Key Terms Flashcards

(156 cards)

1
Q

TCP

A

Transmission Control Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

VPC

A

Virtual Private Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

access key

A

A special set of keys linked to a specific AWS IAM user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ACID

A

The storage consistency of a relational database, based on atomicity, consistency, isolation, and durability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

active-active

A

Multi-region active-active deployment of resources across multiple regions for workloads requiring high availability and failover.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

alarm

A

A warning issued when a single metric crosses a set threshold over a defined number of time periods.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Amazon CloudFront

A

The AWS content delivery network (CDN) hosted in all edge locations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Amazon EBS

A

Amazon Elastic Block Store (EBS)
A virtual hard disk block storage device that is attached to Amazon EC2 instances.
EBS is not mountable outside the AZ. EBS volumes do not provide NFS mounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Amazon Elastic Compute Cloud (EC2)

A

A web service that provides secure, resizable compute capacity in the cloud. It enables you to launch and manage virtual servers, called Amazon Elastic Compute Cloud (EC2) instances, in the AWS cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Amazon ElastiCache

A

A distributed in-memory data store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AMI

A

Amazon Machine Image
A template of an instance’s root drive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

application programming interface (API)

A

A defined set of protocols that enables applications and services to communicate with each other.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

archive

A

An Amazon S3 Glacier grouping of compressed and encrypted files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

asymmetric key

A

One key of a public/private key pair.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Auto Scaling

A

An AWS service that adjusts compute capacity to maintain desired performance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ASG

A

Auto Scaling Group
A group of Amazon EC2 instances that is controlled (that is, scaled up, scaled down, or maintained) using the EC2 Auto Scaling service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

availability zone (AZ)

A

An insulated separate location within a region that contains at least one data center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

AWS Artifact

A

Allows AWS customers to review the compliance standards supported by AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

AWS Direct Connect

A

A dedicated private fiber connection to AWS VPCs or AWS public services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

access control list (ACL)

A

A list that enables you to control access to Amazon S3 buckets by granting read/write permissions to other AWS accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

AWS Identity and Access Management (IAM)

A

The hosted security system for the AWS cloud that controls access to AWS resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

AWS Key Management Service (KMS)

A

An AWS service that centrally manages AWS customers’ cryptographic keys and policies across AWS services that require data encryption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

AWS well-architected framework

A

A framework for designing, deploying, and operating workloads hosted at AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

block storage

A

Data records stored in blocks on a storage area network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
bucket
The storage unit for an Amazon S3 object.
26
bucket policy
A resource policy that is assigned directly to a storage entity such as an Amazon S3 bucket.
27
burst capacity
The ability of a storage unit or a compute instance to increase processing power for a short period of time.
28
burst credits
Performance credits that make it possible to burst above a defined performance baseline.
29
capacity units
A measure of Amazon DynamoDB performance in terms of either reading or writing.
30
certificate authority (CA)
A company or an entity that validates the identities of websites or domains using cryptographic public/private keys.
31
CloudWatch log group
A group that logs information in near real time.
32
codebase
The body of source code for a software program or application.
33
cold storage
Infrequently accessed storage.
34
condition
Special rule in a permission policy.
35
connection draining
The process of deregistering (removing) a registered instance from a load balancer target group.
36
cooldown period
A defined time period when no changes are allowed.
37
cost allocation tags
Tags that are used to categorize and track AWS costs displayed with monthly and hourly cost allocation reports.
38
Cost and Usage Report (CUR)
Tracks your AWS usage and provides estimated charges associated with your account for the current month.
39
data consistency
A definition of how data records are either the same or not the same due to replication.
40
data transfer
Incoming (ingress) and outgoing (egress) packet flow.
41
defense in depth (DiD)
Deployment of multiple security controls (physical, administrative, and technical) to protect a hosted workload.
42
dependencies
Cloud services, applications, servers, and various technology components that depend upon each other when providing a business solution.
43
distributed session
A user session for which user state information is held in a separate durable storage location.
44
DHCP
Dynamic Host Configuration Protocol
45
EBS
Amazon Elastic Block Storage (EBS).
46
EC2
Amazon Elastic Compute Cloud (EC2).
47
ECR
Elastic Container Registry
48
ECS
Elastic Container Service
49
EFS
Amazon Elastic File System (EFS) EFS can provide a simple NFS mount point. These mount points can be accessed and mounted from outside the VPC, either in another region, via VPN or VPC peering, or over a Direct Connect or VPN connection to an on-premises location
50
egress-only Internet gateway (EOIG)
A one-way gateway connection for EC2 instances with IPv6 addresses.
51
EKS
Elastic Kubernetes Service
52
Elastic IP (EIP) address
A static public IP address that is created and assigned to your AWS account.
53
endpoint
A location where communication is made; a private connection from a VPC to AWS services.
54
ENI
Elastic Network Interface
55
ephemeral storage
Temporary local block storage.
56
event notification
Communications about changes in the application stack.
57
externally authenticated user
A user that has authenticated outside Amazon before requesting access to AWS resources.
58
FedRAMP
Federal Risk and Authorization Management Program, establishes the security requirements for usage of cloud services for federal government agencies.
59
health check
A status check for availability.
60
high availability
A group of compute resources that continue functioning even when some of the components fail.
61
IAM group
A group of AWS IAM users.
62
IAM role
A permission policy that provides temporary access to AWS resources.
63
IAM
AWS Identity and Access Management (IAM).
64
immutable
During deployment and updates components are replaced rather than changed.
65
IOPS
Input-Output Operations per Second A performance specification that defines the rate of input and output per second when storing and retrieving data.
66
Internet gateway (IG)
An AWS connection to the Internet for a virtual private cloud (VPC).
67
KMS
AWS Key Management Service (KMS).
68
key-value
An item of data where the key is the name and the value is the data.
69
Lambda@Edge
A custom-created function to control ingress and egress Amazon CloudFront traffic.
70
launch template
A set of detailed EC2 instance installation and configuration instructions.
71
lifecycle hook
A custom action to be performed before or after an Amazon EC2 instance is added to or removed from an Auto Scaling Group.
72
lifecycle policy
A set of rules for controlling the movement of Amazon S3 objects between S3 storage classes.
73
lifecycle rules
Rules that allow customers to transition backups that are stored in warm storage to cheaper cold storage.
74
listener
A load balancer process that checks for connection requests using the defined protocols and ports.
75
load balancer capacity unit (LCU)
Defines the maximum resource consumed calculated on new connections, active, connections, bandwidth, and rule evaluations.
76
Local Zone
A single deployment of compute, storage, and select services close to a large population center.
77
metric
Data collected for an AWS CloudWatch variable.
78
mount point
A logical connection to a directory in a file system; a method to attach Amazon EFS storage to a Linux workload.
79
multi-factor authentication (MFA)
Authentication that involves multiple factors, such as something you have and something you know.
80
multipart upload
An upload in which multiple parts of a file are synchronously uploaded.
81
NACL
Network Access Control Lists A stateless subnet firewall that protects both inbound and outbound subnet traffic.
82
NAT
Network Address Translation
83
NAT gateway service
A service that provides indirect Internet access to Amazon EC2 instances that are located on private subnets.
84
Nitro
The latest AWS hypervisor, which replaces the Xen hypervisor and provides faster networking, compute, encryption, and management services.
85
NoSQL
A database that does not follow SQL rules and architecture, hence the name “no” SQL.
86
NVMe
Non-Volatile Memory Express, a standard hardware interface for SSD drives connected using PCI Express bus.
87
object storage
Data storage as a distinct object with associated metadata containing relevant information.
88
origin access identity (OAI)
A special AWS IAM user account that is provided the permission to access the files in an Amazon S3 bucket.
89
origin failover
An alternate data source location for Amazon CloudFront distributions.
90
password policy
A policy containing global password settings for AWS account IAM users.
91
peering connection
A private networking connection between two VPCs or two transit gateways.
92
Pilot light
An active/passive disaster recovery design that involves maintaining a limited set of compute and data records to be used in case of a disaster to the primary application resources. The compute records are turned off until needed, but the data records are active and are kept up-to-date.
93
primary database
The primary copy of database records.
94
queue
A redundant storage location for messages and application state data for processing.
95
read capacity unit
One strongly consistent read per second, or two eventually consistent reads per second, for items up to 4 KB in size.
96
read replica
A read-only copy of a linked primary database.
97
recovery point objective (RPO)
A metric that specifies the acceptable amount of data that can be lost within a specified period.
98
recovery time objective (RTO)
A metric that specifies the maximum length of time that a service can be down after a failure has occurred.
99
region
A set of AWS cloud resources in a geographic area of the world.
100
regional edge cache
A large throughput cache found at an edge location that provides extra cache storage.
101
regional endpoint
A device that provides HTTPS access to AWS services within a defined AWS region.
102
reliability
The reasonable expectation that an application or service is available and performs as expected.
103
Reserved instance
An Amazon EC2 instance for which you have prepaid.
104
RPO
recovery point objective (RPO).
105
RTO
recovery time objective (RTO).
106
SG
Security Group
107
scale out
To increase compute power automatically.
108
scaling policy
A policy that describes the type of scaling of compute resources to be performed.
109
security group
A stateful firewall protecting Amazon EC2 instances’ network traffic.
110
Server Message Block (SMB)
A network protocol used by Windows systems on the same network to store files.
111
serverless
A type of computing in which compute servers and integrated services are fully managed by AWS.
112
server-side encryption (SSE)
Encryption of data records at rest by an application or a service.
113
service-level agreement (SLA)
A commitment between a cloud service provider and a customer indicating the minimum level of service to be maintained.
114
service-level indicator (SLI)
Indicates the quality of service an end user is receiving at a given time. SLIs are measured as a level of performance.
115
service-level objective (SLO)
An agreement defined as part of each service-level agreement. Objectives could be uptime or response time.
116
service quota
A defined limit for AWS services created for AWS accounts.
117
simple scaling
Scaling instances up or down based on a single AWS CloudWatch metric.
118
SLA
service-level agreement (SLA).
119
snapshot
A point-in-time incremental backup of an EBS volume.
120
Snow device
A variety of network-attached storage devices that can be used to transfer and receive data records to and from Amazon S3 storage.
121
standby database
A synchronized copy of a primary database that is available in the event of a failure.
122
stateful
Refers to a service that requires knowledge of all internal functions.
123
stateless
Refers to a self-contained redundant service that has no knowledge of its place in the application stack.
124
step scaling
Scaling up or down by percentages.
125
sticky session
A user session for which communication is maintained with the initial application server for the length of the session. It ensures that a client is bound to an individual backend instance.
126
Structured Query Language (SQL)
The de facto programming language used in relational databases.
127
subnet
A defined IP address range hosted within a VPC.
128
symmetric key
A key that can both lock and unlock.
129
T instance
An instance provided with a baseline of compute performance.
130
table
A virtual structure in which Amazon DynamoDB stores items and attributes.
131
target group
A group of registered instances that receives specific traffic from a load balancer.
132
task definition
A blueprint that describes how a Docker container should launch.
133
Throughput Optimized
An EBS hard disk drive (HDD) volume option that provides sustained throughput of 500 Mb/s.
134
tiered pricing
The more you use the less you are charged.
135
time to live (TTL)
A value that determines the storage time of an Amazon CloudFront cache object.
136
uptime
the percentage of time that a website is able to function during the course of a calendar year.
137
user state
Data that identifies an end user and the established session between the end user and a hosted application.
138
versioning
A process in which multiple copies of Amazon S3 objects, including the original object, are saved.
139
virtual private cloud (VPC)
A logically isolated virtual network in the AWS cloud.
140
virtual private gateway (VPG)
The AWS side of a VPN connection to a VPC.
141
warm standby
An active/passive disaster recovery design that maintains a limited set of compute and data records that are both on and functioning. When the primary application resources fail, the warm standby resources are resized to production values.
142
write capacity unit (WCU)
One write per second for items up to 1 KB in size.
143
write-once/read-many (WORM)
A security policy that can be deployed on an Amazon S3 bucket or in S3 Glacier storage. The policy indicates that the contents can be read many times but are restricted from any further writes once the policy is enacted.
144
zonal
Refers to an availability zone location.
145
Amazon Timestream
is a fast and scalable serverless time series database designed to store and analyze trillions of events per day.
146
AWS Backup
allowing you to schedule, copy, tag, and life cycle your DynamoDB on-demand backups automatically.
147
VPC peering
is to connect two VPCs with low management overhead. VPC peering is perfect for simple VPC connectivity, such as connecting two VPCs. VPC peering works between AWS accounts and regions. Beyond creating the peering relationship and configuring the routing tables, there is no management with this solution.
148
S3 Access Points
were created to simplify the use of varying access permissions with the same S3 bucket. You can create a separate S3 access for each group or service that requires access to S3 objects, with each point having its own Access Points policy.
149
AWS Transfer Family
includes FTP, SFTP, and FTPS. Using this service would require no changes for companies accessing the shared data.
150
AWS Config
can record all changes and alert through AWS Config rules and inventory. AWS Config can also provide relationship details across account resources. AWS Change Control is a made-up service name. Amazon CloudWatch is not designed to provide inventory, relationships, and record changes. AWS CloudTrail will log the API calls but cannot provide inventory
151
AWS Cost Explorer
Visualize and manage AWS costs and usage over a daily or monthly granularity.
152
TLD
Top Level Domain
153
Service Quotas
utility is used to request a quota increase through AWS support.
154
Elastic Fabric Adapter
provides the best networking performance, much faster than an elastic network interface.
155
Compute Savings Plan
provides deep discounts for both EC2 instances and containers managed by AWS Fargate.
156
DynamoDB on-demand
offers simple pay-per-request pricing for read and write requests so that you only pay for what you use, making it easy to balance costs and performance. For tables using on-demand mode, DynamoDB instantly accommodates customers’ workloads as they ramp up or down to any previously observed traffic level.