Monitoring, Logging, and Remediation |
- Implement metrics, alarms, and filters by using AWS monitoring and logging services
-
Identify, collect, analyze, and export logs (for example, Amazon CloudWatch Logs, CloudWatch Logs Insights, AWS CloudTrail logs)
-
Collect metrics and logs by using the CloudWatch agent
-
Create CloudWatch alarms
-
Create metric filters
-
Create CloudWatch dashboards
-
Configure notifications (for example, Amazon Simple Notification Service [Amazon SNS], Service Quotas, CloudWatch alarms, AWS Health events)
- Remediate issues based on monitoring and availability metrics
-
Troubleshoot or take corrective actions based on notifications and alarms
-
Configure Amazon EventBridge rules to invoke actions
-
Use AWS Systems Manager Automation runbooks to take action based on AWS Config rules
|
20% |
Reliability and Business Continuity |
- Implement scalability and elasticity
-
Create and maintain AWS Auto Scaling plans
-
Implement caching
-
Implement Amazon RDS replicas and Amazon Aurora Replicas
-
Implement loosely coupled architectures
-
Differentiate between horizontal scaling and vertical scaling
- Implement high availability and resilient environments
-
Configure Elastic Load Balancing (ELB) and Amazon Route 53 health checks
-
Differentiate between the use of a single Availability Zone and Multi-AZ deployments (for example, Amazon EC2 Auto Scaling groups, ELB, Amazon FSx, Amazon RDS).
-
Implement fault-tolerant workloads (for example, Amazon Elastic File System [Amazon EFS], Elastic IP addresses)
-
Implement Route 53 routing policies (for example, failover, weighted, latency based)
- Implement backup and restore strategies
-
Automate snapshots and backups based on use cases (for example, RDS snapshots, AWS Backup, RTO and RPO, Amazon Data Lifecycle Manager, retention policy)
-
Restore databases (for example, point-in-time restore, promote read replica)
-
Implement versioning and lifecycle rules
-
Configure Amazon S3 Cross-Region Replication (CRR)
-
Perform disaster recovery procedures
|
16% |
Deployment, Provisioning, and Automation |
- Provision and maintain cloud resources
-
Create and manage AMIs (for example, EC2 Image Builder)
-
Create, manage, and troubleshoot AWS CloudFormation
-
Provision resources across multiple AWS Regions and accounts (for example, AWS Resource Access Manager [AWS RAM], CloudFormation StackSets, IAM cross-account roles)
-
Select deployment scenarios and services (for example, blue/green, rolling, canary)
-
Identify and remediate deployment issues (for example, service quotas, subnet sizing, CloudFormation errors, permissions)
- Automate manual or repeatable processes
|
18% |
Security and Compliance |
- Implement and manage security and compliance policies
-
Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, SAML, federated identity, resource policies, policy conditions).
-
Troubleshoot and audit access issues by using AWS services (for example, CloudTrail, IAM Access Analyzer, IAM policy simulator)
-
Validate service control policies (SCPs) and permissions boundaries
-
Review AWS Trusted Advisor security checks
-
Validate AWS Region and service selections based on compliance requirements
-
Implement secure multi-account strategies (for example, AWS Control Tower, AWS Organizations)
- Implement data and infrastructure protection strategies
|
16% |
Networking and Content Delivery |
- Implement networking features and connectivity
-
Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateway, internet gateway)
-
Configure private connectivity (for example, Systems Manager Session Manager, VPC endpoints, VPC peering, VPN)
-
Configure AWS network protection services (for example, AWS WAF, AWS Shield)
- Configure domains, DNS services, and content delivery
-
Configure Route 53 hosted zones and records
-
Implement Route 53 routing policies (for example, geolocation, geoproximity)
-
Configure DNS (for example, Route 53 Resolver)
-
Configure Amazon CloudFront and S3 origin access control (OAC)
-
Configure S3 static website hosting
- Troubleshoot network connectivity issues
-
Interpret VPC configurations (for example, subnets, route tables, network ACLs, security groups)
-
Collect and interpret logs (for example, VPC Flow Logs, ELB access logs, AWS WAF web ACL logs, CloudFront logs).
-
Identify and remediate CloudFront caching issues
-
Troubleshoot hybrid and private connectivity issues
|
18% |
Cost and Performance Optimization |
- Implement cost optimization strategies
-
Implement cost allocation tags
-
Identify and remediate underutilized or unused resources by using AWS services and tools (for example, Trusted Advisor, AWS Compute Optimizer, AWS Cost Explorer)
-
Configure AWS Budgets and billing alarms
-
Assess resource usage patterns to qualify workloads for EC2 Spot Instances
-
Identify opportunities to use managed services (for example, Amazon RDS, AWS Fargate, Amazon EFS)
- Implement performance optimization strategies
-
Recommend compute resources based on performance metrics
-
Monitor Amazon Elastic Block Store (Amazon EBS) metrics and modify configuration to increase performance efficiency.
-
Implement S3 performance features (for example, S3 Transfer Acceleration, multipart uploads)
-
Monitor RDS metrics and modify the configuration to increase performance efficiency (for example, Performance Insights, RDS Proxy)
-
Enable enhanced EC2 capabilities (for example, Elastic Network Adapter, instance store, placement groups).
|
12% |