Domain 3: Cloud Technology and Services

Deploying and Operating in the AWS Cloud (Task 3.1)

AWS Management Console AWS CLI AWS SDKs AWS CloudFormation AWS Elastic Beanstalk AWS VPN AWS Direct Connect
Exam Tip
Access methods: Console (visual), CLI (scripted), SDKs (in code), CloudFormation (infrastructure as code). One-time task → console; repeatable → CLI/IaC. Deployment models: cloud (all in), hybrid (mix), on-premises. Connectivity: public internet (cheapest, least secure), VPN (encrypted over internet), Direct Connect (dedicated private line, fastest/most consistent).

Methods of Deploying and Operating in the AWS Cloud

Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/ways-to-access-aws.html

The exam tests which access method and connectivity option fits a scenario. Senior engineers go further: they standardize on IaC so environments are reproducible, and they design hybrid connectivity with failover paths, not single links.

Ways to Access and Provision AWS

Method What It Is Best For
AWS Management Console Web GUI Learning, one-time visual tasks, dashboards
AWS CLI Command-line tool, one tool many services Scripting repeatable ops, automation
AWS SDKs Language libraries (Python/boto3, Java, JS, Go) Calling AWS APIs from application code
Infrastructure as Code (CloudFormation) Declarative YAML/JSON templates of resources Repeatable, versioned environments
AWS Elastic Beanstalk Upload code, platform provisions everything Web apps without hand-building infra


Decision rule for the exam: a one-time operation fits the console; anything repeatable ("every Friday", "across 30 environments", "so it is identical each time") fits CLI or CloudFormation.

How the access methods relate (senior view)

Brief: Every method is a client of the same HTTPS API. The console is a GUI over API calls; the CLI is a scripting shell over the same calls; SDKs embed the calls in your code; CloudFormation declaratively describes the calls' end state.

How it works: Because everything is an API, automation is never blocked. A console session is also just API calls signed with temporary credentials — which is why CLI access uses the same IAM policies as the console. Credentials come from the credential chain: environment variables → config file → instance/container role → SSO.

Real use-case: A data engineer must copy 200 GB from an S3 bucket to another account every night at 02:00. Console drag-and-drop is manual and un-auditable; instead an EventBridge-scheduled Lambda (SDK) or a cron'd aws s3 sync runs the job — identical, logged in CloudTrail, and owned by a role, not a person.

Gotchas & interview notes: the exam's "repeatable" keyword means CLI/IaC, never console. For IaC answers prefer CloudFormation (native) unless the question names Terraform. Elastic Beanstalk is still IaC underneath — it generates the infrastructure for you from uploaded code (you keep full control of the resources it creates).

Infrastructure as Code (IaC)

Brief: Define infrastructure in template files instead of clicking consoles.

How it works: CloudFormation templates (YAML/JSON) declare resources and their dependencies; the engine computes an ordered change set, creates/updates/deletes resources as ONE stack, and rolls back failed changes automatically. Templates are version-controlled and peer-reviewed like code; drift detection compares the live stack to the template.

Real use-case: A team provisions the same 3-tier stack in 5 Regions from one template. A security patch means editing ONE template file; the pipeline propagates it everywhere identically. When an experiment ends, deleting the stack removes every resource — nothing keeps billing silently.

Gotchas & interview notes: IaC's hidden enemy is drift — manual console changes the template does not know about. Senior practice: read-only console in prod, drift detection on a schedule, all changes through pipelines.

Cloud Deployment Models

Model Description Typical Use
Cloud (public) Everything runs on AWS New apps, startups, SaaS
Hybrid Some on AWS, some on-premises, connected Legacy databases on-prem + burst compute on AWS
On-premises (private) Everything in your own data center Regulated workloads not yet migrated


Hybrid enablers (memorize the toolbox): AWS Outposts (physical AWS racks in your own data center — AWS APIs on-prem), AWS Storage Gateway (on-prem cache backed by S3), AWS Snow Family (offline bulk transfer), VPN / Direct Connect (connectivity).

Real use-case: A hospital keeps the patient-record database on-premises (regulatory interpretation) but runs its analytics and bursty AI workloads on AWS, connected by Direct Connect — a textbook hybrid.

Gotchas & interview notes: "Cloud-native" vs "hybrid" questions resolve to WHERE the constraint lives: no constraint → all-in cloud; a hard latency/license/regulatory anchor on-prem → hybrid with Outposts/Storage Gateway/DX.

Connectivity Options

Option Nature Latency / Security Cost
Public internet Standard internet path Variable, untrusted (needs TLS) Lowest
AWS Site-to-Site VPN Encrypted IPsec tunnel over the internet Internet-grade latency, private encryption Low, hourly
AWS Direct Connect Dedicated private physical circuit into AWS Consistent low latency, private Highest, monthly + port hours


How it works: A VPN creates two IPsec tunnels (for redundancy) from your router to a Virtual Private Gateway (or Transit Gateway attachment) — encrypted, but riding the public internet, so latency and jitter vary. Direct Connect is a physical circuit (1/10/100 Gbps) provisioned at a partner colocation facility into a Direct Connect location — traffic never touches the internet, so latency is consistent and bandwidth is guaranteed.

Example: A bank needs 10 Gbps of predictable throughput to AWS with no internet exposure → Direct Connect. A startup links its office to its VPC cheaply → Site-to-Site VPN.

Real use-case: An enterprise runs Direct Connect as primary and a Site-to-Site VPN as automatic backup (BGP routing fails over in seconds when the circuit drops) — the standard "DX + VPN failover" pattern the exam loves.

Gotchas & interview notes: Direct Connect takes WEEKS to provision (physical circuit) — if the scenario needs connectivity NOW, the answer is VPN now, DX later. DX is private, not encrypted by default — sensitive traffic can add MACsec or run IPsec over it.

Worked Example

A data engineer must copy 200 GB from an S3 bucket to another account every night at 02:00. Options:

  • Console download/upload nightly — manual, error-prone, slow: rejected.
  • aws s3 sync s3://src s3://dst in a cron job or EventBridge-scheduled Lambda using the CLI/SDK: right choice for automation.
  • If the environment must be rebuilt identically in a new Region later, the buckets and jobs are defined in CloudFormation so the whole pipeline is redeployable in minutes.