Exam Guide: Developer - Associate
Technologies And Concepts Cheat Sheet
📘 Cheat Sheet
1 | Services
Compute
| Service | What It Does | Key Points |
|---|---|---|
| Lambda | Serverless Functions | 15 min timeout, 10240 MB memory max, 1000 default concurrency |
| EC2 | Virtual Servers | Instance profiles for IAM roles, user data for bootstrap |
| ECS/Fargate | Container Orchestration | Task roles for IAM, Fargate = serverless containers |
| Elastic Beanstalk | PaaS Deployment | .ebextensions for config, supports rolling/immutable/blue-green |
Storage & Databases
| Service | What It Does | Key Points |
|---|---|---|
| DynamoDB | NoSQL key-value | Partition keys, GSI/LSI, query vs scan, DAX for caching |
| S3 | Object Storage | SSE-S3/SSE-KMS/SSE-C, lifecycle policies, presigned URLs |
| ElastiCache | In-memory Cache | Redis (complex types, persistence) vs Memcached (simple, multi-threaded) |
| RDS | Relational Database | RDS Proxy for Lambda connection pooling, read replicas |
| OpenSearch | Search & Analytics | Full-text search, log analytics |
API & Integration
| Service | What It Does | Key Points |
|---|---|---|
| API Gateway | REST/HTTP/WebSocket APIs | Stages, authorizers, caching, request validation, throttling |
| SQS | Message Queue | Standard (at-least-once) vs FIFO (exactly-once), visibility timeout, DLQ |
| SNS | Pub/sub messaging | Fanout, filter policies, message attributes |
| EventBridge | Event Bus | Pattern matching, content-based filtering, multiple targets |
| Kinesis | Real-time Streaming | Shards, partition keys, parallelization factor |
| Step Functions | Workflow Orchestration | Standard (long-running) vs Express (high-volume, short) |
Security
| Service | What It Does | Key Points |
|---|---|---|
| IAM | Access Management | Policies, roles, least privilege, STS AssumeRole |
| Cognito | User Auth | User Pools (tokens) vs Identity Pools (AWS credentials) |
| KMS | Key Management | Envelope encryption, 4 KB limit, key rotation, cross-account |
| Secrets Manager | Secret Storage | Auto-rotation, $0.40/secret/month |
| SSM Parameter Store | Config Storage | Standard (free) vs Advanced, SecureString type |
| ACM | SSL/TLS Certificates | Free public certs, auto-renewal, can't export |
CI/CD
| Service | What It Does | Key Points |
|---|---|---|
| CodeCommit | Git Repository | Triggers pipelines on push |
| CodeBuild | Build Service | buildspec.yml, supports Docker |
| CodeDeploy | Deployment Service | appspec.yml, blue/green/canary/rolling |
| CodePipeline | CI/CD Orchestration | Source → Build → Test → Deploy stages |
| SAM | Serverless Framework | template.yaml, sam build/deploy, local testing |
| CloudFormation | IaC | Templates, stacks, change sets, !Sub, !Ref, parameters |
| AppConfig | Runtime Config | Feature flags, gradual rollout, validation |
Observability
| Service | What It Does | Key Points |
|---|---|---|
| CloudWatch Logs | Log storage & Query | Logs Insights query language, log groups, retention |
| CloudWatch Metrics | Metric Tracking | Custom metrics, EMF, math expressions |
| CloudWatch Alarms | Alerting | Metric alarms, composite alarms, SNS actions |
| X-Ray | Distributed Tracing | Segments, subsegments, annotations (indexed), metadata (not indexed) |
| CloudTrail | API Audit Log | Who did what? when? & Debug permission issues |
2 | Numbers
| Item | Limit |
|---|---|
| Lambda timeout | 15 minutes |
| Lambda memory | 128 MB – 10,240 MB |
| Lambda /tmp storage | 512 MB – 10,240 MB |
Lambda deployment (zip) | 50 MB compressed, 250 MB uncompressed |
Lambda deployment (container) | 10 GB |
| Lambda layers | 5 per function, 250 MB total unzipped |
Lambda concurrency (default) | 1,000 per region |
| KMS direct encryption | 4 KB max |
| SQS message size | 256 KB |
| SQS visibility timeout | 0s – 12 hours (default 30s) |
| SQS retention | 1 minute – 14 days (default 4 days) |
| SNS message size | 256 KB |
| DynamoDB item size | 400 KB |
| DynamoDB GSI | 20 per table |
| DynamoDB LSI | 5 per table |
| API Gateway timeout | 29 seconds |
| API Gateway payload | 10 MB |
| S3 object size | 5 TB (5 GB per PUT, use multipart for larger) |
| Secrets Manager secret size | 64 KB |
SSM Parameter Store (standard) | 4 KB |
SSM Parameter Store (advanced) | 8 KB |
| *Step Functions Standard * | 1 year execution |
| Step Functions Express | 5 minutes execution |
3 | Patterns
Decoupling
SQS: point-to-point, one consumer, buffering
SNS: fanout, multiple consumers
SNS + SQS: fanout with reliable delivery
EventBridge: complex routing, content-based filtering
Caching
DAX: DynamoDB reads only, microsecond latency
ElastiCache Redis: general purpose, complex data types
ElastiCache Memcached: simple caching, multi-threaded
CloudFront: edge caching for APIs and static content
API Gateway cache: per-stage, per-method caching
Authentication
Cognito User Pool: user sign-up/sign-in, JWT tokens
Cognito Identity Pool: temporary AWS credentials
Lambda authorizer: custom auth logic
IAM authorization: service-to-service with SigV4
Deployment
AllAtOnce: fastest, highest risk
Canary: small % first, then all (safest)
Linear: gradual rollout over time
Blue/Green: two environments, instant switch
Error Handling
DLQ: capture failed messages (SQS, Lambda async)
Lambda Destinations: route success AND failure (preferred over DLQ)
ReportBatchItemFailures: partial batch failure for SQS
BisectBatchOnFunctionError: split Kinesis batch to isolate bad records
Step Functions: retry and catch at the workflow level
4 | Versus
SQS Standard vs FIFO
| Feature | Standard | FIFO |
|---|---|---|
| Throughput | Unlimited | 300 msg/s (3000 batched) |
| Ordering | Best effort | Guaranteed |
| Delivery | At least once | Exactly once |
| Deduplication | No | Yes (5 min window) |
Secrets Manager vs Parameter Store
| Feature | Secrets Manager | Parameter Store |
|---|---|---|
| Auto Rotation | Built-in | DIY |
| Cost | $0.40/secret/month | Free (standard) |
| Max Size | 64 KB | 4 KB / 8 KB |
| Cross-Account | Yes | Yes (advanced) |
Step Functions Standard vs Express
| Feature | Standard | Express |
|---|---|---|
| Max Duration | 1 year | 5 minutes |
| Execution Model | Exactly once | At least once |
| Pricing | Per state transition | Per execution + duration |
| Use Case | Long-running workflows | High-volume, short tasks |
5 | Cram
Lambda in VPC loses internet access → needs NAT Gateway or VPC endpoints
DynamoDB FilterExpression doesn't reduce read capacity consumed
GSIs are eventually consistent only. No strongly consistent reads
DynamoDB uses Decimal, not float in Python
TTL deletion can take up to 48 hours after expiration
API Gateway timeout is 29 seconds. Can't be increased
SQS FIFO throughput is 300 msg/s (3000 with batching) vs Standard (unlimited)
Lambda Destinations only work with async invocations
Provisioned concurrency costs money even when idle
SSE-C: you manage the key, AWS doesn't store it. Lose the key = lose the data.
CloudFormation !Ref returns different things for different resources (ARN, name, ID)
SAM transforms to CloudFormation:sam buildis required beforesam deploy
X-Ray annotations are indexed and searchable. Metadata is not.
EMF is cheaper than PutMetricData for Lambda custom metrics
SQS long polling(WaitTimeSeconds > 0)reduces empty responses and costs
🏗️
SOCIAL SHARE CARD GENERATOR