AWS
AWS
• Uses of AWS
• Advantages of AWS
• Ways to access AWS
• Creating an AWS account
• Navigation of the AWS Management Console
• AWS Global Infrastructure
• AWS security measures
Amazon Web Services or AWS
AWS—Introduction
Amazon uses decentralized or distributed IT Infrastructure to make several IT resources available on demand.
Manufacturing Architecture
Large Enterprise Media Company
Organization Consulting Company
prototype
Get high-compute
Expand Business Deliver Training rendering of Provide different types of
construction prototypes content
Pay-As-You-Go
Pay-as-You-go platform enables customers to procure services from AWS:
Pay-As-You-Go
Database Storage
Advantages of AWS
AWS diligently listens to its customer feedback. This enables the AWS team to efficiently deliver creative
features and services.
Even today, AWS continues to hone its operational expertise continually to retain lasting reliability by
employing its own advances and industry best practices into its cloud infrastructure. As a result, the
customers tend to benefit significantly from AWS.
The distributed IT infrastructure provided through AWS has evolved with time, through the lessons learned
from over 16 years of experience.
Scale up the required resources Scale them down when the demand falls
to fulfill a sudden demand without affecting speed and performance
Deal with unpredictable and variable loads Benefits of reduced cost and
increased user satisfaction
Security
AWS delivers end-to-end security and privacy to its customers. Its virtual infrastructure offers optimum
availability while managing full privacy for customers and isolation of their operations.
Customers can expect high physical security, and this is due to Amazon’s several years of experience in
designing, developing, and running large-scale IT operation centers.
The purpose of AWS Compliance is to enable you to understand its powerful controls in action and maintain security and
data protection.
Security
AWS provides security to their global infrastructure, along with a variety of features for securing critical data
in cloud.
Controls
Supervises
Customer
DoD Cloud Computing National Institute of Standards Payment Card Industry, or PCI
Criminal Justice Information
Security and Technology Data Security Standard DSS
Services
Requirements Guide Level 1
International Organization for US International Traffic in Section 508/Voluntary Product Federal Information
Standardization Arms Regulations Accessibility Template Processing Standard
Health Insurance
Portability The Family Educational Rights Cloud Security Alliance Motion Picture Association
and Accountability Act and Privacy Act of America
a. Scalability
b. Cost-effectiveness
c. Effortless hosting
d. Security
KNOWLEDGE
CHECK Which of the following is NOT a benefit of Amazon Web Services?
a.
Scalability
b.
Cost-effectiveness
c.
Effortless hosting
d. Security
a. scalability
b. disruptions
c. security
d. flexibility
KNOWLEDGE
CHECK The Deployed environmental systems reduce the influence of _____.
a.
scalability
b.
disruptions
c.
security
d. flexibility
1 2 3 4 5
Amazon S3 data storage infrastructure Amazon DynamoDB with 25 units each Amazon EC2 Container Registry, that
with a standard storage of 5 GB of Read and Write capacity, and 25GB facilitates storage and retrieval of
facilitating 20,000 Get Requests, and storage. It does not expire at the end Docker images with a storage capacity
2,000 Put Requests. of 12 months. of 500MB per month.
1 2 3 4 5
The benefits of the AWS Free Tier can be availed by the user for 12 months
after first signing up.
Once this free usage period expires, you will be required to Pay-As-You-Go,
as per the standard usage rates.
Any leftover free monthly usage limit does not roll over to the next month.
If you exceed the free limit for a month, you Pay-As-You-Go, as per standard
rates.
Monthly Calculator to
estimate the cost Different regions have different prices
Demo 1—Creating an Amazon Web Services (AWS) Account
(Refer to the E-Learning course: Screen Number – 2.5)
Knowledge Check
KNOWLEDGE
CHECK The AWS Management Console refers to a Web interface.
1
a. True
b. False
KNOWLEDGE
CHECK The AWS Management Console refers to a Web interface.
1
a. True
b. False
Explanation: There are five different ways to access AWS to create and manage your applications. First
is the AWS Management Console which refers to a Web interface.
KNOWLEDGE
CHECK What does Amazon Web Services provide to estimate the cost of using AWS?
2
a.
Simple Yearly Calculator
b.
Simple Quarterly Calculator
c.
Simple Monthly Calculator
d. Simple Weekly Calculator
The AWS Management Console has a user-friendly web interface, and accessing the console requires an AWS
account. It manages all the elements of a user's AWS account that include:
Current
Page
Navigation Bar
Navigation
Pane
AWS Management Console—Navigation
Access
History List
Select Region
If you regularly work with Amazon S3, placing the S3 icon on the Navigation bar would enable accessing the service
with just one click.
Selecting a Region
Some services, such as S3 and IAM, are global resources, and do not require a specific region.
Europe
Asia
North America
South America
Australia
By placing resources in distinct regions, you can design a website or application, such that it is closer to its
specific customers, and fulfills legal, contractual and other requirements.
Regions and Availability Zones
Each datacenter site is termed as a region, and each region consists of several distinct sites, termed as
Availability Zones (AZ).
IRELAND
3 2
AWS GOVCLOUD FRANKFURT BEIJING
OREGON 3 2 2 2
3 5 3 TOKYO
N. CALIFORNIA SEOUL
N. VIRGINIA
2
SINGAPORE
3
SAO PAULO 2 SYDNEY
By placing resources in different Availability Zones, you can shield your data, site, or application from the
failure at one location.
Regions and Availability Zones
IRELAND
3 2
AWS GOVCLOUD
UK FRANKFURT BEIJING
OREGON 3 2 MONTREAL
3 NINGXIA 2
2 3 TOKYO
5
N. CALIFORNIA OHIO SEOUL
N. VIRGINIA
INDIA
2
SINGAPORE
3
SAO PAULO 2 SYDNEY
# Regions
Employing multi-factor
access control systems and state- Deploying environmental
of-the-art electronic scrutiny systems
Several regions along with their Availability Zones are resilient against most failures, including even the
one due to natural disaster.
Characteristics of Region and Availability Zone
Region
Risk Assessment Availability Zone
• It is used to:
o Minimize the gap between request and response time, or latency for end-users
Region
Risk Assessment Availability Zone
• The presence of multiple availability zones enable the customers to distribute their
computing resources among several tier 1 Internet Service and Power providers.
Demo 2—Selecting a Region
(Refer to the E-Learning course: Screen Number – 2.9)
Knowledge Check
KNOWLEDGE
CHECK Which of the given feature includes six recently used services?
1
a. Navigation bar
b. Task Manager
c. Region
d. History list
KNOWLEDGE
CHECK Which of the given feature includes six recently used services?
a.
Navigation bar
b.
Task Manager
c.
Region
d. History list
a. True
b. False
KNOWLEDGE
CHECK A region should consist of minimum four Availability Zones.
2
a. True
b. False
Explanation: A region consists of minimum two Availability Zones connected through low-latency
links.
KNOWLEDGE From the following options, identify the number of Availability Zones within the current
CHECK
3 12 geographic AWS Regions.
a. 32
b. 31
c. 35
d. 36
KNOWLEDGE From the following options, identify the number of Availability Zones within the
CHECK current 12 geographic AWS Regions.
a.
32
b.
31
c.
35
d. 36
The AWS provides data security by employing state of the art datacenters and network architecture that help
you meet security related objectives such as:
Alertness Visibility
Security
Manageability Auditability
Information Security
AWS delivers the information related to the implemented security using different mediums such as:
Information Security plays a vital role in letting the customers get acquainted with AWS security controls,
and how an independent author would validate these controls.
Security Measures of AWS
Security Benefits Expert Guidance Access to Different Tools Privacy and Data Protection
AWS infrastructure is designed to offer the highest degree of data security, and robust safety mechanism.
Review
P
on routine tasks to increase security
Security Managers
Verify
Expert Guidance
Following are the expert guidance provided by Amazon Web Services.
Documentation
Products Services
Expert Guidance
AWS offers Trusted Advisor, an online tool to:
Customers seeking a single point of contact to resolve their technical queries, can always connect with their
Technical Account Manager (TAM).
Key Features of Security Tools
Monitoring and maintaining logs of access and changes in the customer’s AWS
environment.
Compliance
AWS products and services cater to different industries, and each industry adheres to their own compliance
and audit standards.
AWS Customers
Shared Responsibility Model for Security
Security
Operates
Host Operating System Virtualization Lab
Manages
Multi-Factor Authentication
Encryption Security Groups Capabilities
Shared Responsibility Model for Security
Customers
Utilize
Data Protection
Services
Datacenters
The AWS team has the expertise to design, build, and operate within large-scale datacenters, and
maintain their physical security.
Physical Security
AWS team undertakes the following key measures to ensure physical security of their facilities and
datacenters:
AWS services provide security for all supported hardware and software products using different AWS
monitoring tools.
Initiating Node
Use SSL and secured API endpoints or customer access points for encrypted transmission over HTTPS.
Allow only users and software with cryptographic keys and certificates to access an AWS API.
Control external access to EC2 instances using built-in firewalls, called security groups.
Enable multi-factor authentication or MFA with the help of hardware token or a Software app.
Offer data encryption of files and objects stored using AWS services such as Amazon S3, Amazon Glacier,
Amazon Redshift, Oracle RDS, and others.
Security Groups
AWS provides security groups that work as built-in firewalls for your virtual servers.
Security Groups
Totally public
Completely private
Creating subnets
Network Security
IAM fails to provide any solution to set application level security, and control resource level access. In case of single
user policies, it uses the least privileged model to aggregate permissions, and maintains a deny bias.
Knowledge Check
KNOWLEDGE
CHECK ____________ permits customers to recognize the strong controls in place at AWS.
1
a. Compliance
b. Cloud Security
c. Availability zones
d. Regions
KNOWLEDGE
CHECK ____________ permits customers to recognize the strong controls in place at AWS.
a. Compliance
b. Cloud Security
c. Availability zones
d. Regions
a. Security Groups
b. Physical Security
c. Compliance
a.
Security Groups
b.
Physical Security
c.
Compliance
d. Virtual Private Cloud
a. confidentiality
b. integrity
c. availability
d. security
QUIZ In the context of user data, Amazon Web Services ensures all of the following except
1 _______.
a. confidentiality
b. integrity
c. availability
d. security
Explanation: Amazon Web Services ensures confidentiality, integrity, and availability of the user’s
data.
QUIZ Which of the following services assists you in securing your systems and data in the
2 cloud?
Explanation: The product category, Security and Identity services, assists you in securing your systems
and data in the cloud.
QUIZ
Which of the following enables you to get hands-on experience with AWS?
3
a. Free Computing
b. Free Networking
c. Free Tier
d. Free Analytics
QUIZ
Which of the following enables you to get hands-on experience with AWS?
3
a. Free Computing
b. Free Networking
c. Free Tier
d. Free Analytics
Explanation: The Free Tier enables you to get hands-on experience with AWS cloud services.
QUIZ
A ___________ is a physical location in the world, which has a multiple Availability Zone.
4
a. Availability Zone
b. Data center
c. Region
d. Resource location
QUIZ
A ___________ is a physical location in the world, which has a multiple Availability Zone.
4
a. Availability Zone
b. Data center
c. Region
d. Resource location
Explanation: A Region is a physical location in the world, which has a multiple Availability Zone.
QUIZ AWS has planned to expand their real estate, with how many more Availability Zones and
5 Regions?
a. 12, 6
b. 11, 5
c. 13, 3
d. 15, 5
QUIZ AWS has planned to expand their real estate, with how many more Availability Zones and
5 Regions?
a. 12, 6
b. 11, 5
c. 13, 3
d. 15, 5
Explanation: AWS has planned to expand their real estate, with 11 more Availability Zones and 5 more
Regions coming online throughout the next year.
QUIZ
AWS replicates data between physical Regions, to avoid ________.
6
Explanation: For avoiding idle time and fault tolerance, AWS replicates data between physical Regions.
QUIZ
Which of the following is not the feature of security measures provided by AWS?
7
a. Expert Guidance
b. Product Features
c. On-Premises Security
d. Security Benefits
QUIZ
Which of the following is not the feature of security measures provided by AWS?
7
a. Expert Guidance
b. Product Features
c. On-Premises Security
d. Security Benefits
Explanation: AWS offers several measures in relation to security. It provides security benefits, expert
guidance, expert guidance, and compliance.
Key Takeaways
Key Takeaways
AWS is Amazon’s cloud computing environment offering significant advantages of flexibility,
economies of scale, scalability, and security.
1 2 3 4 5
Security Benefits Expert Guidance Access to Different Tools Privacy and Data Protection
The infrastructure of AWS resides in Amazon data centers spread across the globe. These
sites are called regions.
You can access AWS through the Management Console, the Command Line Interface,
Command Line Tools, AWS Software Development Kits, and Query APIs.
AWS provides the Simple Monthly Calculator to estimate the cost of using AWS.
Key Takeaways
AWS offers several security benefits, provides expert guidance, allows access to different tools, and
ensures complete privacy and data protection.
Amazon VPC offers you the facility to logically isolate a section of the AWS cloud, and launch AWS
resources in your defined virtual network.
This Concludes 'Introduction to AWS.'
The Next Lesson is 'Storage and Content Delivery.'