED All rights reserved www.dolfined.com 8


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 1 - Suggested Study Plan

© DolfinED All rights reserved www.dolfined.com 9


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 10


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 11


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 2 – Introduction to Cloud Computing

© DolfinED All rights reserved www.dolfined.com 12


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 13


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

On-Premises Data Centers vs. Cloud

© DolfinED All rights reserved www.dolfined.com 14


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 15


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 16


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Private, Public & Hybrid Cloud

© DolfinED All rights reserved www.dolfined.com 17


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 18


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 19


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 20


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 21


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Cloud Services

© DolfinED All rights reserved www.dolfined.com 22


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 23


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 24


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 3 – Introduction to AWS Services – Part 1

Section Outline

© DolfinED All rights reserved www.dolfined.com 25


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Global Infrastructure

© DolfinED All rights reserved www.dolfined.com 26


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 27


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 28


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Free Tier

© DolfinED All rights reserved www.dolfined.com 29


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS IAM 101

© DolfinED All rights reserved www.dolfined.com 30


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Identity and Access Management 101

© DolfinED All rights reserved www.dolfined.com 31


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 32


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 33


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 34


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

IAM Identities – Users & IAM Best Practices

© DolfinED All rights reserved www.dolfined.com 35


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 36


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 37


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 38


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Virtual Private Cloud (101)

© DolfinED All rights reserved www.dolfined.com 39


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Virtual Private Cloud (VPC) - Components

© DolfinED All rights reserved www.dolfined.com 40


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 41


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 42


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 43


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 44


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 45


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

VPC Components (cont.)

© DolfinED All rights reserved www.dolfined.com 46


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 47


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 48


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

VPC – Public vs. Private Subnets & Hybrid Connectivity 101

© DolfinED All rights reserved www.dolfined.com 49


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 50


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 51


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 1

© DolfinED All rights reserved www.dolfined.com 52


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – 10+ Requirements – Are You Ready?!

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 53


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirement # 1

Design a solution for a web application that will be hosted in AWS to satisfy the
following requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 54


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Requirement # 1

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 55


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 4 – Introduction to AWS Services – Part 2

© DolfinED All rights reserved www.dolfined.com 56


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 57


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Compute Cloud (EC2) 101

© DolfinED All rights reserved www.dolfined.com 58


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 59


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 60


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 61


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 62


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Using SSH to connect a Linux EC2 instance

© DolfinED All rights reserved www.dolfined.com 63


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 64


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 65


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 66


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Private, Public, and Elastic IP Addresses

© DolfinED All rights reserved www.dolfined.com 67


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 68


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 69


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 70


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Understanding Security Groups

© DolfinED All rights reserved www.dolfined.com 71


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 72


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge

© DolfinED All rights reserved www.dolfined.com 73


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Understanding Network Access Lists (NACLs)

© DolfinED All rights reserved www.dolfined.com 74


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 75


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 76


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 77


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 78


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 79


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 2

© DolfinED All rights reserved www.dolfined.com 80


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements # 2 & 3

Design a solution for a multi-tier web application to meet the following


requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Launch two EBS-backed EC2 instances, one in each of the two AZs above, these
will serve as the web and application tiers. They should be accessible from the
Internet.
3) Design the VPC security to ensure access control at Layer 4 at the subnet and
Compute levels.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 81


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 2

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 82


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 3

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 83


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Encryption 101

© DolfinED All rights reserved www.dolfined.com 84


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 85


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 86


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 87


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 88


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Key Management Service (KMS) 101

© DolfinED All rights reserved www.dolfined.com 89


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 90


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 91


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 92


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 93


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 94


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 95


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Simple Storage Service (S3) 101

© DolfinED All rights reserved www.dolfined.com 96


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 97


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 98


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 99


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 100


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 101


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 102


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

IAM Access Keys for Programmatic Access to AWS

© DolfinED All rights reserved www.dolfined.com 103


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 104


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 105


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS IAM – Elements and Policies

© DolfinED All rights reserved www.dolfined.com 106


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 107


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 108


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 109


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 IAM Roles

© DolfinED All rights reserved www.dolfined.com 110


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 111


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Monolithic vs. Multi-Tier Applications

© DolfinED All rights reserved www.dolfined.com 112


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 113


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Introduction to Messaging and Notification Services in AWS

© DolfinED All rights reserved www.dolfined.com 114


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 115


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 116


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 2

© DolfinED All rights reserved www.dolfined.com 117


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements

Design a solution for a multi-tier web application to meet the following


requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Moreover, the application on EC2 instances will require access to AWS services.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 118


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 4

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 119


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon CloudFront (Content Delivery Network – CDN) 101

© DolfinED All rights reserved www.dolfined.com 120


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 121


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 122


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 123


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Route 53 101

© DolfinED All rights reserved www.dolfined.com 124


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 125


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 126


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 3

© DolfinED All rights reserved www.dolfined.com 127


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements 5 & 6

Design a solution for a multi-tier web application to meet the following


requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 128


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements 5 & 6

Design a solution for a multi-tier web application to meet the following requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a way
of ensuring a good application performance for all users.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 129


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirements # 5 & 6

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 130


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Relational Database Service (RDS) 101

© DolfinED All rights reserved www.dolfined.com 131


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 132


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 133


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 134


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 4

© DolfinED All rights reserved www.dolfined.com 135


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements

Design a solution for a multi-tier web application to meet the following


requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 136


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 –Requirements 7, 8 & 9

Design a solution for a multi-tier web application to meet the following


requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a
way of ensuring good performance for users in remote locations too.
7) Launch an RDS database in the above VPC. Ensure failover to another AZ in case
of a failure of the primary RDS instance. Ensure the database instances are
secured at layer 4.
8) Ensure that the data is encrypted as it is stored.
9) As the traffic increases, the solution must have a component that decouples the
web/app tier from the database tier to avoid overwhelming the database.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 137


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 7

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 138


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 8

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 139


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 9

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 140


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 5 – Key Architecture Pillars

© DolfinED All rights reserved www.dolfined.com 141


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 142


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Monolithic vs. Microservices Applications

© DolfinED All rights reserved www.dolfined.com 143


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 144


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 145


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

High Availability, Fault Tolerance, Scalability & Elastic Load Balancing 101

© DolfinED All rights reserved www.dolfined.com 146


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 147


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 148


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elasticity and Auto Scaling

© DolfinED All rights reserved www.dolfined.com 149


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 150


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 151


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 152


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 1 - 5

© DolfinED All rights reserved www.dolfined.com 153


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 – Requirements

Design a solution for a multi-tier web application to meet the following


requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 154


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 1 –Requirements

Design a solution for a multi-tier web application to meet the following requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a
way of ensuring good performance for users in remote locations too.
7) Launch an RDS database in the above VPC. Ensure failover to another AZ in case of
a failure of the primary RDS instance.
8) As the traffic increases, the solution must have a component that decouples the
web/app tier from the database tier to avoid overwhelming the database.
9) Ensure that the data is encrypted as it is stored.
10) Ensure that the web/app tier is highly available across the two availability zones.
The load should be distributed evenly across the web/app instances.
11) The solution must be connected to the corporate Datacenter with two
connections, primary with low latency and a secure internet-based backup.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 155


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 10

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 156


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 11

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 157


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirement # 11

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 158


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Monitoring and Visibility – Amazon CloudWatch 101

© DolfinED All rights reserved www.dolfined.com 159


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 160


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Auditing in AWS – Amazon CloudTrail

© DolfinED All rights reserved www.dolfined.com 161


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 162


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 163


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 164


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 165


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Disaster Recovery in AWS 101

© DolfinED All rights reserved www.dolfined.com 166


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 167


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 168


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 169


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 170


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 6 – Virtual Private Cloud (VPC) – Deep Dive

© DolfinED All rights reserved www.dolfined.com 171


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 172


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

NAT Instance & NAT Gateway

© DolfinED All rights reserved www.dolfined.com 173


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 174


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 175


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

NAT Gateway

© DolfinED All rights reserved www.dolfined.com 176


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 177


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 178


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 179


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 180


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 181


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Bastion Host, Proxy & Reverse Proxy Servers

© DolfinED All rights reserved www.dolfined.com 182


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 183


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 184


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Bastion Host

© DolfinED All rights reserved www.dolfined.com 185


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 186


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 187


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 2 - 1

© DolfinED All rights reserved www.dolfined.com 188


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 189


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 190


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

VPC Peering

© DolfinED All rights reserved www.dolfined.com 191


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 192


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 193


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 194


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Transit Gateway

© DolfinED All rights reserved www.dolfined.com 195


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 196


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 197


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 198


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 199


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 200


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

VPC Endpoints

© DolfinED All rights reserved www.dolfined.com 201


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 202


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 203


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 204


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 205


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 206


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 207


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 2- 2

© DolfinED All rights reserved www.dolfined.com 208


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 209


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 210


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 211


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS IPv6 Egress-Only Gateway

© DolfinED All rights reserved www.dolfined.com 212


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 213


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

VPC Flow Logs

© DolfinED All rights reserved www.dolfined.com 214


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 215


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 6 -1 – Hybrid Cloud Networking on AWS

© DolfinED All rights reserved www.dolfined.com 216


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 217


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Hybrid Cloud Connectivity

© DolfinED All rights reserved www.dolfined.com 218


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Managed Virtual Private Networks (VPN)

© DolfinED All rights reserved www.dolfined.com 219


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 220


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 221


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 222


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Direct Connect

© DolfinED All rights reserved www.dolfined.com 223


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 224


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 225


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 226


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 227


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 228


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 7 – EC2 and EBS (Deep Dive)

© DolfinED All rights reserved www.dolfined.com 229


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 230


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 231


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Compute Cloud (EC2)

© DolfinED All rights reserved www.dolfined.com 232


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Instance Types & Instance Lifecycle

© DolfinED All rights reserved www.dolfined.com 233


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 234


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 235


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 236


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 237


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Instance Metadata & User Data

© DolfinED All rights reserved www.dolfined.com 238


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 239


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 240


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Purchasing/Launch Options

© DolfinED All rights reserved www.dolfined.com 241


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 242


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 243


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 244


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 245


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 246


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Spot Instances

© DolfinED All rights reserved www.dolfined.com 247


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 248


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 249


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 250


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 251


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 252


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Placement Groups & Data Transfer Costs

© DolfinED All rights reserved www.dolfined.com 253


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 254


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 255


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 256


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 257


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 258


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EC2 Monitoring

© DolfinED All rights reserved www.dolfined.com 259


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 260


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 261


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 262


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 263


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Block Store (EBS)

© DolfinED All rights reserved www.dolfined.com 264


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Block Store (EBS)

© DolfinED All rights reserved www.dolfined.com 265


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 266


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 267


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 268


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 269


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 270


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

EBS Snapshots

© DolfinED All rights reserved www.dolfined.com 271


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 272


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 273


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 274


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 275


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 276


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 277


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 278


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Creating and Sharing/Copying EC2 AMIs

© DolfinED All rights reserved www.dolfined.com 279


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 280


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 281


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 282


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

RAID and EBS Volumes, AWS Batch

© DolfinED All rights reserved www.dolfined.com 283


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 284


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 285


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Batch

© DolfinED All rights reserved www.dolfined.com 286


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 287


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 8 - Elastic Load Balancing and Auto Scaling on AWS

© DolfinED All rights reserved www.dolfined.com 288


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 289


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 290


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Load Balancing

© DolfinED All rights reserved www.dolfined.com 291


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Target Groups, Listeners, and Health Checks

© DolfinED All rights reserved www.dolfined.com 292


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 293


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 294


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 295


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 296


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 297


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 298


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Cross-Zone Load Balancing, Connection Draining & Subnet Design for HA

© DolfinED All rights reserved www.dolfined.com 299


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 300


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 301


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 302


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 303


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

ELB Security Groups

© DolfinED All rights reserved www.dolfined.com 304


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 305


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 306


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 307


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

ELB and SSL Certificates

© DolfinED All rights reserved www.dolfined.com 308


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 309


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 310


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 311


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 312


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 313


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 314


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 315


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 3

© DolfinED All rights reserved www.dolfined.com 316


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 317


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 318


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 319


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

ELB – Client IP Address, Monitoring, Stickiness, and PFS

© DolfinED All rights reserved www.dolfined.com 320


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 321


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 322


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 323


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 324


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Application Load Balancer

© DolfinED All rights reserved www.dolfined.com 325


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 326


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 327


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 328


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Network Load Balancer

© DolfinED All rights reserved www.dolfined.com 329


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 330


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 331


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 332


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

ELB – Gateway Load Balancer (GWLB)

© DolfinED All rights reserved www.dolfined.com 333


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 334


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Auto Scaling

© DolfinED All rights reserved www.dolfined.com 335


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Auto Scaling

© DolfinED All rights reserved www.dolfined.com 336


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 337


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 338


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 339


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 340


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 341


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon AutoScaling – Launch Templates and Scaling Policies

© DolfinED All rights reserved www.dolfined.com 342


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 343


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 344


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 345


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 346


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 347


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 4

© DolfinED All rights reserved www.dolfined.com 348


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 349


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 350


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 351


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 352


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 353


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 354


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 355


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 356


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 9 – Amazon Relational Database Service (RDS)

© DolfinED All rights reserved www.dolfined.com 357


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 358


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 359


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 360


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 361


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 362


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 363


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 364


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 365


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 366


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 367


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 368


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 369


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 370


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 371


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 372


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 373


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 374


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 375


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 5

© DolfinED All rights reserved www.dolfined.com 376


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 377


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 378


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 379


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Aurora

© DolfinED All rights reserved www.dolfined.com 380


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 381


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 382


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 383


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 384


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 385


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 386


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 387


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 388


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 389


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 390


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 391


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Aurora Serverless

© DolfinED All rights reserved www.dolfined.com 392


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 393


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 394


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 6

© DolfinED All rights reserved www.dolfined.com 395


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 396


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 397


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 398


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Redshift

© DolfinED All rights reserved www.dolfined.com 399


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon RedShift - Introduction

© DolfinED All rights reserved www.dolfined.com 400


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 401


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 402


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 403


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 404


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 405


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 406


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 407


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 408


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 10 - NoSQL Databases in AWS

© DolfinED All rights reserved www.dolfined.com 409


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 410


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon DynamoDB

© DolfinED All rights reserved www.dolfined.com 411


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 412


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 413


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 414


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 415


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 416


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 417


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 418


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon DynamoDB – Advanced Features

© DolfinED All rights reserved www.dolfined.com 419


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 420


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 421


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 422


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 423


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 424


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 425


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 426


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 427


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 7

© DolfinED All rights reserved www.dolfined.com 428


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 429


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 430


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

ElastiCache

© DolfinED All rights reserved www.dolfined.com 431


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 432


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 433


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 434


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 435


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 436


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 437


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 438


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 439


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon DocumentDB and Amazon Neptune

© DolfinED All rights reserved www.dolfined.com 440


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 441


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 442


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 11 - Mid Course Assessment

© DolfinED All rights reserved www.dolfined.com 443


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 12 – Identity and Access Management (IAM) - Intermediate

© DolfinED All rights reserved www.dolfined.com 444


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 445


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

IAM Identity-Based Policies

© DolfinED All rights reserved www.dolfined.com 446


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 447


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 448


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 449


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 450


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 451


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 452


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 453


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 454


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 455


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

IAM Security Token Service (STS) & IAM Roles

© DolfinED All rights reserved www.dolfined.com 456


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 457


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 458


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 459


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 460


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 461


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 462


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

IAM Resource-based Policies, Permissions Boundary, and Policy Evaluation Logic

© DolfinED All rights reserved www.dolfined.com 463


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 464


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 465


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 466


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 467


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 468


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 8

© DolfinED All rights reserved www.dolfined.com 469


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 470


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 471


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 13 – Simple Storage Service (S3) – Deep Dive

© DolfinED All rights reserved www.dolfined.com 472


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 473


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 474


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Data Consistency, Tiered Storage Classes, and S3 Lifecycle Policies

© DolfinED All rights reserved www.dolfined.com 475


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 476


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 477


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 478


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 479


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 480


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 481


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Server Side Encryption and Multipart Upload

© DolfinED All rights reserved www.dolfined.com 482


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 483


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 484


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 485


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 486


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Bucket Versioning and Cross-Region Replication

© DolfinED All rights reserved www.dolfined.com 487


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 488


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 489


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 490


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 491


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 492


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 493


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Object Lock and Glacier Vault Lock

© DolfinED All rights reserved www.dolfined.com 494


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 495


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 496


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 497


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Static Website Hosting

© DolfinED All rights reserved www.dolfined.com 498


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 499


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 500


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Pre-Signed URLS, Transfer Acceleration, and Requester Pays

© DolfinED All rights reserved www.dolfined.com 501


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 502


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 503


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 504


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Access Management and Bucket Policies

© DolfinED All rights reserved www.dolfined.com 505


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 506


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 507


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 508


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 509


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 510


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 511


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 512


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 513


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Cross-Origin Resource Sharing, Batch Operations, and Billing

© DolfinED All rights reserved www.dolfined.com 514


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 515


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 516


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 517


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 9

© DolfinED All rights reserved www.dolfined.com 518


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 519


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 520


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 SELECT, Glacier SELECT, S3 Performance, and AWS Transfer Family

© DolfinED All rights reserved www.dolfined.com 521


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 522


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 523


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 524


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 525


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 10

© DolfinED All rights reserved www.dolfined.com 526


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 527


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 528


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 11

© DolfinED All rights reserved www.dolfined.com 529


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 530


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 531


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

S3 Monitoring, Event Notification, Server Access Logging, and S3 vs. DynamoDB

© DolfinED All rights reserved www.dolfined.com 532


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 533


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 534


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 535


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 14 – CloudFront, Route53, and Global Accelerator

© DolfinED All rights reserved www.dolfined.com 536


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 537


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon CloudFront

© DolfinED All rights reserved www.dolfined.com 538


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 539


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 540


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 541


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 542


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 543


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 544


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 545


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

CloudFront – Additional Features

© DolfinED All rights reserved www.dolfined.com 546


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 547


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 548


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 549


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 550


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Route 53

© DolfinED All rights reserved www.dolfined.com 551


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 552


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 553


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 554


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 555


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 556


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 557


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 558


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 559


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Route 53 Routing Policies (cont.) and Route 53 Resolver

© DolfinED All rights reserved www.dolfined.com 560


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 561


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 562


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 563


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 564


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 565


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 566


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 567


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 12

© DolfinED All rights reserved www.dolfined.com 568


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 569


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 570


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 571


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Global Accelerator

© DolfinED All rights reserved www.dolfined.com 572


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 573


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 574


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 575


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 576


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 577


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 578


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 579


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 13

© DolfinED All rights reserved www.dolfined.com 580


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 581


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 582


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 15 – Serverless Computing in AWS

© DolfinED All rights reserved www.dolfined.com 583


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 584


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Lambda

© DolfinED All rights reserved www.dolfined.com 585


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 586


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 587


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 588


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 589


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 590


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 591


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Lambda@Edge

© DolfinED All rights reserved www.dolfined.com 592


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 593


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

API Gateway

© DolfinED All rights reserved www.dolfined.com 594


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 595


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 596


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 597


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 598


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 599


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 600


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 601


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 602


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 603


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 604


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 14

© DolfinED All rights reserved www.dolfined.com 605


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 606


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 607


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 16 – Storage Services in AWS

© DolfinED All rights reserved www.dolfined.com 608


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 609


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic File System (EFS)

© DolfinED All rights reserved www.dolfined.com 610


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 611


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 612


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 613


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 614


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 615


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 616


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon FSx

© DolfinED All rights reserved www.dolfined.com 617


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon FSx for Windows File Server

© DolfinED All rights reserved www.dolfined.com 618


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 619


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 620


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 621


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon FSx for Lustre

© DolfinED All rights reserved www.dolfined.com 622


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 623


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 624


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 625


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 626


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Storage Gateway

© DolfinED All rights reserved www.dolfined.com 627


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 628


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 629


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 630


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Snow Family

© DolfinED All rights reserved www.dolfined.com 631


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 632


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 633


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 634


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 635


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 15

© DolfinED All rights reserved www.dolfined.com 636


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 637


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 638


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Backup and AWS DataSync

© DolfinED All rights reserved www.dolfined.com 639


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 640


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 641


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 642


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 643


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 644


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 16

© DolfinED All rights reserved www.dolfined.com 645


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 646


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 647


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 17 – Containers in AWS

© DolfinED All rights reserved www.dolfined.com 648


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 649


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Elastic Container Service (ECS)

© DolfinED All rights reserved www.dolfined.com 650


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Containers and ECS

© DolfinED All rights reserved www.dolfined.com 651


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 652


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 653


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 654


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 655


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 656


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 657


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 658


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon ECS – Features and Use Cases

© DolfinED All rights reserved www.dolfined.com 659


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 660


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 661


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 662


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 663


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 664


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 665


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 17

© DolfinED All rights reserved www.dolfined.com 666


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 667


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 668


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 669


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Kubernetes Service (EKS)

© DolfinED All rights reserved www.dolfined.com 670


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 671


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 672


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 673


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 18 – Notification, Messaging and Application Integration in AWS

© DolfinED All rights reserved www.dolfined.com 674


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 675


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Simple Queue Service (SQS)

© DolfinED All rights reserved www.dolfined.com 676


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 677


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 678


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 679


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 680


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 681


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 682


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 683


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 684


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Simple Notification Service (SNS)

© DolfinED All rights reserved www.dolfined.com 685


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 686


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 687


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 688


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 689


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 690


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon MQ

© DolfinED All rights reserved www.dolfined.com 691


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 692


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 693


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Step Functions

© DolfinED All rights reserved www.dolfined.com 694


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 695


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 18

© DolfinED All rights reserved www.dolfined.com 696


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 697


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 698


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 19 – Management, Monitoring, and Auditing in AWS

© DolfinED All rights reserved www.dolfined.com 699


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 700


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon CloudWatch

© DolfinED All rights reserved www.dolfined.com 701


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 702


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 703


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 704


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 705


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon CloudWatch Logs

© DolfinED All rights reserved www.dolfined.com 706


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 707


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 708


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 709


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 710


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 711


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon CloudWatch Events

© DolfinED All rights reserved www.dolfined.com 712


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 713


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 714


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 715


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 20 – Governance, Deployment, and Operations in AWS

© DolfinED All rights reserved www.dolfined.com 716


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 717


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Organizations

© DolfinED All rights reserved www.dolfined.com 718


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 719


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 720


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 721


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 722


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 723


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 724


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 725


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 726


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS CloudFormation

© DolfinED All rights reserved www.dolfined.com 727


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 728


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 729


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 730


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 731


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 732


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 733


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 734


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Elastic Beanstalk

© DolfinED All rights reserved www.dolfined.com 735


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 736


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 737


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 738


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 739


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 740


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 741


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS OpsWorks 101

© DolfinED All rights reserved www.dolfined.com 742


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 743


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 744


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 19

© DolfinED All rights reserved www.dolfined.com 745


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 746


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 747


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Systems Manager

© DolfinED All rights reserved www.dolfined.com 748


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 749


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 750


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Parameter Store

© DolfinED All rights reserved www.dolfined.com 751


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 752


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 753


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 754


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Secrets Manager

© DolfinED All rights reserved www.dolfined.com 755


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 756


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 757


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 758


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Config

© DolfinED All rights reserved www.dolfined.com 759


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 760


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 761


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 762


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 763


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 764


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Trusted Advisor

© DolfinED All rights reserved www.dolfined.com 765


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 766


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 20

© DolfinED All rights reserved www.dolfined.com 767


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 768


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 769


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 21 – Security, Identity and Compliance Services in AWS

© DolfinED All rights reserved www.dolfined.com 770


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

© DolfinED All rights reserved www.dolfined.com 771


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS CloudHSM

© DolfinED All rights reserved www.dolfined.com 772


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 773


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 774


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 775


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 776


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Shield

© DolfinED All rights reserved www.dolfined.com 777


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 778


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 779


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 780


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Web Application Firewall

© DolfinED All rights reserved www.dolfined.com 781


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 782


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 783


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 784


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 21

© DolfinED All rights reserved www.dolfined.com 785


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 786


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirements …..

Satisfied Requirements:
All the below plus,
• Cost effective.
• Least Overhead (Can be fully
serverless).

Satisfied Requirements:
• Caters to global user base.
• Protected, resilient to attacks.
• Scalable Highly available.
• Can block certain countries.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 787


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon GuardDuty

© DolfinED All rights reserved www.dolfined.com 788


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 789


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 790


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 791


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Inspector

© DolfinED All rights reserved www.dolfined.com 792


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 793


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 794


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 795


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Cognito

© DolfinED All rights reserved www.dolfined.com 796


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 797


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 22

© DolfinED All rights reserved www.dolfined.com 798


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 799


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 800


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

© DolfinED All rights reserved www.dolfined.com 801


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Cognito

© DolfinED All rights reserved www.dolfined.com 802


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


Amazon Cognito

Amazon Cognito provides authentication, authorization, and user management for


web and mobile applications.

The main two components of Cognito are :


• Cognito User Pools: Provides user directories that provide sign-up and sign-in
options for users.
• Cognito Identity pools: Can be used to grant AWS credentials (STS) to access AWS
services.

They can be used separately or together.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 803


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


Amazon Cognito User Pools

• Sign up and sign in services.


• Customizable web UI to sign in users.
• Social sign in through Facebook, Google,
Amazon and Apple as well as Open ID
Connect (OIDC) and SAML.
• User directory management and user
profiles.
• Multi Factor Authentication (MFA).
• Checks for compromised credentials.
Authenticate
• Account takeover protection. and get tokens
• Phone/email verification.
• User pools grants authenticated users
JSON Web Tokens (JWT).

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 804


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


Amazon Cognito Identity Pools (Federated Identities)

Cognito identity pools can be used to


generate temporary STS credentials to Authenticate
and get tokens
access AWS services in exchange for a
token from an identity provider or Cognito Exchange
Tokens for AWS
user pools. STS Credentials

Access
AWS Services

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 805


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


Web Identity Federation - Amazon Cognito Identity Pools (Federated Identities)

• We can use Cognito identity


pools to provide federated users
access to AWS services.
• A trust is established between
Exchange Tokens
AWS and these Identity Provides for AWS STS
Credentials
(IdPs) such as Facebook, Amazon,
Apple, Google or SAML 2.0 IdP.
• The token received from
authentication is then exchanged
Access
through identity pools with STS AWS Services
temporary credentials.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 806


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Directory Services

AWS Directory Services


© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 807


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


AWS Directory Service

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 808


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Single Sign-On (SSO)

© DolfinED All rights reserved www.dolfined.com 809


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


AWS Single Sign-On (SSO)

• We can use AWS SSO to AWS


centrally manage SSO
access to all AWS
accounts and cloud
Permissions
applications.
• Users do not have to
maintain multiple
credentials. SSO
• It provides user portals. Access

• It integrates with AWS


Organizations and many
business applications

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 810


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


AWS Single Sign-On (SSO) – User/Group Directory

AWS

The Identities Database


(users, groups, roles) can
be located on:
• AWS SSO itself.
• AWS Managed MS AD
(AWS directory service).
• On-premises MS AD
connected through AWS
AD Connector.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 811


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 23

ADV

What did we learn?!

Knowledge In Action…

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 812


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 23 – Project Details

Design a security solution for a two-tier web application deployed to AWS across
two Availability Zones. The web application consists of an auto-scaled fleet of EC2
instances, in public subnets, behind an Application Load Balancer (ALB). A
CloudFront Distribution is used to serve the content with the ALB as the origin. The
solution must incorporate automated detection and remediation of threats against
the application generated from Internet sources. This solution's goal is to improve
the application’s security posture and minimize the impact of Internet-sourced
attacks, including DDoS attacks. Notification should be sent out via email to the
administrators. The solution must be efficient and very cost-effective in achieving
the required with the least ongoing overhead. Minor changes to the current
architecture are acceptable.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 813


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirements …..


Blocked CloudFront
DynamoDB
Host Table
Event
Rule

Security group

CloudWatch
Events
WAF Filtering
Rule

SNS Network
Amazon
Topic ACL(s)
GuardDuty

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 814


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 22 – Analytics Services in AWS

© DolfinED All rights reserved www.dolfined.com 815


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

Section Outline

In this section, we will learn:


• Amazon RedShift Spectrum
• Elastic Map Reduce (EMR)
• Amazon Athena
• Amazon Glue
• Amazon Kinesis
• Amazon QuickSight
• AWS Data Pipeline

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 816


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Redshift Spectrum

© DolfinED All rights reserved www.dolfined.com 817


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon RedShift Spectrum

• Amazon Redshift spectrum facilitates running


SQL queries against exabytes of data in S3.
• It is a serverless service with nothing to
provision/manage.
• SQL or BI tools will query the In-VPC Redshift
cluster with pointers to external data in S3.
• Redshift Spectrum nodes outside the VPC will
process the request, query data in S3, and return
results to in-VPC clusters for final processing.
• It encrypts data in transit and at rest using SSE.
• Charge is per the number of bytes scanned.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 818


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic MAP Reduce

© DolfinED All rights reserved www.dolfined.com 819


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Hadoop and Amazon EMR - Background

• Hadoop is an open-source software framework for reliable, scalable, and distributed


computing.
• It supports data-intensive distributed processing of large data sets running on large
clusters of compute nodes (EC2 instances in AWS).
• Hadoop runs a processing/programming model called “Map Reduce”, which can process
large data sets quickly.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 820


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Elastic Map Reduce (EMR)

EMR is a managed cluster service used to run big


data frameworks such as Apache Hadoop clusters in
AWS to easily and cost-effectively process vast
amounts of data.
• EMR is ideal for use cases that require fast and
efficient processing of large amounts of data.
• Use cases include web indexing, data mining, log
file analysis, machine learning, financial analysis,
scientific simulation, and bioinformatics research.

EMR can also transfer large data in and out of AWS


data stores such as S3 and DynamoDB. EMR Cluster
• Customers have root access to the EMR Cluster
EC2 instances.
© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 821


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Elastic Map Reduce (EMR) - Features

• EMR is NOT about real-time data ingestion.


• EMR clusters are launched in a single AWS AZ.
• EMR clusters can use RIs, On-demand, or Sport
instances and support auto-scaling.
• EMR integrates with EC2, VPC, S3, CloudWatch,
and Data Pipeline.
• Supports encryption in-transit and SSE in S3.

EMR Cluster

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 822


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Operating on data in S3 - Amazon EMR vs Amazon Redshift Spectrum

EMR with Apache Hive Redshift Spectrum


Compute Cluster-Server based Serverless
Use case SQL based queries - Great SQL based queries - Great
for scale-out processing fit as it can scale out to
like scans, filters, and thousands of nodes to pull
aggregates. data, filter, project,
aggregate, group, and sort.
Ingest the entire data from Not required. Not required.
S3 into the service to
process it?
Complex querying and It gets very slow as the Very efficient.
joins use cases? (very data size and number of
critical for analytics). nodes increases.
Billing Pay for the compute. Pay for the data scanned.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 823


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Athena

© DolfinED All rights reserved www.dolfined.com 824


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Athena

• Athena is a serverless, interactive, query service


that can be used to query and analyze data stored
in S3 using standard SQL.
• Athena uses schema-on-read technology.
• It integrated with Amazon QuickSight for data
visualization.
• Can query unstructured, semi-structured, and
structured data in CSV, JSON, Apache (Parquet,
Avro, and ORC).
• It can query logs in S3 from different AWS services.
Standard SQL Schema
Queries /Table

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 825


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Athena

• It scales automatically.
• Query results are stored in S3 in .csv format.
• Can query encrypted data in S3 and can
encrypt query results.

Standard SQL Schema


Queries /Table

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 826


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Athena vs. Redshift Spectrum - When To Use What?

Athena RedShift Spectrum


Compute (Serverless?) A completely serverless service. Redshift spectrum itself is serverless.
One or more RedShift clusters are required
(higher cost).

Complex Joins, Queries and Not meant for this use case. Ideal for this use case.
Aggregations.

Ad-hoc SQL queries. Ideal for this case. Not meant for this case.

Can query data in S3 without Yes Yes


loading it.
Large data lake users that want Not meant for this use case. Perfect fit for this use case.
to run concurrent BI and
reporting workloads.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 827


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Glue

© DolfinED All rights reserved www.dolfined.com 828


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Glue

Data catalog

AWS Glue is a fully managed, serverless, pay-as- Store the


Crawlers Amazon
you-go, extract, transform, and load (ETL) service. metadata
in the glue
Redshift

• AWS Glue protects data in-transit and at rest. data catalog


Amazon
• It makes it simple to scan, clean, enrich data, AWS
Glue ETL
Athena

infer the schema, and move data between S3 Bucket Glue Loads Amazon
data stores in AWS. transformed
data To Targets
EMR

• AWS Glue runs on Apache Spark which is a Amazon


Redshift
data analytics engine built on Hadoop. Spectrum

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 829


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics
Amazon Glue – Use Cases

Amazon
Redshift

• Run serverless queries against an S3 data Trigger one


(or more)
Lambda
lake. Object Function AWS Glue
ETL Jobs
• Build a data warehouse from different, Glue Loads
transformed
disparate, data sources. S3 Bucket AWS Glue data To Targets

• Create event-driven ETL pipelines with AWS Register the


ETL

Glue and Lambda. metadata in the


glue data catalog
• Understand stored data assets.
Data catalog

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 830


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Glue vs. EMR

Glue EMR
Is a fully managed, pay as you go, ETL Is a managed big data platform known for its
tool for big data. It can transform the speed and ease of data conversions. It also
data and make it ready for analytics supports ETL jobs.
purposes.
Platform Serverless. Server-based.
Based on Hadoop Framework. Based on Hadoop framework.
Runs on top of Hadoop Spark. Supports many of the Hadoop services
including Spark, Hive, and Pig among others.
Cost More expensive. Less expensive.

ETL Operations – Higher. Lower compared to Glue.


Performance and flexibility

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 831


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 23

© DolfinED All rights reserved www.dolfined.com 832


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 24 – Project Details

Design a solution for a company to store large-scale datasets from business


applications, social media, internet-connected sensors, and other devices. The data
will include structured and unstructured components. It is required to be able to run
infrequent SQL queries on the stored data for analytics purposes. The solution must
minimize infrastructure costs and will require the least ongoing overhead.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 833


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirements …..

Crawler

Mobile
client AWS Glue

Athena
Users
Internet
AWS glue data
catalog

Client

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 834


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Kinesis

© DolfinED All rights reserved www.dolfined.com 835


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Kinesis Data Streams

© DolfinED All rights reserved www.dolfined.com 836


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Data Streaming and Amazon Kinesis - Background

• Streaming data is data


generated and sent in small
sizes (KBs or MBs) from a
large number of sources
continuously.
• Kinesis is a managed real-
time streaming data service
in AWS, which is used for IoT
and Big Data analytics.
• Kinesis can continuously
capture and store terabytes
of data per hour from a large
number of sources.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 837


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Data Streams

• Use Kinesis data streams to ingest


large data volumes in real time and
make the data available, in
milliseconds, for consumption by one
or more Kinesis applications in
parallel.
• These applications use Kinesis Client
Library (KCL) and can run on Amazon
EC2 instances.
• The processed data records can be
used in different applications
(dashboards, generate alerts, etc.)
• Data is stored in a stream for 24
hours by default, and up to 7 days.
© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 838


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Kinesis Data Streams – Availability, Durability, Use Cases & Encryption

Kinesis Data Streams synchronously


replicates data across three AZs for high
availability and data durability.

Use cases include:


• Accelerating log and data feed intakes.
• Real time metric and reporting analytics.
• Complex stream processing.

Kinesis data streams can encrypt data into


the stream using SSE and KMS keys.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 839


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Writing to a Kinesis Data Streams (KDSs)

We can write to a Kinesis Data Stream using:


• Amazon Kinesis Producer Library (KPL).
• Amazon KDS APIs using SDKs.
• Kinesis Agent.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 840


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Data Streams – Records, Shards, and Partition Keys
Partition
Key 1
A Kinesis stream is a set of
shards. Partition
Key 2
Producers put records in a
Kinesis stream. Partition
Key 3

Each record has a partition key


specified by the producer, and Partition
Key N
a sequence number specified
by Kinesis.

Kinesis uses the partition key


of the record to generate a A shard can take up to
The sequence number of a
MD5 hash to decide which record is unique per partition 1MB/sec input (writes by
shard to store the data record key within its shard (ordering producers) and up to 2MB/sec
into. output (reads by consumers).
within a shard).

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 841


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Data Streams – Resharding & Consumer Read Throughput

• Kinesis data streams support re-


sharding a stream. Merging
• A shard can be split into two shards.
• We can merge two shards into one. Splitting

• As the number of shards increases,


stream throughput increases, and cost
increases too.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 842


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Data Stream vs. SQS - when to use what?

Kinesis Data Streams SQS


Intended use Real-time ingestion and processing of streaming Reliable, highly scalable hosted queue for
big data. storing messages as they travel between
computers.
Ordering Ordering of records, and ability to read/replay SQS FIFO queues can guarantee message
records in the same order by several Kinesis ordering.
applications.
Use when your • Routing related records to the same record • Messaging semantics (ack/fail) and
requirements are processor (consumer). visibility timeout are required.
any of the following: • When we need ordering of records (Important • You need the queue to scale transparently
in case we need to keep the order of logs without pre-provisioning shards.
messages the same at the consumer as they
arrived from the producers).
• When we need multiple applications to
consume the records concurrently.
• The ability to consume the same records few
hours or couple of days later.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 843


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Kinesis Data Firehose & Kinesis Data Analytics

© DolfinED All rights reserved www.dolfined.com 844


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Data Firehose

Kinesis Data Firehose is a fully managed


service used to automatically capture
real-time streaming data from producers
and deliver it to destinations such as S3,
Redshift, Elasticsearch, and Splunk.
• Use cases include IoT analytics, Log
analytics, Clickstream analytics, and
Security monitoring.
• Kinesis Stream can be a data source.
• It can use a Lambda function to
transform data before delivering it.
• It scales based on demand (no shards)
• Data is buffered for up to 24 hours.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 845


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics Services


Amazon Kinesis Analytics

Amazon Kinesis data analytics is


used to process and analyze real-
time streaming data from Kinesis
Data Streams or Kinesis Data
Firehose using standard SQL code.
• It requires Kinesis Data Analytics
applications to continuously
read and process streaming
data.
• Use case: Produce time series
analytics, feed real-time
dashboards, and create real-
time metrics.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 846


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon QuickSight

© DolfinED All rights reserved www.dolfined.com 847


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics
Amazon QuickSight

1. Data Sources

QuickSight is a business analytics tool.


2. Data Sets
• It can be used to build visualizations, perform ad-hoc
analysis, and provide business insights.
• It can scale to hundreds of thousands of users.
• It starts at data sources, then creates data sets, then 3. Analyses

creates analyses and visuals, which can be shared


through dashboards.
4. Visuals

5. Dashboards

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 848


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Data Pipeline

Data Pipeline

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 849


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics
AWS Data Pipeline

EC2 EMR
• AWS Data Pipeline is a fully managed, scalable, web
service which can be used to automate data
movement and transformation.
• It can be used with many AWS data stores as data ETL/Copy/SQL
sources or destinations.

Use cases:
• Moving data into cloud.
• ETL data from S3, RDS, or DynamoDB into Redshift.
• ETL unstructured data (Ex. Clickstreams, Logs).
• Data Loads and Extracts.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 850


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Knowledge In Action – Project 25

What did we learn?!

Knowledge In Action…

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 851


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Project 25 – Project Details

Design a solution for a company that will collect clickstream data from multiple
online shopping websites in near-real time. The solution must make this data
available for analytics to gain insights in a timely manner. The solution must be cost-
effective and requires the least ongoing overhead.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 852


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

The Solution – Satisfying Project Requirements …..

Users Internet Websites Amazon Kinesis


Amazon Kinesis
Data Firehose Data Analytics

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 853


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section 23 - Additional Services

Additional Services

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 854


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Section Outline

Section Outline

In this section, we will learn:


• Elasticsearch.
• Elastic Transcoder.
• AppSync.
• X-Ray.
• Database Migration Service (DMS).
• Resource Access Manager (RAM).
• Cost Explorer.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 855


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Elasticsearch

© DolfinED All rights reserved www.dolfined.com 856


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics
Elasticsearch - Background

• Elasticsearch is a popular open-source, near real-time, scalable search and analytics


engine.
• Elastic Stack (formerly ELK Stack) includes Elasticsearch with Kibana for visualization, and
Logstash for data collection and log ingestion.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 857


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Analytics
Amazon Elasticsearch (ES)

• Amazon Elasticsearch (ES) is a fully


managed service to deploy, secure,
scale, and operate Elasticsearch cost-
effectively in AWS.
• It supports a built-in alerting and SQL
querying for integration with BI tools.
• Amazon ES integrates with Kibana,
Logstash, Kinesis, S3, DynamoDB, IoT
and Lambda.
• IAM and resource-based policies, and
Cognito for Kibana user
authentication.
• Supports VPC Endpoints
• Pay as you go, no upfront costs.
© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 858


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Elastic Transcoder

Elastic Transcoder

© DolfinED All right reserved

© DolfinED All rights reserved www.dolfined.com 859


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Media, Mobile, End User, and IoT Services


Amazon Elastic Transcoder

Elastic Transcoder manages the complexity of


running media transcoding jobs at a scale in AWS.
• It is used to convert video and audio (media)
files stored in S3 into supported output formats
for playback on user devices.
• It supports wide range of output formats,
resolutions, bitrates, and frame rates.
• Is a pay for what you use service (has a free tier).

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 860


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon AppSync

Amazon AppSync

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 861


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Media, Mobile, End User, and IoT Services


Amazon AppSync

• Is an enterprise-level, fully managed GraphQL service for data synchronization between


web and mobile apps and servers.
• It exposes GraphQL APIs to clients.
• GraphQL is a data language to enable clients to fetch (Query), Change, or Subscribe to
data from servers.
• It has real-time data synchronization and offline programming features.
• We can control authorization to GraphQL APIs

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 862


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon WorkSpaces

Amazon WorkSpaces

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 863


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon Media, Mobile, End User, and IoT Services


Amazon WorkSpaces

• A VDI is a way to provide clients access to


virtual desktops.
• WorkSpaces is Amazon’s VDI solution.
• Provides a persistent user experience.
• Pay per use, hourly or monthly billing.
• WorkSpaces Application Manager (WAM)
• Same tools to manage desktops.
• MFA can be used for additional security.
• Encryption at rest (disks) using KMS keys
and TLS in-transit.
• Integrates with Amazon Directory Services
(Simple AD, AD Connector, or MS Managed
AD).
• Can whitelist corporate network IP range.
© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 864


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon WorkDocs

Amazon WorkDocs

• It is a fully managed, secure enterprise storage and collaboration service.


• Can integrate with existing corporate directories.
• Users can preview and comment on different supported file types.
• Deleted folders and files can be recovered for up to 30 days after deletion.
• Each user account comes with 1TB storage; administrators can add or limit storage
per user.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 865


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Amazon X-Ray

AWS X-Ray

© DolfinED All right reserved

© DolfinED All rights reserved www.dolfined.com 866


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Migration and Data Transfer Services in AWS


AWS X-Ray

Service Graph
• X-Ray provides tools to view, filter, and
gain insights into the application flows.
• Using X-Ray, customers can understand
how an application and its underlying
services are performing.
• Using X-Ray and the insights, we can
analyze and troubleshoot performance
problems.
• X-Ray generates a detailed service
graph from the collected data.

https://docs.aws.amazon.com/xray/latest/devguide/aws-xray.html

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 867


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Migration and Data Transfer Services in AWS


AWS X-Ray – Benefits and other features

Benefits:
• Create a service map.
• Identify errors and bugs.
• Build custom analysis and visualization
apps.

• X-Ray always encrypts traces and related


data at rest using KMS keys.
• X-Ray integrates with EC2, ECS, Lambda,
Elastic BeanStalk, API Gateway, and ELB
services (requires an X-Ray daemon).
• AWS Config can be used to track changes
in X-Ray’s encryption configuration.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 868


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Database Migration Service (DMS)

AWS Database Migration


Service (DMS)
© DolfinED All right reserved

© DolfinED All rights reserved www.dolfined.com 869


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Migration and Data Transfer Services in AWS


AWS Database Migration Service (DMS)

• DMS is a web service, which can be used to


migrate data from a source database to a
target database.
• It can be used to migrate data from On-
Premises to AWS or the other way around.
• Homogenous migration : The source and
target databases are of the same DB Engine
(e.g., Oracle to Oracle or MySQL to MySQL)
• Heterogeneous migration : The source and
target are of different engines (e.g., Oracle to
Aurora or RDS to DynamoDB).
• It can be used to do one-time migration or
ongoing replication.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 870


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Migration and Data Transfer Services in AWS


AWS Database Migration Service (DMS)

• Migration is done using a Replication


instance, which can be configured in a
multi-AZ configuration.
• Using DMS we can achieve, faster
Migrations, changing DB engines, and
pay for what we use.
• DMS supports SSL encryption in-
transit and at rest using KMS keys to
encrypt instance storage and endpoint
connection information.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 871


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Migration and Data Transfer Services in AWS


Heterogeneous Migrations and Schema Conversion Tool (SCT)

Heterogeneous migrations happen in two


steps:
• Use Schema Conversion Tool (SCT) to
generate the target schema.
• Use DMS to migrate the data.

AWS Schema Conversion Tool (AWS SCT) can


be used to convert existing database schema
from one database engine to another.
• It can be used to convert relational OLTP
schema, or OLAP data warehouse schema.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 872


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Resource Access Manager (RAM)

© DolfinED All rights reserved www.dolfined.com 873


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


AWS Resource Access Manager (RAM)

• AWS RAM allows customers to share


resources with any AWS account, and if
an account is part of AWS Organizations,
then RAM can also share resources with
Organizational Units (OUs) or the entire
organization.
• Using AWS RAM is free of charge.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 874


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

Security, Identity, and Access Management


AWS Resource Access Manager (RAM) - Benefits

• Provide security & consistency; visibility &


auditability; and reduce operational
overhead.
• IAM policies and SCPs in the account
resources apply to the shared resources.
• We can use RAM to share VPC resources,
Transit Gateway, Route 53 Rules, EC2,
Aurora, App Mesh, CodeBuild, AWS Glue,
AWS ACM Private CA, AWS Resource
Groups, & License Manager configurations.

https://docs.aws.amazon.com/ram/latest/userguide/shareable.html#shareable-vpc

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 875


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Cost Explorer

Cost Explorer

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 876


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

AWS Cost Explorer

• Is an AWS service that allow


customers to visualize,
understand, and manage their
AWS costs and usage over
time, both at a high level and
at a detailed analysis level.
• Provides default reports and
allows customers to build
their own custom reports.
• Cost & Usage report provide
detailed information about
AWS costs and usage.

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 877


AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook

End of Course

© DolfinED All rights reserved

© DolfinED All rights reserved www.dolfined.com 878

You might also like