Quick Reference

service name · mnemonic · keywords

Full explanations → Deep Notes
DOMAIN 1 · 30% OF EXAM

Design Secure Architectures

IAM & Identity · Network Security · Data Protection · Connectivity

🔑IAM & IdentityDeep Notes →↑ Top
D1 · Secure
IAMAWS Identity and Access Management
"Siapa boleh buat apa dalam AWS"

Control who can access what AWS resources

Principalentiti yang hantar request (User, Role, atau AWS service). Hanya Principal boleh "buat" sesuatu

Useridentiti KEKAL untuk 1 orang/app. Ada credentials sendiri (password + access keys long-term)

Groupbakul untuk kumpul Users. BUKAN identity — tak boleh login, tak boleh jadi Principal. Attach policy kat sini (best practice)

+4 more → Deep Notes
usersgroupsrolespoliciesleast privilegeMFAprincipalsidentity federationIAM RoleIAM UserIAM Groupidentity-based policyresource-based policypermission boundarySCPexplicit denyimplicit denypolicy evaluationservice-linked rolerole chainingsession policycross-account accessPrincipalPrincipal *anonymous accesspublic accesspolicy anatomyEffect Action Resourcesource accountdestination accounttwo keysdouble-checkbucket policyqueue policykey policyABACRBACattribute-based access controltag-based accessaws:PrincipalTagaws:ResourceTagscale permissionspermissions boundary delegateiam:PermissionsBoundaryprivilege escalationdelegate role creationconfused deputyaws:SourceArnaws:SourceAccountcross-servicetrust policy conditioncredential reportaccess advisorlast accessedunused permissionsstale credentialspricing
D1 · Secure
STSAWS Security Token Service
"Pinjam IC sementara — short-lived credentials, auto-expire"

Generate temporary security credentials

temporary credentialsAssumeRoleAssumeRoleWithSAMLAssumeRoleWithWebIdentityGetSessionTokenGetFederationTokencross-accountrole chainingsession policyfederationauto-expire
D1 · Secure
Directory ServiceAWS Directory Service
"Active Directory dalam AWS — tiga jenis, pilih ikut use case"

Managed Microsoft Active Directory, AD Connector, or Simple AD for AWS workloads

Active DirectoryManaged Microsoft ADAD ConnectorSimple ADLDAPKerberosGroup Policyon-premises ADpricing
D1 · Secure
IAM Identity CenterAWS IAM Identity Center (SSO)
"Satu login, semua AWS accounts"

Centralized SSO untuk multiple AWS accounts

Identity sourcedari mana user datang: built-in directory, AWS Managed Microsoft AD, atau external IdP (Okta, Entra ID/Azure AD) via SAML 2.0.

Permission Setkoleksi IAM policies (macam "role template") yang define apa user boleh buat. Contoh: AdministratorAccess, ReadOnly, atau custom. Permission set ni dirender jadi IAM role dalam tiap assigned account.

Account assignmentmap (User/Group) × (Permission Set) × (AWS Account). Ni yang tentukan siapa boleh masuk account mana dengan kebenaran apa.

+1 more → Deep Notes
SSOsingle sign-onmultiple accountsfederationSAML 2.0Active DirectorySaaS integrationEC2 WindowsFleet Managerpermission setaccount assignmentaccess portaltemporary credentialsworkforce identityOktaEntra IDpricing
D1 · Secure
IAM Access AnalyzerAWS IAM Access Analyzer
"Pengawal yang jerit bila ada pintu kau terbuka ke luar"

Detect resources yang ter-expose ke public / account luar / Org luar

External Access findingsresource (S3/role/KMS/SQS/Lambda/Secrets) yang boleh diakses dari LUAR zone of trust (public / account lain / Org lain). FREE.

Unused Access findingsIAM role/user, access key, atau permission yang tak digunakan dalam tempoh tertentu — untuk right-size ke least privilege. BAYAR per resource.

Policy validationsemak policy lawan IAM best practice + grammar semasa kau tulis (>100 checks).

+1 more → Deep Notes
IAM Access Analyzerexternal accessunused accesszone of trustpublic accesscross-account exposureresource shared externalautomated reasoningprovable securitypolicy validationpolicy generationleast privilegefindingsarchive findingsAccess Analyzer vs GuardDutyAccess Analyzer vs Configpricing
D1 · Secure
AWS RAMAWS Resource Access Manager
"Kongsi resource antara account — tak payah buat salinan"

Share AWS resources merentas account / OU dalam Organization

Resource sharebekas yang kau letak resource + senarai principal (account/OU/Org) yang dibenarkan.

Owner accountyang MEMILIKI & urus resource; kekal kawal penuh.

Consumer/participant accountyang dikongsikan; boleh GUNA resource (cth launch EC2 dalam subnet kongsi) tapi tak boleh ubah/padam resource.

+1 more → Deep Notes
AWS RAMResource Access Managershare resourcesVPC sharingshared subnetsTransit Gateway sharingRoute 53 Resolver rulescross-account sharingresource shareOrganizations sharingcentral VPCowner consumerpricingfree
D1 · Secure
IAM Roles AnywhereAWS IAM Roles Anywhere
"Server luar AWS (on-prem) dapat temp IAM creds guna sijil X.509 — bukan access key"

Give on-prem / non-AWS servers temporary AWS credentials without access keys

IAM Roles Anywhereon-premisesX.509 certificatetrust anchorhybridtemporary credentialsno access keysnon-AWS workloadPrivate CAprofileoutside AWSpricing
D1 · Secure
AWS ArtifactAWS Artifact
"Self-service muat turun laporan pematuhan AWS (SOC, ISO, PCI)"

Download AWS compliance reports & accept agreements

AWS Artifactcompliance reportsSOCISO 27001PCI DSSFedRAMPBAAHIPAAGDPR DPAaudit reportsshared responsibilityagreementsfree
D1 · Secure
CognitoAmazon Cognito
"Login untuk user apps — User Pool = siapa kau, Identity Pool = boleh buat apa"

User sign-up/sign-in, federated identity (Google/Facebook), mobile app auth

User PoolsIdentity PoolsOAuthJWTfederated identityMFASTStemp credentialsOIDCSAMLauthenticationauthorizationguest access
D1 · Secure
RAMAWS Resource Access Manager
"Share AWS resources antara accounts tanpa copy"

Share subnets, Transit Gateway, Route 53 resolver rules cross-account

cross-account sharingshared subnetsTransit Gateway sharingno resource duplicationAWS Organizationscentralized resources
D1 · Secure
AWS OrganizationsAWS Organizations + Control Tower + SCPs
"HQ yang kawal semua anak syarikat"

Manage multiple AWS accounts centrally with guardrails

multi-accountSCPsguardrailsControl Towermanagement accountOUmanagement account exemptionSCP cannot grantS3 Block Public Access SCPpricingfreeconsolidated billingvolume discountlanding zoneAccount Factorydrift detectiongoverned baselinemandatory guardrailelective guardrailprovision accounts at scalemember accountFinance accountDev accountProd accountblast radiusaccount hierarchyRoot userpayer accountaccount drift notificationsdrift notification SNSmonitor OU changesOU hierarchy changes
🛡️Network SecurityDeep Notes →↑ Top
D1 · Secure
Security GroupsVPC Security Groups
"Bodyguard EC2 — stateful, allow only, ingat connections"

Instance-level firewall — control inbound/outbound per EC2/ENI

statefulinstance-levelallow onlycustom SG defaultinbound deniedoutbound allowed
D1 · Secure
NACLsNetwork Access Control Lists
"Guard kat pintu masuk subnet — check both ways"

Subnet-level firewall, stateless, boleh block IP

statelesssubnet-levelallow & denynumbered rulesexplicit both waysephemeral portsexplicit denyblock IPSG vs NACL
D1 · Secure
WAFAWS Web Application Firewall
"Penapis website dari serangan Layer 7"

Protect against SQL injection, XSS, rate limiting

Layer 7SQL injectionXSSrate limitingmanaged rulesALBCloudFrontURI-specific rate-based ruletargeted throttlingweb ACLrule groupsIP setregex pattern setpricing
D1 · Secure
AWS ShieldAWS Shield Standard & Advanced
"Pelindung DDoS — Standard free, Advanced bayar"

DDoS protection Layer 3/4 (Standard) and Layer 7 (Advanced)

DDoSLayer 3/4Shield StandardShield AdvancedDRTalways-onShield Standard freeShield Advanced paidcustom mitigationreal-time visibilitycost protectionpricing
D1 · Secure
Network FirewallAWS Network Firewall
"Polis traffic dalam VPC — deep inspection, Layer 3-7, pakai Suricata"

VPC-level managed firewall — stateful deep packet inspection, domain filtering, IDS/IPS

deep packet inspectionstatefulstatelessVPC-levelintrusion preventionIDS/IPSdomain filteringSuricataegress filteringfirewall subnetmanaged firewall
D1 · Secure
VPC Flow LogsVPC Flow Logs
"CCTV network VPC — log SIAPA cakap dengan SIAPA, bukan APA dia cakap"

Capture IP traffic metadata to/from ENIs — troubleshoot SG/NACL, security analysis, compliance

VPC Flow Logsnetwork monitoringACCEPTREJECTmetadataCloudWatch LogsS3Data FirehoseAthenatroubleshoot SG NACLsecurity analysisTraffic Mirroringaggregation intervalENIsubnet levelGuardDuty source
D1 · Secure
GuardDutyAmazon GuardDuty
"Mata-mata AWS — detect threats auto guna ML"

Automated threat detection: crypto-mining, unusual API calls, compromised instances

threat detectionMLCloudTrail logsVPC Flow Logsno agentsfindingsS3 Protectionmanagement eventsdata eventsobject-level APISecurity HubDetectiveCSPM
D1 · Secure
DetectiveAmazon Detective
"Siasatan selepas GuardDuty detect — forensics AWS"

Investigate and analyze security findings from GuardDuty, Security Hub, Macie

security investigationforensicsGuardDuty findingsroot causebehavior graphpost-incident
D1 · Secure
InspectorAmazon Inspector
"Scanner kelemahan — CVE/vuln untuk EC2, ECR, Lambda (continuous, automatic)"

Find OS/software vulnerabilities, CVEs, unintended network exposure in EC2, ECR images, Lambda

vulnerability scanningCVEEC2ECRLambdacontinuousnetwork reachabilitypackage vulnerabilityautomatedsecurity findingsSSM agentagentless
D1 · Secure
MacieAmazon Macie
"Pemburu data sensitif dalam S3 — ML scan PII, credentials, financial data"

Discover and protect sensitive data in S3: PII, credentials, financial data, compliance

PII detectionsensitive dataS3ML-baseddata privacyGDPRdata discoverypolicy findingspricing
D1 · Secure
Security HubAWS Security Hub
"Satu dashboard kumpul SEMUA finding security + compliance score"

Central view of security findings across accounts + compliance checks

Security Hubaggregate findingssingle pane of glasscompliance scoreCISPCI DSSFSBPASFFsecurity posturecentralized securitydelegated administratorcompliance checkspricing
D1 · Secure
Firewall ManagerAWS Firewall Manager
"Satu tempat urus WAF/Shield/SG/Network Firewall untuk SEMUA account"

Centrally manage firewall rules across all accounts in an Organization

Firewall Managercentral firewallacross accountsOrganization wideWAF policyShield Advancedsecurity group policyNetwork Firewall policyDNS Firewallauto enforcecompliancenew accountspricing
D1 · Secure
Penetration TestingAWS Penetration Testing Policy
"AWS bagi pentest 8 services — tak perlu minta kebenaran dulu, tapi DoS dilarang"

Faham polisi AWS untuk security testing & Acceptable Use Policy

🟢 Pre-authorized (NO approval)8 service: EC2, RDS, Aurora, CloudFront, API Gateway, Lambda (+ Lambda@Edge), Lightsail, Elastic Beanstalk. Terus test resource sendiri.

🔴 Prohibited (haram, walau resource sendiri)DoS/DDoS simulation, port flooding, protocol flooding, request flooding, DNS zone walking via Route 53.

🟡 Needs separate programDDoS / network stress / simulated event testing: kena engage AWS DDoS Simulation Testing program / dapat kebenaran khas dulu.

penetration testingpentestsecurity assessmentAUPAcceptable Use Policyno prior approval8 servicesprohibited activitiesDoS DDoS prohibitedDNS zone walkingDDoS simulation testingpre-authorized services
D1 · Secure
Security StackAWS Security Services — Custom Rules & Integration
"Lego keselamatan AWS — detection auto (ML), protection kau TULIS rules, Security Hub gam semua jadi satu"

Faham service mana boleh custom rules vs auto, macam mana security services integrate, + keyword cost tolak jawapan ke versi jimat/premium

security stackdefense in depthlayered securitycustom rulessuppression rulescustom data identifierthreat IP listintegrationwork togetheraggregate findingsASFFEventBridgeauto-remediationSecurity HubGuardDuty DetectiveWAF Shield combocost-effectiveShield Standard vs Advancedkeyword directionpricing
🔐Data ProtectionDeep Notes →↑ Top
D1 · Secure
KMSAWS Key Management Service
"Simpan dan urus kunci enkripsi"

Encrypt data at rest, manage encryption keys

encryption at restCMKkey rotationSSE-KMSenvelope encryptionCloudTrail auditasymmetric keyssymmetric keysdigital signingsign and verifykey usageverify authenticitytamperpublic keyprivate keyonly sender signsmulti-region keysaws:SourceVpceCloudHSMFIPS 140-2single-tenantcustom key storekey policycross-account KMSroot of trustcross-account decrypt
D1 · Secure
Secrets ManagerAWS Secrets Manager
"Simpan password apps, auto-rotate"

Store dan auto-rotate credentials, API keys, DB passwords

auto-rotationcredentialsAPI keysno hardcoded secretsLambda integrationcustom rotationon-premises databaseParameter StoreSecureStringcross-region replicationKMSRDSAuroraDocumentDBpricingleast operational overhead
D1 · Secure
S3 Object LockAmazon S3 Object Lock
"Lock file — tak boleh delete atau ubah (WORM)"

WORM compliance, prevent deletion/modification

WORMcomplianceretention periodGovernance modeCompliance modelegal holdversioning requiredBypassGovernanceRetentionimmutableSEC 17a-4FINRARetain Until Date
D1 · Secure
S3 Glacier VaultAmazon S3 Glacier Vault Lock & Access Policy
"Vault Lock = immutable compliance. Vault Access Policy = mutable access control"

WORM compliance for Glacier archives — enforce retention policies that cannot be changed

Vault LockVault Access PolicyWORMcomplianceimmutableretentionGlacier archivein-progress state24-hour windowlock IDtwo-step lock
D1 · Secure
Amazon RedshiftAmazon Redshift — Encryption & DataShare
"Data warehouse — KMS untuk at rest, SSL untuk in transit, DataShare untuk cross-account"

Encrypt data warehouse at rest (KMS) and in transit (SSL); share data cross-account via DataShare

RedshiftKMSencryption at restSSL TLSin transitAES-256data warehouseDataSharecross-account analyticsno ETL
D1 · Secure
CloudTrailAWS CloudTrail
"CCTV untuk semua API calls AWS"

Audit who did what and when — compliance, forensics, account activity

API auditwho did whatcomplianceforensicsaccount activity90-day retentionCloudTrail LakeSQL querylong-term retention7 yearsmanagement eventsdata eventscontrol planedata planeS3 object-levelLambda invocationsmulti-region trailInsight Eventsvs CloudWatchvs Config
D1 · Secure
ACMAWS Certificate Manager
"SSL cert percuma untuk HTTPS"

Provision free SSL/TLS certificates for ALB, CloudFront, API Gateway

ACM Public Certificatecert percuma untuk public-facing HTTPS (browser-trusted). Auto-renew selagi DNS validation. Tak boleh export.

ACM Private CA (Private Certificate Authority)private PKI untuk internal resources/IoT devices — TAK browser-trusted. Berbayar ($400/bln per CA). Boleh export private certs.

Imported Certificatecert kau beli dari pihak ketiga (DigiCert dll), import masuk ACM untuk guna kat ALB/CloudFront. ACM TAK auto-renew imported cert — kau jaga renewal sendiri.

SSLTLSHTTPSfree certificateauto-renewalALBCloudFrontAPI GatewayDNS validationemail validationpending validationus-east-1N. VirginiaACM Private CAprivate PKIimported certificatecannot exportpricing
D1 · Secure
CloudHSMAWS CloudHSM
"KMS tapi kau fully control dedicated hardware"

FIPS 140-2 Level 3 compliance, customer-exclusive HSM hardware

dedicated HSMFIPS 140-2 Level 3customer controlsingle-tenanthardware securityTDEOracle RDSSQL Server RDSMySQLMariaDBPostgreSQLTransparent Data Encryptionencrypt at restno application changesPKCS#11EBKPBKbackuppricing
🔗ConnectivityDeep Notes →↑ Top
D1 · Secure
Direct ConnectAWS Direct Connect
"Kabel terus ke AWS — private dedicated lane"

Private dedicated connection from on-premises to AWS

dedicated connectionprivateconsistent latency1Gbps/10Gbpsno internetvs VPNIPSec backupdata transfer costDirect Connect Gatewaynot encryptedVPN over DXpublic VIFprivate VIF
D1 · Secure
Site-to-Site VPNAWS Site-to-Site VPN
"Tunnel rahsia ke AWS, guna internet biasa — NETWORK ke NETWORK"

Encrypted IPSec tunnel from on-premises network to VPC over internet

IPSecencryptedinternet-basedVirtual Private GatewayCustomer GatewayTransit Gatewaytwo tunnelsquick setupcost-effectivenetwork to networkDX backupBGPvs Client VPN
D1 · Secure
Client VPNAWS Client VPN
"VPN untuk individual users — bukan network-to-network"

Allow individual users to authenticate and connect to a VPC from their devices

Client VPNuser authenticationOpenVPNSAMLauthorization rulesper-user accessremote accesstemporary accessSite-to-Site VPNDirect Connectpricing
🏘️VPC & NetworkingDeep Notes →↑ Top
D1 · Secure
VPCAmazon Virtual Private Cloud
"Kawasan perumahan gated sendiri dalam AWS — kau yang design layout"

Isolated private network — the foundation for all AWS resources

VPC CIDRIP range keseluruhan (172.16.0.0/16 = 65,536 IPs)

Public SubnetAda route ke IGW. EC2 boleh dapat public IP

Private SubnetTiada route terus ke internet. DB, app servers letak sini

+1 more → Deep Notes
VPCCIDRsubnetpublicprivateisolated networkdefault VPCprivate network
D1 · Secure
CIDR & SubnetsIP Addressing & Subnet Calculator
"2^(32−prefix) = total IPs, tolak 5 = usable"

Plan IP address ranges — VPC perlu CIDR sebelum boleh buat subnets

/1665,536 total → 65,531 usable (guna untuk VPC range)

/24256 total → 251 usable (subnet standard)

/25128 total → 123 usable

+3 more → Deep Notes
CIDRsubnet maskIP addressing/24/26/275 reserved IPsusable hosts
D1 · Secure
Private/Public/Elastic IPEC2 IP Addresses — Private vs Public vs Elastic
"Private = borak dalam rumah (kekal). Public = alamat sewa (tukar bila Stop/Start). Elastic = alamat beli tetap (statik, boleh alih)"

Tentukan macam mana EC2 dialamatkan — internal (Private), internet sementara (Public), atau internet statik yang tak berubah (Elastic)

Private IPAuto-assign dari CIDR subnet masa launch (wajib ada minimum satu). Internal VPC sahaja. Kekal melekat selagi EC2 wujud; hanya lepas bila Terminate. Stop/Start TAK ubah private IP.

Public IPOptional, auto-assign dari pool awam AWS bila EC2 dalam public subnet (setting "auto-assign public IP"). BERUBAH setiap Stop/Start (lepas balik ke pool, dapat baru bila start). Tak boleh dialih manual. IPv4.

Elastic IPAllocate ke akaun kau, kekal milik kau sampai release. Associate ke instance/ENI. Static — tak berubah walau Stop/Start. Boleh disassociate & re-associate ke EC2 lain (failover). Property of ENI. Limit 5/region. IPv4 sahaja.

Private IPPublic IPElastic IPEIPstatic IPconsistent public IPStop Start IP changefailover IPwhitelistDNS A recordinternal communicationIPv4idle Elastic IPleast operational overheadpublic IPv4 chargepricing
D1 · Secure
Internet GatewayVPC Internet Gateway (IGW)
"Pintu pagar utama — dua arah, free, satu per VPC"

Connect VPC to internet (bidirectional) — kena ada untuk public subnet

IGWinternet gatewaypublic subnetbidirectionalfree0.0.0.0/0
D1 · Secure
NAT GatewayNetwork Address Translation Gateway
"Keluar boleh, masuk tak boleh — untuk private subnet"

Private subnet instances download patches/call APIs without being exposed to internet

NAToutbound onlyprivate subnetElastic IPpaidno inboundbastion hostcross-AZ costper-AZ NAT Gatewaydata transfer chargesIPv6Egress-Only Internet GatewayEIGWNAT64ErrorPortAllocationconnection limit55000 connectionspricingStop Startdelete recreateLambda EventBridgeCost ExplorerEC2-OtherNatGateway-HoursNatGateway-BytesLinked AccountManagement Accountpayer accountAWS BudgetsCost and Usage ReportCURData ExportsQuickSightAthenaOrganizations costconsolidated costkongsi vs asing
D1 · Secure
Route TablesVPC Route Tables
"Papan tanda jalan — arah ke mana traffic pergi"

Control traffic direction: public subnet → IGW, private subnet → NAT GW

Localtraffic dalam VPC sendiri (auto, tak boleh delete)

0.0.0.0/0igw-xxx (public subnet — keluar ke internet)

0.0.0.0/0nat-xxx (private subnet — outbound je)

+1 more → Deep Notes
route tablerouting0.0.0.0/0local routesubnet associationmain route table
D1 · Secure
SG vs NACLSecurity Groups vs Network ACLs — Defence Layers
"SG = Smart/Stateful (instance). NACL = Needs-both-ways/stateless (subnet)"

Two-layer defence: SG guards each EC2, NACL guards each subnet

SGNACLstatefulstatelessinstance-levelsubnet-leveldenydefense-in-depth
D1 · Secure
Laluan Packet VPCPerjalanan Satu Packet — VPC Traffic Flow (end-to-end)
"Jejak JALAN, bukan hafal komponen. Pergi: IGW → Route Table → NACL → SG → EC2. Balik: terbalik, tapi SG ingat (auto), NACL lupa (kena rule)."

Faham urutan checkpoint satu packet lalui dari internet sampai EC2 dan balik — kunci untuk semua soalan troubleshoot VPC

packet journeytraffic flowlaluan packetorder of evaluationIGW route table NACL SGinbound orderoutbound orderpublic subnetprivate subnetNAT Gatewayephemeral portsstatefulstatelesstroubleshoot VPCpricing
D1 · Secure
VPC PeeringVPC Peering Connection
"Jambatan terus antara dua VPC — non-transitive"

Connect 2 VPCs privately — same account, cross-account, atau cross-region

VPC peeringcross-accountcross-regionnon-transitiveno IP overlapprivate routing
D1 · Secure
Transit GatewayAWS Transit Gateway
"Hub tengah yang connect semua VPCs — gantikan peering mesh"

Connect 3+ VPCs dan on-premises networks melalui satu hub yang transitive

Transit Gatewayhubtransitive routingmany VPCsreplace peering meshon-premisescross-accountECMPVPN throughputmultiple tunnelsaggregate bandwidth
D1 · Secure
VPC EndpointsVPC Endpoints (Gateway & Interface)
Sepasang akronim poket: "GD Free" = Gateway → DynamoDB + S3, FREE, Route Table | "IP Paid" = Interface → PrivateLink/Pelbagai servis, PAID, ENI. Habis 100% skop VPC Endpoints.

Access S3/DynamoDB (free) atau AWS services lain (paid) dari private subnet secara private

VPC endpointGateway endpointInterface endpointPrivateLinkS3DynamoDBno internetfreeaws:sourceVpcebucket policyNAT Gateway deniedaws:sourceVpcEndpoint ServiceGWLBeGateway Load Balancer EndpointNLBexpose own serviceMarketplace SaaSprovider consumerno peering
DOMAIN 2 · 26% OF EXAM

Design Resilient Architectures

High Availability · Disaster Recovery · Backup & Storage Resilience

High Availability & ScalingDeep Notes →↑ Top
D2 · Resilient
Region & AZAWS Global Infrastructure — Region, Availability Zone, Edge
"Region = bandar · AZ = mall berasingan dalam bandar"

Faham geografi AWS — asas semua keputusan HA, DR, latency & data residency

Regionkawasan geografi (cth ap-southeast-1). Servis & harga berbeza ikut Region. Pilih ikut latency, kos, compliance/data residency, ketersediaan servis

Availability Zone (AZ)1+ datacenter fizikal berasingan dalam Region (kuasa/penyejuk/rangkaian sendiri). Berkilometer jauh tapi link <2ms. Min 3 AZ per Region biasanya

AZ ID (cth use1-az1)ID fizikal tetap; nama AZ (us-east-1a) di-map rawak per account supaya beban seimbang. Guna AZ ID bila nak padan AZ across account (RAM/shared VPC)

+3 more → Deep Notes
regionavailability zoneAZAZ IDedge locationlocal zonewavelengthglobal infrastructuremulti-AZmulti-regiondata residencydata sovereigntycross-AZ data transferinter-AZlatencyCloudFront PoPphysical isolationdatacenterpricingdata transfer costsurvive AZ outagesurvive region outageglobal vs regional service
D2 · Resilient
Auto Scaling GroupsAmazon EC2 Auto Scaling
"Auto tambah/kurang server ikut demand"

Automatically scale EC2 instances based on load

horizontal scalingscale out/inlaunch templatescaling policiesdesired capacitymin/maxOldestLaunchTemplatetermination policyAMI rolloutMixed Instances PolicyOn-Demand baselineSpotfault-tolerantcost optimization spikehigh availabilityfault tolerancescalabilityelasticitythroughputvertical scalingscale upzero downtimeeliminate single point of failurecustom metricSQS backlogApproximateNumberOfMessagesVisiblebacklog per taskqueue-based scalinglifecycle hooks
D2 · Resilient
RDS Multi-AZAmazon RDS Multi-AZ Deployment
"Backup database sedia tunggu dalam AZ lain"

High availability for RDS — automatic failover

automatic failoverstandbydifferent AZsync replicationsame endpointHA onlyautomated backupsmanual snapshotpoint-in-time restoreretention periodMulti-AZ DB clusterMulti-AZ DB instancereadable standbysemisynchronoustwo readable standbysthree AZfaster failover
D2 · Resilient
RDS Read ReplicasAmazon RDS Read Replicas
"Photocopy database untuk baca je — boleh cross-region"

Scale read traffic, reporting queries, multi-region read access

read scalingasync replicationcross-regionup to 15 replicasread-onlymulti-regionpromote to master
D2 · Resilient
RDS ProxyAmazon RDS Proxy
"Perantara yang pool connections — jimat RDS dari connection tsunami"

Connection pooling for RDS — handle too many connections from Lambda/Auto Scaling

connection poolingtoo many connectionsLambda scalingidle connectionsconnection multiplexingfaster failoverIAM authenticationSecrets Manager
D2 · Resilient
Global AcceleratorAWS Global Accelerator
"Highway AWS untuk user seluruh dunia"

Route global users to nearest healthy endpoint via AWS backbone

global routingAWS backboneanycaststatic IPTCP/UDPfailover <30stwo static IPsIP cachingIoTHIPAA
D2 · Resilient
AuroraAmazon Aurora
"RDS tapi 5x laju, 6 copies auto, failover 30 saat"

High-performance relational DB, MySQL/PostgreSQL compatible, enterprise HA

MySQL compatiblePostgreSQL compatible6 copies3 AZsauto storage 256 TiBfast failover15 read replicasGlobal Databasecross-region DRRTO 1 minRPO 1sshared cluster volumeMulti-AZ DB ClusterAurora vs Multi-AZ DB Clustershared storage
D2 · Resilient
Aurora ServerlessAmazon Aurora Serverless
"Database yang tidur bila tak pakai, scale sendiri"

Unpredictable/intermittent workloads — auto-scale DB capacity, pay per second

scale to zeroACUpay per secondintermittentdev/testauto-pausevariable trafficv1 vs v20.5 ACU incrementsno connection dropsMySQL-compatible2 GiB per ACUmemory 2-16 GiBon-premises replacementunpredictable spikesmix provisioned serverless
D2 · Resilient
DynamoDBAmazon DynamoDB
"NoSQL yang tak pernah slow — milliseconds at any scale"

Serverless key-value/document store, single-digit ms latency at any scale

NoSQLkey-valueserverlessmillisecond latencyDAXGlobal Tablesstreamsauto-scalepartition keyLSIGSIsecondary indexprovisionedon-demandhot partitionitem collectionhash attributerange attributenested attributes
D2 · Resilient
DAXAmazon DynamoDB Accelerator (DAX)
"Cache depan DynamoDB — baca dalam microseconds"

Read-heavy DynamoDB workloads needing microsecond response times

DynamoDB Acceleratormicrosecond latencyin-memory cacheread cachingdrop-in compatibleDAX vs ElastiCache
🔄Disaster Recovery PatternsDeep Notes →↑ Top
D2 · Resilient
Backup & RestoreDR Pattern: Backup & Restore
"Save game — kalau rosak restore dari backup"

Non-critical systems, lowest cost DR strategy

RPO: hours/daysRTO: hourslowest costno standby infraS3/Glacier backupDR spectrumPilot LightWarm StandbyMulti-Siteactive/passiveactive/activefinancial institutebudget concerns20 minutes RTO
D2 · Resilient
Pilot LightDR Pattern: Pilot Light
"Api kecil sedia — boleh bakar besar bila perlu"

Core DB running in DR region, app servers off until needed

RPO: minutesRTO: minutes-hourscore DB runningapp servers offmedium costfinancial institutebudget concerns20 minutes RTOtens of minutes
D2 · Resilient
Warm StandbyDR Pattern: Warm Standby
"Anak syarikat kecil sedia — scale up masa emergency"

Scaled-down full stack running in DR, quick scale up

RPO: seconds/minutesRTO: minutesscaled-down activequick scale uphigher cost
D2 · Resilient
Multi-Site Active/ActiveDR Pattern: Multi-Site Active/Active
"Dua HQ berjalan serentak — saling backup"

Mission-critical — full capacity in both regions simultaneously

RPO: near-zeroRTO: secondsfull capacity bothhighest costmission-criticalzero downtime
D2 · Resilient
AWS Elastic Disaster RecoveryAWS Elastic Disaster Recovery (AWS DRS)
"Replicate server berterusan ke AWS — failover bila bencana, failback bila pulih"

DR-as-a-service: continuously replicate on-prem/cloud/EC2 servers to AWS

AWS DRSElastic Disaster RecoveryCloudEndure Disaster Recoverycontinuous replicationblock-level replicationfailoverfailbackstaging arealow-cost DRDR as a serviceon-premises DRcross-region DRDRS vs MGNRPO secondsRTO minutespricing
🗂️Backup & Storage ResilienceDeep Notes →↑ Top
D2 · Resilient
AWS BackupAWS Backup
"Backup manager untuk semua AWS services"

Centralized backup across EC2, RDS, EFS, DynamoDB, S3

Backup Plan"resepi": schedule (frequency) + retention + lifecycle (transition ke cold storage) + cross-region / cross-account copy

Resource assignmentpilih resource ikut TAG atau resource ID (auto-cover resource baru yang match tag)

Backup Vaultbekas tempat recovery point disimpan, encrypt dengan KMS

+3 more → Deep Notes
centralized backupbackup plansbackup vaultvault lockWORMimmutable backupransomware protectionretentioncross-regioncross-accountcomplianceautomatedEFS backupBackup Audit Managermonitoringpricing
D2 · Resilient
S3 Versioning & CRRS3 Versioning + Cross-Region Replication
"Simpan semua versi, auto copy ke region lain"

Protect against accidental deletion, cross-region DR for S3

Versioningsetiap PUT jadi version baru (version ID unik); delete = letak delete marker (object "hilang" tapi versi lama kekal, boleh undo). Kena enable per bucket; sekali ON cuma boleh suspend, tak boleh OFF

Delete markerpenanda "latest = deleted"; buang delete marker = object muncul balik

MFA Deletewajib kod MFA untuk delete version / suspend versioning (lindung dari delete malicious)

+3 more → Deep Notes
versioningCRRSRRdelete markerMFA Deleteaccidental deletioncross-region replicationsame-region replicationS3 Batch Replicationnoncurrent versiondata residencypoint-in-time recoverypricing
D2 · Resilient
EBS SnapshotsAmazon EBS Snapshots
"Gambar volume pada satu masa — restore anytime"

Point-in-time backup of EBS volumes, cross-region DR

Standard tiersnapshot biasa, INCREMENTAL (block berubah je disimpan), disimpan dalam S3 managed. $0.05/GB-mo

Archive tier (Snapshot Archive)untuk snapshot rarely-accessed simpan 90+ hari. Convert incremental → FULL snapshot, sampai 75% lebih murah. Restore ambil 24-72 jam

Fast Snapshot Restore (FSR)volume yang dibuat dari snapshot terus fully-initialized, takde first-access latency. Enable per snapshot + per AZ, max 5/Region, snapshot ≤16 TiB. Mahal (DSU-hours)

+3 more → Deep Notes
incremental backuppoint-in-timecross-AZcross-region copyEC2 recoverySnapshot Archivearchive tierFast Snapshot RestoreFSRData Lifecycle ManagerDLMRecycle BinAMI vs snapshotsnapshot encryptionKMScross-account sharerarely accessedlong-term backupfirst-access latencypricing
D2 · Resilient
FSxAmazon FSx
"EFS tapi untuk Windows, HPC, atau enterprise NAS"

Managed file systems: Windows SMB, HPC Lustre, NetApp ONTAP, OpenZFS

FSx for Windows File ServerSMB / NTFS + Active Directory, DFS namespaces, VSS shadow copies. Single-AZ atau Multi-AZ. Untuk Windows apps & file share

FSx for LustrePOSIX, throughput ratus GB/s + jutaan IOPS, sub-ms latency. Native S3 integration (DRA). Dua deployment: Scratch (sementara, no replication, murah) vs Persistent (durable, replicated dalam AZ). Untuk HPC / ML / media

FSx for NetApp ONTAPMULTI-PROTOCOL (NFS + SMB + iSCSI serentak), feature ONTAP penuh: snapshot, SnapMirror, dedup, compression, auto data tiering ke capacity pool murah. Untuk migrate NetApp enterprise

+2 more → Deep Notes
Windows SMBNTFSActive DirectoryDFSVSSLustre HPCScratchPersistentNetApp ONTAPSnapMirrormulti-protocolOpenZFSZFSmanaged file systemS3 integrationDRADataSyncmulti-AZsingle-AZPOSIXcapacity pool tieringpricing
D2 · Resilient
Storage GatewayAWS Storage Gateway
"Jambatan on-prem ↔ AWS." Mnemonic 4 jenis = FBT: Fail (File GW → S3 atau FSx), Blok (Volume GW, iSCSI), Tape (Tape GW, VTL). Cached vs Stored → "Cached = Cloud dulu (primary S3); Stored = Simpan Sini (primary on-prem)".

Hybrid cloud storage — on-premises apps guna AWS storage secara seamless

S3 File Gatewaymount NFS/SMB on-prem, file disimpan sebagai object dalam S3 (boleh lifecycle ke Glacier). Local cache untuk akses laju

FSx File Gatewaymount SMB on-prem dengan Active Directory, backend Amazon FSx for Windows File Server. Untuk Windows file share low-latency

Volume Gatewayexpose iSCSI block volume ke server on-prem. Backup point-in-time = EBS snapshot dalam S3. Dua mode: Cached vs Stored

+2 more → Deep Notes
hybrid storageS3 File GatewayFSx File GatewayVolume GatewayTape Gatewaycached volumestored volumeVTLvirtual tape libraryon-premisesNFSSMBiSCSIActive DirectoryEBS snapshotlocal cacheongoing hybrid accesslegacy backup softwarereplace physical tapelow latency entire datasetminimize on-prem storagepricing
D2 · Resilient
DataSyncAWS DataSync
"Pemindah data automatik dan laju — dari on-prem ke AWS atau cross-region"

One-time or recurring data migration from on-premises to S3, EFS, or FSx; also EFS cross-region replication

data migrationautomated transferS3EFSFSxNFSSMBHDFSone-time migrationscheduled transferStorage GatewayEFS cross-regionprivate networkno public internetincrementalrecurringcost-effectivepricing
D2 · Resilient
DMSAWS Database Migration Service
"Pindah database ke AWS tanpa downtime"

Migrate databases to AWS — homogeneous (MySQL→RDS MySQL) or heterogeneous (Oracle→Aurora)

database migrationminimal downtimehomogeneousheterogeneousSchema Conversion ToolSCTCDCchange data captureDMS Serverlessreplication instanceMulti-AZpricingS3 stagingDynamoDB targetNoSQL migration
D2 · Resilient
Snow FamilyAWS Snow Family
"Peti besi AWS untuk data besar-besaran — hantar by post"

Petabyte-scale data transfer bila internet terlalu lambat/mahal, atau edge computing

SnowconeSnowball EdgeSnowmobilephysical transferpetabyteedge computingoffline migrationOpsHubcompute optimizedstorage optimized210TBpricing
🚚Migration & TransferDeep Notes →↑ Top
D2 · Resilient
Transfer FamilyAWS Transfer Family
"SFTP/FTP managed server — files terus masuk S3 atau EFS"

Legacy FTP/SFTP/FTPS/AS2 file transfers stored directly into S3 or EFS — no code changes needed

SFTPFTPFTPSAS2S3 backendEFS backendmanaged FTPlegacy protocolB2B file transferActive Directoryno code changepricing
D2 · Resilient
AWS MGNAWS Application Migration Service (MGN)
"Lift-and-shift server migration ke EC2 — continuous replication, minimal downtime"

Migrate servers (physical/virtual/cloud) to AWS EC2 with minimal downtime

MGNApplication Migration Servicelift-and-shiftrehostserver migrationEC2 migrationblock replicationCloudEndureApplication Discovery Serviceminimal downtimepricing
D2 · Resilient
Migration HubAWS Migration Hub
"Dashboard pusat untuk track semua migration activities"

Single pane of glass to track application migrations across multiple AWS tools

migration trackingsingle pane of glassdashboardhome regionstrategy recommendationsorchestratorrefactor spacespricing
D2 · Resilient
AWS OutpostsAWS Outposts
"AWS datang ke rumah kau — rack AWS dalam data center sendiri"

Run AWS services on-premises for compliance, low latency, or data residency requirements

Outposts hardwarerack 42U atau server 1U/2U yang AWS hantar & pasang dalam data center kau (AWS yang maintain).

Supported services on OutpostsEC2, EBS, S3 on Outposts, ECS, EKS, RDS, EMR, ElastiCache — run LOCAL, data kekal on-prem.

Service Linksambungan (VPN over internet / Direct Connect) balik ke parent AWS Region untuk control plane (management, monitoring).

+3 more → Deep Notes
OutpostsOutposts rackOutposts serveron-premises AWSdata residencycompliancecannot migratelocal processinglow latencyconsistent hybridService LinkLocal GatewayLGWLocal Network InterfaceLNIparent RegionLocal ZonesWavelengthStorage GatewayDataSyncSnow Familyhybridpricing
DOMAIN 3 · 24% OF EXAM

Design High-Performing Architectures

Compute · Storage · Networking · Messaging · Infrastructure

🖥️ComputeDeep Notes →↑ Top
D3 · High-Performing
EC2Elastic Compute Cloud
"Virtual computer"

Run any workload, full control

full controlcustom OSlift and shiftplacement groupscluster/partition/spreadpricingper-second billingper-hour WindowsOn-Demand costReserved discountDedicated Host billingInstance Schedulerstart stop scheduleoffice hourspart-time workloadscheduled start stopweekday only
D3 · High-Performing
LambdaAWS Lambda
"Jalankan code, bayar per run"

Serverless, event-driven

Functionunit code + config (memory, timeout, runtime, env vars, role). Ini benda yang kau deploy

Handlerentry point: method yang Lambda panggil tiap kali invoke (cth handler(event, context))

Execution Environmentmicro-VM (Firecracker) yang isolate + run code. Init sekali (= COLD START), lepas tu di-reuse (WARM)

+8 more → Deep Notes
serverlessevent-driven15-min maxreserved concurrencyprovisioned concurrencycold startsnapstartLambda SnapStartFirecracker snapshotJava cold startevent source mappinginvocation modelasynchronous invocationsynchronous invocationpoll-basedLambda destinationsDLQdead letter queueLambda layersresponse streamingSQS decouplethrottling429execution environmentexecution role/tmp ephemeral storageEFS mountLambda EFSpersistent storageshared storagefunction URLenvironment variablesencryption helpersKMS env var
D3 · High-Performing
Elastic BeanstalkAWS Elastic Beanstalk
"Hantar code je, AWS urus selebihnya"

Deploy app tanpa urus server

Applicationbekas teratas (umbrella) untuk app kau — pegang banyak version + environment

Application Versionsatu source bundle (.zip/.war) yang dilabel & disimpan dalam S3. Deploy = pilih version untuk satu environment

Environmentset resource AWS (EC2 + ALB + ASG + health monitoring) yang menjalankan SATU version. Satu app boleh ada banyak environment (dev/test/prod)

+4 more → Deep Notes
PaaSdeploy appdeveloper friendlyauto EC2+ALB+ASGfree servicedeployment policyall at oncerollingrolling with additional batchimmutable deploymentblue greenblue/green CNAME swaptraffic splittingcanaryweb server tierworker tiersqsd.ebextensionsmanaged platform updateszero downtime deploymentpricing
D3 · High-Performing
ECSElastic Container Service
"Docker manager AWS-native — Cluster → Service → Task ikut Task Definition"

Run & orchestrate Docker containers (AWS-native, bukan Kubernetes)

Clusterpool logikal capacity (EC2 instances atau Fargate) tempat tasks jalan

Task Definitionblueprint JSON: image, vCPU, memory, ports, env vars, volumes + Task Role + Task Execution Role. BUKAN benda yang "run" — ia resepi sahaja

Tasksatu running instance dari Task Definition (boleh ada 1+ container)

+6 more → Deep Notes
Dockercontainersmicroservicestask definitionJSON templateFargateEC2 launch typeservicetaskclusterTask RoleTask Execution Roleper-task IAMbinpackspreadrandomtask placementdesired countECS storageEFS volumesEBS volumesbind mountsephemeral storagepersistent storagestateful containersshared storagecontainer instanceECS agentcapacity provider
D3 · High-Performing
EKSElastic Kubernetes Service
"Kubernetes manager"

Container orchestration guna K8s

Control Plane (AWS managed)API server (min 2 node, multi-AZ) + etcd (3 AZ) + scheduler. Kau tak sentuh langsung

Worker NodesEC2 yang run kubelet + container runtime. 3 jenis: Managed Node Groups, Self-Managed, Fargate (serverless per-pod)

Podunit terkecil K8s (1+ container). Dapat REAL VPC IP via AWS VPC CNI plugin

+8 more → Deep Notes
KubernetesK8scontainer orchestrationIRSAIAM Roles for Service Accountspod identityECS vs EKScontrol plane costEKS storagepersistent volumeEBS CSI DriverEFS CSI DriverReadWriteManyRWXReadWriteOnceRWOshared storage podspods different nodesFSx for Lustre EKSEBS Multi-AttachAWS Load Balancer ControllerALB ingressKubernetes ingresspath-based routing EKSNLB EKSNGINX ingressroute by URL pathcontrol planeworker nodesVPC CNINamespaceKarpenter
D3 · High-Performing
EKS VariantsEKS Anywhere vs EKS Distro vs ECS Anywhere
"EKS Anywhere = K8s on-prem + AWS control plane. EKS Distro = pure on-prem, no AWS control plane. ECS Anywhere = ECS on-prem"

Run container workloads on-premises with varying levels of AWS integration

EKS AnywhereDeploy K8s clusters on-prem using open-source tools, connected to AWS control plane for management consistency

EKS DistroAWS K8s distribution used by EKS — run fully on-prem, NO AWS control plane dependency. Full open-source freedom

ECS AnywhereRun ECS tasks on on-premises servers, managed by AWS ECS control plane

EKS AnywhereEKS DistroECS Anywhereon-premises Kuberneteshybrid containers
D3 · High-Performing
AWS LB ControllerAWS Load Balancer Controller
"Kubernetes Ingress → auto-provision ALB/NLB. Path-based routing = ALB, least setup"

Auto-provision AWS load balancers (ALB/NLB) dari Kubernetes Ingress/Service resources

Ingress ResourceKubernetes YAML yang define HTTP routing rules (path, host). Controller watch ni dan create ALB

ALB (auto-created)Layer 7 load balancer dengan path/host rules. Controller create target groups + listener rules automatically

NLB (auto-created)For Service type LoadBalancer. Controller create NLB untuk TCP/UDP traffic

+2 more → Deep Notes
AWS Load Balancer ControllerALBNLBIngresspath-based routingEKSKubernetesLayer 7auto-provision
D3 · High-Performing
EC2 User DataEC2 User Data Scripts
"Script masa launch"

Auto-configure EC2 instance on first boot

bootstraplaunch scriptcloud-initfirst bootinitialization16KB limituser data vs metadataauto-configurepull from S3
D3 · High-Performing
EC2 HibernationAmazon EC2 Hibernation
"EC2 tidur tapi ingat semua — RAM saved to EBS"

Preserve in-memory state across stop/start — fast resume for memory-intensive apps

hibernationRAM saveEBS rootfast resumein-memory stateencrypted root volumestop start reboot terminateinstance lifecyclewarm-up timepricing
D3 · High-Performing
EC2 MetadataEC2 Instance Metadata Service (IMDS)
"ID kad instance sendiri"

Get info about the running instance from within the instance

meta-data/info instance: instance-id, local/public-ipv4, hostname, security-groups, placement/az

meta-data/iam/security-credentials/<role>temporary IAM role credentials (auto-rotate) — ni yang SSRF nak curi

dynamic/instance-identity/documentJSON identity (region, accountId, instanceType) untuk verify identity

+1 more → Deep Notes
169.254.169.254instance infoIMDSv2IMDSv1hostnameIP addressIAM role nameSSRFHttpTokenshop limitlink-local
D3 · High-Performing
Recycle BinAWS Recycle Bin (AMI & EBS Snapshots)
"Tong sampah untuk AMI dan snapshots — boleh recover dalam tempoh tertentu"

Recover accidentally deleted AMIs and EBS snapshots within a defined retention period

Recycle BinAMI recoveryEBS snapshot recoveryaccidental deletionretention periodretention ruleData Lifecycle ManagerDLMAWS Backuppricing
D3 · High-Performing
AWS BatchAWS Batch
"Ketua pekerja batch jobs — submit kerja, AWS upah & bubar pekerja (compute) sendiri"

Run batch / long-running compute jobs at scale without managing EC2 infrastructure

Jobsatu unit kerja (container/script) yang kau submit

Job Definitionblueprint: image mana, vCPU, memory, IAM role

Job Queuetempat job beratur ikut priority sebelum dijalankan

+1 more → Deep Notes
AWS Batchbatch computinglong-running jobmanagedjob queuejob definitioncompute environmentEC2 fleetFargateSpotrun to completionreplace third-partypricingjob storageEFS shared dataFSx for Lustrescratch storage
D3 · High-Performing
FargateAWS Fargate
"Serverless CONTAINER — bawak Docker image je, tak payah ada EC2"

Run container (ECS/EKS) tanpa urus EC2 langsung

serverless containersECSEKSno EC2 managementpay per vCPU/memoryFargate Spotvs Lambdano time limitFargate storageephemeral storage20 GiB200 GiBephemeralStorageEFS volumespersistent storage
D3 · High-Performing
ECRAmazon Elastic Container Registry
"Docker Hub versi AWS — private, IAM-controlled"

Simpan, version & deploy Docker image secara private dalam AWS

Registrysatu registry private per akaun AWS per region (auto-wujud)

Repository"folder" untuk satu app/image (cth my-app), simpan banyak versi

Image tagversi image (cth :latest, :v1.2) — tag boleh mutable atau immutable (immutable = elak orang timpa :v1

+4 more → Deep Notes
container registryDocker imagesprivate registryIAM integrationimage scanninglifecycle policyimmutable tagsreplicationAmazon Inspectorrate limitDocker HubKMSpricingECSEKS
D3 · High-Performing
Instance StoreAmazon EC2 Instance Store
"Disk sementara dalam EC2 — laju tapi data hilang bila stop"

Temporary block storage physically attached to the host server — highest IOPS, zero cost

Disk fizikal pada HOSTtak boleh detach, tak boleh pindah ke instance lain

Ephemeraldata HILANG bila instance stop/terminate/fail

NVMe atau SSD/HDDIOPS jauh melebihi EBS (jutaan)

+3 more → Deep Notes
ephemeraltemporary storagehigh IOPSNVMescratch diskdata lost on stopphysically attachedno snapshotfreeHPCbig datashuffle space
D3 · High-Performing
ENI/ENA/EFAEC2 Network Interfaces — ENI · ENA · EFA
"Huruf belakang main peranan: Interface (biasa) · Adapter (laju) · Fabric (ekstrem HPC). Macam enjin kereta: Kancil → Sports Turbo → Formula 1"

Network connectivity dan performance — pilih ikut keperluan (standard vs high-throughput vs HPC)

ENIVirtual network card (NIC). Boleh attach ke EC2 untuk network tambahan. Boleh ada IP private, public IP, security groups, MAC address. Boleh detach dari satu EC2 → attach ke EC2 lain (failover IP). Guna untuk: management network, NAT, bastion.

ENAElastic Network Adapter = driver/software untuk enable network performance tinggi pada instance yang support. Up to 100 Gbps. Dua versi: ENA (standard, sampai 25 Gbps) dan ENAv2 (sampai 100 Gbps).

EFAElastic Fabric Adapter = NIC special untuk HPC. Ada ENA capabilities + OS-bypass (libfabric API). Instance boleh communicate terus (bypass OS network stack) → latency rendah + throughput tinggi untuk message passing (MPI, CUDA). Hanya Linux.

ENIENAEFAnetwork interfacevirtual NICOS-bypasslibfabricMPIHPC networkinglow latencyultra-low latencyenhanced networkinghigh throughputfailover IPdetach attach100 Gbpsplacement group clustermachine learning trainingtightly-coupledpricing
D3 · High-Performing
Lambda@EdgeAWS Lambda@Edge
"Lambda yang jalan di CloudFront edge — code dekat dengan user, bukan di region"

Run Lambda functions AT CloudFront edge locations — customize content delivery closer to users

Viewer Requestbila user hantar request ke CloudFront (sebelum cache check). Boleh inspect/modify request, redirect.

Viewer Responsesebelum CloudFront hantar response ke user. Boleh modify headers, inject content.

Origin Requestbila cache MISS, sebelum CloudFront hantar request ke origin. Boleh rewrite path, pilih origin.

+1 more → Deep Notes
Lambda@Edgeedge computingCloudFrontViewer RequestViewer ResponseOrigin RequestOrigin ResponseCloudFront FunctionsA/B testingcustom authURL rewriteus-east-1Node.jsPythonlightweight JS
D3 · High-Performing
EC2 TenancyEC2 Tenancy & Dedicated Hosts
"Shared = ramai kongsi. Dedicated Instance = hardware sendiri tapi tak pilih physical. Dedicated Host = physical server sendiri, boleh lihat socket/core untuk lesen BYOL"

Pilih tahap isolation hardware — shared vs dedicated instance vs dedicated host

tenancyshareddedicated instancededicated hostsingle-tenantBYOLbring your own licenseOracleSQL Serversocketcorehost affinitylicense compliancephysical server
D3 · High-Performing
EBSElastic Block Store
"Hard disk untuk EC2"

Block storage, attach ke 1 EC2

Volume"hard disk" maya, attach ke 1 EC2 (network-attached). Hidup dalam SATU AZ je

Snapshotbackup volume ke S3 (incremental). Boleh copy cross-region/cross-account untuk DR

DeleteOnTerminationflag: root volume default TRUE (hilang bila terminate), extra volume default FALSE (kekal)

+3 more → Deep Notes
block storagesingle EC2persistent diskinstance storeephemeralElastic Volumesresizeencryptiondata in transitpricinggp3 costio2 costst1 costsc1 costsnapshot cost
D3 · High-Performing
EBS Volume TypesAmazon EBS — Volume Types & Multi-Attach
"gp3 = general best. io2 = mission-critical + Multi-Attach. st1 = sequential log. sc1 = cold"

Choose right EBS type for workload: random I/O vs sequential, IOPS vs throughput, cost vs performance

gp3General Purpose SSD (default). Baseline 3,000 IOPS + 125 MB/s INCLUDED free; boleh provision IOPS & throughput BERASINGAN dari saiz (up to 16,000 IOPS / 1,000 MB/s — exam classic; docs terkini list ceiling lebih tinggi pada Nitro). Boot volume ✓

gp2Older General Purpose SSD. IOPS terikat saiz (3 IOPS/GB, burst 3,000). Less predictable; migrate ke gp3 (gp3 ~20% murah)

io2 / io2 Block ExpressProvisioned IOPS SSD, paling power. 99.999% durability. io2 standard ~64,000 IOPS; io2 Block Express sampai 256,000 IOPS / 4,000 MB/s, sub-ms latency. Supports Multi-Attach

+4 more → Deep Notes
gp3gp2io2io1io2 Block Expressst1sc1Magneticstandard volumeMulti-AttachProvisioned IOPSthroughput HDDIOPSthroughputrandom I/Osequentialboot volumeEBS typespricingbaseline IOPS
D3 · High-Performing
EFSElastic File System
"Shared drive, ramai boleh access — multi-AZ NFS"

Shared file storage for multiple EC2 instances simultaneously

File System"shared drive" NFS sebenar, auto-scale (bayar ikut guna). Span banyak AZ

Mount Target1 ENI per AZ (alamat EC2 mount). Setiap AZ kena ada satu; SG-nya MESTI allow inbound TCP 2049

Performance Mode (set masa create)General Purpose (latency rendah, default) vs Max I/O (latency lebih tinggi, parallel besar)

+3 more → Deep Notes
shared storagemultiple EC2NFSGeneral PurposeMax I/OProvisioned ThroughputBursting ThroughputElastic ThroughputTLS 1.2mount helper-o tlsTCP 2049cross-VPC EFSEFS mount targetReadWriteManyRWXReadWriteOnceRWOEFS CSI DriverEKS shared storagepods different nodesKubernetes persistent volumeEFS storage classesOne Zone-IAStandard-IAEFS One Zonerarely accessedsingle AZre-creatableregenerated if lostlow-costcheapest EFSredundant storagehigh-throughputEFS lifecycle365 days maxvs S3 lifecycle 730 days
D3 · High-Performing
S3Simple Storage Service
"Infinite bucket — object storage, 11 nines durability"

Object storage: images, video, backup, data lake, static website

Bucketbekas top-level, nama GLOBAL unik (semua AWS), terikat pada 1 Region

Objectfail sebenar; identified by Key (full path nama, cth photos/2026/cat.jpg)

Key"nama penuh" object dalam bucket (prefix + nama). Tiada folder sebenar — prefix je

+3 more → Deep Notes
object storage11 nines durabilitystrong consistencybucket policyblock public accessversioningCRRSRRSSE-S3SSE-KMSSSE-Cmultipart upload5TBtransfer acceleration503 slow downprefixstatic websiteevent notificationlifecycle policy2 years730 daysStandard-IAGlacierglobal upload
D3 · High-Performing
S3 Access ControlS3 Access Control & Policies (IAM · Bucket Policy · ACL · BPA)
"Banyak 'policy' tu sebenarnya 2 famili: SIAPA boleh sentuh vs APA jadi kat data"

Kawal siapa boleh access bucket/object — pilih antara IAM Policy, Bucket Policy, ACL, atau Block Public Access

IAM Policyattach ke USER/ROLE (identity-based). "Apa user aku boleh buat" dalam akaun sama

Bucket Policyattach ke BUCKET (resource-based JSON). Cross-account, public, force HTTPS/encryption

ACLlegacy, per-object/bucket, coarse. AWS galak DISABLE (Bucket owner enforced)

+3 more → Deep Notes
S3 access controlIAM policybucket policyACLaccess control listblock public accessBPAcross-accountresource-based policyidentity-based policyexplicit denyaws:SecureTransportforce HTTPSOACCloudFront OACpublic bucketprincipalpricing
D3 · High-Performing
S3 GlacierAmazon S3 Glacier (storage classes)
"S3 sejuk beku — murah, tapi tunggu lama nak retrieve"

Archive jangka panjang, jarang/tak pernah access (compliance, backup lama)

archivingcold storageGlacier Instant RetrievalGlacier Flexible RetrievalGlacier Deep Archiverestore jobExpeditedStandardBulkmin storage durationlifecycle policyWORM11 nines
D3 · High-Performing
S3 Storage ClassesS3 Storage Classes — 7 Main Tiers + Express One Zone
"7 tingkat storan + Express One Zone — makin sejuk makin murah, makin lama nak cairkan"

Pilih S3 class ikut access pattern + retrieval speed + kos (the THE exam storage decision)

S3 StandardHot data, access frequent, default untuk most workloads (99.99% avail, ≥3 AZ)

S3 Standard-IAInfrequent access (~sebulan sekali) TAPI masih perlu millisecond retrieval; multi-AZ (contoh: DR backup)

S3 One Zone-IAInfrequent access, data dalam 1 AZ sahaja (20% lebih murah dari Standard-IA, risiko AZ musnah)

+5 more → Deep Notes
S3 StandardStandard-IAOne Zone-IAIntelligent-TieringS3 Express One ZoneGlacier Instant RetrievalGlacier Flexible RetrievalDeep Archivepricingstorage classretrieval feemin storage durationavailability11 nines durabilitylifecycle transitionauto-tieringrestore jobdirect GETmillisecond retrievalsingle-digit millisecondlatency-sensitiveAZ resiliencerarely accessed
D3 · High-Performing
S3 LifecycleS3 Lifecycle Management
"Auto-pindah object ke kelas murah ikut umur — macam roti: fresh → semalam → beku"

Automatically transition objects to cheaper storage classes + expire old objects

Transition rule"bila object umur X hari, pindah ke class Y" (cth: 30 hari → Standard-IA)

Expiration rule"bila object umur Z hari, delete permanently" (cth: 2555 hari → delete)

Filterboleh scope rule ikut prefix (folder), tags, atau object size

+3 more → Deep Notes
lifecycletransition ruleexpiration ruleauto-moveauto-deleteage-basedstorage class transitiontransition waterfallnoncurrent versionversioning cleanupS3 lifecycle policycost optimizationprefix filtertag filter2 years730 daysEFS lifecycle 365 max
D3 · High-Performing
S3 CORSS3 Cross-Origin Resource Sharing (CORS)
"Browser block request dari domain lain — CORS rule bagi kebenaran"

Allow web apps on one domain to access S3 resources on a different domain

CORScross-originbrowser securityAllowedOriginAccess-Control-Allow-Originweb appdomainbucket CORSXML configuration
D3 · High-Performing
S3 Pre-Signed URLS3 Pre-Signed URLs
"URL dengan tiket sementara — siapa ada boleh access, tapi hanya untuk tempoh tertentu"

Grant temporary time-limited access to a single S3 object without sharing credentials

presigned URLtemporary accessno credentialsIAM credentialsexpiry timedownloaduploadPUTGET403one objectvs CloudFront signed URL
🌐Networking & DeliveryDeep Notes →↑ Top
D3 · High-Performing
CloudFrontAmazon CloudFront
"CDN, content laju sampai — cache kat edge"

Deliver content laju via edge locations + serve private content securely

CloudFront Signed URL/Cookieaccess private content MELALUI CloudFront (edge-cached, global low latency, boleh restrict by IP range + expiry, guna trusted key group). Untuk serve at scale via CDN.

S3 Presigned URLdirect access ke SATU S3 object, signed dengan IAM credentials orang yang generate (inherit permission dia), takde CDN caching. Untuk one-off upload/download terus ke S3.

CDNedge locationlow latencystatic contentOACOrigin Access ControlLambda@EdgeCloudFront FunctionsSSE-KMSprivate S3signed URLsigned cookieS3 presigned URLTTLcachinginvalidationgeo restrictiongeo blockingprice class
D3 · High-Performing
ALBApplication Load Balancer
"Traffic director — by path/host, Layer 7"

HTTP/HTTPS path-based routing, microservices, containers

Listener"telinga" ALB yang dengar request pada port + protocol tertentu (cth HTTP:80, HTTPS:443). Sini kau pasang ACM cert untuk SSL/TLS termination.

Rulesundang-undang saringan pada listener: "kalau path = /api/* → hantar ke Target Group Backend". Dinilai ikut priority; ada default rule sebagai fallback. Condition boleh path, host, header, query string, source IP.

Target Groupbakul server yang buat satu tugas. Health check jalan ke SETIAP target dalam bakul ni. Satu rule tunjuk ke satu target group.

+2 more → Deep Notes
ELBElastic Load BalancingELB vs ALBEC2 behind ELBEC2 behind ALBload balancer typesALB vs NLBpath-based routinghost-based routingHTTPHTTPSlayer 7IP targetscross-VPCmicroservicesListenerListener RulesTarget Grouptarget typeshealth checkSSL terminationTLS terminationACM certificateSNIstickinesssession affinitycross-zone load balancingderegistration delayconnection drainingSpot interruptionAuto ScalingASGMixed Instances Policycapacity rebalancing502 Bad GatewayLambda targetX-Forwarded-Forpricing
D3 · High-Performing
NLBNetwork Load Balancer
"Traffic director — ultra laju, Layer 4, static IP"

TCP/UDP, low latency, static IP, PrivateLink endpoint service, cross-VPC with IP targets

Listenerdengar pada protokol Layer 4: TCP, UDP, TCP_UDP, atau TLS (+ QUIC). TIADA "Rules path/host" macam ALB — NLB tak baca HTTP. TLS listener boleh terminate SSL guna ACM cert (offload decrypt dari target).

Target Groupbakul target; protokol TCP/UDP/TCP_UDP/TLS/QUIC. Health check PER target group, boleh guna TCP, HTTP, atau HTTPS (boleh ketuk path /health walaupun NLB sendiri L4).

Targets3 jenis: instance (EC2 by ID), ip (peered VPC / on-prem via DX/VPN), atau ALB (NLB boleh daftar ALB sebagai target → dapat static IP + L7 path routing serentak). ASG daftar/drain automatik.

+2 more → Deep Notes
TCPUDPTCP_UDPTLSQUIClayer 4static IPElastic IPIP targetscross-VPClow latencymillions of requestspreserve source IPpreserve client IPPrivateLinkVPC Endpoint Serviceendpoint serviceNLB frontTLS terminationTLS passthroughidle timeouttcp.idle_timeout.secondslong-lived connectioncross-zone load balancingALB as targethealth checkgamingIoTVoIPpricing
D3 · High-Performing
GWLBGateway Load Balancer
"Pos pemeriksaan keselamatan — semua paket lalu firewall/IDS, Layer 3, GENEVE 6081"

Salur SEMUA trafik melalui fleet virtual appliance (firewall / IDS / IPS / DPI) secara terpusat & transparent

Listenerdengar SEMUA IP packet merentas SEMUA port (Layer 3). Tiada port/protocol spesifik macam ALB (HTTP:443) atau NLB (TCP:80) — GWLB telan semua. Satu listener, hantar ke satu target group.

Target Groupbakul virtual appliance (firewall / IDS / IPS / DPI). Target jenis instance (EC2 by ID) atau ip. Health check pastikan appliance hidup; appliance rosak dibuang dari rotation.

Targetsmesin pemeriksa sebenar (3rd-party security appliance). GWLB + appliance bertukar trafik guna GENEVE encapsulation port 6081 — paket asal dibalut, dihantar ke appliance untuk inspect, pastu dipulangkan.

+2 more → Deep Notes
GWLBGateway Load Balancerlayer 3IP packetsGENEVEGENEVE 6081port 6081virtual appliancefirewallIDSIPSdeep packet inspectionDPItransparentbump-in-the-wireflow stickiness5-tuple3-tuple2-tupleGWLBeGateway Load Balancer EndpointPrivateLinkcentralized inspectionsecurity VPCinspection VPCnext hoproute tablePalo AltoFortinet3rd-party applianceegress inspectioneast-west trafficpricing
D3 · High-Performing
Route 53Amazon Route 53
"GPS untuk domain"

DNS management, domain routing

DNSdomainrouting policyfailoverAlias recordCNAMEapex domainroot domaincannot CNAME apexhosted zonepublic hosted zoneprivate hosted zonepricing
D3 · High-Performing
Route 53 Routing PoliciesAmazon Route 53 — Routing Policies
"Cara Route 53 decide siapa dapat traffic"

Control how DNS traffic is routed to resources

Simple1 resource, no health check, no failover

Weightedsplit traffic by % (A=70%, B=30%)

Latency-basedroute to lowest latency AWS region

+4 more → Deep Notes
failoveractive-passivehealth checkweightedlatency-basedgeolocationsimpleEvaluate Target Healthhybrid failovertwo alias recordson-premises secondary
📨Messaging & ServerlessDeep Notes →↑ Top
D3 · High-Performing
SQSSimple Queue Service
"Baris gilir message"

Decouple services, async queue

Visibility TimeoutMessage invisible semasa diproses (max 12 jam). Jika consumer mati sebelum siap → message visible semula selepas timeout

Delay SecondsDelay sebelum message pertama kali visible dalam queue (max 15 minit)

Dead Letter Queue (DLQ)Message yang gagal diproses N kali dihantar ke DLQ untuk debug

+1 more → Deep Notes
queuedecoupleasyncpull-basedvisibility timeoutFIFODLQat-least-onceexactly-oncelong pollingshort pollingbatch operationsduplicate messagesqueue policycross-account SQSresource-based policySNS SQS Lambda fan-outSQS vs SNS vs EventBridgepilih messaging servicepull vs pushS3 SQS decoupleasync file uploadburst traffic bufferstore file S3 not DynamoDBtemporary file storagemaxReceiveCountRedrivePolicyDLQ redrivepoison pillfailed messagesisolate corrupted messagesdead-letter queuePrincipalsource accountdestination accounttwo keysdua kunciSendMessage cross-accountaws:PrincipalOrgIDqueue policy JSONqueue-based scalingApproximateNumberOfMessagesVisiblebacklog per taskcustom metric scalingscale on queue depthLambda producer consumerLambda throttling bufferacknowledge when acceptedpricing
D3 · High-Performing
SNSSimple Notification Service
"Broadcast message ke ramai sekaligus — push, bukan pull"

Push notification ke many subscribers (fan-out)

Message FilteringSubscriber boleh set filter policy (JSON) supaya hanya terima message yang match criteria — tak perlu filter dalam app code

Message DeliveryPush-based, SNS hantar ke subscriber endpoint. Retry policy built-in untuk HTTP/S

FIFO TopicsOrdered, deduplicated delivery (pair dengan SQS FIFO queues). Max 300 publishes/sec (3000 with batching)

+1 more → Deep Notes
pub/subpush notificationfan-outbroadcasttopicsubscriptionfilter policymessage filteringSNS FIFOcross-account SNSS3 event notificationpush-based
D3 · High-Performing
KinesisAmazon Kinesis (Data Streams vs Firehose)
"Streaming pipe — Streams = real-time + code, Firehose = auto-deliver no code"

Ingest & process real-time streaming data (logs, clickstream, IoT, metrics)

real-timestreamingdata pipelineanalyticsData StreamsFirehoseshardsretentionclickstreamIoTreplayserverless deliveryKinesis Video StreamsKVSvideo streamCCTVManaged Service for Apache FlinkKinesis Data Analytics
D3 · High-Performing
Kinesis Video StreamsAmazon Kinesis Video Streams (KVS)
"Paip VIDEO — bukan paip data. CCTV/drone/doorbell masuk cloud. Dua mod: simpan+playback ATAU WebRTC dua-hala"

Ingest, simpan, playback & proses VIDEO/audio live dari beribu kamera/IoT device (CCTV, drone, dashcam, video doorbell) untuk ML/playback

Kinesis Video StreamsKVSvideo streamCCTVcameradronedashcamvideo doorbellbaby monitorWebRTCtwo-waypeer-to-peersignaling channelSTUNTURNHLSDASHRTSPGStreamerkvssinkfragmentRekognition Videotime-encoded datamedia streamlive videoplaybacktelehealthpricing
D3 · High-Performing
API GatewayAmazon API Gateway
"Pintu masuk untuk API — REST / HTTP / WebSocket"

Manage & expose REST, HTTP, dan WebSocket APIs

REST APIfull features: API keys + usage plans (per-client throttling), request validation, AWS WAF, resource policies, private endpoint, endpoint types edge-optimized/regional/private

HTTP APIminimal features, ~70% lebih murah, lower latency, JWT (OIDC/OAuth2) authorizer, regional sahaja — pilih bila tak perlu REST extras

WebSocket APIbidirectional real-time (chat, games, trading, live dashboard) — server push ke client

REST APIHTTP APIWebSocketreal-timebidirectionalAPI managementthrottlingusage plansAPI keysrequest validationAWS WAFJWT authorizerCognitoLambda authorizerIAM authorizeredge-optimizedregional endpointprivate endpointmapping templatesbackward compatibilityVTLresponse transformationcache keyCORSexecution loggingaccess loggingrequest response payloadsVPC Linkcross-account LambdaOpenAPISwaggerimport definitionserverless
D3 · High-Performing
EventBridgeAmazon EventBridge
"Trafik light untuk events — route events ke tempat betul"

Serverless event bus: decouple services, schedule tasks, react to AWS service changes

event busevent-drivencron schedulerule-based routingdecoupleSaaS integrationCloudWatch Eventsschema registryarchive replayEventBridge PipesEventBridge Scheduler
D3 · High-Performing
Step FunctionsAWS Step Functions
"Flowchart yang run sendiri — orchestrate multi-step workflows"

Coordinate multi-step processes with error handling, retry, and branching

workflowstate machineorchestrationretry logicerror handlingLambda orchestrationvisual workflowDistributed Mapparallel processingStandard workflowExpress workflowexactly-onceat-least-onceidempotentcallback patternwaitForTaskTokensync integrationASLAmazon States LanguageChoice stateMap stateActivitiesSWFpricingstate transition pricing
D3 · High-Performing
Amazon MQAmazon MQ
"SQS tapi untuk apps lama yang guna ActiveMQ/RabbitMQ"

Migrate existing ActiveMQ/RabbitMQ message brokers to AWS without code changes

EngineActiveMQ atau RabbitMQ (pilih ikut protokol app sedia ada)

Protokol terbukaAMQP, MQTT, STOMP, OpenWire, WebSocket, JMS — sebab itu app lama boleh sambung tanpa tukar code

Brokerinstance yang AWS urus (patching, HA). Bukan serverless macam SQS

+2 more → Deep Notes
ActiveMQRabbitMQAMQPMQTTlift-and-shiftmessage brokerlegacy migrationopen protocolsSTOMPOpenWireJMSAmazon MQ vs SQSmanaged broker
D3 · High-Performing
Kinesis Data FirehoseAmazon Kinesis Data Firehose
"Paip streaming data terus ke S3/Redshift — no code needed"

Capture and load streaming data to S3, Redshift, OpenSearch, Splunk automatically

delivery streamS3 deliveryRedshiftOpenSearchno consumer codebuffertransform with LambdaParquet conversionpricing
D3 · High-Performing
AppFlowAWS AppFlow
"Penyambung SaaS → AWS, tanpa code"

Automated no-code data transfer between SaaS apps (Salesforce, ServiceNow, Slack) and AWS services

AppFlowSaaS integrationSalesforceServiceNowno-code connectordata transferbidirectionalS3RedshiftDataSyncGluepricing
D3 · High-Performing
AppSyncAWS AppSync
"GraphQL API yang managed — real-time + offline sync"

Build GraphQL APIs with real-time data sync and offline capability

GraphQLreal-timesubscriptionsWebSocketoffline syncconflict resolutionresolversDynamoDBmultiple data sourcesmobileAmplifyAPI Gatewaypricing
D3 · High-Performing
AmplifyAWS Amplify
"Heroku/Vercel-nya AWS — fullstack web/mobile hosting + backend"

Build and host fullstack web/mobile apps with managed backend services

fullstackCI/CDfrontend hostingmobileReactNext.jsCognitoAppSyncbackend-as-a-serviceBaaSFirebaseFirebase alternativeAmplify AuthAmplify StorageGit deployCDN
🏗️InfrastructureDeep Notes →↑ Top
D3 · High-Performing
CloudFormationAWS CloudFormation
"Blueprint untuk AWS resources"

Automate infrastructure deployment, consistent environment

IaCInfrastructure as Codetemplatestackrollbackrepeatable deploymentLambda-backed custom resourceAMI lookupdynamic parametersmulti-region templateMappingsOutputscross-stack referenceFn::ImportValuecfn-initcfn-signalcfn-hupcfn-get-metadatachange setdrift detectionstack rollbackDeletionPolicynested stacksAWS::CloudFormation::Stackmodular templatesStackSetsfreepricingno additional chargeResourcesTransformSAMServerless Application ModelStack PolicyTermination ProtectionMetadatatemplate sectionsConditionsParameters
D3 · High-Performing
SSMAWS Systems Manager
"Remote control untuk EC2 fleet"

Manage, patch, and run commands on EC2 instances at scale

Run CommandPatch ManagerParameter StoreSession Managerno SSHfleet managementparallel executionAmazonSSMManagedInstanceCoreSecureStringKMSStandard tierAdvanced tierbastion-freeSecrets Managerauto-rotationpricingfree tieradvanced params costsession manager included
D3 · High-Performing
AWS ConfigAWS Config
"Audit & track apa yang berubah"

Track configuration changes and compliance of AWS resources

Configuration Recorderenjin yang detect & rekod setiap perubahan config resource. Kena ON dulu, kalau OFF Config tak rekod apa-apa

Configuration Item (CI)1 snapshot point-in-time bagi SATU resource (state + relationship + metadata). Ini unit yang kau bayar $0.003 setiap satu

Configuration Historytimeline semua CI bagi satu resource — boleh banding "semalam vs hari ni"

+3 more → Deep Notes
complianceauditconfig changesconfig rulesresource historydrift detectionauto-remediationconformance packsConfig aggregatorSSM Automationmanaged rulescustom rulespricingper configuration itemper rule evaluation
D3 · High-Performing
CodeCommitAWS CodeCommit
"GitHub tapi dalam AWS"

Private Git repository dalam AWS ecosystem

Gitsource controlversion controlprivate repoIAM integrationpricing
D3 · High-Performing
CI/CD PipelineCodeCommit → CodeBuild → CodeDeploy → CodePipeline
"4 Code services = full DevOps pipeline"

Automate build, test, and deploy pipeline end-to-end

CodeCommitStore & version control source code (Git)

CodeBuildCompile, test, produce build artifacts

CodeDeployDeploy ke EC2, Lambda, ECS, on-premises

+1 more → Deep Notes
CI/CDCodePipelineCodeBuildCodeDeployDevOpsautomationpipelineblue-greencanaryorchestratorpricing
D3 · High-Performing
CloudWatchAmazon CloudWatch
"Dashboard, logs, dan alarm untuk semua dalam AWS"

Monitor metrics, collect logs, set alarms, create dashboards for AWS resources

metricslogsalarmsdashboardsCPU monitoringcustom metricsLog GroupsVPC Flow LogsCloudWatch agentunified agentmemory utilizationdetailed monitoringLogs Insightsquery logsSQL-likepricingfree tiercustom metrics costlog ingestion cost
D3 · High-Performing
X-RayAWS X-Ray
"GPS untuk trace request melalui microservices"

Distributed tracing — debug latency and errors across microservices and serverless

distributed tracingservice maplatency analysismicroservicesLambda tracingbottleneckdebuggingSQS tracingend-to-end tracebottleneck detectionX-Ray Insightsanomaly detectionpricing
D3 · High-Performing
AWS Health DashboardAWS Health Dashboard
"Status AWS untuk AKAUN KAU sendiri, bukan global"

See AWS service issues and scheduled changes that affect YOUR specific account/resources

service healthpersonal health dashboardscheduled changesaccount eventsEventBridgeoperational issuesmaintenance notification
🗄️DatabasesDeep Notes →↑ Top
D3 · High-Performing
Pilih DatabaseWhich AWS Database? — purpose-built selector
"Tiap database ada KERJA dia — match shape data dengan engine"

Pilih database betul ikut shape data + access pattern (THE exam decision)

purpose-built databaseOLTP vs OLAPrelationalNoSQLkey-valuedocumentgraphwide-columntime-seriesdatabase selectionwhich databaseserverless vs instancepricingwhat is RDSnot RDSRDS enginessix RDS enginesMySQL PostgreSQL MariaDB Oracle SQL Serverserver-based vs serverlessRDS vs Aurora ServerlessAurora not serverless
D3 · High-Performing
DocumentDBAmazon DocumentDB
"MongoDB dalam AWS — JSON documents"

JSON document store, MongoDB-compatible workloads migrate to AWS

Clustersatu primary instance (read+write) + sampai 15 replica (read-only) merentas AZ untuk HA.

Compute & storage BERPISAHinstance handle query, storage layer auto-grow 10GB → 64TB sendiri (kau tak provision disk).

Storage replicate 6 salinan / 3 AZ (sama macam Aurora)durable + failover auto.

+2 more → Deep Notes
MongoDB compatibledocument storeJSONBSONcollectionsNoSQLMongoDB migrationDocumentDB pricingpricing64TBI/O-Optimized
D3 · High-Performing
NeptuneAmazon Neptune
"Database untuk connections antara data — graph"

Social networks, fraud detection, knowledge graphs, recommendation engines

Data simpan sebagai nodes (benda) + edges (hubungan) + propertiesbukan rows/columns. Query = "ikut benang hubungan", bukan JOIN table.

Cluster1 primary (write) + sampai 15 read replica merentas AZ; storage auto-grow ke 64TB, 6 copies / 3 AZ (macam Aurora).

Dua model queryProperty Graph (guna Gremlin / openCypher) ATAU RDF (guna SPARQL). Pilih ikut data model app.

+1 more → Deep Notes
graph databasesocial networkfraud detectionfraud ringrecommendation engineGremlinSPARQLopenCypherproperty graphRDFrelationshipsknowledge graphconnected dataNeptune ServerlessNCUpricing
D3 · High-Performing
KeyspacesAmazon Keyspaces
"Cassandra dalam AWS — wide column, IoT, time-series"

Migrate Apache Cassandra workloads, IoT telemetry, time-series data

Keyspacemacam "database" dalam Cassandra; dalam dia ada tables (wide-column). Akses guna CQL (Cassandra Query Language) — sama macam Cassandra tulen.

Serverless penuhtakde node/cluster nak urus. AWS auto-scale throughput naik-turun ikut traffic.

Data replicate 3 salinan merentas AZ automatikdurable, HA.

+1 more → Deep Notes
Cassandra compatibleCQLwide columnIoT telemetrytime-serieshigh write throughputserverlesson-demand capacityprovisioned capacityWRURRUKeyspaces pricingpricing
D3 · High-Performing
TimestreamAmazon Timestream (for LiveAnalytics)
"Database khusus data ikut MASA — IoT sensor, metrics"

IoT sensor readings, app/DevOps metrics, apa-apa data yang ada timestamp & masuk berterusan

Ingestionterima writes laju (jutaan/saat), serverless, auto-scale. Setiap rekod = timestamp + dimensions + measures.

Memory storedata BARU duduk sini: laju untuk query terkini + write. Mahal/GB. Kau set tempoh simpan (cth 12 jam).

Magnetic storedata LAMA auto-turun sini: murah, untuk query sejarah. Kau set retention (cth 1 tahun).

+1 more → Deep Notes
time-seriesTimestreamIoT telemetrysensor datametrics over timememory storemagnetic storetiered storageserverlesshigh ingesttimestampTimestream pricingpricing
D3 · High-Performing
MemoryDBAmazon MemoryDB (Valkey / Redis OSS compatible)
"Redis yang TAK hilang data — in-memory tapi durable, jadi DB utama"

Primary database in-memory: microsecond reads + durability, untuk microservices yang perlu laju TAPI tak boleh hilang data

In-memory data storesemua data dalam RAM → microsecond reads, single-digit ms writes. Valkey/Redis OSS commands.

Multi-AZ transactional logINI yang bagi durability: setiap write ditulis ke log merentas berbilang AZ SEBELUM di-ack. Node mati → data tak hilang, failover pulih dari log.

Cluster + shardsdata dipecah ikut shard (horizontal scale); tiap shard ada primary + replica untuk HA.

+1 more → Deep Notes
MemoryDBdurable in-memoryRedisValkeyprimary databasemicrosecond readsMulti-AZ transactional login-memory databasedurabilityElastiCache alternativeMemoryDB pricingpricing
📊Analytics & StreamingDeep Notes →↑ Top
D3 · High-Performing
RedshiftAmazon Redshift
"Data warehouse — OLAP, columnar, petabyte SQL analytics"

Data warehouse: complex/recurring analytics atas structured data berskala besar

Leader Nodeterima query, buat plan, agih ke compute node, kumpul hasil

Compute Nodessimpan data + jalankan query selari (MPP)

RA3 + Managed Storagecompute & storage berasingan, bayar ikut guna; scale tanpa pindah data

+3 more → Deep Notes
data warehouseOLAPcolumnarMPPRA3managed storageRMSRedshift SpectrumRedshift Serverlessconcurrency scalingzero-ETLclusterleader nodecompute nodenode slicesdistribution keyDISTKEYsort keySORTKEYzone mapspetabyteBI analyticsAQUAAdvanced Query Acceleratornetwork bandwidthCPU processing limitspush down computequery acceleratorAQUA vs Spectrummanual snapshots costpricing
D3 · High-Performing
QuickSightAmazon QuickSight
"QuickSight = panel meter kereta: sensor (data) → meter cluster (SPICE) → pemandu nampak sekali pandang. Serverless BI, drag-drop, dia visualize."

Business intelligence dashboards, data visualization, ML-powered analytics

Data sourcesS3, Athena, Redshift, RDS/Aurora, sumber luar (databases, SaaS); QuickSight baca TERUS, tak payah ETL dulu

SPICESuper-fast Parallel In-memory Calculation Engine; cache data import dalam memori untuk dashboard laju & repeatable. Alternatif: Direct Query (pukul sumber live)

Analysiskanvas tempat kau bina visual (carta, jadual, peta)

+3 more → Deep Notes
QuickSightBIdashboardforecastingML InsightsvisualizationS3 directSPICEDirect Queryrow-level securityEnterprise editionembedded analyticsanomaly detectionauto-narrativeIoT analyticsActive Directory
D3 · High-Performing
AthenaAmazon Athena
"SQL terus pada S3 — serverless, bayar per TB scan"

Ad-hoc SQL analysis of data in S3 without loading to a database

serverless SQLS3 queriespay per scanParquetORCGlue Cataloglog analysisad-hocpartitioncolumnarQuickSightserverless analytics patternpricing
D3 · High-Performing
GlueAWS Glue
"Crawler endus schema → Catalog simpan → ETL Job transform. Glue = gam yang sambung data lake."

ETL jobs, data catalog for data lake, prepare and transform data for analytics

Data Catalogkedai metadata pusat (database, table, column, partition). Satu sumber kebenaran untuk Athena, EMR, Redshift Spectrum, Lake Formation

Crawlerconnect ke sumber (S3/JDBC/DynamoDB), infer schema, ISI Data Catalog. Boleh jadual berkala

Classifierkenal pasti format data (CSV/JSON/Parquet/custom grok); Crawler panggil Classifier untuk tentukan schema

+4 more → Deep Notes
ETLdata catalogSparkserverlesscrawlerclassifierETL jobDataBrewGlue Studioworkflowdata laketransformParquetschema discoveryDynamoDBschema inferenceDPUdata storedata sourcedata targetGlue tablemetadata definitiondatabase
D3 · High-Performing
Lake FormationAWS Lake Formation
"Pengawal keselamatan kolam (data lake) — row, column, cell level access + bina secure lake laju"

Fine-grained access control on data lake (row/column/cell) + simplify & accelerate creation of a secure data lake

Lake Formationrow-level securitycolumn-levelcell-levelfine-grained accessdata lakeGlue Data Catalogsecure data lakeaccelerate data lakesimplify data lakedata lake vs data warehousedata warehousegovernancecentralized access controlblueprintdata cleansingpricingdata swampraw zonelanding zonecleanse zonecurated zoneanalytics zonethree-zone data lakedata lake zones
D3 · High-Performing
EMRAmazon EMR
"EMR = Elastic + Master node + Ramai-pekerja: Elastic cluster, Master node (ketua agih kerja), Ramai pekerja (Core/Task). Hadoop/Spark, kau urus cluster (BUKAN serverless)."

Process petabyte-scale data with Spark, Hadoop, Hive, Presto — full control

HadoopSparkHivePrestoHBasebig dataclusterpetabytemanagedSpot instancesmaster nodecore nodetask nodeHDFSNameNodeDataNodeblockreplicationEMRFSETL pipelinetransient clusterEMR ServerlessEMR on EKS
D3 · High-Performing
OpenSearchAmazon OpenSearch Service
"Enjin carian dan log analytics — Elasticsearch dalam AWS"

Full-text search, real-time log/event analytics, dashboard visualisation

search enginelog analyticsElasticsearch compatibleKibanaOpenSearch Dashboardsreal-time analyticsfull-text searchfuzzyUltraWarmcold storagededicated masterFirehose ingestionrelevance ranking
D3 · High-Performing
MSKAmazon MSK
"Kafka dalam AWS — managed, tak payah urus brokers"

Real-time event streaming dengan Kafka API — migrate or build Kafka workloads

Kafkamanagedstreamingevent streamingmigrationKafka APIreal-time pipelinebrokersno SSHevent source mappingMSK Serverlessauto scaling storagepartitionpricingbroker-hour
D3 · High-Performing
KendraAmazon Kendra
"Google-like ML search for your enterprise documents"

Intelligent enterprise search across diverse document repositories

Kendraenterprise searchML searchsemantic searchnatural language queryFAQsunstructured documentsintelligent searchpricingexpensive
D3 · High-Performing
Data ExchangeAWS Data Exchange
"AWS marketplace untuk beli/subscribe third-party data"

Subscribe to and access third-party datasets for analytics

Data Exchangethird-party datadata marketplacedata subscriptionmarket datafinancial datadata productsS3 deliverylicensingentitlementpricing
D3 · High-Performing
AWS AI/ML ServicesAWS AI Services — Polly, Rekognition, Lex, Comprehend, Textract, Transcribe, Translate
"Polly = cakap. Transcribe = dengar. Lex = faham + balas. Rekognition = nampak. Comprehend = baca. Textract = scan dokumen. Translate = tukar bahasa"

AI/ML services untuk audio, video, text, image analysis without training models

Amazon PollyText-to-Speech (TTS): convert text jadi audio (natural voice)

Amazon TranscribeSpeech-to-Text (STT): convert audio/video jadi text

Amazon LexConversational chatbot: NLU + ASR, maintains context, integrates Lambda (powers Alexa)

+5 more → Deep Notes
PollyTranscribeLexRekognitionComprehendComprehend MedicalTextractTranslateKinesis Video Streamstext-to-speechspeech-to-textchatbotimage analysisStartSpeechSynthesisTaskaudiobookOCRNLPsentiment analysisentity recognitiondocument extractionmachine translationPHIHIPAA
D3 · High-Performing
SageMakerAmazon SageMaker
"Custom ML end-to-end — train, tune, deploy your own models"

Build, train, and deploy custom ML models with full control

SageMakercustom MLtrainingAutoMLAutopilothyperparameter tuningmodel deploymentMLOpsFeature StorePipelinesreal-time endpointserverless inferencebatch transformasync inferencepricing
DOMAIN 4 · 20% OF EXAM

Design Cost-Optimized Architectures

Pricing Models · Storage · Networking · Database

💰EC2 Pricing ModelsDeep Notes →↑ Top
D4 · Cost-Optimized
On-DemandEC2 On-Demand Instances
"Bayar ikut jam, bila-bila boleh stop"

Workload tak menentu, short-term, testing

no commitmentflexibleshort-termhighest costper-second billingper-hour billingpricingOn-Demand Capacity ReservationODCRguaranteed capacity
D4 · Cost-Optimized
Reserved InstancesEC2 Reserved Instances (RI)
"Commit 1-3 thn → diskaun sampai 72%. Standard = murah-tegar, Convertible = fleksibel-kurang"

Workload steady predictable 24/7 untuk 1-3 tahun

1 or 3 yearup to 72% discountStandard RIConvertible RIexchangemodifyAll UpfrontPartial UpfrontNo UpfrontRegional RIZonal RIcapacity reservationRI Marketplace
D4 · Cost-Optimized
Spot InstancesEC2 Spot Instances
"Kapasiti EC2 lebihan, sampai 90% murah — tapi AWS boleh ambil balik dengan notis 2 minit"

Batch jobs, fault-tolerant & stateless workloads, flexible timing

Notis interrupt 2 minit datang melalui DUA saluran: (1) EventBridge event "EC2 Spot Instance Interruption Warning" (detail-type), dan (2) instance metadata pada instance itu sendiri. Best practice: poll metadata setiap 5 saat. Ada juga Rebalance Recommendation — signal AWAL sebelum notis 2 minit, bagi peluang pindahkan beban lebih cepat. NOTA: kalau interruption behavior = hibernate, kau dapat notis tapi BUKAN 2 minit awal (hibernate mula serta-merta).

up to 90% discountinterruptible2-minute interruption noticeEventBridgeinstance metadatarebalance recommendationterminatestophibernatepersistent requestSpot FleetEC2 Fleetmixed instances policycapacity-optimizedprice-capacity-optimizedcapacity rebalancingfault-tolerantbatch jobs
D4 · Cost-Optimized
Savings PlansAWS Savings Plans (SP)
"Commit $/jam, bukan instance. Compute = paling fleksibel (+Fargate/Lambda), EC2 Instance = diskaun lebih besar"

Steady compute spend tapi nak fleksibiliti tukar instance/region — auto-apply

flexiblehourly commitmentup to 66% discountCompute Savings PlansEC2 Instance Savings PlansFargateLambdaauto-applyvs Reserved Instancesbilling apply order
D4 · Cost-Optimized
Compute OptimizerAWS Compute Optimizer
"AI yang cadang right-size EC2, Lambda, EBS — guna ML analyse usage"

Rightsizing recommendations for EC2, Lambda, EBS, ECS on Fargate, Auto Scaling Groups

rightsizingML recommendationsEC2 optimizationLambda optimizationcost savingsunderutilizedvs Trusted Advisor14 days metricsfreepricing
D4 · Cost-Optimized
Trusted AdvisorAWS Trusted Advisor
"Penasihat jimat kos AWS"

Identify idle resources, cost optimization recommendations

Cost Optimizationidle/underutilized resources, idle load balancers, unassociated Elastic IPs, RI/SP purchase opportunities

Performanceover-utilized instances, high-latency config, EBS throughput, service config yang melambatkan

Securityopen security groups, public S3 buckets, MFA on root, IAM key exposure, exposed access keys

+2 more → Deep Notes
cost recommendationsidle resourcesrightsizingunderutilizedservice limitsfive categoriesCost OptimizationPerformanceSecurityFault Tolerancerule-basedvs Compute Optimizer7 core checksBusiness supportEnterprise supportpricing
D4 · Cost-Optimized
AWS BudgetsAWS Budgets
"Alarm sebelum spend cecah limit"

Set cost/usage thresholds and get alerted before overspending

budget alertscost thresholdSNS notificationusage budgetforecast alertbefore overspendbudget actionspricing
D4 · Cost-Optimized
Cost ExplorerAWS Cost Explorer
"Graf dan analisis spending AWS"

Visualise and analyse AWS costs — understand patterns, get RI/SP recommendations

cost analysisspending visualizationRI recommendationsusage patternsrightsizingforecasthourly granularityanomaly detectionCost Anomaly Detectionunusual spendinganomalous spendvs BudgetsCUR
D4 · Cost-Optimized
Cost Anomaly DetectionAWS Cost Anomaly Detection
"ML detect spike pelik → alert + root cause — bukan threshold tetap"

Detect unusual/anomalous AWS spend patterns and alert departments automatically

Cost Anomaly Detectionunusual spendinganomalous spendMLcost monitorroot causeSNS alertseasonalityvs Budgetsvs CloudWatch EstimateChargesvs Cost Explorerzero spend budgetpricing
D4 · Cost-Optimized
Instance SchedulerInstance Scheduler on AWS
"Office hours je — auto stop EC2 + RDS malam & weekend (CFN template)"

Auto start/stop EC2 + RDS on a fixed weekday schedule with minimal ops overhead

Instance Scheduler on AWSstart stop scheduleoffice hoursweekday onlypart-time workloadCloudFormation solutionEC2 RDS scheduleminimal operational overheadAWS Solutionstag-based schedule70% savingsvs Reserved Instancesvs Savings Planspricing
D4 · Cost-Optimized
Cost & Usage ReportAWS Cost and Usage Report (CUR)
"Data billing PALING detail → drop ke S3 → query guna Athena"

Raw line-item billing paling granular untuk custom/deep cost analysis

Cost and Usage ReportCURline-item billingmost granularS3 deliveryCSVParquetAthenaRedshiftQuickSightper-resourcehourlyraw billing data
D4 · Cost-Optimized
Cost Allocation TagsAWS Cost Allocation Tags
"Label resource → tahu duit pergi mana"

Track & group kos ikut team / projek / environment

cost allocation tagsAWS-generateduser-definedactivate in billingtrack cost by tagcost center
D4 · Cost-Optimized
Consolidated BillingAWS Organizations Consolidated Billing
"Satu bil untuk semua account + diskaun dikongsi"

Gabung billing banyak account, kongsi volume/RI/SP discount

consolidated billingmanagement accountmember accountsvolume discountshared RIshared Savings Plansone billfree
💾Storage Cost OptimizationDeep Notes →↑ Top
D4 · Cost-Optimized
S3 Storage TiersAmazon S3 Storage Classes — Cost View (the TOTAL bill, bukan storage je)
"4 lapisan bil: storan + retrieval fee + min-duration + min 128KB/objek"

Pilih tier yang paling MURAH all-in untuk access pattern data — cost-optimization (D4 angle, bukan retrieval-speed)

Lapisan 1 — Storage $/GB-moharga simpan tiap GB sebulan (Standard mahal → Deep Archive paling murah)

Lapisan 2 — Retrieval fee $/GBbayar tiap kali tarik data balik (Standard & Intelligent-Tiering = $0; IA & Glacier kena caj, makin sejuk makin mahal tarik)

Lapisan 3 — Minimum storage durationdelete sebelum tempoh min still kena bayar baki (Standard none · IA 30d · Glacier 90d · Deep Archive 180d)

+2 more → Deep Notes
storage classescost optimizationlifecycle policyinfrequent accessglacierGlacier Instant RetrievalGlacier Deep ArchiveOne Zone-IAStandard-IAIntelligent-Tieringretrieval feeminimum storage durationearly delete feeminimum billable object size128KBbreak-evensmall objectsStorage Class Analysistransition request costpricing
D4 · Cost-Optimized
S3 Intelligent-TieringS3 Intelligent-Tiering
"AWS pilihkan tier yang paling murah secara auto"

Data dengan access pattern tak menentu

Frequent Accesstier default masuk. Sama harga macam S3 Standard ($0.023/GB)

Infrequent Accessauto turun lepas 30 hari TAK akses. Sama harga Standard-IA ($0.0125/GB)

Archive Instant Accessauto turun lepas 90 hari tak akses. Retrieval ms (instant). ~$0.004/GB

+2 more → Deep Notes
auto-tieringunpredictable accessno retrieval feesaccess tiersfrequent accessinfrequent accessarchive instant accessarchive accessdeep archive accessmonitoring feechanging access pattern128KB minimumS3 storage classespricing
🌐Networking Cost OptimizationDeep Notes →↑ Top
D4 · Cost-Optimized
CloudFrontAmazon CloudFront
"CDN yang jimatkan data transfer cost"

Reduce data transfer cost, cache content dekat user

reduce data transferedge cachingCDNcost saving
D4 · Cost-Optimized
VPC EndpointsAWS VPC Endpoints
"Jalan dalam rumah, tak payah keluar internet"

EC2 → S3/DynamoDB tanpa kena NAT Gateway fees

no NAT feesprivate connectionS3 gatewayno internet
🗄️Database Cost OptimizationDeep Notes →↑ Top
D4 · Cost-Optimized
ElastiCacheAmazon ElastiCache
"Cache depan database, kurangkan DB load"

Cache frequent queries, reduce RDS cost

RedisMemcachedin-memoryreduce DB loadcachingsub-millisecondleaderboardssession storelazy loadingwrite-throughcache missTTLmulti-threadedpersistencereplication
D4 · Cost-Optimized
DynamoDB On-DemandAmazon DynamoDB On-Demand
"Database bayar per request, zero urus capacity"

Unpredictable traffic, serverless apps

NoSQLpay per requestserverlessauto-scaleunpredictable trafficprovisioned capacityRCUWCUread request unitswrite request unitsreserved capacitycapacity modepricing
🔄DR Strategies (Cost vs RTO/RPO)Deep Notes →↑ Top
D4 · Cost-Optimized
DR Cost SpectrumDisaster Recovery — Cost vs RTO/RPO Spectrum
"Kiri murah+lambat → kanan mahal+laju. Bajet ketat + RTO puluhan minit = Pilot Light"

Pick the cheapest DR pattern that still meets stated RTO/RPO — exam loves budget + recovery-time trade-offs

Backup & Restore — tiada infra DR. Bencanaprovision semua + restore backup. RTO/RPO jam. Kos $.

Pilot Light — data replicate & LIVE (DB on). App server OFF. Bencanahidupkan app + scale. RTO/RPO puluhan minit. Kos $$.

Warm Standby — full stack scaled-down SENTIASA ON. Bencanascale up + failover DNS. RTO/RPO minit. Kos $$$.

+1 more → Deep Notes
DR spectrumRTORPOPilot LightWarm StandbyBackup and RestoreMulti-Siteactive/passiveactive/activebudget concernsfinancial institute20 minutescost-optimized DRpricing
FRAMEWORK · ALL DOMAINS

AWS Well-Architected Framework

SAA-C03 exam validates ability to design solutions based on the Well-Architected Framework.

🏛️Six PillarsDeep Notes →↑ Top
Framework · all domains
Operational ExcellenceWell-Architected: Operational Excellence
"Jalankan dan pantau systems, improve processes"

Run and monitor systems to deliver business value and continually improve processes

IaCautomationrunbooksCI/CDmonitoringcontinuous improvement
Framework · all domains
SecurityWell-Architected: Security
"Lindungi data, systems, dan assets"

Protect information, systems, and assets via risk assessments and mitigation strategies

least privilegeIAMencryptiondetective controlsdata protectionincident response
Framework · all domains
ReliabilityWell-Architected: Reliability
"Recover dari failures, scale untuk demand"

Ensure workload performs correctly and consistently, including recovery from failures

Multi-AZauto-recoveryRTORPOdisaster recoveryhorizontal scalingfault isolation
Framework · all domains
Performance EfficiencyWell-Architected: Performance Efficiency
"Guna resources dengan efficient, adapt bila ada perubahan"

Use computing resources efficiently to meet requirements and maintain efficiency as demand changes

right-sizingserverlesscachingCDNglobal deploymentbenchmarking
Framework · all domains
Cost OptimizationWell-Architected: Cost Optimization
"Deliver value pada harga terendah"

Run systems to deliver business value at the lowest price point

right-sizingReserved InstancesSpotSavings Planseliminate wastecost allocation tags
Framework · all domains
SustainabilityWell-Architected: Sustainability
"Kurangkan environmental impact — pillar ke-6 (2021)"

Minimize environmental impacts of running cloud workloads

sustainabilitycarbon footprintenvironmental impact6th pillarserverlessutilisationrenewable energy2021
BONUS · NOT IN EXAM

Extra Tools & Open-Source

Bukan AWS native — tapi berguna untuk real-world. Tak keluar dalam SAA-C03.

🛠️Open-Source Database ToolsDeep Notes →↑ Top
Extra · not in exam
LitestreamLitestream (SQLite Streaming Replication)
"SQLite backup ke S3 secara real-time — murah, mudah, auto"

Continuously replicate a SQLite database to S3 (or GCS / Azure Blob) for near-zero-cost backup and restore

SQLiteWALS3 replicationsidecaropen-sourcebackupnot AWS nativesingle servercheap DB