Topik Index

Ada ke cover? Cari sini.

Index semua topik → card Deep Notes. Taip keyword (cth: encryption, NAT, failover, lifecycle, queue scaling) dan terus klik ke card penuh.

Trigger WordsGlossaryDeep NotesScenarios

DOMAIN 1 · 30% OF EXAMDesign Secure Architectures

🔑 IAM & Identity · 11

IAMAWS Identity and Access Management

users, groups, roles, policies, least privilege, MFA, principals, identity federation

STSAWS Security Token Service

temporary credentials, AssumeRole, AssumeRoleWithSAML, AssumeRoleWithWebIdentity, GetSessionToken, GetFederationToken, cross-account, role chaining

Directory ServiceAWS Directory Service

Active Directory, Managed Microsoft AD, AD Connector, Simple AD, LDAP, Kerberos, Group Policy, on-premises AD

IAM Identity CenterAWS IAM Identity Center (SSO)

SSO, single sign-on, multiple accounts, federation, SAML 2.0, Active Directory, SaaS integration, EC2 Windows

IAM Access AnalyzerAWS IAM Access Analyzer

IAM Access Analyzer, external access, unused access, zone of trust, public access, cross-account exposure, resource shared external, automated reasoning

AWS RAMAWS Resource Access Manager

AWS RAM, Resource Access Manager, share resources, VPC sharing, shared subnets, Transit Gateway sharing, Route 53 Resolver rules, cross-account sharing

IAM Roles AnywhereAWS IAM Roles Anywhere

IAM Roles Anywhere, on-premises, X.509 certificate, trust anchor, hybrid, temporary credentials, no access keys, non-AWS workload

AWS ArtifactAWS Artifact

AWS Artifact, compliance reports, SOC, ISO 27001, PCI DSS, FedRAMP, BAA, HIPAA

CognitoAmazon Cognito

User Pools, Identity Pools, OAuth, JWT, federated identity, MFA, STS, temp credentials

RAMAWS Resource Access Manager

cross-account sharing, shared subnets, Transit Gateway sharing, no resource duplication, AWS Organizations, centralized resources

AWS OrganizationsAWS Organizations + Control Tower + SCPs

multi-account, SCPs, guardrails, Control Tower, management account, OU, management account exemption, SCP cannot grant

🛡️ Network Security · 14

Security GroupsVPC Security Groups

stateful, instance-level, allow only, custom SG default, inbound denied, outbound allowed

NACLsNetwork Access Control Lists

stateless, subnet-level, allow & deny, numbered rules, explicit both ways, ephemeral ports, explicit deny, block IP

WAFAWS Web Application Firewall

Layer 7, SQL injection, XSS, rate limiting, managed rules, ALB, CloudFront, URI-specific rate-based rule

AWS ShieldAWS Shield Standard & Advanced

DDoS, Layer 3/4, Shield Standard, Shield Advanced, DRT, always-on, Shield Standard free, Shield Advanced paid

Network FirewallAWS Network Firewall

deep packet inspection, stateful, stateless, VPC-level, intrusion prevention, IDS/IPS, domain filtering, Suricata

VPC Flow LogsVPC Flow Logs

VPC Flow Logs, network monitoring, ACCEPT, REJECT, metadata, CloudWatch Logs, S3, Data Firehose

GuardDutyAmazon GuardDuty

threat detection, ML, CloudTrail logs, VPC Flow Logs, no agents, findings, S3 Protection, management events

DetectiveAmazon Detective

security investigation, forensics, GuardDuty findings, root cause, behavior graph, post-incident

InspectorAmazon Inspector

vulnerability scanning, CVE, EC2, ECR, Lambda, continuous, network reachability, package vulnerability

MacieAmazon Macie

PII detection, sensitive data, S3, ML-based, data privacy, GDPR, data discovery, policy findings

Security HubAWS Security Hub

Security Hub, aggregate findings, single pane of glass, compliance score, CIS, PCI DSS, FSBP, ASFF

Firewall ManagerAWS Firewall Manager

Firewall Manager, central firewall, across accounts, Organization wide, WAF policy, Shield Advanced, security group policy, Network Firewall policy

Penetration TestingAWS Penetration Testing Policy

penetration testing, pentest, security assessment, AUP, Acceptable Use Policy, no prior approval, 8 services, prohibited activities

Security StackAWS Security Services — Custom Rules & Integration

security stack, defense in depth, layered security, custom rules, suppression rules, custom data identifier, threat IP list, integration

🔐 Data Protection · 8

🔗 Connectivity · 3

🏘️ VPC & Networking · 11

VPCAmazon Virtual Private Cloud

VPC, CIDR, subnet, public, private, isolated network, default VPC, private network

CIDR & SubnetsIP Addressing & Subnet Calculator

CIDR, subnet mask, IP addressing, /24, /26, /27, 5 reserved IPs, usable hosts

Private/Public/Elastic IPEC2 IP Addresses — Private vs Public vs Elastic

Private IP, Public IP, Elastic IP, EIP, static IP, consistent public IP, Stop Start IP change, failover IP

Internet GatewayVPC Internet Gateway (IGW)

IGW, internet gateway, public subnet, bidirectional, free, 0.0.0.0/0

NAT GatewayNetwork Address Translation Gateway

NAT, outbound only, private subnet, Elastic IP, paid, no inbound, bastion host, cross-AZ cost

Route TablesVPC Route Tables

route table, routing, 0.0.0.0/0, local route, subnet association, main route table

SG vs NACLSecurity Groups vs Network ACLs — Defence Layers

SG, NACL, stateful, stateless, instance-level, subnet-level, deny, defense-in-depth

Laluan Packet VPCPerjalanan Satu Packet — VPC Traffic Flow (end-to-end)

packet journey, traffic flow, laluan packet, order of evaluation, IGW route table NACL SG, inbound order, outbound order, public subnet

VPC PeeringVPC Peering Connection

VPC peering, cross-account, cross-region, non-transitive, no IP overlap, private routing

Transit GatewayAWS Transit Gateway

Transit Gateway, hub, transitive routing, many VPCs, replace peering mesh, on-premises, cross-account, ECMP

VPC EndpointsVPC Endpoints (Gateway & Interface)

VPC endpoint, Gateway endpoint, Interface endpoint, PrivateLink, S3, DynamoDB, no internet, free

DOMAIN 2 · 26% OF EXAMDesign Resilient Architectures

High Availability & Scaling · 10

Region & AZAWS Global Infrastructure — Region, Availability Zone, Edge

region, availability zone, AZ, AZ ID, edge location, local zone, wavelength, global infrastructure

Auto Scaling GroupsAmazon EC2 Auto Scaling

horizontal scaling, scale out/in, launch template, scaling policies, desired capacity, min/max, OldestLaunchTemplate, termination policy

RDS Multi-AZAmazon RDS Multi-AZ Deployment

automatic failover, standby, different AZ, sync replication, same endpoint, HA only, automated backups, manual snapshot

RDS Read ReplicasAmazon RDS Read Replicas

read scaling, async replication, cross-region, up to 15 replicas, read-only, multi-region, promote to master

RDS ProxyAmazon RDS Proxy

connection pooling, too many connections, Lambda scaling, idle connections, connection multiplexing, faster failover, IAM authentication, Secrets Manager

Global AcceleratorAWS Global Accelerator

global routing, AWS backbone, anycast, static IP, TCP/UDP, failover <30s, two static IPs, IP caching

AuroraAmazon Aurora

MySQL compatible, PostgreSQL compatible, 6 copies, 3 AZs, auto storage 256 TiB, fast failover, 15 read replicas, Global Database

Aurora ServerlessAmazon Aurora Serverless

scale to zero, ACU, pay per second, intermittent, dev/test, auto-pause, variable traffic, v1 vs v2

DynamoDBAmazon DynamoDB

NoSQL, key-value, serverless, millisecond latency, DAX, Global Tables, streams, auto-scale

DAXAmazon DynamoDB Accelerator (DAX)

DynamoDB Accelerator, microsecond latency, in-memory cache, read caching, drop-in compatible, DAX vs ElastiCache

🔄 Disaster Recovery Patterns · 5

🗂️ Backup & Storage Resilience · 8

🚚 Migration & Transfer · 4

DOMAIN 3 · 24% OF EXAMDesign High-Performing Architectures

🖥️ Compute · 18

EC2Elastic Compute Cloud

full control, custom OS, lift and shift, placement groups, cluster/partition/spread, pricing, per-second billing, per-hour Windows

LambdaAWS Lambda

serverless, event-driven, 15-min max, reserved concurrency, provisioned concurrency, cold start, snapstart, Lambda SnapStart

Elastic BeanstalkAWS Elastic Beanstalk

PaaS, deploy app, developer friendly, auto EC2+ALB+ASG, free service, deployment policy, all at once, rolling

ECSElastic Container Service

Docker, containers, microservices, task definition, JSON template, Fargate, EC2 launch type, service

EKSElastic Kubernetes Service

Kubernetes, K8s, container orchestration, IRSA, IAM Roles for Service Accounts, pod identity, ECS vs EKS, control plane cost

EKS VariantsEKS Anywhere vs EKS Distro vs ECS Anywhere

EKS Anywhere, EKS Distro, ECS Anywhere, on-premises Kubernetes, hybrid containers

AWS LB ControllerAWS Load Balancer Controller

AWS Load Balancer Controller, ALB, NLB, Ingress, path-based routing, EKS, Kubernetes, Layer 7

EC2 User DataEC2 User Data Scripts

bootstrap, launch script, cloud-init, first boot, initialization, 16KB limit, user data vs metadata, auto-configure

EC2 HibernationAmazon EC2 Hibernation

hibernation, RAM save, EBS root, fast resume, in-memory state, encrypted root volume, stop start reboot terminate, instance lifecycle

EC2 MetadataEC2 Instance Metadata Service (IMDS)

169.254.169.254, instance info, IMDSv2, IMDSv1, hostname, IP address, IAM role name, SSRF

Recycle BinAWS Recycle Bin (AMI & EBS Snapshots)

Recycle Bin, AMI recovery, EBS snapshot recovery, accidental deletion, retention period, retention rule, Data Lifecycle Manager, DLM

AWS BatchAWS Batch

AWS Batch, batch computing, long-running job, managed, job queue, job definition, compute environment, EC2 fleet

FargateAWS Fargate

serverless containers, ECS, EKS, no EC2 management, pay per vCPU/memory, Fargate Spot, vs Lambda, no time limit

ECRAmazon Elastic Container Registry

container registry, Docker images, private registry, IAM integration, image scanning, lifecycle policy, immutable tags, replication

Instance StoreAmazon EC2 Instance Store

ephemeral, temporary storage, high IOPS, NVMe, scratch disk, data lost on stop, physically attached, no snapshot

ENI/ENA/EFAEC2 Network Interfaces — ENI · ENA · EFA

ENI, ENA, EFA, network interface, virtual NIC, OS-bypass, libfabric, MPI

Lambda@EdgeAWS Lambda@Edge

Lambda@Edge, edge computing, CloudFront, Viewer Request, Viewer Response, Origin Request, Origin Response, CloudFront Functions

EC2 TenancyEC2 Tenancy & Dedicated Hosts

tenancy, shared, dedicated instance, dedicated host, single-tenant, BYOL, bring your own license, Oracle

💾 Storage · 10

EBSElastic Block Store

block storage, single EC2, persistent disk, instance store, ephemeral, Elastic Volumes, resize, encryption

EBS Volume TypesAmazon EBS — Volume Types & Multi-Attach

gp3, gp2, io2, io1, io2 Block Express, st1, sc1, Magnetic

EFSElastic File System

shared storage, multiple EC2, NFS, General Purpose, Max I/O, Provisioned Throughput, Bursting Throughput, Elastic Throughput

S3Simple Storage Service

object storage, 11 nines durability, strong consistency, bucket policy, block public access, versioning, CRR, SRR

S3 Access ControlS3 Access Control & Policies (IAM · Bucket Policy · ACL · BPA)

S3 access control, IAM policy, bucket policy, ACL, access control list, block public access, BPA, cross-account

S3 GlacierAmazon S3 Glacier (storage classes)

archiving, cold storage, Glacier Instant Retrieval, Glacier Flexible Retrieval, Glacier Deep Archive, restore job, Expedited, Standard

S3 Storage ClassesS3 Storage Classes — 7 Main Tiers + Express One Zone

S3 Standard, Standard-IA, One Zone-IA, Intelligent-Tiering, S3 Express One Zone, Glacier Instant Retrieval, Glacier Flexible Retrieval, Deep Archive

S3 LifecycleS3 Lifecycle Management

lifecycle, transition rule, expiration rule, auto-move, auto-delete, age-based, storage class transition, transition waterfall

S3 CORSS3 Cross-Origin Resource Sharing (CORS)

CORS, cross-origin, browser security, AllowedOrigin, Access-Control-Allow-Origin, web app, domain, bucket CORS

S3 Pre-Signed URLS3 Pre-Signed URLs

presigned URL, temporary access, no credentials, IAM credentials, expiry time, download, upload, PUT

🌐 Networking & Delivery · 6

📨 Messaging & Serverless · 12

SQSSimple Queue Service

queue, decouple, async, pull-based, visibility timeout, FIFO, DLQ, at-least-once

SNSSimple Notification Service

pub/sub, push notification, fan-out, broadcast, topic, subscription, filter policy, message filtering

KinesisAmazon Kinesis (Data Streams vs Firehose)

real-time, streaming, data pipeline, analytics, Data Streams, Firehose, shards, retention

Kinesis Video StreamsAmazon Kinesis Video Streams (KVS)

Kinesis Video Streams, KVS, video stream, CCTV, camera, drone, dashcam, video doorbell

API GatewayAmazon API Gateway

REST API, HTTP API, WebSocket, real-time, bidirectional, API management, throttling, usage plans

EventBridgeAmazon EventBridge

event bus, event-driven, cron schedule, rule-based routing, decouple, SaaS integration, CloudWatch Events, schema registry

Step FunctionsAWS Step Functions

workflow, state machine, orchestration, retry logic, error handling, Lambda orchestration, visual workflow, Distributed Map

Amazon MQAmazon MQ

ActiveMQ, RabbitMQ, AMQP, MQTT, lift-and-shift, message broker, legacy migration, open protocols

Kinesis Data FirehoseAmazon Kinesis Data Firehose

delivery stream, S3 delivery, Redshift, OpenSearch, no consumer code, buffer, transform with Lambda, Parquet conversion

AppFlowAWS AppFlow

AppFlow, SaaS integration, Salesforce, ServiceNow, no-code connector, data transfer, bidirectional, S3

AppSyncAWS AppSync

GraphQL, real-time, subscriptions, WebSocket, offline sync, conflict resolution, resolvers, DynamoDB

AmplifyAWS Amplify

fullstack, CI/CD, frontend hosting, mobile, React, Next.js, Cognito, AppSync

🏗️ Infrastructure · 8

🗄️ Databases · 6

📊 Analytics & Streaming · 12

RedshiftAmazon Redshift

data warehouse, OLAP, columnar, MPP, RA3, managed storage, RMS, Redshift Spectrum

QuickSightAmazon QuickSight

QuickSight, BI, dashboard, forecasting, ML Insights, visualization, S3 direct, SPICE

AthenaAmazon Athena

serverless SQL, S3 queries, pay per scan, Parquet, ORC, Glue Catalog, log analysis, ad-hoc

GlueAWS Glue

ETL, data catalog, Spark, serverless, crawler, classifier, ETL job, DataBrew

Lake FormationAWS Lake Formation

Lake Formation, row-level security, column-level, cell-level, fine-grained access, data lake, Glue Data Catalog, secure data lake

EMRAmazon EMR

Hadoop, Spark, Hive, Presto, HBase, big data, cluster, petabyte

OpenSearchAmazon OpenSearch Service

search engine, log analytics, Elasticsearch compatible, Kibana, OpenSearch Dashboards, real-time analytics, full-text search, fuzzy

MSKAmazon MSK

Kafka, managed, streaming, event streaming, migration, Kafka API, real-time pipeline, brokers

KendraAmazon Kendra

Kendra, enterprise search, ML search, semantic search, natural language query, FAQs, unstructured documents, intelligent search

Data ExchangeAWS Data Exchange

Data Exchange, third-party data, data marketplace, data subscription, market data, financial data, data products, S3 delivery

AWS AI/ML ServicesAWS AI Services — Polly, Rekognition, Lex, Comprehend, Textract, Transcribe, Translate

Polly, Transcribe, Lex, Rekognition, Comprehend, Comprehend Medical, Textract, Translate

SageMakerAmazon SageMaker

SageMaker, custom ML, training, AutoML, Autopilot, hyperparameter tuning, model deployment, MLOps

DOMAIN 4 · 20% OF EXAMDesign Cost-Optimized Architectures

💰 EC2 Pricing Models · 13

On-DemandEC2 On-Demand Instances

no commitment, flexible, short-term, highest cost, per-second billing, per-hour billing, pricing, On-Demand Capacity Reservation

Reserved InstancesEC2 Reserved Instances (RI)

1 or 3 year, up to 72% discount, Standard RI, Convertible RI, exchange, modify, All Upfront, Partial Upfront

Spot InstancesEC2 Spot Instances

up to 90% discount, interruptible, 2-minute interruption notice, EventBridge, instance metadata, rebalance recommendation, terminate, stop

Savings PlansAWS Savings Plans (SP)

flexible, hourly commitment, up to 66% discount, Compute Savings Plans, EC2 Instance Savings Plans, Fargate, Lambda, auto-apply

Compute OptimizerAWS Compute Optimizer

rightsizing, ML recommendations, EC2 optimization, Lambda optimization, cost savings, underutilized, vs Trusted Advisor, 14 days metrics

Trusted AdvisorAWS Trusted Advisor

cost recommendations, idle resources, rightsizing, underutilized, service limits, five categories, Cost Optimization, Performance

AWS BudgetsAWS Budgets

budget alerts, cost threshold, SNS notification, usage budget, forecast alert, before overspend, budget actions, pricing

Cost ExplorerAWS Cost Explorer

cost analysis, spending visualization, RI recommendations, usage patterns, rightsizing, forecast, hourly granularity, anomaly detection

Cost Anomaly DetectionAWS Cost Anomaly Detection

Cost Anomaly Detection, unusual spending, anomalous spend, ML, cost monitor, root cause, SNS alert, seasonality

Instance SchedulerInstance Scheduler on AWS

Instance Scheduler on AWS, start stop schedule, office hours, weekday only, part-time workload, CloudFormation solution, EC2 RDS schedule, minimal operational overhead

Cost & Usage ReportAWS Cost and Usage Report (CUR)

Cost and Usage Report, CUR, line-item billing, most granular, S3 delivery, CSV, Parquet, Athena

Cost Allocation TagsAWS Cost Allocation Tags

cost allocation tags, AWS-generated, user-defined, activate in billing, track cost by tag, cost center

Consolidated BillingAWS Organizations Consolidated Billing

consolidated billing, management account, member accounts, volume discount, shared RI, shared Savings Plans, one bill, free

💾 Storage Cost Optimization · 2

🌐 Networking Cost Optimization · 2

🗄️ Database Cost Optimization · 2

🔄 DR Strategies (Cost vs RTO/RPO) · 1

FRAMEWORK · ALL DOMAINSAWS Well-Architected Framework

BONUS · NOT IN EXAMExtra Tools & Open-Source

173 service cards · taip untuk filter · klik untuk ke Deep Notes