AWS Training
Modules Listen All tracks

← Fundamentals

SAAF Cheat sheet — Fundamentals

Verified 2026-09-25 against the pages cited in each lesson. Items marked [unverified] were not retrieved from a page I fetched — look them up.

Cloud computing — two lists, don't mix them

AWS definition: "on-demand delivery … via the internet with pay-as-you-go pricing."

NIST SP 800-145 — 5 essential characteristics AWS — 6 advantages
On-demand self-service Trade fixed expense for variable expense
Broad network access Benefit from massive economies of scale
Resource pooling Stop guessing capacity
Rapid elasticity Increase speed and agility
Measured service ("pay-per-use") Stop spending money running and maintaining data centers
Go global in minutes

Service models: IaaS → PaaS → SaaS. ⚠️ The OS is the line — IaaS consumer "has control over operating systems"; PaaS consumer "does not".

Deployment models: AWS = Cloud · Private cloud (on-premises) · Hybrid. NIST = private · community · public · hybrid. AWS has no community cloud; AWS equates private cloud with on-prem.

Exam guide target candidate: "at least 1 year of hands-on experience designing cloud solutions that use AWS services." No recommended-knowledge list on the HTML home page.

Global infrastructure

Thing Key words (verbatim)
Region "a separate geographic area" · "isolated from the other Regions" · "we don't automatically replicate them for you"
AZ "one or more discrete data centers" · "dedicated metro fiber" · "within 100 km (60 miles) of each other" (S3 page)
Local Zone "an extension of an AWS Region in geographic proximity to your users" · enable → subnet → launch · e.g. us-west-2-lax-1
Wavelength Zone "edge of communications service providers' (CSP) networks" · 5G · carrier gateway · opt in
Outpost AWS capacity "at a customer site" · "as part of an AWS Region" · exam's hybrid-compute example
Edge location / POP CloudFront; request "routed to the edge location that provides the lowest latency"

Zonal / Regional / Global

Source: AWS Fault Isolation Boundaries whitepaper (Nov 16, 2022) + each service's page.

Scope Test Examples (verified) To survive more
Zonal you choose the AZ EC2 instance · EBS volume ("must be in the same Availability Zone") · subnet · EFS One Zone · S3 One Zone-IA 2nd AZ
Regional one Regional endpoint S3 (≥3 AZs) · DynamoDB (3 AZs, 99.99%) · SQS (whitepaper) · EFS Regional 2nd Region + replication
Global control plane in ONE Region, data plane everywhere IAM · Organizations (us-east-1) · Route 53 public DNS · CloudFront · ACM/WAF for CloudFront (us-east-1) · Global Accelerator · ARC (us-west-2) keep its control plane out of recovery

Shared Responsibility

AWS = "of" the cloud: "from the host operating system and virtualization layer down to the physical security of the facilities." Customer = "in" the cloud: "guest operating system (including updates and security patches)… security group firewall" — and "determined by the AWS Cloud services that a customer selects."

Control Example
Inherited "Physical and Environmental controls"
Shared ("completely separate contexts") Patch mgmt · Configuration mgmt · Awareness & training
Customer specific "Service and Communications Protection or Zone Security"
EC2 RDS Lambda S3
Guest OS patch you AWS performs; you pick window; optional updates — "RDS does not apply these automatically" [unverified] AWS
Runtime/engine you AWS (maintenance) Auto mode: Lambda; container image: you redeploy —
Network access VPC + SGs VPC + SGs IAM (+VPC) policies
Data · IAM · encryption choices you you you you

⚠️ Public S3 bucket = customer ("Managing access to your data"). Lambda requires TLS 1.2.

Networking

Virtualisation

Encryption

DNS & DNSSEC

Four things to carry in

  1. Five characteristics are NIST's; six advantages are AWS's.
  2. If you choose the AZ, it's zonal. "Global" still has a one-Region control plane.
  3. Host OS is AWS's; guest OS is yours when you run it. Data, IAM and encryption choices are always yours.
  4. A subnet is public because of its route table — and it lives in exactly one AZ.