AWS CERTIFIED SOLUTIONS ARCHITECT ASSOCIATE
Student e-Notebook Version 1.0
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Table of Contents
Section 1 - Suggested Study Plan .......................................................................................................................... 9
Section 2 – Introduction to Cloud Computing ..................................................................................................... 12
Section Outline ....................................................................................................................................................... 13
On-Premises Data Centers vs. Cloud ...................................................................................................................... 14
Private, Public & Hybrid Cloud................................................................................................................................ 17
Cloud Services......................................................................................................................................................... 22
Section 3 – Introduction to AWS Services – Part 1............................................................................................... 25
Section Outline ....................................................................................................................................................... 25
AWS Global Infrastructure ..................................................................................................................................... 26
AWS Free Tier ......................................................................................................................................................... 29
AWS IAM 101 ......................................................................................................................................................... 30
Identity and Access Management 101 ................................................................................................................... 31
IAM Identities – Users & IAM Best Practices .......................................................................................................... 35
AWS Virtual Private Cloud (101)............................................................................................................................. 39
AWS Virtual Private Cloud (VPC) - Components ..................................................................................................... 40
VPC Components (cont.) ......................................................................................................................................... 46
VPC – Public vs. Private Subnets & Hybrid Connectivity 101 .................................................................................. 49
Knowledge In Action – Project 1 - 1........................................................................................................................ 52
Section 4 – Introduction to AWS Services – Part 2............................................................................................... 56
Section Outline ....................................................................................................................................................... 57
Elastic Compute Cloud (EC2) 101 ........................................................................................................................... 58
Using SSH to connect a Linux EC2 instance ............................................................................................................ 63
Private, Public, and Elastic IP Addresses ................................................................................................................ 67
Understanding Security Groups.............................................................................................................................. 71
Understanding Network Access Lists (NACLs) ........................................................................................................ 74
Encryption 101 ....................................................................................................................................................... 84
AWS Key Management Service (KMS) 101 ............................................................................................................. 89
Simple Storage Service (S3) 101 ............................................................................................................................. 96
IAM Access Keys for Programmatic Access to AWS ............................................................................................. 103
AWS IAM – Elements and Policies ........................................................................................................................ 106
© DolfinED All rights reserved www.dolfined.com 1
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 IAM Roles ...................................................................................................................................................... 110
Monolithic vs. Multi-Tier Applications.................................................................................................................. 112
Introduction to Messaging and Notification Services in AWS .............................................................................. 114
Knowledge In Action – Project 1 - 2...................................................................................................................... 117
Amazon CloudFront (Content Delivery Network – CDN) 101 ............................................................................... 120
Amazon Route 53 101 .......................................................................................................................................... 124
Knowledge In Action – Project 1 - 3...................................................................................................................... 127
Amazon Relational Database Service (RDS) 101 .................................................................................................. 131
Knowledge In Action – Project 1 - 4...................................................................................................................... 135
Section 5 – Key Architecture Pillars................................................................................................................... 141
Section Outline ..................................................................................................................................................... 142
Monolithic vs. Microservices Applications............................................................................................................ 143
High Availability, Fault Tolerance, Scalability & Elastic Load Balancing 101 ....................................................... 146
Elasticity and Auto Scaling ................................................................................................................................... 149
Knowledge In Action – Project 1 - 5...................................................................................................................... 153
Monitoring and Visibility – Amazon CloudWatch 101.......................................................................................... 159
Auditing in AWS – Amazon CloudTrail ................................................................................................................. 161
Disaster Recovery in AWS 101 .............................................................................................................................. 166
Section 6 – Virtual Private Cloud (VPC) – Deep Dive .......................................................................................... 171
NAT Instance & NAT Gateway.............................................................................................................................. 173
NAT Gateway ....................................................................................................................................................... 176
Bastion Host, Proxy & Reverse Proxy Servers ....................................................................................................... 182
Bastion Host ......................................................................................................................................................... 185
Knowledge In Action – Project 2 - 1...................................................................................................................... 188
VPC Peering .......................................................................................................................................................... 191
AWS Transit Gateway .......................................................................................................................................... 195
VPC Endpoints ...................................................................................................................................................... 201
Knowledge In Action – Project 2- 2....................................................................................................................... 208
AWS IPv6 Egress-Only Gateway ........................................................................................................................... 212
VPC Flow Logs ...................................................................................................................................................... 214
Hybrid Cloud Connectivity .................................................................................................................................... 218
AWS Managed Virtual Private Networks (VPN) ................................................................................................... 219
Direct Connect ...................................................................................................................................................... 223
Section 7 – EC2 and EBS (Deep Dive) ................................................................................................................. 229
© DolfinED All rights reserved www.dolfined.com 2
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline ..................................................................................................................................................... 230
Elastic Compute Cloud (EC2) ................................................................................................................................ 232
EC2 Instance Types & Instance Lifecycle .............................................................................................................. 233
EC2 Instance Metadata & User Data ................................................................................................................... 238
EC2 Purchasing/Launch Options .......................................................................................................................... 241
EC2 Spot Instances ............................................................................................................................................... 247
EC2 Placement Groups & Data Transfer Costs ..................................................................................................... 253
EC2 Monitoring .................................................................................................................................................... 259
Elastic Block Store (EBS) ....................................................................................................................................... 264
Elastic Block Store (EBS) ....................................................................................................................................... 265
EBS Snapshots ...................................................................................................................................................... 271
Creating and Sharing/Copying EC2 AMIs ............................................................................................................. 279
RAID and EBS Volumes, AWS Batch ..................................................................................................................... 283
AWS Batch ............................................................................................................................................................ 286
Section 8 - Elastic Load Balancing and Auto Scaling on AWS ............................................................................. 288
Section Outline ..................................................................................................................................................... 289
Elastic Load Balancing .......................................................................................................................................... 291
Target Groups, Listeners, and Health Checks ....................................................................................................... 292
Cross-Zone Load Balancing, Connection Draining & Subnet Design for HA ......................................................... 299
ELB Security Groups.............................................................................................................................................. 304
ELB and SSL Certificates ....................................................................................................................................... 308
Knowledge In Action – Project 3 ........................................................................................................................... 316
ELB – Client IP Address, Monitoring, Stickiness, and PFS ..................................................................................... 320
Application Load Balancer.................................................................................................................................... 325
Network Load Balancer ........................................................................................................................................ 329
ELB – Gateway Load Balancer (GWLB) ................................................................................................................. 333
Amazon Auto Scaling ........................................................................................................................................... 335
Auto Scaling ......................................................................................................................................................... 336
Amazon AutoScaling – Launch Templates and Scaling Policies ........................................................................... 342
Knowledge In Action – Project 4 ........................................................................................................................... 348
Section 9 – Amazon Relational Database Service (RDS) ..................................................................................... 357
Knowledge In Action – Project 5 ........................................................................................................................... 376
Amazon Aurora .................................................................................................................................................... 380
Amazon Aurora Serverless ................................................................................................................................... 392
Knowledge In Action – Project 6 ........................................................................................................................... 395
© DolfinED All rights reserved www.dolfined.com 3
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Redshift .................................................................................................................................................. 399
Amazon RedShift - Introduction ........................................................................................................................... 400
Section 10 - NoSQL Databases in AWS .............................................................................................................. 409
Section Outline ..................................................................................................................................................... 410
Amazon DynamoDB ............................................................................................................................................. 411
Amazon DynamoDB – Advanced Features ........................................................................................................... 419
Knowledge In Action – Project 7 ........................................................................................................................... 428
ElastiCache ........................................................................................................................................................... 431
Amazon DocumentDB and Amazon Neptune....................................................................................................... 440
Section 11 - Mid Course Assessment................................................................................................................. 443
Section 12 – Identity and Access Management (IAM) - Intermediate ................................................................ 444
IAM Identity-Based Policies .................................................................................................................................. 446
IAM Security Token Service (STS) & IAM Roles ..................................................................................................... 456
IAM Resource-based Policies, Permissions Boundary, and Policy Evaluation Logic ............................................. 463
Knowledge In Action – Project 8 ........................................................................................................................... 469
Section 13 – Simple Storage Service (S3) – Deep Dive ....................................................................................... 472
Section Outline ..................................................................................................................................................... 473
S3 Data Consistency, Tiered Storage Classes, and S3 Lifecycle Policies................................................................ 475
S3 Server Side Encryption and Multipart Upload ................................................................................................. 482
S3 Bucket Versioning and Cross-Region Replication ............................................................................................ 487
S3 Object Lock and Glacier Vault Lock.................................................................................................................. 494
S3 Static Website Hosting .................................................................................................................................... 498
S3 Pre-Signed URLS, Transfer Acceleration, and Requester Pays ......................................................................... 501
S3 Access Management and Bucket Policies ........................................................................................................ 505
S3 Cross-Origin Resource Sharing, Batch Operations, and Billing ........................................................................ 514
Knowledge In Action – Project 9 ........................................................................................................................... 518
S3 SELECT, Glacier SELECT, S3 Performance, and AWS Transfer Family............................................................... 521
Knowledge In Action – Project 10......................................................................................................................... 526
Knowledge In Action – Project 11......................................................................................................................... 529
S3 Monitoring, Event Notification, Server Access Logging, and S3 vs. DynamoDB .............................................. 532
Section 14 – CloudFront, Route53, and Global Accelerator ............................................................................... 536
Section Outline ..................................................................................................................................................... 537
Amazon CloudFront .............................................................................................................................................. 538
CloudFront – Additional Features......................................................................................................................... 546
© DolfinED All rights reserved www.dolfined.com 4
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Route 53 ................................................................................................................................................. 551
Route 53 Routing Policies (cont.) and Route 53 Resolver ..................................................................................... 560
Knowledge In Action – Project 12......................................................................................................................... 568
Global Accelerator ................................................................................................................................................ 572
Knowledge In Action – Project 13......................................................................................................................... 580
Section 15 – Serverless Computing in AWS ....................................................................................................... 583
Section Outline ..................................................................................................................................................... 584
AWS Lambda ........................................................................................................................................................ 585
Lambda@Edge ..................................................................................................................................................... 592
API Gateway ......................................................................................................................................................... 594
Knowledge In Action – Project 14......................................................................................................................... 605
Section 16 – Storage Services in AWS ............................................................................................................... 608
Section Outline ..................................................................................................................................................... 609
Elastic File System (EFS) ....................................................................................................................................... 610
Amazon FSx .......................................................................................................................................................... 617
Amazon FSx for Windows File Server ................................................................................................................... 618
Amazon FSx for Lustre .......................................................................................................................................... 622
Amazon Storage Gateway.................................................................................................................................... 627
Amazon Snow Family ........................................................................................................................................... 631
Knowledge In Action – Project 15......................................................................................................................... 636
AWS Backup and AWS DataSync .......................................................................................................................... 639
Knowledge In Action – Project 16......................................................................................................................... 645
Section 17 – Containers in AWS ........................................................................................................................ 648
Section Outline ..................................................................................................................................................... 649
Amazon Elastic Container Service (ECS) ............................................................................................................... 650
Containers and ECS .............................................................................................................................................. 651
Amazon ECS – Features and Use Cases ................................................................................................................ 659
Knowledge In Action – Project 17......................................................................................................................... 666
Elastic Kubernetes Service (EKS) ........................................................................................................................... 670
Section 18 – Notification, Messaging and Application Integration in AWS ........................................................ 674
Section Outline ..................................................................................................................................................... 675
Simple Queue Service (SQS) .................................................................................................................................. 676
Amazon Simple Notification Service (SNS) ........................................................................................................... 685
Amazon MQ ......................................................................................................................................................... 691
© DolfinED All rights reserved www.dolfined.com 5
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Step Functions ...................................................................................................................................................... 694
Knowledge In Action – Project 18......................................................................................................................... 696
Section 19 – Management, Monitoring, and Auditing in AWS ........................................................................... 699
Section Outline ..................................................................................................................................................... 700
Amazon CloudWatch ............................................................................................................................................ 701
Amazon CloudWatch Logs.................................................................................................................................... 706
Amazon CloudWatch Events ................................................................................................................................ 712
Section 20 – Governance, Deployment, and Operations in AWS ....................................................................... 716
Section Outline ..................................................................................................................................................... 717
AWS Organizations .............................................................................................................................................. 718
AWS CloudFormation ........................................................................................................................................... 727
AWS Elastic Beanstalk .......................................................................................................................................... 735
AWS OpsWorks 101.............................................................................................................................................. 742
Knowledge In Action – Project 19......................................................................................................................... 745
AWS Systems Manager ........................................................................................................................................ 748
Parameter Store ................................................................................................................................................... 751
AWS Secrets Manager .......................................................................................................................................... 755
AWS Config........................................................................................................................................................... 759
AWS Trusted Advisor ............................................................................................................................................ 765
Knowledge In Action – Project 20......................................................................................................................... 767
Section 21 – Security, Identity and Compliance Services in AWS ....................................................................... 770
Section Outline ..................................................................................................................................................... 771
AWS CloudHSM .................................................................................................................................................... 772
Amazon Shield ...................................................................................................................................................... 777
Web Application Firewall ..................................................................................................................................... 781
Knowledge In Action – Project 21......................................................................................................................... 785
Amazon GuardDuty .............................................................................................................................................. 788
Amazon Inspector ................................................................................................................................................ 792
Amazon Cognito ................................................................................................................................................... 796
Knowledge In Action – Project 22......................................................................................................................... 798
Amazon Cognito ................................................................................................................................................... 802
AWS Directory Services ........................................................................................................................................ 807
AWS Single Sign-On (SSO) .................................................................................................................................... 809
Knowledge In Action – Project 23......................................................................................................................... 812
© DolfinED All rights reserved www.dolfined.com 6
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 22 – Analytics Services in AWS ............................................................................................................. 815
Section Outline ..................................................................................................................................................... 816
Amazon Redshift Spectrum .................................................................................................................................. 817
Elastic MAP Reduce .............................................................................................................................................. 819
Amazon Athena .................................................................................................................................................... 824
Amazon Glue ........................................................................................................................................................ 828
Knowledge In Action – Project 23......................................................................................................................... 832
Amazon Kinesis .................................................................................................................................................... 835
Kinesis Data Streams ............................................................................................................................................ 836
Kinesis Data Firehose & Kinesis Data Analytics .................................................................................................... 844
Amazon QuickSight .............................................................................................................................................. 847
Data Pipeline ........................................................................................................................................................ 849
Knowledge In Action – Project 25......................................................................................................................... 851
Section 23 - Additional Services ........................................................................................................................ 854
Section Outline ..................................................................................................................................................... 855
Amazon Elasticsearch........................................................................................................................................... 856
Elastic Transcoder ................................................................................................................................................ 859
Amazon AppSync .................................................................................................................................................. 861
Amazon WorkSpaces ............................................................................................................................................ 863
Amazon WorkDocs ............................................................................................................................................... 865
Amazon X-Ray ...................................................................................................................................................... 866
AWS Database Migration Service (DMS).............................................................................................................. 869
AWS Resource Access Manager (RAM) ................................................................................................................ 873
AWS Cost Explorer ................................................................................................................................................ 876
© DolfinED All rights reserved www.dolfined.com 7
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The course is available on Udemy & DolfinED websites,
https://www.udemy.com/course/aws-certified-solutions-architect-associate-/
Visit DolfinED’s website to browse the available courses and enroll at a discounted
price.
www.dolfined.com/course-catalog
When you visit the above URL @ www.dolfined.com, Enroll in the free course,
TCP/IP Introduction and Cloud Pre-Requisite Knowledge
Which will teach you many topics required for Cloud and IT in general, including
TCP/IP, IP Routing, IP Subnetting, Containers, Virtualization, SSL and Digital
Certificates, Encryption, NAT, and PAT, among other topics.
The course is full of animation and graphics, high quality knowledge, audio, and
video. Definitely worth having a look at.
© DolfinED All rights reserved www.dolfined.com 8
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 1 - Suggested Study Plan
© DolfinED All rights reserved www.dolfined.com 9
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 10
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 11
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 2 – Introduction to Cloud Computing
© DolfinED All rights reserved www.dolfined.com 12
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 13
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
On-Premises Data Centers vs. Cloud
© DolfinED All rights reserved www.dolfined.com 14
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 15
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 16
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Private, Public & Hybrid Cloud
© DolfinED All rights reserved www.dolfined.com 17
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 18
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 19
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 20
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 21
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Cloud Services
© DolfinED All rights reserved www.dolfined.com 22
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 23
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 24
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 3 – Introduction to AWS Services – Part 1
Section Outline
© DolfinED All rights reserved www.dolfined.com 25
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Global Infrastructure
© DolfinED All rights reserved www.dolfined.com 26
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 27
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 28
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Free Tier
© DolfinED All rights reserved www.dolfined.com 29
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS IAM 101
© DolfinED All rights reserved www.dolfined.com 30
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Identity and Access Management 101
© DolfinED All rights reserved www.dolfined.com 31
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 32
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 33
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 34
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
IAM Identities – Users & IAM Best Practices
© DolfinED All rights reserved www.dolfined.com 35
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 36
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 37
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 38
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Virtual Private Cloud (101)
© DolfinED All rights reserved www.dolfined.com 39
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Virtual Private Cloud (VPC) - Components
© DolfinED All rights reserved www.dolfined.com 40
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 41
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 42
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 43
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 44
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 45
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
VPC Components (cont.)
© DolfinED All rights reserved www.dolfined.com 46
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 47
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 48
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
VPC – Public vs. Private Subnets & Hybrid Connectivity 101
© DolfinED All rights reserved www.dolfined.com 49
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 50
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 51
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 1
© DolfinED All rights reserved www.dolfined.com 52
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – 10+ Requirements – Are You Ready?!
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 53
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirement # 1
Design a solution for a web application that will be hosted in AWS to satisfy the
following requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 54
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Requirement # 1
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 55
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 4 – Introduction to AWS Services – Part 2
© DolfinED All rights reserved www.dolfined.com 56
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 57
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Compute Cloud (EC2) 101
© DolfinED All rights reserved www.dolfined.com 58
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 59
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 60
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 61
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 62
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Using SSH to connect a Linux EC2 instance
© DolfinED All rights reserved www.dolfined.com 63
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 64
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 65
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 66
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Private, Public, and Elastic IP Addresses
© DolfinED All rights reserved www.dolfined.com 67
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 68
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 69
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 70
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Understanding Security Groups
© DolfinED All rights reserved www.dolfined.com 71
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 72
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge
© DolfinED All rights reserved www.dolfined.com 73
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Understanding Network Access Lists (NACLs)
© DolfinED All rights reserved www.dolfined.com 74
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 75
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 76
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 77
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 78
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 79
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 2
© DolfinED All rights reserved www.dolfined.com 80
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements # 2 & 3
Design a solution for a multi-tier web application to meet the following
requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Launch two EBS-backed EC2 instances, one in each of the two AZs above, these
will serve as the web and application tiers. They should be accessible from the
Internet.
3) Design the VPC security to ensure access control at Layer 4 at the subnet and
Compute levels.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 81
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 2
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 82
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 3
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 83
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Encryption 101
© DolfinED All rights reserved www.dolfined.com 84
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 85
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 86
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 87
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 88
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Key Management Service (KMS) 101
© DolfinED All rights reserved www.dolfined.com 89
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 90
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 91
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 92
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 93
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 94
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 95
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Simple Storage Service (S3) 101
© DolfinED All rights reserved www.dolfined.com 96
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 97
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 98
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 99
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 100
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 101
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 102
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
IAM Access Keys for Programmatic Access to AWS
© DolfinED All rights reserved www.dolfined.com 103
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 104
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 105
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS IAM – Elements and Policies
© DolfinED All rights reserved www.dolfined.com 106
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 107
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 108
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 109
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 IAM Roles
© DolfinED All rights reserved www.dolfined.com 110
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 111
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Monolithic vs. Multi-Tier Applications
© DolfinED All rights reserved www.dolfined.com 112
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 113
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Introduction to Messaging and Notification Services in AWS
© DolfinED All rights reserved www.dolfined.com 114
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 115
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 116
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 2
© DolfinED All rights reserved www.dolfined.com 117
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements
Design a solution for a multi-tier web application to meet the following
requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Moreover, the application on EC2 instances will require access to AWS services.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 118
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 4
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 119
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon CloudFront (Content Delivery Network – CDN) 101
© DolfinED All rights reserved www.dolfined.com 120
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 121
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 122
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 123
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Route 53 101
© DolfinED All rights reserved www.dolfined.com 124
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 125
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 126
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 3
© DolfinED All rights reserved www.dolfined.com 127
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements 5 & 6
Design a solution for a multi-tier web application to meet the following
requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 128
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements 5 & 6
Design a solution for a multi-tier web application to meet the following requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a way
of ensuring a good application performance for all users.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 129
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirements # 5 & 6
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 130
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Relational Database Service (RDS) 101
© DolfinED All rights reserved www.dolfined.com 131
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 132
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 133
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 134
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 4
© DolfinED All rights reserved www.dolfined.com 135
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements
Design a solution for a multi-tier web application to meet the following
requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 136
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 –Requirements 7, 8 & 9
Design a solution for a multi-tier web application to meet the following
requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a
way of ensuring good performance for users in remote locations too.
7) Launch an RDS database in the above VPC. Ensure failover to another AZ in case
of a failure of the primary RDS instance. Ensure the database instances are
secured at layer 4.
8) Ensure that the data is encrypted as it is stored.
9) As the traffic increases, the solution must have a component that decouples the
web/app tier from the database tier to avoid overwhelming the database.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 137
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 7
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 138
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 8
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 139
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 9
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 140
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 5 – Key Architecture Pillars
© DolfinED All rights reserved www.dolfined.com 141
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 142
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Monolithic vs. Microservices Applications
© DolfinED All rights reserved www.dolfined.com 143
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 144
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 145
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
High Availability, Fault Tolerance, Scalability & Elastic Load Balancing 101
© DolfinED All rights reserved www.dolfined.com 146
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 147
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 148
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elasticity and Auto Scaling
© DolfinED All rights reserved www.dolfined.com 149
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 150
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 151
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 152
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 1 - 5
© DolfinED All rights reserved www.dolfined.com 153
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 – Requirements
Design a solution for a multi-tier web application to meet the following
requirements:
1) The application will be launched in a VPC with CIDR block 10.0.0.0/16 with:
• 2 Public subnets in two different AZs. Use 10.0.10.0/24 and 10.0.20.0/24.
• 2 Private Subnets in the same AZs as in 1) above. Use 10.0.100.0/24 and 10.
0.200.0/24.
2) Design the VPC security to ensure access control at Layer 4 at the subnet and
compute levels.
3) Launch two EBS-backed EC2 instances, one in each of the two AZs above; these
will serve as the web and application tiers.
4) Administrators and developers will need programmatic access to AWS services.
Also, the application on EC2 instances will require access to AWS services.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 154
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 1 –Requirements
Design a solution for a multi-tier web application to meet the following requirements:
5) The Domain name will be registered with AWS.
6) The application will have users across the globe. Ensure that the solution has a
way of ensuring good performance for users in remote locations too.
7) Launch an RDS database in the above VPC. Ensure failover to another AZ in case of
a failure of the primary RDS instance.
8) As the traffic increases, the solution must have a component that decouples the
web/app tier from the database tier to avoid overwhelming the database.
9) Ensure that the data is encrypted as it is stored.
10) Ensure that the web/app tier is highly available across the two availability zones.
The load should be distributed evenly across the web/app instances.
11) The solution must be connected to the corporate Datacenter with two
connections, primary with low latency and a secure internet-based backup.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 155
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 10
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 156
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 11
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 157
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirement # 11
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 158
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Monitoring and Visibility – Amazon CloudWatch 101
© DolfinED All rights reserved www.dolfined.com 159
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 160
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Auditing in AWS – Amazon CloudTrail
© DolfinED All rights reserved www.dolfined.com 161
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 162
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 163
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 164
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 165
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Disaster Recovery in AWS 101
© DolfinED All rights reserved www.dolfined.com 166
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 167
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 168
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 169
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 170
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 6 – Virtual Private Cloud (VPC) – Deep Dive
© DolfinED All rights reserved www.dolfined.com 171
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 172
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
NAT Instance & NAT Gateway
© DolfinED All rights reserved www.dolfined.com 173
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 174
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 175
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
NAT Gateway
© DolfinED All rights reserved www.dolfined.com 176
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 177
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 178
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 179
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 180
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 181
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Bastion Host, Proxy & Reverse Proxy Servers
© DolfinED All rights reserved www.dolfined.com 182
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 183
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 184
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Bastion Host
© DolfinED All rights reserved www.dolfined.com 185
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 186
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 187
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 2 - 1
© DolfinED All rights reserved www.dolfined.com 188
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 189
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 190
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
VPC Peering
© DolfinED All rights reserved www.dolfined.com 191
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 192
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 193
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 194
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Transit Gateway
© DolfinED All rights reserved www.dolfined.com 195
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 196
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 197
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 198
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 199
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 200
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
VPC Endpoints
© DolfinED All rights reserved www.dolfined.com 201
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 202
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 203
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 204
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 205
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 206
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 207
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 2- 2
© DolfinED All rights reserved www.dolfined.com 208
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 209
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 210
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 211
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS IPv6 Egress-Only Gateway
© DolfinED All rights reserved www.dolfined.com 212
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 213
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
VPC Flow Logs
© DolfinED All rights reserved www.dolfined.com 214
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 215
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 6 -1 – Hybrid Cloud Networking on AWS
© DolfinED All rights reserved www.dolfined.com 216
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 217
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Hybrid Cloud Connectivity
© DolfinED All rights reserved www.dolfined.com 218
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Managed Virtual Private Networks (VPN)
© DolfinED All rights reserved www.dolfined.com 219
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 220
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 221
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 222
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Direct Connect
© DolfinED All rights reserved www.dolfined.com 223
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 224
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 225
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 226
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 227
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 228
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 7 – EC2 and EBS (Deep Dive)
© DolfinED All rights reserved www.dolfined.com 229
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 230
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 231
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Compute Cloud (EC2)
© DolfinED All rights reserved www.dolfined.com 232
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Instance Types & Instance Lifecycle
© DolfinED All rights reserved www.dolfined.com 233
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 234
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 235
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 236
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 237
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Instance Metadata & User Data
© DolfinED All rights reserved www.dolfined.com 238
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 239
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 240
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Purchasing/Launch Options
© DolfinED All rights reserved www.dolfined.com 241
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 242
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 243
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 244
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 245
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 246
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Spot Instances
© DolfinED All rights reserved www.dolfined.com 247
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 248
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 249
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 250
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 251
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 252
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Placement Groups & Data Transfer Costs
© DolfinED All rights reserved www.dolfined.com 253
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 254
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 255
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 256
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 257
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 258
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EC2 Monitoring
© DolfinED All rights reserved www.dolfined.com 259
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 260
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 261
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 262
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 263
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Block Store (EBS)
© DolfinED All rights reserved www.dolfined.com 264
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Block Store (EBS)
© DolfinED All rights reserved www.dolfined.com 265
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 266
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 267
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 268
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 269
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 270
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
EBS Snapshots
© DolfinED All rights reserved www.dolfined.com 271
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 272
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 273
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 274
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 275
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 276
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 277
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 278
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Creating and Sharing/Copying EC2 AMIs
© DolfinED All rights reserved www.dolfined.com 279
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 280
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 281
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 282
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
RAID and EBS Volumes, AWS Batch
© DolfinED All rights reserved www.dolfined.com 283
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 284
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 285
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Batch
© DolfinED All rights reserved www.dolfined.com 286
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 287
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 8 - Elastic Load Balancing and Auto Scaling on AWS
© DolfinED All rights reserved www.dolfined.com 288
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 289
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 290
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Load Balancing
© DolfinED All rights reserved www.dolfined.com 291
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Target Groups, Listeners, and Health Checks
© DolfinED All rights reserved www.dolfined.com 292
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 293
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 294
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 295
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 296
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 297
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 298
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Cross-Zone Load Balancing, Connection Draining & Subnet Design for HA
© DolfinED All rights reserved www.dolfined.com 299
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 300
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 301
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 302
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 303
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
ELB Security Groups
© DolfinED All rights reserved www.dolfined.com 304
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 305
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 306
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 307
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
ELB and SSL Certificates
© DolfinED All rights reserved www.dolfined.com 308
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 309
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 310
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 311
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 312
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 313
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 314
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 315
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 3
© DolfinED All rights reserved www.dolfined.com 316
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 317
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 318
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 319
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
ELB – Client IP Address, Monitoring, Stickiness, and PFS
© DolfinED All rights reserved www.dolfined.com 320
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 321
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 322
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 323
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 324
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Application Load Balancer
© DolfinED All rights reserved www.dolfined.com 325
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 326
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 327
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 328
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Network Load Balancer
© DolfinED All rights reserved www.dolfined.com 329
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 330
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 331
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 332
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
ELB – Gateway Load Balancer (GWLB)
© DolfinED All rights reserved www.dolfined.com 333
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 334
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Auto Scaling
© DolfinED All rights reserved www.dolfined.com 335
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Auto Scaling
© DolfinED All rights reserved www.dolfined.com 336
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 337
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 338
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 339
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 340
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 341
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon AutoScaling – Launch Templates and Scaling Policies
© DolfinED All rights reserved www.dolfined.com 342
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 343
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 344
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 345
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 346
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 347
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 4
© DolfinED All rights reserved www.dolfined.com 348
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 349
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 350
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 351
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 352
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 353
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 354
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 355
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 356
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 9 – Amazon Relational Database Service (RDS)
© DolfinED All rights reserved www.dolfined.com 357
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 358
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 359
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 360
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 361
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 362
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 363
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 364
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 365
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 366
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 367
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 368
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 369
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 370
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 371
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 372
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 373
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 374
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 375
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 5
© DolfinED All rights reserved www.dolfined.com 376
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 377
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 378
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 379
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Aurora
© DolfinED All rights reserved www.dolfined.com 380
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 381
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 382
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 383
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 384
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 385
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 386
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 387
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 388
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 389
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 390
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 391
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Aurora Serverless
© DolfinED All rights reserved www.dolfined.com 392
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 393
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 394
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 6
© DolfinED All rights reserved www.dolfined.com 395
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 396
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 397
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 398
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Redshift
© DolfinED All rights reserved www.dolfined.com 399
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon RedShift - Introduction
© DolfinED All rights reserved www.dolfined.com 400
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 401
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 402
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 403
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 404
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 405
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 406
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 407
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 408
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 10 - NoSQL Databases in AWS
© DolfinED All rights reserved www.dolfined.com 409
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 410
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon DynamoDB
© DolfinED All rights reserved www.dolfined.com 411
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 412
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 413
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 414
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 415
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 416
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 417
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 418
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon DynamoDB – Advanced Features
© DolfinED All rights reserved www.dolfined.com 419
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 420
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 421
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 422
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 423
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 424
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 425
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 426
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 427
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 7
© DolfinED All rights reserved www.dolfined.com 428
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 429
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 430
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
ElastiCache
© DolfinED All rights reserved www.dolfined.com 431
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 432
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 433
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 434
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 435
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 436
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 437
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 438
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 439
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon DocumentDB and Amazon Neptune
© DolfinED All rights reserved www.dolfined.com 440
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 441
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 442
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 11 - Mid Course Assessment
© DolfinED All rights reserved www.dolfined.com 443
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 12 – Identity and Access Management (IAM) - Intermediate
© DolfinED All rights reserved www.dolfined.com 444
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 445
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
IAM Identity-Based Policies
© DolfinED All rights reserved www.dolfined.com 446
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 447
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 448
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 449
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 450
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 451
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 452
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 453
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 454
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 455
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
IAM Security Token Service (STS) & IAM Roles
© DolfinED All rights reserved www.dolfined.com 456
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 457
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 458
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 459
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 460
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 461
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 462
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
IAM Resource-based Policies, Permissions Boundary, and Policy Evaluation Logic
© DolfinED All rights reserved www.dolfined.com 463
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 464
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 465
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 466
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 467
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 468
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 8
© DolfinED All rights reserved www.dolfined.com 469
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 470
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 471
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 13 – Simple Storage Service (S3) – Deep Dive
© DolfinED All rights reserved www.dolfined.com 472
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 473
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 474
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Data Consistency, Tiered Storage Classes, and S3 Lifecycle Policies
© DolfinED All rights reserved www.dolfined.com 475
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 476
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 477
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 478
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 479
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 480
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 481
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Server Side Encryption and Multipart Upload
© DolfinED All rights reserved www.dolfined.com 482
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 483
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 484
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 485
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 486
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Bucket Versioning and Cross-Region Replication
© DolfinED All rights reserved www.dolfined.com 487
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 488
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 489
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 490
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 491
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 492
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 493
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Object Lock and Glacier Vault Lock
© DolfinED All rights reserved www.dolfined.com 494
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 495
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 496
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 497
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Static Website Hosting
© DolfinED All rights reserved www.dolfined.com 498
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 499
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 500
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Pre-Signed URLS, Transfer Acceleration, and Requester Pays
© DolfinED All rights reserved www.dolfined.com 501
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 502
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 503
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 504
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Access Management and Bucket Policies
© DolfinED All rights reserved www.dolfined.com 505
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 506
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 507
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 508
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 509
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 510
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 511
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 512
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 513
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Cross-Origin Resource Sharing, Batch Operations, and Billing
© DolfinED All rights reserved www.dolfined.com 514
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 515
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 516
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 517
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 9
© DolfinED All rights reserved www.dolfined.com 518
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 519
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 520
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 SELECT, Glacier SELECT, S3 Performance, and AWS Transfer Family
© DolfinED All rights reserved www.dolfined.com 521
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 522
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 523
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 524
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 525
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 10
© DolfinED All rights reserved www.dolfined.com 526
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 527
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 528
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 11
© DolfinED All rights reserved www.dolfined.com 529
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 530
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 531
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
S3 Monitoring, Event Notification, Server Access Logging, and S3 vs. DynamoDB
© DolfinED All rights reserved www.dolfined.com 532
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 533
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 534
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 535
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 14 – CloudFront, Route53, and Global Accelerator
© DolfinED All rights reserved www.dolfined.com 536
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 537
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon CloudFront
© DolfinED All rights reserved www.dolfined.com 538
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 539
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 540
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 541
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 542
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 543
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 544
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 545
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
CloudFront – Additional Features
© DolfinED All rights reserved www.dolfined.com 546
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 547
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 548
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 549
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 550
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Route 53
© DolfinED All rights reserved www.dolfined.com 551
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 552
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 553
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 554
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 555
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 556
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 557
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 558
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 559
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Route 53 Routing Policies (cont.) and Route 53 Resolver
© DolfinED All rights reserved www.dolfined.com 560
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 561
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 562
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 563
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 564
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 565
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 566
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 567
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 12
© DolfinED All rights reserved www.dolfined.com 568
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 569
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 570
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 571
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Global Accelerator
© DolfinED All rights reserved www.dolfined.com 572
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 573
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 574
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 575
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 576
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 577
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 578
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 579
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 13
© DolfinED All rights reserved www.dolfined.com 580
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 581
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 582
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 15 – Serverless Computing in AWS
© DolfinED All rights reserved www.dolfined.com 583
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 584
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Lambda
© DolfinED All rights reserved www.dolfined.com 585
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 586
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 587
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 588
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 589
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 590
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 591
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Lambda@Edge
© DolfinED All rights reserved www.dolfined.com 592
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 593
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
API Gateway
© DolfinED All rights reserved www.dolfined.com 594
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 595
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 596
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 597
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 598
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 599
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 600
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 601
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 602
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 603
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 604
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 14
© DolfinED All rights reserved www.dolfined.com 605
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 606
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 607
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 16 – Storage Services in AWS
© DolfinED All rights reserved www.dolfined.com 608
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 609
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic File System (EFS)
© DolfinED All rights reserved www.dolfined.com 610
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 611
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 612
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 613
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 614
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 615
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 616
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon FSx
© DolfinED All rights reserved www.dolfined.com 617
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon FSx for Windows File Server
© DolfinED All rights reserved www.dolfined.com 618
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 619
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 620
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 621
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon FSx for Lustre
© DolfinED All rights reserved www.dolfined.com 622
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 623
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 624
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 625
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 626
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Storage Gateway
© DolfinED All rights reserved www.dolfined.com 627
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 628
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 629
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 630
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Snow Family
© DolfinED All rights reserved www.dolfined.com 631
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 632
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 633
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 634
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 635
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 15
© DolfinED All rights reserved www.dolfined.com 636
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 637
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 638
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Backup and AWS DataSync
© DolfinED All rights reserved www.dolfined.com 639
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 640
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 641
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 642
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 643
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 644
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 16
© DolfinED All rights reserved www.dolfined.com 645
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 646
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 647
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 17 – Containers in AWS
© DolfinED All rights reserved www.dolfined.com 648
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 649
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Elastic Container Service (ECS)
© DolfinED All rights reserved www.dolfined.com 650
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Containers and ECS
© DolfinED All rights reserved www.dolfined.com 651
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 652
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 653
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 654
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 655
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 656
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 657
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 658
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon ECS – Features and Use Cases
© DolfinED All rights reserved www.dolfined.com 659
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 660
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 661
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 662
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 663
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 664
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 665
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 17
© DolfinED All rights reserved www.dolfined.com 666
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 667
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 668
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 669
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Kubernetes Service (EKS)
© DolfinED All rights reserved www.dolfined.com 670
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 671
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 672
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 673
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 18 – Notification, Messaging and Application Integration in AWS
© DolfinED All rights reserved www.dolfined.com 674
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 675
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Simple Queue Service (SQS)
© DolfinED All rights reserved www.dolfined.com 676
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 677
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 678
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 679
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 680
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 681
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 682
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 683
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 684
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Simple Notification Service (SNS)
© DolfinED All rights reserved www.dolfined.com 685
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 686
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 687
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 688
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 689
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 690
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon MQ
© DolfinED All rights reserved www.dolfined.com 691
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 692
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 693
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Step Functions
© DolfinED All rights reserved www.dolfined.com 694
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 695
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 18
© DolfinED All rights reserved www.dolfined.com 696
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 697
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 698
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 19 – Management, Monitoring, and Auditing in AWS
© DolfinED All rights reserved www.dolfined.com 699
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 700
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon CloudWatch
© DolfinED All rights reserved www.dolfined.com 701
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 702
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 703
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 704
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 705
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon CloudWatch Logs
© DolfinED All rights reserved www.dolfined.com 706
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 707
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 708
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 709
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 710
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 711
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon CloudWatch Events
© DolfinED All rights reserved www.dolfined.com 712
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 713
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 714
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 715
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 20 – Governance, Deployment, and Operations in AWS
© DolfinED All rights reserved www.dolfined.com 716
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 717
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Organizations
© DolfinED All rights reserved www.dolfined.com 718
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 719
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 720
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 721
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 722
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 723
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 724
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 725
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 726
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS CloudFormation
© DolfinED All rights reserved www.dolfined.com 727
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 728
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 729
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 730
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 731
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 732
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 733
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 734
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Elastic Beanstalk
© DolfinED All rights reserved www.dolfined.com 735
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 736
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 737
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 738
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 739
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 740
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 741
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS OpsWorks 101
© DolfinED All rights reserved www.dolfined.com 742
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 743
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 744
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 19
© DolfinED All rights reserved www.dolfined.com 745
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 746
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 747
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Systems Manager
© DolfinED All rights reserved www.dolfined.com 748
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 749
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 750
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Parameter Store
© DolfinED All rights reserved www.dolfined.com 751
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 752
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 753
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 754
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Secrets Manager
© DolfinED All rights reserved www.dolfined.com 755
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 756
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 757
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 758
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Config
© DolfinED All rights reserved www.dolfined.com 759
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 760
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 761
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 762
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 763
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 764
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Trusted Advisor
© DolfinED All rights reserved www.dolfined.com 765
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 766
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 20
© DolfinED All rights reserved www.dolfined.com 767
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 768
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 769
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 21 – Security, Identity and Compliance Services in AWS
© DolfinED All rights reserved www.dolfined.com 770
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
© DolfinED All rights reserved www.dolfined.com 771
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS CloudHSM
© DolfinED All rights reserved www.dolfined.com 772
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 773
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 774
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 775
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 776
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Shield
© DolfinED All rights reserved www.dolfined.com 777
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 778
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 779
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 780
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Web Application Firewall
© DolfinED All rights reserved www.dolfined.com 781
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 782
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 783
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 784
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 21
© DolfinED All rights reserved www.dolfined.com 785
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 786
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirements …..
Satisfied Requirements:
All the below plus,
• Cost effective.
• Least Overhead (Can be fully
serverless).
Satisfied Requirements:
• Caters to global user base.
• Protected, resilient to attacks.
• Scalable Highly available.
• Can block certain countries.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 787
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon GuardDuty
© DolfinED All rights reserved www.dolfined.com 788
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 789
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 790
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 791
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Inspector
© DolfinED All rights reserved www.dolfined.com 792
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 793
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 794
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 795
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Cognito
© DolfinED All rights reserved www.dolfined.com 796
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 797
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 22
© DolfinED All rights reserved www.dolfined.com 798
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 799
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 800
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
© DolfinED All rights reserved www.dolfined.com 801
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Cognito
© DolfinED All rights reserved www.dolfined.com 802
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
Amazon Cognito
Amazon Cognito provides authentication, authorization, and user management for
web and mobile applications.
The main two components of Cognito are :
• Cognito User Pools: Provides user directories that provide sign-up and sign-in
options for users.
• Cognito Identity pools: Can be used to grant AWS credentials (STS) to access AWS
services.
They can be used separately or together.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 803
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
Amazon Cognito User Pools
• Sign up and sign in services.
• Customizable web UI to sign in users.
• Social sign in through Facebook, Google,
Amazon and Apple as well as Open ID
Connect (OIDC) and SAML.
• User directory management and user
profiles.
• Multi Factor Authentication (MFA).
• Checks for compromised credentials.
Authenticate
• Account takeover protection. and get tokens
• Phone/email verification.
• User pools grants authenticated users
JSON Web Tokens (JWT).
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 804
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
Amazon Cognito Identity Pools (Federated Identities)
Cognito identity pools can be used to
generate temporary STS credentials to Authenticate
and get tokens
access AWS services in exchange for a
token from an identity provider or Cognito Exchange
Tokens for AWS
user pools. STS Credentials
Access
AWS Services
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 805
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
Web Identity Federation - Amazon Cognito Identity Pools (Federated Identities)
• We can use Cognito identity
pools to provide federated users
access to AWS services.
• A trust is established between
Exchange Tokens
AWS and these Identity Provides for AWS STS
Credentials
(IdPs) such as Facebook, Amazon,
Apple, Google or SAML 2.0 IdP.
• The token received from
authentication is then exchanged
Access
through identity pools with STS AWS Services
temporary credentials.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 806
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Directory Services
AWS Directory Services
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 807
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
AWS Directory Service
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 808
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Single Sign-On (SSO)
© DolfinED All rights reserved www.dolfined.com 809
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
AWS Single Sign-On (SSO)
• We can use AWS SSO to AWS
centrally manage SSO
access to all AWS
accounts and cloud
Permissions
applications.
• Users do not have to
maintain multiple
credentials. SSO
• It provides user portals. Access
• It integrates with AWS
Organizations and many
business applications
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 810
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
AWS Single Sign-On (SSO) – User/Group Directory
AWS
The Identities Database
(users, groups, roles) can
be located on:
• AWS SSO itself.
• AWS Managed MS AD
(AWS directory service).
• On-premises MS AD
connected through AWS
AD Connector.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 811
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 23
ADV
What did we learn?!
Knowledge In Action…
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 812
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 23 – Project Details
Design a security solution for a two-tier web application deployed to AWS across
two Availability Zones. The web application consists of an auto-scaled fleet of EC2
instances, in public subnets, behind an Application Load Balancer (ALB). A
CloudFront Distribution is used to serve the content with the ALB as the origin. The
solution must incorporate automated detection and remediation of threats against
the application generated from Internet sources. This solution's goal is to improve
the application’s security posture and minimize the impact of Internet-sourced
attacks, including DDoS attacks. Notification should be sent out via email to the
administrators. The solution must be efficient and very cost-effective in achieving
the required with the least ongoing overhead. Minor changes to the current
architecture are acceptable.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 813
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirements …..
Blocked CloudFront
DynamoDB
Host Table
Event
Rule
Security group
CloudWatch
Events
WAF Filtering
Rule
SNS Network
Amazon
Topic ACL(s)
GuardDuty
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 814
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 22 – Analytics Services in AWS
© DolfinED All rights reserved www.dolfined.com 815
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
Section Outline
In this section, we will learn:
• Amazon RedShift Spectrum
• Elastic Map Reduce (EMR)
• Amazon Athena
• Amazon Glue
• Amazon Kinesis
• Amazon QuickSight
• AWS Data Pipeline
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 816
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Redshift Spectrum
© DolfinED All rights reserved www.dolfined.com 817
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon RedShift Spectrum
• Amazon Redshift spectrum facilitates running
SQL queries against exabytes of data in S3.
• It is a serverless service with nothing to
provision/manage.
• SQL or BI tools will query the In-VPC Redshift
cluster with pointers to external data in S3.
• Redshift Spectrum nodes outside the VPC will
process the request, query data in S3, and return
results to in-VPC clusters for final processing.
• It encrypts data in transit and at rest using SSE.
• Charge is per the number of bytes scanned.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 818
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic MAP Reduce
© DolfinED All rights reserved www.dolfined.com 819
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Hadoop and Amazon EMR - Background
• Hadoop is an open-source software framework for reliable, scalable, and distributed
computing.
• It supports data-intensive distributed processing of large data sets running on large
clusters of compute nodes (EC2 instances in AWS).
• Hadoop runs a processing/programming model called “Map Reduce”, which can process
large data sets quickly.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 820
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Elastic Map Reduce (EMR)
EMR is a managed cluster service used to run big
data frameworks such as Apache Hadoop clusters in
AWS to easily and cost-effectively process vast
amounts of data.
• EMR is ideal for use cases that require fast and
efficient processing of large amounts of data.
• Use cases include web indexing, data mining, log
file analysis, machine learning, financial analysis,
scientific simulation, and bioinformatics research.
EMR can also transfer large data in and out of AWS
data stores such as S3 and DynamoDB. EMR Cluster
• Customers have root access to the EMR Cluster
EC2 instances.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 821
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Elastic Map Reduce (EMR) - Features
• EMR is NOT about real-time data ingestion.
• EMR clusters are launched in a single AWS AZ.
• EMR clusters can use RIs, On-demand, or Sport
instances and support auto-scaling.
• EMR integrates with EC2, VPC, S3, CloudWatch,
and Data Pipeline.
• Supports encryption in-transit and SSE in S3.
EMR Cluster
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 822
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Operating on data in S3 - Amazon EMR vs Amazon Redshift Spectrum
EMR with Apache Hive Redshift Spectrum
Compute Cluster-Server based Serverless
Use case SQL based queries - Great SQL based queries - Great
for scale-out processing fit as it can scale out to
like scans, filters, and thousands of nodes to pull
aggregates. data, filter, project,
aggregate, group, and sort.
Ingest the entire data from Not required. Not required.
S3 into the service to
process it?
Complex querying and It gets very slow as the Very efficient.
joins use cases? (very data size and number of
critical for analytics). nodes increases.
Billing Pay for the compute. Pay for the data scanned.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 823
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Athena
© DolfinED All rights reserved www.dolfined.com 824
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Athena
• Athena is a serverless, interactive, query service
that can be used to query and analyze data stored
in S3 using standard SQL.
• Athena uses schema-on-read technology.
• It integrated with Amazon QuickSight for data
visualization.
• Can query unstructured, semi-structured, and
structured data in CSV, JSON, Apache (Parquet,
Avro, and ORC).
• It can query logs in S3 from different AWS services.
Standard SQL Schema
Queries /Table
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 825
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Athena
• It scales automatically.
• Query results are stored in S3 in .csv format.
• Can query encrypted data in S3 and can
encrypt query results.
Standard SQL Schema
Queries /Table
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 826
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Athena vs. Redshift Spectrum - When To Use What?
Athena RedShift Spectrum
Compute (Serverless?) A completely serverless service. Redshift spectrum itself is serverless.
One or more RedShift clusters are required
(higher cost).
Complex Joins, Queries and Not meant for this use case. Ideal for this use case.
Aggregations.
Ad-hoc SQL queries. Ideal for this case. Not meant for this case.
Can query data in S3 without Yes Yes
loading it.
Large data lake users that want Not meant for this use case. Perfect fit for this use case.
to run concurrent BI and
reporting workloads.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 827
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Glue
© DolfinED All rights reserved www.dolfined.com 828
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Glue
Data catalog
AWS Glue is a fully managed, serverless, pay-as- Store the
Crawlers Amazon
you-go, extract, transform, and load (ETL) service. metadata
in the glue
Redshift
• AWS Glue protects data in-transit and at rest. data catalog
Amazon
• It makes it simple to scan, clean, enrich data, AWS
Glue ETL
Athena
infer the schema, and move data between S3 Bucket Glue Loads Amazon
data stores in AWS. transformed
data To Targets
EMR
• AWS Glue runs on Apache Spark which is a Amazon
Redshift
data analytics engine built on Hadoop. Spectrum
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 829
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics
Amazon Glue – Use Cases
Amazon
Redshift
• Run serverless queries against an S3 data Trigger one
(or more)
Lambda
lake. Object Function AWS Glue
ETL Jobs
• Build a data warehouse from different, Glue Loads
transformed
disparate, data sources. S3 Bucket AWS Glue data To Targets
• Create event-driven ETL pipelines with AWS Register the
ETL
Glue and Lambda. metadata in the
glue data catalog
• Understand stored data assets.
Data catalog
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 830
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Glue vs. EMR
Glue EMR
Is a fully managed, pay as you go, ETL Is a managed big data platform known for its
tool for big data. It can transform the speed and ease of data conversions. It also
data and make it ready for analytics supports ETL jobs.
purposes.
Platform Serverless. Server-based.
Based on Hadoop Framework. Based on Hadoop framework.
Runs on top of Hadoop Spark. Supports many of the Hadoop services
including Spark, Hive, and Pig among others.
Cost More expensive. Less expensive.
ETL Operations – Higher. Lower compared to Glue.
Performance and flexibility
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 831
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 23
© DolfinED All rights reserved www.dolfined.com 832
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 24 – Project Details
Design a solution for a company to store large-scale datasets from business
applications, social media, internet-connected sensors, and other devices. The data
will include structured and unstructured components. It is required to be able to run
infrequent SQL queries on the stored data for analytics purposes. The solution must
minimize infrastructure costs and will require the least ongoing overhead.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 833
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirements …..
Crawler
Mobile
client AWS Glue
Athena
Users
Internet
AWS glue data
catalog
Client
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 834
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Kinesis
© DolfinED All rights reserved www.dolfined.com 835
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Kinesis Data Streams
© DolfinED All rights reserved www.dolfined.com 836
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Data Streaming and Amazon Kinesis - Background
• Streaming data is data
generated and sent in small
sizes (KBs or MBs) from a
large number of sources
continuously.
• Kinesis is a managed real-
time streaming data service
in AWS, which is used for IoT
and Big Data analytics.
• Kinesis can continuously
capture and store terabytes
of data per hour from a large
number of sources.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 837
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Data Streams
• Use Kinesis data streams to ingest
large data volumes in real time and
make the data available, in
milliseconds, for consumption by one
or more Kinesis applications in
parallel.
• These applications use Kinesis Client
Library (KCL) and can run on Amazon
EC2 instances.
• The processed data records can be
used in different applications
(dashboards, generate alerts, etc.)
• Data is stored in a stream for 24
hours by default, and up to 7 days.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 838
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Kinesis Data Streams – Availability, Durability, Use Cases & Encryption
Kinesis Data Streams synchronously
replicates data across three AZs for high
availability and data durability.
Use cases include:
• Accelerating log and data feed intakes.
• Real time metric and reporting analytics.
• Complex stream processing.
Kinesis data streams can encrypt data into
the stream using SSE and KMS keys.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 839
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Writing to a Kinesis Data Streams (KDSs)
We can write to a Kinesis Data Stream using:
• Amazon Kinesis Producer Library (KPL).
• Amazon KDS APIs using SDKs.
• Kinesis Agent.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 840
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Data Streams – Records, Shards, and Partition Keys
Partition
Key 1
A Kinesis stream is a set of
shards. Partition
Key 2
Producers put records in a
Kinesis stream. Partition
Key 3
Each record has a partition key
specified by the producer, and Partition
Key N
a sequence number specified
by Kinesis.
Kinesis uses the partition key
of the record to generate a A shard can take up to
The sequence number of a
MD5 hash to decide which record is unique per partition 1MB/sec input (writes by
shard to store the data record key within its shard (ordering producers) and up to 2MB/sec
into. output (reads by consumers).
within a shard).
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 841
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Data Streams – Resharding & Consumer Read Throughput
• Kinesis data streams support re-
sharding a stream. Merging
• A shard can be split into two shards.
• We can merge two shards into one. Splitting
• As the number of shards increases,
stream throughput increases, and cost
increases too.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 842
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Data Stream vs. SQS - when to use what?
Kinesis Data Streams SQS
Intended use Real-time ingestion and processing of streaming Reliable, highly scalable hosted queue for
big data. storing messages as they travel between
computers.
Ordering Ordering of records, and ability to read/replay SQS FIFO queues can guarantee message
records in the same order by several Kinesis ordering.
applications.
Use when your • Routing related records to the same record • Messaging semantics (ack/fail) and
requirements are processor (consumer). visibility timeout are required.
any of the following: • When we need ordering of records (Important • You need the queue to scale transparently
in case we need to keep the order of logs without pre-provisioning shards.
messages the same at the consumer as they
arrived from the producers).
• When we need multiple applications to
consume the records concurrently.
• The ability to consume the same records few
hours or couple of days later.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 843
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Kinesis Data Firehose & Kinesis Data Analytics
© DolfinED All rights reserved www.dolfined.com 844
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Data Firehose
Kinesis Data Firehose is a fully managed
service used to automatically capture
real-time streaming data from producers
and deliver it to destinations such as S3,
Redshift, Elasticsearch, and Splunk.
• Use cases include IoT analytics, Log
analytics, Clickstream analytics, and
Security monitoring.
• Kinesis Stream can be a data source.
• It can use a Lambda function to
transform data before delivering it.
• It scales based on demand (no shards)
• Data is buffered for up to 24 hours.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 845
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics Services
Amazon Kinesis Analytics
Amazon Kinesis data analytics is
used to process and analyze real-
time streaming data from Kinesis
Data Streams or Kinesis Data
Firehose using standard SQL code.
• It requires Kinesis Data Analytics
applications to continuously
read and process streaming
data.
• Use case: Produce time series
analytics, feed real-time
dashboards, and create real-
time metrics.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 846
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon QuickSight
© DolfinED All rights reserved www.dolfined.com 847
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics
Amazon QuickSight
1. Data Sources
QuickSight is a business analytics tool.
2. Data Sets
• It can be used to build visualizations, perform ad-hoc
analysis, and provide business insights.
• It can scale to hundreds of thousands of users.
• It starts at data sources, then creates data sets, then 3. Analyses
creates analyses and visuals, which can be shared
through dashboards.
4. Visuals
5. Dashboards
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 848
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Data Pipeline
Data Pipeline
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 849
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics
AWS Data Pipeline
EC2 EMR
• AWS Data Pipeline is a fully managed, scalable, web
service which can be used to automate data
movement and transformation.
• It can be used with many AWS data stores as data ETL/Copy/SQL
sources or destinations.
Use cases:
• Moving data into cloud.
• ETL data from S3, RDS, or DynamoDB into Redshift.
• ETL unstructured data (Ex. Clickstreams, Logs).
• Data Loads and Extracts.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 850
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Knowledge In Action – Project 25
What did we learn?!
Knowledge In Action…
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 851
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Project 25 – Project Details
Design a solution for a company that will collect clickstream data from multiple
online shopping websites in near-real time. The solution must make this data
available for analytics to gain insights in a timely manner. The solution must be cost-
effective and requires the least ongoing overhead.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 852
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
The Solution – Satisfying Project Requirements …..
Users Internet Websites Amazon Kinesis
Amazon Kinesis
Data Firehose Data Analytics
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 853
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section 23 - Additional Services
Additional Services
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 854
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Section Outline
Section Outline
In this section, we will learn:
• Elasticsearch.
• Elastic Transcoder.
• AppSync.
• X-Ray.
• Database Migration Service (DMS).
• Resource Access Manager (RAM).
• Cost Explorer.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 855
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Elasticsearch
© DolfinED All rights reserved www.dolfined.com 856
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics
Elasticsearch - Background
• Elasticsearch is a popular open-source, near real-time, scalable search and analytics
engine.
• Elastic Stack (formerly ELK Stack) includes Elasticsearch with Kibana for visualization, and
Logstash for data collection and log ingestion.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 857
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Analytics
Amazon Elasticsearch (ES)
• Amazon Elasticsearch (ES) is a fully
managed service to deploy, secure,
scale, and operate Elasticsearch cost-
effectively in AWS.
• It supports a built-in alerting and SQL
querying for integration with BI tools.
• Amazon ES integrates with Kibana,
Logstash, Kinesis, S3, DynamoDB, IoT
and Lambda.
• IAM and resource-based policies, and
Cognito for Kibana user
authentication.
• Supports VPC Endpoints
• Pay as you go, no upfront costs.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 858
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Elastic Transcoder
Elastic Transcoder
© DolfinED All right reserved
© DolfinED All rights reserved www.dolfined.com 859
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Media, Mobile, End User, and IoT Services
Amazon Elastic Transcoder
Elastic Transcoder manages the complexity of
running media transcoding jobs at a scale in AWS.
• It is used to convert video and audio (media)
files stored in S3 into supported output formats
for playback on user devices.
• It supports wide range of output formats,
resolutions, bitrates, and frame rates.
• Is a pay for what you use service (has a free tier).
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 860
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon AppSync
Amazon AppSync
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 861
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Media, Mobile, End User, and IoT Services
Amazon AppSync
• Is an enterprise-level, fully managed GraphQL service for data synchronization between
web and mobile apps and servers.
• It exposes GraphQL APIs to clients.
• GraphQL is a data language to enable clients to fetch (Query), Change, or Subscribe to
data from servers.
• It has real-time data synchronization and offline programming features.
• We can control authorization to GraphQL APIs
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 862
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon WorkSpaces
Amazon WorkSpaces
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 863
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon Media, Mobile, End User, and IoT Services
Amazon WorkSpaces
• A VDI is a way to provide clients access to
virtual desktops.
• WorkSpaces is Amazon’s VDI solution.
• Provides a persistent user experience.
• Pay per use, hourly or monthly billing.
• WorkSpaces Application Manager (WAM)
• Same tools to manage desktops.
• MFA can be used for additional security.
• Encryption at rest (disks) using KMS keys
and TLS in-transit.
• Integrates with Amazon Directory Services
(Simple AD, AD Connector, or MS Managed
AD).
• Can whitelist corporate network IP range.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 864
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon WorkDocs
Amazon WorkDocs
• It is a fully managed, secure enterprise storage and collaboration service.
• Can integrate with existing corporate directories.
• Users can preview and comment on different supported file types.
• Deleted folders and files can be recovered for up to 30 days after deletion.
• Each user account comes with 1TB storage; administrators can add or limit storage
per user.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 865
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Amazon X-Ray
AWS X-Ray
© DolfinED All right reserved
© DolfinED All rights reserved www.dolfined.com 866
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Migration and Data Transfer Services in AWS
AWS X-Ray
Service Graph
• X-Ray provides tools to view, filter, and
gain insights into the application flows.
• Using X-Ray, customers can understand
how an application and its underlying
services are performing.
• Using X-Ray and the insights, we can
analyze and troubleshoot performance
problems.
• X-Ray generates a detailed service
graph from the collected data.
https://docs.aws.amazon.com/xray/latest/devguide/aws-xray.html
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 867
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Migration and Data Transfer Services in AWS
AWS X-Ray – Benefits and other features
Benefits:
• Create a service map.
• Identify errors and bugs.
• Build custom analysis and visualization
apps.
• X-Ray always encrypts traces and related
data at rest using KMS keys.
• X-Ray integrates with EC2, ECS, Lambda,
Elastic BeanStalk, API Gateway, and ELB
services (requires an X-Ray daemon).
• AWS Config can be used to track changes
in X-Ray’s encryption configuration.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 868
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Database Migration Service (DMS)
AWS Database Migration
Service (DMS)
© DolfinED All right reserved
© DolfinED All rights reserved www.dolfined.com 869
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Migration and Data Transfer Services in AWS
AWS Database Migration Service (DMS)
• DMS is a web service, which can be used to
migrate data from a source database to a
target database.
• It can be used to migrate data from On-
Premises to AWS or the other way around.
• Homogenous migration : The source and
target databases are of the same DB Engine
(e.g., Oracle to Oracle or MySQL to MySQL)
• Heterogeneous migration : The source and
target are of different engines (e.g., Oracle to
Aurora or RDS to DynamoDB).
• It can be used to do one-time migration or
ongoing replication.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 870
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Migration and Data Transfer Services in AWS
AWS Database Migration Service (DMS)
• Migration is done using a Replication
instance, which can be configured in a
multi-AZ configuration.
• Using DMS we can achieve, faster
Migrations, changing DB engines, and
pay for what we use.
• DMS supports SSL encryption in-
transit and at rest using KMS keys to
encrypt instance storage and endpoint
connection information.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 871
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Migration and Data Transfer Services in AWS
Heterogeneous Migrations and Schema Conversion Tool (SCT)
Heterogeneous migrations happen in two
steps:
• Use Schema Conversion Tool (SCT) to
generate the target schema.
• Use DMS to migrate the data.
AWS Schema Conversion Tool (AWS SCT) can
be used to convert existing database schema
from one database engine to another.
• It can be used to convert relational OLTP
schema, or OLAP data warehouse schema.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 872
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Resource Access Manager (RAM)
© DolfinED All rights reserved www.dolfined.com 873
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
AWS Resource Access Manager (RAM)
• AWS RAM allows customers to share
resources with any AWS account, and if
an account is part of AWS Organizations,
then RAM can also share resources with
Organizational Units (OUs) or the entire
organization.
• Using AWS RAM is free of charge.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 874
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
Security, Identity, and Access Management
AWS Resource Access Manager (RAM) - Benefits
• Provide security & consistency; visibility &
auditability; and reduce operational
overhead.
• IAM policies and SCPs in the account
resources apply to the shared resources.
• We can use RAM to share VPC resources,
Transit Gateway, Route 53 Rules, EC2,
Aurora, App Mesh, CodeBuild, AWS Glue,
AWS ACM Private CA, AWS Resource
Groups, & License Manager configurations.
https://docs.aws.amazon.com/ram/latest/userguide/shareable.html#shareable-vpc
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 875
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Cost Explorer
Cost Explorer
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 876
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
AWS Cost Explorer
• Is an AWS service that allow
customers to visualize,
understand, and manage their
AWS costs and usage over
time, both at a high level and
at a detailed analysis level.
• Provides default reports and
allows customers to build
their own custom reports.
• Cost & Usage report provide
detailed information about
AWS costs and usage.
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 877
AWS Certified Solutions Architect Associate SAA-C02 Student e-Notebook
End of Course
© DolfinED All rights reserved
© DolfinED All rights reserved www.dolfined.com 878