certslothcertsloth
SAA-C03/Topic 28

AWS / Associate

Other Services

6 min read5 recall promptsReviewed 2026-10-10

Memory hook: Separate deployment, administration, cost evidence and application delivery before choosing a tool.

Must remember

Ownership and controlled administration

  • CloudFormation manages stack resources. Its logical resource ID, the AWS physical ID and a Terraform wrapper's resource address are different identities. Importing a stack-owned child into another state without transferring ownership creates competing lifecycle control.
  • A CloudFormation service role supplies execution permissions. Associating or changing it requires appropriate iam:PassRole permission; users authorized to operate an existing stack can use its already-associated role without their own PassRole permission. Scope both the role and access to the stack carefully.
  • Systems Manager Session Manager provides interactive access without inbound SSH when the managed agent, IAM and service connectivity are configured. Run Command executes documents across managed nodes. Patch Manager applies approved patch baselines; Automation orchestrates multi-step operational runbooks. A document's existence does not execute it.
  • Service Catalog distributes approved infrastructure products with governance constraints, useful when teams should self-provision standardized options. License Manager helps track and manage software-license usage and rules; it does not magically supply licenses or eliminate vendor contract requirements.
  • The AWS CLI and Management Console both require appropriate identities and permissions; neither bypasses IAM.

Match the money question

  • Pricing Calculator: estimate a proposed architecture before deployment. Include storage, requests, transfer and networking rather than only compute.
  • Cost Explorer: explore historical cost/usage, trends and forecasts. Cost and Usage Reports (CUR) provide detailed billing data for custom analysis, commonly delivered to S3; current Data Exports options extend the reporting choices.
  • AWS Budgets: compare spend or usage against thresholds and notify or run separately configured actions. Cost Anomaly Detection: identify unusual spending patterns. Neither is a guaranteed immediate account spending cap; billing and notification delays matter.
  • Compute Optimizer: suggests resource configuration improvements using observed utilization for supported resources. Validate recommendations against peak demand, application performance and recovery capacity; a quiet monitoring window can hide important workload needs.
  • Cost allocation tags help attribute spend after required billing activation; they do not guarantee complete historical attribution. Consolidated billing changes cost visibility and potential discount sharing, not resource ownership.
  • Right-size and remove waste before evaluating commitments. Stable workloads may justify Reserved Instances or Savings Plans; interruptible work may suit Spot. Compare operational effort and commitment risk with the compute choices in capacity notes.
  • Instance Scheduler is a deployed AWS solution for scheduled resource stops/starts. A stopped instance can still leave storage, snapshots and some address/network charges. Scheduling is not complete teardown.

Delivery, media and application integration

  • SES sends email with identity verification and applicable sending restrictions. Pinpoint engagement is the historical campaign/journey service: closed to new customers, with support scheduled to end October 30, 2026, still upcoming on this pack's October 9 review. Channel APIs have separate migration paths.
  • Elastic Transcoder retired November 13, 2025 but remains named in the published exam service list. Retain the media-transcoding concept; evaluate a supported service such as MediaConvert for real deployments. Kinesis Video Streams ingests and manages video streams for playback/processing; it is different from generic ordered application records in Kinesis Data Streams.
  • Batch queues jobs and orchestrates compute environments; underlying compute/storage still bill. AppFlow transfers data between supported SaaS and AWS systems; connectors and external authorization determine feasibility.
  • Amplify provides frontend/application development and delivery tooling, with build, hosting and backend resource lifecycles. Device Farm tests applications on supported device/browser environments; it is a testing service, not the application's production hosting platform.
  • Check service status: exam scope and deployment availability differ. Legacy exam concepts never justify prohibited subscriptions or costly capacity here.

Choose under exam pressure

Clue in the requirement Choose or investigate
Estimate a design before launch Pricing Calculator
Explore monthly spend trends Cost Explorer
Analyze detailed billing line items yourself CUR/Data Exports and an analytical pipeline
Recommend resource sizing from observed utilization Compute Optimizer
Publish approved self-service infrastructure options Service Catalog
Track supported software-license usage License Manager
Apply approved OS patches across a fleet Patch Manager
Move records from a supported SaaS system to S3 AppFlow
Test a mobile app across real devices Device Farm

Traps

  • A recommendation is not automatically a safe production change; validate business and recovery requirements.
  • Setting a budget does not instantly stop every charge, and stopping compute does not delete its other resources.
  • An existing stack's service-role permissions can exceed a caller's direct permissions; control who may operate that stack.

Active recall

1. A team needs a forecast before deployment and detailed analysis after deployment. Which cost tools answer the separate questions?

Use Pricing Calculator for assumptions about the proposed design, then Cost Explorer for spend exploration or CUR/Data Exports for detailed custom analysis. An estimate is not observed billing evidence.

2. An engineer can update a stack but cannot pass a new IAM role. Can its existing service role still matter?

Yes. Authorized stack operations can use the already-associated service role even without the engineer having independent PassRole permission. Limit the role and stack-operation permissions to avoid unintended escalation.

3. Developers should deploy only approved infrastructure templates while choosing allowed parameters. What fits better than copying snippets into a wiki?

Service Catalog can publish approved products and apply governance constraints. Documentation remains useful, but it does not itself enforce the self-service provisioning boundary.

4. Compute Optimizer suggests shrinking a standby instance. Why should the team hesitate before applying the recommendation?

Observed quiet usage may reflect its standby role rather than future failover demand. Validate recovery capacity, startup/scaling time and performance requirements before reducing it.

5. An overnight stop schedule reduced EC2 compute cost, but billing continues. Is the scheduler necessarily broken?

No. EBS, snapshots, retained resources and some networking/address allocations can continue billing. Inventory those resources and distinguish temporary stopping from full teardown.

Terraform anchor: Manage a remote object through one authoritative owner, and account for the lifecycle of supporting resources rather than treating a stopped workload as deleted.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.