🌐 Networking
🌍 AWS Global Infrastructure
Region
“An AWS Region is a separate geographic area containing multiple isolated Availability Zones. I choose a Region based on latency to users, service availability, compliance/data residency, and cost.”
Availability Zone — AZ
“An Availability Zone is one or more discrete data centers within an AWS Region, designed with independent power, networking, and connectivity. I distribute production workloads across multiple AZs to protect against AZ-level failures.”
Interview distinction: Region = geographic boundary AZ = isolated infrastructure within a Region
VPC
“Amazon VPC is a logically isolated network in AWS where I control IP addressing, subnets, routing, and network security. I use it to design secure and highly available application networks, typically distributing workloads across multiple Availability Zones.”
Interview keyword: isolation + control + multi-AZ.
Public vs Private Subnets
“A public subnet has a route to an Internet Gateway, whereas a private subnet does not have direct inbound internet access. I typically place load balancers in public subnets and application servers and databases in private subnets.”
Important: A subnet is not inherently public/private; its route table determines that.
Route Tables
“A route table determines where network traffic goes from a subnet. For example, public subnets typically have a default route to an Internet Gateway, while private subnets may route outbound internet traffic through a NAT Gateway.”
Think: Route table = traffic decision maker.
Internet Gateway — IGW
“An Internet Gateway provides internet connectivity between a VPC and the internet. It is horizontally scaled and highly available, and I typically use it for resources in public subnets that need internet connectivity.”
NAT Gateway
“A NAT Gateway allows resources in private subnets to initiate outbound internet connections without allowing unsolicited inbound internet connections. For high availability, I generally deploy a NAT Gateway per Availability Zone.”
Classic question:
Why NAT instead of IGW?
“Because private workloads should not be directly reachable from the internet.”
Security Groups vs NACLs
| Security Group | NACL |
|---|---|
| Resource level | Subnet level |
| Stateful(Return traffic automatically allowed) | Stateless(Return traffic must be explicitly allowed) |
| Allow rules only | Allow + Deny |
| Primary workload security control | Additional subnet-level control |
Interview answer:
“I use Security Groups as the primary stateful firewall for workloads. NACLs provide an additional stateless security layer at the subnet boundary.”
VPC Endpoints
“VPC endpoints allow private connectivity from a VPC to supported AWS services without traversing the public internet. I use them to improve security and potentially reduce NAT Gateway data-processing costs.”
Know:
ALB
“Application Load Balancer operates at Layer 7 and is designed for HTTP/HTTPS traffic. I use it when I need host-based or path-based routing, such as routing
/apiand/ordersto different target groups.”
NLB
“Network Load Balancer operates at Layer 4 and is designed for high-performance TCP, UDP, or TLS workloads where very high throughput, low latency, or static IP requirements are important.”
Simple distinction:
ALB = application-aware HTTP routing. NLB = high-performance network-level load balancing.
Route 53
“Amazon Route 53 is AWS's highly available DNS service. I use it for domain resolution, health checks, and routing policies such as weighted, latency-based, failover, and geolocation routing.”
VPC Peering
“VPC Peering provides private network connectivity between two VPCs using AWS's network. It's useful for simpler point-to-point connectivity, but it doesn't provide transitive routing.”
Key phrase:
No transitive routing.
Transit Gateway
“Transit Gateway acts as a central network hub connecting multiple VPCs and on-premises networks. I prefer it over a large mesh of VPC peering connections because it simplifies network architecture and routing at scale.”
VPN
“AWS Site-to-Site VPN provides encrypted connectivity between an on-premises network and AWS over the internet. It's relatively quick to deploy and is commonly used for hybrid connectivity or as a backup connection.”
Direct Connect
“AWS Direct Connect provides a dedicated private network connection between on-premises and AWS. I use it when I need more consistent network performance, higher bandwidth, or predictable latency compared with internet-based VPN.”
Remember:
VPN = encrypted over internet Direct Connect = dedicated connectivity
🖥️ Compute
EC2
“Amazon EC2 provides resizable virtual servers in AWS. I use it when I need operating-system-level control, custom configurations, or workloads that aren't well suited to serverless or managed container services.”
Auto Scaling
“EC2 Auto Scaling automatically adjusts the number of instances based on demand or policies. I use it to maintain availability during failures and dynamically handle changing workloads while controlling cost.”
Load Balancers
“Elastic Load Balancing distributes incoming traffic across healthy targets and improves availability and scalability. I select ALB for Layer-7 HTTP routing and NLB for Layer-4 high-performance workloads.”
Lambda
“AWS Lambda is a serverless, event-driven compute service where AWS manages the underlying infrastructure. I use it for short-running, event-driven workloads where I want automatic scaling without managing servers.”
Interview caveat:
“I wouldn't choose Lambda simply because it's serverless; I'd validate execution duration, runtime, concurrency, latency, and workload characteristics first.”
ECS
“Amazon ECS is AWS's managed container orchestration service. I use it when I want to run containerized applications without managing Kubernetes complexity.”
Fargate
“AWS Fargate is a serverless compute engine for containers. It lets me run ECS or EKS workloads without managing EC2 instances.”
Think:
ECS = orchestration Fargate = serverless compute for containers
EKS
“Amazon EKS is AWS's managed Kubernetes service. I use it when the organization requires Kubernetes capabilities, portability, or an existing Kubernetes ecosystem, while AWS manages the Kubernetes control plane.”
Interview point:
Don't choose EKS just because it's more powerful. Kubernetes introduces operational complexity.
💾 Storage
S3
“Amazon S3 is highly durable object storage designed for virtually unlimited scale. I use it for unstructured data such as documents, images, backups, logs, data lakes, and static assets.”
Key phrase:
Object storage, not a traditional filesystem.
EBS
“Amazon EBS provides persistent block storage for EC2. I use it when an application needs low-latency block-level storage, such as operating systems, databases, or transactional workloads.”
EFS
“Amazon EFS is a managed, elastic NFS file system that can be mounted by multiple compute instances. I use it when multiple workloads need shared file-system access.”
Simple:
EBS → block EFS → shared file system S3 → object
S3 Storage Classes
Interview answer:
“I select S3 storage classes based on access frequency and retrieval requirements. S3 Standard is for frequently accessed data, while Intelligent-Tiering automatically optimizes storage cost based on access patterns. For infrequently accessed data I consider Standard-IA or One Zone-IA, and for archival workloads I use Glacier classes.”
Don't memorize every class unless specifically asked.
Lifecycle Policies
“S3 Lifecycle policies automatically transition objects between storage classes or expire them based on rules. I use them to reduce storage costs without requiring application changes.”
Example:
Logs → Standard → IA → Glacier → Expire
🗄️ Databases
RDS
“Amazon RDS is a managed relational database service that handles tasks such as provisioning, backups, patching, and maintenance. I use it when the application needs SQL, relational data modeling, and transactional capabilities.”
Aurora
“Amazon Aurora is a cloud-optimized relational database compatible with MySQL and PostgreSQL. I consider it when I need higher performance, availability, and scalability than a traditional managed relational database can provide.”
DynamoDB
“Amazon DynamoDB is a fully managed NoSQL database designed for low-latency performance at scale. I use it when the application has well-defined access patterns and requires horizontal scalability without managing database servers.”
Important:
Design DynamoDB around access patterns, not around traditional relational normalization.
ElastiCache
“Amazon ElastiCache provides managed in-memory caching using engines such as Redis OSS and Memcached. I use it to reduce database load and improve application latency for frequently accessed data.”
Typical architecture:
Application → ElastiCache → Database
Read Replicas vs Multi-AZ
This is a very common interview question.
“Multi-AZ is primarily for high availability and failover, whereas Read Replicas are primarily for read scalability.”
Remember:
Multi-AZ → availability
Read Replica → read scaling
Relational vs NoSQL
“I choose relational databases when I need structured relationships, SQL, joins, and strong transactional consistency. I consider NoSQL when I need massive horizontal scalability, predictable low latency, flexible schemas, or application-specific access patterns.”
Don't say:
NoSQL is faster.
Say:
“The choice depends on access patterns, consistency requirements, scalability, and data relationships.”
🔐 Security
IAM
“AWS IAM controls authentication and authorization to AWS resources. I use IAM policies to implement least-privilege access and avoid unnecessary permissions.”
IAM Roles
“IAM Roles provide temporary credentials that AWS services, applications, or users can assume. I prefer roles over embedding long-lived AWS access keys in applications.”
Excellent interview phrase:
“Applications should use IAM roles rather than hard-coded credentials.”
KMS
“AWS KMS is a managed key-management service used to create and control encryption keys. I use it to encrypt data at rest and control access to encryption keys through IAM and key policies.”
Secrets Manager
“AWS Secrets Manager securely stores and manages sensitive credentials such as database passwords and API keys. It can also automatically rotate supported secrets.”
Difference:
KMS → encryption keys Secrets Manager → secrets/credentials
WAF
“AWS WAF is a web application firewall that protects HTTP/HTTPS applications from common web attacks and unwanted traffic using configurable rules.”
Think:
Layer 7 protection.
Shield
“AWS Shield provides protection against DDoS attacks. Shield Standard provides automatic protection for common network and transport-layer attacks, while Shield Advanced provides enhanced protection and additional capabilities.”
CloudTrail
“AWS CloudTrail records API activity and account actions, allowing me to answer who performed what action, when, and from where. I use it primarily for auditing, security investigations, and compliance.”
Think:
CloudTrail = API activity/audit
GuardDuty
“Amazon GuardDuty is a threat-detection service that continuously analyzes AWS activity and related data sources to identify potentially malicious or suspicious behavior.”
Think:
GuardDuty = threat detection
AWS Organizations / SCP
“AWS Organizations lets me centrally manage multiple AWS accounts. Service Control Policies, or SCPs, define the maximum permissions available to accounts or organizational units; they don't grant permissions themselves.”
Very important interview point:
SCP is a permission boundary at the organization/account level, not an IAM permission grant.
🔄 Migration
AWS DMS — Database Migration Service
“AWS DMS helps migrate databases to AWS with minimal downtime. It supports ongoing replication, so I can keep the target synchronized while the source remains operational and then perform a controlled cutover.”
Interview keywords: migration + replication + minimal downtime.
Migration Hub
“AWS Migration Hub provides a centralized view of migration progress across applications and migration tools. I use it to track and coordinate migrations rather than performing the migration itself.”
Application Migration Service — MGN
“AWS Application Migration Service helps lift and shift physical, virtual, or cloud servers into AWS with automated replication and conversion to run on AWS. I use it when the goal is to migrate servers with minimal application changes.”
Think: MGN = server migration
Application Discovery Service
“AWS Application Discovery Service collects information about on-premises servers, configurations, utilization, and dependencies. I use it during migration planning to understand the existing environment and identify application dependencies before moving workloads.”
Think: Discovery = understand before migrating
🤖 Generative AI
Amazon Bedrock
“Amazon Bedrock is a managed service that provides access to foundation models through APIs, allowing me to build generative AI applications without managing the underlying model infrastructure.”
For an architecture interview, add:
“I can combine Bedrock with enterprise data, retrieval, guardrails, IAM, and monitoring to build secure GenAI applications.”
Think: Bedrock = build GenAI applications using foundation models without managing model infrastructure.
Amazon Q
“Amazon Q is AWS's generative AI assistant designed for enterprise use cases, including helping developers with software development and helping employees interact with business information.”
Interview distinction:
Bedrock → build your own GenAI applications Amazon Q → use an AWS-managed generative AI assistant for specific enterprise/developer use cases
📨 Event-Driven Architecture
SNS
“Amazon SNS is a pub/sub messaging service used to fan out messages to multiple subscribers. I use it when one event needs to notify or trigger multiple downstream consumers.”
Think: SNS = fan-out
SQS
“Amazon SQS is a managed message queue that decouples producers from consumers. I use it to absorb traffic spikes, process work asynchronously, and improve resilience between application components.”
Think: SQS = queue + decoupling
EventBridge
“Amazon EventBridge is a serverless event bus that routes events between applications and AWS services based on rules. I use it when I need loosely coupled event-driven architectures across different systems.”
Think: EventBridge = event routing
Step Functions
“AWS Step Functions orchestrates multiple services and long-running workflows using state machines. I use it when a business process has multiple steps, retries, branching, or error-handling requirements.”
Example:
Order → Payment → Inventory → Shipping → Notification
🔥 SNS vs SQS vs EventBridge
This is worth memorizing:
“SNS is primarily for pub/sub and fan-out, SQS is for reliable asynchronous queuing and decoupling, while EventBridge is for event routing between distributed applications and services based on event patterns.”
📊 Observability
CloudWatch
“Amazon CloudWatch provides metrics, logs, alarms, dashboards, and monitoring for AWS resources and applications. I use it to detect performance issues, trigger alerts, and understand application health.”
CloudTrail
Already covered — API activity, auditing, and governance.
X-Ray
“AWS X-Ray provides distributed tracing for applications, helping me trace requests across services and identify latency bottlenecks, errors, and dependencies.”
Example:
X-Ray helps identify where the request is spending time or failing.
CloudWatch Insights
“CloudWatch Logs Insights lets me interactively query and analyze application and infrastructure logs. I use it during troubleshooting to identify patterns, errors, and operational issues without manually searching large log files.”
Observability interview answer
“I use CloudWatch for metrics, logs, alarms, and dashboards; CloudTrail for AWS API auditing; and X-Ray for distributed request tracing. Together they give me infrastructure, security, and application-level visibility.”
💰 Cost Optimization
Compute Optimizer
“AWS Compute Optimizer analyzes resource utilization and provides recommendations for right-sizing compute resources such as EC2, EBS, Lambda, and other supported resources. I use it to identify over-provisioned or under-utilized resources.”
Think: Compute Optimizer = right-sizing recommendations
Cost Explorer
“AWS Cost Explorer provides interactive analysis of AWS costs and usage over time. I use it to identify spending trends, cost drivers, and opportunities for optimization.”
AWS Budgets
“AWS Budgets allows me to define cost and usage thresholds and receive alerts when spending approaches or exceeds those thresholds.”
Think: Budget = proactive cost alert
Spot Instances
“Spot Instances use spare AWS compute capacity at discounted prices, but they can be interrupted. I use them for fault-tolerant and flexible workloads such as batch processing, big-data workloads, and stateless scalable applications.”
Don't use Spot blindly for:
critical workloads that cannot tolerate interruption.
Reserved Instances
“Reserved Instances provide discounted pricing in exchange for a commitment to a specific configuration and term. I consider them when I have predictable, steady-state workloads.”
Savings Plans
“Savings Plans provide discounted pricing in exchange for a commitment to a consistent amount of compute usage over a term. They generally provide more flexibility than committing to a specific instance configuration.”
Cost Optimization interview answer
“I first identify the major cost drivers using Cost Explorer, then right-size resources using Compute Optimizer, use Auto Scaling for variable workloads, evaluate Savings Plans or Reserved Instances for predictable workloads, and use Spot for interruption-tolerant workloads. For storage, I also use lifecycle policies and appropriate storage classes.”
📈 Analytics
AWS Glue
“AWS Glue is a serverless data integration and ETL service. I use it to discover, catalog, transform, and move data between data sources for analytics workloads.”
Think: Glue = ETL + Data Catalog
EMR
“Amazon EMR is a managed big-data platform for frameworks such as Spark and Hadoop. I use it when I need large-scale distributed data processing and more control over the underlying big-data environment.”
Think: EMR = big-data processing
Athena
“Amazon Athena is a serverless interactive query service that lets me analyze data directly in S3 using SQL, without managing database infrastructure.”
Classic architecture:
S3 → Athena → SQL analysis
QuickSight
“Amazon QuickSight is a managed business intelligence service used to create dashboards, visualizations, and reports from data sources.”
Think: QuickSight = BI / dashboards
Kinesis
“Amazon Kinesis is used for real-time streaming data ingestion and processing. I use it when applications need to process continuously generated data such as logs, telemetry, clickstreams, or IoT events.”
Analytics architecture answer
“For a typical data lake, I could ingest streaming data using Kinesis, store raw data in S3, use Glue for cataloging and ETL, query the data with Athena, and expose business insights through QuickSight. For large-scale distributed processing requirements, I would consider EMR.”
🚀 DevOps
CloudFormation
“AWS CloudFormation is Infrastructure as Code for AWS resources. I use templates to provision infrastructure consistently, repeatably, and in an automated manner rather than manually creating resources.”
Important interview keywords:
- Infrastructure as Code
- repeatability
- consistency
- automation
- version control
- stack management
🧩 Very Important Architecture Combinations
For the interview, don't learn these services independently. Learn how they fit together.
1. Highly Available Application
Route 53 → ALB → Auto Scaling → EC2 → RDS/Aurora
2. Serverless
3. Event-Driven
Producer → EventBridge/SNS → SQS → Consumer
4. GenAI / RAG
Application → Bedrock → Retrieval/Knowledge Store → Enterprise Data
5. Data Lake
Kinesis → S3 → Glue → Athena → QuickSight
6. Hybrid Migration
On-Premises → VPN/Direct Connect → AWS
For servers:
Application Discovery → MGN → AWS
For databases:
Source DB → DMS → Target DB
7. Observability
CloudWatch → Metrics/Logs/Alarms CloudTrail → API Audit X-Ray → Distributed Tracing
8. Cost Optimization
Cost Explorer → identify cost drivers Compute Optimizer → right-size Savings Plans/RIs → predictable workloads Spot → fault-tolerant workloads Budgets → spending alerts
🧠 The 20-second AWS Architecture answer
When the interviewer asks:
“How would you design a secure, highly available AWS application?”
You can articulate:
“I would start by clarifying availability, scalability, latency, security, compliance, RTO/RPO, and cost requirements. I would typically use a multi-AZ VPC with public subnets for the load balancer and private subnets for application workloads and databases. Route 53 would provide DNS, and an ALB would distribute HTTP traffic across healthy application instances or containers. I'd use Auto Scaling for compute elasticity, and RDS/Aurora with Multi-AZ for relational workloads. S3 would handle object storage, while ElastiCache could reduce database load. I'd apply IAM least privilege, KMS encryption, Secrets Manager for credentials, WAF for application-layer protection, CloudTrail for auditing, and GuardDuty for threat detection. Finally, I'd validate observability, disaster recovery, and cost optimization against the business requirements.”
That is the tone I want you to use in your AWS interview: requirements → design → reasoning → trade-offs, rather than simply listing AWS services.
