Cloud and AWS fundamentals
Before designing anything on AWS, you need a clear mental model of what "the cloud" gives you, how AWS's global infrastructure is laid out, who is responsible for what, and how you are billed. These ideas appear in almost every exam question, often without being named.
What cloud computing gives you
Cloud computing is renting IT resources — servers, storage, databases, networks, software — over the internet, paying only for what you use.
| Benefit | What it means in practice |
|---|---|
| Trade capital expense for variable expense | No buying servers up front; pay monthly for usage |
| Economies of scale | AWS's scale makes per-unit prices lower than you could achieve alone |
| Stop guessing capacity | Scale up and down with demand instead of over-provisioning |
| Speed and agility | New resources in minutes, not weeks |
| Focus on what differentiates you | Less time racking servers, more time on your product |
| Go global in minutes | Deploy in Regions around the world |
Service models: Infrastructure as a Service (IaaS — e.g. EC2), Platform as a Service (PaaS — e.g. Elastic Beanstalk, RDS), Software as a Service (SaaS). The more managed the service, the less you operate — a recurring exam theme ("least operational overhead").
AWS global infrastructure
| Component | What it is | Why it matters |
|---|---|---|
| Region | A geographic area (e.g. ap-south-1, Mumbai) containing multiple AZs |
Choose for latency to users, data residency laws, service availability and price |
| Availability Zone (AZ) | One or more discrete data centres with independent power, cooling and networking, connected to other AZs in the Region by low-latency links | Deploy across multiple AZs for high availability |
| Local Zone | AWS infrastructure in a metro area, extending a Region | Single-digit-millisecond latency to users in that city |
| Wavelength Zone | AWS compute inside telecom 5G networks | Ultra-low latency for mobile and edge applications |
| AWS Outposts | AWS racks installed in your own data centre | Run AWS services on-premises with the same APIs (data residency, low latency to local systems) |
| Edge locations / points of presence | Hundreds of sites used by CloudFront, Route 53 and Global Accelerator | Bring content and DNS close to users worldwide |
A Region failure is rare; an AZ failure is the classic event you design for. "Highly available" on the exam almost always means at least two AZs. "Disaster recovery" often means another Region.
Choosing a Region
- Compliance and data residency — some data must stay in a country.
- Latency — close to your users.
- Service availability — not every service or feature is in every Region.
- Price — prices differ between Regions.
Global, Regional and zonal services
- Global: IAM, Route 53, CloudFront, WAF (for CloudFront), Organizations.
- Regional: S3 (buckets live in a Region), DynamoDB, Lambda, SQS, most services.
- Zonal: EC2 instances, EBS volumes, subnets, NAT gateways — each lives in one AZ.
Knowing the scope tells you what fails together and what you must replicate.
The shared responsibility model
Security is shared between AWS and you:
- AWS is responsible for security of the cloud — physical data centres, hardware, the global network, and the software that runs managed services.
- You are responsible for security in the cloud — your data, IAM permissions, encryption choices, network configuration (security groups, NACLs), operating system patches on EC2, and application code.
The split moves with the service type:
| Service | AWS manages | You manage |
|---|---|---|
| EC2 (IaaS) | Hardware, hypervisor, physical network | Guest OS patches, software, security groups, data, IAM |
| RDS (managed) | Hardware, OS, database engine patching, backups infrastructure | Database users, network access, encryption settings, data |
| Lambda / S3 / DynamoDB (serverless) | Almost all infrastructure | Code, data, access policies, encryption settings |
"Who patches the operating system on an EC2 instance?" — the customer. "Who patches the database engine on RDS?" — AWS (in the maintenance window you choose).
Accessing AWS
- Management Console — the web UI.
- AWS CLI — command line, scriptable.
- SDKs — libraries for programming languages.
- Infrastructure as code — CloudFormation (and tools built on it) to define resources as templates.
All of these call the same APIs, authenticated with IAM credentials.
Pricing fundamentals
- Pay as you go for compute time, storage used and requests made.
- Data transfer into AWS is free; data transfer out to the internet is charged. Data between AZs and between Regions is also charged — an important cost-design detail (see network performance and cost).
- Pay less with commitment — Reserved Instances and Savings Plans.
- Pay less with scale — tiered pricing (e.g. S3 storage gets cheaper per GB as you store more).
- Free tier — limited free usage for learning (terms vary; check current details).
Service quotas
Every account has quotas (formerly "limits") — e.g. number of running instances or Lambda concurrent executions per Region. Many are adjustable through Service Quotas. Exam tip: a disaster-recovery Region needs the same quotas raised in advance, or failover may fail when you try to scale.
Three ideas underpin almost every design question: deploy across multiple AZs for availability, use managed services to reduce operational overhead, and remember who is responsible for each layer of security.