AWS SAA · Domain 4
Design Cost-Optimized Architectures
About 20% of the exam
Pricing models for compute
- On-Demand
- no commitment, highest hourly rate
- Reserved Instance
- one or three year commitment
- Savings Plan
- commit to hourly spend
- Spot
- spare capacity, can be reclaimed
- Dedicated Host
- physical server, licensing control
- Dedicated Instance
- isolated hardware, no host visibility
- Capacity Reservation
- guarantees capacity in a zone
- Free tier
- limited, expires after twelve months
Steady baseline on a commitment, variable peaks on demand, and anything interruptible on Spot
Savings Plans and Reserved Instances
- Compute Savings Plan
- most flexible across services
- EC2 Instance Savings Plan
- family and Region locked
- Standard Reserved Instance
- biggest discount, least flexible
- Convertible Reserved Instance
- exchangeable for another type
- Payment options
- all, partial or no upfront
- Regional scope
- flexible across zones
- Zonal scope
- reserves capacity in one zone
- Coverage report
- shows uncommitted steady usage
Spot done safely
- Two minute interruption notice
- Diversify across families and zones
- Mixed instances policy blends purchase options
- Checkpoint long running jobs frequently
- Never run the only database
- Batch and rendering suit Spot
- Capacity optimized allocation lowers interruptions
Storage cost levers
- Match the class to access frequency
- Intelligent-Tiering when patterns are unknown
- One Zone classes for reproducible data
- Delete incomplete multipart uploads
- Old snapshots accumulate quietly
- gp3 usually beats gp2 on cost
- Detach and delete unused volumes
S3 lifecycle rules
- Transition objects between storage classes
- Expire objects after a retention period
- Abort incomplete multipart uploads automatically
- Expire noncurrent versions on versioned buckets
- Minimum storage duration charges apply
- Retrieval costs rise as tiers cool
- Storage Lens shows where bytes sit
Where the data transfer bill comes from
Free or cheap
- Inbound traffic to AWS
- Same zone private addresses
- Gateway endpoints to S3
- CloudFront to an origin in AWS
Charged
- Outbound to the internet
- Cross-zone chatter between tiers
- Cross-Region replication traffic
- NAT gateway processing per gigabyte
Fixes
- Endpoints instead of NAT paths
- Keep chatty services in one zone
- CloudFront in front of egress
- Compress before you transfer
Database cost levers
- Single-AZ for development environments
- Stop non-production instances overnight
- Aurora Serverless for spiky workloads
- On-demand against provisioned DynamoDB capacity
- Reserved nodes for steady clusters
- Right-size before adding replicas
- Trim automated backup retention
Serverless cost thinking
- Pay per request and duration
- Memory setting changes both speed and cost
- Idle costs nothing at all
- Provisioned concurrency is a standing charge
- Graviton runtimes cost less per millisecond
- Chatty state machines add transition charges
- HTTP APIs cost less than REST
Cost visibility tooling
- Cost Explorer
- trends, forecasts and grouping
- Cost and Usage Report
- line level detail in S3
- Budgets
- alerts when spend crosses thresholds
- Cost Anomaly Detection
- flags unusual spend automatically
- Compute Optimizer
- right-sizing advice from metrics
- Trusted Advisor
- idle and underused resource checks
- Pricing Calculator
- estimate before you build
- Cost allocation tags
- attribute spend to teams
Governance for spend
- Consolidated billing pools volume discounts
- Tag policies keep allocation tags clean
- An SCP denies expensive instance families
- Budget actions can stop resources
- Expiry tags for temporary environments
- Review cost as a recurring ritual
The right-sizing loop
- Measure utilization
- Compare recommendations
- Change one thing
- Verify performance
- Repeat quarterly
Cost work is continuous because usage patterns and pricing options both keep changing underneath you
Cost anti-patterns
- Idle load balancers and elastic addresses
- Orphaned snapshots and stale images
- Multi-AZ on every test database
- NAT gateway carrying all S3 traffic
- Logging everything at full detail
- Reservations bought before measuring usage
Rapid recall: cheapest fit
- Interruptible batch
- Spot Instances
- Steady three year baseline
- Compute Savings Plan
- Unknown access pattern
- S3 Intelligent-Tiering
- Archive kept for years
- S3 Glacier Deep Archive
- Frequent S3 calls privately
- gateway endpoint
- Spiky database traffic
- Aurora Serverless
- Attribute spend to teams
- cost allocation tags
- Catch a surprise bill
- Cost Anomaly Detection
Reference strip: buy, store, move, run, watch
Buy right
- On-Demand for unpredictable load
- Savings Plans for the baseline
- Spot for interruptible work
- Reservations only after measuring
Store right
- Class matched to access
- Lifecycle rules automate transitions
- Delete orphaned snapshots
- Prefer gp3 over gp2
Move right
- Endpoints instead of NAT
- CloudFront for egress
- Keep traffic in zone
- Compress before transfer
Run right
- Right-size from real metrics
- Stop idle non-production resources
- Serverless for spiky loads
- Auto Scaling follows demand
Watch it
- Cost Explorer and budgets
- Anomaly detection alerts
- Allocation tags per team
- Quarterly review cadence
Quick exam traps
- Trap: Reserved Instances can be refunded when the workload changes
- Trap: Spot Instances are reclaimed only when you stop paying
- Trap: Data transferred into AWS costs the same as data leaving it
- Trap: Glacier Deep Archive is cheaper for data read every week
- Trap: Consolidated billing stops volume discounts from pooling
- Trap: Intelligent-Tiering carries no monitoring charge per object
- Trap: A NAT gateway is cheaper than a gateway endpoint for S3
cybercertprep.com · original revision sheet written from the public body of knowledge