AWS Associate Certifications

·4 min read·Graham Mace
AWS Associate Certifications

I’ve started my AWS certification journey and I’ve been working through the three AWS Associate certifications on Pluralsight:

I deliberately started with SysOps and Developer to build practical, hands-on depth before moving on to the broader architectural concepts in Solutions Architect. These are my condensed notes – the key concepts and exam tips that stuck with me. Since I already had a solid grasp of the fundamentals, this page is lighter than a full course summary, but I hope it complements your own study plan.


Contents

  1. Designing Secure Architectures
  2. Designing Resilient Architectures
  3. Designing High Performing Architectures
  4. Designing Cost-Optimised Architectures

Designing Secure Architectures

Network ACLs (NACLs)

  • Every subnet must be associated with a NACL; if you don’t explicitly assign one, it inherits the default NACL.

AWS Network Firewall

  • Fully managed by AWS; used for VPC-to-VPC traffic inspection and logically separating networks.

Security Groups

  • You can attach up to 5 security groups per EC2 instance.
  • Know your ports: 22 for SSH, 443 for HTTPS.

Subnets

  • Subnets use the VPC’s main route table unless explicitly associated with a custom one.
  • Each subnet lives in exactly one Availability Zone.
  • A subnet whose traffic routes to an Internet Gateway is a public subnet.
  • Virtual Private Gateways are for site-to-site connectivity, not internet access – that’s the IGW’s job.

RDS credentials

  • IAM database authentication lets you attach role-based credentials to EC2 instances instead of managing passwords.

Cloud security posture management

  • AWS Security Hub – CSPM with automated remediation support.
  • Amazon GuardDuty - threat detection; ingests CloudTrail logs, DNS logs, EKS audit logs, and VPC flow logs.

Multi-account management

  • AWS Organizations gives you a hierarchical structure of accounts; Identity Center centralises identity across them.
  • Control Tower deploys a Log Archive account for centralised security logging and an Audit account for SNS notifications on policy violations.

Designing Resilient Architectures

RDS

  • Understand the difference between Multi-AZ (synchronous standby for failover) and Read Replicas (async copies for scaling reads and cross-region DR).

EC2 metadata and user data

  • Both are reachable at http://169.254.169.254/latest/... (meta-data/ and user-data/). With IMDSv2, requests must first obtain a session token.

Databases & integration

  • DynamoDB is a great fit for storing web session data.
  • Amazon AppFlow moves data between SaaS providers (Salesforce, Slack, etc.) and AWS services with no code.
  • EKS on-premises runs on the Amazon EKS Distro.

Monitoring

  • CloudWatch does not track memory, swap, disk space, or page file utilisation out of the box – these require custom metrics (via the CloudWatch agent) or collected logs.
  • AWS Health events can drive automation: EventBridge rule triggered by AWS Health → Lambda function → act on EC2 instances.

CloudFront secure delivery

  • A handful of files → signed URLs.
  • Hundreds of files → signed cookies.

Designing High-Performing Architectures

Load balancers

  • NLB operates at Layer 4 – handles millions of requests with ultra-low latency.
  • ALB operates at Layer 7 – more routing intelligence, lower raw throughput.

Machine learning building blocks

  • Know which service is which: Polly (text-to-speech), Lex (conversational interfaces), Transcribe (speech-to-text).

Disaster recovery math

  • RTO ~1 hour, RPO ~15 minutes, multi-region → a cross-region read replica fits.
  • Single region, availability-focused → Multi-AZ.

Compute placement & scaling

  • Placement groups: low-latency, high-throughput workloads belong in a cluster placement group.
  • Auto Scaling default cooldown is 300 seconds (5 minutes).

Data streaming

  • Kinesis Data Firehose delivers to destinations like OpenSearch, S3, and (via S3) Athena for querying.
  • SNS supports filter policies, letting you route messages selectively to SQS queues.

Storage

  • EBS volume families worth knowing: gp3 (general purpose SSD), io1/io2 Block Express (high-performance provisioned IOPS).

Big data orchestration

  • EMR is the managed big-data cluster platform; Step Functions can orchestrate EMR jobs (start clusters, run steps, terminate).

Designing Cost-Optimised Architectures

  • Cost and Usage Reports can be exported as CSV to S3 for granular analysis.
  • Commitment-based savings: watch for plans like All Upfront SageMaker Savings Plans – when a question specifies a single service and usage level, savings plans usually beat RI-style purchases.
  • Site-to-Site VPN reuses your existing VPN equipment – far cheaper than a Direct Connect for smaller budgets.
  • Set a billing alarm to catch charges crossing a threshold.
  • S3 Standard-IA beats Glacier-class storage when retrieval frequency is high enough that retrieval fees outweigh storage savings.

Happy studying – good luck with the exams!

Related Posts