AWS Certified Cloud Practitioner
Today I passed AWS Certified Cloud Practitioner (CLF-C01). I appeared for this examination just to get started. Plan is to appear for next set of examination in near future. I would like to share my experience with all.
I mostly referred to Stephane Maarek's presentation material and practice examinations. Here is the summary of his course content
- Region, Availability Zones, Edge Location
- IAM Section - Users, Groups, Policies, Permissions, MFA, MFA Options, Access Keys, Options to access AWS
- EC2 Section - EC2 Instance Types, Security Groups, SSH, EC2 Instance Purchasing option (This section is favourite in examination)
- EC2 Instance Storage Section - EBS Volume, EBS Snapshots, AMI Overview, EC2 Instance Store, EFS, EBS Vs EFS, EFS infrequent Access, Amazon EFX
- Elastic Load Balancing & Auto Scaling Group - Scalability and high Availability, difference between Horizontal and Vertical scalability, Scale in / Scale Out / Scale Up, Scalability Vs Elasticity, four types of load balancers, Scaling Strategies
- Amazon S3 - Use cases for S3 (This is important since though it is primarily perceived as storage service it has various use cases related to Application hosting / hosting static website. You can expect some questions related to use cases wherein S3 is used with other services), S3 Buckets, Objects, S3 Security, Bucket Policies (When to use Bucket Policy versus IAM Roles), Hosting Public web site, S3 Versioning and its benefits, Replication CRR - SRR, Various Storage classes (You will find multiple questions on this topic in the examination, though you are not expected to know the actual availability . durability numbers for each S3 Storage class you are expected to know the scenario where each storage class presents best use case, S3 Encryption
- AWS Snow Family - Snow Cone, Snowball Edge and Snow Mobile, the data Migration and Edge computing use cases for them, Edge Computing, AWS Ops Hub, Hybrid Cloud for storage, AWS Storage Gateway
- AWS Stores data in Block, file and Object native format. One needs to be clear which storage device stores data in which specific format
- Databases in AWS - Relational / No-SQL Databases, AWS RDS, Amazon Aurora, RDS Deployments - Read Replicas, Multi AZ , Multi Region (And the objectives we achieve with each one of these options), Amazon ElastiCache, DynamoDB, DynamoDB Accelerator - DAX, Global Tables, RedShift, Amazon EMR, Athena, Amazon QuickSight, Amazon Neptune, Amazon QLDB, AWS Glue, Database Migration Service. This is where for each of these services we need to be clear about the use case where they are best suited. You will also find that some of these services may overlap in some way, so if both options appear as answer to a question then read question with full concentration for a specific keyword
- Other Compute Section - Docker Concept, ECS, Fargate, ECR, AWS Lambda, Pricing (Parameters affecting the pricing), Amazon API Gateway, AWS Batch, Amazon LightSail
- Deploying and Managing Infrastructure at Scale - CloudFormation, AWS CDK, Amazon Elastic Beanstalk, Amazon CodeDeploy, AWS CodeCommit, AWS CodeBuild, AWS CodePipeline, AWS CodeArtifact, AWS Cloud9, AWS SSM, AWS OpsWorks. Here you need to know the exact difference between each one of these services since there is some overlap. Remember the sequence
- CodeCommit - CodeBuild - CodeDeploy - Elastic Beanstalk
- Global Services - We need to know which services are Global versus which are regional in nature. Also for each one of these services, what are AWS Responsibilities versus Customer Responsibilities.
- AWS Route 53 - Routing Policies, Amazon CloudFront, S3 Transfer Acceleration, AWS Global Accelerator. Again you will find multiple services here.
- Cloud integration Section - Amazon SQS, Amazon Kinesis, Amazon SNS, Amazon MQ. Some of these are used for decoupling between application tiers
- Cloud Monitoring Section - Amazon CloudWatch, Amazon EventBridge, AWS CloudTrail, AWS X RAY, CodeGuru, AWS Health Dashboard (Overall / For your personal account
- VPC - IP Addresses in AWS, VPC and Subnet, Internet and NAT Gateways, Network ACL and Security Groups, VPC Peering, VPC EndPoints - Gateway (S3 and Dynamo DB) and Interface (Others), AWS PrivateLink, Site to Site VPN, Direct Connect, Transit Gateway (You will find few questions related to these use case)
- Security Section - AWS Shield, AWS Shield Advanced, AWS WAF, CloudFront and Route 53 (Be clear which Layer each one of these protect, Which are used for DDOs Attack, Penetration Testing - Whose responsibility it is), AWS KMS, CloudHSM, Types of Customer Master Keys, ACM, AWS Secrets Manager, AWS Artifact, Amazon GuardDuty, Amazon Inspector, AWS Config, Amazon Macie, AWS Security Hub, Amazon Detective, AWS Abuse, IAM Access Analyzer,
- Machine Learning Section - Amazon Transcribe, Amazon Polly, Amazon Translate, Amazon Lex and Connect, Amazon Comprehend, Amazon SageMaker, Amazon Forecast, Amazon Kendra, Amazon Personalize, Amazon Textract
- Account Management, Billing - AWS Organization, Service Control Policies, Consolidated Billing, AWS Control Tower (runs on top of organization). Pricing Models in AWS, AWS Compute Optimizer, AWS Pricing Calculator, AWS Billing Dashboard, Cost Allocation Tags, Cost and Usage Report, Cost Explorer, AWS Budgets and when it creates alerts, AWS Cost anomaly Detection, Trusted Advisor and its recommendation in 5 categories
- AWS Support Plans - Basic, Developer, Business, Enterprise On-Ramp and Enterprise - You will see minimum 2-3 Questions on use case for each plans
- Advanced Identity section - AWS STS, Amazon Cognito, Microsoft AD, IAM Identity Center
- Other AWS Services - Amazon Workspaces, Amazon WorkStream 2.0, AWS IoT Core, Amazon Transcoder, AWS Amplify, AWS Device Farm, AWS Migration Service, AWS Migration Evaluator, AWS Fault Injection Simulator, AWS Step Functions, AWS Ground Station, Amazon Pinpoint
- Amazon Well Architected Framework - General Guiding Principles, 6 Pillars (Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability)
- CAF Perspective -Business, People and Governance
- AWS Professional Network and Partner Network
- Study material has around 25 key topics. He has summary section at the end of each topic. You need to know all points he has mentioned at the end of the each topic.
- Once you have gone through study material at least twice, start solving his practice papers. They are much tougher than actual examination. But once you take these exams, review solutions option become available to you and it is immensely helpful. It explains why a particular option is correct. The various EC2 Instance Purchasing options, S3 Storage Options, Different Security Services, Costing Services - some of these have overlap. So these solutions / justification helps you to distinguish between them clearly.
- The actual examination is does not go to deep level. So you need to understand one to two lines of justification for each of the services / features listed in each bullet and you should be good.
- On the day prior to examination just refresh summary pages of Stephane's study material with clear understanding of their purpose along with your notes. Read all six question papers with their answers and you should be good.
Comments
Post a Comment