Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
SAP-C02 · ProfessionalSolutions Architect - Professional
  • Week 1
    • 1.The Game Called the SAP Exam: Hands-On Techniques for Decomposing Scenarios
    • 2.IAM, STS, and Federation: Splitting the Word "Permission" into Six Layers
    • 3.The Anatomy of a VPC: What Route Tables Really Decide
    • 4.Four Compute Pillars in Depth: Revisiting Nitro, EBS, ELB, and Auto Scaling Through a Pro Lens
    • 5.Week 1 Integration: When IAM, VPC, and EC2 Meet in a Single Scenario
  • Week 2
    • 1.AWS Organizations: A New Unit of Thought for Multi-Account Architecture
    • 2.Service Control Policy: The Ceiling as a Thinking Tool
    • 3.Control Tower and Landing Zone: Automating Governance
    • 4.IAM Identity Center, Permission Set, Consolidated Billing: Multi-Account SSO Standard
    • 5.Week 2 Integration: When Organizations·SCP·CT·IDC Meet in One Scenario
  • Week 3
    • 1.Share TGW via RAM from network account
    • 2.Cisco Router Example (BGP route-map)
    • 3.Create Customer Gateway (on-premises router IP and ASN)
    • 4.Interface Endpoint supported service examples
    • 5.Day 5
  • Week 4
    • 1.AWS Outposts, Local Zones, Wavelength: Extending the Cloud at the Boundary
    • 2.Storage Gateway 4 Types Comparison: Extending On-Premises Storage to the Cloud
    • 3.Snow Family and Large-Scale Data Transfer: The Moment Physics Beats the Internet
    • 4.EKS Anywhere, ECS Anywhere, Hybrid Containers: Extending Orchestration Boundaries
    • 5.Week 4 Review: Comprehensive Hybrid Cloud Architecture
  • Week 5
    • 1.Multi-Region Architecture: Why Global Distribution Is Difficult
    • 2.7 Route 53 Routing Policies: DNS Determines Architecture
    • 3.CloudFront Advanced: Why CDN Is More Than Simple Caching
    • 4.Route 53 Advanced: Health Check Algorithms, DNSSEC, Geoproximity Math, Hybrid DNS Resolver
    • 5.Week 5 Review: Global Architecture Integrated Scenarios
  • Week 6
    • 1.7R Migration Strategies: Decision Language for Cloud Migration
    • 2.AWS MGN Deep Dive: Physics of Block-Level Replication, DRS Comparison, Migration Hub Orchestrator
    • 3.AWS DMS + SCT: The Science of Database Migration
    • 4.Migration Acceleration Tools: App2Container, MAP, Migration Hub
    • 5.Week 6 Review: Integrated Migration Strategy Scenarios
  • Week 7
    • 1.Container Orchestration Crossroads: The Real Criteria for Choosing ECS, EKS, Fargate
    • 2.Inside EKS — Node Groups, IRSA, Karpenter Set the Operations Standard
    • 3.Fargate Cost Anatomy — Serverless Container's Real Price Tag
    • 4.Service Mesh Anatomy — App Mesh, Service Connect, Cloud Map Divergence
    • 5.Week 7 Synthesis — Container Scenario Practice 12 Questions
  • Week 8
    • 1.Day 1
    • 2.Day 2
    • 3.EventBridge: Unified Model of Event Bus, Pipes, and Scheduler
    • 4.AppSync GraphQL and the Essence of SQS/SNS/Kinesis Messaging
    • 5.Week 8 Comprehensive — 12 Serverless & Event Architecture Scenarios
  • Week 9
    • 1.Data Lake Architecture: Internal Operations and Cost Models of S3, Glue, Athena
    • 2.Redshift Deep Dive: MPP Internal Operations, RA3 Storage Separation, Spectrum and Zero-ETL
    • 3.EMR, Glue, MWAA: Big Data Orchestration and Distributed Processing Engines
    • 4.Lake Formation, Data Governance, MSK: Fine-Grained Permissions and Real-Time Streams Under the Hood
    • 5.Week 9 Comprehensive Review: Data Architecture as One Picture
  • Week 10
    • 1.SageMaker Deep Dive: ML Lifecycle, 4 Types of Inference Endpoints, Training Cost Math
    • 2.Bedrock Deep Dive: Generative AI Architecture, RAG Internals, Vector Search Math
    • 3.Managed AI Services Deep Dive: Pre-trained AI Selection Logic and Sync/Async Patterns
    • 4.MLOps Deep Dive: Science of Drift, Feature Store, Automated Retraining Pipelines
    • 5.Week 10 Comprehensive Review: ML/AI Architecture Decision-Making + 12 Scenario Problems
  • Week 11
    • 1.Day 1
    • 2.Detection Trinity: Internal Operations of Macie·GuardDuty·Inspector and Threat Detection
    • 3.Integrated Monitoring: Security Hub·Detective·Audit Manager Roles and Responsibilities
    • 4.Edge Security: WAF·Shield·Firewall Manager and Layered DDoS Defense
    • 5.Integrated Security: Encryption·Detection·Unified Monitoring·Edge Defense in One Scenario
  • Week 12
    • 1.Savings Plans·RI Strategy — Commitment Discount Math, Application Order Internal Operations, Organization Sharing
    • 2.Day 2
    • 3.Cost Explorer·Budgets·CUR — Layers of Cost Visibility, Budget Auto-Control, FinOps Data Pipeline
    • 4.Hidden Cost Anatomy — S3 Storage Tiers, Data Transfer Fee Structure, NAT Gateway Traps
    • 5.Integrated Cost Optimization: Commitment Economics and Hidden Cost Trade-Offs
  • Week 13
    • 1.Day 1
    • 2.Operational Excellence & Security Pillars Deep Dive — GitOps Roots, Shared Responsibility Model Boundaries, Three Types of Traceability Internals
    • 3.Reliability & Performance Efficiency Pillars Deep Dive — CAP Theorem, Idempotency and Retry Mathematics, HPC Networking Physics
    • 4.Cost & Sustainability Pillars Deep Dive — Unit Economics, Regulatory Roots of Carbon Accounting, Trade-Offs Between Two Pillars
    • 5.Well-Architected Comprehensive Review: Distilling Six Pillars Into One Scenario
  • Week 14
    • 1.Four DR Strategies and RTO/RPO Mapping — History of Disaster Recovery, Physics of Sync/Async Replication, Cloud DR Economics
    • 2.Backup: AWS Backup & Cross-Region Copy — Legal Origins of WORM, Vault Lock Irreversibility, Multi-Account Backup Governance
    • 3.Resilience Hub & Fault Injection Simulator — Birth of Chaos Engineering, Stop Condition's Safety Engineering, DR Verification Automation
    • 4.RDS, Aurora, DynamoDB Global DR — Sync/Async Replication Internals, Aurora Storage Architecture, Active-Active Conflict Resolution
    • 5.Resilience and DR Comprehensive Review: Four Strategies Honoring RTO/RPO and Validation Tools
  • Week 15
    • 1.Enterprise Global ERP Migration — Multi-Account Governance History, 7R Migration Anatomy, Data Sovereignty Legal & Technical Roots
    • 2.Startup Serverless-First Architecture — Cost-Zero Scaling, No Ops Overhead, Function Composition Limits
    • 3.Financial Services Compliance & Real-Time Settlement — FINRA/SOX/PCI-DSS Audit, Active-Active Multi-Region, Zero Data Loss
    • 4.Media & Entertainment Streaming — PB-Scale Global CDN, Real-Time Analytics, Cost Efficiency
    • 5.Healthcare & Public Sector — HIPAA/GxP/FEDRAMP, Immutable Audit, Highly Regulated Compliance
  • Week 16
    • 1.Well-Architected Framework Synthesis — 6 Pillars Integrated, Trade-offs Across Domains
    • 2.Exam Strategy & Question Patterns — Recognizing Trade-offs, Ruling Out Decoys, Time Management
    • 3.Cost Optimization Deep Dive — Reserved Capacity, Commitment Discounts, Unit Economics
    • 4.Migration & Rehost Strategies — 7Rs in Practice, Time + Data Volume Trade-offs
    • 5.Final Review & Exam Simulation — Full-Stack Scenario, Trade-off Decision Under Constraints
DOP-C02 · ProfessionalDevOps Engineer - Professional
SCS-C03 · SpecialtySecurity - Specialty
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← SAP-C02/Week 1/Day 5
SAP-C02· ProWeek 1 · Day 5~36 min read

Day 5 - Week 1 Integration: When IAM, VPC, and EC2 Meet in a Single Scenario

On the Pro exam, questions that ask about only a single service are practically nonexistent. Whatever scenario unfolds, IAM (who is accessing), VPC (where it flows), and EC2/EBS/ELB (what processes that traffic) appear simultaneously. So today we revisit the three areas we studied separately during the week in the way they meet within a single scenario. This is the real way of thinking that works on the exam floor.

Today's article has three parts.

  1. 40 one-line summaries of Week 1: facts that must surface within 0.5 seconds in the exam room.
  2. The 3-layer method: the hands-on technique of decomposing scenarios into IAM ⇒ VPC ⇒ Compute.
  3. 12 scenario questions: Pro difficulty, 30 minutes of solving time.

Practice these three as one bundle, and when you meet a scenario in the exam room your hands will move first. The "5-step decomposition" from Day 1 fires in your head within 5 seconds, and those 5 steps flow again into the 3 layers of IAM-VPC-Compute.

40 One-Line Summaries of Week 1

Exam Strategy (1-5)

  1. SAP-C02 = 75 questions / 180 minutes / 750 to pass; ESL +30 minutes can be requested (210 minutes total).
  2. 5-step scenario decomposition: WHO · WHAT · WHY · CONSTRAINTS · KEYWORD. The adjective in the last sentence decides the answer.
  3. Four elimination patterns for the 4 options: over-engineering / under-engineering / build-it-yourself / wrong combination.
  4. The 3-2-2 rule: under 3 minutes per question, change your answer at most 2 times, flag if unsolved within 2 minutes.
  5. The first-instinct fallacy — statistically, changed answers are wrong more often. Without solid grounds, keep your first intuition.

IAM·STS·Federation (6-15)

  1. 6 layers of permission evaluation: SCP → Permission Boundary → Identity Policy → Resource Policy → Session Policy → VPC Endpoint Policy. If any one of the 6 layers denies, it's blocked; all must allow to pass.
  2. An explicit deny beats every allow — a single explicit Deny is the end.
  3. Cross-account access requires Allow on both sides (Trust Policy + Resource Policy or Identity Policy).
  4. SCPs and Permission Boundaries have deny-only semantics — they grant no permissions, they only set a ceiling.
  5. The 5 STS operations: AssumeRole / AssumeRoleWithSAML / AssumeRoleWithWebIdentity / GetFederationToken / GetSessionToken.
  6. ExternalId prevents the confused deputy attack — mandatory for SaaS third-party access, specified in the Trust Policy.
  7. GitHub Actions → AWS uses OIDC + AssumeRoleWithWebIdentity (no long-lived keys needed); restrict repo/branch via the sub claim in the Trust Policy.
  8. Multi-account SSO is IAM Identity Center + Permission Sets, with automatic sync via SCIM (RFC 7644).
  9. ABAC is tag-based — matching aws:PrincipalTag/Project ↔ aws:ResourceTag/Project prevents policy explosion.
  10. IAM Access Analyzer automatically detects external access using Zelkova (SMT-based formal verification) from Microsoft Research.

VPC·Network (16-26)

  1. RFC 1918 private IPs: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. Range /16–/28; prevent company-wide IP conflicts with IPAM.
  2. 5 reserved IPs per subnet: .0 (network) / .1 (router) / .2 (DNS) / .3 (reserved) / .255 (broadcast).
  3. NAT Gateway is AZ-local → one per AZ for availability. A single NAT means all outbound is blocked when that AZ dies.
  4. SGs are stateful (return traffic auto-allowed), NACLs are stateless (explicit both ways).
  5. NACL ephemeral ports: Linux 32768-60999, Windows 49152-65535; the safe range is 1024-65535.
  6. S3 and DynamoDB use Gateway Endpoints (free, prefix list in the Route Table); everything else uses Interface Endpoints ($0.01/hour + data).
  7. PrivateLink: a SaaS exposes its service behind an NLB as an Endpoint Service, no bidirectional routing.
  8. SG ID references only work within the same VPC and Peered VPCs; Transit Gateway allows IP CIDR references only.
  9. VPC Flow Logs record ENI 5-tuples + outcomes, no payload. Traffic Mirroring captures payload.
  10. Transit Gateway is BGP-based hub-and-spoke, up to 5000 VPCs, segmentation per route table.
  11. Direct Connect is dedicated (dedicated line) vs hosted (partner-shared), with 3 VIF types (Private/Public/Transit).

EC2·EBS·ELB·ASG (27-40)

  1. Nitro System: ASIC-based card virtualization, under 1% overhead. Network, EBS, Security, and Hypervisor on separate cards.
  2. Graviton (g suffix) is ARM Neoverse-based, 20-40% price-performance advantage over equivalent x86. Multi-arch containers mandatory.
  3. Inferentia/Trainium ASICs cut costs 60-70% versus GPU for LLM inference/training.
  4. gp3 provisions IOPS and size independently (20% cheaper than gp2), but no burst.
  5. io2 Block Express is NVMe-oF-based sub-ms latency, 256K IOPS, r5b/x2idn only.
  6. EBS is AZ-local + 3 synchronous replicas; other AZs only via snapshot.
  7. EBS Multi-Attach: io1/io2 + clustered filesystem (GFS2/OCFS2/OracleRAC) + 16 instances.
  8. Only NLB has static IPs + client IP preservation + millions of packets per second (flow-hash-based ECMP).
  9. ALB has direct Cognito integration (X-Amzn-Oidc-Data header), first-class gRPC support.
  10. Warm Pool pre-boots stopped instances, cold start 5 min → 30 sec.
  11. Mixed Instances Policy + price-capacity-optimized is the Spot standard.
  12. Spot averages 70% off, reclaimed after a 2-minute warning, diversify across families.
  13. Placement Groups: Cluster (low-latency HPC) / Spread (isolation, 7/AZ) / Partition (HDFS/Cassandra rack-aware).
  14. Lifecycle Hook default heartbeat is 1 hour, max 48 hours; calling complete-lifecycle-action is mandatory.

The 3-Layer Method: IAM ⇒ VPC ⇒ Compute

When solving Pro scenarios, checking the 3 layers in order reveals missing elements.

┌──────────────────────────────────────────────────┐
│ Layer 1: IAM   "Who is accessing?"               │
│   - SCP / Permission Boundary / IAM / Resource   │
│   - Federation (SAML/OIDC), STS, ABAC            │
│   - Cross-Account Role + ExternalId              │
├──────────────────────────────────────────────────┤
│ Layer 2: VPC   "Where does it flow?"             │
│   - VPC CIDR, Subnet, Route Table                │
│   - SG (stateful) + NACL (stateless)             │
│   - VPC Endpoint (Gateway/Interface), PrivateLink│
│   - Transit Gateway, Direct Connect, VPN         │
├──────────────────────────────────────────────────┤
│ Layer 3: Compute  "What processes it?"           │
│   - EC2 family / pricing / Nitro / Graviton      │
│   - EBS type (gp3/io2BE/st1), Snapshot, FSR      │
│   - The 4 ELBs (ALB/NLB/GLB/CLB)                 │
│   - ASG (Target/Step/Predictive/Warm Pool)       │
└──────────────────────────────────────────────────┘

💡 Related theory: This 3-layer approach is a direct implementation of "Complete Mediation" and "Defense in Depth" from Saltzer and Schroeder's 8 security principles (1975). Every request passes through three gates: (1) permission check at IAM, (2) network isolation at VPC, (3) workload execution at Compute. If one gate is breached, another gate blocks. The Capital One incident breached the IAM gate via SSRF, but if a VPC Endpoint Policy had also been applied, the S3 access would have been blocked.

🔍 Deeper dive: Between the three layers there is boundary translation. The IAM Principal ARN turns into a VPC Source IP (which appears externally as the same IP when going through NAT), and at Compute it is translated back into the IAM Role from instance metadata. Information gets blurred during these translations, so when tracing with CloudTrail in multi-account environments you must look at user-agent + source IP + role session name all together. With a single variable, you may not know who did it.

A Hands-On Example of Scenario Decomposition

Scenario: "A global pharmaceutical company runs 80 accounts in AWS Organizations. The research division uses EC2 + RDS PostgreSQL to handle clinical trial data. Under FDA 21 CFR Part 11 regulations, all data access must have an audit trail, and the data must stay only in ap-northeast-2. Additionally, external SaaS providers (Veeva, Medidata) must read some of the data, and the use of access keys is prohibited. What is the most appropriate architecture?"

5-step decomposition + 3-layer mapping:

  1. WHO: global pharma, 80 accounts, research division + external SaaS (Veeva/Medidata).
  2. WHAT: EC2 + RDS PostgreSQL, clinical trial data.
  3. WHY: FDA 21 CFR Part 11, data sovereignty (ap-northeast-2).
  4. CONSTRAINTS: all access audited, access key usage prohibited.
  5. KEYWORD: regulation + multi-account + SaaS access + key avoidance.

→ 3-layer answer:

  • IAM layer: SCP denies regions other than ap-northeast-2. External SaaS uses Cross-Account Role + ExternalId (avoiding access keys). Unify CloudTrail across 80 accounts with an Org Trail. Encrypt data with a KMS custom CMK + Key Policy.
  • VPC layer: VPC Endpoints (S3, RDS, KMS) + Endpoint Policies to block external flows. External SaaS exposed via PrivateLink behind an NLB. Block outbound internet with NACLs/SGs (no internet traversal).
  • Compute layer: EC2 enforces IMDSv2, EBS is KMS-encrypted, RDS is Multi-AZ + automatic backups + 35-day retention. Export RDS audit logs to CloudWatch Logs.

Almost all of Week 1's learning is packed into this one scenario. The standard solving flow in the exam room is for your hand to draw the 3 layers automatically and fill each layer with keywords.

📝 Practice Questions

Click a choice to reveal the answer and explanation.

Question 1

A company operates 100 accounts. The security team wants to "block root user logins entirely in the production OU, and also block IAM calls without MFA." The most suitable method?

Question 2

A global SaaS operates in us-east-1 and is expanding to eu-west-1. EU user data must stay in the EU per GDPR. To guarantee data isolation while keeping a single codebase?

Question 3

A fintech wants to enforce that no EC2 can use any region other than us-east-1, for PCI-DSS certification. To minimize operational burden?

Question 4

A company accesses S3 from EC2. Traffic goes through a NAT Gateway, costing $30,000/month. A PCI-DSS audit also flagged that "S3 traffic traverses the internet." How to solve?

Question 5

A media company runs global game matchmaking (WebSocket). It exposes static IPs externally, needs failover within seconds on regional failure, and handles 1 million packets per second. The suitable combination?

Question 6

A company deploys to AWS Lambda from GitHub Actions. The security team requires "no long-lived AWS Access Keys stored in GitHub Secrets." How to solve?

Question 7

A company runs 100 EC2 instances for 4 hours for a nightly ETL batch (stateless, restartable). Minimize cost + meet the SLA (complete by 09:00 the next day).

Question 8

A company applies authentication behind an ALB. The backend (Node.js) wants almost no auth code and just wants to receive user info. The most suitable method?

Question 9

A company runs RDS MySQL in us-east-1 and wants to build DR in ap-northeast-2. RPO within 1 minute, RTO within 5 minutes. The most suitable solution?

Question 10

A SaaS wants to make its service usable via private IPs inside customer VPCs. The standard pattern?

Question 11

A company has an AD with 200 employees. SSO access to 80 accounts in AWS Organizations. When an employee leaves, permissions must be revoked automatically across all accounts. The most suitable solution?

Question 12

There are 3 Private Subnets across Multi-AZ, calling external APIs. To secure availability while minimizing cost, how should NAT Gateways be placed?

Wrapping Up

Week 1 reviewed the grammar of the exam and the four core SAA areas (IAM, VPC, EC2, ELB) at Pro depth. When the 40 one-line summaries and the 3-layer method work in the exam room, your hands automatically start decomposing even a scenario you've never seen.

From Week 2 we enter multi-account architecture (Organizations, SCP, Control Tower, Identity Center) — covered in earnest only at the SAP level. It accounts for 26% of Domain 1, so it's the biggest ROI. Solve today's 12 scenario questions once more, and for the ones you got wrong, apply the decomposition method to see where you went wrong. The moment your hand draws the 5 boxes first in the exam room is the signal of a pass.

PreviousFour Compute Pillars in Depth: Revisiting Nitro, EBS, ELB, and Auto Scaling Through a Pro LensWeek 1 · Day 4Next AWS Organizations: A New Unit of Thought for Multi-Account ArchitectureWeek 2 · Day 1

On this page

  • 40 One-Line Summaries of Week 1
  • Exam Strategy (1-5)
  • IAM·STS·Federation (6-15)
  • VPC·Network (16-26)
  • EC2·EBS·ELB·ASG (27-40)
  • The 3-Layer Method: IAM ⇒ VPC ⇒ Compute
  • A Hands-On Example of Scenario Decomposition
  • 12 Scenario Questions (Pro Difficulty)
  • Wrapping Up