Secure Cloud Services — Week 5: Main Lecture

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/78

flashcard set

Earn XP

Description and Tags

Last updated 5:18 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

79 Terms

1
New cards

What four main factors should you consider when choosing a database?

Scalability, storage requirements, data characteristics and access patterns, and durability/availability/recoverability. Also consider cost and regulatory obligations.

2
New cards

What is capacity planning?

Analysing current capacity, predicting future needs, and deciding how to scale resources.

3
New cards

What is vertical scaling?

Using a bigger server with more resources, such as CPU or memory. It usually involves downtime.

4
New cards

What is horizontal scaling?

Adding more servers or instances to distribute the workload. It usually avoids downtime.

5
New cards

Why should you avoid underprovisioning and overprovisioning?

Underprovisioning can cause poor performance or application failure. Overprovisioning wastes money.

6
New cards

Why does data residency matter when choosing a database location?

Regulatory obligations, such as GDPR-related requirements for EU workloads, can affect where data should be stored.

7
New cards

How does a relational database organise data?

In tables containing rows and columns, with a defined schema.

8
New cards

How does a non-relational database organise data?

Using models such as key-value, document, graph or in-memory, often with a flexible schema.

9
New cards

What are the main strengths of relational databases?

Data integrity, ACID transactions, SQL and joins.

10
New cards

What does ACID stand for?

Atomicity, Consistency, Isolation and Durability.

11
New cards

What are the main strengths of non-relational databases?

Scalability, schema flexibility and high throughput.

12
New cards

Can relational databases scale horizontally?

Yes. For example, RDS read replicas distribute read workloads across multiple instances.

13
New cards

What is the main benefit of using a managed AWS database service?

AWS automates infrastructure and database operations, reducing the customer's maintenance workload.

14
New cards

What remains the customer's responsibility with a managed database?

Optimising the application and queries, and correctly configuring access and security.

15
New cards

What is Amazon RDS?

A managed relational database service that automates provisioning, patching, backups, failure detection and repair.

16
New cards

Which database engines are listed for RDS in the lecture?

Aurora with MySQL or PostgreSQL compatibility, MySQL, MariaDB, PostgreSQL, Oracle, SQL Server and Db2.

17
New cards

How should you decide which RDS instance resources to increase?

Identify the constrained resource, such as CPU or memory, and choose an upgrade that addresses it.

18
New cards

Where should the database sit in the lecture's application architecture?

Inside a VPC in a private subnet, rather than directly facing the internet.

19
New cards

What is the main purpose of a traditional RDS Multi-AZ deployment with a standby?

High availability through automatic failover to a standby database.

20
New cards

What type of replication does a traditional RDS Multi-AZ standby deployment use?

Synchronous replication.

21
New cards

Does the standby in the lecture's traditional RDS Multi-AZ deployment serve read queries?

No. It is a standby for failover, not a read-scaling replica.

22
New cards

What is the main purpose of RDS read replicas?

Scaling read performance by offloading read-only queries from the primary database.

23
New cards

What type of replication do RDS read replicas use?

Asynchronous replication.

24
New cards

How do traditional Multi-AZ deployments and read replicas differ during failure?

Multi-AZ automatically fails over to the standby. A read replica can be manually promoted to a standalone database.

25
New cards

Can RDS read replicas operate across AWS Regions?

Yes. The traditional Multi-AZ standby deployment described in the lecture stays within one Region.

26
New cards

What is the simplest way to remember Multi-AZ versus read replicas?

Multi-AZ means availability. Read replicas mean read scalability.

27
New cards

What is Amazon Aurora?

A cloud-native relational database managed by RDS, compatible with MySQL and PostgreSQL.

28
New cards

How is Aurora storage distributed?

Its cluster storage volume is replicated across three Availability Zones.

29
New cards

What Aurora storage limit does the lecture give?

Aurora storage automatically grows up to 256 TiB.

30
New cards

How many Aurora Replicas can an Aurora cluster have?

Up to 15 Aurora Replicas.

31
New cards

What are the roles of Aurora's primary instance and replicas?

The primary handles reads and writes. Replicas handle read-only queries and can act as failover targets.

32
New cards

When is Aurora Serverless v2 useful?

For variable or unpredictable workloads, new applications, and development or testing, because it automatically scales capacity.

33
New cards

What is Amazon RDS Proxy?

A fully managed, highly available database proxy for RDS and Aurora.

34
New cards

How does RDS Proxy help with database connections?

It pools and shares connections so the database handles fewer, longer-lived connections.

35
New cards

When should you consider RDS Proxy?

When an application has too many connections, frequently opens and closes connections, or holds many connections open.

36
New cards

How does RDS Proxy improve resilience and security?

It reduces failover disruption, supports IAM authentication, and can keep database credentials in AWS Secrets Manager.

37
New cards

What is the main purpose of RDS automated backups?

Point-in-time recovery using daily backups and transaction logs.

38
New cards

What is the maximum RDS automated backup retention stated in the lecture?

Up to 35 days.

39
New cards

How do manual RDS snapshots differ from automated backups?

Manual snapshots are user-initiated, restore a known state, remain until deleted, and can be shared subject to applicable restrictions.

40
New cards

Which controls protect access to an RDS database?

A private subnet, security groups restricting connections, and IAM controlling who can manage RDS.

41
New cards

How should RDS data be encrypted?

Use TLS for data in transit and AWS KMS encryption for data at rest.

42
New cards

How can you encrypt an existing unencrypted RDS database using the lecture's method?

Create a snapshot, copy the snapshot with encryption enabled, and restore a new database from the encrypted copy.

43
New cards

What is Amazon DynamoDB?

A fully managed, serverless NoSQL database supporting key-value and document data models.

44
New cards

What performance characteristic does the lecture associate with DynamoDB?

Single-digit millisecond performance at any scale, with automatic scaling.

45
New cards

How does DynamoDB handle encryption and access?

Data is encrypted at rest by default, and access is controlled through IAM rather than database usernames and passwords.

46
New cards

What are DynamoDB tables, items and attributes?

A table contains items. An item is similar to a row. Attributes are the item's key-value data fields.

47
New cards

What keys can form a DynamoDB primary key?

A partition key alone, or a composite primary key consisting of a partition key and a sort key.

48
New cards

How does DynamoDB support a flexible schema?

Items must contain the required primary-key attributes, but other attributes can differ between items.

49
New cards

Why use Device ID as the partition key and Timestamp as the sort key for sensor readings?

It groups readings by device and distinguishes or orders readings using their timestamps.

50
New cards

What is a DynamoDB global secondary index, or GSI?

An index that provides an alternate query pattern using a different partition key and optionally a different sort key.

51
New cards

What is a DynamoDB local secondary index, or LSI?

An index using the same partition key as the base table but a different sort key.

52
New cards

When can GSIs and LSIs be created?

GSIs can be created after the table exists. LSIs must be created when the table is created.

53
New cards

What GSI and LSI limits does the lecture give?

Up to 20 GSIs and up to 5 LSIs per table.

54
New cards

How do GSI and LSI read consistency differ?

GSIs support eventually consistent reads only. LSIs support eventually consistent or strongly consistent reads.

55
New cards

How do GSI and LSI capacity differ?

A GSI has its own capacity. An LSI uses the base table's capacity.

56
New cards

How could you query sensor readings with Error status = High without scanning the whole table?

Create a GSI with Error status as its partition key, then query that index.

57
New cards

What are DynamoDB global tables?

Multi-Region, multi-active replicated tables where every replica accepts reads and writes.

58
New cards

What are the benefits of DynamoDB global tables?

Fast local access across Regions and resilience against a Region outage.

59
New cards

What are DynamoDB Streams used for?

Supporting event-driven applications by exposing changes made to table items.

60
New cards

Which DynamoDB recovery window does the lecture give?

Point-in-time recovery covering up to 35 days.

61
New cards

Which AWS database services suit structured transactional workloads, or OLTP?

Amazon RDS and Amazon Aurora.

62
New cards

Which AWS service suits analytics over huge datasets, or OLAP?

Amazon Redshift.

63
New cards

Which AWS database suits JSON document workloads?

Amazon DocumentDB.

64
New cards

Which AWS database suits wide-column or Cassandra workloads?

Amazon Keyspaces.

65
New cards

Which AWS services suit in-memory workloads?

Amazon MemoryDB and Amazon ElastiCache.

66
New cards

Which AWS database suits highly connected data, such as social-network relationships?

Amazon Neptune, a graph database.

67
New cards

Which AWS database does the lecture associate with time-stamped IoT or operational data?

Amazon Timestream.

68
New cards

What is AWS Database Migration Service, or AWS DMS?

A service for migrating database data, with support for ongoing replication while the source remains online.

69
New cards

What is a homogeneous database migration?

A migration between the same database engine, such as MySQL on EC2 to RDS for MySQL.

70
New cards

What is a heterogeneous database migration?

A migration between different database engines, such as Oracle to Aurora PostgreSQL.

71
New cards

What must happen before migrating data between different database engines?

Convert the schema and code using AWS SCT or DMS Schema Conversion, then migrate the data using DMS.

72
New cards

What endpoint requirement does the lecture give for AWS DMS?

At least one endpoint must be on AWS.

73
New cards

Besides a one-time migration, what can AWS DMS do?

Continuously replicate data, for example into an Amazon S3 data lake.

74
New cards

How does the Well-Architected performance efficiency pillar apply to databases?

Choose the database based on data characteristics and access patterns, load test, and evaluate trade-offs such as eventual consistency.

75
New cards

How does the Well-Architected security pillar apply to databases?

Use secure key management with AWS KMS and enforce encryption at rest.

76
New cards

How does the Well-Architected cost optimisation pillar apply to databases?

Right-size the type, size and number of resources, and consider Aurora Serverless to avoid overprovisioning.

77
New cards

In the sample exam question, which database supports a highly available relational workload starting at 8 TB, growing daily, and requiring at least eight read replicas?

Amazon Aurora, because it is relational, its storage grows automatically, and it supports up to 15 read replicas.

78
New cards

Why are DynamoDB and Neptune wrong answers in the lecture's sample exam question?

DynamoDB is non-relational, and Neptune is a graph database rather than the required relational database.

79
New cards

Why is Redshift wrong in the lecture's sample exam question?

It is designed for data warehousing and does not provide the required read-replica arrangement.