Network security
| Security group | Network ACL | |
|---|---|---|
| Applies to | ENI or instance | Subnet |
| State | Stateful: return traffic is allowed automatically | Stateless: return traffic (ephemeral ports) needs its own rule |
| Rules | Allow only | Allow and deny, evaluated in number order |
| Can reference | Other security groups | CIDR ranges only |
| Decider | “Allow only from the web tier” | “Block this IP range” |
| AWS WAF | Shield Standard | Shield Advanced | Network Firewall | |
|---|---|---|---|---|
| Protects against | L7 attacks: SQLi, XSS, bots, rate abuse | L3/L4 DDoS | L3–L7 DDoS with a response team and cost protection | Stateful traffic inspection in the VPC, domain filtering, IPS |
| Attached to | CloudFront, ALB, API Gateway, AppSync | Automatic, free | CloudFront, Route 53, ALB, Elastic IP, Global Accelerator | VPC subnets |
Private connectivity
| Gateway endpoint | Interface endpoint (PrivateLink) | |
|---|---|---|
| Services | S3 and DynamoDB only | Most AWS services, your own services, partner services |
| How it works | Route table entry | ENI with a private IP in your subnet |
| Cost | Free | Hourly plus per GB |
| Reachable from on premises | No | Yes (over DX or VPN) |
| VPC peering | Transit Gateway | PrivateLink | |
|---|---|---|---|
| Shape | One-to-one, not transitive | Hub and spoke, transitive | Consumer to one service |
| Scale | Few VPCs | Hundreds of VPCs, VPNs, DX | Many consumers, one provider |
| Overlapping CIDRs | Not allowed | Not allowed between routed networks | Allowed |
| Cost | No hourly charge | Per attachment plus per GB | Per endpoint plus per GB |
| Site-to-Site VPN | Direct Connect | |
|---|---|---|
| Path | Encrypted IPsec over the internet | Private dedicated circuit |
| Setup | Minutes | Weeks |
| Performance | Variable | Consistent bandwidth and latency |
| Encryption | Built in | Not by default: add a VPN over it, or MACsec |
| Decider | Fast, cheap, backup link | Steady high volume, predictable performance |
Edge
| CloudFront | Global Accelerator | |
|---|---|---|
| Traffic | HTTP/HTTPS, WebSocket | Any TCP/UDP |
| Caches content | Yes | No |
| IP addresses | Changing edge IPs | Two static anycast IPs |
| Failover | Origin groups | Health-based endpoint failover across Regions in seconds |
| Decider | Caching, static and dynamic web content | Static IPs, non-HTTP traffic, gaming, IoT |
Load balancers
| ALB | NLB | GWLB | |
|---|---|---|---|
| Layer | 7 (HTTP/HTTPS, gRPC) | 4 (TCP/UDP/TLS) | 3 (IP packets, GENEVE) |
| Routing | Path, host, header, query string | Port | To appliance fleets |
| Static IP | No (put Global Accelerator or an NLB in front) | Yes, one per AZ (Elastic IP supported) | No |
| Extras | Lambda targets, OIDC/Cognito authentication, WAF | Extreme throughput, PrivateLink services | Third-party firewalls and IDS |
Messaging and streaming
| SQS | SNS | EventBridge | Kinesis Data Streams | Data Firehose | |
|---|---|---|---|---|---|
| Model | Queue (pull) | Pub/sub (push) | Event bus with rules | Stream (pull, shards) | Managed delivery |
| Consumers | One group; message deleted after processing | Many subscribers | Many targets by pattern | Many, each reads independently | Destinations: S3, Redshift, OpenSearch, HTTP |
| Replay | No | No | Archive and replay | Yes (within retention) | No |
| Ordering | FIFO queues | FIFO topics | No | Per shard | No |
| Decider | Decouple and buffer | Fan-out | SaaS and AWS events, content routing, schedules | Real-time, replay, custom consumers | Zero-admin loading, format conversion |
| Step Functions Standard | Step Functions Express | |
|---|---|---|
| Duration | Up to 1 year | Up to 5 minutes |
| Execution | Exactly-once | At-least-once |
| Fits | Long business workflows, human approval | High-volume event processing |
Compute purchasing
| Savings Plans | Reserved Instances | Spot | On-Demand | |
|---|---|---|---|---|
| Commitment | Spend per hour, 1 or 3 years | Instance config, 1 or 3 years | None | None |
| Flexibility | Compute SP: any family, Region, Fargate, Lambda | Convertible RIs can be exchanged | Can be interrupted with a 2-minute notice | Full |
| Discount | High | High | Highest | None |
| Decider | Steady usage that may change shape | Steady and fixed; RDS and other services | Stateless, fault-tolerant | Short, spiky, uninterruptible |
Dedicated Host is for BYOL per-socket or per-core licences and host visibility. Dedicated Instance is single-tenant hardware without host control.
Storage
| EBS | Instance store | EFS | FSx for Windows | FSx for Lustre | S3 | |
|---|---|---|---|---|---|---|
| Type | Block | Block (ephemeral) | File (NFS) | File (SMB) | File (Lustre) | Object |
| Shared | One instance (Multi-Attach io1/io2 in one AZ) | No | Thousands of Linux clients, multi-AZ | Windows clients, AD | HPC clusters | Any client via API |
| Survives a stop | Yes | No | Yes | Yes | Yes | Yes |
| Decider | Boot and databases | Scratch at top IOPS | Shared Linux POSIX | SMB and Active Directory | HPC, linked to S3 | Unlimited objects, static sites, data lakes |
FSx for NetApp ONTAP is for multi-protocol access (NFS, SMB, iSCSI). FSx for OpenZFS is for migrating ZFS file servers.
| DataSync | Storage Gateway | Snowball Edge | Transfer Family | |
|---|---|---|---|---|
| Purpose | Online bulk and scheduled copy | Ongoing hybrid access to cloud storage | Offline bulk transfer | SFTP/FTPS/FTP endpoint on S3 or EFS |
| Decider | “Migrate or sync over the network” | “On-premises apps keep using NFS, SMB, iSCSI or tape” | “Too much data for the link” | “Partners upload by SFTP” |
Databases
| RDS | Aurora | DynamoDB | |
|---|---|---|---|
| Model | Relational | Relational (MySQL/PostgreSQL-compatible) | Key-value and document |
| Scale | Vertical, plus read replicas | Up to 15 low-lag replicas, Serverless v2 | Virtually unlimited, horizontal |
| Failover | Multi-AZ, typically 1–2 min | Typically under 30 s | Built-in across AZs |
| Multi-Region | Cross-Region read replicas | Global Database (under 1 s lag) | Global tables (multi-active) |
| Decider | Standard engines (including Oracle and SQL Server) | Performance, fast failover, global reads | Massive scale, serverless, key-based access |
| Multi-AZ | Read replica | |
|---|---|---|
| Purpose | Availability | Read scaling |
| Replication | Synchronous | Asynchronous |
| Readable | No (instance deployment); yes (Multi-AZ DB cluster) | Yes |
| Cross-Region | No | Yes |
| ElastiCache (Valkey / Redis OSS) | ElastiCache Memcached | DAX | |
|---|---|---|---|
| Features | Replication, Multi-AZ, persistence, sorted sets, pub/sub | Simple, multi-threaded, no persistence | DynamoDB-only, API-compatible |
| Decider | Sessions, leaderboards, HA cache | Plain object cache | Microsecond DynamoDB reads with no code rewrite |
Identity and secrets
| Cognito user pool | Cognito identity pool | IAM Identity Center | |
|---|---|---|---|
| Gives | Sign-up, sign-in, JWT tokens | Temporary AWS credentials | Workforce SSO to accounts and apps |
| For | App end users | App users calling AWS directly | Employees |
| Secrets Manager | Parameter Store | |
|---|---|---|
| Rotation | Native automatic rotation | None built in |
| Cost | Per secret per month | Standard tier free |
| Decider | Database credentials that must rotate | Configuration and simple secrets |
Security services
| Service | One-line job |
|---|---|
| GuardDuty | Threat detection from CloudTrail, VPC Flow Logs and DNS logs |
| Inspector | Vulnerability scanning of EC2, container images and Lambda |
| Macie | Sensitive data (PII) discovery in S3 |
| Detective | Root-cause investigation of findings |
| Security Hub | Aggregated findings and posture checks |
| Config | Resource configuration history and compliance rules |
| CloudTrail | Who called which API, and when |
| SSE-S3 | SSE-KMS | SSE-C | CloudHSM | |
|---|---|---|---|---|
| Key control | AWS | You (key policy, rotation, audit in CloudTrail) | You supply the key with each request | Single-tenant HSM, you alone |
| Decider | Default, no management | Control and audit | Keys held outside AWS | Dedicated hardware under exclusive control |