# AWS Associate Certifications

*2024-03-22*

> Notes from studying for the AWS Associate certifications


I've started my [AWS certification journey]({{< relref "posts/2024/getting-aws-certified" >}}) and I've been working through the three AWS Associate certifications on [Pluralsight](https://www.pluralsight.com/):

- [AWS Certified SysOps Administrator – Associate](https://www.pluralsight.com/paths/aws-certified-sysops-admin-associate)
- [AWS Certified Developer – Associate](https://www.pluralsight.com/paths/aws-certified-developer-associate-dva-c01)
- [AWS Certified Solutions Architect - Associate](https://www.pluralsight.com/paths/aws-certified-solutions-architect-associate-saa-c03)

I deliberately started with SysOps and Developer to build practical, hands-on depth before moving on to the broader architectural concepts in Solutions Architect. These are my condensed notes – the key concepts and exam tips that stuck with me. Since I already had a solid grasp of the fundamentals, this page is lighter than a full course summary, but I hope it complements your own study plan.

---

## Contents

1. [Designing Secure Architectures](#designing-secure-architectures)
2. [Designing Resilient Architectures](#designing-resilient-architectures)
3. [Designing High Performing Architectures](#designing-high-performing-architectures)
4. [Designing Cost-Optimised Architectures](#designing-cost-optimised-architectures)

## Designing Secure Architectures{#designing-secure-architectures}

**Network ACLs (NACLs)**
- Every subnet must be associated with a NACL; if you don't explicitly assign one, it inherits the default NACL.

**AWS Network Firewall**
- Fully managed by AWS; used for VPC-to-VPC traffic inspection and logically separating networks.

**Security Groups**
- You can attach up to 5 security groups per EC2 instance.
- Know your ports: 22 for SSH, 443 for HTTPS.

**Subnets**
- Subnets use the VPC's main route table unless explicitly associated with a custom one.
- Each subnet lives in exactly one Availability Zone.
- A subnet whose traffic routes to an Internet Gateway is a *public* subnet.
- Virtual Private Gateways are for site-to-site connectivity, not internet access – that's the IGW's job.

**RDS credentials**
- IAM database authentication lets you attach role-based credentials to EC2 instances instead of managing passwords.

**Cloud security posture management**
- **AWS Security Hub** – CSPM with automated remediation support.
- **Amazon GuardDuty** - threat detection; ingests CloudTrail logs, DNS logs, EKS audit logs, and VPC flow logs.

**Multi-account management**
- **AWS Organizations** gives you a hierarchical structure of accounts; **Identity Center** centralises identity across them.
- **Control Tower** deploys a Log Archive account for centralised security logging and an Audit account for SNS notifications on policy violations.

## Designing Resilient Architectures{#designing-resilient-architectures}

**RDS**
- Understand the difference between Multi-AZ (synchronous standby for failover) and Read Replicas (async copies for scaling reads and cross-region DR).

**EC2 metadata and user data**
- Both are reachable at `http://169.254.169.254/latest/...` (`meta-data/` and `user-data/`). With IMDSv2, requests must first obtain a session token.

**Databases & integration**
- **DynamoDB** is a great fit for storing web session data.
- **Amazon AppFlow** moves data between SaaS providers (Salesforce, Slack, etc.) and AWS services with no code.
- **EKS on-premises** runs on the Amazon EKS Distro.

**Monitoring**
- CloudWatch does **not** track memory, swap, disk space, or page file utilisation out of the box – these require custom metrics (via the CloudWatch agent) or collected logs.
- AWS Health events can drive automation: EventBridge rule triggered by AWS Health → Lambda function → act on EC2 instances.

**CloudFront secure delivery**
- A handful of files → **signed URLs**.
- Hundreds of files → **signed cookies**.

## Designing High-Performing Architectures{#designing-high-performing-architectures}

**Load balancers**
- **NLB** operates at Layer 4 – handles millions of requests with ultra-low latency.
- **ALB** operates at Layer 7 – more routing intelligence, lower raw throughput.

**Machine learning building blocks**
- Know which service is which: **Polly** (text-to-speech), **Lex** (conversational interfaces), **Transcribe** (speech-to-text).

**Disaster recovery math**
- RTO ~1 hour, RPO ~15 minutes, multi-region → a **cross-region read replica** fits.
- Single region, availability-focused → **Multi-AZ**.

**Compute placement & scaling**
- Placement groups: low-latency, high-throughput workloads belong in a **cluster** placement group.
- Auto Scaling default cooldown is 300 seconds (5 minutes).

**Data streaming**
- Kinesis Data Firehose delivers to destinations like OpenSearch, S3, and (via S3) Athena for querying.
- SNS supports **filter policies**, letting you route messages selectively to SQS queues.

**Storage**
- EBS volume families worth knowing: `gp3` (general purpose SSD), `io1`/`io2 Block Express` (high-performance provisioned IOPS).

**Big data orchestration**
- **EMR** is the managed big-data cluster platform; **Step Functions** can orchestrate EMR jobs (start clusters, run steps, terminate).

## Designing Cost-Optimised Architectures{#designing-cost-optimised-architectures}

- **Cost and Usage Reports** can be exported as CSV to S3 for granular analysis.
- Commitment-based savings: watch for plans like **All Upfront SageMaker Savings Plans** – when a question specifies a single service and usage level, savings plans usually beat RI-style purchases.
- **Site-to-Site VPN** reuses your existing VPN equipment – far cheaper than a Direct Connect for smaller budgets.
- Set a **billing alarm** to catch charges crossing a threshold.
- **S3 Standard-IA** beats Glacier-class storage when retrieval frequency is high enough that retrieval fees outweigh storage savings.

---

Happy studying – good luck with the exams!
