QUICK REFERENCE
Compare Common Comparisons
Compare services with similar names, purposes, or exam scenarios.PUBLIC NOTES
Knowledge Notes
Console vs Local CLI vs CloudShell vs SDK vs CloudFormation
Compares graphical operations, local commands, browser shell, application code, and declarative infrastructure.
→IAM Policy Types, JSON, and Permission Evaluation
Connects IAM policy attachment, JSON elements, and final permission evaluation.
→Credentials Report vs Access Advisor vs Access Analyzer vs Policy Simulator
Separate credential inventory, usage timing, access-path analysis, and request authorization simulation.
→Password Policy, MFA, Access Key, and Temporary Credentials
Separates password rules, additional authentication factors, long-term keys, and expiring credentials.
→Root User, IAM User, Group, Policy, and Role
Distinguishes identities, user collections, permission rules, and assumable temporary identities.
→Architecture, Dev Tools, End-User Computing & Business Services
Choose quickly among standards, reviews, observability, delivery pipelines, APIs, communications, apps, desktops, browsers, and devices.
→AWS Account, Identity, Session, Region, and Visibility
A layered way to troubleshoot why an AWS resource is not visible.
→DMS vs SCT
DMS moves and replicates database data, while AWS SCT converts schemas and code for heterogeneous migrations.
→Migration Phases, 7Rs & AWS Migration Services
Separate project sequence, application strategy, and the services used for evaluation, discovery, replication, transfer, and coordination.
→Region, AZ, Edge, Global, and Regional Scope
A single comparison of AWS geographic layers, service scope, and resource placement.
→Billing, Budgets, Cost Explorer, Pricing Calculator & Support
Compare AWS billing, budgets, cost analysis, estimates, optimization, procurement, and support responsibilities.
→Monitoring, Audit, Compliance & Governance
Compare AWS monitoring, audit, compliance, multi-account governance, and best-practice services.
→Amazon Athena vs Amazon Redshift
Athena fits ad hoc queries directly over S3; Redshift fits sustained, frequent, and complex warehouse analytics.
→AWS AI Services vs SageMaker vs ML Infrastructure
The three layers differ in ready-made capability, customization, low-level control, and operational responsibility.
→Inspector vs GuardDuty vs Macie vs Detective vs Security Hub
Vulnerability scanning, threat detection, sensitive-data discovery, investigation, and centralized aggregation cover different stages of the security workflow.
→Kinesis Data Streams vs Amazon Data Firehose
Both handle streaming data, but Data Streams provides a readable, replayable stream while Data Firehose provides managed delivery.
→KMS vs Secrets Manager vs ACM
KMS manages encryption keys, Secrets Manager manages secret values, and ACM manages certificates used for HTTPS.
→SageMaker JumpStart vs Bedrock vs Amazon Q
JumpStart is a model starting point in SageMaker, Bedrock is a foundation-model API platform, and Amazon Q is a ready-made assistant.
→WAF vs Shield vs Security Group
WAF filters Layer 7 requests, Shield mitigates DoS and DDoS, and security groups control resource-level network connections.
→Client VPN vs Site-to-Site VPN vs PrivateLink vs Direct Connect
Choose by who connects, whether a whole network is linked, whether access is service-private, and whether a dedicated circuit is required.
→CloudWatch vs CloudTrail vs Config
CloudWatch monitors operations, CloudTrail records API activity, and AWS Config tracks resource configuration and compliance.
→DAX vs ElastiCache vs Read Replica vs CloudFront
Choose DAX for DynamoDB caching, ElastiCache for application caching, read replicas for database reads, and CloudFront for edge delivery.
→DRS vs AWS Backup vs EBS Snapshot vs Storage Gateway
DRS recovers servers, AWS Backup governs backups, EBS snapshots protect volumes, and Storage Gateway provides hybrid storage interfaces.
→EC2 vs Lambda vs Fargate
Choose EC2 for host control, Lambda for short event-driven functions, and Fargate for serverless container tasks.
→ECS vs EKS
ECS offers simpler AWS-native orchestration, while EKS provides managed Kubernetes compatibility and ecosystem access.
→Multi-AZ vs Multi-Region
Multi-AZ protects availability within one Region; Multi-Region addresses regional disasters, global latency, or residency.
→RDS vs Aurora vs DynamoDB
Use RDS for managed relational engines, Aurora for AWS-optimized relational workloads, and DynamoDB for serverless key-value access.
→RDS vs DynamoDB vs DocumentDB vs Neptune
Select the database by data model and access pattern: relational, key-value, document, or graph.
→Route 53 vs CloudFront vs Global Accelerator
Route 53 selects destinations through DNS, CloudFront caches content at the edge, and Global Accelerator optimizes global network paths.
→S3 vs EBS vs EFS vs FSx
Choose S3 for objects, EBS for instance-attached blocks, EFS for shared Linux files, and FSx for specialized managed file systems.
→SQS vs SNS vs EventBridge
Use SQS to queue work, SNS to fan out notifications, and EventBridge to route structured events by rules.
→Security Group vs NACL
A comparison of stateful resource-level security and stateless subnet-level access control, including their roles in design and troubleshooting.
→TOPIC INDEX