2024年6月19日 星期三

【IT Notes】AWS SAA-C03重點整理

 花了三個多月的時間,考了兩次才通過這次考試,必須說AWS SAA-C03真的有難度,共用了一個月上線上課程、兩個月做考古題,覺得還是勤做考古題比較有效果,光是聽課就只是產生一點印象,做考古題才能知道自己有哪些細節不熟,回頭再去補強。即使準備充足,還是得要懂得應付考試的題目的眉角,這邊就整理一下自己這三個月以來的考古題筆記。


AWS功能 

關鍵字與重點整理

IAMIAM Identities(Users,Groups,Roles)
SCPOU,member,服務相關,不影響服務角色
KMS金鑰加密,IAM Policy
Secret Manager金鑰輪替,密鑰保存
Congnito跟社交媒體,SaaS同步帳號認證
Congnito User Pools身份管理,驗證
Congnito Identity Pools授予APP對AWS服務資源存取的權限
Control Tower中央集中管理,多帳號管理
SQSlong transaction, process, decouple, 持續交易, 程序, 解耦, polling, 輪詢
SQS FIFO每秒300條SQS transaction,每秒3000訊息
SQS Long Polling至少有一條訊息才會回應,訊息量少故較便宜
SQS Short Polling未查詢到訊息也會回應
SNSdecouple, 解耦, notification,通知
AmazonMQ   MQ, MQTT, RabbitMQ
Eventbridge事件匹配,多元事件,一整包事件服務
Kenesisreal-time, 即時, stream, 流, 流資料, 大數據, 分片, 大量且快速
Kenesis Firehosestream+加載, S3, RedShift, Splunk
Pinpoint SMS,簡訊,通知
Multi-AZ,多可用區High Availability, 高可用 
read-only replica,唯獨副本流量大時分流
CloudFormation Stack單一帳戶和區域建立資源
CloudFormation Stackset多帳戶和區域部署資源
LambdaServerless,無伺服器,省成本,15分鐘,短期
Lambda@EdgeCloudFront的Edge Location執行,加速
ALB,NLB可擴充,擴展,scalable
ASG可用性,擴充,縮減,scalable
Global Accelerator 加速,UDP
Config    追蹤和記錄 AWS 資源的配置,安全性,稽核,成本效率
Inspector偵測軟體漏洞和弱點
GuardDuty惡意程式防護(EC2, ECS, EKS), 授權行為,紀錄VPN/DNS/Cloud Trail event log
Budgets控制成本,警報通知,短期
Cost Explorer    視覺化和圖形化分析費用及成本,支出模式,長期
System Management自動化,遠端管理,部署
BeanstalkPaaS,快速
Trusted Advisor分析成本,配置優化,安全性、性能和成本效率的建議
Shield AdvancedDDos,跟WAF結合,L3/4/7防護
WAFSQL injection,XXS,跟 CloudFront與ALB接合,應用程式防火牆
Firewall Manager多帳號,多防火牆和多區域,較複雜的防護大禮包(WAF, Network Firewall, Shied, Route53 Firewall, Security Group )
Security GroupInstance,只有允許,stateful,要指定instance
ACLSubnet,允許和拒絕,stateless,對所有instance有效
NAT網際網路,outbound only
IGW,Internet Gateway網際網路,允許雙向通訊
DataSyncNFS,SMB,Fsx,EFS,S3,大規模,複雜,同步
Transfer Family分成FTP和SFTP,資料傳輸到S3,EFS,EBS...
EBS掛載磁區或磁碟,volume
EFS共用File System,文件
Transfer Acceleration提升Transfer傳輸速度,CloudFront
Storage Gateway:
分以下三種
1.File GatewayNFS,SMB,文件接口
2.Volume Gatewayiscsi volume,EBS,Stored Volume,Cached Volume
3.Tape GatewayTape,磁帶,S3 Glacier
SSE-S3S3託管金鑰,單一用途,免費
SSE-CS3加密,用戶自己保管金鑰,收費但不貴
SSE-KMSKMS加密和保管金鑰,較安全但也較貴
Client Side Encryption用戶端自己加密和保管交金鑰,免費,適合金融業
S3 Object lockS3內的物件防止刪除(適合金融業)
S3 Glacier Vault lockS3 Glacier bucket的防止誤刪用的鎖定
S3 Standard標準,較快速
S3 IT(Intelligent Tier)資料有頻繁和不頻繁區分,讓系統自動判別
S3 Standard IA (Infrequently Accessed) 資料不頻繁取用,一個月取用一次很適合
S3 IA One-Zone比上者更便宜,可接受資料遺失
S3 Glacier便宜,資料取用幾分鐘~小時
S3 Glacier Deep Archive最便宜,資料取用12~48小時
RDSMySQL,Oracle,MSSQL,關聯性
DynomoDBNoSQL,MongoDB,結構靈活,key value,非關聯性
Aurora全球,快速,高性能,可擴充,高可用
Aurora Serverless自動調整容量,以量計費,短時間的大量需求
Quantum Ledger Database密碼編譯,歷史紀錄
Elastic Redis支援地理和多點,支援複製和存檔snapshot,不支援多thread,複雜
Elastic Memcached不支援地理和多點,不支援複製和存檔snapshot,支援多thread,簡單
On-Demand Instance隨用即用,用多少算多少錢,較靈活,適合開發環境,優化成本考量
Reserved Instance預設範圍,穩定,可預測的工作型態,適合production環境
Spot Instance用戶競價的關係,價格最低,穩定較差,可接受中斷
Cluster Group PlacementHPC,高性能,快速
Spread Group Placement遇到少量需要隔離的情形,降低故障
Partition Group PlacementHadoop,低故障率
Dedicated Host專用主機,完全孤立,自由配置,符合法規和license,昂貴
Dedicated Instance客製化的instance,依照instance計費,可自選Spot/On-Demanded/Reserved Instance
GlueETL,爬蟲,JDBC
AppFlowSaaS
EMRSpark,Glue
Rekognition人臉辨識
Transcribe語音辨識
TextractOCR
AthenaSQL Query,ODBC
RedshiftDW,提供數據服務,資料儲存與SQL Query功能
Redshift Spectrum可用SQL Query S3
QuickSightBI,不提供數據服務,資料可視化與分析
Geoproximityclient和AWS之間的距離
Geolocation直接將流量路由到特定的地理區域
CloudWatchlogs,日誌
CloudTrailAPI追蹤
Restful APIstateless
WebSocket APIstateful
Neptune圖形化,serverless,社交關連
SageMakerML,Machine Learning


考古題我是做了Udemy和examtopics的題庫,後者的精準度滿高的,不過要能閱讀所有題庫要噴不少錢錢,所以我大部分的時間都是做Udemy,都是反覆做好幾次來增加記憶,第一次考沒過的時候我只做了兩遍,第二次我就連續做了四、五遍,看不懂的題目就背下來,有些題目重複率滿高的,記得有些題目連續兩次都有考出來,像是:

A company has an Amazon S3 bucket that contains critical data. The company must protect the data from accidental deletion.
Which combination of steps should a solutions architect take to meet these requirements? (Choose two.)

  • A. Enable versioning on the S3 bucket.
  • B. Enable MFA Delete on the S3 bucket.
  • C. Create a bucket policy on the S3 bucket.
  • D. Enable default encryption on the S3 bucket.
  • E. Create a lifecycle policy for the objects in the S3 bucket.

答案:AB

A company maintains its accounting records in a custom application that runs on Amazon EC2 instances. The company needs to migrate the data to an AWS managed service for development and maintenance of the application data. The solution must require minimal operational support and provide immutable, cryptographically verifiable logs of data changes.

Which solution will meet these requirements MOST cost-effectively?

  • A. Copy the records from the application into an Amazon Redshift cluster.
  • B. Copy the records from the application into an Amazon Neptune cluster.
  • C. Copy the records from the application into an Amazon Timestream database.
  • D. Copy the records from the application into an Amazon Quantum Ledger Database (Amazon QLDB) ledger.

答案:D


還有一題是考前一晚看考古題才知道的,若沒有做題目的話這題我大概也不會解:

A company's application integrates with multiple software-as-a-service (SaaS) sources for data collection. The company runs Amazon EC2 instances to receive the data and to upload the data to an Amazon S3 bucket for analysis. The same EC2 instance that receives and uploads the data also sends a notification to the user when an upload is complete. The company has noticed slow application performance and wants to improve the performance as much as possible.
Which solution will meet these requirements with the LEAST operational overhead?

  • A. Create an Auto Scaling group so that EC2 instances can scale out. Configure an S3 event notification to send events to an Amazon Simple Notification Service (Amazon SNS) topic when the upload to the S3 bucket is complete.
  • B. Create an Amazon AppFlow flow to transfer data between each SaaS source and the S3 bucket. Configure an S3 event notification to send events to an Amazon Simple Notification Service (Amazon SNS) topic when the upload to the S3 bucket is complete.
  • C. Create an Amazon EventBridge (Amazon CloudWatch Events) rule for each SaaS source to send output data. Configure the S3 bucket as the rule's target. Create a second EventBridge (Cloud Watch Events) rule to send events when the upload to the S3 bucket is complete. Configure an Amazon Simple Notification Service (Amazon SNS) topic as the second rule's target.
  • D. Create a Docker container to use instead of an EC2 instance. Host the containerized application on Amazon Elastic Container Service (Amazon ECS). Configure Amazon CloudWatch Container Insights to send events to an Amazon Simple Notification Service (Amazon SNS) topic when the upload to the S3 bucket is complete.

答案:B
想到去年八月跟Victor去南港展覽館的AWS大會,參加他們展覽(其實是去排隊領贈品),他當時就一直跟我推要學習雲端技術,開始我是聽的懵懵懂懂的,現在在雲端公司上班後,才知道AWS、PaaS和VPS這些以前都沒碰過的技術,至少這個技術維持個10年應該是跑不掉的。去年什麼都還不知道,想不到今年就已經走進雲端的世界,有時候人生真的是很多想不到事情,還是時時叮嚀自己,好好把握時間和身邊的人事物。

人生中的第三張證照,斜槓人生再接再厲。



   

沒有留言:

張貼留言

【IT Notes】透過api移轉Gmail到Exchange

 在雲端裡面串接api不是一件很好學的技術,第一次有機會學習到將GWS的Gmail信件全部轉移到M365的Exchange,其實方法很多種,像以前用的pst檔匯出轉移的方式等,但透過api串接,可以批次和排程轉移,是非常方便且準確的作法。唯一讓人感到困難的是學習成本不小,通常需要...