certslothcertsloth
SAA-C03/Topic 03

AWS / Associate

EC2 Fundamentals

5 min read5 recall promptsReviewed 2026-10-10

Memory hook: Match the machine to the bottleneck, the purchase model to the commitment, and access to a temporary role.

Must remember

Compute and bootstrap

  • An AMI supplies the launch image; the instance type supplies CPU, memory, networking and supported storage characteristics. Both must support the chosen CPU architecture.
  • Choose compute optimized for CPU-heavy work, memory optimized for large in-memory datasets, storage optimized for demanding local I/O, and accelerated instances for supported GPU/accelerator workloads. General purpose balances resources.
  • T-family burstable instances use CPU credits. Standard and unlimited credit modes have different sustained-load and billing consequences; a small headline hourly price is not the whole workload cost.
  • Graviton/ARM instances require compatible OS images, binaries and containers. A lower-cost architecture is not a drop-in replacement for an incompatible binary.
  • User data usually bootstraps on first launch and runs with elevated privileges. A stopped/started instance does not automatically rerun ordinary first-boot logic. Keep secrets out of it.
  • A maintained golden AMI preinstalls software; user data finishes environment-specific configuration.

Connectivity and credentials

  • Security groups are stateful allow rules attached to interfaces. Rules from associated groups combine; SGs do not have explicit deny rules. Return traffic for an allowed flow is tracked.
  • Restrict sources using CIDRs or supported SG references; references identify source interfaces, not inherited rules.
  • Common ports: SSH 22, FTP control 21, HTTP 80, HTTPS 443, RDP 3389, DNS 53, SMTP 25/587, NFS 2049. FTP data behavior and DNS TCP/UDP needs depend on the protocol use case.
  • SSH requires the right OS user/key and a reachable network path. EC2 Instance Connect supplies temporary SSH public-key access but still needs connectivity; an Instance Connect Endpoint is a separate networking option.
  • Session Manager needs an agent, IAM and service-endpoint access, without inbound SSH. Private instances can use VPC endpoints.
  • An instance role/profile provides temporary AWS credentials; IMDSv2 requires session tokens. Local software should use the role credential chain instead of permanent keys.

Buying capacity and controlling cost

Workload clue Choice Main tradeoff
Short or unpredictable use On-Demand No long-term discount commitment
Stable matching configuration Reserved Instances One/three-year commitment; flexibility varies
Stable dollar-per-hour usage Savings Plans Spend commitment; flexibility depends on plan type
Interruptible, restartable processing Spot Spare capacity can disappear
Physical licensing/placement control Dedicated Host Host management and licensing economics
Single-tenant hardware Dedicated Instances No equivalent physical host placement control
Need matching capacity in a particular AZ Capacity Reservation Unused reserved capacity can still bill
  • Standard versus Convertible RIs: discount/flexibility differ; Convertible provides supported exchanges. Regional RIs provide a billing benefit without a capacity reservation; zonal RIs reserve matching AZ capacity. Savings Plans do not themselves reserve capacity.
  • Spot Fleet/EC2 Fleet can diversify instance types and AZ capacity pools. Use retries, checkpoints and interruption-tolerant design; do not rely on one irreplaceable stateful worker.
  • Spot stop/terminate notices normally provide two minutes, on a best-effort basis. Hibernation interruption begins immediately rather than providing that same advance window.
  • AWS Budgets alerts use delayed billing data and need sufficient history for forecasts. An alert is not a hard real-time cap. EBS, snapshots, public IPv4 and commitments can keep billing after an instance stops.

Choose under exam pressure

Requirement Decision and reason
CPU saturated while RAM remains free Investigate compute sizing before buying more memory
Batch jobs can retry on another worker Spot with resilient orchestration and diversification
Must launch in one AZ at a known time Capacity guarantee, not only a discount
Administer private instances without SSH keys Session Manager with endpoint access and roles
Application must access another AWS service Least-privilege instance role

Traps

  • Discount and guaranteed capacity differ. A Savings Plan cannot fix insufficient capacity in a chosen AZ.
  • Stopped is not deleted. Retained storage, IP allocations and commitments may remain billable.
  • Timeout and refusal suggest different investigations. Routing/SG/NACL issues often time out; no application listener may refuse the connection.

Active recall

1. A financial batch job checkpoints progress and can restart. Is a cheaper Spot worker reasonable?

Yes, if deadlines tolerate interruption and variable capacity. Combine checkpoints, retries and diversified pools; price alone does not establish suitability.

2. A Savings Plan exists, but an instance cannot launch in a busy AZ. Why?

Savings Plans are billing commitments, not capacity reservations. Matching zonal reserved capacity or an appropriate Capacity Reservation addresses that separate requirement; its unused capacity cost must be considered.

3. An x86-only vendor binary fails on a cheaper t4g instance. What was missed?

CPU-architecture compatibility. t4g uses ARM; the image and application need compatible builds. Instance right-sizing includes software compatibility, not only vCPU and memory counts.

4. SSH fails despite an allowed SG rule. What else must be correct?

Routing, addressing, NACLs, the SSH server, OS username and key authorization. A security-group Allow does not establish a route or start an application. Instance Connect changes key delivery, not all networking prerequisites.

5. A stopped lab still incurs charges after a budget alert. Is this contradictory?

No. Alerts are delayed; stopping EC2 leaves EBS, snapshots and allocated IPv4. Review all resources and commitments, not compute state alone.

Terraform anchor: Module inputs can change IAM names, user data and resource identity; review replacement markers and ongoing costs before applying.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.