[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"lesson-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-multi-account-provisioning-en":3,"cheat-sheet---en":3,"domain-info---en":3,"prev-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-multi-account-provisioning-en":3,"next-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-multi-account-provisioning-en":3,"topic-info-aws-certified-cloudops-engineer-associate-deployment-provisioning-automation-multi-account-provisioning-en":4,"course-lesson-metadata-aws-certified-cloudops-engineer-associate-en":70},null,{"meta":5,"body":8},{"title":6,"description":7},"Multi-Account and Multi-Region Provisioning","StackSets across accounts and Regions, resource sharing with AWS RAM, and governed self-service provisioning with Service Catalog and Control Tower.",{"type":9,"value":10,"toc":63},"minimark",[11,15,20,53,57,60],[12,13,14],"p",{},"Everything in the previous topic assumed one account. Real organizations run dozens, and the same template, the same transit gateway, and the same set of approved building blocks have to reach all of them without a person clicking through each one. This topic covers the three mechanisms AWS provides for that, and the boundary between them is where most of the exam questions live.",[16,17,19],"h2",{"id":18},"what-this-topic-covers","What This Topic Covers",[21,22,23,27,30,33,41,44,47,50],"ul",{},[24,25,26],"li",{},"CloudFormation StackSets: stack sets, stack instances, and stacks, and why an instance can exist without a stack",[24,28,29],{},"Self-managed versus service-managed permissions, the two named IAM roles, trusted access with AWS Organizations, and delegated administrators",[24,31,32],{},"Deployment targets, OU targeting with account filters, concurrency, failure tolerance per Region, and Region deployment order",[24,34,35,36,40],{},"Stack set drift detection, the statuses that need action, and the operation that reports ",[37,38,39],"code",{},"SUCCEEDED"," while stacks failed",[24,42,43],{},"AWS RAM: resource shares, managed permissions, invitations versus organization sharing, and which resource types can leave the organization",[24,45,46],{},"Shared VPC subnets: what the owner controls, what a participant can build, cross-account security group references, and why Availability Zone IDs matter",[24,48,49],{},"Service Catalog: products, portfolios, launch roles, and the five constraint types, plus shared versus copied catalogs",[24,51,52],{},"AWS Control Tower: the landing zone structure, Log Archive and Audit accounts, preventive, detective, and proactive controls, Account Factory, and drift",[16,54,56],{"id":55},"why-it-matters","Why It Matters",[12,58,59],{},"Skill 3.1.4 of the SOA-C03 exam guide names AWS RAM and CloudFormation StackSets directly, and the surrounding governance services show up throughout the security and networking domains as well. Questions here rarely ask what a service is. They describe a rollout that reached 37 of 40 accounts, a subnet a participant account cannot route out of, or a developer who needs to launch a database without database permissions, and ask for the mechanism or the fix.",[12,61,62],{},"The job pressure is identical. Multi-account is where small mistakes multiply: a baseline that quietly skipped the management account, a resource share that stopped working after an OU reorganization, a launch role scoped so wide that self-service became a permissions bypass. Knowing which mechanism owns which problem is what keeps a growing account structure manageable instead of becoming forty separate environments that happen to share a bill.",{"title":64,"searchDepth":65,"depth":65,"links":66},"",3,[67,69],{"id":18,"depth":68,"text":19},2,{"id":55,"depth":68,"text":56},{"lessons":71,"cheatSheets":406,"mockTestsAvailable":80},[72,77,82,86,90,94,98,102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,226,230,234,238,242,246,250,254,258,262,266,270,274,278,282,286,290,294,298,302,306,310,314,318,322,326,330,334,338,342,346,350,354,358,362,366,370,374,378,382,386,390,394,398,402],{"path":73,"title":74,"isFree":75,"description":76},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/01-cloudwatch-metrics-fundamentals","CloudWatch Metrics Fundamentals",true,"How CloudWatch identifies, stores, and ages metric data: namespaces, dimensions, resolution, statistics, and the retention rollup that decides what you can still query six months from now.",{"path":78,"title":79,"isFree":80,"description":81},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/02-cloudwatch-logs-and-insights","CloudWatch Logs and Logs Insights",false,"Log groups, retention, and the three ways log data leaves CloudWatch Logs: metric filters that create alarms, subscription filters that stream in near real time, and Logs Insights queries that answer one-off questions.",{"path":83,"title":84,"isFree":80,"description":85},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/03-cloudwatch-agent-deployment","Deploying the CloudWatch Agent","Why memory and disk metrics never appear on their own, and how to install, configure, and troubleshoot the unified CloudWatch agent across an EC2 fleet using Systems Manager and Parameter Store.",{"path":87,"title":88,"isFree":80,"description":89},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/04-cloudtrail-for-operations","CloudTrail for Operations","The audit trail of who called which API: event history versus trails, the four event types and what each costs, organization trails, CloudTrail Lake, and wiring a trail into CloudWatch Logs so you can alarm on account activity.",{"path":91,"title":92,"isFree":80,"description":93},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/05-container-insights-and-prometheus","Container Insights, Prometheus, and Grafana","Getting container-level telemetry out of ECS and EKS: how Container Insights collects performance log events, what enhanced observability adds, and when to send metrics to Amazon Managed Service for Prometheus and visualize them in Amazon Managed Grafana instead.",{"path":95,"title":96,"isFree":80,"description":97},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/01-cloudwatch-metrics-and-logs/06-monitoring-serverless-and-ai-workloads","Monitoring Serverless and AI Workloads","Telemetry when there is no server to log into: Lambda metrics and the throttle-versus-error distinction, Lambda Insights and X-Ray, API Gateway latency breakdowns, and monitoring Amazon Bedrock with CloudWatch metrics and model invocation logging.",{"path":99,"title":100,"isFree":75,"description":101},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/02-alarms-dashboards-and-notifications/01-cloudwatch-alarms-fundamentals","CloudWatch Alarms Fundamentals","How a CloudWatch alarm decides to change state: period, evaluation periods, datapoints to alarm, the evaluation range it quietly reaches back into, and the missing-data setting that decides whether silence means healthy or broken.",{"path":103,"title":104,"isFree":80,"description":105},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/02-alarms-dashboards-and-notifications/02-sns-for-operational-alerting","SNS for Operational Alerting","How an alarm notification actually reaches a human: SNS topics and subscriptions, the confirmation step that silently breaks alerting, filter policies, retry behavior per protocol, dead-letter queues, and the KMS permission that stops encrypted topics from receiving alarms.",{"path":107,"title":108,"isFree":80,"description":109},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/02-alarms-dashboards-and-notifications/03-composite-alarms-and-alarm-actions","Composite Alarms and Alarm Actions","Turn a wall of individual alarms into one signal with composite alarm rule expressions and action suppression, and make alarms fix things instead of just reporting them with EC2, Auto Scaling, Lambda, and Systems Manager actions.",{"path":111,"title":112,"isFree":80,"description":113},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/02-alarms-dashboards-and-notifications/04-cloudwatch-dashboards","CloudWatch Dashboards","Build the view an engineer opens at 03:00: custom and automatic dashboards, the widget types worth knowing, cross-account and cross-Region graphs, dashboards as JSON in source control, and what sharing a dashboard really grants.",{"path":115,"title":116,"isFree":75,"description":117},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/03-event-driven-remediation/01-eventbridge-fundamentals","EventBridge Fundamentals","Learn how EventBridge routes events: the event envelope, default and custom buses, the exact-match rules of event pattern evaluation, target permissions, and input transformation.",{"path":119,"title":120,"isFree":80,"description":121},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/03-event-driven-remediation/02-eventbridge-pipes-and-troubleshooting","EventBridge Pipes and Troubleshooting","Build point-to-point integrations with EventBridge Pipes using filtering and enrichment, then diagnose event delivery failures with retry policies, dead-letter queues, pipe logs, and the AWS/Events metrics.",{"path":123,"title":124,"isFree":80,"description":125},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/03-event-driven-remediation/03-systems-manager-automation-runbooks","Systems Manager Automation Runbooks","Write and run Systems Manager Automation runbooks: the action vocabulary, step properties that make a repair safe to run unattended, the two-role permission chain, approvals, and rate control across a fleet.",{"path":127,"title":128,"isFree":80,"description":129},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/03-event-driven-remediation/04-automated-remediation-patterns","Automated Remediation Patterns","Assemble detection and repair into working self-healing designs: alarm actions, event-driven runbooks, AWS Config remediation, scheduled sweeps, the guardrails each one needs, and where AWS DevOps Agent and Kiro fit.",{"path":131,"title":132,"isFree":75,"description":133},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/04-compute-and-storage-performance/01-ec2-right-sizing-and-compute-optimizer","EC2 Right-Sizing and Compute Optimizer","Find the instances that are the wrong size using Compute Optimizer findings, the metrics CloudWatch cannot see on its own, and the credit model that makes T instances behave unlike every other family.",{"path":135,"title":136,"isFree":80,"description":137},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/04-compute-and-storage-performance/02-ec2-placement-and-network-performance","EC2 Placement Groups and Network Performance","Why a 25 Gbps instance moves 5 Gbps on one connection, how network I/O credits and ENA allowance counters explain throttling that CloudWatch hides, and which placement group strategy each workload needs.",{"path":139,"title":140,"isFree":80,"description":141},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/04-compute-and-storage-performance/03-ebs-performance-optimization","EBS Performance Optimization","Pick the right EBS volume type, read the credit and exceeded-check metrics that explain slow storage, and tell the difference between a volume that is throttled and an instance that is.",{"path":143,"title":144,"isFree":80,"description":145},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/04-compute-and-storage-performance/04-s3-performance-and-data-transfer","S3 Performance and Data Transfer","Read S3 request rates and 503 Slow Down responses correctly, speed up transfers with prefixes, byte-range fetches, and multipart uploads, and choose between Transfer Acceleration, DataSync, and Snow devices.",{"path":147,"title":148,"isFree":80,"description":149},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/04-compute-and-storage-performance/05-efs-and-fsx-shared-storage","EFS and FSx Shared Storage","Choose and tune shared file storage on AWS: EFS performance and throughput modes, lifecycle policies, the four FSx file systems, and the protocol question that decides between them.",{"path":151,"title":152,"isFree":75,"description":153},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/05-rds-performance/01-rds-monitoring-and-performance-insights","RDS Monitoring and Performance Insights","Tell apart the 3 layers of RDS monitoring by where their data comes from, and read DB load in average active sessions to find which query and which wait event is actually holding the database back.",{"path":155,"title":156,"isFree":80,"description":157},"/courses/aws-certified-cloudops-engineer-associate/en/domains/01-monitoring-logging-performance/05-rds-performance/02-rds-proxy-and-performance-tuning","RDS Proxy and Performance Tuning","Fix connection exhaustion with RDS Proxy, recognize the session pinning that quietly cancels its benefit, and pick the right tuning lever when the bottleneck is the instance, the storage, or the queries instead.",{"path":159,"title":160,"isFree":75,"description":161},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/01-load-balancing-and-health-checks/01-elastic-load-balancing-fundamentals","Elastic Load Balancing Fundamentals","What a load balancer actually is in AWS, how ALB, NLB, and Gateway Load Balancer differ in the routing decision each can make, and the target group settings that decide how traffic reaches your instances.",{"path":163,"title":164,"isFree":80,"description":165},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/01-load-balancing-and-health-checks/02-troubleshooting-elb-and-target-health","Troubleshooting ELB and Target Health","How to read a target health reason code, the ordered list of causes behind an unhealthy target, the fail-open behavior that hides an outage, and the difference between an ELB error code and a target error code.",{"path":167,"title":168,"isFree":80,"description":169},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/01-load-balancing-and-health-checks/03-route53-health-checks-and-failover","Route 53 Health Checks and DNS Failover","How Route 53 decides an endpoint is healthy, why alias records use Evaluate Target Health instead of a health check, and how failover routing and zonal shift move traffic away from a failure the load balancer cannot see.",{"path":171,"title":172,"isFree":75,"description":173},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/02-scaling-compute-workloads/01-ec2-auto-scaling-groups","EC2 Auto Scaling Groups","How an Auto Scaling group holds a fleet at the size you asked for: the three capacity numbers, the health checks that decide what gets replaced, zonal balance, and the rules that pick which instance dies on scale in.",{"path":175,"title":176,"isFree":80,"description":177},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/02-scaling-compute-workloads/02-scaling-policies-in-depth","Scaling Policies in Depth","Target tracking, step, simple, scheduled, and predictive scaling: what each one decides, the cooldown and warmup timers that hold them back, and how AWS resolves several policies pointing at the same group.",{"path":179,"title":180,"isFree":80,"description":181},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/02-scaling-compute-workloads/03-asg-lifecycle-and-instance-refresh","ASG Lifecycle Hooks and Instance Refresh","The states an instance passes through inside an Auto Scaling group, the lifecycle hooks that pause it at launch and termination, warm pools for slow boots, and how instance refresh rolls a new AMI across the fleet without dropping capacity.",{"path":183,"title":184,"isFree":80,"description":185},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/02-scaling-compute-workloads/04-scaling-containers-and-serverless","Scaling Containers and Serverless","What changes when the unit of capacity is a task, a pod, or a request: Application Auto Scaling for ECS services, the second scaling layer under EC2-backed clusters, EKS node scaling, and Lambda concurrency.",{"path":187,"title":188,"isFree":75,"description":189},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/03-caching-and-database-scaling/01-caching-with-cloudfront-and-elasticache","Caching with CloudFront and ElastiCache","Where to put a cache so it removes real load: the CloudFront cache key and TTL rules that decide what the edge keeps, and the lazy loading, write-through, and TTL strategies that decide what ElastiCache holds in front of your database.",{"path":191,"title":192,"isFree":80,"description":193},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/03-caching-and-database-scaling/02-rds-and-aurora-scaling","Scaling RDS and Aurora","Read replicas, storage autoscaling, and RDS Proxy on Amazon RDS, and the shared cluster volume that changes the rules for Aurora: reader endpoints, Aurora Auto Scaling, and Serverless capacity.",{"path":195,"title":196,"isFree":80,"description":197},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/03-caching-and-database-scaling/03-dynamodb-scaling-and-dax","DynamoDB Scaling and DAX","Capacity units and the arithmetic behind them, on-demand versus provisioned with auto scaling, why a table throttles while it still has headroom, and what DAX caches and what it quietly refuses to.",{"path":199,"title":200,"isFree":75,"description":201},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/04-backup-restore-and-disaster-recovery/01-multi-az-and-fault-tolerant-architectures","Multi-AZ and Fault-Tolerant Architectures","What an Availability Zone actually is, which AWS resources live inside one and which span the Region, and how to build a compute and data tier that keeps serving traffic when an entire AZ goes away.",{"path":203,"title":204,"isFree":80,"description":205},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/04-backup-restore-and-disaster-recovery/02-aws-backup-and-snapshots","AWS Backup and Snapshots","How EBS snapshots actually store data incrementally, when to automate them with Amazon Data Lifecycle Manager versus AWS Backup, and how backup plans, vaults, cross-Region and cross-account copies, and Vault Lock combine into a policy you can prove.",{"path":207,"title":208,"isFree":80,"description":209},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/04-backup-restore-and-disaster-recovery/03-database-restore-strategies","Database Restore Strategies","RDS automated backups and point-in-time recovery, manual snapshots and cross-Region copies, Aurora continuous backups, cloning and Backtrack, and DynamoDB PITR, including the settings every restore silently leaves behind.",{"path":211,"title":212,"isFree":80,"description":213},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/04-backup-restore-and-disaster-recovery/04-storage-versioning-and-replication","Storage Versioning and Replication","S3 versioning states, delete markers, and the two very different deletes; Object Lock for immutability; and S3 Replication including what it silently refuses to copy and how Batch Replication and Replication Time Control close those gaps.",{"path":215,"title":216,"isFree":80,"description":217},"/courses/aws-certified-cloudops-engineer-associate/en/domains/02-reliability-business-continuity/04-backup-restore-and-disaster-recovery/05-disaster-recovery-strategies","Disaster Recovery Strategies","RTO and RPO as the numbers that pick the architecture, the four AWS disaster recovery strategies from backup and restore to multi-site active/active, the data plane rule that decides how you fail over, and why every strategy still needs backups.",{"path":219,"title":220,"isFree":75,"description":221},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/01-machine-and-container-images/01-amis-and-ec2-image-builder","AMIs and EC2 Image Builder","What an AMI actually contains, where the line between baking and bootstrapping sits, how an EC2 Image Builder pipeline turns a base image into a tested and distributed golden AMI, and the difference between deprecating, disabling, and deregistering an image.",{"path":223,"title":224,"isFree":80,"description":225},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/01-machine-and-container-images/02-container-images-and-ecr","Container Images and Amazon ECR","How container images are layered and addressed by digest, how ECR authentication and its three permission layers work, and how tag immutability, basic and enhanced scanning, lifecycle policies, replication, and pull through cache keep a registry usable in production.",{"path":227,"title":228,"isFree":75,"description":229},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/02-infrastructure-as-code/01-cloudformation-fundamentals","CloudFormation Fundamentals","How a CloudFormation template describes infrastructure: the template sections, parameters with real guardrails, intrinsic functions, the dependency graph CloudFormation builds for you, and the resource attributes that decide what survives a delete.",{"path":231,"title":232,"isFree":80,"description":233},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/02-infrastructure-as-code/02-cloudformation-stack-operations","CloudFormation Stack Operations","Changing a running stack without breaking it: the three update behaviors, change sets, stack policies, signals and rolling updates, rollback options and triggers, drift detection, nested stacks, and importing existing resources.",{"path":235,"title":236,"isFree":80,"description":237},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/02-infrastructure-as-code/03-troubleshooting-cloudformation-deployments","Troubleshooting CloudFormation Deployments","A method for failed deployments: find the first failure in the stack events, read the status reason, and match it to its class - permissions, capacity and subnet sizing, missing signals, resources that never stabilize, and rollbacks that themselves fail.",{"path":239,"title":240,"isFree":80,"description":241},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/02-infrastructure-as-code/04-aws-cdk-essentials","AWS CDK Essentials","How the AWS CDK turns code into CloudFormation: the three construct levels, apps and stacks, bootstrapping, the synth-diff-deploy workflow, and what changes for the operator once a stack is generated rather than written.",{"path":243,"title":244,"isFree":80,"description":245},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/02-infrastructure-as-code/05-terraform-and-git-for-cloudops","Terraform and Git for CloudOps","The third-party half of infrastructure as code: how Terraform state works and why it needs a locked remote backend on AWS, the write-plan-apply workflow, how Terraform differs from CloudFormation operationally, and the Git workflow that makes any of it safe in a team.",{"path":247,"title":248,"isFree":75,"description":249},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/03-multi-account-provisioning/01-cloudformation-stacksets","CloudFormation StackSets","Deploying one template to many accounts and Regions from a single operation: stack sets and stack instances, self-managed versus service-managed permissions, deployment targets and account filters, concurrency and failure tolerance, drift, and the failures that hide behind a SUCCEEDED status.",{"path":251,"title":252,"isFree":80,"description":253},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/03-multi-account-provisioning/02-resource-sharing-with-aws-ram","Resource Sharing with AWS RAM","Sharing one resource with many accounts instead of duplicating it: resource shares and managed permissions, the two-layer permission model, invitations and organization sharing, and the ownership split inside a shared VPC subnet.",{"path":255,"title":256,"isFree":80,"description":257},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/03-multi-account-provisioning/03-service-catalog-and-control-tower","Service Catalog and Control Tower","Letting teams provision for themselves without handing them the keys: Service Catalog portfolios, products, and constraints, shared versus copied catalogs, and the Control Tower landing zone with its OUs, shared accounts, controls, and drift.",{"path":259,"title":260,"isFree":75,"description":261},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/04-deployment-strategies/01-deployment-strategies-overview","Choosing a Deployment Strategy","The five deployment strategies the exam expects you to tell apart: all at once, rolling, immutable, blue/green, and canary or linear traffic shifting. What each one costs in capacity, in time, and in exposed users, and why the data tier is the part none of them fix.",{"path":263,"title":264,"isFree":80,"description":265},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/04-deployment-strategies/02-deploying-updates-to-live-workloads","Deploying Updates to Live Workloads","The AWS settings that produce each deployment strategy: Auto Scaling instance refresh percentages and rollback, the three CloudFormation update policies for an Auto Scaling group, ECS rolling and blue/green deployments with bake time and circuit breakers, Lambda weighted aliases, and managed RDS blue/green switchover.",{"path":267,"title":268,"isFree":75,"description":269},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/05-operational-automation/01-systems-manager-fleet-management","Systems Manager Fleet Management","Manage a fleet through Systems Manager instead of SSH: the three conditions that make a node manageable, instance profiles versus Default Host Management Configuration, Session Manager, Run Command targeting and rate control, Fleet Manager and Inventory, and the diagnostic order for a node that never appears.",{"path":271,"title":272,"isFree":80,"description":273},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/05-operational-automation/02-patch-and-state-management","Patch and State Management","Keep a fleet patched and stop it drifting: Scan versus Install, patch baseline approval rules and their 7-day default, how patch groups pick a baseline, the compliance states and the reboot option that produces them, maintenance windows with duration and cutoff, patch policies, and State Manager associations.",{"path":275,"title":276,"isFree":80,"description":277},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/05-operational-automation/03-parameter-store-for-configuration","Parameter Store for Configuration","Centralize configuration in Parameter Store: the three parameter types and SecureString encryption, hierarchies and the IAM path trap, the standard and advanced tiers, parameter policies, versions and labels, the 40 TPS throughput ceiling that breaks scale-out events, public parameters, CloudFormation dynamic references, and where Secrets Manager takes over.",{"path":279,"title":280,"isFree":80,"description":281},"/courses/aws-certified-cloudops-engineer-associate/en/domains/03-deployment-provisioning-automation/05-operational-automation/04-event-driven-operations-automation","Event-Driven Operations Automation","Wire routine operational work to run itself: S3 Event Notifications and their delivery guarantees, direct destinations versus EventBridge, EventBridge Scheduler for time-based work, choosing where a schedule lives among four AWS mechanisms, Lambda versus an Automation runbook, and Change Calendar as a guardrail.",{"path":283,"title":284,"isFree":75,"description":285},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/01-iam-and-access-management/01-iam-policies-and-roles","IAM Policies and Roles","The building blocks of every authorization decision on AWS: principals and identities, the elements of a JSON policy, identity-based versus resource-based policies, managed versus inline, and why a role carries two policies instead of one.",{"path":287,"title":288,"isFree":80,"description":289},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/01-iam-and-access-management/02-iam-policy-evaluation-and-conditions","Policy Evaluation and Conditions","How AWS turns 6 competing policies into one allow or deny: the enforcement order, which policy types add permissions and which only subtract, permissions boundaries, and the condition operators and global condition keys that decide the close calls.",{"path":291,"title":292,"isFree":80,"description":293},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/01-iam-and-access-management/03-mfa-federation-and-account-security","MFA, Federation, and Account Security","Hardening the credentials themselves: the root user and the tasks that still require it, password policy limits, the MFA types AWS supports and how to enforce them, access key hygiene, and the federation options that let you stop creating IAM users at all.",{"path":295,"title":296,"isFree":80,"description":297},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/01-iam-and-access-management/04-troubleshooting-access-with-iam-tools","Troubleshooting Access with IAM Tools","Turning an AccessDenied into an answer: reading what the error message already tells you, testing with the policy simulator, and using IAM Access Analyzer, last accessed information, the credential report, and CloudTrail to find both the permissions you are missing and the ones you should never have granted.",{"path":299,"title":300,"isFree":75,"description":301},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/02-multi-account-governance/01-organizations-and-service-control-policies","AWS Organizations and Service Control Policies","How an organization gives you a control point above the account: roots, OUs, and the management account, plus the SCP inheritance rules that decide whether a permission survives the path from the root down to the account.",{"path":303,"title":304,"isFree":80,"description":305},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/02-multi-account-governance/02-iam-identity-center","IAM Identity Center","How one identity source and a handful of permission sets replace per-account IAM users across an organization: instance types, assignments, the IAM roles Identity Center creates for you, session durations, and attribute-based access control.",{"path":307,"title":308,"isFree":80,"description":309},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/02-multi-account-governance/03-trusted-advisor-remediation","Trusted Advisor and Security Check Remediation","How to read Trusted Advisor security findings and act on them: what each check actually detects, which checks a Basic Support account gets, the refresh rules, and how to automate the response with EventBridge, Systems Manager, and organizational view.",{"path":311,"title":312,"isFree":80,"description":313},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/02-multi-account-governance/04-aws-config-and-conformance-packs","AWS Config and Conformance Packs","How to turn a compliance requirement into a continuously evaluated control: the configuration recorder and configuration items, rule triggers and evaluation modes, automatic remediation through Systems Manager, and packaging rules for an entire organization.",{"path":315,"title":316,"isFree":75,"description":317},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/03-data-protection/01-data-classification-and-macie","Data Classification and Amazon Macie","How to build a data classification scheme that survives contact with a real S3 estate: tiers with handling rules attached, tags as the enforcement handle, and Amazon Macie to find the sensitive data your tags did not declare.",{"path":319,"title":320,"isFree":80,"description":321},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/03-data-protection/02-encryption-at-rest-with-kms","Encryption at Rest with AWS KMS","How KMS actually protects data: envelope encryption and data keys, the 3 key types, why a key policy behaves unlike every other resource policy, rotation and what it does not do, the deletion waiting period, and the failures these produce in S3 and EBS.",{"path":323,"title":324,"isFree":80,"description":325},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/03-data-protection/03-encryption-in-transit-with-acm","Encryption in Transit with ACM","How to get TLS certificates that renew themselves, why some ACM certificates quietly do not, and how to terminate and enforce TLS across load balancers, CloudFront, and S3.",{"path":327,"title":328,"isFree":80,"description":329},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/03-data-protection/04-secrets-management","Secrets Management","Where credentials belong on AWS and why: Parameter Store tiers and SecureString, Secrets Manager rotation and staging labels, cross-account access, and the failures each design produces.",{"path":331,"title":332,"isFree":75,"description":333},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/04-threat-detection-and-response/01-guardduty-and-inspector","Amazon GuardDuty and Amazon Inspector","The two detection services answer different questions: GuardDuty watches behavior in your logs to find attacks in progress, and Inspector scans your workloads to find the weaknesses an attacker would use. This lesson covers what each one sees, how to read their findings, and how suppression differs between them.",{"path":335,"title":336,"isFree":80,"description":337},"/courses/aws-certified-cloudops-engineer-associate/en/domains/04-security-and-compliance/04-threat-detection-and-response/02-security-hub-and-automated-response","Security Hub and Automated Response","How to turn scattered findings from GuardDuty, Inspector, Macie, and Config into one prioritized queue and then act on it without a human in the loop: Security Hub CSPM aggregation and scoring, automation rules, EventBridge remediation, and where exposure findings and AWS Security Agent fit.",{"path":339,"title":340,"isFree":75,"description":341},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/01-vpc-fundamentals/01-vpc-subnets-and-route-tables","VPC, Subnets, and Route Tables","A VPC is an address range plus a router, and almost every networking incident traces back to one of those two. This lesson covers CIDR planning that you cannot undo, why a subnet gives you fewer addresses than the math suggests, and how route tables decide where every packet goes.",{"path":343,"title":344,"isFree":80,"description":345},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/01-vpc-fundamentals/02-internet-nat-and-egress-gateways","Internet, NAT, and Egress-Only Gateways","Three devices connect a VPC to the internet, and each one exists because the other two cannot do its job. This lesson covers what an internet gateway actually translates, why NAT gateways fail in ways that look like application bugs, and why IPv6 needs a fourth answer entirely.",{"path":347,"title":348,"isFree":80,"description":349},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/01-vpc-fundamentals/03-security-groups-vs-network-acls","Security Groups and Network ACLs","Two firewalls guard every packet in a VPC, and they disagree about almost everything: where they sit, whether they can deny, how their rules are read, and whether replies come back for free. This lesson makes the boundary between them sharp enough to answer a scenario question in one pass.",{"path":351,"title":352,"isFree":75,"description":353},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/02-private-and-hybrid-connectivity/01-vpc-endpoints-and-privatelink","VPC Endpoints and AWS PrivateLink","Two kinds of VPC endpoint keep traffic off the public path to AWS services, and they solve different problems. This lesson separates gateway endpoints from interface endpoints by reach, cost, and failure mode, then covers endpoint policies and hosting your own PrivateLink service.",{"path":355,"title":356,"isFree":80,"description":357},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/02-private-and-hybrid-connectivity/02-vpc-peering-and-transit-gateway","VPC Peering and Transit Gateway","VPC peering is a one to one wire between 2 VPCs with 3 hard limits; Transit Gateway is a regional router that removes all 3 and adds route tables of its own. This lesson covers both, the point where a mesh stops being viable, and how to troubleshoot the 4 layers of routing a transit gateway introduces.",{"path":359,"title":360,"isFree":80,"description":361},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/02-private-and-hybrid-connectivity/03-site-to-site-and-client-vpn","Site-to-Site VPN and Client VPN","Two hybrid problems, 2 services: connecting a data center to AWS over IPsec, and connecting individual people to a VPC over TLS. This lesson covers tunnels, static against BGP routing, where Direct Connect changes the answer, and the Client VPN rule that drops traffic even when the route exists.",{"path":363,"title":364,"isFree":75,"description":365},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/03-dns-and-content-delivery/01-route53-dns-and-resolver","Route 53 DNS and Resolver","A name that resolves from your laptop and returns NXDOMAIN inside a VPC is not a broken record, it is a different resolver answering. This lesson covers hosted zones, alias records, private hosted zones, and the inbound and outbound Resolver endpoints that make hybrid name resolution work.",{"path":367,"title":368,"isFree":80,"description":369},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/03-dns-and-content-delivery/02-route53-routing-policies","Route 53 Routing Policies","Eight routing policies answer the same question differently: given this query, which of my endpoints should the caller get? This lesson covers health checks first, then each policy, and the boundaries between the 3 policies that all claim to route by location.",{"path":371,"title":372,"isFree":80,"description":373},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/03-dns-and-content-delivery/03-cloudfront-distributions","CloudFront Distributions","A CloudFront distribution is a set of rules that decide, at an edge location, whether to answer from cache or ask your origin. This lesson covers cache behaviors and their matching order, the cache key, the TTL rules that override your Cache-Control headers, invalidation, HTTPS with custom domains, and locking the origin down with OAC.",{"path":375,"title":376,"isFree":80,"description":377},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/03-dns-and-content-delivery/04-global-accelerator-vs-cloudfront","Global Accelerator against CloudFront","Both services put AWS edge locations in front of your workload, and only one of them caches. This lesson covers Global Accelerator's anycast static IPs, listeners, endpoint groups, and traffic dials, then draws the boundary that decides which service a scenario is describing.",{"path":379,"title":380,"isFree":75,"description":381},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/04-network-protection-and-cost/01-auditing-network-protection-services","Auditing Network Protection Services","AWS WAF, Shield, Network Firewall, and Route 53 Resolver DNS Firewall each guard a different piece of traffic, and each has a way of looking deployed while blocking nothing. This lesson gives you a repeatable audit for all 4 in a single account.",{"path":383,"title":384,"isFree":80,"description":385},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/04-network-protection-and-cost/02-optimizing-network-costs","Optimizing Network Costs","Network charges are not a resource you provisioned, they are a consequence of the path your packets take. This lesson covers the 3 shapes of network charge, how to read them in the bill, and the arithmetic behind NAT gateways, VPC endpoints, cross-AZ traffic, and Transit Gateway.",{"path":387,"title":388,"isFree":75,"description":389},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/05-network-troubleshooting/01-troubleshooting-vpc-connectivity","Troubleshooting VPC Connectivity","A connection inside a VPC can fail at seven different places, and guessing wastes the outage. This lesson gives you an ordered walk down the path plus Reachability Analyzer, the tool that reads the whole path for you.",{"path":391,"title":392,"isFree":80,"description":393},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/05-network-troubleshooting/02-analyzing-network-logs","Analyzing Network Logs","VPC Flow Logs, ELB access logs, CloudFront logs, WAF logs, and Resolver query logs each watch a different hop of the same request. This lesson teaches you to read each one and to pick the right one before you start querying.",{"path":395,"title":396,"isFree":80,"description":397},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/05-network-troubleshooting/03-troubleshooting-cloudfront-issues","Troubleshooting CloudFront Issues","A CloudFront error can come from the viewer, the edge, or your origin, and the status code alone will not tell you which. This lesson teaches you to read the response headers and log fields that do, and to fix a collapsing cache hit ratio.",{"path":399,"title":400,"isFree":80,"description":401},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/05-network-troubleshooting/04-troubleshooting-hybrid-connectivity","Troubleshooting Hybrid and Private Connectivity","A VPN tunnel that will not come up, a Direct Connect BGP session stuck in Active, an endpoint that resolves to the wrong address. This lesson gives you a bottom-up diagnostic order for hybrid links and the private connectivity failures that look like them.",{"path":403,"title":404,"isFree":80,"description":405},"/courses/aws-certified-cloudops-engineer-associate/en/domains/05-networking-content-delivery/05-network-troubleshooting/05-cloudwatch-network-monitoring","CloudWatch Network Monitoring","Internet Monitor, Network Flow Monitor, and Network Synthetic Monitor each watch a different segment of your network, and picking the wrong one gives you a dashboard that cannot see the problem. This lesson separates them and pairs them with the per-resource metrics that catch silent failures.",[407,408,409,410,411],"monitoring-logging-performance","reliability-business-continuity","deployment-provisioning-automation","security-and-compliance","networking-content-delivery"]