Domain 2: Configuration Management and IaC (17% of the exam content)
This domain accounts for 17% of the exam content.
Topics
Task 2.1: Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle
Knowledge of:
Infrastructure as code (IaC) options and tools for
Change management processes for IaC-based platforms
Configuration management services and strategies
Skills in:
Composing and deploying IaC templates (for example, Serverlos Application Model [ SAM], CloudFormation, Cloud Development Kit [ CDK])
Applying CloudFormation StackSets across multiple accounts and Regions
Determining optimal configuration management services (for example, Systems Manager, AppConfig)
Implementing infrastructure and application configuration management
Implementing IaC lifecycle management (for example, drift detection, stack updates)
Implementing IaC security controls (for example, CloudFormation Guard)
Task 2.2: Automate configuration management to enforce desired state
Knowledge of:
Configuration management tools and services
Desired state management
Immutable infrastructure concepts
Skills in:
Implementing configuration management services (for example, Systems Manager State Manager, Config)
Implementing patch management (for example, Systems Manager Patch Manager)
Implementing application configuration management (for example, AppConfig)
Implementing desired state management (for example, Systems Manager State Manager)
Implementing infrastructure and application configuration management
Task 2.3: Implement compliance as code
Knowledge of:
Compliance as code concepts
Compliance and security scanning tools
Compliance and security remediation strategies
Skills in:
Implementing compliance scanning tools (for example, Config, Security Hub, Amazon Inspector)
Implementing automated remediation (for example, Config, Systems Manager)
Implementing security scanning tools (for example, Amazon Inspector, Security Hub)
Implementing infrastructure security scanning (for example, cfn-nag, CloudFormation Guard)