SlideShare a Scribd company logo
Security Overview
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Topics
Introduction to AWS Security
The AWS Shared Responsibility Model
AWS Access Control and Management
AWS Security Resources
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Introduction to AWS Security
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Introduction to AWS Security
Security is of the utmost importance to AWS.
Approach to security
AWS environment controls
AWS offerings and features
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Keep Your Data Safe
Resilient infrastructure
High security
Strong safeguards
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Continual Improvement
Rapid innovation
Constantly evolving security services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay For What You Need
Advanced security services
Address real-time emerging risks
Meeting needs at a lower operational cost
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Meet Compliance Requirements
Governance-enabled features
 Additional oversight
 Security control
 Central automation
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security Products and Features
Tools
 Access from AWS and partners
 Use for monitoring and logging
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Network Security
Built-in firewalls
Encryption in transit
Private/dedicated connections
Distributed denial of service (DDoS) mitigation
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Inventory and Configuration Management
Deployment tools
Inventory and configuration tools
Template definition and management tools
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Data Encryption
Encryption capabilities
Key management options
 AWS Key Management Service
Hardware-based cryptographic key storage options
 AWS CloudHSM
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Access Control and Management
Identity and Access Management (IAM)
Multi-factor authentication (MFA)
Integration and federation with corporate directories
Amazon Cognito
AWS Single Sign-On
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Monitoring and Logging
Tools and features to reduce your risk profile:
 Deep visibility into API calls
 Log aggregation and options
 Alert notifications
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Marketplace
Qualified partners to market/sell software to AWS
customers
Online software store that can run on AWS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The AWS Shared Responsibility
Model
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Shared Responsibility Model
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security of the Cloud
Protection of the AWS global infrastructure is top priority
Availability of third-party reports
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security of the Cloud
Amazon EC2
Amazon EBS
AWS Foundation Services
Unmanaged services Managed Services
Amazon DynamoDB
Amazon RDS
Amazon Redshift
Amazon EMR
Amazon WorkSpaces
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security of the Cloud
Inherited Controls
 Physical
 Environmental
Shared Controls
 Patch Management
 Configuration Management
 Awareness and Training
AWS Foundation Services
Unmanaged services
(such as EC2, EBS)
Managed Services
Customer Specific
 Service/Communication
Protection
 Zone Security
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security in the Cloud
What to store
Which AWS services
In what location
In what content format and
structure
Who has access
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security in the Cloud
Customers retain control
Changes to model depend on services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security in the Cloud
AWS Service Catalog
Virtual Machine Images
Servers
Software
Databases
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security in the Cloud
Benefits
Centrally manage common IT services
Achieve consistent governance
Meet compliance requirements
Quickly deploy approved IT services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Example
Customer Responsibility:
 Guest OS
 Application
 Security group
Amazon
S3
Amazon
EC2 Amazon
Workspaces
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
AWS and the customer share security responsibilities
 AWS: Security of the cloud
 Customer: Security in the cloud
Customer has full control over security measures
Customer can use AWS Service Catalog
“Infrastructure” Service
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Access Control and
Management
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM
Control access to AWS resources
 Authentication
 Authorization
Controls access to services such as:
Compute
Storage
Database
Application services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM
Create users and groups
Grant permissions
User Group Permissions Role
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM
Functionality
Manage
 Users and their access
 Roles and their permissions
 Federate users and their permissions
IAM Corp
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Account Root User
Account root user has complete access to
all AWS Services.
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Account Root User
Recommendations
1. Delete root user access keys.
2. Create an IAM user.
3. Grant administrator access.
4. Use IAM credentials to
interact with AWS.
IAM
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM: Authentication
Programmatic access
 Enables access key ID and secret access key
Management console access
 Uses AWS account name and password
 MFA prompts for code
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM: Authorization
Access AWS services
 Grant authorization
Assign permissions
 Create an AWS IAM policy
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS IAM: Policy Assignment
IAM Policy
IAM User IAM Group IAM Roles
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
IAM Best Practices
Delete AWS root account access keys
Activate multi-factor authentication (MFA)
Give IAM users only the permissions they must have
Use IAM groups
Apply an IAM password policy
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Security Resources
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Security Resources
AWS communicates security and control environment
 Certifications and attestations
 Whitepapers and web content
 Compliance reports provided under NDA
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Trusted Advisor
Is a “customized cloud expert”
Helps you follow best practices
Inspects your AWS environment
Helps close security gaps
Finds opportunities and best practices in:
 Cost optimization
 Performance
 Security
 Fault Tolerance
 Service Limits
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Account Teams
Are first point of contact
Guide deployment
Point toward the right resources to resolve security issues
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Enterprise Support*
15-minute response time
24/7, by phone, chat, or email
Dedicated Technical Account Manager
*for details, see:
https://aws.amazon.com/premiumsupport/enterprise-support/
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Professional Services and
AWS Partner Network
APN has hundreds of certified AWS Consulting Partners
worldwide
 Help develop security policies
 Help meet compliance requirements
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Advisories and Bulletins
Advisories/bulletins provided on current vulnerabilities and
threats
Customers work with experts to address:
 Reporting abuse
 Vulnerabilities
 Penetration testing
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Auditor Learning Path
Understand how internal operations gain
compliance on AWS
Visit the compliance website:
 Recommended training
 Self-paced labs
 Auditing resources
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Compliance Solutions Guide
Understand the Shared Responsibility Model
Request a compliance report
Complete a security questionnaire
Services in Scope
AWS Security Blog
Case Studies
FAQs
*for details, see:
https://aws.amazon.com/compliance/resources/
AWS Architecting Essentials
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Introduction to the Well-
Architected Framework
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Introduction
Assess and improve architectures
Understand how design decisions impact business
Learn the five pillars and design principles
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
5 Pillars
Security
Reliability
Performance efficiency
Cost optimization
Operational excellence
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security Pillar
Identity and access management (IAM)
Detective controls
Infrastructure protection
Data protection
Incident response
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Security Pillar: Design Principles
Implement security at all layers
Enable traceability
Apply principle of least privilege
Focus on securing your system
Automate
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Reliability Pillar
Recover from issues/failures
Apply best practices in:
 Foundations
 Change management
 Failure management
Anticipate, respond, and prevent failures
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Reliability Pillar: Design Principles
Test recovery procedures
Automatically recover
Scale horizontally
Stop guessing capacity
Manage change in automation
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Performance Efficiency Pillar
Select customizable solutions
Review to continually innovate
Monitor AWS services
Consider the trade-offs
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Performance Efficiency Pillar: Design Principles
Democratize advanced technologies
Go global in minutes
Use a serverless architectures
Experiment more often
Have mechanical sympathy
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Cost Optimization Pillar
Use cost-effective resources
Matching supply with demand
Increase expenditure awareness
Optimize over time
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Cost Optimization Pillar: Design Principles
Adopt a consumption model
Measure overall efficiency
Reduce spending on data center operations
Analyze and attribute expenditure
Use managed services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Operational Excellence Pillar
Manage and automate changes
Respond to events
Define the standards
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Five pillars and their associated design principles
 Security
 Reliability
 Performance Efficiency
 Cost Optimization
 Operational Excellence
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Reference Architecture –
Fault Tolerance and High Availability
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Fault Tolerance
Ability of a system to remain operational
Built-in redundancy of an application’s components
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
High Availability
High availability is designed to keep
Systems generally functioning and accessible
Downtime minimized
Minimal human intervention required
Minimal up-front financial investment
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
High Availability: On Premises vs AWS
Traditional (on premises)
 Expensive
 Only mission-critical
applications
AWS
 Multiple servers
 Availability zones
 Regions
 Fault-tolerant services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
High Availability: AWS Services
AWS Services and High Availability
 Amazon S3 and Amazon
Glacier
 DynamoDB
 Amazon CloudFront
 Amazon SWF
 Amazon SQS
 Amazon SNS
 Amazon SES
 Amazon Route53
 Elastic Load Balancing
 IAM
 Amazon CloudWatch
 Amazon CloudSearch
 AWS Data Pipeline
 Amazon Kinesis
 Auto Scaling
 Amazon Elastic File System
 AWS CloudFormation
 Amazon WorkMail
 AWS Directory Service
 AWS Lambda
 Amazon EBS
 Amazon RDS
 Amazon EC2
 Amazon VPC
 Amazon Redshift
 Amazon ElastiCache
 AWS Direct Connect
*Not all services are listed here.
Inherently HA services HA with the right architecture
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
High Availability Service Tools
Elastic load balancers
Elastic IP addresses
Amazon Route 53
Auto Scaling
Amazon CloudWatch
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Elastic Load Balancers
Distributes incoming traffic (loads)
Sends metrics to Amazon CloudWatch
Triggers and notifies
 High latency
 Over used
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Elastic Load Balancers
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Elastic IP Addresses
Are static IP addresses
Mask failures (if they were to occur)
Continues to access applications if an instance fails
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon Route 53
Authoritative DNS service
 Translates domain names to IP addresses
Supports:
 Simple routing
 Latency-based routing
 Health checks
 DNS failovers
 Geo-location routing
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Auto Scaling
Terminates and launches instances
Assists with adjusting or modifying capacity
Creates new resources on demand
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon CloudWatch
Alarm examples:
 If CPU utilization is >60% for 5 minutes…
 If number of simultaneous connections is >10 for one
minute…
 If number of healthy hosts is <5 for 10 minutes…
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Fault Tolerant Tools
Amazon Simple Queue Service
Amazon Simple Storage Service
Amazon SimpleDB
Amazon Relational Database Service
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Fault Tolerant and highly available architectures
Services to assist architectures
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Reference Architecture:
Web Hosting
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Web Hosting
Web hosting on AWS:
 Fast
 Straightforward
 Low cost
Common web applications:
 Company website
 Content management system
 Social media application development
 Internal SharePoint site
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Cost Effective Alternative
Leverage on-demand provisioning
Eliminate wasted capacity
Continuously adjust to actual traffic patterns
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Scalable
Handle unexpected traffic peaks or unexpected loads
Launch new hosts in minutes
Scale hosts up or down
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
On-Demand Solution for Various Environments
Provision testing fleets
Develop staging in minutes
Simulate use traffic
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Migrating to AWS: Web Hosting Services
Products to assist transition:
 Amazon Virtual Private Cloud
 Amazon Route 53
 Amazon CloudFront
 Elastic load balancing
 Firewalls/AWS Shield
 Auto Scaling
 App servers/EC2 instances
 Amazon ElastiCache
 Amazon RDS/Amazon DynamoDB
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Key Architectural Considerations
Replace physical network appliances with software solutions
Deploy firewalls everywhere
Make available multiple data centers
Build an ephemeral and dynamic architecture
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
AWS and web hosting
AWS web hosted services
Key considerations for web hosted architectures
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following is NOT one of the four areas of the
performance efficiency pillar?
Tradeoffs
Selection
Monitoring
Traceability
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What tool helps avoid limitations of being able to create new
resources on-demand or scheduled?
Route 53
Elastic load balancer
Auto Scaling
CloudWatch
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
In a physical data center, security is typically considered in what
area?
Only in the perimeter
In an edge location
In the closest region
In the closest availability zones
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What is defined as the ability for a system to remain operational
even if some of the components of that system fail?
DNS failovers
High durability
High availability
Fault tolerance
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following are high availability characteristics of
Amazon Route 53? (Choose 2)
Latency-based routing
Geo-location routing
Collect and track high latency metrics
Mask failure of an instance/software
Terminate instances based on specified conditions
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What design principles are recommended when considering
performance efficiency? (Choose 2)
Enabling traceability
Democratize advanced technologies
Expenditure awareness
Matching supply and demand
Serverless architecture
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following cloud security controls are designed for
only allowing authorized and authenticated users can access
your resources?
Detective controls
Identity and Access Management
Infrastructure protection
Incident response
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
When considering cost optimization, what model allows you to
pay only for what computing resources you actually use?
Consumption model
Economies of scope model
Economies of scale model
Expenditure model
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following describes Elastic Load Balancers (ELB)?
Launches or terminates instances based on specified conditions
Creates new resources on-demand
Distributes incoming traffic amongst your instances
Translates domain names into IP addresses
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following is NOT considered a fault tolerant tool?
S3
WAF
SQS
RDS
© 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or
in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited.
Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at:
https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.
Module 6: Pricing and
Support Overview
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Topics
Fundamentals of Pricing
Pricing Details
Overview of the Total Cost of Ownership Calculator
Overview of AWS Support Plans
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Fundamentals of Pricing
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Pricing Model
Pay-as-you-go
Pay less when you reserve
Pay even less per unit by using more
Pay even less as AWS grows
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay-As-You-Go
Pay only for the services you consume, with no large
upfront expenses.
Lower variable costs
Pay only as long as you need the service
Adapt to changing business needs
Redirect focus on innovation and invention
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay Less When You Reserve
Invest in reserved instances
Save up to 75%
Options
 All Upfront
 Partial Upfront
 No Upfront payments
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay Less By Using More
Realize volume-based discounts
Savings as usage increases
Tiered pricing for services (for example, Amazon S3,
Amazon EC2)
No charge for inbound data transfer
Storage services options
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay Even Less as AWS Grows
As AWS grows
Focuses on lowering cost of doing business
Passes savings from economies of scale down to you
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Custom Pricing
Meet varying needs through custom pricing
Available for high-volume projects with unique
requirements
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Free Tier
AWS Free Tier helps customer get started in the cloud
Limitations:
 Up to one year
 Certain services and options
For more details, see: https://www.aws.amazon.com/free
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
No Extra Charge
AWS services for no additional charge:
Amazon VPC
AWS Elastic Beanstalk
AWS CloudFormation
AWS IAM
Auto Scaling
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Pay only for what you use
Start and stop anytime
No long-term contracts required
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pricing Details
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Fundamentals
Pay for AWS fundamentals:
 Compute
 Storage
 Outbound data transfer
No charge:
 Inbound data transfer
Charge for aggregated outbound
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Service Pricing for AWS Offerings
Amazon EC2
Amazon S3
Amazon EBS
Amazon RDS
Amazon CloudFront
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2
Provide resizable compute capacity in the cloud
Allows the configuration of capacity with minimal friction
Provides complete control
Charges only for capacity used
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2: Billing and Instance Configuration
Clock-Second/Hourly Billing
Resources incur charges only when running
Instance Configuration
Physical capacity of the instance
Pricing varies with:
 AWS region
 OS
 Instance Type
 Instance Size
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2: Purchase Types
Ways to pay for Amazon EC2 instances
On-demand instances
 Compute capacity by the hour and second
 Minimum of 60 seconds
Reserved Instances
 Low or no up-front payment instances reserved
 Discount on hourly charge for that instance
Spot Instances
 Bid for unused Amazon EC2 capacity
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2: Number of Instances and Load
Balancing
Number of Instances
Provision multiple instances to handle peak loads
Load Balancing
Uses Elastic Load Balancing to distribute traffic
Calculates monthly cost based on
 Hours load balancer runs
 Data load balancer processes
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2: Monitoring
Use Amazon CloudWatch to monitor instances.
Basic monitoring (default)
Detailed monitoring
 Fixed monthly rate
 Prorated partial months
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2
Auto Scaling
Automatically adjusts number of instances
Incurs no additional charge
Elastic IP Addresses
No charge for one Elastic IP address associated with a running
instance.
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EC2: OS and Software
Pricing for operating systems and software packages:
Includes OS prices in instance prices
Partners with other vendors for certain software
Requires licenses from vendors for other software
Brings existing license through specific vendor programs
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon S3: Storage Classes
Types of storage classes
Standard Storage
 99.999999999% durability
 99.99% availability
Standard-Infrequent Access (S-IA)
 99.999999999% durability
 99.9% availability
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon S3: Storage
Considerations for estimating storage cost
 The number and size of objects
 Type of storage
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon S3
Requests:
Pricing based on
Number of requests
Type of requests
 Different rates for GET requests
Data Transfer
Pricing based on the amount of data transferred out of the
Amazon S3 region
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EBS
Block-level storage for instances
EBS volumes persist independently from the instance
Analogous to virtual disks in the cloud
Three volume types:
 General Purpose (SSD)
 Provisioned IOPS (SSD)
 Magnetic
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EBS: Volumes and IOPS
Volumes
All volume types are charged by the amount provisioned per month
IOPS
General Purpose (SSD)
 Included in price
Magnetic
 Charged by the number of requests
Provisioned IOPS (SSD)
 Charged by the amount you provision in IOPS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon EBS: Snapshots and Data Transfer
Snapshots
Added cost of EBS snapshots to Amazon S3 is per GB-month of
data stored
Data Transfer
Inbound data transfer has no charge
Outbound data transfer charges are tiered
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon RDS
Relational database in the cloud
Cost-efficient and resizable capacity
Management of time-consuming administrative tasks
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon RDS: Clock-Hour Billing and Database
Characteristics
Clock-Hour Billing
Resources incur charges when running
Database Characteristics
Physical capacity of database:
 Engine
 Instance Type
 Instance Size
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon RDS: DB Purchase Type and Multiple
DB Instances
DB Purchase Type
On-demand database instances
 By the hour
Reserved database instances
 Up-front payment for database instances reserved
Multiple DB Instances
Provision multiple DB instances to handle peak loads
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon RDS: Storage
Provisioned Storage
No charge
 Backup storage of up to 100% of database storage
Charge (GB/month)
 Backup storage for terminated DB instances
Additional Storage
Charge (GB/month)
 Backup storage in addition to provisioned storage
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon RDS: Deployment Type and Data
Transfer
Storage and I/O charges vary depending on deployment type
Single Availability Zones
Multiple Availability Zones
Data Transfer
No charge for Inbound data transfer
Tiered charges for outbound data transfer
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon CloudFront
Web service for content delivery
Integration with other AWS services
 Low latency
 High data transfer speeds
 No minimum commitments
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon CloudFront: Traffic Distribution
Pricing
Vary across geographic regions
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Amazon CloudFront: Requests and Data
Transfer Out
Requests
Pricing based on
Number/type of requests
Geographic region
Data Transfer Out
Pricing is based on the amount of data transferred out of
Amazon CloudFront edge locations
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Fundamental characteristics of product
Estimate usage
Map usage to prices
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Overview of the Total Cost of
Ownership Calculator
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS TCO Calculator
Use the TCO calculator to
Estimate cost savings
Use detailed reports
Modify assumptions
Accessing the TCO Calculator:
https://awstcocalculator.com
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Estimate cost savings
Use detailed set of reports
Modify assumptions for business needs
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Overview of AWS Support Plans
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Support
Provide unique combination of tools/expertise
 AWS Support
 AWS Support Plans
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Support
Support is provided for
Experimenting with AWS
Production use of AWS
Business critical use of AWS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Support
Proactive guidance
 Technical Account Manager (TAM)
Best practices
 Trusted Advisor
Account assistance
 AWS Support Concierge
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Support Plans
AWS Support offers four support plans:
Basic Support
Developer Support
Business Support
Enterprise Support
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
AWS Support
AWS Support Plans
 Basic Support plan
 Developer Support plan
 Business Support plan
 Enterprise Support plan
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
When calculating the cost of Amazon EC2, what factors will
impact pricing? (Choose 2)
Number of items in your inbound data transfer
Number and size of objects stored in your Amazon S3 buckets
Number of instances
Number of seconds and hours Elastic Load Balancer runs
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What charges apply to data transfer across AWS? (Choose 2)
No charge for inbound data transfer across all Amazon Web Services in
all regions
No charge for outbound data transfer across all Amazon Web Services
in all regions
No charge for inbound data transfer for EC2 instances
No charge for outbound data transfer between Amazon Web Services
within the same region
No charge for inbound data transfer between Amazon Web Services
within the same region
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
As AWS grows, the general cost of doing business is reduced and
savings are passed back to the customer in the form of lower
pricing. What is this cost optimization called?
Economies of scope
Economies of labor
Economies of scale
Economies of cost
Economies of optimization
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What type of applications are recommended for Amazon EC2
reserved instances?
Applications that are only feasible at lower compute prices
Applications that have flexible start and end times
Applications with steady state or predictable usage
Applications being developed or tested for the first time
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What are the characteristics of the Developer Support Plan?
(Choose 2)
One primary contact may open a case
Unlimited contacts may open a case
Business hours access to cloud support associates via email
24/7 access to cloud support engineers via email, chat, and phone
Assigned to a Technical Account Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What is NOT a consideration when estimating the cost of
Amazon S3?
Number and size of objects
Storage class
Requests
Input Output Operations per Second (IOPS)
Data transfer
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
With the “Pay as you go” pricing model, how often do you pay
for compute resources from the time you launch a resource until
you terminate it?
Quarterly
Yearly
Monthly
Daily
Secondly and Hourly
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
What AWS tool compares the cost of running your application in
an on-premise data center to AWS?
Total Cost of Operation (TCO) Calculator
Total Cost of Application (TCA) Calculator
Total Cost of Services (TCS) Calculator
Total Cost of Products (TCP) Calculator
Total Cost of Ownership (TCO) Calculator
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Knowledge Check
Which of the following is NOT available in the Business Support
Plan?
Access to Personal Health Dashboard and Health API
Access to cloud support engineers for technical issues
Access to Infrastructure Event Management
Access to third-party software support
Access to Well-Architected review delivered by AWS Solution Architects
© 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or
in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited.
Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at:
https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
With deep expertise on AWS, APN Partners can help your
organization at any stage of your Cloud Adoption Journey.
AWS Managed Service Providers
APN Consulting Partners who are skilled at cloud
infrastructure and application migration, and offer
proactive management of their customer’s environment.
AWS Competency Partners
APN Partners who have demonstrated technical
proficiency and proven customer success in specialized
solution areas.
AWS Service Delivery Partners
APN Partners with a track record of delivering specific
AWS services to customers.
Ready to get started with an APN Partner?
Find a partner: https://aws.amazon.com/partners/find/
AWS Marketplace
A digital catalog with thousands of software listings from
independent software vendors that make it easy to find,
test, buy, and deploy software that runs on AWS.
AWS Cloud Practitioner
Essentials Course Summary
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Congratulations
You have completed AWS Cloud Practitioner Essentials
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summary
Section 1: AWS Cloud Concepts
Section 2: AWS Core Services
Section 3: AWS Security
Section 4: AWS Architecting
Section 5: AWS Pricing and Support
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Course Feedback
Thank you for participating!
© 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or
in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited.
Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at:
https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.

More Related Content

What's hot

Scaling threat detection and response on AWS
Scaling threat detection and response on AWSScaling threat detection and response on AWS
Scaling threat detection and response on AWS
Amazon Web Services
 
Module 5 - AWSome Day Online Conference 2018
Module 5 - AWSome Day Online Conference 2018Module 5 - AWSome Day Online Conference 2018
Module 5 - AWSome Day Online Conference 2018
Amazon Web Services
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Amazon Web Services
 
AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview
Amazon Web Services
 
AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training
Amazon Web Services
 
AWSome Day Madrid - March 2018
AWSome Day Madrid -  March 2018AWSome Day Madrid -  March 2018
AWSome Day Madrid - March 2018
Amazon Web Services
 
The Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
The Evolution of Identity and Access Management on AWS - AWS Online Tech TalksThe Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
The Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
Amazon Web Services
 
AWS PROTECTED Webinar
AWS PROTECTED WebinarAWS PROTECTED Webinar
AWS PROTECTED Webinar
Amazon Web Services
 
Fundamentals of AWS Security
Fundamentals of AWS SecurityFundamentals of AWS Security
Fundamentals of AWS Security
Amazon Web Services
 
AWSome Day 2019 - Detroit
AWSome Day 2019 - DetroitAWSome Day 2019 - Detroit
AWSome Day 2019 - Detroit
Amazon Web Services
 
Costruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSCostruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWS
Amazon Web Services
 
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF LoftIdentity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Amazon Web Services
 
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
Amazon Web Services
 
AWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS FoundationsAWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS Foundations
Amazon Web Services
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
Amazon Web Services
 
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF LoftAdding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
Amazon Web Services
 
Cloud Security (AWS)
Cloud Security (AWS)Cloud Security (AWS)
Cloud Security (AWS)
Scott Arveseth
 
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
Amazon Web Services
 
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Amazon Web Services
 
AWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applicationsAWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applications
Amazon Web Services
 

What's hot (20)

Scaling threat detection and response on AWS
Scaling threat detection and response on AWSScaling threat detection and response on AWS
Scaling threat detection and response on AWS
 
Module 5 - AWSome Day Online Conference 2018
Module 5 - AWSome Day Online Conference 2018Module 5 - AWSome Day Online Conference 2018
Module 5 - AWSome Day Online Conference 2018
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
 
AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview
 
AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training
 
AWSome Day Madrid - March 2018
AWSome Day Madrid -  March 2018AWSome Day Madrid -  March 2018
AWSome Day Madrid - March 2018
 
The Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
The Evolution of Identity and Access Management on AWS - AWS Online Tech TalksThe Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
The Evolution of Identity and Access Management on AWS - AWS Online Tech Talks
 
AWS PROTECTED Webinar
AWS PROTECTED WebinarAWS PROTECTED Webinar
AWS PROTECTED Webinar
 
Fundamentals of AWS Security
Fundamentals of AWS SecurityFundamentals of AWS Security
Fundamentals of AWS Security
 
AWSome Day 2019 - Detroit
AWSome Day 2019 - DetroitAWSome Day 2019 - Detroit
AWSome Day 2019 - Detroit
 
Costruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSCostruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWS
 
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF LoftIdentity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
 
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
Build a dashboard using serverless security analytics - SDD201 - AWS re:Infor...
 
AWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS FoundationsAWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS Foundations
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
 
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF LoftAdding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
Adding the Sec to Your DevOps Pipelines: AWS Security Week at the SF Loft
 
Cloud Security (AWS)
Cloud Security (AWS)Cloud Security (AWS)
Cloud Security (AWS)
 
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
Cross-account encryption with AWS KMS and Slack Enterprise Key Management - S...
 
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
 
AWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applicationsAWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applications
 

Similar to Module 3: Security, Architecting Best Practices, Pricing, Partner Solutions, Training and Certification – Virtual AWSome Day June 2018

AWSome Day Online Conference 2018 - Module 3
AWSome Day Online Conference 2018 - Module 3AWSome Day Online Conference 2018 - Module 3
AWSome Day Online Conference 2018 - Module 3
Amazon Web Services
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Amazon Web Services
 
Module 3 - AWSome Day Online Conference 2018
Module 3 - AWSome Day Online Conference 2018Module 3 - AWSome Day Online Conference 2018
Module 3 - AWSome Day Online Conference 2018
Amazon Web Services
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices
Security Framework Shakedown: Chart Your Journey with AWS Best PracticesSecurity Framework Shakedown: Chart Your Journey with AWS Best Practices
Security Framework Shakedown: Chart Your Journey with AWS Best Practices
Amazon Web Services
 
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Amazon Web Services
 
Landing Zones Creating a Foundation - AWS Summit Sydney 2018
Landing Zones Creating a Foundation - AWS Summit Sydney 2018Landing Zones Creating a Foundation - AWS Summit Sydney 2018
Landing Zones Creating a Foundation - AWS Summit Sydney 2018
Amazon Web Services
 
Security Framework Shakedown
Security Framework ShakedownSecurity Framework Shakedown
Security Framework Shakedown
Amazon Web Services
 
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
Amazon Web Services
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
Amazon Web Services
 
AWS Security By Design
AWS Security By DesignAWS Security By Design
AWS Security By Design
Amazon Web Services
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by Design
Amazon Web Services
 
Landing zones: Creating a Foundation for Your AWS Migrations
Landing zones: Creating a Foundation for Your AWS MigrationsLanding zones: Creating a Foundation for Your AWS Migrations
Landing zones: Creating a Foundation for Your AWS Migrations
Ali Asgar Juzer
 
How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdf
Amazon Web Services
 
Introduction to AWS Security: Security Week at the SF Loft
Introduction to AWS Security: Security Week at the SF LoftIntroduction to AWS Security: Security Week at the SF Loft
Introduction to AWS Security: Security Week at the SF Loft
Amazon Web Services
 
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
Amazon Web Services
 
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
Amazon Web Services
 
AWS Systems Manage: Bridging Operational Models
AWS Systems Manage: Bridging Operational Models AWS Systems Manage: Bridging Operational Models
AWS Systems Manage: Bridging Operational Models
Amazon Web Services
 
New AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your WorkloadNew AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your Workload
Amazon Web Services
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
Amazon Web Services
 
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
Amazon Web Services
 

Similar to Module 3: Security, Architecting Best Practices, Pricing, Partner Solutions, Training and Certification – Virtual AWSome Day June 2018 (20)

AWSome Day Online Conference 2018 - Module 3
AWSome Day Online Conference 2018 - Module 3AWSome Day Online Conference 2018 - Module 3
AWSome Day Online Conference 2018 - Module 3
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
Security Framework Shakedown: Chart Your Journey with AWS Best Practices (SEC...
 
Module 3 - AWSome Day Online Conference 2018
Module 3 - AWSome Day Online Conference 2018Module 3 - AWSome Day Online Conference 2018
Module 3 - AWSome Day Online Conference 2018
 
Security Framework Shakedown: Chart Your Journey with AWS Best Practices
Security Framework Shakedown: Chart Your Journey with AWS Best PracticesSecurity Framework Shakedown: Chart Your Journey with AWS Best Practices
Security Framework Shakedown: Chart Your Journey with AWS Best Practices
 
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
 
Landing Zones Creating a Foundation - AWS Summit Sydney 2018
Landing Zones Creating a Foundation - AWS Summit Sydney 2018Landing Zones Creating a Foundation - AWS Summit Sydney 2018
Landing Zones Creating a Foundation - AWS Summit Sydney 2018
 
Security Framework Shakedown
Security Framework ShakedownSecurity Framework Shakedown
Security Framework Shakedown
 
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
AWS Security Best Practices in a Zero Trust Security Model - DEM08 - Toronto ...
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
AWS Security By Design
AWS Security By DesignAWS Security By Design
AWS Security By Design
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by Design
 
Landing zones: Creating a Foundation for Your AWS Migrations
Landing zones: Creating a Foundation for Your AWS MigrationsLanding zones: Creating a Foundation for Your AWS Migrations
Landing zones: Creating a Foundation for Your AWS Migrations
 
How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdf
 
Introduction to AWS Security: Security Week at the SF Loft
Introduction to AWS Security: Security Week at the SF LoftIntroduction to AWS Security: Security Week at the SF Loft
Introduction to AWS Security: Security Week at the SF Loft
 
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
[NEW LAUNCH!] Introduction to AWS Security Hub (SEC397) - AWS re:Invent 2018
 
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
Using AMS to get FSI Regulated Workloads on the Cloud, Fast - AWS Summit Sydn...
 
AWS Systems Manage: Bridging Operational Models
AWS Systems Manage: Bridging Operational Models AWS Systems Manage: Bridging Operational Models
AWS Systems Manage: Bridging Operational Models
 
New AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your WorkloadNew AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your Workload
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
Mastering Identity at Every Layer of the Cake (SEC401-R1) - AWS re:Invent 2018
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
Amazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
Amazon Web Services
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Amazon Web Services
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
Amazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Amazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
Amazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Amazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Module 3: Security, Architecting Best Practices, Pricing, Partner Solutions, Training and Certification – Virtual AWSome Day June 2018

  • 2. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Topics Introduction to AWS Security The AWS Shared Responsibility Model AWS Access Control and Management AWS Security Resources
  • 3. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Introduction to AWS Security
  • 4. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Introduction to AWS Security Security is of the utmost importance to AWS. Approach to security AWS environment controls AWS offerings and features
  • 5. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Keep Your Data Safe Resilient infrastructure High security Strong safeguards
  • 6. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Continual Improvement Rapid innovation Constantly evolving security services
  • 7. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay For What You Need Advanced security services Address real-time emerging risks Meeting needs at a lower operational cost
  • 8. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Meet Compliance Requirements Governance-enabled features  Additional oversight  Security control  Central automation
  • 9. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security Products and Features Tools  Access from AWS and partners  Use for monitoring and logging
  • 10. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Network Security Built-in firewalls Encryption in transit Private/dedicated connections Distributed denial of service (DDoS) mitigation
  • 11. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Inventory and Configuration Management Deployment tools Inventory and configuration tools Template definition and management tools
  • 12. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Data Encryption Encryption capabilities Key management options  AWS Key Management Service Hardware-based cryptographic key storage options  AWS CloudHSM
  • 13. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Access Control and Management Identity and Access Management (IAM) Multi-factor authentication (MFA) Integration and federation with corporate directories Amazon Cognito AWS Single Sign-On
  • 14. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Monitoring and Logging Tools and features to reduce your risk profile:  Deep visibility into API calls  Log aggregation and options  Alert notifications
  • 15. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Marketplace Qualified partners to market/sell software to AWS customers Online software store that can run on AWS
  • 16. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The AWS Shared Responsibility Model
  • 17. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Shared Responsibility Model
  • 18. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security of the Cloud Protection of the AWS global infrastructure is top priority Availability of third-party reports
  • 19. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security of the Cloud Amazon EC2 Amazon EBS AWS Foundation Services Unmanaged services Managed Services Amazon DynamoDB Amazon RDS Amazon Redshift Amazon EMR Amazon WorkSpaces
  • 20. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security of the Cloud Inherited Controls  Physical  Environmental Shared Controls  Patch Management  Configuration Management  Awareness and Training AWS Foundation Services Unmanaged services (such as EC2, EBS) Managed Services Customer Specific  Service/Communication Protection  Zone Security
  • 21. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security in the Cloud What to store Which AWS services In what location In what content format and structure Who has access
  • 22. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security in the Cloud Customers retain control Changes to model depend on services
  • 23. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security in the Cloud AWS Service Catalog Virtual Machine Images Servers Software Databases
  • 24. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security in the Cloud Benefits Centrally manage common IT services Achieve consistent governance Meet compliance requirements Quickly deploy approved IT services
  • 25. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Example Customer Responsibility:  Guest OS  Application  Security group Amazon S3 Amazon EC2 Amazon Workspaces
  • 26. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary AWS and the customer share security responsibilities  AWS: Security of the cloud  Customer: Security in the cloud Customer has full control over security measures Customer can use AWS Service Catalog “Infrastructure” Service
  • 27. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Access Control and Management
  • 28. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM Control access to AWS resources  Authentication  Authorization Controls access to services such as: Compute Storage Database Application services
  • 29. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM Create users and groups Grant permissions User Group Permissions Role
  • 30. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM Functionality Manage  Users and their access  Roles and their permissions  Federate users and their permissions IAM Corp
  • 31. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Account Root User Account root user has complete access to all AWS Services.
  • 32. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Account Root User Recommendations 1. Delete root user access keys. 2. Create an IAM user. 3. Grant administrator access. 4. Use IAM credentials to interact with AWS. IAM
  • 33. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM: Authentication Programmatic access  Enables access key ID and secret access key Management console access  Uses AWS account name and password  MFA prompts for code
  • 34. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM: Authorization Access AWS services  Grant authorization Assign permissions  Create an AWS IAM policy
  • 35. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS IAM: Policy Assignment IAM Policy IAM User IAM Group IAM Roles
  • 36. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. IAM Best Practices Delete AWS root account access keys Activate multi-factor authentication (MFA) Give IAM users only the permissions they must have Use IAM groups Apply an IAM password policy
  • 37. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Security Resources
  • 38. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Security Resources AWS communicates security and control environment  Certifications and attestations  Whitepapers and web content  Compliance reports provided under NDA
  • 39. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Trusted Advisor Is a “customized cloud expert” Helps you follow best practices Inspects your AWS environment Helps close security gaps Finds opportunities and best practices in:  Cost optimization  Performance  Security  Fault Tolerance  Service Limits
  • 40. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Account Teams Are first point of contact Guide deployment Point toward the right resources to resolve security issues
  • 41. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Enterprise Support* 15-minute response time 24/7, by phone, chat, or email Dedicated Technical Account Manager *for details, see: https://aws.amazon.com/premiumsupport/enterprise-support/
  • 42. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Professional Services and AWS Partner Network APN has hundreds of certified AWS Consulting Partners worldwide  Help develop security policies  Help meet compliance requirements
  • 43. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Advisories and Bulletins Advisories/bulletins provided on current vulnerabilities and threats Customers work with experts to address:  Reporting abuse  Vulnerabilities  Penetration testing
  • 44. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Auditor Learning Path Understand how internal operations gain compliance on AWS Visit the compliance website:  Recommended training  Self-paced labs  Auditing resources
  • 45. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Compliance Solutions Guide Understand the Shared Responsibility Model Request a compliance report Complete a security questionnaire Services in Scope AWS Security Blog Case Studies FAQs *for details, see: https://aws.amazon.com/compliance/resources/
  • 47. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Introduction to the Well- Architected Framework
  • 48. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Introduction Assess and improve architectures Understand how design decisions impact business Learn the five pillars and design principles
  • 49. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 5 Pillars Security Reliability Performance efficiency Cost optimization Operational excellence
  • 50. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security Pillar Identity and access management (IAM) Detective controls Infrastructure protection Data protection Incident response
  • 51. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Security Pillar: Design Principles Implement security at all layers Enable traceability Apply principle of least privilege Focus on securing your system Automate
  • 52. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Reliability Pillar Recover from issues/failures Apply best practices in:  Foundations  Change management  Failure management Anticipate, respond, and prevent failures
  • 53. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Reliability Pillar: Design Principles Test recovery procedures Automatically recover Scale horizontally Stop guessing capacity Manage change in automation
  • 54. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Performance Efficiency Pillar Select customizable solutions Review to continually innovate Monitor AWS services Consider the trade-offs
  • 55. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Performance Efficiency Pillar: Design Principles Democratize advanced technologies Go global in minutes Use a serverless architectures Experiment more often Have mechanical sympathy
  • 56. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Cost Optimization Pillar Use cost-effective resources Matching supply with demand Increase expenditure awareness Optimize over time
  • 57. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Cost Optimization Pillar: Design Principles Adopt a consumption model Measure overall efficiency Reduce spending on data center operations Analyze and attribute expenditure Use managed services
  • 58. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Operational Excellence Pillar Manage and automate changes Respond to events Define the standards
  • 59. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Five pillars and their associated design principles  Security  Reliability  Performance Efficiency  Cost Optimization  Operational Excellence
  • 60. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Reference Architecture – Fault Tolerance and High Availability
  • 61. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Fault Tolerance Ability of a system to remain operational Built-in redundancy of an application’s components
  • 62. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. High Availability High availability is designed to keep Systems generally functioning and accessible Downtime minimized Minimal human intervention required Minimal up-front financial investment
  • 63. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. High Availability: On Premises vs AWS Traditional (on premises)  Expensive  Only mission-critical applications AWS  Multiple servers  Availability zones  Regions  Fault-tolerant services
  • 64. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. High Availability: AWS Services AWS Services and High Availability  Amazon S3 and Amazon Glacier  DynamoDB  Amazon CloudFront  Amazon SWF  Amazon SQS  Amazon SNS  Amazon SES  Amazon Route53  Elastic Load Balancing  IAM  Amazon CloudWatch  Amazon CloudSearch  AWS Data Pipeline  Amazon Kinesis  Auto Scaling  Amazon Elastic File System  AWS CloudFormation  Amazon WorkMail  AWS Directory Service  AWS Lambda  Amazon EBS  Amazon RDS  Amazon EC2  Amazon VPC  Amazon Redshift  Amazon ElastiCache  AWS Direct Connect *Not all services are listed here. Inherently HA services HA with the right architecture
  • 65. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. High Availability Service Tools Elastic load balancers Elastic IP addresses Amazon Route 53 Auto Scaling Amazon CloudWatch
  • 66. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Elastic Load Balancers Distributes incoming traffic (loads) Sends metrics to Amazon CloudWatch Triggers and notifies  High latency  Over used
  • 67. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Elastic Load Balancers
  • 68. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Elastic IP Addresses Are static IP addresses Mask failures (if they were to occur) Continues to access applications if an instance fails
  • 69. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Route 53 Authoritative DNS service  Translates domain names to IP addresses Supports:  Simple routing  Latency-based routing  Health checks  DNS failovers  Geo-location routing
  • 70. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Auto Scaling Terminates and launches instances Assists with adjusting or modifying capacity Creates new resources on demand
  • 71. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon CloudWatch Alarm examples:  If CPU utilization is >60% for 5 minutes…  If number of simultaneous connections is >10 for one minute…  If number of healthy hosts is <5 for 10 minutes…
  • 72. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Fault Tolerant Tools Amazon Simple Queue Service Amazon Simple Storage Service Amazon SimpleDB Amazon Relational Database Service
  • 73. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Fault Tolerant and highly available architectures Services to assist architectures
  • 74. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Reference Architecture: Web Hosting
  • 75. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Web Hosting Web hosting on AWS:  Fast  Straightforward  Low cost Common web applications:  Company website  Content management system  Social media application development  Internal SharePoint site
  • 76. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Cost Effective Alternative Leverage on-demand provisioning Eliminate wasted capacity Continuously adjust to actual traffic patterns
  • 77. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Scalable Handle unexpected traffic peaks or unexpected loads Launch new hosts in minutes Scale hosts up or down
  • 78. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. On-Demand Solution for Various Environments Provision testing fleets Develop staging in minutes Simulate use traffic
  • 79. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Migrating to AWS: Web Hosting Services Products to assist transition:  Amazon Virtual Private Cloud  Amazon Route 53  Amazon CloudFront  Elastic load balancing  Firewalls/AWS Shield  Auto Scaling  App servers/EC2 instances  Amazon ElastiCache  Amazon RDS/Amazon DynamoDB
  • 80. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Key Architectural Considerations Replace physical network appliances with software solutions Deploy firewalls everywhere Make available multiple data centers Build an ephemeral and dynamic architecture
  • 81. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary AWS and web hosting AWS web hosted services Key considerations for web hosted architectures
  • 82. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following is NOT one of the four areas of the performance efficiency pillar? Tradeoffs Selection Monitoring Traceability
  • 83. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What tool helps avoid limitations of being able to create new resources on-demand or scheduled? Route 53 Elastic load balancer Auto Scaling CloudWatch
  • 84. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check In a physical data center, security is typically considered in what area? Only in the perimeter In an edge location In the closest region In the closest availability zones
  • 85. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What is defined as the ability for a system to remain operational even if some of the components of that system fail? DNS failovers High durability High availability Fault tolerance
  • 86. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following are high availability characteristics of Amazon Route 53? (Choose 2) Latency-based routing Geo-location routing Collect and track high latency metrics Mask failure of an instance/software Terminate instances based on specified conditions
  • 87. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What design principles are recommended when considering performance efficiency? (Choose 2) Enabling traceability Democratize advanced technologies Expenditure awareness Matching supply and demand Serverless architecture
  • 88. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following cloud security controls are designed for only allowing authorized and authenticated users can access your resources? Detective controls Identity and Access Management Infrastructure protection Incident response
  • 89. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check When considering cost optimization, what model allows you to pay only for what computing resources you actually use? Consumption model Economies of scope model Economies of scale model Expenditure model
  • 90. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following describes Elastic Load Balancers (ELB)? Launches or terminates instances based on specified conditions Creates new resources on-demand Distributes incoming traffic amongst your instances Translates domain names into IP addresses
  • 91. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following is NOT considered a fault tolerant tool? S3 WAF SQS RDS
  • 92. © 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited. Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at: https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.
  • 93. Module 6: Pricing and Support Overview
  • 94. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Topics Fundamentals of Pricing Pricing Details Overview of the Total Cost of Ownership Calculator Overview of AWS Support Plans
  • 95. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Fundamentals of Pricing
  • 96. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Pricing Model Pay-as-you-go Pay less when you reserve Pay even less per unit by using more Pay even less as AWS grows
  • 97. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay-As-You-Go Pay only for the services you consume, with no large upfront expenses. Lower variable costs Pay only as long as you need the service Adapt to changing business needs Redirect focus on innovation and invention
  • 98. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay Less When You Reserve Invest in reserved instances Save up to 75% Options  All Upfront  Partial Upfront  No Upfront payments
  • 99. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay Less By Using More Realize volume-based discounts Savings as usage increases Tiered pricing for services (for example, Amazon S3, Amazon EC2) No charge for inbound data transfer Storage services options
  • 100. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay Even Less as AWS Grows As AWS grows Focuses on lowering cost of doing business Passes savings from economies of scale down to you
  • 101. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Custom Pricing Meet varying needs through custom pricing Available for high-volume projects with unique requirements
  • 102. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Free Tier AWS Free Tier helps customer get started in the cloud Limitations:  Up to one year  Certain services and options For more details, see: https://www.aws.amazon.com/free
  • 103. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. No Extra Charge AWS services for no additional charge: Amazon VPC AWS Elastic Beanstalk AWS CloudFormation AWS IAM Auto Scaling
  • 104. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Pay only for what you use Start and stop anytime No long-term contracts required
  • 105. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pricing Details
  • 106. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Fundamentals Pay for AWS fundamentals:  Compute  Storage  Outbound data transfer No charge:  Inbound data transfer Charge for aggregated outbound
  • 107. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Service Pricing for AWS Offerings Amazon EC2 Amazon S3 Amazon EBS Amazon RDS Amazon CloudFront
  • 108. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2 Provide resizable compute capacity in the cloud Allows the configuration of capacity with minimal friction Provides complete control Charges only for capacity used
  • 109. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2: Billing and Instance Configuration Clock-Second/Hourly Billing Resources incur charges only when running Instance Configuration Physical capacity of the instance Pricing varies with:  AWS region  OS  Instance Type  Instance Size
  • 110. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2: Purchase Types Ways to pay for Amazon EC2 instances On-demand instances  Compute capacity by the hour and second  Minimum of 60 seconds Reserved Instances  Low or no up-front payment instances reserved  Discount on hourly charge for that instance Spot Instances  Bid for unused Amazon EC2 capacity
  • 111. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2: Number of Instances and Load Balancing Number of Instances Provision multiple instances to handle peak loads Load Balancing Uses Elastic Load Balancing to distribute traffic Calculates monthly cost based on  Hours load balancer runs  Data load balancer processes
  • 112. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2: Monitoring Use Amazon CloudWatch to monitor instances. Basic monitoring (default) Detailed monitoring  Fixed monthly rate  Prorated partial months
  • 113. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2 Auto Scaling Automatically adjusts number of instances Incurs no additional charge Elastic IP Addresses No charge for one Elastic IP address associated with a running instance.
  • 114. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EC2: OS and Software Pricing for operating systems and software packages: Includes OS prices in instance prices Partners with other vendors for certain software Requires licenses from vendors for other software Brings existing license through specific vendor programs
  • 115. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon S3: Storage Classes Types of storage classes Standard Storage  99.999999999% durability  99.99% availability Standard-Infrequent Access (S-IA)  99.999999999% durability  99.9% availability
  • 116. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon S3: Storage Considerations for estimating storage cost  The number and size of objects  Type of storage
  • 117. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon S3 Requests: Pricing based on Number of requests Type of requests  Different rates for GET requests Data Transfer Pricing based on the amount of data transferred out of the Amazon S3 region
  • 118. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EBS Block-level storage for instances EBS volumes persist independently from the instance Analogous to virtual disks in the cloud Three volume types:  General Purpose (SSD)  Provisioned IOPS (SSD)  Magnetic
  • 119. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EBS: Volumes and IOPS Volumes All volume types are charged by the amount provisioned per month IOPS General Purpose (SSD)  Included in price Magnetic  Charged by the number of requests Provisioned IOPS (SSD)  Charged by the amount you provision in IOPS
  • 120. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon EBS: Snapshots and Data Transfer Snapshots Added cost of EBS snapshots to Amazon S3 is per GB-month of data stored Data Transfer Inbound data transfer has no charge Outbound data transfer charges are tiered
  • 121. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon RDS Relational database in the cloud Cost-efficient and resizable capacity Management of time-consuming administrative tasks
  • 122. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon RDS: Clock-Hour Billing and Database Characteristics Clock-Hour Billing Resources incur charges when running Database Characteristics Physical capacity of database:  Engine  Instance Type  Instance Size
  • 123. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon RDS: DB Purchase Type and Multiple DB Instances DB Purchase Type On-demand database instances  By the hour Reserved database instances  Up-front payment for database instances reserved Multiple DB Instances Provision multiple DB instances to handle peak loads
  • 124. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon RDS: Storage Provisioned Storage No charge  Backup storage of up to 100% of database storage Charge (GB/month)  Backup storage for terminated DB instances Additional Storage Charge (GB/month)  Backup storage in addition to provisioned storage
  • 125. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon RDS: Deployment Type and Data Transfer Storage and I/O charges vary depending on deployment type Single Availability Zones Multiple Availability Zones Data Transfer No charge for Inbound data transfer Tiered charges for outbound data transfer
  • 126. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon CloudFront Web service for content delivery Integration with other AWS services  Low latency  High data transfer speeds  No minimum commitments
  • 127. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon CloudFront: Traffic Distribution Pricing Vary across geographic regions
  • 128. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon CloudFront: Requests and Data Transfer Out Requests Pricing based on Number/type of requests Geographic region Data Transfer Out Pricing is based on the amount of data transferred out of Amazon CloudFront edge locations
  • 129. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Fundamental characteristics of product Estimate usage Map usage to prices
  • 130. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Overview of the Total Cost of Ownership Calculator
  • 131. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS TCO Calculator Use the TCO calculator to Estimate cost savings Use detailed reports Modify assumptions Accessing the TCO Calculator: https://awstcocalculator.com
  • 132. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Estimate cost savings Use detailed set of reports Modify assumptions for business needs
  • 133. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Overview of AWS Support Plans
  • 134. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Support Provide unique combination of tools/expertise  AWS Support  AWS Support Plans
  • 135. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Support Support is provided for Experimenting with AWS Production use of AWS Business critical use of AWS
  • 136. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Support Proactive guidance  Technical Account Manager (TAM) Best practices  Trusted Advisor Account assistance  AWS Support Concierge
  • 137. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Support Plans AWS Support offers four support plans: Basic Support Developer Support Business Support Enterprise Support
  • 138. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary AWS Support AWS Support Plans  Basic Support plan  Developer Support plan  Business Support plan  Enterprise Support plan
  • 139. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check When calculating the cost of Amazon EC2, what factors will impact pricing? (Choose 2) Number of items in your inbound data transfer Number and size of objects stored in your Amazon S3 buckets Number of instances Number of seconds and hours Elastic Load Balancer runs
  • 140. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What charges apply to data transfer across AWS? (Choose 2) No charge for inbound data transfer across all Amazon Web Services in all regions No charge for outbound data transfer across all Amazon Web Services in all regions No charge for inbound data transfer for EC2 instances No charge for outbound data transfer between Amazon Web Services within the same region No charge for inbound data transfer between Amazon Web Services within the same region
  • 141. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check As AWS grows, the general cost of doing business is reduced and savings are passed back to the customer in the form of lower pricing. What is this cost optimization called? Economies of scope Economies of labor Economies of scale Economies of cost Economies of optimization
  • 142. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What type of applications are recommended for Amazon EC2 reserved instances? Applications that are only feasible at lower compute prices Applications that have flexible start and end times Applications with steady state or predictable usage Applications being developed or tested for the first time
  • 143. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What are the characteristics of the Developer Support Plan? (Choose 2) One primary contact may open a case Unlimited contacts may open a case Business hours access to cloud support associates via email 24/7 access to cloud support engineers via email, chat, and phone Assigned to a Technical Account Manager
  • 144. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What is NOT a consideration when estimating the cost of Amazon S3? Number and size of objects Storage class Requests Input Output Operations per Second (IOPS) Data transfer
  • 145. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check With the “Pay as you go” pricing model, how often do you pay for compute resources from the time you launch a resource until you terminate it? Quarterly Yearly Monthly Daily Secondly and Hourly
  • 146. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check What AWS tool compares the cost of running your application in an on-premise data center to AWS? Total Cost of Operation (TCO) Calculator Total Cost of Application (TCA) Calculator Total Cost of Services (TCS) Calculator Total Cost of Products (TCP) Calculator Total Cost of Ownership (TCO) Calculator
  • 147. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Knowledge Check Which of the following is NOT available in the Business Support Plan? Access to Personal Health Dashboard and Health API Access to cloud support engineers for technical issues Access to Infrastructure Event Management Access to third-party software support Access to Well-Architected review delivered by AWS Solution Architects
  • 148. © 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited. Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at: https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.
  • 149. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. With deep expertise on AWS, APN Partners can help your organization at any stage of your Cloud Adoption Journey. AWS Managed Service Providers APN Consulting Partners who are skilled at cloud infrastructure and application migration, and offer proactive management of their customer’s environment. AWS Competency Partners APN Partners who have demonstrated technical proficiency and proven customer success in specialized solution areas. AWS Service Delivery Partners APN Partners with a track record of delivering specific AWS services to customers. Ready to get started with an APN Partner? Find a partner: https://aws.amazon.com/partners/find/ AWS Marketplace A digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on AWS.
  • 151. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Congratulations You have completed AWS Cloud Practitioner Essentials
  • 152. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summary Section 1: AWS Cloud Concepts Section 2: AWS Core Services Section 3: AWS Security Section 4: AWS Architecting Section 5: AWS Pricing and Support
  • 153. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Course Feedback
  • 154. Thank you for participating! © 2018 Amazon Web Services, Inc. or its affiliates. All rights reserved. This work may not be reproduced or redistributed, in whole or in part, without prior written permission from Amazon Web Services, Inc. Commercial copying, lending, or selling is prohibited. Corrections or feedback on the course, please email us at: aws-course-feedback@amazon.com. For all other questions, contact us at: https://aws.amazon.com/contact-us/aws-training/. All trademarks are the property of their owners.