Practice topics by certification
- 1.1 - AWS Cloud value proposition and benefits
- 1.2 - Cloud concepts and AWS global infrastructure
- 1.3 - AWS design principles and Cloud Adoption Framework
- 1.4 - Cloud migration and cost-saving strategies
- 2.1 - The AWS Shared Responsibility Model
- 2.2 - AWS Identity and Access Management (IAM)
- 2.3 - AWS compliance and governance
- 2.4 - AWS security services (KMS, WAF, Shield, GuardDuty)
- 3.1 - Ways to interact with AWS (Console, CLI, SDK)
- 3.2 - AWS networking basics (VPC, subnets, gateways)
- 3.3 - Core AWS services (EC2, S3, RDS, Lambda)
- 3.4 - AWS management and monitoring services
- 4.2 - Scaling and high availability on AWS
- 4.3 - S3 features and programmatic access
- 4.4 - Application integration services (SQS, SNS)
- 4.5 - AWS AI and machine learning services
- 4.1 - AWS pricing models and purchase options
- 4.2 - AWS cost management and billing tools
- 4.3 - AWS Support plans
- 1.1 - Design and implement an incident response plan (runbooks, forensic account, chain of custody)
- 1.2 - Detect threats and anomalies with AWS services (GuardDuty, Inspector, Macie, Detective, Security Hub)
- 1.3 - Respond to compromised resources and workloads (isolation, revoked sessions, automated containment)
- 2.1 - Design and implement monitoring and alerting (EventBridge, metric filters, anomaly detection)
- 2.2 - Troubleshoot monitoring and alerting (silent rules, INSUFFICIENT_DATA, missing findings)
- 2.3 - Design and implement a logging solution (CloudTrail, Flow Logs, Athena, Logs Insights, OpenSearch)
- 2.4 - Troubleshoot logging solutions (empty buckets, KMS denials, missing data events)
- 3.1 - Design edge network security controls (CloudFront, WAF, Shield, API Gateway)
- 3.2 - Design internal network security controls (security groups, NACLs, endpoints, Flow Logs, Reachability Analyzer)
- 3.3 - Design and implement compute security (Session Manager, IMDSv2, Patch Manager, IRSA, Nitro Enclaves)
- 4.1 - Design, implement and troubleshoot authentication (Identity Center, SAML, OIDC, Cognito, MFA, Roles Anywhere)
- 4.2 - Design, implement and troubleshoot authorization (identity and resource policies, ABAC, permissions boundaries, Access Denied)
- 5.1 - Encryption in transit (ACM, TLS, mTLS, VPN)
- 5.2 - Encryption at rest (KMS, CloudHSM, rotation, key policies)
- 5.3 - Data lifecycle (Macie, Object Lock, backups, retention)
- 5.4 - Protecting credentials and secrets (Secrets Manager, Parameter Store, CloudHSM, access keys)
- 6.1 - Centralized account management (Organizations, Control Tower, SCPs)
- 6.2 - Secure and consistent deployment (CloudFormation, StackSets, Service Catalog)
- 6.3 - Evaluating resource compliance (Config, Security Hub, Audit Manager, Artifact)
- 6.4 - Identifying gaps through architecture review and cost analysis (Well-Architected, Trusted Advisor)
- 1.1 - Network connectivity strategies (Transit Gateway, Direct Connect, Route 53 Resolver)
- 1.2 - Multi-account security and shared services (inspection VPC, RAM, Managed AD, OIDC)
- 1.3 - Cross-account data protection and access (KMS, S3 Access Points, delegated admin)
- 1.4 - Multi-account governance and sharing (Organizations, SCPs, RAM, StackSets)
- 1.5 - Organization policies, cost management and resilience strategy
- 2.1 - Selecting compute, storage and data services
- 2.2 - Designing for reliability and disaster recovery
- 2.3 - Secure, decoupled application design (WAF, Secrets Manager, VPC endpoints)
- 2.4 - Performance, throughput and integration services
- 2.5 - Orchestration, analytics and edge services
- 2.6 - Event-driven architecture and cost-aware design
- 2.7 - Deployment strategies and purpose-built services
- 3.1 - Improving monitoring, logging and operational response
- 3.2 - Improving reliability and fault tolerance
- 3.3 - Improving performance, cost and resilience of existing workloads
- 3.4 - Operational tooling: remediation, observability and safe releases
- 3.5 - Cost optimization and security hardening
- 4.1 - Planning and assessing migrations (Discovery, Migration Hub, 7 Rs)
- 4.2 - Executing migrations (MGN, DMS, Snowball, 7 Rs strategies)
- 4.3 - Database migration and refactoring tools (SCT, DMS, Refactor Spaces)
- 4.4 - Modernizing workloads (strangler-fig, serverless, blue/green)
- 1.1 - CloudWatch metrics and alarms
- 1.2 - Logging and log analysis (CloudWatch Logs, CloudTrail, Config)
- 1.3 - Automated remediation (EventBridge and SSM Automation)
- 2.1 - Scalability and high availability
- 2.2 - Backup, restore, and disaster recovery
- 3.1 - Provisioning with CloudFormation and StackSets
- 3.2 - Automation with Systems Manager (Run Command, Patch Manager)
- 3.3 - Deployment strategies, AMIs and launch templates
- 4.1 - Identity and data protection (IAM, KMS, Secrets Manager)
- 4.2 - Compliance and governance (Config, Organizations, SCPs)
- 4.3 - Threat detection and protection (GuardDuty, WAF, Shield)
- 5.1 - VPC networking and connectivity
- 5.2 - DNS, content delivery and network troubleshooting
- 6.1 - Cost and performance optimization
- 1.1 - Laptop and mobile hardware components
- 1.2 - Laptop display components
- 1.3 - Mobile device accessories and connectivity
- 1.4 - Mobile connectivity: hotspot, tethering, Bluetooth and NFC
- 2.1 - Common ports and protocols
- 2.2 - Switches, MAC addresses and PoE
- 2.3 - Network cabling and connectors
- 2.4 - Wireless standards and encryption
- 2.5 - IP addressing: IPv4, IPv6, APIPA and DHCP
- 2.6 - Networking devices: routers, DHCP and VLANs
- 2.7 - Network services: NAT, proxy, load balancer and IoT
- 2.8 - VPNs and network tools
- 3.1 - Cables and connectors
- 3.2 - RAM types and configuration
- 3.3 - Storage devices: SSD, NVMe and HDD
- 3.4 - Motherboards, RAID and cooling
- 3.5 - Power supplies and connectors
- 3.6 - Printer types and maintenance
- 3.7 - Custom PC and server configurations
- 4.1 - Cloud concepts and characteristics
- 4.2 - Cloud service models and virtualization
- 5.1 - The CompTIA troubleshooting methodology
- 5.2 - Troubleshooting POST and boot problems
- 5.3 - Troubleshooting storage and drive failures
- 5.4 - Troubleshooting drives, boot order and display
- 5.5 - Troubleshooting RAID, RAM and system faults
- 5.6 - Troubleshooting laptop and printer hardware
- 5.7 - Troubleshooting displays, printers and connectivity
- 1.1 - Cloud service models (IaaS, PaaS, SaaS, serverless)
- 1.2 - Cloud networking (VPCs, subnets, gateways)
- 1.3 - Cloud storage and database types
- 1.4 - The shared responsibility model
- 1.5 - Hybrid and cloud connectivity
- 2.1 - Cloud migration strategies (the 6 Rs)
- 2.2 - Infrastructure as Code (IaC)
- 2.3 - VM images, snapshots and conversions
- 2.4 - Scaling and load balancing
- 3.1 - Cloud monitoring and observability
- 3.2 - Cloud operations and optimization
- 3.3 - Backups and point-in-time recovery
- 3.4 - Cost management and disaster recovery
- 3.5 - Cloud pricing and purchase options
- 4.1 - Cloud identity and access management
- 4.2 - Cloud network and data protection
- 4.3 - Immutability and object lock
- 4.4 - Cloud security tools (DLP, secrets, scanning)
- 4.5 - Cloud compliance and frameworks
- 5.1 - CI/CD and continuous integration
- 5.2 - Deployment strategies (blue-green, canary, rolling)
- 5.3 - Configuration management and containers
- 5.4 - Configuration drift, artifacts and webhooks
- 1.1 - Manage Microsoft Entra ID identities (users, groups, domains)
- 1.2 - Azure RBAC roles, assignments and scope
- 1.3 - Governance: resource locks, Azure Policy and cost
- 2.1 - Storage accounts, redundancy and shared access signatures
- 2.3 - Azure Files, File Sync and data movement tools
- 3.1 - Deploy VMs, images and templates (ARM, Bicep)
- 3.2 - VM sizing, scale sets and configuration
- 4.1 - Virtual networks, subnets and Azure DNS
- 4.3 - VNet peering, Azure Bastion and VPN gateways
- 4.4 - Load Balancer, Application Gateway and private endpoints
- 5.1 - Azure Monitor, Log Analytics and KQL
- 5.3 - Network Watcher, Site Recovery and Update Manager
- 1.1 - Cloud models and shared responsibility
- 1.2 - Benefits of cloud computing (scalability, elasticity, availability)
- 1.3 - Service models and cloud pricing (IaaS, PaaS, SaaS)
- 2.1 - Core architecture (regions, availability zones, resource groups)
- 2.2 - Compute and management services (VMs, containers, App Service)
- 2.3 - Networking and storage services (VNet, Blob, redundancy)
- 2.4 - Databases, identity and security services (Cosmos DB, Entra, Key Vault)
- 3.1 - Cost management and pricing tools (reservations, TCO, budgets)
- 3.2 - Governance and compliance (Azure Policy, locks, RBAC)
- 3.3 - Deployment tools and monitoring (ARM/Bicep, Azure Monitor, Advisor)
- 3.4 - Service health, SLAs and service lifecycle