SOA-C03: AWS Monitoring, Security, and Storage: Key Concepts and Tools

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/107

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

108 Terms

1
New cards

CloudWatch Agent

collects detailed system metrics and logs from EC2, ECS, and EKS nodes for CloudWatch.

2
New cards

CloudWatch Composite Alarms

combine multiple alarms into a single evaluation to reduce alert noise.

3
New cards

CloudWatch Dashboards

customizable metric dashboards shared across accounts and Regions.

4
New cards

CloudWatch Metric Filters

extract structured data from CloudWatch Logs to create actionable metrics.

5
New cards

CloudTrail Event History

records API calls for auditing and troubleshooting access issues.

6
New cards

CloudTrail Organization Trails

central logging of API activity across all accounts for compliance.

7
New cards

CloudTrail Lake

queryable event storage that allows SQL-style analysis of audit logs.

8
New cards

EventBridge Event Buses

routes and transforms events between AWS services and custom applications.

9
New cards

EventBridge Rules

filter events and trigger targets like Lambda, SQS, SNS, or SSM Automation.

10
New cards

EventBridge Pipes

connects event sources like SQS or Kinesis directly to targets with filtering and enrichment.

11
New cards

SNS Topics

broadcast system alarms or operational alerts to email, SMS, or subscribers.

12
New cards

SSM Automation Runbooks

predefined or custom actions that automate remediation and operational workflows.

13
New cards

SSM Documents

configuration templates used for patching, commands, and automation flows.

14
New cards

SSM Parameter Store Advanced Parameters

store encrypted configuration data with versioning and TTL.

15
New cards

SSM Session Manager

allows shell access to EC2 instances without SSH or inbound ports.

16
New cards

SSM Patch Manager

automates OS patching across EC2 fleets based on patch baselines.

17
New cards

Compute Optimizer

recommends compute, EBS, and Lambda right-sizing based on performance telemetry.

18
New cards

Trusted Advisor Security Checks

automated findings related to IAM, S3, EC2, and account configuration.

19
New cards

Security Hub

aggregates and normalizes findings from GuardDuty, Inspector, Macie, and Config rules.

20
New cards

GuardDuty

detects threat activity like compromised instances, anomalous API calls, or malicious DNS queries.

21
New cards

Inspector EC2 Scanning

analyzes EC2 instances for vulnerabilities, network exposure, and CIS hardening gaps.

22
New cards

IAM Identity Center

central management of SSO access to AWS accounts with permission sets.

23
New cards

IAM Access Analyzer

identifies unintended external access to S3, IAM roles, KMS keys, and more.

24
New cards

KMS Key Policies

core permission documents that control who can administer or use encryption keys.

25
New cards

KMS Key Rotation

automated yearly rotation for symmetric keys to meet compliance expectations.

26
New cards

ACM Certificate Validation

DNS or email-based verification for issuing TLS certificates.

27
New cards

Secrets Manager Automatic Rotation

rotates credentials using Lambda-based rotation logic.

28
New cards

AWS Config Rules

evaluate resource configurations for compliance and trigger remediation.

29
New cards

AWS Config Conformance Packs

grouped rules that enforce company-wide compliance standards.

30
New cards

AWS Backup Plans

define schedules and lifecycle rules for backups of EC2, RDS, EFS, DynamoDB, and more.

31
New cards

AWS Backup Vault Lock

enforces write-once, read-many controls to prevent accidental or malicious deletion.

32
New cards

EBS Volume Types (gp3/io2/io2 Block Express)

performance-optimized storage tiers with different IOPS and throughput.

33
New cards

EBS Snapshots

point-in-time backups stored incrementally in S3 for restoration or replication.

34
New cards

EBS Fast Snapshot Restore

pre-warms snapshots so new volumes launch with full performance instantly.

35
New cards

EFS Lifecycle Policies

move files to Infrequent Access tiers automatically to reduce cost.

36
New cards

EFS Access Points

provide permission-scoped entry points for multi-client file systems.

37
New cards

FSx for Windows File Server

managed SMB file storage integrated with Active Directory.

38
New cards

FSx for Lustre

high-performance parallel file system for analytics or HPC workloads.

39
New cards

RDS Performance Insights

real-time analytics on database load and query bottlenecks.

40
New cards

RDS Proxy

connection pooling service that protects SQL databases from oversaturation and boosts scalability.

41
New cards

RDS Multi-AZ with Failover

synchronous standby used to maintain high availability during outages.

42
New cards

DynamoDB DAX

in-memory NoSQL caching accelerator that reduces read latency to microseconds.

43
New cards

DynamoDB Point-in-Time Recovery

continuous backup capability with second-level restores.

44
New cards

Auto Scaling Predictive Scaling

forecasts demand to scale EC2 instances ahead of time.

45
New cards

Launch Templates

versioned configuration blueprints used to start EC2 instances consistently.

46
New cards

EC2 Placement Groups (Cluster/Spread/Partition)

placement strategies for performance or high availability.

47
New cards

EC2 IMDSv2

metadata access protocol that prevents SSRF and enhances instance security.

48
New cards

EC2 Instance Connect

secure SSH access without managing long-lived keys.

49
New cards

S3 Transfer Acceleration

speeds data uploads to S3 by routing through edge locations.

50
New cards

S3 Multipart Uploads

parallelizes large object transfers for reliability and performance.

51
New cards

S3 Lifecycle Policies

transition objects to cheaper tiers or expire them automatically.

52
New cards

S3 Object Lock

provides WORM protection for compliance or ransomware defense.

53
New cards

S3 Versioning

stores multiple object versions to protect against overwrite and deletion issues.

54
New cards

DataSync

automated service for moving data between NFS, SMB, S3, EFS, and FSx.

55
New cards

CloudFront Origin Shield

centralized caching layer that reduces origin load.

56
New cards

CloudFront Field-Level Encryption

encrypts sensitive viewer data before it reaches the origin.

57
New cards

CloudFront Cache Invalidations

used to purge outdated cached content on demand.

58
New cards

Global Accelerator

improves global application performance through Anycast routing.

59
New cards

Route 53 Resolver DNS Firewall

blocks known malicious domains inside VPC DNS queries.

60
New cards

Route 53 Health Checks

monitor endpoint health and route traffic away from failures.

61
New cards

Route 53 Weighted Routing

distributes traffic based on weights for testing or partial rollouts.

62
New cards

Route 53 Latency Routing

routes clients to the Region with the lowest latency.

63
New cards

PrivateLink Endpoints

provide private connectivity to AWS services without public internet.

64
New cards

Interface Endpoints

ENI-based access points for PrivateLink-enabled services.

65
New cards

Gateway Endpoints

private S3 and DynamoDB access without NAT or internet gateway.

66
New cards

NAT Gateway

allows outbound internet access for private subnet instances.

67
New cards

Egress-Only Internet Gateway

provides IPv6-only outbound access while blocking inbound connections.

68
New cards

Network ACLs

stateless subnet-level traffic filters for inbound and outbound rules.

69
New cards

VPC Flow Logs

capture network-level logs to analyze traffic patterns and troubleshoot.

70
New cards

VPC Traffic Mirroring

packet capture capability for deep inspection or threat detection.

71
New cards

Transit Gateway

scalable hub that connects multiple VPCs and on-prem networks.

72
New cards

Reachability Analyzer

path analysis tool that identifies routing or security group blockers.

73
New cards

AWS VPN CloudHub

connects multiple on-prem sites together using AWS as the hub.

74
New cards

Elastic Load Balancer Access Logs

request-level logging used to diagnose latency or routing issues.

75
New cards

Application Load Balancer Target Groups

manage health checks and routes for different microservices.

76
New cards

NLB Cross-Zone Load Balancing

distributes traffic across all AZs to improve resilience.

77
New cards

IPAM (IP Address Manager)

manages IP allocation and helps avoid overlapping CIDR blocks.

78
New cards

Service Control Policies

enforce guardrails for entire AWS Organization accounts.

79
New cards

Resource Access Manager

shares VPC subnets, Transit Gateways, and other resources across accounts.

80
New cards

StackSets

deploy CloudFormation stacks consistently across accounts and Regions.

81
New cards

EC2 Image Builder Pipelines

automated AMI creation and hardening workflows.

82
New cards

CDK Constructs

reusable IaC components written in modern programming languages.

83
New cards

S3 Event Notifications

trigger Lambda, SQS, or SNS when objects are created or modified.

84
New cards

Lambda Destinations

route async Lambda results to EventBridge, SQS, or SNS for auditing or chaining actions.

85
New cards
SSM State Manager
automates keeping EC2 or hybrid servers in a desired state by applying policies like patching, configuration, or software installs.
86
New cards
SSM Inventory
collects software and metadata from EC2 and on-prem servers to help with audits, patching, and compliance.
87
New cards
CloudWatch Network Monitor
tests and monitors network paths between VPCs and on-prem locations to detect latency, packet loss, or connectivity issues.
88
New cards
Cost Explorer
visualizes AWS spending trends and helps identify cost optimization opportunities.
89
New cards
Cost and Usage Reports
detailed billing dataset that breaks down every line item of AWS usage for analysis or chargeback.
90
New cards
Savings Plans
discount model that reduces compute costs in exchange for committing to a consistent hourly spend.
91
New cards
Amazon ECR
managed container registry used to store, scan, and version Docker images for ECS, EKS, and EC2 workloads.
92
New cards
Amazon Managed Service for Prometheus
managed Prometheus-compatible monitoring service for container and microservice metrics.
93
New cards
Amazon Managed Grafana
hosted Grafana dashboards for querying metrics from Prometheus, CloudWatch, X-Ray, and more.
94
New cards
AWS X-Ray
tracing service that maps requests across microservices to diagnose latency and dependency issues.
95
New cards
Route 53 Resolver Endpoints
inbound and outbound DNS endpoints used for hybrid DNS forwarding between AWS and on-prem datacenters.
96
New cards
Route 53 Resolver Query Logging
captures DNS queries inside a VPC to help with troubleshooting or security investigations.
97
New cards
AWS Control Tower
automates multi-account setup, guardrails, and baseline security controls across an AWS organization.
98
New cards
AWS Service Catalog
publishes approved infrastructure templates and lets teams deploy standardized resources safely.
99
New cards
AWS Step Functions
orchestrates multi-step workflows with visual state machines that integrate with Lambda, ECS, SSM, and EventBridge.
100
New cards
AWS WAF
layer 7 firewall that blocks malicious HTTP patterns like SQLi, XSS, bot traffic, and unwanted IPs.

Explore top flashcards