AWS Associate Certifications

I’ve started my AWS certification journey and I’ve been working through the three AWS Associate certifications on Pluralsight:
- AWS Certified SysOps Administrator – Associate
- AWS Certified Developer – Associate
- AWS Certified Solutions Architect - Associate
I deliberately started with SysOps and Developer to build practical, hands-on depth before moving on to the broader architectural concepts in Solutions Architect. These are my condensed notes – the key concepts and exam tips that stuck with me. Since I already had a solid grasp of the fundamentals, this page is lighter than a full course summary, but I hope it complements your own study plan.
Contents
- Designing Secure Architectures
- Designing Resilient Architectures
- Designing High Performing Architectures
- Designing Cost-Optimised Architectures
Designing Secure Architectures
Network ACLs (NACLs)
- Every subnet must be associated with a NACL; if you don’t explicitly assign one, it inherits the default NACL.
AWS Network Firewall
- Fully managed by AWS; used for VPC-to-VPC traffic inspection and logically separating networks.
Security Groups
- You can attach up to 5 security groups per EC2 instance.
- Know your ports: 22 for SSH, 443 for HTTPS.
Subnets
- Subnets use the VPC’s main route table unless explicitly associated with a custom one.
- Each subnet lives in exactly one Availability Zone.
- A subnet whose traffic routes to an Internet Gateway is a public subnet.
- Virtual Private Gateways are for site-to-site connectivity, not internet access – that’s the IGW’s job.
RDS credentials
- IAM database authentication lets you attach role-based credentials to EC2 instances instead of managing passwords.
Cloud security posture management
- AWS Security Hub – CSPM with automated remediation support.
- Amazon GuardDuty - threat detection; ingests CloudTrail logs, DNS logs, EKS audit logs, and VPC flow logs.
Multi-account management
- AWS Organizations gives you a hierarchical structure of accounts; Identity Center centralises identity across them.
- Control Tower deploys a Log Archive account for centralised security logging and an Audit account for SNS notifications on policy violations.
Designing Resilient Architectures
RDS
- Understand the difference between Multi-AZ (synchronous standby for failover) and Read Replicas (async copies for scaling reads and cross-region DR).
EC2 metadata and user data
- Both are reachable at
http://169.254.169.254/latest/...(meta-data/anduser-data/). With IMDSv2, requests must first obtain a session token.
Databases & integration
- DynamoDB is a great fit for storing web session data.
- Amazon AppFlow moves data between SaaS providers (Salesforce, Slack, etc.) and AWS services with no code.
- EKS on-premises runs on the Amazon EKS Distro.
Monitoring
- CloudWatch does not track memory, swap, disk space, or page file utilisation out of the box – these require custom metrics (via the CloudWatch agent) or collected logs.
- AWS Health events can drive automation: EventBridge rule triggered by AWS Health → Lambda function → act on EC2 instances.
CloudFront secure delivery
- A handful of files → signed URLs.
- Hundreds of files → signed cookies.
Designing High-Performing Architectures
Load balancers
- NLB operates at Layer 4 – handles millions of requests with ultra-low latency.
- ALB operates at Layer 7 – more routing intelligence, lower raw throughput.
Machine learning building blocks
- Know which service is which: Polly (text-to-speech), Lex (conversational interfaces), Transcribe (speech-to-text).
Disaster recovery math
- RTO ~1 hour, RPO ~15 minutes, multi-region → a cross-region read replica fits.
- Single region, availability-focused → Multi-AZ.
Compute placement & scaling
- Placement groups: low-latency, high-throughput workloads belong in a cluster placement group.
- Auto Scaling default cooldown is 300 seconds (5 minutes).
Data streaming
- Kinesis Data Firehose delivers to destinations like OpenSearch, S3, and (via S3) Athena for querying.
- SNS supports filter policies, letting you route messages selectively to SQS queues.
Storage
- EBS volume families worth knowing:
gp3(general purpose SSD),io1/io2 Block Express(high-performance provisioned IOPS).
Big data orchestration
- EMR is the managed big-data cluster platform; Step Functions can orchestrate EMR jobs (start clusters, run steps, terminate).
Designing Cost-Optimised Architectures
- Cost and Usage Reports can be exported as CSV to S3 for granular analysis.
- Commitment-based savings: watch for plans like All Upfront SageMaker Savings Plans – when a question specifies a single service and usage level, savings plans usually beat RI-style purchases.
- Site-to-Site VPN reuses your existing VPN equipment – far cheaper than a Direct Connect for smaller budgets.
- Set a billing alarm to catch charges crossing a threshold.
- S3 Standard-IA beats Glacier-class storage when retrieval frequency is high enough that retrieval fees outweigh storage savings.
Happy studying – good luck with the exams!
Related Posts
2024-03-06
2024-01-07