AWS 006: Entry skills and personal-account safety
Purpose of this checkpoint
This checkpoint verifies that you can begin the cloud and IT foundation safely. It is not an AWS certification exam. It tests the operating habits that every later lab depends on.
Experienced Linux administrators may use this checkpoint as a fast-track assessment. If the instructor verifies equivalent evidence and the learner passes the safety, account, cost, Region, naming, and command-interpretation tasks, the mechanical Linux refresher work in AWS 017 may be skipped. Learners with a gap complete AWS 017 as remediation. No fast track bypasses AWS-specific lessons.
Complete the tasks without using the AWS CLI. CloudShell and AWS CLI are introduced later with identity, Region, syntax, output, and error handling.
Rules
- Use your normal Linux user, not
root. - Do not use
sudo. - Do not create an AWS service resource.
- Do not expose an account ID, password, MFA value, access key, session token, private key, payment detail, or personal contact.
- Read each command explanation before running it.
- Record actual evidence. Do not mark an unchecked item as complete.
Critical safety failures:
- publishing a credential or secret;
- creating a root access key;
- using the AWS root user for an unrelated everyday task;
- creating a chargeable AWS resource during this checkpoint;
- claiming cleanup or verification that did not occur.
Task 1: Linux evidence handling, 20 points
1.1 Confirm execution context
Run:
whoami
pwd
whoami displays the current Linux user. pwd displays the current directory.
Pass condition:
whoamidoes not returnroot;- the working directory is a location your user owns.
1.2 Create the checkpoint directory
Run:
mkdir -p "$HOME/nitwings-aws/evidence/aws-006"
1.3 Create a controlled source file
Run:
printf '%s\n' \
'lesson=AWS-006' \
'user=normal-linux-user' \
'aws_resources_created=none' \
> "$HOME/nitwings-aws/evidence/aws-006/source.txt"
1.4 Copy rather than overwrite the source
Run:
cp \
"$HOME/nitwings-aws/evidence/aws-006/source.txt" \
"$HOME/nitwings-aws/evidence/aws-006/submission.txt"
cp copies the first path to the second path.
1.5 Verify contents and integrity
Run:
sed -n '1,10p' "$HOME/nitwings-aws/evidence/aws-006/submission.txt"
sha256sum \
"$HOME/nitwings-aws/evidence/aws-006/source.txt" \
"$HOME/nitwings-aws/evidence/aws-006/submission.txt"
sha256sum calculates a fingerprint for each file. Because the copy is identical, both fingerprints should match.
Pass evidence:
- the three expected lines are visible;
- the two SHA-256 values match;
- no command required
sudo.
Scoring:
- 5 points for safe execution context;
- 5 points for correct directory and files;
- 5 points for correct displayed content;
- 5 points for matching hashes and explanation.
Task 2: Placeholder and command interpretation, 15 points
Consider:
COURSE_REGION="<COURSE_REGION>"
Answer:
- Should this be used without editing?
- What do the angle brackets mean?
- What would a valid replacement look like?
- Does setting this shell variable create an AWS resource?
Expected answer:
- No.
- The value is a placeholder.
- A valid Region code selected in AWS 004, for example
ap-south-1orus-east-2. - No. It changes only the current shell state.
Scoring:
- 10 points for all four answers;
- 5 points for explaining that a future AWS command still needs identity and Region verification even after the variable is set.
Task 3: Account ownership and identity, 15 points
For each action, choose root, everyday learner identity, or workload role.
| Action | Your answer |
|---|---|
| Change a root-user setting that only root can change | |
| Browse and build normal course labs | |
| Allow an EC2 instance to read one approved S3 object | |
| Create programmatic root access keys | |
| Use temporary credentials for a workload |
Expected answers:
| Action | Correct answer |
|---|---|
| Change a root-only setting | Root, only for that task |
| Browse and build normal course labs | Everyday learner identity |
| Allow EC2 to read an approved S3 object | Workload role |
| Create programmatic root access keys | Never do this |
| Use temporary credentials for a workload | Workload role |
Scoring: 3 points each.
Task 4: Cost and cleanup reasoning, 20 points
Scenario:
A lesson creates an EC2 instance with an EBS volume and an Elastic IP. The learner stops the instance, closes the browser, and reports that cleanup is complete.
Answer:
- Is cleanup complete?
- Which retained components might still matter for cost?
- What evidence should be checked?
- Why is a budget alert insufficient proof?
Expected reasoning:
- No, stopping an instance is not dependency-aware cleanup.
- EBS storage, Elastic IP or other public IPv4 use, snapshots, and related resources can remain.
- Inspect resource lists in the correct Region, resource state, tags, deletion settings, the course inventory, and later billing data.
- Budget information can be delayed and is a notification mechanism, not a deletion or hard-stop guarantee.
Scoring:
- 5 points for rejecting the cleanup claim;
- 5 points for identifying retained components;
- 5 points for a Regional evidence plan;
- 5 points for explaining the budget limitation.
Task 5: Region, naming, and tagging, 15 points
Scenario:
You are asked to create a learning VPC in lesson AWS 053 for project P04. No resource is created in this checkpoint.
Write:
- the proposed resource name;
- the six course tag keys;
- the Region evidence required before creation;
- one value that must never be placed in a tag.
Expected example:
Name: nw-aws053-vpc
Tags: Course, Lesson, Project, Environment, OwnerAlias, DeleteAfter
Region evidence: the selected Region code matches the AWS 004 decision
Never tag: password, secret key, token, personal email, or other sensitive data
Scoring:
- 4 points for the name;
- 6 points for tag keys;
- 3 points for Region evidence;
- 2 points for a prohibited sensitive value.
Task 6: Select the correct learning treatment, 15 points
Match each requirement to its primary treatment:
| Requirement | Treatment |
|---|---|
| Explain who manages the operating system in IaaS, PaaS, and SaaS | |
| Build and verify an EC2 server | |
| Diagnose an unreachable application | |
| Select a disaster recovery design from business targets | |
| Deploy a repeatable VPC from source control |
Available treatments:
- concept lesson;
- guided lab;
- break-fix lab;
- architecture challenge;
- automation lab.
Each correct match is worth 3 points.
Record the checkpoint result
Create:
printf '%s\n' \
'Task 1 Linux evidence: __/20' \
'Task 2 placeholder interpretation: __/15' \
'Task 3 account identity: __/15' \
'Task 4 cost and cleanup: __/20' \
'Task 5 Region naming and tagging: __/15' \
'Task 6 learning treatment: __/15' \
'Total: __/100' \
'Critical safety failure: YES/NO' \
'Result: PASS/REMEDIATE' \
> "$HOME/nitwings-aws/evidence/aws-006/checkpoint-result.txt"
Fill in the scores after checking the expected answers.
Display:
sed -n '1,20p' "$HOME/nitwings-aws/evidence/aws-006/checkpoint-result.txt"
Troubleshooting the local task
Permission denied
Likely cause: you tried to write outside your home directory or the evidence directory has incorrect ownership.
Check:
whoami
ls -ld "$HOME" "$HOME/nitwings-aws" "$HOME/nitwings-aws/evidence"
Do not fix the problem with sudo. Use a directory owned by your normal user.
No such file or directory
Likely cause: a parent directory or filename differs.
Check:
ls -la "$HOME/nitwings-aws/evidence"
ls -la "$HOME/nitwings-aws/evidence/aws-006"
Re-run the exact mkdir -p command if aws-006 is missing.
Hashes do not match
Likely cause: submission.txt was modified after it was copied.
Compare:
diff \
"$HOME/nitwings-aws/evidence/aws-006/source.txt" \
"$HOME/nitwings-aws/evidence/aws-006/submission.txt"
No output means the files match. Any displayed line identifies a difference.
Pass, remediation, and retest
Pass when:
- total score is at least 80;
- every required evidence file exists;
- there is no critical safety failure.
Remediate when:
- the score is below 80;
- a task has missing evidence;
- an answer relies on an unsafe assumption;
- a critical safety failure occurred.
Retest only the failed task after reviewing AWS 001 through AWS 005. A critical safety failure requires a complete safety review before continuing.
Submission
Submit:
source.txt;submission.txt;- the two matching SHA-256 values;
checkpoint-result.txt;- short answers for Tasks 2 through 6;
- no secrets or sensitive account data.
Cleanup
No AWS resource should exist from this checkpoint.
The local aws-006 evidence directory is retained as the checkpoint record. If you created test files outside it, remove only those exact test files after confirming their paths.