AWS Services A–Z

Glossary 113+ service liên quan SAA-C03

Mô tả một câu + “khi nào dùng” + tip thi. Nhanh ôn tên khi gặp câu hỏi trong đề. Click vào service có biểu tượng ▾ để xem sơ đồ.

113/113 service

A

Amplify

Developer
Fullstack mobile/web

Host + backend (Auth, Data, Storage) cho frontend dev.

API Gateway

Integration
API GW

REST/HTTP/WebSocket API managed.

Khi dùng: Expose Lambda/HTTP backend.

Exam tip: REST full feature $ vs HTTP cheap; WebSocket cho 2-chiều; throttle 10k/s.

App Mesh

Networking
Service mesh

Envoy-based service mesh managed.

Khi dùng: Microservice cần observability + traffic shaping nội bộ.

App Runner

Developer
Simple container PaaS

Deploy container/image với 1 bước.

Application Migration Service

Migration
MGN

Lift-and-shift EC2 từ on-prem/VMware/cloud khác.

AppSync

Integration
Managed GraphQL

GraphQL + subscription realtime.

Khi dùng: Mobile/web cần data fetching flex.

Athena

Analytics
Serverless SQL on S3

Query data S3 bằng SQL không cần load.

Khi dùng: Ad-hoc analysis log/parquet/csv S3.

Audit Manager

Security
Compliance audit

Chuẩn hóa evidence cho compliance framework.

Aurora

Database
Cloud-native SQL

MySQL/Postgres compatible, 5x/3x performance.

Khi dùng: High-scale SQL, serverless v2, Global Database.

Exam tip: Storage 10-128TB; 15 replica; Global DB 5 secondary region; Backtrack 72h.

B

Backup

Storage
AWS Backup

Centralize backup cho nhiều service.

Khi dùng: Policy 1 chỗ cho EBS/RDS/EFS/DynamoDB/Storage Gateway/FSx/EC2.

Batch

Compute
AWS Batch

Orchestrate batch job trên EC2/Fargate/Spot.

Khi dùng: Scientific compute, image rendering, ML offline.

Budgets

Management
Budget alerts

Cost/usage/RI coverage alert.

C

CDK

Developer
Cloud Dev Kit

IaC bằng code (TS/Python/Java/Go).

Certificate Manager

Security
ACM

Phát cert TLS free cho AWS service.

Khi dùng: HTTPS cho CloudFront/ALB/API GW/App Runner.

Exam tip: Public cert chỉ us-east-1 cho CloudFront; Private CA có phí.

Client VPN

Networking
Remote worker VPN

OpenVPN-based cho user cá nhân.

Khi dùng: Remote worker truy cập VPC/on-prem.

Cloud Map

Networking
Service discovery

Map tên service → IP/ARN động.

Khi dùng: Service discovery cho ECS/EKS/EC2 dynamic.

CloudFormation

Management
IaC native

JSON/YAML template khai báo resource.

Khi dùng: IaC chuẩn AWS.

CloudFront

Networking
CDN

CDN 600+ PoP với WAF/cache.

Khi dùng: Static + dynamic content toàn cầu.

Exam tip: OAC thay OAI; Signed URL/Cookie; Functions vs Lambda@Edge.

CloudHSM

Security
Hardware Security Module

HSM tenant single, FIPS 140-2 level 3.

Khi dùng: Compliance yêu cầu HSM độc quyền.

CloudTrail

Management
API audit

Audit trail mọi API call.

Khi dùng: Compliance audit, security investigation.

Exam tip: Management event default 90 ngày, data event opt-in $.

CloudWatch

Management
Metrics/Logs/Alarms

Observability: metric, log, alarm, event, dashboard.

Khi dùng: Mọi thứ monitoring.

CodeBuild

Developer
CI build

Build container managed pay-per-minute.

CodeCommit

Developer
Managed git

Git repo quản bởi AWS.

CodeDeploy

Developer
App deploy

Blue/green, rolling cho EC2/ECS/Lambda.

CodePipeline

Developer
CI/CD

Pipeline source → build → test → deploy.

Cognito

Security
User identity

User Pool (auth) + Identity Pool (authz IAM temp).

Khi dùng: Mobile/web app sign-in, social federation.

Comprehend

ML
NLP

Sentiment, entity, topic modelling.

Compute Optimizer

Management
Rightsize

ML recommendation rightsize EC2/ASG/EBS/Lambda/ECS.

Config

Management
Resource config + compliance

Inventory + change + compliance rule.

Khi dùng: Drift detection, compliance.

Control Tower

Management
Landing zone

Multi-account best-practice setup.

Cost Explorer

Management
Cost analysis

Visualize cost theo tag, service, thời gian.

D

Data Exchange

Analytics
3rd-party data

Marketplace dataset bên thứ ba.

DataSync

Migration
Data move

Move file on-prem → S3/EFS/FSx.

Khi dùng: Large file migration tăng tốc 10x.

Detective

Security
Root cause

Phân tích, visualize security finding.

Khi dùng: Forensic investigation.

Direct Connect

Networking
Private fiber

1/10/100 Gbps dedicated tới AWS.

Khi dùng: Bandwidth lớn, latency ổn định, compliance.

Exam tip: Không mã hóa native → VPN over DX nếu cần encrypt.

Directory Service

Security
Managed AD

Microsoft AD, Simple AD, AD Connector.

Khi dùng: EC2 Windows cần AD, FSx Windows.

DMS

Migration
Database Migration Service

Migrate DB engine (heterogeneous OK).

Khi dùng: Oracle → Aurora Postgres, on-prem → RDS.

DocumentDB

Database
MongoDB compat

MongoDB 4.0/5.0 compatible, Aurora storage.

Khi dùng: App Mongo cần managed.

DynamoDB

Database
Serverless NoSQL

Key-value/document, single-digit ms.

Khi dùng: Session, cart, IoT, gaming.

Exam tip: Item 400KB; TX 100 item/4MB; GSI 20 / LSI 5; DAX cache µs; Global Tables.

E

EBS

Storage
Elastic Block Store

Block storage gắn vào EC2 (1 AZ).

Khi dùng: OS volume, DB data volume.

Exam tip: gp3 baseline 3k IOPS / 125 MB/s; io2 Block Express 256k IOPS; snapshot incremental.

EC2

Compute
Elastic Compute Cloud

Máy ảo IaaS, tuỳ biến OS/CPU/RAM.

Khi dùng: Cần control OS, license BYOL, hoặc workload đặc biệt.

Exam tip: Phân biệt On-Demand/Reserved/Savings Plans/Spot/Dedicated Host.

ECS

Compute
Elastic Container Service

Orchestrator container AWS-native.

Khi dùng: Container app không muốn K8s complexity.

Exam tip: ECS on EC2 vs Fargate; task role vs execution role.

EFS

Storage
Elastic File System

NFS shared multi-AZ elastic.

Khi dùng: Content, home dir, CMS, ECS bind mount.

Exam tip: Throughput 50 MB/s per TB; storage class Standard vs IA.

EKS

Compute
Elastic Kubernetes Service

Managed Kubernetes control plane.

Khi dùng: Team đã có toolchain K8s, multi-cloud portable.

Exam tip: EKS on EC2 vs EKS on Fargate; control plane cost $0.10/h.

Elastic Beanstalk

Compute
PaaS

Deploy app web với config tự động (EC2/ALB/ASG).

Khi dùng: Dev team không muốn quản infrastructure.

Exam tip: Ít khi hỏi sâu nhưng biết là PaaS.

ElastiCache

Database
In-memory cache

Redis hoặc Memcached managed.

Khi dùng: Session store, leaderboard, cache read-heavy DB.

Exam tip: Redis: persist, pub/sub, cluster mode; Memcached: multi-thread, no persist.

ELB

Networking
Elastic Load Balancer

ALB/NLB/GWLB/CLB.

Khi dùng: Distribute traffic tới EC2/ECS/Lambda.

Exam tip: ALB L7 HTTP; NLB L4 TCP/UDP + static IP; GWLB L3 appliance.

EMR

Analytics
Elastic MapReduce

Hadoop/Spark/Hive cluster managed.

Khi dùng: Big data processing scale lớn.

EventBridge

Integration
Event bus

Event routing + SaaS partner + schedule.

Khi dùng: Event-driven architecture, replace cron.

F

Fargate

Compute
Serverless container

Chạy container không cần quản server.

Khi dùng: Utilisation biến động, muốn billing per use.

Exam tip: Billing vCPU-sec + GB-sec.

Firewall Manager

Security
Centralize WAF/SG

Policy WAF/SG/DNS Firewall/Shield Advanced org-wide.

FSx

Storage
Managed file systems

Windows SMB / Lustre HPC / NetApp ONTAP / OpenZFS.

Khi dùng: Workload cụ thể cần file system đặc thù.

Exam tip: Windows: AD integration. Lustre: HPC + S3 link.

G

Global Accelerator

Networking
Anycast IP

2 anycast IP + AWS backbone + region failover.

Khi dùng: TCP/UDP cần static IP hoặc failover nhanh.

Glue

Analytics
ETL serverless

Data Catalog + Spark ETL + crawler.

Khi dùng: Serverless ETL cho data lake.

GuardDuty

Security
Threat detection

ML phát hiện anomaly từ CloudTrail/VPC/DNS/EKS/S3/Malware.

Khi dùng: Security monitoring baseline.

I

IAM

Security
Identity & Access Management

User/Group/Role/Policy.

Khi dùng: Mọi tác vụ access control.

Exam tip: Thứ tự evaluate policy; SCP vs Boundary vs Session.

IAM Identity Center

Security
AWS SSO

SSO + permission sets cho Org.

Khi dùng: Quản user access nhiều account.

Inspector

Security
Vulnerability scan

CVE cho EC2, ECR image, Lambda.

Khi dùng: Continuous vulnerability scan.

IoT Core

Integration
IoT MQTT broker

MQTT broker + device shadow + rule engine.

Khi dùng: IoT fleet management.

K

Keyspaces

Database
Cassandra compat

Cassandra-compatible serverless.

Khi dùng: Workload Cassandra không muốn cluster tự quản.

Kinesis Data Streams

Integration
KDS

Shard-based stream + replay.

Khi dùng: Real-time analytics, CDC.

Kinesis Firehose

Integration
Delivery stream

Managed load → S3/Redshift/OpenSearch.

Khi dùng: ETL đơn giản, no-code, buffer 1MB/1min.

KMS

Security
Key Management Service

Tạo, quản, dùng cryptographic key.

Khi dùng: Encrypt-at-rest cho mọi service.

Exam tip: Key policy root; ViaService; Multi-Region Key; rotation 1 năm.

L

Lake Formation

Analytics
Data lake governance

Permission + audit cho data lake S3.

Lambda

Compute
Serverless function

Chạy code theo sự kiện, ms billing.

Khi dùng: Event-driven, <15 phút, spiky.

Exam tip: 15 phút, 10 GB RAM, 10 GB image; 1000 concurrent default; 6 MB sync payload.

License Manager

Management
License tracking

BYOL license enforcement.

Lightsail

Compute
Simple VPS

VPS giá cố định cho SMB.

Khi dùng: Dự án nhỏ, WordPress, bundled pricing.

Local Zones

Compute
Edge compute

AWS compute gần metro lớn (city-level).

Khi dùng: Latency < 10ms tới thành phố, real-time gaming/media.

M

Macie

Security
PII discovery

Phát hiện PII/sensitive data trong S3.

Khi dùng: Compliance privacy.

MemoryDB

Database
Redis durable

Redis API + durability 11 9's.

Khi dùng: Primary DB không chỉ cache.

Migration Hub

Migration
Tracker

Theo dõi tiến độ migration đa tool.

MQ

Integration
Amazon MQ

Managed ActiveMQ/RabbitMQ.

Khi dùng: Lift-and-shift JMS/AMQP/STOMP/MQTT.

MSK

Integration
Managed Kafka

Apache Kafka managed.

Khi dùng: Workload Kafka đã có.

N

Neptune

Database
Graph DB

Graph với Gremlin/SPARQL/openCypher.

Khi dùng: Fraud detection, knowledge graph, social.

Network Firewall

Security
VPC firewall

Stateful firewall tại VPC boundary.

Khi dùng: Deep packet inspection, egress filter.

O

OpenSearch

Analytics
Search + analytics

Elasticsearch fork managed + Kibana.

Khi dùng: Log analytics, search.

Exam tip: UltraWarm + Cold storage giảm cost.

Organizations

Management
Multi-account

OU, SCP, consolidated billing.

Khi dùng: Quản nhiều account.

Outposts

Compute
AWS on-prem

Rack AWS hardware đặt tại on-prem.

Khi dùng: Latency cực thấp tới hệ thống on-prem hoặc compliance data residency.

P

Polly

ML
Text-to-speech

Giọng nói neural.

PrivateLink

Networking
VPC Endpoint Services

Expose service qua NLB cho consumer VPC.

Khi dùng: SaaS provider, cross-account service không qua Internet.

Q

QLDB

Database
Ledger DB

Immutable, cryptographically verifiable.

Khi dùng: Audit log, supply chain.

QuickSight

Analytics
BI tool

Serverless BI, SPICE in-memory.

Khi dùng: Dashboard cho business user.

R

RDS

Database
Relational DB Service

Managed MySQL/Postgres/MariaDB/Oracle/SQL Server.

Khi dùng: Engine SQL truyền thống cần managed.

Exam tip: Multi-AZ (HA) vs Read Replica (scale read); backup 35 ngày.

Redshift

Database
Data warehouse

Columnar PB-scale.

Khi dùng: OLAP, BI reporting.

Exam tip: Spectrum query trực tiếp S3.

Rekognition

ML
Image/Video AI

Detect object, face, text.

Resource Access Manager

Management
RAM

Share resource cross-account (VPC subnet, TGW, Resolver rule).

Route 53

Networking
Managed DNS

DNS + health check + traffic routing.

Khi dùng: Domain management, failover, latency routing.

Exam tip: Alias record, 8 routing policy, Resolver Inbound/Outbound.

S

S3

Storage
Simple Storage Service

Object storage bền bỉ, scale không giới hạn.

Khi dùng: Backup, data lake, static website, archive.

Exam tip: Storage classes & lifecycle; multipart 5GB; 3500/5500 req/prefix; encryption SSE-S3/KMS/C.

S3 Glacier

Storage
Archive storage

Archive giá rẻ, retrieval phút → giờ → ngày.

Khi dùng: Compliance log 7 năm, ít truy cập.

SageMaker

ML
ML platform

Train/deploy ML model managed.

Khi dùng: ML workflow end-to-end.

Secrets Manager

Security
Secrets

Lưu secret + rotation tự động.

Khi dùng: DB password, API key cần rotate.

Security Hub

Security
Findings aggregator

Tổng hợp finding từ GuardDuty/Macie/Inspector/partner.

Khi dùng: Single pane of glass security.

Service Catalog

Management
Approved products

Self-service CloudFormation template cho team.

Shield

Security
DDoS protection

Standard free L3/4; Advanced L3/4/7 + DRT.

Khi dùng: Advanced cho mission-critical, cost protection.

Site-to-Site VPN

Networking
IPsec VPN

2 tunnel IPsec qua Internet.

Khi dùng: Quick setup hoặc lúc chờ DX.

Snow Family

Migration
Snowcone/Ball/Mobile

Thiết bị vật lý chuyển dữ liệu lớn.

Khi dùng: TB – PB với băng thông hẹp.

SNS

Integration
Simple Notification Service

Pub/sub fan-out.

Khi dùng: Broadcast tới nhiều subscriber.

SQS

Integration
Simple Queue Service

Message queue managed.

Khi dùng: Decouple, buffer, retry.

Exam tip: Standard unlimited TPS best-effort; FIFO 300/3k/70k TPS order + dedup.

Step Functions

Integration
Workflow orchestration

State machine JSON, Standard 1 năm / Express 5 phút.

Khi dùng: Workflow phức tạp, retry, branch, parallel.

Storage Gateway

Storage
Hybrid storage

Kéo dài storage on-prem lên AWS (file/volume/tape).

Khi dùng: Backup tape → S3, SMB share cached, iSCSI volume.

SWF

Integration
Simple Workflow

Legacy workflow, code-based.

Khi dùng: Hiếm thấy; ưu tiên Step Functions.

Systems Manager

Management
SSM

Run Command, Session Manager, Patch, Parameter Store.

Khi dùng: Fleet management & automation.

T

Timestream

Database
Time-series DB

Serverless time-series, auto-tier.

Khi dùng: IoT, DevOps metrics.

Transcribe

ML
Speech-to-text

ASR streaming/batch.

Transfer Family

Migration
SFTP/FTPS/FTP/AS2

Managed SFTP etc lên S3/EFS.

Transit Gateway

Networking
TGW

Hub kết nối VPC + VPN + DX.

Khi dùng: Scale nhiều VPC, nhiều site.

Exam tip: 5,000 attachment; route table isolation.

Translate

ML
Machine translation

Neural MT 70+ ngôn ngữ.

Trusted Advisor

Management
Best practice check

Cost, Perf, Security, Fault Tolerance, Quotas, OpsEx.

V

VPC

Networking
Virtual Private Cloud

Mạng ảo riêng trong AWS.

Khi dùng: Mặc định cho mọi workload.

Exam tip: CIDR, subnet, route table, SG, NACL, endpoint.

VPC Endpoint

Networking
Interface/Gateway

Truy cập AWS service không qua Internet.

Khi dùng: Gateway: S3, DDB free. Interface: PrivateLink $.

W

WAF

Security
Web Application Firewall

Rule chặn SQLi/XSS/bot/rate-limit L7.

Khi dùng: CloudFront/ALB/API GW/AppSync/Cognito UP.

Wavelength

Compute
5G edge

Compute AWS trong mạng 5G carrier.

Khi dùng: Ultra-low latency cho mobile app.

X

X-Ray

Developer
Distributed tracing

Trace request qua service.