AWS In Practice
Courses
  • Welcome to AWS In Practice by IT Assist Labs!
  • Courses
    • AWS Powered E-commerce Application: A Guided Tour
      • Lesson Learning Paths
        • Lesson Learning Paths - Certification Prep
        • Lesson Learning Paths - Interview Prep
      • Lesson Summaries
        • Introduction
          • E-commerce Application Architecture
        • Multi-Account Strategy
          • Multi-Account Strategy Overview
          • Organization Units
          • Core Accounts
        • Core Microservices
          • Services Overview
          • AWS Well-Architected design framework application
          • Site Reliability Engineering Application
          • DevOps Application
          • Monitoring, Logging and Observability Application
        • AWS Service By Layer
          • AWS Service By Layer Overview
          • Presentation Layer
          • Business Logic Layer
          • Data Layer
        • E-commerce Application Use Cases
          • E-commerce Application Use Cases
          • Roles
      • Lesson Content Navigation Demonstration
    • Explore a Live AWS Environment Powering an E-commerce Application
  • Resources
    • AWS Certification Guide
      • Concepts
        • Security, Identity & Compliance
          • AWS IAM-Related Concepts in Certification Exams
        • Design High-Performing Architectures
          • Designing a high-performing architecture with EC2 and Auto Scaling Groups (ASGs)
    • Insights
      • Zero Trust Architecture (ZTA)
      • Implementing a Zero Trust Architecture(ZTA) with AWS
      • The Modern Application Development Lifecycle - Blue/Green Deployments
      • Microservices Communication Patterns
    • Interview Preparation
      • AWS Solutions Archictect
  • AWS Exploration
    • Use Cases
      • Multi-Region Resiliency with Active-Active Setup
        • Exploration Summary
    • Foundational Solutions Architect Use Cases
    • Security Engineer / Cloud Security Architect Use Cases
    • DevOps / Site Reliability Engineer (SRE) Use Cases
    • Cloud Engineer / Cloud Developer
    • Data Engineer Use Cases
    • Machine Learning Engineer / AI Practitioner Use Cases
    • Network Engineer (Cloud) Use Cases
    • Cost Optimization / FinOps Practitioner Use Cases
    • IT Operations / Systems Administrator Use Cases
  • Study Group
    • AWS Certified Solutions Architect - Associate
      • Study Guide Introduction
      • Domain 1: Design Secure Architectures
        • Task Statement 1.1: Design secure access to AWS resources
          • SecureCart's Journey
          • AWS Identity & Access Management (IAM) Fundamentals
          • AWS Security Token Service (STS)
          • AWS Organization
          • IAM Identity Center
          • AWS Policies
          • Federated Access
          • Directory Service
          • Managing Access Across Multiple Accounts
          • Authorization Models in IAM
          • AWS Control Tower
          • AWS Service Control Policies (SCPs)
          • Use Cases
            • Using IAM Policies and Tags for Access Control in AWS
        • Task Statement 1.2: Design Secure Workloads and Applications
          • SecureCart Journey
          • Application Configuration & Credential Security
          • Copy of Application Configuration & Credential Security
          • Network Segmentation Strategies & Traffic Control
          • Securing Network Traffic & AWS Service Endpoints
          • Protecting Applications from External Threats
          • Securing External Network Connections
          • AWS Network Firewall
          • AWS Firewall Manager
          • IAM Authentication Works with Databases
          • AWS WAF (Web Application Firewall)
          • Use Cases
            • AWS Endpoint Policy for Trusted S3 Buckets
            • Increasing Fault Tolerance for AWS Direct Connect in SecureCart’s Multi-VPC Network
            • Securing Multi-Domain SSL with ALB in SecureCart Using SNI-Based SSL
            • Configuring a Custom Domain Name for API Gateway with AWS Certificate Manager and Route 53
            • Application Load Balancer (ALB) – Redirecting HTTP to HTTPS
            • Security Considerations in ALB Logging & Monitoring
          • Amazon CloudFront and Different Origin Use Cases
          • Security Group
          • CloudFront
          • NACL
          • Amazon Cognito
          • VPC Endpoint
        • Task Statement 1.3: Determine appropriate data security controls
          • SecureCart Journey
          • Data Access & Governance
          • Data Encryption & Key Management
          • Data Retention, Classification & Compliance
          • Data Backup, Replication & Recovery
          • Managing Data Lifecycle & Protection Policies
          • KMS
          • S3 Security Measures
          • KMS Use Cases
          • Use Cases
            • Safely Storing Sensitive Data on EBS and S3
            • Managing Compliance & Security with AWS Config
            • Preventing Sensitive Data Exposure in Amazon S3
            • Encrypting EBS Volumes for HIPAA Compliance
            • EBS Encryption Behavior
            • Using EBS Volume While Snapshot is in Progress
          • Compliance
          • Implementing Access Policies for Encryption Keys
          • Rotating Encryption Keys and Renewing Certificates
          • Implementing Policies for Data Access, Lifecycle, and Protection
          • Rotating encryption keys and renewing certificates
          • Instance Store
          • AWS License Manager
          • Glacier
          • AWS CloudHSM Key Management & Zeroization Protection
          • EBS
        • AWS Security Services
        • Use Cases
          • IAM Policy & Directory Setup for S3 Access via Single Sign-On (SSO)
          • Federating AWS Access with Active Directory (AD FS) for Hybrid Cloud Access
      • Domain 2
        • Task Statement 2.1: Design Scalable and Loosely Coupled Architectures
          • SecureCart Journey
          • API Creation & Management
          • Microservices & Event-Driven Architectures
          • Load Balancing & Scaling Strategies
          • Caching Strategies & Edge Acceleration
          • Serverless & Containerization
          • Workflow Orchestration & Multi-Tier Architectures
        • Task Statement 2.2: Design highly available and/or fault-tolerant architectures
          • SecureCart Journey
          • AWS Global Infrastructure & Distributed Design
          • Load Balancing & Failover Strategies
          • Disaster Recovery (DR) Strategies & Business Continuity
          • Automation & Immutable Infrastructure
          • Monitoring & Workload Visibility
          • Use Cases
            • Amazon RDS Failover Events & Automatic Failover Mechanism
      • Domain 3
        • Task Statement 3.1: Determine high-performing and/or scalable storage solutions
          • SecureCart Journey
          • Understanding AWS Storage Types & Use Cases
          • Storage Performance & Configuration Best Practices
          • Scalable & High-Performance Storage Architectures
          • Hybrid & Multi-Cloud Storage Solutions
          • Storage Optimization & Cost Efficiency
          • Hands-on Labs & Final Challenge
        • Task Statement 3.2: Design High-Performing and Elastic Compute Solutions
          • SecureCart
          • AWS Compute Services & Use Cases
          • Elastic & Auto-Scaling Compute Architectures
          • Decoupling Workloads for Performance
          • Serverless & Containerized Compute Solutions
          • Compute Optimization & Cost Efficiency
        • Task Statement 3.3: Determine High-Performing Database Solutions
          • SecureCart Journey
          • AWS Database Types & Use Cases
          • Database Performance Optimization
          • Caching Strategies for High-Performance Applications
          • Database Scaling & Replication
          • High Availability & Disaster Recovery for Databases
        • Task Statement 3.4: Determine High-Performing and/or Scalable Network Architectures
          • SecureCart Journey
          • AWS Networking Fundamentals & Edge Services
          • Network Architecture & Routing Strategies
          • Load Balancing for Scalability & High Availability
          • Hybrid & Private Network Connectivity
          • Optimizing Network Performance
          • Site-to-Site VPN Integration for SAP HANA in AWS
        • Task Statement 3.5: Determine High-Performing Data Ingestion and Transformation Solutions
          • SecureCart Journey
          • Data Ingestion Strategies & Patterns
          • Data Transformation & ETL Pipelines
          • Secure & Scalable Data Transfer
          • Building & Managing Data Lakes
          • Data Visualization & Analytics
      • Domain 4
        • Task Statement 4.1: Design Cost-Optimized Storage Solutions
          • SecureCart Journey
          • AWS Storage Services & Cost Optimization
          • Storage Tiering & Auto Scaling
          • Data Lifecycle Management & Archival Strategies
          • Hybrid Storage & Data Migration Cost Optimization
          • Cost-Optimized Backup & Disaster Recovery
        • Task Statement 4.2: Design Cost-Optimized Compute Solutions
          • SecureCart Journey
          • AWS Compute Options & Cost Management Tools
          • Compute Purchasing Models & Optimization
          • Scaling Strategies for Cost Efficiency
          • Serverless & Container-Based Cost Optimization
          • Hybrid & Edge Compute Cost Strategies
          • AWS License Manager
        • Task Statement 4.3: Design cost-optimized database solutions
          • SecureCart Journey
          • AWS Database Services & Cost Optimization Tools
          • Database Sizing, Scaling & Capacity Planning
          • Caching Strategies for Cost Efficiency
          • Backup, Retention & Disaster Recovery
          • Cost-Optimized Database Migration Strategies
        • Task Statement 4.4: Design Cost-Optimized Network Architectures
          • SecureCart Journey
          • AWS Network Cost Management & Monitoring
          • Load Balancing & NAT Gateway Cost Optimization
          • Network Connectivity & Peering Strategies
          • Optimizing Data Transfer & Network Routing Costs
          • Content Delivery Network & Edge Caching
      • Week Nine
        • Final Review Session
        • Final Practice Test
Powered by GitBook

@ 2024 IT Assist LLC

On this page
  • 🔹 Step 1: Overview of AWS Storage Types
  • 🔹 Step 2: Object Storage with Amazon S3
  • 🔹 Step 3: Block Storage with Amazon EBS
  • 🔹 Step 4: File Storage with Amazon EFS & Amazon FSx
  • 🔹 Step 5: Comparing AWS Storage Services for SecureCart
  • 🚀 Summary
  1. Study Group
  2. AWS Certified Solutions Architect - Associate
  3. Domain 3
  4. Task Statement 3.1: Determine high-performing and/or scalable storage solutions

Understanding AWS Storage Types & Use Cases

AWS offers various storage options to meet different use cases, balancing performance, scalability, durability, and cost. SecureCart, as an e-commerce platform, needs to store and manage product images, order transactions, logs, and customer data efficiently using the appropriate AWS storage services.

✔ Why does SecureCart need different AWS storage types?

  • Scalability: Handles growing product catalogs and customer data.

  • Performance: Ensures fast access to frequently used data (e.g., customer sessions, inventory updates).

  • Durability: Prevents data loss by replicating storage across multiple AWS Availability Zones (AZs).

  • Cost Optimization: Uses tiered storage solutions for cost-effective data management.


🔹 Step 1: Overview of AWS Storage Types

✔ AWS Storage is categorized into three main types:

Storage Type

Purpose

SecureCart Use Case

Object Storage (Amazon S3)

Stores unstructured data such as images, backups, and logs.

Stores product images, order receipts, and static website content.

Block Storage (Amazon EBS)

Provides low-latency storage for compute workloads (EC2).

Stores SecureCart’s database files and transaction logs for high-speed access.

File Storage (Amazon EFS & FSx)

Provides shared storage for multiple instances.

Hosts shared files for SecureCart’s microservices and application logs.

✅ Best Practices: ✔ Use S3 for durable, cost-effective storage of static assets. ✔ Use EBS for databases requiring low-latency access. ✔ Use EFS for microservices that require shared file systems.


🔹 Step 2: Object Storage with Amazon S3

✔ What is Amazon S3? Amazon S3 is a highly scalable, durable, and secure object storage service that is ideal for storing unstructured data like media files, logs, backups, and static content.

✔ Key Features of S3:

  • 99.999999999% (11 nines) durability for data reliability.

  • Global availability with Cross-Region Replication (CRR).

  • Lifecycle policies for automatic archiving and cost optimization.

✔ SecureCart’s Use Cases for Amazon S3:

Feature

Purpose

SecureCart Implementation

S3 Standard

General-purpose, high-performance storage.

Stores product images and static website files.

S3 Intelligent-Tiering

Auto-moves data between access tiers based on usage.

Optimizes storage costs for transaction logs.

S3 Glacier

Low-cost archival storage.

Stores order history and compliance-related data.

S3 Object Lock

Protects objects from being deleted or modified.

Prevents accidental deletion of transaction records.

✅ Best Practices: ✔ Use S3 Lifecycle Policies to move data to lower-cost tiers automatically. ✔ Enable versioning to protect against accidental overwrites or deletions. ✔ Encrypt all sensitive data in S3 using AWS KMS.


🔹 Step 3: Block Storage with Amazon EBS

✔ What is Amazon EBS? Amazon Elastic Block Store (EBS) is low-latency, high-performance storage designed for use with Amazon EC2 instances. It provides persistence for compute workloads such as databases and transaction logs.

✔ SecureCart’s Use Cases for Amazon EBS:

EBS Volume Type

Purpose

SecureCart Implementation

gp3 (General Purpose SSD)

Balances cost and performance for most workloads.

Used for SecureCart’s database and web servers.

io2 (Provisioned IOPS SSD)

High-performance database storage.

Ensures low-latency access for checkout transactions.

st1 (Throughput Optimized HDD)

Optimized for sequential workloads like big data.

Used for SecureCart’s analytics and reporting systems.

✅ Best Practices: ✔ Use Multi-Attach EBS for high-availability architectures. ✔ Enable EBS Snapshots for backup and disaster recovery. ✔ Monitor and optimize EBS IOPS to match application needs.


🔹 Step 4: File Storage with Amazon EFS & Amazon FSx

✔ What is Amazon EFS & Amazon FSx? Amazon EFS and FSx provide shared file storage for applications that require multiple compute resources to access the same data.

✔ SecureCart’s Use Cases for File Storage:

File Storage Service

Purpose

SecureCart Implementation

Amazon EFS (Elastic File System)

Scalable, serverless file storage for Linux workloads.

Hosts shared assets for SecureCart’s application microservices.

Amazon FSx for Windows

Fully managed Windows file server.

Supports SecureCart’s legacy applications that require SMB-based file sharing.

Amazon FSx for Lustre

High-speed parallel file system.

Enhances SecureCart’s AI-based product recommendations.

✅ Best Practices: ✔ Use EFS for applications requiring shared storage across multiple EC2 instances. ✔ Enable automatic backups and encryption for FSx. ✔ Choose FSx for Lustre when performance-intensive workloads are required.


🔹 Step 5: Comparing AWS Storage Services for SecureCart

✔ Which storage solution is right for SecureCart’s workloads?

Requirement

Recommended AWS Service

Scalable object storage for product images and logs

Amazon S3

High-performance block storage for databases

Amazon EBS

Shared file storage for microservices

Amazon EFS

Low-cost archival storage for transaction history

Amazon S3 Glacier

Real-time session caching for fast access

Amazon ElastiCache (Redis)

✅ Best Practices: ✔ Use a combination of S3, EBS, and EFS based on workload needs. ✔ Optimize cost by moving infrequently accessed data to archival storage (S3 Glacier). ✔ Monitor storage performance using Amazon CloudWatch.


🚀 Summary

✔ Use Amazon S3 for scalable, cost-effective object storage. ✔ Deploy Amazon EBS for high-performance block storage, especially for databases. ✔ Utilize Amazon EFS and FSx for shared file storage across applications. ✔ Optimize cost and performance using storage tiering and caching. ✔ Monitor storage utilization and performance using AWS monitoring tools.

Scenario:

SecureCart must choose the right storage types for its applications, considering performance, cost, and scalability.

Key Learning Objectives:

✅ Understand object, file, and block storage types ✅ Learn when to use Amazon S3, EFS, and EBS ✅ Identify appropriate storage services for different workloads

Hands-on Labs:

1️⃣ Deploy an S3 Bucket & Enable Versioning 2️⃣ Set Up Amazon EBS for an EC2 Instance 3️⃣ Create an Amazon EFS File System for Shared Storage

🔹 Outcome: SecureCart chooses the right AWS storage services based on workload requirements.

PreviousSecureCart JourneyNextStorage Performance & Configuration Best Practices

Last updated 3 months ago