56 – 135: Core AWS Services, Security, Networking, Cost & AI
- AWS Control Tower – Multi-account setup with guardrails (best practice governance).
- AWS Landing Zone – Initial secure enterprise account blueprint (older concept).
- Multi-AZ vs Multi-Region – Multi-AZ → high availability | Multi-Region → disaster recovery.
- AWS Backup Vault Lock – Prevents backups from being deleted (ransomware protection).
- AWS Elastic Disaster Recovery (DRS) – Fast recovery of servers from on-prem/AWS to AWS.
- AWS Migration Hub – Central place for migration tracking.
- AWS Application Migration Service (MGN) – Lift-and-shift migration tool.
- AWS Database Migration Service (DMS) – Move databases between engines (e.g., Oracle → Aurora).
- Amazon Aurora Serverless v2 – Auto-scales instantly, SQL-compatible.
- Amazon QLDB – Immutable ledger database (tamper-proof log).
- Amazon Neptune – Graph database for relationships (social graphs).
- Amazon OpenSearch Service – Search, logs, analytics (replacement for Elasticsearch).
- AWS Step Functions – Serverless orchestration of Lambda / SQS / APIs.
- AWS Batch – Run large batch workloads without managing servers.
- AWS Glue – Serverless ETL service for data processing (data catalog).
- Amazon Athena – Query S3 data using SQL — serverless analytics.
- Amazon QuickSight – Visualization and BI dashboards.
- Amazon Kinesis – Real-time data streaming analytics.
- Amazon EMR – Big data processing (Spark, Hadoop, Hive).
- AWS IQ – Hire certified AWS experts for on-demand work.
- AWS CodeCommit – Private Git repositories service.
- AWS CodeBuild – Fully managed CI build service.
- AWS CodeDeploy – Deploy to EC2, Lambda, on-prem servers.
- AWS CodePipeline – Orchestrate CI/CD pipelines.
- AWS AppRunner – Easy way to run containerized apps (fully managed).
- AWS Elastic Beanstalk – Deploy applications without managing servers (PaaS).
- AWS Amplify – Frontend/mobile hosting + backend APIs + Auth.
- AWS GameLift – Deploy and scale multiplayer game servers.
- AWS IoT Core – Connect and manage IoT devices securely.
- AWS Greengrass – Run Lambda + ML on edge (IoT gateway).
- IAM Policies – JSON format, Allow/Deny rules, identity-based + resource-based.
- IAM Permission Boundaries – Maximum permissions allowed to a user/role.
- IAM Access Analyzer – Detects public or cross-account access.
- AWS GuardDuty – Threat detection using machine learning.
- AWS Macie – Finds & protects sensitive S3 data (PII detection).
- AWS Detective – Investigates security incidents using AI.
- Security Groups – Stateful firewall for EC2 instances.
- NACL (Network ACL) – Stateless VPC security layer.
- VPC Peering – Connect VPCs privately (one-to-one).
- AWS Transit Gateway – Central hub connecting thousands of VPCs.
- VPC Endpoints – Private AWS service connections.
- Direct Connect – Dedicated fiber link to AWS.
- AWS Certificate Manager (ACM) – Free SSL/TLS certificates.
- AWS Secrets Manager – Store & rotate secrets.
- AWS Parameter Store – Configuration storage (SSM).
- Public vs Private Subnet – Public → IGW | Private → NAT.
- Route Tables – Control traffic flow between subnets.
- NAT Gateway – Secure internet access for private subnets.
- Internet Gateway – Public internet access.
- AWS Global Infrastructure Benefits – Fault tolerance, availability, low latency.
- Availability Zones Failure Independence – One AZ failure won’t affect others.
- Edge Caching in CloudFront – Improves speed, reduces origin load.
- S3 Object Lock – Prevents deletion of objects.
- MFA Delete – Extra layer for S3 delete protection.
- AWS Resilience Hub – Automatic workload resilience evaluation.
- AWS Support Plans – Basic, Developer, Business, Enterprise On-Ramp, Enterprise.
- Business Plan Features – 24/7 support, full Trusted Advisor, fast response.
- Enterprise Support Features – Architect, TAM, concierge billing.
- AWS Cost Anomaly Detection – Alerts on unusual usage spikes.
- AWS Savings Plans – 1 or 3-year compute commitments.
- Compute Savings Plan – EC2 + Lambda + Fargate.
- EC2 Instance Savings Plan – EC2 only.
- Spot Instances Best Use Cases – Batch & flexible workloads.
- Reserved Instances – Capacity commitment for discounts.
- AWS TCO Calculator – On-prem vs cloud cost comparison.
- AWS Pricing Calculator – Estimate AWS architecture cost.
- AWS Billing Alarms – Cost threshold alerts.
- AWS Glue Data Catalog – Central metadata store.
- S3 Replication – Cross-region / same-region replication.
- S3 Pre-Signed URLs – Temporary secure access URLs.
- Athena Partitioning – Faster & cheaper queries.
- Redshift Spectrum – Query S3 data from Redshift.
- Kinesis Firehose – Streaming ingestion → S3 / Redshift.
- Kinesis Data Streams – Real-time event pipeline.
- Amazon Polly – Text-to-speech ML.
- Amazon Rekognition – Image & video analysis.
- Amazon Textract – OCR & document text extraction.
- Amazon SageMaker – End-to-end ML platform.
- AWS Snowcone – Portable 8TB edge device.
- AWS Compute Optimizer – Cost & performance recommendations.