AI Cert Prep
Type to search documentation.

Start with AWS

AWS Services Glossary

A–Z reference of the 73 AWS services, features and operational terms that the Cloud Practitioner, Solutions Architect, SysOps, Developer and AI Practitioner exams name directly.

73 entries across 22 letters. This glossary covers the AWS services and operational vocabulary tested by the five certification tracks on this site — Cloud Practitioner, Solutions Architect – Associate, SysOps Administrator – Associate, Developer – Associate and AI Practitioner. It is deliberately separate from the AIB-C01 glossary, which defines the business vocabulary of the AI Business Strategist exam and assesses no services at all.

Each definition is written at the depth the exams test: what the service does, the discriminator that separates it from the service candidates confuse it with, and the operational detail that shows up in item stems.

Jump to: A · B · C · D · E · F · G · H · I · K · L · M · N · O · P · Q · R · S · T · V · W · X


A

ACM (AWS Certificate Manager) – A managed service for provisioning, managing, and deploying SSL/TLS certificates for use with AWS services. ACM provides free public certificates for domains you own, handles automatic renewal before expiration, and integrates natively with CloudFront, Application Load Balancers, API Gateway, and CloudFormation. Eliminating manual certificate management prevents outages from expired certificates — a common production failure mode.

Amazon Athena – An interactive, serverless query service that allows you to analyze data directly in Amazon S3 using standard SQL — no data loading, ETL pipelines, or infrastructure to manage. Athena is billed per TB of data scanned, making it cost-effective for ad-hoc analytics on large datasets. It integrates with AWS Glue Data Catalog for schema management and supports formats like Parquet, ORC, JSON, and CSV. Partitioning and columnar formats dramatically reduce scan costs.

Amazon Aurora – AWS’s proprietary, MySQL and PostgreSQL-compatible relational database engine, designed from the ground up for cloud-scale performance. Aurora’s distributed storage replicates data six ways across three AZs automatically and scales up to 128 TB without manual intervention. It delivers up to 5x MySQL and 3x PostgreSQL performance on equivalent hardware. Aurora Serverless v2 automatically adjusts capacity in fine-grained increments to match workload demand — ideal for variable or unpredictable traffic.

AMI (Amazon Machine Image) – A pre-configured template used to launch EC2 instances. An AMI includes the operating system, application server, pre-installed software, and configuration. AMIs are region-specific — to use one in another region it must be copied. Custom AMIs are commonly used to bake application code and dependencies into a repeatable, version-controlled launch template.

API Gateway – A fully managed service for creating, publishing, securing, and monitoring RESTful and WebSocket APIs at any scale. API Gateway handles traffic management, authorization (IAM, Lambda authorizers, Cognito), throttling, caching, and stage management. It integrates natively with Lambda as a serverless backend and supports canary deployments for safe API version rollouts.

Auto Scaling Group (ASG) – A logical group of EC2 instances managed together for automatic scaling and self-healing. An ASG maintains a desired capacity, launches new instances when demand increases (scale out), terminates instances when demand drops (scale in), and automatically replaces unhealthy instances. Scaling policies include Target Tracking, Step Scaling, Simple Scaling, and Scheduled Scaling.

Availability Zone (AZ) – One or more discrete data centers within an AWS Region, each with independent power, cooling, and networking. AZs within a region are physically separated but interconnected via high-bandwidth, low-latency private fiber. Spreading workloads across multiple AZs is the primary mechanism for achieving high availability — a failure in one AZ does not affect resources in another.

B

AWS Batch – A fully managed service for running large-scale batch computing jobs on AWS. You submit jobs that AWS Batch automatically schedules and runs on dynamically provisioned EC2 or Fargate compute resources, scaling the fleet up during peak load and back to zero when jobs are complete. AWS Batch eliminates the need to manage job queues, cluster sizing, or compute infrastructure for batch workloads like genomics, financial risk analysis, rendering, and ML training pipelines.

Bastion Host – A hardened EC2 instance in a public subnet that serves as the sole entry point for SSH or RDP administrative access to instances in private subnets. Traffic flows: administrator → bastion host (via internet) → private instance (via private IP). Bastion hosts should be minimal, tightly locked down to known source IPs, and have all sessions logged. AWS Systems Manager Session Manager is the modern alternative that eliminates the need for bastion hosts entirely.

Blue/Green Deployment – A deployment strategy that runs two identical environments simultaneously — the current production environment (blue) and a new environment with the updated version (green). Traffic is shifted to green when it passes validation, and blue remains running as an instant rollback target. Blue/green eliminates deployment downtime and enables instant rollback. AWS CodeDeploy, Elastic Beanstalk, and ECS all support blue/green deployments.

C

Amazon Cognito – AWS’s fully managed user identity and authentication service for web and mobile applications. Cognito User Pools provide a user directory with sign-up, sign-in, MFA, social federation (Google, Facebook, Apple), and SAML-based enterprise identity. Cognito Identity Pools (Federated Identities) exchange authenticated tokens for temporary AWS credentials, granting users scoped access to AWS services directly from client-side code. Cognito eliminates the need to build and maintain custom authentication infrastructure.

AWS CodeDeploy – A fully managed deployment service that automates application deployments to EC2 instances, on-premises servers, Lambda functions, and ECS services. CodeDeploy supports in-place (rolling) deployments that update existing instances, and blue/green deployments that provision fresh instances with zero downtime. The AppSpec file (appspec.yml) defines lifecycle event hooks and the actions to run at each deployment phase (BeforeInstall, AfterInstall, ApplicationStart, ValidateService).

AWS CodePipeline – A fully managed continuous delivery service that automates the end-to-end software release pipeline — from source code change through build, test, and deployment. CodePipeline orchestrates stages: a source stage (CodeCommit, GitHub, S3), a build stage (CodeBuild), optional test stages, and one or more deploy stages (CodeDeploy, Elastic Beanstalk, ECS, CloudFormation). Manual approval actions pause the pipeline and require human sign-off before proceeding, typically used before production deployments.

AWS Config – A service that continuously records the configuration state of AWS resources and evaluates them against defined compliance rules. Config creates a configuration item every time a resource is created or modified, building a complete configuration history. Config Rules (AWS-managed or custom Lambda functions) evaluate whether resources comply with organizational policies. Config is reactive — it identifies non-compliant resources after changes occur — unlike preventive controls like SCPs. Config Aggregator consolidates compliance data across multiple accounts.

CIDR (Classless Inter-Domain Routing) – A notation for specifying IP address ranges, written as an IP address followed by a prefix length (e.g., 10.0.0.0/16). The prefix length determines how many bits are fixed (network portion) and how many are variable (host portion). A /16 block provides 65,536 addresses; a /24 provides 256 (251 usable in AWS after 5 reserved addresses). CIDR notation is used to define VPC address spaces and subnet ranges.

CloudFormation – AWS’s Infrastructure as Code (IaC) service. You declare your entire AWS infrastructure in JSON or YAML templates; CloudFormation provisions, updates, and deletes resources in the correct dependency order. Key concepts: Stacks (instantiated templates), ChangeSets (preview before applying), DeletionPolicy (Retain/Snapshot/Delete on stack removal), cfn-signal (bootstrap validation), and StackSets (deploy across multiple accounts and regions).

CloudFront – AWS’s global Content Delivery Network (CDN). CloudFront caches content at hundreds of edge locations worldwide, serving requests from the location nearest to the user to minimize latency. Origins can be S3 buckets, ALBs, EC2 instances, or any HTTP endpoint. Key concepts: TTL (cache duration), cache invalidation (force refresh), Origin Access Control (OAC) to restrict S3 bucket access to CloudFront only, and Lambda@Edge for request/response customization at the edge.

CloudTrail – AWS’s API audit logging service. CloudTrail records every API call made in your account — who made it, from which IP, using which credentials, at what time, and what parameters were passed. It is the answer to “who changed what in my AWS account?” Events are delivered to S3 (within ~15 minutes) and can be streamed to CloudWatch Logs for real-time alerting. CloudTrail is mandatory for security investigations, compliance audits, and governance.

CloudWatch – AWS’s unified monitoring and observability service. CloudWatch collects metrics (EC2 CPU, RDS connections, Lambda errors), aggregates logs from any source (EC2, Lambda, CloudTrail, VPC Flow Logs), fires alarms when thresholds are breached, and provides dashboards. Default EC2 metrics are reported every 5 minutes; detailed monitoring reduces this to 1 minute. RAM utilization and disk space require the CloudWatch Agent because the hypervisor cannot observe them.

D

AWS DMS (Database Migration Service) – A managed service for migrating databases to AWS with minimal downtime. DMS supports homogeneous migrations (e.g., MySQL to RDS MySQL) and heterogeneous migrations (e.g., Oracle to Aurora PostgreSQL, using the Schema Conversion Tool for schema translation). DMS can perform one-time full-load migrations or ongoing replication to keep the source and target databases in sync — enabling near-zero-downtime cutovers by running target and source in parallel until the cutover window.

Direct Connect – A dedicated private network connection between your on-premises data center and AWS, bypassing the public internet entirely. Direct Connect provides consistent network performance, lower latency, and higher bandwidth than internet-based VPN connections. It is required for workloads that need predictable throughput (large data transfers, latency-sensitive databases) or strict compliance requirements prohibiting internet exposure of sensitive traffic.

DynamoDB – AWS’s fully managed, serverless NoSQL key-value and document database delivering single-digit millisecond performance at any scale. Data is replicated across three AZs automatically. Key concepts: partition key (determines data distribution), sort key (enables range queries), GSI (Global Secondary Index for non-primary-key queries), Streams (CDC for event-driven processing), DAX (in-memory cache for microsecond reads), and Global Tables (multi-region active-active replication).

E

Amazon EventBridge – A serverless event bus that connects AWS services, custom applications, and SaaS providers using events. EventBridge rules match incoming events and route them to target services (Lambda, SQS, Step Functions, API Gateway, etc.). It supports scheduled rules using cron or rate expressions for time-based automation. EventBridge is the evolution of CloudWatch Events, adding event schema registry, cross-account event buses, and native SaaS integrations. It is the foundation for event-driven architectures and operational automation on AWS.

EBS (Elastic Block Store) – Persistent, network-attached block storage volumes for EC2 instances that survive instance stops and reboots. EBS volumes are confined to a single AZ. Types: gp3/gp2 (General Purpose SSD), io2/io1 (Provisioned IOPS SSD for high-IOPS databases), st1 (Throughput-Optimized HDD for sequential big data), sc1 (Cold HDD for infrequent access). Volumes can be resized and type-changed live (Elastic Volumes) without detaching.

EC2 (Elastic Compute Cloud) – AWS’s virtual machine service — the foundation of most AWS compute workloads. EC2 instances are configurable by instance family (T/M for general-purpose, C for compute, R for memory, I for storage, G for GPU), size, OS, networking, and storage. Purchasing options: On-Demand (per-second billing), Reserved Instances (up to 75% discount for 1/3-year commitments), Spot (up to 90% discount on spare capacity, interruptible), and Dedicated Hosts (physical server isolation).

ECR (Elastic Container Registry) – A fully managed Docker container image registry that stores, manages, and deploys container images. ECR integrates natively with ECS, EKS, and CodePipeline for seamless CI/CD workflows. Images are stored encrypted in S3, scanned for vulnerabilities using Amazon Inspector, and access is controlled via IAM policies. ECR lifecycle policies automatically delete old image versions to manage storage costs. ECR Public is a separate registry for sharing public container images.

ECS (Elastic Container Service) – AWS’s managed container orchestration service for running Docker containers. ECS manages scheduling, placement, scaling, and health of containerized tasks on either EC2 instances (EC2 launch type) or AWS Fargate (serverless, no infrastructure to manage). ECS tasks are granted AWS permissions via IAM Task Roles — never hardcode credentials in containers. ECS integrates with ALB for service discovery and load balancing.

EKS (Elastic Kubernetes Service) – AWS’s managed Kubernetes service that runs the Kubernetes control plane across multiple AZs — handling API server, etcd, and controller management. You focus on deploying worker nodes (EC2 or Fargate) and your containerized workloads. EKS is fully compatible with the Kubernetes ecosystem (Helm, kubectl, standard manifests), making it straightforward to lift-and-shift existing Kubernetes workloads to AWS. Use EKS when you need Kubernetes-specific features (custom operators, service mesh, advanced scheduling) or portability across cloud providers.

Elastic Beanstalk – A Platform-as-a-Service (PaaS) that abstracts away infrastructure provisioning for web applications. You upload your application code (ZIP, WAR, or container) and specify the platform (Node.js, Python, Java, PHP, Ruby, .NET, Go, or Docker). Beanstalk automatically provisions EC2 instances, load balancers, Auto Scaling groups, and monitoring — all managed via CloudFormation under the hood. You retain full access to underlying resources for customization via .ebextensions configuration files.

Elastic IP – A static public IPv4 address allocated to your AWS account that you can associate with EC2 instances, NAT Gateways, or Network Load Balancers. Unlike the dynamic public IP assigned to an EC2 instance at launch (which changes on stop/start), an Elastic IP remains fixed and can be instantly remapped to a different instance — enabling rapid failover scenarios where a stable public endpoint is required. Elastic IPs are free while associated with a running instance; AWS charges for unassociated or idle Elastic IPs.

ElastiCache – A managed in-memory caching service supporting Redis and Memcached. Caching frequently accessed database results or session state dramatically reduces database load and improves response times. Redis supports persistence, replication, Pub/Sub, and rich data structures (sorted sets, lists) — making it suitable for session storage, leaderboards, and real-time analytics. Memcached is simpler and designed for pure horizontal scaling of a distributed cache.

ELB (Elastic Load Balancer) – AWS’s managed load balancing service, available in three types. ALB (Application Load Balancer, Layer 7) supports URL path-based and host-based routing — ideal for microservices. NLB (Network Load Balancer, Layer 4) handles millions of requests per second with sub-millisecond latency and provides static Elastic IPs per AZ. CLB (Classic Load Balancer) is the legacy option. All types integrate with Auto Scaling Groups and perform health checks to route traffic only to healthy targets.

F

Fargate – A serverless compute engine for running containers on ECS and EKS. With Fargate, you define the CPU and memory your container needs and AWS provisions, scales, and manages the underlying infrastructure. You never patch or manage EC2 instances. Fargate is billed per vCPU and memory used per second, making it cost-effective for variable or unpredictable container workloads where managing a fixed EC2 fleet would be wasteful.

G

AWS Global Accelerator – A networking service that improves the availability and performance of global applications by routing user traffic through AWS’s private global backbone network rather than the public internet. Users connect to the nearest AWS edge location, and traffic travels over AWS’s optimized fiber backbone to your application endpoints in any region. Global Accelerator provides two static Anycast IP addresses that front your application globally — improving latency, reducing packet loss, and enabling instant regional failover without DNS propagation delays.

AWS Glue – A fully managed serverless ETL (Extract, Transform, Load) service for preparing and integrating data for analytics. Glue crawlers automatically discover data schemas in S3, RDS, and other sources and populate the Glue Data Catalog — a central metadata repository used by Athena, Redshift Spectrum, and EMR. Glue ETL jobs transform and load data using auto-generated or custom PySpark or Python Shell scripts. Glue is the standard data integration layer in AWS data lake architectures.

Glacier – AWS’s lowest-cost archival storage service within the S3 family. S3 Glacier Instant Retrieval provides millisecond access for quarterly-accessed archive data. S3 Glacier Flexible Retrieval offers retrieval times of minutes to hours. S3 Glacier Deep Archive (the cheapest AWS storage option) has retrieval times of 12–48 hours and is designed for data retained for 7–10 years for regulatory compliance. Glacier Vault Lock enables WORM (Write Once Read Many) policies for immutable retention.

H

High Availability (HA) – An architectural property where a system continues operating despite the failure of one or more components, typically measured as a percentage of uptime (e.g., 99.99%). In AWS, HA is achieved by distributing resources across multiple Availability Zones, using Auto Scaling Groups to replace unhealthy instances, and configuring services like RDS Multi-AZ or Route 53 health-check-based failover routing to automatically redirect traffic away from failed components.

I

IAM (Identity and Access Management) – AWS’s centralized service for controlling who can do what across your AWS account. IAM is global (not regional) and is built around four primitives: Users (individual identities), Groups (collections of users sharing policies), Roles (assumable identities for services, instances, or cross-account access), and Policies (JSON documents defining allowed or denied actions on specific resources). New users have zero permissions by default. An explicit Deny in any policy always overrides any Allow.

Internet Gateway (IGW) – A horizontally scalable, highly available VPC component that enables two-way communication between instances in a VPC and the internet. For a subnet to be “public”, its route table must contain an entry pointing 0.0.0.0/0 to the IGW, and instances must have public or Elastic IP addresses. Only one IGW can be attached to a VPC at a time. Contrast with NAT Gateway: an IGW enables two-way internet communication; a NAT Gateway enables one-way outbound-only internet access from private subnets.

K

Kinesis – AWS’s real-time data streaming platform. Kinesis Data Streams ingests and stores streaming data (logs, events, IoT sensor data) for multiple independent consumers to process simultaneously, with configurable data retention (24 hours to 365 days) enabling replay. Kinesis Data Firehose is a fully managed delivery service that loads streaming data into S3, Redshift, or OpenSearch without writing consumer code. Kinesis is preferred over SQS when multiple consumers need to process the same stream independently.

KMS (Key Management Service) – AWS’s managed cryptographic key service for creating, storing, and controlling encryption keys. KMS uses FIPS 140-2 validated hardware security modules (HSMs). Customer Master Keys (CMKs) never leave KMS unencrypted. KMS implements envelope encryption: a data encryption key (DEK) encrypts your data; the CMK encrypts the DEK; only the encrypted DEK is stored alongside your data. KMS integrates with S3, EBS, RDS, Secrets Manager, and dozens of other AWS services.

L

Lambda – AWS’s serverless compute service that runs code in response to events without provisioning or managing servers. Lambda scales from zero to thousands of concurrent executions automatically. Billing is per 100ms of execution and per million invocations — zero cost when idle. Key constraints: max 15-minute execution timeout, 10 GB memory, ephemeral /tmp storage. Common triggers: API Gateway, S3 events, DynamoDB Streams, SQS, SNS, EventBridge, and CloudWatch scheduled rules.

Launch Template – The modern replacement for Launch Configurations in Auto Scaling Groups. Launch Templates define all instance configuration (AMI, instance type, key pair, security groups, user data, IAM role, storage) and support versioning, mixed instance types, and Spot/On-Demand combinations in a single ASG. Unlike Launch Configurations, templates can be reused, versioned, and shared. AWS recommends migrating all ASGs from Launch Configurations to Launch Templates.

M

Amazon EMR (Elastic MapReduce) – A managed big data platform that runs open-source frameworks — Apache Spark, Hadoop, Hive, Presto, and HBase — on resizable clusters of EC2 instances. EMR handles cluster provisioning, configuration, and tuning, allowing data engineers to focus on workloads rather than infrastructure. Common use cases include large-scale ETL, data processing for ML feature engineering, log analysis, and genomics. EMR clusters can scale dynamically and use Spot Instances for the majority of worker nodes to minimize cost.

Amazon MSK (Managed Streaming for Apache Kafka) – A fully managed Apache Kafka service that handles cluster provisioning, patching, scaling, and availability. MSK is the AWS-native choice for teams already using Kafka in on-premises environments and needing a lift-and-shift migration path — it is API-compatible with open-source Kafka. MSK is used for high-throughput, real-time data streaming pipelines where Kafka’s ecosystem (connectors, streams API, exactly-once semantics) is already a dependency. For new streaming workloads without existing Kafka investment, Kinesis Data Streams is typically simpler.

Multi-AZ – An RDS feature that creates a synchronous standby replica of your primary database in a different Availability Zone. Every write to the primary is synchronously replicated to the standby before being acknowledged. If the primary fails (hardware, OS, AZ outage), RDS automatically promotes the standby and updates the DNS endpoint — typically within 1–2 minutes. Multi-AZ is a high availability feature, not a read-scaling feature. The standby is never readable during normal operation.

N

NACL (Network Access Control List) – A stateless subnet-level firewall in a VPC. NACLs evaluate rules in ascending numerical order — the first matching rule wins. They support both allow and deny rules (unlike Security Groups which only support allow). Because NACLs are stateless, return traffic must be explicitly allowed in both inbound and outbound rules, including ephemeral ports (1024–65535). NACLs are the correct tool for blocking specific IP addresses or ranges at scale across an entire subnet.

NAT Gateway – A managed AWS service that enables instances in private subnets to initiate outbound connections to the internet while remaining unreachable from inbound internet traffic. NAT Gateways are deployed in public subnets, scale automatically up to 45 Gbps, are highly available within a single AZ, and require no management. For cross-AZ high availability, deploy one NAT Gateway per AZ and point each AZ’s private route table to its local NAT Gateway. NAT Gateways cannot be associated with Security Groups.

O

Amazon OpenSearch Service – A managed service for deploying, operating, and scaling OpenSearch (the open-source fork of Elasticsearch) clusters on AWS. OpenSearch is used for full-text search, log analytics (often replacing ELK stacks), real-time application monitoring, and as a vector database for RAG systems (using k-NN approximate nearest-neighbor search for embedding similarity). The managed service handles cluster provisioning, patching, backups, and scaling, with native integration to Kinesis Firehose, CloudWatch Logs, and AWS Glue.

Organizations (AWS) – AWS’s service for centrally managing multiple AWS accounts. Organizations enables consolidated billing (single invoice, volume discounts shared across accounts), hierarchical account grouping via Organizational Units (OUs), and Service Control Policies (SCPs). SCPs are permission boundaries applied to all users and roles within an OU or account — even the root user cannot exceed what an SCP allows. Organizations is the foundation for AWS Control Tower landing zones.

P

AWS PrivateLink – A technology that enables private connectivity between VPCs and AWS services, third-party SaaS applications, or your own services — without exposing traffic to the public internet. PrivateLink creates an Interface VPC Endpoint (an ENI with a private IP) in your subnet; traffic flows over the AWS private network backbone. PrivateLink is how VPC Interface Endpoints work, and it enables service providers to offer their services to thousands of consumer VPCs without VPC peering or complex networking.

Parameter Store – A feature of AWS Systems Manager that provides secure, hierarchical storage for configuration data and secrets. Parameters can be plain-text String values (hostnames, feature flags, port numbers) or SecureString values encrypted with a KMS key (passwords, API keys, database credentials). Parameter Store is free for standard parameters; Advanced parameters add higher throughput and larger size limits for a fee. It is commonly used to inject environment-specific configuration into Lambda functions, EC2 user data, and ECS task definitions.

Q

Amazon QuickSight – AWS’s fully managed, serverless business intelligence (BI) and data visualization service. QuickSight connects to data sources including Redshift, Athena, S3, RDS, and third-party SaaS applications, and generates interactive dashboards and visualizations accessible from any browser or mobile device without managing BI infrastructure. QuickSight Q uses natural language querying — business users can ask questions in plain English and receive instant data visualizations. SPICE (Super-fast, Parallel, In-memory Calculation Engine) caches data for millisecond-response dashboards.

R

Amazon Redshift – AWS’s fully managed, petabyte-scale data warehouse optimized for OLAP (Online Analytical Processing) queries on large datasets. Redshift uses columnar storage — storing each column separately rather than row-by-row — dramatically reducing I/O for analytical queries that only access a few columns. Massively parallel processing (MPP) distributes queries across all nodes simultaneously. Redshift Spectrum extends SQL queries to data stored directly in S3 without loading it into the warehouse. Redshift is the standard choice for business intelligence and historical analytics workloads.

RDS (Relational Database Service) – AWS’s managed relational database service supporting MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, and Amazon Aurora. AWS handles provisioning, OS patching, automated backups (1–35 day retention, point-in-time recovery), and hardware maintenance. RDS Multi-AZ provides synchronous standby replicas for automatic failover (HA). Read Replicas provide asynchronous copies for read-scaling (up to 5 replicas, requires application routing logic). Aurora is MySQL/PostgreSQL-compatible with 5x higher performance and auto-scaling storage.

Reserved Instances (RI) – An EC2 purchasing model offering up to 75% discount in exchange for a commitment to use a specific instance configuration for 1 or 3 years. Standard RIs are fixed to one instance type and AZ (or region for Regional RIs). Convertible RIs allow changing instance family, OS, and tenancy during the term at a lower discount. Savings Plans are the modern, more flexible alternative — they apply a discount to any EC2, Lambda, or Fargate usage in exchange for a $/hour commitment regardless of instance type.

Route 53 – AWS’s scalable, highly available DNS service and domain registrar. Route 53 translates domain names to IP addresses and supports multiple routing policies: Simple (single resource), Weighted (A/B testing, gradual traffic migration), Latency-based (route to lowest-latency region), Failover (active-passive with health checks), and Geolocation (route by user’s geographic location). Route 53 health checks enable DNS-level failover, automatically removing unhealthy endpoints from DNS responses.

S

AWS Secrets Manager – A managed service for storing, retrieving, and automatically rotating secrets — database credentials, API keys, OAuth tokens, and other sensitive configuration values. Secrets are encrypted at rest using KMS. The key differentiator from SSM Parameter Store is built-in automatic rotation: Secrets Manager has pre-built rotation Lambda functions for RDS, Redshift, and DocumentDB, updating both the secret value and the database password simultaneously. Applications retrieve secrets via API, eliminating hardcoded credentials.

AWS Step Functions – A serverless orchestration service for building multi-step workflows as state machines defined in Amazon States Language (JSON/YAML). Step Functions coordinate Lambda functions, ECS tasks, DynamoDB operations, SNS notifications, and any AWS service into reliable, auditable workflows. Each state transition is logged, enabling visual debugging of complex processes. Standard Workflows provide exactly-once execution with up to one-year duration; Express Workflows are for high-volume, short-duration event processing. Step Functions eliminate custom retry logic and error handling code.

S3 (Simple Storage Service) – AWS’s object storage service offering virtually unlimited capacity with 11 nines (99.999999999%) of durability. S3 stores data as objects (file + metadata) in buckets. Storage classes optimize cost for different access patterns: Standard (frequent), Standard-IA (infrequent), One Zone-IA (cheaper, single AZ), Intelligent-Tiering (auto-tiering), Glacier Instant/Flexible/Deep Archive (archival). Key features: versioning, lifecycle policies, server-side encryption (SSE-S3, SSE-KMS, SSE-C), Cross-Region Replication, Pre-signed URLs, and S3 Transfer Acceleration.

SageMaker – AWS’s fully managed, end-to-end machine learning platform covering the full ML lifecycle. Key services: Data Wrangler (data preparation, 300+ transforms), Canvas (no-code ML), Ground Truth (human labeling), JumpStart (pre-trained FM hub), Feature Store (feature repository), Clarify (bias detection + SHAP explainability), Model Monitor (drift detection in production), and Automatic Model Tuning (AMT). SageMaker integrates with Bedrock for foundation model fine-tuning.

Security Group – A stateful virtual firewall applied at the instance (ENI) level in a VPC. Security Groups evaluate all rules before deciding — there is no rule ordering. They support allow rules only (no explicit deny). Because they are stateful, response traffic for an established connection is automatically allowed regardless of outbound rules. By default, all inbound is denied and all outbound is allowed. Security Groups can reference other Security Groups as sources/destinations, enabling powerful tier-based access patterns (e.g., allow inbound only from the ALB’s Security Group).

SNS (Simple Notification Service) – AWS’s managed pub/sub messaging service. A publisher sends a single message to an SNS Topic; SNS fans it out to all subscribed endpoints simultaneously. Supported subscribers: SQS queues, Lambda functions, HTTP/HTTPS endpoints, email addresses, and SMS. The SNS → SQS fan-out pattern is the standard way to trigger multiple independent processing pipelines from a single event: one SNS publish delivers the message to many SQS queues, each consumed by a different service.

SQS (Simple Queue Service) – AWS’s fully managed message queue service for decoupling application components. Producers write messages to the queue; consumers poll and process at their own pace. SQS Standard offers virtually unlimited throughput with at-least-once delivery and best-effort ordering. SQS FIFO guarantees exactly-once processing and strict ordering at 3,000 messages/second. The visibility timeout (default 30s, max 12h) hides a message from other consumers while it is being processed. Long polling reduces cost by waiting up to 20 seconds for messages before returning an empty response.

STS (Security Token Service) – AWS’s service for requesting temporary, limited-privilege credentials. STS credentials have a configurable lifetime (15 minutes to 12 hours) and expire automatically, eliminating the need to rotate long-lived access keys. Common use cases: AssumeRole for cross-account access, AssumeRoleWithWebIdentity for web identity federation (Cognito), and AssumeRoleWithSAML for enterprise SSO. The AWS SDK automatically refreshes STS credentials when using EC2 instance profiles or ECS task roles.

Subnet – A subdivision of a VPC’s CIDR block assigned to a specific Availability Zone. A subnet cannot span multiple AZs. Public subnets have a route table entry pointing 0.0.0.0/0 to an Internet Gateway; private subnets route internet-bound traffic through a NAT Gateway. AWS reserves 5 IP addresses per subnet (network address, VPC router, DNS, future use, broadcast). A /24 subnet provides 251 usable addresses.

T

Transit Gateway – A regional network transit hub that simplifies connectivity between VPCs, AWS accounts, and on-premises networks. Instead of maintaining a full mesh of VPC peering connections (which is non-transitive and scales poorly), you attach each VPC and on-premises connection to the Transit Gateway and configure route tables centrally. Transit Gateway supports thousands of attachments and enables transitive routing, making it the standard architecture for large multi-account, multi-VPC network topologies.

Trusted Advisor – An AWS tool that evaluates your AWS environment against best practices and provides recommendations across five categories: Cost Optimization (unused resources, RI opportunities), Performance (underutilized EC2, CloudFront optimization), Security (open Security Group ports, MFA on root), Fault Tolerance (RDS Multi-AZ, EBS backups, AZ balance), and Service Limits (approaching quota limits). The full set of checks is available with Business or Enterprise Support plans.

V

VPC (Virtual Private Cloud) – A logically isolated section of the AWS Cloud where you control the networking environment: IP address space (CIDR block up to /16), subnets, route tables, gateways, and firewall rules. Each AWS account has a default VPC per region (with pre-configured public subnets and internet access). Custom VPCs start with no internet access by default. Key components: subnets, route tables, Internet Gateway, NAT Gateway, Security Groups, NACLs, and VPC Endpoints.

VPC Endpoint – A private connection between your VPC and an AWS service that keeps traffic within the Amazon network, never traversing the public internet. Interface Endpoints create an ENI with a private IP in your subnet (powered by AWS PrivateLink) — used for SQS, SNS, KMS, Secrets Manager, and hundreds of other services. Gateway Endpoints add a route table entry (free of charge) — available only for S3 and DynamoDB. VPC Endpoints are the standard answer for private connectivity requirements in exam scenarios.

VPC Peering – A private networking connection between two VPCs allowing instances to communicate using private IP addresses as if they were in the same network. Peering works within the same account, across accounts, and across regions (inter-region peering). Critical constraint: peering is non-transitive — A peered with B and B peered with C does not enable A-to-C communication. Peered VPCs cannot have overlapping CIDR blocks. For large-scale multi-VPC connectivity, AWS Transit Gateway is the scalable alternative.

W

WAF (Web Application Firewall) – An AWS service that protects web applications from common Layer 7 exploits: SQL injection, cross-site scripting (XSS), malicious bots, and other OWASP Top 10 vulnerabilities. WAF rules match on IP addresses, HTTP headers, URI strings, geographic origin, and request body content. WAF integrates with CloudFront, Application Load Balancers, API Gateway, and AppSync. AWS Managed Rule groups provide pre-built protection against known threat categories without writing custom rules.

X

AWS X-Ray – A distributed tracing service for analyzing and debugging production applications built with microservices or serverless architectures. X-Ray collects trace data from each component of a request’s journey — API Gateway, Lambda, SQS, DynamoDB, and any instrumented service — and assembles them into a service map showing request flow, latency at each hop, and error rates. X-Ray helps pinpoint performance bottlenecks (“which service is adding 800ms of latency?”) and error sources (“which downstream call is failing 5% of the time?”) in complex distributed systems.

Last updated Sep 18, 2026