Lesson 247 · AWS Learning Path

AWS 247: Reliability, deployment, security, and networking

· Published · 8 min read

Labelled process diagram for AWS 247: Reliability or security scenario to Deployment and network evidence to Safe operation or recovery decision to Score, remediation, and retest, with decision, proof and rejection...

Why this checkpoint exists

AWS246 tested SOA-C03 Domain 1. This gate tests the remaining four domains before the independent operations capstone. You must reason from business requirements and evidence - not service-name recognition - across recovery, scaling, infrastructure as code, automation, IAM, encryption, compliance, VPC routing, DNS, edge delivery, and hybrid connectivity.

Current SOA-C03 scored-content weights are Reliability and Business Continuity 22%, Deployment, Provisioning, and Automation 22%, Security and Compliance 16%, and Networking and Content Delivery 18%. The exam uses compensatory scoring, but this course requires competence in every domain because a high deployment score cannot make an unsafe restore, public security-group rule, or broken route acceptable.

What is assessed

DomainCurrent tasksScenariosPractical evidence
2 Reliability and business continuityscalability/elasticity; HA/resilience; backup/restore1–8restore case
3 Deployment, provisioning, automationprovision/maintain; automate existing resources9–16failed deployment timeline
4 Security and compliancetools/policies; protect data/infrastructure17–24access investigation
5 Networking and content deliveryconnectivity; DNS/content delivery; troubleshooting25–32two packet paths

The scenarios are original course material. They are not copied exam questions, remembered exam content, or an exam dump.

Required assessment pack

Download the AWS247 Domains 2–5 checkpoint pack. It contains:

  • DOMAINS2_5_CHECKPOINT_WORKBOOK.md - answer sheet, evidence template, scoring, corrections;
  • DOMAINS2_5_SCENARIOS.md - 32 single- and multiple-response scenarios;
  • SUPPLIED_OPERATIONAL_CASES.md - five evidence cases with unfamiliar outputs;
  • INSTRUCTOR_ANSWER_DIRECTIONS.md - answer and rubric; keep closed during the timed attempt.

Use 80 minutes for scenarios and 75 minutes for evidence cases. Select the stated number of responses; a multiple-response item is correct only when the complete set is selected. Record confidence before grading. No notes, answer key, search, or AI assistance during the first attempt. Afterward, official documentation is required for correction.

Domain 2 operating model: reliability is measured recovery

demand/failure model -> scaling and fault isolation -> protected state
         -> detected event -> controlled failover/restore -> RTO/RPO proof

Scalability handles increased load; elasticity adds and removes capacity with demand. Auto Scaling target tracking, step, scheduled, and predictive policies solve different signals. Cooldowns, instance warmup, health-check grace, lifecycle hooks, launch-template versions, subnet capacity, service quotas, and load-balancer health can prevent expected scaling. A cache reduces repeated origin/database work only when cacheability, invalidation, TTL, consistency, and failure behavior are understood.

Availability is not backup. Multi-AZ can provide synchronous standby/failover but does not protect against every logical deletion or credential compromise. Read replicas serve eligible reads and can support some DR designs but replication lag affects RPO. Route 53 health checks and routing decisions need endpoint, evaluator, TTL, and failure-mode analysis.

RTO is acceptable recovery duration; RPO is acceptable data-loss window. A completed backup job proves a recovery point was produced, not that it is readable, correctly authorized, application-consistent, restorable within RTO, or protected from deletion. Test restores in an isolated environment, validate data and application behavior, record elapsed time, and clean up. Compare backup/restore, pilot light, warm standby, and active/active by RTO/RPO, complexity, consistency, operations, and cost.

Domain 3 operating model: desired state with controlled change

Infrastructure as code turns reviewed source into repeatable change, but a successful deployment is not automatically correct. CloudFormation events expose the first causal resource failure; later rollback events are consequences. Understand parameters, dependencies, conditions, outputs, change sets, stack policy, rollback behavior, drift, nested stacks, StackSets, and IAM capabilities. ROLLBACK_COMPLETE after failed creation generally cannot be updated as if creation succeeded; investigate, correct source/prerequisites, and recreate through the approved workflow.

CDK synthesizes CloudFormation; the generated template and assets remain reviewable deployment inputs. AMIs and container images need patched, scanned, versioned, reproducible pipelines and promotion - not mutable “latest” assumptions. AWS RAM shares supported resources but does not copy them. StackSets distribute stacks across accounts/Regions with administration/execution roles and bounded concurrency/failure controls.

Event-driven automation inherits duplicate delivery, retry, ordering, authorization, and loop risks. Systems Manager automation needs guard clauses, idempotency, finite waits, least privilege, verification, and compensation. Git/Terraform or another third-party tool requires remote-state protection, locking, version control, plan review, provider/version management, secret handling, and drift/ownership rules. Do not let two systems manage the same field without an explicit contract.

Domain 4 operating model: effective permission and protected data

An AWS request is allowed only when all applicable policy layers permit it and no explicit deny applies. Evaluate identity policies, resource policies, permissions boundaries, session policies, SCPs, VPC endpoint policies, KMS key policies/grants, and service-specific controls. SCPs limit maximum permissions; they do not grant access. A permissions boundary also does not grant. Role trust permits assumption; role permissions govern actions after assumption.

Use temporary federated roles, MFA, least privilege, and break-glass controls with monitoring. Troubleshoot from the denied principal, API, resource, account, Region, condition context, and CloudTrail event. The policy simulator is useful but does not reproduce every service/runtime context. IAM Access Analyzer identifies external/public access and policy findings; CloudTrail shows supported API activity.

Classify data before choosing controls. KMS key policy and IAM permission can both matter; encryption context and grants can narrow use. Rotation does not retroactively re-encrypt all ciphertext, and disabling/deleting a key can make data unavailable. ACM public certificates are Region-bound to integrating services, except CloudFront viewer certificates use us-east-1. Secrets Manager supports managed rotation workflows and version stages; Parameter Store has different features and cost. Never place secret values in templates, logs, tags, user data, or assessment submissions.

GuardDuty detects threats, Inspector assesses supported workloads/packages/images, Macie discovers sensitive S3 data, Security Hub aggregates/normalizes findings, and Config evaluates supported configuration. A finding is a lead with severity, resource, state, and evidence - not automatic proof that destructive remediation is safe.

Domain 5 operating model: packet and name path

Trace one direction at a time:

name -> resolver/record/TTL -> source ENI/subnet route
 -> SG egress -> NACL egress -> gateway/TGW/peering/endpoint/VPN
 -> destination route/NACL ingress/SG ingress -> listener/target/application
 -> stateful or stateless return path

Security groups are stateful; NACLs are stateless and require return-path ephemeral ports. A public IPv4 address is not enough without an internet-gateway route and permitted controls. Private IPv4 internet egress commonly uses a NAT gateway in a public subnet; NAT gateways do not accept unsolicited inbound connections and are not used for IPv6. An egress-only internet gateway supports outbound-initiated IPv6. Gateway endpoints add route-table entries for supported services; interface endpoints create private ENIs/DNS behavior and apply endpoint/security-group policy boundaries.

Peering is non-transitive. Transit Gateway route tables create scalable hub connectivity but association and propagation do not mean every intended route exists. Overlapping CIDRs break many routing designs. Site-to-Site VPN needs both tunnels, routes/BGP, customer gateway, phase negotiation, and symmetric paths. Flow Logs show observed accepted/rejected flows, not DNS answers or application success; Reachability Analyzer models configured paths, not live packet or application behavior.

Route 53 routing policy, health evaluation, TTL/caching, resolver rules/endpoints, private-zone association, and delegation are separate. CloudFront caches by cache key and policy; stale content can come from TTL, key omissions, origin headers, or invalidation assumptions. Global Accelerator provides static anycast IPs and routes TCP/UDP to healthy regional endpoints; it is not a content cache. Compare data-processing, hourly, cross-AZ, NAT, endpoint, transit, and egress costs.

Five practical evidence cases

The pack includes:

  1. a backup marked COMPLETED whose restore misses the RTO and lacks KMS permission;
  2. a CloudFormation deployment where the earliest failure is subnet exhaustion and rollback noise follows;
  3. an S3 denial involving an SCP, role policy, bucket policy, and KMS context;
  4. a public ALB packet path with a stateless return NACL fault;
  5. a private/hybrid path with overlapping CIDR and missing Transit Gateway route propagation.

For each, submit impact/scope, three falsifiable hypotheses, evidence for/against, next read-only discriminator, bounded correction, rollback/compensation, customer/security verification, cost effect, and prevention owner. Do not “fix networking” with 0.0.0.0/0, disable encryption, bypass an SCP, delete a stack, or restore over the source.

Optional read-only inventory

The supplied track is complete. With account-owner permission, prove caller/Region and redact identifiers:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws backup list-recovery-points-by-backup-vault --backup-vault-name replace-me
aws cloudformation describe-stack-events --stack-name replace-me --max-items 50
aws iam get-role --role-name replace-me
aws ec2 describe-route-tables --filters Name=vpc-id,Values=vpc-redacted
aws ec2 describe-network-acls --filters Name=vpc-id,Values=vpc-redacted
aws route53 list-resource-record-sets --hosted-zone-id replace-me

Inventory alone does not prove recovery, deployment correctness, effective permission, packet reachability, DNS behavior, or cleanup. This checkpoint authorizes no mutations.

Scoring gate

  • Scenarios: 32 points, eight per domain.
  • Practical cases: 50 points, ten per case.
  • Total: 82 points.

Pass requires at least 26/32 scenarios, at least 40/50 practical, at least 6/8 in each domain, at least 8/10 in each practical case, and no critical safety miss. Critical misses include destructive recovery without isolation, broad public access, bypassing governance, exposing a secret, unbounded automation, changing before diagnosis, or claiming success without restore/customer/packet evidence.

These are course thresholds, not AWS exam score claims. Every wrong or low-confidence response receives an error label - concept, scope, evidence, wording, safety, or confidence - an official-source correction, deliberate practice, and a changed retest. Memorizing answer letters does not satisfy the gate.

Cost, privacy, and cleanup

This assessment creates nothing. Real designs must price standby capacity, backup storage/copies/restores, snapshots, cross-Region/account transfer, NAT/endpoint/TGW/VPN processing and hours, CloudFront invalidations/transfer, logs, Config evaluations, findings, KMS requests, Automation steps, and temporary restore resources. Redact account IDs, full ARNs, public/private addresses when sensitive, customer data, key material, tokens, and presigned URLs. Evidence needs an owner and expiry.

Acceptance evidence

Submit timed original answers and confidence, all five case analyses, per-domain/practical scores, error taxonomy, official-source corrections, changed retests, and signed no-create statement. The reviewer must be able to trace each conclusion to evidence and each proposed change to a rollback and verification plan.

Official sources

Advertisement