Domain 2: Configuration Management and IaC (17% of the exam content) - AWS Certification

Domain 2: Configuration Management and IaC (17% of the exam content)

This domain accounts for 17% of the exam content.

Task 2.1: Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle

Knowledge of:

  • Infrastructure as code (IaC) options and tools for

  • Change management processes for IaC-based platforms

  • Configuration management services and strategies

Skills in:

  • Composing and deploying IaC templates (for example, Serverlos Application Model [ SAM], CloudFormation, Cloud Development Kit [ CDK])

  • Applying CloudFormation StackSets across multiple accounts and Regions

  • Determining optimal configuration management services (for example, Systems Manager, AppConfig)

  • Implementing infrastructure and application configuration management

  • Implementing IaC lifecycle management (for example, drift detection, stack updates)

  • Implementing IaC security controls (for example, CloudFormation Guard)

Task 2.2: Automate configuration management to enforce desired state

Knowledge of:

  • Configuration management tools and services

  • Desired state management

  • Immutable infrastructure concepts

Skills in:

  • Implementing configuration management services (for example, Systems Manager State Manager, Config)

  • Implementing patch management (for example, Systems Manager Patch Manager)

  • Implementing application configuration management (for example, AppConfig)

  • Implementing desired state management (for example, Systems Manager State Manager)

  • Implementing infrastructure and application configuration management

Task 2.3: Implement compliance as code

Knowledge of:

  • Compliance as code concepts

  • Compliance and security scanning tools

  • Compliance and security remediation strategies

Skills in:

  • Implementing compliance scanning tools (for example, Config, Security Hub, Amazon Inspector)

  • Implementing automated remediation (for example, Config, Systems Manager)

  • Implementing security scanning tools (for example, Amazon Inspector, Security Hub)

  • Implementing infrastructure security scanning (for example, cfn-nag, CloudFormation Guard)