AWS SysOps Certificate

Get Started. It's Free
or sign up with your email address
Rocket clouds
AWS SysOps Certificate by Mind Map: AWS SysOps Certificate

1. Monitoring, Metrics, Analizies

1.1. CloudWatch

1.1.1. Types EC2 Host Level Metrics Consist of EBS Metrics Volume Status Check ELB every 60 seconds important  metrics ElastiCache Memcached Redis DynamoDB RDS by metrics by events Custom Metrics min interval is 1 min Log Files of application

1.1.2. Storing Metrics By default - 2 weeks can be longer than 2 weeks using GetMetricStatistics API or using third party tools You can retrieve data from terminated EC2 RDS instance for up to 2 weeks, after terminating

1.1.3. Centralized Monitoring If you need to monitor the entire infrastructure you need to use Centalized Monitoring (Zennos, Splunk, Nagios etc)

1.2. Storages

1.2.1. EBS I/O Credits Each volume gets 5,400,000 I/O credits on the balance When you are not over your provisioned IO level you will be earning IO credits burst is up to 3000 IO for volumes bigger than 1 Gb Pre-Warming EBS Volumes New EBS volumes receive their maximum performance the moment that they are available and do not require initialization (formerly known as pre-warming). Storage blocks on volumes that were restored from snapshots must be initialized (pulled down from Amazon S3 and written to the volume) before you can access the block.

1.3. CostOptimisation

1.3.1. Heavy,Medium utilization for reserved instances

2. High Availability

2.1. Elasticity

2.1.1. Scale OUT

2.1.2. Short term period of time (Hours, Days)

2.1.3. EC2: increase number of instances in ASG

2.1.4. DynamoDB: increase IOPS for additional spikes in traffic

2.1.5. RDS: not very elastic

2.2. Scalability

2.2.1. Long term period (weeks, months)

2.2.2. Scale UP

2.2.3. EC2: increase instance type

2.2.4. DynamoDB Unlimited amount of storage

2.2.5. RDS: Increase instance size

2.3. RDS

2.3.1. Read Replica up to 5 Read Replicas for MySQL and Postgres Read Replicas cross Region For MySQL Replication for Read Replicas is Asynchronous Read Replicas can NOT be Multi-AZ Read Replica of Read Replica (ONLY MySQL) increase latency DB Snapshot or Automated Backup can NOT be taken for Read Replica Key Metrica is REPLICA LAG Requires   Automated Backups OR created snapshot

2.3.2. Multi-AZ Auto Failover NOT a scaling solution

2.4. Trouble Shooting

2.4.1. Instances not launching in to Autoscaling Groups Assosiated Key Pair doesn't exist Security Group Doesn't exist Autoscaling config is not working correctly ASG not found Instance type is not supported in the AZ AZ is not longer supported Invalid EBS device mapping Autoscaling Service is not enabled in your account Attempting to attach EBS device to an instance store AMI

3. Deploying & Provisioning

3.1. Services give root access to OS

3.1.1. EC2

3.1.2. Opsworks

3.1.3. MapReduce

3.1.4. Beanstalk

3.2. ELB

3.2.1. supports different AZ in same VPC, same region

3.2.2. Types External Internal Only addresable in your VPC

3.2.3. Sticky Session Disabled by default Types Duration Based Session Stickyness Application-controlled Session Stickyness

3.2.4. CloudWatch ELB Latency SurgeQueueLength SpillOverCount

3.2.5. Prewarming ELB You need to contact with AWS support to preconfigure ELB

4. Data Management

4.1. Disaster Recovery

4.1.1. Services Regions Storage S3- 99,999999999% durability and Cross Region Replication Glacier EBS AWS Storage Gateway Compute EC2 EC2 VM Import Connector Networking Route53 ELB VPC Direct Connect Databases RDS DynamoDB RedShift Orchestration CloudFormation ElasicBeanstalk Opsworks Lambda

4.1.2. Recovery Time Objective (RTO)

4.1.3. Recovery Point Objective (RPO) amount of data your organisation is prepared to lose in event disaster

4.1.4. DR Scenarios Backup & Restore (24 hours) Pilot Light (2 hours) the minimal version of your environment is always runs  in cloud Predefined AMI for EC2 instalces Small RDS instances with replication Network Warm Standby (0.5 hours) Multi Site (0 hours)

4.2. Automated Backups

4.2.1. Services Have automated backups from the box RDS ElastiCache (only for Redis) Redshift NOT have automated backups from the box EC2

4.3. Storage Type

4.3.1. Instance Store Root Volume Size is up to 10 Gb boot time is less than 5 min Terminating Root volume will be deleted automatically Other instance store volumes will be deleted automatically Other EBS volumes will persist can NOT be stopped You will lose data of Instace Store Volume under following circumstancies Failed underling drive Stopping EBS backed instance Terminating instance

4.3.2. EBS Root Volume Size is up to 1 or 2 Tb depending on the OS boot time is less than 1 min you can update instance type, kernel RAM disk user data ... Terimnating Root volume will be removed by default (can be changed while creating instance) Other volumes will be preserved

5. Security

5.1. Security Token Service (STS)

5.1.1. Federation (AD) uses Security Assertion Markup Language (SAML) Grants temporal access based off the users AD credentials. Doesn't need to be a user of IAM Single sign on allows user to log in to AWS consol without assigning IAM credentials

5.1.2. Federation with Mobile Apps Use Facebook/Amazon/Google or other OpenID providers to log in

5.1.3. Cross Account Access Let's users from one account access resources in another

5.1.4. Terms Federation Combining/Joining a list of user in one domain (such as IAM)  with list of users in another domain (such as AD, Facebook...) Identity Broker A service that allows you to take an identity from point A and join it (federate it) to point B. You need to configure it Identity Store Services like AD, Facebook.... Identities A users of services like Facebook etc

5.1.5. Scenario1 Employee enters username and password Identity Broker captures the username and password Identity Broker uses LDAP direcotry to validate Identity Broker calls the new GetFederationToken. The call includes IAM policy and a duration return access key, secret key, token and duration

5.1.6. Scenario2 Develop an Identity Broker to communicate with LDAP and AWS STS Identity Broker always authenticate with LDAP first, gets IAM Role associated with a user Application then authenticates with STS and assumes that IAM role Application uses that IAM role to interact with S3

5.1.7. Tips You need to develop Identity Broker to communicate with LDAP and AWS STS Identity Broker always authenticate with LDAP first and THEN with AWS STS Application gets temporal access to AWS resources

6. Network

6.1. Network throughput depend on instance type

6.2. Different instance type has different EBS throughput to the disk

6.3. Route53

6.3.1. Failover need to configure health check

6.3.2. Weighted

6.3.3. Latency based routing

6.3.4. Geolocation

6.4. Direct Connect

7. Questions

7.1. Retantion period for SQS

7.1.1. SQS automatically deletes messages that have been in a queue for more than maximum message retention period. The default message retention period is 4 days. However, you can set the message retention period to a value from 60 seconds to 1209600 seconds (14 days) with SetQueueAttributes.

7.2. custom CloudWatch metric for Disk full percentage of an Elastic Block Store Volume

7.3. You have been tasked with identifying an appropriate storage solution for a 300 GB MongoDB database that requires random I/O reads of greater than 110,000 4kB IOPS. Which EC2 option will meet this requirement?

7.4. You are using ElastiCache to cache your web application. The caching seems be running slower and slower and you want to diagnose the cause of this issue. If you are using Memcached as your caching engine, what parameter should be adjusted if you find that the overhead pool is less than 50MB?

7.4.1. Memcached_Connections_Overhead

7.5. Your EBS Volume status check is showing impaired. What does this mean?

7.5.1. The volume is stalled or not available.

7.6. You have a web application which queries elasticache to cache your database queries. You are using memached with elasticache and you use CloudWatch metrics to monitor your memcached performance. You notice that two metrics, Evictions (The number of non-expired items the cache evicted to allow space for new writes.) and GetMisses (The number of get requests the cache has received where the key requested was not found.) are getting very high. What should you do to scale your environment further?

7.6.1. Increase the number of nodes in your memcached cluster or increase the size of each node in your cluster.

7.7. You are leading a design team to implement an urgently needed collection and analysis project. You will be collecting data for an array of 50,000 anonymous data collectors which will be summarized each day and then rarely used again. The data will be pulled from collectors approximately once an hour. The Dev responsible for the DynamoDB design is concerned about how to design the Partition and Local keys to ensure efficient use of the DynamoDB tables. What advice would you provide. (Select 2)

7.7.1. Create a new table each day, and reconfigure the old table for infrequent use after the summation is complete

7.7.2. insert a calculated hash in front of the Date/Time value in the partition key to force DynamoDB to hop from partition to to partition.

7.7.3. There are two issues here. How to handle stale data to avoid paying for high provisioned throughput for infrequently used data. Plus how to design a partition key to distribute IO from sequential data across partitions evenly to avoid performance bottlenecks Further information: