Home / Community / AWS Solutions Architect Associate (SAA-C03) - Core Services & Architecture
Public

AWS Solutions Architect Associate (SAA-C03) - Core Services & Architecture

Master AWS SAA-C03 core services like EC2, S3, RDS, and Lambda, and design highly available, scalable, and secure cloud solutions. Elevate your cloud architecture skills for exam success.

22 accessible of 22 cards

Card Preview

22 accessible of 22 cards

A quick, read-only look at the deck content.

Term

What are the primary considerations when choosing an EC2 instance type?

Definition

When selecting an EC2 instance type, key considerations include:
  • Compute: CPU cores, clock speed.
  • Memory: RAM capacity.
  • Storage: Instance store (ephemeral) vs. EBS-optimized.
  • Networking: Network performance, dedicated bandwidth.
  • Cost: Pricing model (On-Demand, Reserved, Spot).
  • Workload: General purpose, compute-optimized, memory-optimized, storage-optimized, accelerated computing.

Term

Differentiate between AWS Security Groups and Network ACLs (NACLs).

Definition

Both Security Groups and Network ACLs act as firewalls for your VPC, but at different layers:
  • Security Groups: Operate at the instance level, are stateful (return traffic is automatically allowed), and support allow rules only.
  • NACLs: Operate at the subnet level, are stateless (return traffic must be explicitly allowed), and support both allow and deny rules. They are processed in order by rule number.

Term

Explain the use cases for Application Load Balancers (ALB) and Network Load Balancers (NLB).

Definition

  • Application Load Balancer (ALB): Best suited for HTTP/HTTPS traffic, offering advanced routing features based on URL path, host header, or query string. Ideal for microservices and container-based applications.
  • Network Load Balancer (NLB): Best suited for extreme performance, static IP addresses, and handling TCP/UDP/TLS traffic. Ideal for high-throughput, low-latency applications where preserving client IP is critical.

Term

Describe the core components of an AWS Auto Scaling Group.

Definition

An Auto Scaling Group (ASG) ensures you have the correct number of EC2 instances available to handle your application's load. Its core components are:
  • Launch Template/Configuration: Defines how new EC2 instances are launched (AMI, instance type, security groups, user data).
  • Scaling Policies: Dictate when to scale out (add instances) or scale in (remove instances) based on metrics (e.g., CPU utilization, network I/O).
  • Minimum/Maximum/Desired Capacity: Sets the boundaries for the number of instances in the group.
  • Health Checks: Monitors instance health and replaces unhealthy instances.

Term

Compare and contrast S3 Standard, S3 Standard-IA, and S3 One Zone-IA storage classes.

Definition

  • S3 Standard: For frequently accessed data, offering high durability (11 nines) and availability, stored redundantly across multiple Availability Zones (AZs).
  • S3 Standard-IA (Infrequent Access): For less frequently accessed data that requires rapid access when needed. Lower storage cost than Standard but higher retrieval fees. Stored across multiple AZs.
  • S3 One Zone-IA: For infrequently accessed, non-critical data that can be recreated. Lower storage cost than Standard-IA but data is stored in a single AZ, making it vulnerable to AZ loss.

Term

How do S3 Versioning and S3 Cross-Region Replication contribute to data durability and disaster recovery?

Definition

  • S3 Versioning: Protects against accidental deletions and overwrites by keeping multiple versions of an object. It allows you to restore previous versions, enhancing data durability.
  • S3 Cross-Region Replication (CRR): Automatically replicates objects to a destination bucket in a different AWS Region. This provides a robust disaster recovery strategy by maintaining a geographically separate copy of your data, ensuring business continuity even in the event of a regional outage.

Term

Explain the difference in purpose between RDS Multi-AZ deployments and Read Replicas.

Definition

  • RDS Multi-AZ: Primarily for high availability and disaster recovery. It creates a synchronous standby replica in a different Availability Zone. If the primary instance fails, RDS automatically fails over to the standby, minimizing downtime. It does not improve read performance.
  • RDS Read Replicas: Primarily for read scalability and performance improvement. They are asynchronous copies of the primary database that can handle read traffic, offloading the primary instance. They can also be promoted to a standalone database for disaster recovery, but with potential data loss due to asynchronous replication.

Term

List and briefly describe the essential components required to launch an EC2 instance in a public subnet within a custom VPC.

Definition

To launch an EC2 instance in a public subnet within a custom VPC, you need:
  • VPC: The isolated virtual network.
  • Subnet: A range of IPs within the VPC, designated as 'public' (meaning it has a route to an Internet Gateway).
  • Internet Gateway (IGW): Allows communication between instances in your VPC and the internet.
  • Route Table: Contains rules (routes) that determine where network traffic from your subnet is directed (e.g., 0.0.0.0/0 to the IGW for public subnets).
  • Security Group: Acts as a virtual firewall for the EC2 instance, controlling inbound and outbound traffic.
  • EC2 Instance: The virtual server itself.