Block and file storage
Not everything fits in object storage. Operating systems and databases need block storage; shared folders need file storage. The exam expects you to pick the right type and tier for performance and cost.
Storage types at a glance
| Type | Service | Accessed as | Shared by many servers? |
|---|---|---|---|
| Object | S3 | HTTP API | Yes (any number of clients) |
| Block | EBS, instance store | A disk attached to an instance | Generally no (EBS Multi-Attach is a niche exception) |
| File | EFS, FSx | A network file system (NFS, SMB) | Yes |
Amazon EBS
Network-attached block volumes for EC2.
- Lives in one AZ; attaches to instances in the same AZ.
- Persists independently of the instance.
- Can be resized and changed between types online (Elastic Volumes).
Volume types
| Type | Media | Use | Notes |
|---|---|---|---|
| gp3 | SSD | General purpose: boot volumes, most apps, dev/test | Baseline 3,000 IOPS and 125 MiB/s included; IOPS and throughput can be raised independently of size; usually cheaper than gp2 |
| gp2 | SSD | Older general purpose | IOPS tied to size (burst credits for small volumes) |
| io2 Block Express / io1 | SSD | Mission-critical, I/O-intensive databases | Provisioned IOPS, sub-millisecond latency, highest durability (io2); supports Multi-Attach |
| st1 | HDD | Throughput-intensive, sequential: big data, data warehouses, log processing | Can't be a boot volume |
| sc1 | HDD | Lowest cost, infrequently accessed cold data | Can't be a boot volume |
Random I/O, databases → SSD (gp3 or io2). Large sequential reads/writes → st1. Cheapest for rarely accessed data → sc1. Boot volume → SSD only.
Snapshots
- Point-in-time, incremental backups stored in S3 (managed by AWS).
- Copy across Regions (DR) and share across accounts.
- Restore to a new volume in any AZ — this is how you "move" a volume to another AZ.
- Fast Snapshot Restore removes first-read latency on restored volumes.
- Snapshot archive tier — cheaper storage for rarely needed snapshots.
- Automate with Amazon Data Lifecycle Manager or AWS Backup.
Encryption
KMS-encrypted volumes encrypt data at rest, in transit to the instance, and in snapshots. Turn on EBS encryption by default per Region. Encrypt an existing unencrypted volume by snapshotting it, copying the snapshot with encryption, and creating a new volume.
Instance store
Physically attached disks: extremely fast, but ephemeral — data is lost when the instance stops, hibernates or terminates, or the host fails. Use for caches, buffers, scratch space, or data replicated elsewhere (e.g. distributed databases).
Amazon EFS (Elastic File System)
- Managed NFS file system for Linux — mount from many EC2 instances, containers (ECS/EKS, including Fargate) and Lambda at the same time.
- Regional (data across multiple AZs) or One Zone (cheaper, single AZ).
- Grows and shrinks automatically — pay for what you store.
- Storage classes: Standard, Infrequent Access, Archive, with lifecycle management to move files automatically.
- Throughput modes: Elastic (scales automatically — good default), Provisioned, Bursting.
- Performance modes: General Purpose (lowest latency), Max I/O (legacy, for highly parallel workloads).
- Encryption at rest (KMS) and in transit (TLS).
Amazon FSx family
| Service | Protocol / purpose | Cue words |
|---|---|---|
| FSx for Windows File Server | SMB, Windows-native, Active Directory integration, DFS | "Windows file shares", "SMB", "Active Directory permissions" |
| FSx for Lustre | High-performance parallel file system; integrates with S3 | "HPC", "machine learning training", "sub-millisecond, hundreds of GB/s" |
| FSx for NetApp ONTAP | NFS, SMB and iSCSI; NetApp features (snapshots, cloning, replication) | "Migrate NetApp", "multi-protocol" |
| FSx for OpenZFS | NFS with ZFS features | "Migrate ZFS/Linux file servers" |
Choosing storage
| Requirement | Choose |
|---|---|
| Boot disk or database on a single instance | EBS (gp3; io2 for heavy I/O) |
| Temporary, very fast scratch space | Instance store |
| Shared Linux file system across instances/AZs | EFS |
| Shared Windows (SMB) file system with AD | FSx for Windows File Server |
| HPC or ML with massive throughput, linked to S3 | FSx for Lustre |
| Unstructured data, web assets, backups, data lake | S3 |
Exam patterns
- "Many Linux EC2 instances in several AZs need the same files" → EFS.
- "A Windows application needs a shared drive with AD permissions" → FSx for Windows File Server.
- "Move an EBS volume to another AZ" → snapshot and restore in the target AZ.
- "Log processing needs high sequential throughput at low cost" → st1.
- "Database needs 64,000 consistent IOPS" → io2 (Block Express).