Question Bank
Chapter-1: Introduction to Cloud Computing and AWS
Q1. What is Cloud Computing? Explain its characteristics.
Cloud Computing is the on-demand delivery of IT resources (such as compute, storage, databases, and networking) over the Internet with pay-as-you-go pricing. Rather than purchasing, owning, and maintaining physical data centers and servers, organizations can access technology services on an as-needed basis from a cloud provider. It represents a paradigm shift from traditional hardware-centric IT to a more flexible, service-oriented model.
Key Characteristics (as defined by NIST):
- On-demand Self-Service: Consumers can independently and unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with the service provider.
- Broad Network Access: Cloud capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, tablets, laptops, and workstations).
- Resource Pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand.
- Rapid Elasticity: Capabilities can be elastically provisioned and released, sometimes automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the resources available for provisioning often appear to be unlimited.
- Measured Service: Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth). Resource usage can be monitored, controlled, and reported, providing transparency.
Q2. Explain key benefits of cloud computing.
Cloud computing offers several transformational benefits for organizations:
- Trade Capital Expense for Variable Expense: Instead of having to invest heavily in data centers and servers before you know how you are going to use them, you can pay only when you consume computing resources, and pay only for how much you consume.
- Benefit from Massive Economies of Scale: By using cloud computing, you can achieve a lower variable cost than you can get on your own. Because usage from hundreds of thousands of customers is aggregated in the cloud, providers like AWS can achieve higher economies of scale, which translates into lower pay-as-you-go prices.
- Stop Guessing Capacity: Eliminate guessing on your infrastructure capacity needs. When you make a capacity decision prior to deploying an application, you often end up either sitting on expensive idle resources or dealing with limited capacity. With cloud computing, you can access as much or as little capacity as you need, and scale up and down as required with only a few minutes' notice.
- Increase Speed and Agility: In a cloud computing environment, new IT resources are only a click away, which means that you reduce the time to make those resources available to your developers from weeks to just minutes. This results in a dramatic increase in agility for the organization.
- Stop Spending Money Running and Maintaining Data Centers: Focus on projects that differentiate your business, not the infrastructure. Cloud computing lets you focus on your own customers, rather than on the heavy lifting of racking, stacking, and powering servers.
- Go Global in Minutes: Easily deploy your application in multiple regions around the world with just a few clicks. This means you can provide lower latency and a better experience for your customers at a minimal cost.
Q3. Differentiate between IaaS, PaaS, and SaaS.
| Feature | IaaS (Infrastructure as a Service) | PaaS (Platform as a Service) | SaaS (Software as a Service) |
|---|---|---|---|
| Definition | Provides fundamental compute, network, and storage resources over the internet. | Provides a platform allowing customers to develop, run, and manage applications without the complexity of building infrastructure. | Provides a complete software product that is run and managed by the service provider, accessed via a web browser. |
| Management Responsibility | The user manages the Operating System (OS), middleware, runtime environments, data, and applications. The provider manages the physical hardware, networking, and virtualization. | The user manages only the applications and data. The provider manages everything else, including the OS, runtime, middleware, and underlying hardware. | The user manages nothing except their own account data and user preferences. The provider handles all software maintenance, patching, and infrastructure. |
| Target Audience | System Administrators, IT Operations professionals, Network Architects. | Software Developers, Application Operations. | End Users, Business consumers. |
| Flexibility vs Ease of Use | Highest flexibility and control over the IT resources; requires the most technical expertise to manage. | Focuses on developer productivity and deployment efficiency; abstracting away underlying server management. | Easiest to use; highly standardized with limited customizability. Ready to consume immediately. |
| Examples | Amazon EC2 (Elastic Compute Cloud), AWS VPC, Microsoft Azure VMs, Google Compute Engine. | AWS Elastic Beanstalk, Google App Engine, Heroku, Microsoft Azure App Services. | Gmail, Salesforce, Dropbox, Microsoft Office 365, Zoom. |
Q4. Explain cloud deployment models.
Cloud computing offers three primary deployment models to suit different organizational requirements:
- Public Cloud: The cloud infrastructure is provisioned for open use by the general public. It is owned, managed, and operated by a cloud provider (e.g., AWS, Azure, GCP). All hardware, software, and other supporting infrastructure are owned and managed by the cloud provider. Users access these services over the internet. It is highly scalable and cost-effective as costs are shared among multiple tenants.
- Private Cloud: The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off-premises. Private clouds offer higher security and control, making them suitable for organizations with strict compliance or data privacy requirements (e.g., healthcare, finance).
- Hybrid Cloud: A composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load-balancing between clouds). This allows organizations to keep critical, sensitive data on a private cloud while leveraging the public cloud for scalable, less sensitive computing tasks, offering maximum flexibility.
Q5. What is AWS? Explain its advantages.
Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform, offering over 200 fully featured services from data centers globally. Millions of customers—including the fastest-growing startups, largest enterprises, and leading government agencies—are using AWS to lower costs, become more agile, and innovate faster.
Advantages of AWS:
- Comprehensive Service Offering: AWS has significantly more services, and more features within those services, than any other cloud provider–from infrastructure technologies like compute, storage, and databases–to emerging technologies, such as machine learning and artificial intelligence, data lakes and analytics, and Internet of Things.
- Security: AWS is architected to be the most flexible and secure cloud computing environment available today. Its core infrastructure is built to satisfy the security requirements for the military, global banks, and other high-sensitivity organizations. It supports over 90 security standards and compliance certifications.
- Global Footprint: AWS has the most extensive global cloud infrastructure, with numerous Regions and Availability Zones. This allows customers to deploy workloads globally in milliseconds and serve users with single-digit millisecond latency.
- Cost-Effective (Pay-As-You-Go): AWS provides transparent, pay-as-you-go pricing without long-term contracts or complex licensing. Customers can optimize costs by leveraging Reserved Instances or Spot Instances.
- Massive Ecosystem: AWS possesses the largest and most dynamic community, with millions of active customers and tens of thousands of partners globally. This ecosystem includes a vast marketplace of third-party software solutions pre-configured to run on AWS.
Q6. Describe AWS Global Infrastructure.
The AWS Global Infrastructure is designed to be the most secure, extensive, and reliable cloud platform, built around Regions and Availability Zones (AZs).
- Regions: A physical, geographical location in the world where AWS has multiple Availability Zones. Examples include US East (N. Virginia), Europe (Ireland), and Asia Pacific (Mumbai). Regions are entirely isolated from one another to achieve the greatest possible fault tolerance and stability. Choosing the right region helps achieve data compliance, reduce latency for end-users, and optimize service costs.
- Availability Zones (AZs): Each Region consists of a minimum of three isolated, physically separate AZs within a geographic area. An AZ consists of one or more discrete data centers, each with redundant power, networking, and connectivity, housed in separate facilities. If one AZ goes down due to a natural disaster or power failure, applications can continue running uninterrupted in another AZ.
- Edge Locations: AWS uses a vast network of Edge Locations and Regional Edge Caches across the globe to deliver content to end-users with ultra-low latency. These are utilized by services like Amazon CloudFront (CDN) and Amazon Route 53 (DNS) to cache static and dynamic content closer to the users requesting them.
Q7. Explain scalability in cloud computing.
Scalability is the ability of a system, network, or process to handle a growing amount of work in a capable manner or its ability to be enlarged to accommodate that growth. In cloud computing, it ensures that your application performs consistently well, even as the number of users or the volume of data increases dramatically.
- Vertical Scaling (Scaling Up/Down): This involves increasing or decreasing the capacity of an existing individual resource. For example, upgrading an EC2 instance from a
t2.micro(1 vCPU, 1GB RAM) to at2.large(2 vCPUs, 8GB RAM) to handle increased database processing load. While straightforward, it eventually hits hardware limits and usually requires some downtime (restarting the instance). - Horizontal Scaling (Scaling Out/In): This involves adding or removing instances of resources to share the workload. Instead of making one server bigger, you add more servers. For example, adding three more EC2 instances behind an Elastic Load Balancer to handle a surge in web traffic. Horizontal scaling is preferred in modern cloud architecture because it offers virtually infinite scalability and improves high availability, as traffic can be distributed and no single point of failure exists.
Q8. Differentiate scalability and elasticity.
While often used interchangeably, scalability and elasticity have distinct meanings in cloud computing:
| Feature | Scalability | Elasticity |
|---|---|---|
| Definition | The ability of a system to increase workload capacity by adding resources (either vertically or horizontally) to maintain performance levels. | The ability of a system to automatically scale resources up or down, rapidly and dynamically, based on real-time current demand. |
| Primary Goal | To handle an increasing, long-term load effectively without system degradation. It is about long-term capacity planning. | To match resource supply with demand exactly to optimize cost and performance at any given moment. It is about short-term, dynamic adjustments. |
| Nature of Operation | Can be a manual, planned, or automated process. Once scaled, it often remains at that new capacity. | Almost strictly an automated, dynamic process controlled by metrics and policies (e.g., Auto Scaling). |
| Ideal Use Case | A database that is steadily growing in size over several years and needs more storage or CPU. | An e-commerce website that experiences massive, unpredictable traffic spikes during a flash sale or holiday season, and then returns to baseline traffic afterward. |
| Financial Impact | Prevents system crashes, but can lead to over-provisioning if scaled resources are constantly running. | Highly cost-optimized, as you only pay for the exact resources needed during peak times and shed them during off-peak times. |
Q9. Explain Availability Zones in AWS.
An Availability Zone (AZ) is a fundamental component of the AWS Global Infrastructure. It consists of one or more discrete data centers with redundant power, networking, and connectivity within an AWS Region.
- Physical Isolation: AZs are physically separated by a meaningful distance (usually miles) from other AZs in the same Region. This spatial separation protects applications from localized disasters such as fires, floods, earthquakes, or widespread power grid failures.
- High-Speed Interconnection: Despite being physically isolated, all AZs in a Region are interconnected through high-bandwidth, low-latency networking over fully redundant, dedicated metro fiber. This allows applications to replicate data synchronously across AZs.
- High Availability and Fault Tolerance: By architecting applications to span multiple AZs (Multi-AZ deployment), organizations ensure that if one entire AZ fails, the application automatically fails over to the remaining healthy AZs without significant disruption. Services like Amazon RDS and Amazon EC2 Auto Scaling heavily leverage Multi-AZ deployments for robust resilience.
Q10. Discuss applications of cloud computing.
Cloud computing has revolutionized IT and is utilized across virtually every industry. Key applications include:
- Data Backup and Disaster Recovery: The cloud provides a secure, cost-effective way to store backups off-site. Cloud-based disaster recovery allows organizations to maintain standby environments that can be spun up in minutes if their primary on-premises data center fails.
- Big Data Analytics: Processing massive, petabyte-scale volumes of data requires immense computational power. Cloud services provide highly scalable Hadoop, Spark, and data warehousing clusters on-demand, allowing organizations to analyze data without investing in massive hardware.
- Software Testing and Development: Developers can rapidly spin up complex environments (Dev/Test/QA) in minutes, thoroughly test their code, and then tear the environments down when finished, paying only for the hours used. This accelerates the software development lifecycle (SDLC).
- Web Applications and E-commerce: Hosting highly scalable websites capable of handling sudden, unpredictable traffic spikes (e.g., Netflix streaming, Amazon retail events). Cloud infrastructure uses auto-scaling and content delivery networks to ensure smooth performance globally.
- Internet of Things (IoT): The cloud acts as the central backend for millions of connected devices, providing services for data ingestion, real-time processing, device management, and analytics on a global scale.
Chapter-2: Networking Services
Q1. What is Amazon VPC?
Amazon Virtual Private Cloud (Amazon VPC) is a foundational networking service that lets you provision a logically isolated section of the AWS Cloud. Within this isolated section, you can launch AWS resources in a virtual network that you define and control.
- Complete Control: You have complete control over your virtual networking environment, including the selection of your own IPv4 and IPv6 address ranges (CIDR blocks), creation of subnets, and configuration of route tables and network gateways.
- Security: VPC provides advanced security features, including Security Groups and Network Access Control Lists (NACLs), to enable inbound and outbound filtering at the instance level and subnet level, respectively.
- Connectivity Options: You can securely connect your VPC to your on-premises corporate data center using an IPsec AWS Site-to-Site VPN or a dedicated AWS Direct Connect connection, turning the AWS cloud into an extension of your own infrastructure.
Q2. Explain subnets in AWS.
A Subnet is a segmented range of IP addresses within your VPC's larger CIDR block. You must launch AWS resources, like EC2 instances or RDS databases, into a specified subnet. Subnets map one-to-one with a specific Availability Zone.
- Public Subnet: A subnet is considered "public" if its associated route table contains a route directing internet-bound traffic (usually
0.0.0.0/0) to an Internet Gateway (IGW). Instances launched here (like web servers) can communicate directly with the internet if assigned a public IP. - Private Subnet: A subnet is considered "private" if its route table does not have a route to an IGW. Instances in a private subnet cannot be accessed directly from the public internet, making it the ideal location for backend servers and databases. To grant them outbound internet access (e.g., for software updates), you must use a NAT Gateway located in a public subnet.
- Purpose: Subnets allow you to partition your network logically, implement tiered security architectures, and distribute resources across multiple AZs for high availability.
Q3. What is a route table?
A Route Table is a vital networking component within a VPC that contains a set of rules, called "routes," which are used to determine where network traffic directed from your subnet or gateway should go.
- Subnet Association: Each subnet in your VPC must be explicitly or implicitly associated with one route table at a time, which governs its traffic routing. However, a single route table can be associated with multiple subnets.
- Structure: Each route specifies a destination CIDR block and a target. For example, a route might dictate that traffic destined for
10.0.0.0/16(the local VPC network) is targeted tolocal, while traffic destined for anywhere else (0.0.0.0/0) is targeted to an Internet Gateway (igw-12345). - Main vs. Custom: When you create a VPC, a "Main Route Table" is automatically generated. It's a best practice to leave the Main Route Table private (no internet route) and create Custom Route Tables for public subnets to explicitly control internet access.
Q4. Explain security groups.
A Security Group acts as a virtual, stateful firewall that controls incoming and outgoing traffic for your AWS resources (most commonly EC2 instances, but also RDS, load balancers, etc.).
- Stateful Nature: Security Groups are stateful. This means if you send a request from your instance (outbound), the response traffic for that request is automatically allowed to flow back in, regardless of your inbound security group rules.
- Default Posture: By default, a newly created security group allows all outbound traffic (so instances can reach the internet) and denies all inbound traffic. You must explicitly open ports (e.g., Port 80 for HTTP, Port 22 for SSH) to allow inbound connections.
- Allow Rules Only: You can only configure "allow" rules; you cannot create "deny" rules in a Security Group.
- Instance-Level: They are applied directly to the Elastic Network Interface (ENI) of an instance, meaning instances in the same subnet can have different security group rules.
Q5. Differentiate Security Groups and NACL.
Security Groups and Network Access Control Lists (NACLs) are both firewalls, but they operate at different layers and have different characteristics:
| Feature | Security Groups (SG) | Network ACLs (NACL) |
|---|---|---|
| Scope of Operation | Operates at the instance level (specifically attached to the Network Interface). | Operates at the subnet level, providing a blanket rule for everything inside the subnet. |
| Statefulness | Stateful. Return traffic is automatically allowed, regardless of inbound rules. | Stateless. Return traffic must be explicitly allowed by rules (e.g., opening ephemeral ports). |
| Rule Types | Supports only "Allow" rules. Traffic not explicitly allowed is denied. | Supports both "Allow" and "Deny" rules, allowing you to explicitly block specific bad IP addresses. |
| Rule Evaluation | All rules are evaluated simultaneously before deciding whether to allow traffic. | Rules are evaluated in strict numerical order (lowest to highest) until the first match is found. |
| Primary Use Case | The primary defense mechanism defining what an application should talk to. | A secondary layer of defense, often used as a boundary firewall to block known malicious networks. |
Q6. What is AWS Route 53?
Amazon Route 53 is a highly available, globally distributed, and scalable cloud Domain Name System (DNS) web service. It is designed to give developers and businesses an extremely reliable and cost-effective way to route end-users to internet applications.
- DNS Resolution: Its primary function is to translate human-readable domain names (like
www.amazon.com) into numeric IP addresses that computers use to connect to each other. - Domain Registration: Route 53 acts as a domain registrar, allowing you to purchase and manage custom domain names directly within the AWS console.
- Health Checks: Route 53 can monitor the health of your application endpoints. If a server fails a health check, Route 53 can automatically route traffic away from the failing endpoint to healthy ones.
- Advanced Routing Policies: It offers sophisticated routing mechanisms, including Simple routing, Weighted routing (load distribution), Latency-based routing (routing users to the closest region), Failover routing (for disaster recovery), and Geolocation routing.
Q7. Explain Amazon CloudFront.
Amazon CloudFront is a fast, highly secure, programmable Content Delivery Network (CDN) service that accelerates the delivery of data, videos, applications, and APIs to users globally.
- Edge Caching: It works by caching copies of your static and dynamic content at a massive global network of Edge Locations and Regional Edge Caches.
- Low Latency Delivery: When a user requests your content, CloudFront routes the request to the Edge Location that can serve the request with the lowest latency, ensuring excellent performance regardless of the user's geographical location.
- Integration: It integrates seamlessly with other AWS services. You can use Amazon S3, an EC2 instance, or an Elastic Load Balancer as your "Origin" server.
- Security: It provides robust security, natively integrating with AWS WAF (Web Application Firewall) and AWS Shield to protect against DDoS attacks and malicious web exploits at the edge, before they reach your infrastructure.
Q8. Describe VPC creation steps.
Creating a functional, custom VPC involves several sequential steps:
- Define the VPC CIDR Block: Navigate to the VPC dashboard, click "Create VPC," and define the primary IPv4 CIDR block (e.g.,
10.0.0.0/16), providing a large pool of IP addresses. - Create Subnets: Create subnets within the VPC's CIDR block. Allocate smaller CIDR blocks (e.g.,
10.0.1.0/24for Public,10.0.2.0/24for Private) and carefully map each subnet to a specific Availability Zone. - Attach an Internet Gateway (IGW): To allow internet communication, create an Internet Gateway and attach it to your VPC.
- Configure Route Tables: Create a custom Route Table. Add a route that points all internet-bound traffic (
0.0.0.0/0) to the IGW you just created. Finally, associate this Route Table with the subnet you want to be "Public." - Configure Network Security: Adjust the default Security Groups or create new ones to define what traffic is allowed in and out of your instances. Optionally, modify the default Network ACL for subnet-level restrictions.
Q9. How to launch a web server in VPC?
To launch a functional, internet-facing web server within a VPC:
- Prepare the Network: Ensure you have a VPC with a Public Subnet (a subnet associated with a route table that directs
0.0.0.0/0traffic to an attached Internet Gateway). - Configure Security Group: Create a Security Group that permits inbound HTTP (TCP port 80) and HTTPS (TCP port 443) traffic from anywhere (
0.0.0.0/0), and allows SSH/RDP from your specific IP address for administration. - Launch the EC2 Instance: Initiate the EC2 launch wizard. Select an AMI (e.g., Amazon Linux 2), choose an instance type, and critically, select your VPC and the Public Subnet. Ensure the option to "Auto-assign Public IP" is enabled.
- Provide User Data: In the advanced details, provide a bootstrap script (User Data) to automate software installation upon launch. For example:
yum update -y && yum install httpd -y && systemctl start httpd && systemctl enable httpd && echo "Hello World" > /var/www/html/index.html. - Access the Server: Once the instance is running, copy its Public IP address and paste it into a web browser to view your deployed web page.
Q10. Explain VPC security best practices.
Securing a VPC requires a defense-in-depth approach utilizing multiple AWS features:
- Principle of Least Privilege with Security Groups: Never use overly permissive rules (like allowing SSH
0.0.0.0/0). Restrict inbound traffic strictly to the necessary ports and trusted source IP addresses. - Utilize Private Subnets: Place backend application servers, databases, and internal services in private subnets. Only place resources that require direct internet access (like Load Balancers or Bastion Hosts) in public subnets.
- Secure Remote Access: Avoid exposing SSH/RDP ports to the internet directly. Instead, use AWS Systems Manager Session Manager for secure, audited access without needing Bastion Hosts, open inbound ports, or managing SSH keys.
- Implement Network ACLs judiciously: Use NACLs as a secondary, stateless boundary firewall to explicitly deny known malicious IP blocks or enforce subnet boundaries.
- Enable VPC Flow Logs: Always enable VPC Flow Logs to capture detailed information about the IP traffic going to and from network interfaces in your VPC. This data is critical for monitoring network throughput, troubleshooting connectivity issues, and conducting security forensics.
Chapter-3: Compute Services
Q1. What is Amazon EC2?
Amazon Elastic Compute Cloud (Amazon EC2) is a core AWS service that provides scalable computing capacity in the cloud. It allows users to rent virtual computers on which to run their own computer applications. Using Amazon EC2 eliminates the need to invest in costly physical hardware up front, allowing you to develop and deploy applications significantly faster. You can use Amazon EC2 to launch as many or as few virtual servers (instances) as you need, dynamically scale them up or down to handle changes in requirements or spikes in popularity, configure intricate security and networking, and manage persistent storage. You maintain complete administrative control over these instances (root/administrator access) and are responsible for patching the guest operating system.
Q2. Explain EC2 instance types.
AWS offers a vast array of EC2 instance types, grouped into families, optimized for different computing profiles and workloads:
- General Purpose (e.g., T, M series): These provide a balanced ratio of compute, memory, and networking resources. They are ideal for a broad range of applications like web servers, smaller databases, and development environments. The 'T' series offers burstable CPU performance.
- Compute Optimized (e.g., C series): These offer the lowest price per vCPU and are designed for compute-bound workloads that benefit from high-performance processors, such as batch processing, scientific modeling, high-traffic web servers, and machine learning inference.
- Memory Optimized (e.g., R, X, z series): These are built for workloads that process extremely large data sets in memory, offering the lowest price per GiB of RAM. Use cases include high-performance relational databases, NoSQL databases, and in-memory analytics.
- Storage Optimized (e.g., I, D series): These are intended for workloads requiring high, sequential read and write access to very large data sets on local storage (e.g., massive data warehouses, Elasticsearch clusters, distributed file systems).
- Accelerated Computing (e.g., P, G series): These use hardware accelerators, or co-processors (like GPUs or custom FPGAs), to perform functions like floating-point number calculations, graphics processing, or machine learning model training much more efficiently than CPUs.
Q3. What is Elastic Load Balancing?
Elastic Load Balancing (ELB) is a service that automatically distributes incoming application traffic and scales resources to meet traffic demands. It ensures that no single EC2 instance is overwhelmed, thereby increasing the fault tolerance and availability of applications. ELB can handle varying traffic loads across multiple instances in a single Availability Zone or spread them across multiple AZs. It performs regular health checks on registered targets and stops routing traffic to unhealthy instances until they recover. AWS offers three primary types:
- Application Load Balancer (ALB): Operates at Layer 7 (HTTP/HTTPS), ideal for advanced routing (path-based, host-based) for microservices and containers.
- Network Load Balancer (NLB): Operates at Layer 4 (TCP/UDP), capable of handling millions of requests per second while maintaining ultra-low latencies.
- Gateway Load Balancer (GWLB): Operates at Layer 3, used to deploy, scale, and manage third-party virtual appliances like firewalls and intrusion detection systems.
Q4. Explain Auto Scaling in AWS.
Amazon EC2 Auto Scaling is a highly critical service that helps you maintain application availability and allows you to automatically add or remove EC2 instances according to conditions you define. It ensures you have the correct number of Amazon EC2 instances available to handle the load for your application.
- Dynamic Scaling: You can create scaling policies based on CloudWatch metrics. For example, a policy can instruct Auto Scaling to add two instances if the average CPU utilization exceeds 70% for five minutes, and remove an instance if it drops below 30%.
- Predictive Scaling: Uses machine learning to analyze historical traffic patterns and automatically schedule the right number of instances in anticipation of future demand.
- Fleet Management: It constantly monitors instance health. If an instance terminates unexpectedly or fails a health check, Auto Scaling will automatically launch a replacement instance to maintain your defined "desired capacity," ensuring high availability.
Q5. Describe launching an EC2 instance.
The process of launching an EC2 instance involves several configuration steps through the AWS Management Console:
- Choose an Amazon Machine Image (AMI): Select the base software configuration. An AMI includes the Operating System (e.g., Amazon Linux, Ubuntu, Windows Server) and sometimes pre-installed software stacks (e.g., LAMP stack, deep learning libraries).
- Choose an Instance Type: Select the hardware profile that meets your compute, memory, and storage needs (e.g.,
t3.micro,m5.large). - Configure Instance Details: Specify the number of instances, select the target VPC and Subnet, assign an IAM role (for permissions), and decide whether to assign a public IP address. You can also provide User Data scripts here.
- Add Storage: Configure the Elastic Block Store (EBS) root volume (size and type, like
gp3) and optionally attach additional data volumes. - Add Tags: Assign key-value metadata (e.g.,
Environment: Production,CostCenter: 1234) to help manage, filter, and track costs. - Configure Security Group: Define the virtual firewall rules. Select an existing group or create a new one to allow necessary inbound traffic (like SSH on port 22 or HTTP on port 80).
- Review and Launch: Finalize the settings, and select an existing SSH Key Pair (or create and download a new one) required to securely connect to the instance via SSH.
Q6. What is serverless computing?
Serverless computing is a cloud execution model where the cloud provider dynamically manages the allocation and provisioning of servers, completely abstracting the underlying infrastructure away from the developer. In a serverless architecture, you do not need to provision, configure, or maintain virtual machines, nor do you have to worry about operating system patches, capacity planning, or high availability configuration. You simply write your application code and deploy it. The most distinct feature of serverless is the pricing model: you are charged based on the actual compute time consumed (measured in milliseconds) and the number of executions, rather than paying for pre-provisioned, idle server capacity. If your code is not running, you pay nothing for compute. Key AWS serverless services include AWS Lambda, Amazon API Gateway, and Amazon DynamoDB.
Q7. Explain AWS Lambda.
AWS Lambda is the pioneering serverless, event-driven compute service provided by AWS. It allows developers to run code for virtually any type of application or backend service without provisioning or managing servers. You organize your code into discrete entities called "Lambda functions." Lambda is deeply integrated with the AWS ecosystem and is designed to execute your function code in response to specific events or triggers. These triggers can be changes in data (like an image uploaded to an S3 bucket), shifts in system state (a CloudWatch alarm), or user actions (an HTTP request routed through API Gateway). Lambda handles all the operational complexity: it automatically provisions the necessary compute environments, scales highly precisely from a few requests per day to tens of thousands per second, and provides built-in high availability across multiple Availability Zones.
Q8. How to configure Lambda functions?
Configuring a Lambda function involves several key components within the AWS console:
- Function Code and Runtime: You must provide your code and specify the runtime environment (e.g., Node.js, Python, Java, Go). Code can be written directly in the inline editor, uploaded as a ZIP file, or deployed as a container image.
- Execution Role (IAM): You must attach an IAM execution role to the function. This role dictates what other AWS services the Lambda function is permitted to interact with (e.g., giving it permission to read from a specific DynamoDB table).
- Triggers and Destinations: You configure "Triggers" (event sources like S3, SQS, API Gateway) that invoke the function. You can also configure "Destinations" to automatically send the result of an asynchronous invocation to another service (like SNS or EventBridge).
- General Configuration: You must allocate the amount of memory available to the function (from 128 MB to 10,240 MB). AWS allocates CPU power proportionally based on the memory configured. You also set the execution timeout (maximum 15 minutes).
- VPC Settings: By default, Lambda runs in a secure AWS-managed VPC. If your function needs to access private resources like an RDS database or ElastiCache cluster, you must attach the function to your own custom VPC.
Q9. What is Elastic Beanstalk?
AWS Elastic Beanstalk is a highly automated Platform as a Service (PaaS) offering designed to make it incredibly easy for developers to deploy and scale web applications and services. It supports applications developed with Java, .NET, PHP, Node.js, Python, Ruby, Go, and Docker. With Elastic Beanstalk, developers simply upload their application code. The service automatically handles all the complex infrastructure orchestration details, including capacity provisioning (EC2 instances), load balancing (ELB), auto-scaling, application deployment, and continuous health monitoring. Crucially, unlike many other PaaS solutions, Elastic Beanstalk does not restrict you. It provides abstraction for speed, but you retain full, transparent control over the underlying AWS resources powering your application and can access and modify them at any time if advanced customization is required.
Q10. Explain application deployment using Elastic Beanstalk.
Deploying an application via Elastic Beanstalk is a streamlined process designed for developer efficiency:
- Create an Application: In the Elastic Beanstalk console, define a new application, which acts as a logical container for your environments and versions.
- Create an Environment: Choose the environment tier. Select "Web server environment" for standard HTTP applications, or "Worker environment" for background processing tasks that pull from an SQS queue.
- Select Platform: Choose the appropriate managed platform that matches your code's language and framework (e.g., Python 3.9, Node.js 16, Tomcat).
- Upload Application Code: Provide your source code either by uploading a local ZIP file or specifying an S3 URL where your deployment package resides.
- Launch Configuration: You can customize settings like instance types, VPC configuration, and database creation. Upon clicking launch, Beanstalk uses CloudFormation under the hood to provision the EC2 instances, configure the load balancer, establish the auto-scaling group, and deploy the code.
- Iterative Updates: To deploy a new version, you simply upload a new ZIP file. Beanstalk can apply the update using various deployment policies (like Rolling or Immutable deployments) to ensure zero downtime.
Chapter-4: Storage Services
Q1. Differentiate Object, Block, and File Storage.
Understanding the three primary types of cloud storage is crucial for architectural decisions:
| Feature | Block Storage | File Storage | Object Storage |
|---|---|---|---|
| Data Organization | Data is chopped into raw, fixed-size chunks called "blocks." No metadata is inherently attached. | Data is organized as files within a hierarchical structure of nested folders and directories. | Data is stored as discrete units called "objects," containing the data, expansive metadata, and a globally unique identifier, sitting in a flat address space. |
| Access Protocol | Accessed by operating systems at a very low level, treating it as a raw, physical hard drive (SAN/DAS). | Accessed over a local network by multiple clients using standard file-level protocols like NFS or SMB (NAS). | Accessed programmatically over the internet using RESTful HTTP/HTTPS APIs (GET, PUT, DELETE). |
| Performance Characteristics | Ultra-low latency, highly consistent, ideal for high IOPS (Input/Output Operations Per Second). | Good performance for shared access, supports file locking and concurrent read/writes. | Highly scalable and highly durable, but generally has slightly higher latency than block storage. Not suited for databases. |
| Primary Use Cases | Databases (Oracle, SQL), Operating System boot volumes, enterprise applications requiring high performance. | Shared corporate network drives, content management systems, multi-instance web servers requiring shared configurations. | Big data analytics, media storage (videos/images), backup archives, static website hosting, data lakes. |
| AWS Service Equivalent | Amazon Elastic Block Store (EBS) | Amazon Elastic File System (EFS), Amazon FSx | Amazon Simple Storage Service (S3) |
Q2. What is Amazon S3?
Amazon Simple Storage Service (Amazon S3) is AWS's flagship object storage service, providing industry-leading scalability, data availability, security, and performance. It allows customers of all sizes and industries to store and protect any amount of data for a range of use cases, such as data lakes, websites, mobile applications, backup and restore, archive, enterprise applications, IoT devices, and big data analytics. Data in S3 is stored as "objects" (files) within logical containers called "buckets." Because it is an object store, there is no hierarchical folder structure; instead, objects are identified by a unique key. S3 is designed to provide 99.999999999% (11 9's) of durability, meaning the statistical probability of losing a file is practically zero, achieved by redundantly storing objects on multiple devices across multiple facilities within an AWS Region. It is highly accessible via robust REST APIs.
Q3. Explain S3 storage classes.
Amazon S3 offers a range of storage classes designed for different use cases, allowing you to optimize costs based on data access patterns:
- S3 Standard: Offers high durability, availability, and performance object storage for frequently accessed data. It delivers low latency and high throughput, making it ideal for cloud applications, dynamic websites, and content distribution.
- S3 Standard-Infrequent Access (S3 Standard-IA): For data that is accessed less frequently, but requires rapid access when needed (e.g., long-term backups or disaster recovery files). It offers a lower storage price but charges a per-GB retrieval fee.
- S3 One Zone-Infrequent Access (S3 One Zone-IA): Stores data in a single Availability Zone (unlike other classes that use at least three). It costs 20% less than Standard-IA but is vulnerable to data loss if that specific AZ is destroyed.
- S3 Glacier Flexible Retrieval: A low-cost archival storage class for data accessed 1-2 times per year, with retrieval times ranging from minutes to hours.
- S3 Glacier Deep Archive: The absolute lowest-cost storage class in AWS. It is designed for long-term digital preservation and regulatory compliance archiving, where retrieval times of 12 hours or more are acceptable.
- S3 Intelligent-Tiering: Uses machine learning to automatically move objects between a frequent access tier and an infrequent access tier based on actual usage patterns, optimizing costs without any operational overhead or retrieval fees.
Q4. What is Amazon EBS?
Amazon Elastic Block Store (Amazon EBS) provides highly available, persistent, block-level storage volumes specifically designed for use with Amazon EC2 instances. EBS volumes behave like raw, unformatted external physical hard drives. Once attached to an EC2 instance, you can create a file system on top of them, run a database, or use them in any way you would use a block device.
EBS volumes are inherently highly available; data is automatically replicated across multiple servers within a single Availability Zone to prevent data loss from a single hardware component failure. AWS offers several volume types to balance price and performance: SSD-backed volumes (like gp3 for general purpose workloads and io2 for mission-critical, high-IOPS databases) and HDD-backed volumes (like st1 for high throughput big data workloads and sc1 for cold data).
Q5. Explain Amazon EFS.
Amazon Elastic File System (Amazon EFS) provides a simple, scalable, and fully managed elastic file system for Linux-based workloads running on AWS and on-premises resources. It is built to support the Network File System version 4 (NFSv4) protocol. The core strength of EFS is its elasticity. The file system grows and shrinks automatically as you add and remove files, meaning you never have to provision storage capacity in advance, and you only pay for the storage you use. EFS is a regional service, storing data redundantly across multiple Availability Zones for high durability and availability. A single EFS file system can be mounted concurrently by tens, hundreds, or even thousands of EC2 instances, making it the perfect solution for shared data workloads, container storage, and highly available web server clusters.
Q6. Differentiate EBS and EFS.
While both provide storage for EC2 instances, their architecture and capabilities differ significantly:
| Feature | Amazon EBS (Elastic Block Store) | Amazon EFS (Elastic File System) |
|---|---|---|
| Storage Architecture | Block Storage (acts like a physical hard drive). | File Storage (acts like a shared network drive/NAS). |
| Attachment Capabilities | Generally attached to only a single EC2 instance at a time (though EBS Multi-Attach exists for specific clustered applications). | Can be mounted concurrently by thousands of EC2 instances across multiple AZs. |
| Availability Scope | Confined to a single Availability Zone. If an AZ goes down, the EBS volume is inaccessible until restored elsewhere. | Spans across multiple Availability Zones in a Region, offering inherently higher availability. |
| Scalability & Provisioning | Capacity is provisioned in advance. Volumes must be manually resized if they run out of space. | Highly elastic. Automatically grows and shrinks as files are added or removed; no capacity planning required. |
| OS Compatibility | Supports both Linux and Windows operating systems. | Primarily designed for Linux operating systems (uses NFSv4). |
| Cost | Generally lower cost per GB, paying for provisioned space regardless of usage. | Generally higher cost per GB, but you strictly pay only for data stored. |
Q7. What is lifecycle management in S3?
S3 Lifecycle Management provides a set of rules that you define to manage your objects so that they are stored as cost-effectively as possible throughout their entire lifecycle. As data ages, its access frequency typically decreases, making it inefficient to keep it in the expensive S3 Standard tier. Lifecycle rules automate the process of moving or deleting objects. There are two primary types of actions:
- Transition Actions: These define when objects should transition to another storage class. For example, a rule could state that objects created in a specific bucket should be moved to the cheaper S3 Standard-IA class 30 days after creation, and then further moved to S3 Glacier for long-term archiving after 90 days.
- Expiration Actions: These define when objects expire and should be permanently deleted by AWS. For example, you can set a rule to automatically delete application log files 365 days after they were generated. This automation is crucial for controlling cloud storage costs without requiring manual intervention.
Q8. How to create an EBS volume?
Creating and utilizing a standalone EBS volume involves these steps in the AWS Management Console:
- Navigate to EBS: Open the EC2 Dashboard and select Volumes under the Elastic Block Store section.
- Initiate Creation: Click the Create Volume button.
- Select Volume Type: Choose the storage type that matches your workload requirements (e.g., General Purpose SSD
gp3for a balance of price and performance, or Provisioned IOPSio2for high-performance databases). - Specify Capacity: Define the Size (in GiB) and, depending on the volume type, allocate specific IOPS or Throughput values.
- Select Availability Zone: This is critical: you must select the exact same Availability Zone as the EC2 instance you intend to attach it to (e.g.,
us-east-1a), as EBS volumes cannot span AZs. - Optional Configurations: You can choose to create the volume from an existing Snapshot (backup) to restore data, and you should enable EBS Encryption using a KMS key for security.
- Create and Attach: Click Create. Once the volume's state changes to "Available," select the volume, click Actions, choose Attach Volume, and select your target running EC2 instance. Finally, you will need to log into the OS to format and mount the new drive.
Q9. Explain static website hosting using S3.
Amazon S3 can be configured to host a robust, highly available static website without the need to provision, manage, or pay for a traditional web server like an EC2 instance. Static websites consist of fixed content (HTML, CSS, client-side JavaScript, and media assets) and do not utilize server-side processing scripts (like PHP, Python, or database queries). Steps to configure:
- Bucket Creation: Create an S3 bucket. If you plan to use a custom domain, the bucket name must exactly match the domain name (e.g.,
www.example.com). - Upload Content: Upload your static assets, ensuring you have an entry point file, typically
index.html. - Enable Hosting: In the bucket's "Properties" tab, enable "Static website hosting." You must specify the name of your index document and an optional error document (e.g.,
404.html). - Set Permissions: S3 buckets are private by default. You must disable "Block Public Access" and attach a Bucket Policy that explicitly grants
s3:GetObjectpermissions to anyone ("Principal": "*") so internet users can view the content. - Access: You can then access the site using the S3-provided endpoint URL, or use Route 53 to map your custom domain to the S3 bucket.
Q10. Discuss advantages of AWS storage services.
AWS provides a comprehensive suite of storage services (Object, Block, and File) offering significant advantages over traditional on-premises storage arrays:
- Unmatched Durability and Reliability: Services like S3 are designed for 11 9's of durability (99.999999999%), utilizing redundant storage across multiple facilities. This makes data loss statistically near-impossible, far exceeding what traditional data centers can offer.
- Infinite Scalability: AWS storage services are virtually limitless. You can scale storage capacity from gigabytes to exabytes seamlessly without having to plan capacity, purchase hardware arrays, or migrate data.
- Cost-Efficiency and Flexibility: The pay-as-you-go model ensures you only pay for what you use. Furthermore, varied storage classes (like Glacier) and features like S3 Intelligent-Tiering allow organizations to aggressively optimize costs based on how frequently data is accessed.
- Robust Security and Compliance: AWS offers enterprise-grade security features, including encryption at rest (using AWS KMS) and in transit, granular access control policies (IAM, Bucket Policies, ACLs), and supports numerous compliance certifications (HIPAA, PCI-DSS).
- Seamless Integration: AWS storage services integrate natively with the entire AWS ecosystem, making it easy to feed data into analytics pipelines (Redshift, Athena), machine learning models (SageMaker), or compute resources (EC2, Lambda).
Chapter-5: AWS Architecture and Database Services
Q1. What is AWS Well-Architected Framework?
The AWS Well-Architected Framework is a comprehensive guide developed by AWS to help cloud architects build secure, high-performing, resilient, and efficient infrastructure for their applications and workloads. It provides a consistent approach for customers and partners to evaluate their architectures and implement designs that will scale gracefully over time. The framework is not a set of rigid rules, but rather a set of best practices and questions to encourage critical thinking about architecture. It is built upon six foundational pillars:
- Operational Excellence: Focusing on running and monitoring systems to deliver business value and continually improving processes.
- Security: Protecting information and systems, focusing on confidentiality and integrity.
- Reliability: Ensuring a workload performs its intended function correctly and consistently when expected.
- Performance Efficiency: Using computing resources efficiently to meet system requirements and maintaining that efficiency as demand changes.
- Cost Optimization: Avoiding unnecessary costs and maximizing the value delivered at the lowest price point.
- Sustainability: Minimizing the environmental impacts of running cloud workloads.
Q2. Explain AWS design principles.
To implement the Well-Architected Framework effectively, AWS outlines general design principles that facilitate good cloud architecture:
- Stop guessing your capacity needs: In traditional IT, poor capacity planning leads to expensive idle resources or limited capacity causing poor user experience. In AWS, utilize Auto Scaling to dynamically adjust resources based on real-time demand.
- Test systems at production scale: In the cloud, you can provision a complete, production-scale test environment on demand, run massive load tests, and then decommission the environment, paying only for the hours tested.
- Automate to make architectural experimentation easier: Use Infrastructure as Code (IaC) tools like AWS CloudFormation or Terraform. Automation allows you to create and replicate environments rapidly, reducing manual errors and encouraging experimentation.
- Allow for evolutionary architectures: Traditional architectures are static. The cloud enables you to automate and test on demand, lowering the risk of design changes and allowing systems to evolve over time to adopt new technologies.
- Drive architectures using data: Make architectural choices based on concrete data. Collect comprehensive metrics and logs on application behavior to analyze how choices affect performance and cost.
- Improve through game days: Regularly simulate unexpected events or failures in your production environment (Chaos Engineering) to test how your architecture and operational teams respond.
Q3. What is Amazon RDS?
Amazon Relational Database Service (Amazon RDS) is a fully managed, scalable, and highly available relational database web service provided by AWS. It is designed to simplify the setup, operation, and scaling of a relational database in the cloud. RDS handles routine, time-consuming database administration tasks. It automates underlying hardware provisioning, operating system installation, database engine setup, minor version patching, and automated backups (with point-in-time recovery). This allows database administrators and developers to focus on higher-value tasks like application logic, schema design, and query optimization. RDS supports several popular database engines, giving developers the flexibility to choose: Amazon Aurora (proprietary high-performance engine), PostgreSQL, MySQL, MariaDB, Oracle Database, and Microsoft SQL Server. It also easily supports Multi-AZ deployments for synchronous replication and high availability.
Q4. Differentiate MySQL and PostgreSQL.
While both are highly popular open-source relational databases supported by RDS, they have distinct characteristics:
| Feature | MySQL | PostgreSQL |
|---|---|---|
| Database Paradigm | Pure Relational Database Management System (RDBMS). Focuses heavily on speed and simplicity. | Object-Relational Database Management System (ORDBMS). Focuses on extensibility and standard compliance. |
| Performance Profile | Highly optimized for fast read-heavy operations. It is the backbone of many dynamic web applications (like WordPress) and simple CRUD apps. | Better suited for complex analytical queries, heavy write operations, massive data volumes, and complex data warehousing tasks. |
| Concurrency Control | Traditionally uses table-level locking in some engines, which can cause bottlenecks during high-concurrency write operations. | Implements Multiversion Concurrency Control (MVCC), which handles high concurrency and simultaneous reads/writes exceptionally well without locking. |
| JSON & NoSQL Features | Provides basic JSON support, but is generally less flexible for unstructured data. | Offers exceptional, robust JSON (and JSONB) support, often allowing it to replace dedicated NoSQL databases for hybrid workloads. |
| Standard Compliance | Partially compliant with SQL standards; prioritizes speed over strict compliance. | Highly compliant with ANSI SQL standards, offering advanced features like common table expressions (CTEs) and window functions. |
Q5. Explain Amazon Aurora.
Amazon Aurora is a proprietary, fully managed relational database engine built exclusively for the cloud by AWS, offering full compatibility with MySQL and PostgreSQL. It is designed to combine the performance and availability of high-end commercial databases (like Oracle) with the simplicity and cost-effectiveness of open-source databases.
- Exceptional Performance: Aurora delivers up to 5 times the throughput of standard MySQL and up to 3 times the throughput of standard PostgreSQL running on similar hardware.
- Innovative Storage Architecture: It uses a fault-tolerant, self-healing, distributed storage system that automatically scales up to 128 TiB per database instance. Data is synchronously replicated 6 times across 3 Availability Zones, ensuring incredible durability without impacting performance.
- High Availability: It offers ultra-fast failover (typically under 30 seconds) to a replica instance if the primary instance fails, and supports up to 15 low-latency read replicas for massive read scaling.
Q6. What is Amazon DynamoDB?
Amazon DynamoDB is a fully managed, serverless, key-value and document NoSQL database service designed to deliver single-digit millisecond performance at virtually any scale.
- Serverless and Scalable: There are no servers to provision, patch, or manage. DynamoDB automatically scales read and write capacity up and down in response to application traffic, capable of handling peaks of more than 20 million requests per second.
- Performance at Scale: Unlike relational databases that slow down as data grows, DynamoDB provides consistent, ultra-low latency performance regardless of table size.
- Built for Enterprise: It includes built-in security, continuous automated backups, point-in-time recovery, and in-memory caching capability (DAX). Furthermore, DynamoDB Global Tables provides fully managed, multi-active replication across multiple AWS Regions for globally distributed applications. It is widely used in gaming, ad-tech, mobile backends, and IoT.
Q7. Explain Amazon Redshift.
Amazon Redshift is a fully managed, petabyte-scale cloud data warehouse service specifically designed for large-scale data analytics and Business Intelligence (BI) workloads.
- Purpose and Architecture: While RDS is designed for transactional processing (OLTP), Redshift is designed for analytical processing (OLAP). It uses columnar data storage and Massively Parallel Processing (MPP) architectures to distribute SQL operations across multiple compute nodes, delivering exceptionally fast query performance on massive datasets.
- Data Integration: It allows you to run complex analytical queries against structured and semi-structured data using standard SQL. With a feature called Redshift Spectrum, you can even query exabytes of data directly in Amazon S3 data lakes without having to load the data into Redshift tables first.
- Cost-Effective Analytics: It provides high performance at a fraction of the cost of traditional on-premises data warehouses.
Q8. Describe launching an RDS instance.
Provisioning a database via the RDS console involves several configuration parameters:
- Initiate Creation: Open the AWS RDS Console and click "Create database." Choose the "Standard create" method to view all configuration options.
- Select Engine: Choose the required database engine (e.g., MySQL, PostgreSQL, Oracle).
- Choose Template: Select a template based on the environment: Production (configures Multi-AZ for high availability), Dev/Test, or Free Tier.
- Configure Settings: Define the DB instance identifier (name), and set the master username and a strong master password for database administration.
- Instance and Storage: Select the DB instance class (which dictates the CPU and RAM) and define the storage type (e.g., General Purpose SSD) and allocated capacity. Note that storage can auto-scale.
- Network Connectivity: Place the database in the correct VPC and Subnet Group. Define Security Groups to strictly control inbound traffic (e.g., only allow port 3306 from the web server security group). Crucially, ensure "Public access" is set to "No" for security.
- Finalize: Click "Create database." AWS manages the complex provisioning process, and the database endpoint will be available shortly.
Q9. Differentiate SQL and NoSQL databases.
Understanding the difference between SQL (Relational) and NoSQL (Non-Relational) is fundamental for cloud data architecture:
| Feature | SQL (Relational Databases) | NoSQL (Non-Relational Databases) |
|---|---|---|
| Data Model | Stores data in highly structured tables comprised of rows and columns, linked by complex relationships (foreign keys). | Stores data in flexible formats such as JSON documents, key-value pairs, wide-column stores, or graph structures. |
| Schema Flexibility | Requires a rigid, pre-defined schema. You must alter the table structure to accommodate new data types, which can cause downtime. | Features a dynamic, flexible schema. You can insert data without defining structure first, and different documents in the same collection can have different fields. |
| Scaling Mechanism | Primarily vertically scalable (Scaling Up). Handling more load requires migrating to a larger, more expensive server with more CPU/RAM. | Inherently horizontally scalable (Scaling Out). Handling more load simply involves adding more cheap commodity servers to the cluster. |
| Data Integrity Principles | Strictly adheres to ACID properties (Atomicity, Consistency, Isolation, Durability), ensuring absolute data integrity, crucial for financial transactions. | Generally adheres to BASE properties (Basically Available, Soft state, Eventual consistency), favoring high availability and speed over immediate consistency. |
| AWS Examples | Amazon RDS, Amazon Aurora | Amazon DynamoDB, Amazon DocumentDB |
Q10. Discuss AWS database services.
AWS embraces the philosophy of "purpose-built databases," arguing that no single database fits all use cases. They offer a diverse portfolio of managed database services tailored for specific data models:
- Relational (RDBMS): Amazon RDS and Amazon Aurora. Best for structured data, complex joins, and transactional applications like ERP, CRM, and e-commerce platforms requiring strict ACID compliance.
- Key-Value: Amazon DynamoDB. A highly scalable, serverless database ideal for applications requiring consistent single-digit millisecond latency at any scale, such as high-traffic web apps, real-time bidding, and IoT data stores.
- In-Memory Caching: Amazon ElastiCache (supporting Redis and Memcached). Used to cache frequently queried data in memory to achieve microsecond latency, dramatically improving the performance of read-heavy applications and acting as session stores.
- Document: Amazon DocumentDB. A fast, scalable, highly available, and fully managed document database service that supports MongoDB workloads, ideal for content management systems and user profiles.
- Graph: Amazon Neptune. Designed to store and navigate highly connected datasets. Ideal for recommendation engines, fraud detection, and social networking applications.
- Time-Series: Amazon Timestream. Built to efficiently collect, store, and process massive volumes of time-stamped data, perfect for IoT telemetry and DevOps operational metrics.