100% found this document useful (1 vote)
116 views

What Is Identity & Access Management (IAM) ?

This document defines several key AWS services and concepts: - IAM manages user accounts and access to AWS services. - CloudWatch monitors applications, resources, and metrics in AWS. - S3 provides scalable cloud storage through buckets and objects. - ECS runs containers on a managed service, allowing for scalability and reliability. - VPC creates private networks within AWS similar to virtual private networks.

Uploaded by

Ishan CompFin
Copyright
© © All Rights Reserved
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
116 views

What Is Identity & Access Management (IAM) ?

This document defines several key AWS services and concepts: - IAM manages user accounts and access to AWS services. - CloudWatch monitors applications, resources, and metrics in AWS. - S3 provides scalable cloud storage through buckets and objects. - ECS runs containers on a managed service, allowing for scalability and reliability. - VPC creates private networks within AWS similar to virtual private networks.

Uploaded by

Ishan CompFin
Copyright
© © All Rights Reserved
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 8

What is Identity & Access Management It is an AWS service that manages user

(IAM)? accounts and their access to various AWS


services.

What is a Firewall? It's a software that permits or blocks internet


traffic.

What is CloudWatch? It's AWS monitoring service. You can use it to


monitor applications and monitor network traffic,
disk space, CPU usage, etc.

What is SNS? SNS is a Simple Notification Service. You can


use SNS with CloudWatch and CloudTrail.

What is Consolidated Billing? It allows you to manage billing for multiple


account using a central account.

What is AWS ECS? Amazon Elastic Container Service (Amazon


ECS) is a fully managed container orchestration
service. Customers such as Duolingo,
Samsung, GE, and Cook Pad use ECS to run
their most sensitive and mission critical
applications because of its security, reliability,
and scalability.

What is AWS? AWS is a cloud service provider.

What is the Cloud? In the simplest terms, cloud computing means


storing and accessing data and programs over
the Internet instead of your computer's hard
drive.
What is Fault Tolerance?
Fault tolerance is the property that enables a system to continue operating properly in the event of
the failure of some of its components.

What is High Availability?


The ability to access something whenever you wish to do so and be available for you.

What is Scalability?
The ability to grow in size or number when needed.

What is Elasticity?
The ability to grow and reduce in size when needed.

What is S3?
It is AWS Simple Storage Service. It's like that Big Container in your house where you store
everything in.

What are root level folders in S3 Called?


Buckets

What are files uploaded to S3 referred to as?


Objects
List S3 Storage Classes
1. Standard
2. Standard-IA
3. One Zone-IA
4. Intelligent Tiering
5. Glacier

What is Object Durability?


The % over a 1 year time that your file will not be LOST.
What is Object Availability?
The % over a 1 year time that your file will be ACCESSIBLE.
What is Object Sharing?
The ability to make any object available via a URL link on the web.
What is Object LifeCycles?
The ability to set rules to automatically transfer objects between different storage classes at
defined time intervals.
What is Object Versioning?
The ability to keep multiple versions of the same object.
What is Virtual Private Cloud (VPC)?
It's a private section of AWS that you control. It's basically a Virtual Network (VNet).
What is a Subnet?
It's a subsection (partition) of a network. In the context of AWS, it's a partition of a VPC.
What is a Network Access Control List (NACL)?
It's a firewall that control access to a subnet.
What is a Security Group?
It's a firewall the control access to a server (EC2).
What is EC2?
It's amazon primarily computing service. Think of it like a Linux or Windows server.
What is AMI?
It's EC2 Amazon Machine Images.
What are the three EC2 Buying Options?
1. On-Demand.
2. Reserved.
3. Spot Pricing.
4. Dedicated Hosts.
What is Lambda?
It's AWS serverless computing service. Run code on-Demand.
What is Elastic Load Balancing (ELB)?
ELB evenly distributes traffic among various EC2 instances. It improves High Availability and Fault
Tolerance.
What is Auto Scaling?
The process of adding or removing EC2 instances based on demand. It improves Scalability and
Elasticity.
What is DNS?
It's the Domain Name System. It's a service that translates (resolves) domain names to IP
addresses.
What is Route 53?
It's an AWS service that manages domains for websites and other web applications.
List Four things that Route 53 does.
1. Domain Registration.
2. DNS Routing.
3. Health Checking.
4. Traffic Management.
What is CloudFront?
It's a Fast Content Delivery Network (CDN) that allows you to cache your content and store in
different edge locations for faster delivery. It also protects against DDOS Attacks.
What is CloudTrail?
It's AWS logging and auditing service. You can use it to track user actions on your system.
What is RDS?
It's AWS relational database service (SQL).
What is DynamoDB?
It's AWS non-relational database service (NoSQL).
What is ElastiCache?
It's a data caching service that improves the speed of web apps.
What is Redshift?
It's a data warehouse database service designed to handle perabytes of data for analysis
(structured data, business intelligence).
What is AWS Organization?
It allows you to manage multiple user accounts in one interface.
What are the three AWS pricing model?
Pay As You Go.
Pay Less When You Reserve.
Pay Less By Using More.
What is TCO?
Total Cost of Ownership calculator, helps you predict the cost of Migration to AWS.
What is Cost Explorer?
It helps you analyze your spending and also forecast future costs.
What is the Shared Responsibility Mode?
The things that you are (customer) responsible for vs. the things that AWS is responsible for.
What is DDOS?
A Distributed Denial Of Service (DDoS) attack that occurs when multiple systems attack a single
system at the same time.
What is Penetration Testing?
Scanning and testing a system for vulnerabilities with tools like Nmap and Metasploit.
What is AWS Trusted Advisor?
A service that inspects your environment and makes recommendations when opportunities exist to
save money, improve system availability and performance, or help close security gaps.
What is AWS White Papers?
Technical documents to explain relevant AWS topics.
What is AWS Service Documentation?
Collection of technical documents specific to describe the use of each AWS service.
List the four AWS account support plans:
1. Basic
2. Developer.
3. Business.
4. Enterprise.
What is AWS CloudFormation?
A service that helps you model and set up your AWS resources based on a JSON template. It
allows organizations to deploy, modify, and update resources in a controlled and predictable way.
CloudFormation is a powerful Infrastructure as Code tool that can help automate and manage your
AWS deployments.
What is EFS (Elastic File System)?
Amazon Elastic File System (Amazon EFS) is a storage service that provides a scalable, elastic,
shared file system for use with AWS Cloud services and on-premises resources. EFS uses the
NFS protocol.
AWS Support Concierge
The Concierge team will quickly and efficiently assist you with your billing and account inquiries,
and work with you to help implement billing and account best practices so that you can focus on
running your business.
What is AWS OpsWorks?
AWS OpsWorks is a configuration management service that provides managed instances of Chef
and Puppet.
What is AWS Quick Start Reference Deployments?
It outlines the architectures for popular enterprise solutions on AWS and provide AWS
CloudFormation templates to automate their deployment.
What is AWS Artifact?
AWS Artifact is a self-service audit artifact retrieval portal that provides our customers with on-
demand access to AWS' compliance documentation and AWS agreements.
What is Amazon SQS?
Amazon Simple Queue Service (SQS) is a fully managed message queuing service that enables
you to decouple and scale microservices, distributed systems, and serverless applications.
What is AWS EMR?
Amazon Elastic MapReduce (EMR) is an Amazon Web Services (AWS) tool for big data
processing and analysis. Amazon EMR offers the expandable low-configuration service as an
easier alternative to running in-house cluster computing.
What is AWS KMS?
It is a secure and resilient service that uses hardware security modules that have been validated
under FIPS 140-2, or are in the process of being validated, to protect your keys. AWS KMS is
integrated with AWS CloudTrail to provide you with logs of all key usage to help meet your
regulatory and compliance needs.
What is the AWS Abuse Team?
The AWS Abuse team can assist you when AWS resources are being used to engage in the
following types of abusive behaviour: Spam: You are receiving unwanted emails from an AWS-
owned IP address, or AWS resources are being used to spam websites or forums.
What is AWS Shield?
AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards
applications running on AWS.
What is TAM (Technical Account Manager)?
TAM is the primary point of contact for ongoing support needs, and you have a direct telephone
line to your TAM.
What is Vertical Scaling?
Auto Scaling by increasing (or decreasing) computing power (CPU, RAM) to an existing machine.
What is Horizontal Scaling?
Auto Scaling by adding (or removing) machines into your pool of resources.
What is AWS EBS (Elastic Block Store)?
Amazon Elastic Block Store provides raw block-level storage that can be attached to Amazon EC2
instances and is used by Amazon Relational Database Service.
What is SPOF?
A single point of failure (SPOF) is a part of a system that, if it fails, will stop the entire system from
working.
What is Amazon Athena?
Amazon Athena is an interactive query service that makes it easy to analyze data in Amazon S3
using standard SQL. Athena is serverless, so there is no infrastructure to setup or manage, and
you can start analyzing data immediately.
What is APN Consulting Partners?
APN Consulting Partners are professional services firms that help customers of all types and sizes
design, architect, build, migrate, and manage their workloads and applications on AWS,
accelerating their journey to the cloud. These professional services firms include system
integrators, strategic consultancies, agencies, managed service providers (MSPs), and value-
added resellers.
What is APN Technology Partners?
APN Technology Partners provide hardware, connectivity services, or software solutions that are
hosted on, or integrated with, the AWS Cloud. APN Technology Partners gain access to a variety
of trainings, programs, tools, resources, and support to help you build, market, and sell your
offerings with APN.
What is AWS WAF?
AWS WAF is a web application firewall that helps protect your web applications or APIs against
common web exploits that may affect availability, compromise security, or consume excessive
resources. AWS WAF also protects against SQL injection and cross-site scripting attacks.
What is AWS Elastic Beanstalk?
AWS Elastic Beanstalk is an orchestration service offered by Amazon Web Services for deploying
applications which orchestrates various AWS services, including EC2, S3, Simple Notification
Service, CloudWatch, autoscaling, and Elastic Load Balancers.
What is AWS CodePipeline?
AWS CodePipeline is a fully managed continuous delivery service that helps you automate your
release pipelines for fast and reliable application and infrastructure updates. You can easily
integrate AWS CodePipeline with third-party services such as GitHub or with your own custom
plugin.
Whatis AWS X-Ray?
AWS X-Ray helps developers analyze and debug production, distributed applications, such as
those built using a microservices architecture. With X-Ray, you can understand how your
application and its underlying services are performing to identify and troubleshoot the root cause
of performance issues and errors. X-Ray provides an end-to-end view of requests as they travel
through your application, and shows a map of your application's underlying components. You can
use X-Ray to analyze both applications in development and in production, from simple three-tier
applications to complex microservices applications consisting of thousands of services.
What is Amazon Cloud9?
AWS Cloud9 is a cloud-based integrated development environment (IDE) that lets you write, run,
and debug your code with just a browser. It includes a code editor, debugger, and terminal.
Cloud9 comes prepackaged with essential tools for popular programming languages, including
JavaScript, Python, PHP, and more, so you don't need to install files or configure your
development machine to start new projects.
What is AWS Direct Connect?
AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated private
network connection from your premises to AWS.
What is AWS VPN?
AWS Virtual Private Network (AWS VPN) lets you establish a secure and private encrypted tunnel
from your network or device to the AWS global network. AWS VPN is comprised of two services:
AWS Site-to-Site VPN and AWS Client VPN.
What is AWS Snowball?
Snowball is a petabyte-scale data transport solution that uses devices designed to be secure to
transfer large amounts of data into and out of the AWS Cloud.
What is BYOL?
Bring licenses to AWS. For example, If you've already purchased Microsoft software, bring your
own licenses (BYOL) to the AWS Cloud.
What is CloudEndure?
CloudEndure Migration simplifies the process of migrating applications from physical, virtual, and
cloud-based infrastructure, ensuring that they are fully operational in any AWS Region without
compatibility issues.
What is Amazon Neptune?
Amazon Neptune is a fast, reliable, fully managed graph database service that makes it easy to
build and run applications that work with highly connected datasets.
What is Amazon Aurora?
Amazon Aurora is a fully managed relational database engine that's compatible with MySQL and
PostgreSQL.
What is Amazon Inspector?
Amazon Inspector is an automated security assessment service that helps improve the security
and compliance of applications deployed on AWS. Amazon Inspector automatically assesses
applications for exposure, vulnerabilities, and deviations from best practices.
What is IaaS (Infrastructure-as-a-Service)?
Infrastructure-as-a-service (IaaS), also known as cloud infrastructure services, is a form of cloud
computing in which infrastructure services are provided to the user via a cloud, through the
internet. The user handles any applications, data, operating system(s), middleware, and
runtimes.The user relies on the provider to manage the virtualization, storage, network, and
servers for them. This way, the user doesn't have to have an on-site datacenter and doesn't have
to worry about physically updating or maintaining these components themselves—it's all handled
by the provider.
What is PaaS (Platform-as-a-Service)?
Platform-as-a-service (PaaS) is a form of cloud computing where hardware and an application
software platform is provided by another party. Primarily for developers and programmers, a PaaS
allows the user to develop, run, and manage their own apps without having to build and maintain
the infrastructure or platform usually associated with the process.
What is SaaS (Software-as-a-Service)?
Software as a service (SaaS) is a cloud computing offering that provides users with access to a
vendor's cloud-based software. Users do not install applications on their local devices. Instead, the
applications reside on a remote cloud network accessed through the web or an API. Through the
application, users can store and analyze data and collaborate on projects.
What is MFA?
Multifactor authentication (MFA) is a security system that requires more than one method of
authentication from independent categories of credentials to verify the user's identity for a login or
other transaction.

Multifactor authentication combines two or more independent credentials: what the user knows
(password), what the user has (security token) and what the user is (biometric verification).
What is AWS Batch?
AWS Batch enables you to run batch computing workloads on the AWS Cloud. Batch computing is
a common way for developers, scientists, and engineers to access large amounts of compute
resources, and AWS Batch removes the undifferentiated heavy lifting of configuring and managing
the required infrastructure, similar to traditional batch computing software. This service can
efficiently provision resources in response to jobs submitted in order to eliminate capacity
constraints, reduce compute costs, and deliver results quickly.
What is an AWS region?
A region is a geographical area that consists of different availability zones. Each region consists of
2 (or more) Availability Zones.
What is an Availability Zone?
An Availability Zone (AZ) is one or more discrete data centers with redundant power, networking,
and connectivity in an AWS Region.
What is AWS CLI?
The AWS Command Line Interface (AWS CLI) is an open source tool that enables you to interact
with AWS services using commands in your command-line shell.
What is Amazon Cognito?
Amazon Cognito provides authentication, authorization, and user management for your web and
mobile apps. Your users can sign in directly with a user name and password, or through a third
party such as Facebook, Amazon, Google or Apple.
What is Amazon SES?
Amazon Simple Email Service (Amazon SES) is a cloud-based email sending service designed to
help digital marketers and application developers send marketing, notification, and transactional
emails. It is a reliable, cost-effective service for businesses of all sizes that use email to keep in
contact with their customers.
What is AWS IoT?
AWS IoT (Internet of Things) provides secure, bi-directional communication between Internet-
connected devices such as sensors, actuators, embedded micro-controllers, or smart appliances
and the AWS Cloud. This enables you to collect telemetry data from multiple devices, and store
and analyze the data. You can also create applications that enable your users to control these
devices from their phones or tablets.
What is Public Cloud?
Public clouds are cloud environments typically created from IT infrastructure not owned by the end
user. Some of the largest public cloud providers include Alibaba Cloud, Amazon Web Services
(AWS), Google Cloud, IBM Cloud, and Microsoft Azure.
What is On-Premises (Private Cloud)?
Deploying resources on-premises, using virtualization and resource management tools, is
sometimes called "private cloud". On-premises deployment does not provide many of the benefits
of cloud computing but is sometimes sought for its ability to provide dedicated resources. In most
cases this deployment model is the same as legacy IT infrastructure while using application
management and virtualization technologies to try and increase resource utilization.
What is Hybrid Cloud?
A hybrid deployment is a way to connect infrastructure and applications between cloud-based
resources and existing resources that are not located in the cloud. The most common method of
hybrid deployment is between the cloud and existing on-premises infrastructure to extend, and
grow, an organization's infrastructure into the cloud while connecting cloud resources to internal
system
What are Access Keys?
Access keys are long-term credentials for an IAM user or the AWS account root user. You can use
access keys to sign programmatic requests to the AWS CLI or AWS API (directly or using the
AWS SDK).
What is AWS Budgets?
AWS Budgets gives you the ability to set custom budgets that alert you when your costs or usage
exceed (or are forecasted to exceed) your budgeted amount.
What is an IAM policy?
A policy is an object in AWS that, when associated with an identity or resource, defines their
permissions. AWS evaluates these policies when an IAM principal (user or role) makes a request.
Permissions in the policies determine whether the request is allowed or denied.
What is an IAM role?
An IAM role is an IAM identity that you can create in your account that has specific permissions.
An IAM role is similar to an IAM user, in that it is an AWS identity with permission policies that
determine what the identity can and cannot do in AWS.

You might also like