2025-10-09 14:22:41
๋ฐ˜์‘ํ˜•

๐Ÿ“˜ Q3. AWS Storage Gateway ๋ฌธ์ œ ์ •๋ฆฌ

โ“ ๋ฌธ์ œ ์š”์•ฝ

  • ํ•œ ํšŒ์‚ฌ์—๋Š” ๋Œ€์šฉ๋Ÿ‰ ํŒŒ์ผ ์ €์žฅ์ด ํ•„์š”ํ•œ ์‚ฌ์šฉ์ž ๊ทธ๋ฃน์ด ์žˆ์Œ.
  • ํ˜„์žฌ ์˜จํ”„๋ ˆ๋ฏธ์Šค(๋กœ์ปฌ) ์Šคํ† ๋ฆฌ์ง€๋Š” ์šฉ๋Ÿ‰์ด ๋ถ€์กฑํ•จ.
  • ํด๋ผ์šฐ๋“œ๋กœ ํŒŒ์ผ ์ €์žฅ ๊ณต๊ฐ„์„ ํ™•์žฅํ•˜๋ ค๊ณ  ํ•จ.
  • ๋‹จ, ๋กœ์ปฌ ํŒŒ์ผ ๊ณต์œ  ์„ฑ๋Šฅ(๋น ๋ฅธ ์ ‘๊ทผ์„ฑ) ์€ ์œ ์ง€ํ•ด์•ผ ํ•จ.

โœ… ์ •๋‹ต: B. Configure and deploy an AWS Storage Gateway file gateway.


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

๐Ÿ”น ์„ ํƒ์ง€ B: AWS Storage Gateway – File Gateway

  • ์˜จํ”„๋ ˆ๋ฏธ์Šค ํ™˜๊ฒฝ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ํŒŒ์ผ ์„œ๋ฒ„์™€ AWS S3๋ฅผ ์—ฐ๊ฒฐํ•˜๋Š” ์„œ๋น„์Šค.
  • ์‚ฌ์šฉ์ž๋Š” ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์˜ SMB/NFS ๊ณต์œ  ๋ฐฉ์‹์œผ๋กœ ํŒŒ์ผ์— ์ ‘๊ทผ.
  • ๋ฐฑ์—”๋“œ์—์„œ๋Š” ์ž๋™์œผ๋กœ S3์— ์—…๋กœ๋“œ/์ €์žฅ,
    ์ž์ฃผ ์“ฐ๋Š” ํŒŒ์ผ์€ ๋กœ์ปฌ ์บ์‹œ์— ๋‚จ๊ฒจ ๋น ๋ฅธ ์•ก์„ธ์Šค ๊ฐ€๋Šฅ.
  • ๊ฒฐ๊ณผ์ ์œผ๋กœ ์˜จํ”„๋ ˆ๋ฏธ์Šค์˜ ์„ฑ๋Šฅ + ํด๋ผ์šฐ๋“œ์˜ ํ™•์žฅ์„ฑ์„ ๋ชจ๋‘ ์–ป์„ ์ˆ˜ ์žˆ์Œ.
  • ์šด์˜ ํšจ์œจ์„ฑ(Operation Efficiency)์ด ๊ฐ€์žฅ ๋†’์Œ โœ…

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ์„ค๋ช…ํ‹€๋ฆฐ ์ด์œ 
A. Amazon S3 ๋ฒ„ํ‚ท์„ ์‚ฌ์šฉ์ž๋ณ„๋กœ ์ƒ์„ฑ ๊ฐ ์‚ฌ์šฉ์ž๊ฐ€ ์ง์ ‘ S3 ๋ฒ„ํ‚ท์„ ๋งˆ์šดํŠธ ๊ด€๋ฆฌ ๋ณต์žก์„ฑ ๋†’๊ณ , ๋กœ์ปฌ ์บ์‹ฑ ์—†์Œ → ๋น„ํšจ์œจ์  โŒ
C. Amazon WorkSpaces + WorkDocs ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ๊ฐ€์ƒ ๋ฐ์Šคํฌํƒ‘ & ๋ฌธ์„œ ํ˜‘์—… ์„œ๋น„์Šค ๋‹จ์ˆœ ํŒŒ์ผ ์ €์žฅ/๊ณต์œ  ์‹œ ์˜ค๋ฒ„์—”์ง€๋‹ˆ์–ด๋ง โŒ
D. EC2 + EBS ๊ณต์œ  EBS๋ฅผ EC2์— ์—ฐ๊ฒฐํ•ด ๋„คํŠธ์›Œํฌ ๊ณต์œ  EBS๋Š” ์ธ์Šคํ„ด์Šค ์ „์šฉ ์Šคํ† ๋ฆฌ์ง€๋กœ ์—ฌ๋Ÿฌ ์‚ฌ์šฉ์ž ๊ณต์œ  ๋ถˆ๊ฐ€ โŒ

๐Ÿ“Š ๋น„๊ต ์š”์•ฝ

ํ•ญ๋ชฉAWS Storage GatewayS3 ์ง์ ‘ ๋งˆ์šดํŠธWorkSpaces/WorkDocsEC2 + EBS
๋กœ์ปฌ ์ ‘๊ทผ ์†๋„ โœ… ๋น ๋ฆ„ (์บ์‹œ) โŒ ๋А๋ฆผ โš™๏ธ ์ œํ•œ์  โš™๏ธ ์ œํ•œ์ 
AWS ํ™•์žฅ์„ฑ โœ… ์ž๋™ ํ™•์žฅ โœ… ์ž๋™ ํ™•์žฅ โš™๏ธ ๋ฌธ์„œ ์ค‘์‹ฌ โš™๏ธ ์ œํ•œ์ 
์šด์˜ ํšจ์œจ์„ฑ โœ… ๊ฐ€์žฅ ๋†’์Œ โŒ ์‚ฌ์šฉ์ž๋ณ„ ๊ด€๋ฆฌ ํ•„์š” โŒ ๊ด€๋ฆฌ ์˜ค๋ฒ„ํ—ค๋“œ โŒ ๊ธฐ์ˆ ์  ์ œ์•ฝ
๊ถŒ์žฅ ์‚ฌ๋ก€ ํŒŒ์ผ ์„œ๋ฒ„ ํ™•์žฅ ๋‹จ์ˆœ ๋ฐฑ์—… ํ˜‘์—… ๋ฌธ์„œ ๊ด€๋ฆฌ ๋ธ”๋ก ์Šคํ† ๋ฆฌ์ง€ ์ „์šฉ

๐Ÿ” ํ•ต์‹ฌ ์š”์•ฝ

“์˜จํ”„๋ ˆ๋ฏธ์Šค์—์„œ ์‚ฌ์šฉ ์ค‘์ธ ํŒŒ์ผ ์„œ๋ฒ„๋ฅผ ํด๋ผ์šฐ๋“œ๋กœ ํ™•์žฅํ•˜๋ ค๋ฉด
AWS Storage Gateway File Gateway๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ
๋กœ์ปฌ ์บ์‹œ ์„ฑ๋Šฅ์„ ์œ ์ง€ํ•˜๋ฉด์„œ S3์— ํ™•์žฅ ์ €์žฅ์†Œ๋ฅผ ๊ตฌ์ถ•ํ•˜๋ผ.”


๐Ÿงฉ ๊ตฌ์กฐ ์‹œ๊ฐํ™”

 
flowchart LR A[On-Premise Users] -->|SMB/NFS Access| B[File Gateway] B -->|Cache & Upload| C[(Amazon S3 Bucket)] C --> D[Scalable Cloud Storage] B -.->|Local Cache| E[Fast Local Performance]

โœ… ์ •๋‹ต: B. AWS Storage Gateway File Gateway
โ˜๏ธ ํ•ต์‹ฌ ๊ฐœ๋…: ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํŒŒ์ผ ์Šคํ† ๋ฆฌ์ง€ ํ™•์žฅ + ๋กœ์ปฌ ์บ์‹ฑ + S3 ์—ฐ๋™


๐Ÿ“˜ Q24. Internet Gateway์˜ ์—ญํ• 

โ“ ๋ฌธ์ œ ์š”์•ฝ

VPC(๊ฐ€์ƒ ์‚ฌ์„ค ํด๋ผ์šฐ๋“œ) ๋‚ด์— Internet Gateway(IGW)๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ์ด์œ ๋Š”?


โœ… ์ •๋‹ต: B. To allow communication between the VPC and the Internet

VPC์™€ ์ธํ„ฐ๋„ท ๊ฐ„์˜ ์–‘๋ฐฉํ–ฅ ํ†ต์‹ ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•จ์ด๋‹ค.


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

๐Ÿ”น Internet Gateway๋ž€?

  • AWS VPC ๋‚ด๋ถ€ ๋ฆฌ์†Œ์Šค(์˜ˆ: EC2 ์ธ์Šคํ„ด์Šค)๊ฐ€ ์ธํ„ฐ๋„ท๊ณผ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ๋„๋ก ์—ฐ๊ฒฐํ•ด์ฃผ๋Š” ์ถœ์ž…๋ฌธ ์—ญํ• 
  • ์–‘๋ฐฉํ–ฅ ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ:
    • Outbound: EC2 → ์ธํ„ฐ๋„ท
    • Inbound: ์ธํ„ฐ๋„ท → EC2 (๋ณด์•ˆ ๊ทธ๋ฃน์—์„œ ํ—ˆ์šฉ ์‹œ)
  • IGW๋ฅผ ์—ฐ๊ฒฐํ•˜๊ณ , Route Table์— 0.0.0.0/0 → IGW ๊ฒฝ๋กœ๋ฅผ ์ถ”๊ฐ€ํ•ด์•ผ ์™ธ๋ถ€ ํ†ต์‹  ๊ฐ€๋Šฅ

โŒ ์˜ค๋‹ต ํ•ด์„ค


๋ณด๊ธฐ ์„ค๋ช… ์™œ ํ‹€๋ ธ๋Š”๊ฐ€
A. To create a VPN connection to the VPC VPN ์—ฐ๊ฒฐ์€ Virtual Private Gateway (VGW) ๋กœ ๊ตฌ์„ฑ IGW๋Š” VPN์šฉ์ด ์•„๋‹˜ โŒ
B. To allow communication between the VPC and the internet VPC ↔ ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ โœ… ์ •๋‹ต
C. To impose bandwidth constraints ๋Œ€์—ญํญ ์ œํ•œ์€ IGW๊ฐ€ ์•„๋‹Œ Network ACL, QoS ์ •์ฑ… ๋“ฑ์—์„œ ์„ค์ • โŒ
D. To load balance traffic across EC2 ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ์€ Elastic Load Balancer (ELB) ์˜ ์—ญํ•  โŒ

๐ŸŒ ๊ตฌ์กฐ ์‹œ๊ฐํ™”

 
```mermaid
flowchart TD
    %% ๐ŸŒ ์ธํ„ฐ๋„ท ์˜์—ญ
    subgraph Internet
        I["๐ŸŒ Internet User"]
    end

    %% โ˜๏ธ VPC ๋‚ด๋ถ€ ๊ตฌ์„ฑ
    subgraph VPC
        IGW["๐Ÿ”— Internet Gateway"]
        E["๐Ÿ’ป EC2 Instance<br>Public Subnet"]
    end

    %% ๐Ÿ” ์—ฐ๊ฒฐ ๊ด€๊ณ„
    I <--> IGW <--> E

    %% ๐Ÿ’ก ์„ค๋ช… ๋…ธ๋“œ
    N["๐Ÿ’ก IGW allows internet access<br>only for resources with Public IPs"]
    IGW --- N
```
 

๐Ÿงฉ ํ•ต์‹ฌ ์š”์•ฝ

ํ•ญ๋ชฉ์„ค๋ช…
์„œ๋น„์Šค๋ช… Internet Gateway (IGW)
๊ธฐ๋Šฅ VPC ๋ฆฌ์†Œ์Šค์™€ ์ธํ„ฐ๋„ท ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ์ค‘๊ณ„
ํ•„์ˆ˜ ๊ตฌ์„ฑ์š”์†Œ Route Table + ํผ๋ธ”๋ฆญ IP
๊ด€๋ จ ์„œ๋น„์Šค ๋น„๊ต VPN → Virtual Private Gateway / NAT → ์‚ฌ์„ค ์„œ๋ธŒ๋„ท์šฉ ์ธํ„ฐ๋„ท ์ ‘๊ทผ

โœ… ํ•œ ์ค„ ์š”์•ฝ

“Internet Gateway๋Š” VPC์™€ ์ธํ„ฐ๋„ท ๊ฐ„ ํ†ต์‹ ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋Š” ๊ด€๋ฌธ ์—ญํ• ์„ ํ•œ๋‹ค.”


๐Ÿ“˜ Q34. AWS Cloud์—์„œ์˜ ๋ฏผ์ฒฉ์„ฑ(Agility) ๊ฐœ๋…

โ“ ๋ฌธ์ œ ์š”์•ฝ

AWS ํด๋ผ์šฐ๋“œ ์ปดํ“จํŒ…์—์„œ “๋ฏผ์ฒฉ์„ฑ(Agility)”์˜ ๊ฐœ๋…์€ ๋ฌด์—‡์„ ์˜๋ฏธํ•˜๋Š”๊ฐ€?
(์ •๋‹ต 2๊ฐœ ์„ ํƒ)


โœ… ์ •๋‹ต: A, C


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

์„ ํƒ์ง€ ์„ค๋ช…
A. The speed at which AWS resources are implemented AWS์—์„œ๋Š” ๋ฆฌ์†Œ์Šค๋ฅผ ๋ช‡ ๋ถ„ ๋‚ด๋กœ ๋น ๋ฅด๊ฒŒ ๊ตฌ์ถ• ๋ฐ ๋ฐฐํฌ ๊ฐ€๋Šฅ → ํ•˜๋“œ์›จ์–ด ๊ตฌ๋งค/์„ค์น˜ ๊ณผ์ • ๋ถˆํ•„์š” → ๋น ๋ฅธ ๊ฐœ๋ฐœ ์ฃผ๊ธฐ ์‹คํ˜„
C. The ability to experiment quickly ์ƒˆ๋กœ์šด ์•„์ด๋””์–ด๋‚˜ ์„œ๋น„์Šค๋ฅผ ์‰ฝ๊ณ  ๋น ๋ฅด๊ฒŒ ์‹คํ—˜ ๊ฐ€๋Šฅ → ์‹คํŒจ ์‹œ์—๋„ ์ฆ‰์‹œ ๋ฆฌ์†Œ์Šค ์ข…๋ฃŒ(๋น„์šฉ ์ตœ์†Œํ™”) → ํ˜์‹ (innovation) ๊ณผ ์ง๊ฒฐ

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ๋‚ด์šฉ ์™œ ํ‹€๋ ธ๋Š”๊ฐ€
B. The speed at which AWS creates new AWS Regions AWS ์ž์ฒด ์ธํ”„๋ผ ํ™•์žฅ ์†๋„ ๊ณ ๊ฐ์˜ “๋ฏผ์ฒฉ์„ฑ”๊ณผ ๊ด€๋ จ ์—†์Œ โŒ
D. The elimination of wasted capacity ๋‚ญ๋น„๋˜๋Š” ์šฉ๋Ÿ‰ ์ œ๊ฑฐ๋Š” ํƒ„๋ ฅ์„ฑ(Elasticity) ๊ฐœ๋… โŒ
E. The low cost of entry into cloud computing ์ง„์ž… ๋น„์šฉ ์ ˆ๊ฐ์€ ๊ฒฝ์ œ์„ฑ(Economy of Scale) ๊ฐœ๋… โŒ

๐Ÿ“Š ๊ฐœ๋… ์ •๋ฆฌ ๋น„๊ต

๊ฐœ๋… ํ‚ค์›Œ๋“œ ์„ค๋ช…
๋ฏผ์ฒฉ์„ฑ (Agility) ๋น ๋ฅธ ๊ตฌ์ถ•, ์‹ ์†ํ•œ ์‹คํ—˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๋น ๋ฅด๊ฒŒ ๋ฐฐํฌํ•˜๊ณ , ์‹คํ—˜·๊ฐœ๋ฐœ ์†๋„๋ฅผ ๋†’์ž„
ํƒ„๋ ฅ์„ฑ (Elasticity) ์ž๋™ ํ™•์žฅ/์ถ•์†Œ ์ˆ˜์š” ๋ณ€ํ™”์— ๋งž๊ฒŒ ์ž์› ์กฐ์ •
๊ฒฝ์ œ์„ฑ (Economy of Scale) ๋น„์šฉ ํšจ์œจ ๋Œ€๊ทœ๋ชจ ์ธํ”„๋ผ ์šด์˜์œผ๋กœ ๋‹จ๊ฐ€ ์ ˆ๊ฐ
ํ™•์žฅ์„ฑ (Scalability) ์„ฑ์žฅ ๋Œ€์‘ ์‚ฌ์šฉ๋Ÿ‰ ์ฆ๊ฐ€ ์‹œ ์‹œ์Šคํ…œ ํ™•์žฅ ๊ฐ€๋Šฅ

โš™๏ธ ์‹œ๊ฐํ™” (Mermaid)

 
```mermaid
flowchart TD
    A["๐Ÿ’ก ์•„์ด๋””์–ด ๋˜๋Š”<br>์š”๊ตฌ์‚ฌํ•ญ ๋ฐœ์ƒ"] --> B["๐Ÿš€ ๋น ๋ฅด๊ฒŒ ๋ฆฌ์†Œ์Šค ์ƒ์„ฑ<br>Agility"]
    B --> C["๐Ÿงช ์‹คํ—˜ ๋ฐ ํ…Œ์ŠคํŠธ"]
    C --> D{"โŒ ์‹คํŒจ?"}
    D -->|Yes| E["๐Ÿ›‘ ์ฆ‰์‹œ ์ข…๋ฃŒํ•˜์—ฌ<br>๋น„์šฉ ์ ˆ๊ฐ"]
    D -->|No| F["โœ… ์„œ๋น„์Šค ํ™•์žฅ ๋ฐ ๋ฐฐํฌ"]
```
 

๐Ÿงฉ ํ•ต์‹ฌ ์š”์•ฝ

๋ฏผ์ฒฉ์„ฑ(Agility) = “๋ฆฌ์†Œ์Šค๋ฅผ ๋น ๋ฅด๊ฒŒ ๋ฐฐํฌํ•˜๊ณ , ์•„์ด๋””์–ด๋ฅผ ์‹ ์†ํ•˜๊ฒŒ ์‹คํ—˜ํ•  ์ˆ˜ ์žˆ๋Š” ๋Šฅ๋ ฅ”
→ ํด๋ผ์šฐ๋“œ๊ฐ€ ์ œ๊ณตํ•˜๋Š” ๊ฐ€์žฅ ํฐ ๋น„์ฆˆ๋‹ˆ์Šค ํ˜์‹ ์˜ ๊ธฐ๋ฐ˜


โœ… ์ •๋‹ต

A. The speed at which AWS resources are implemented
C. The ability to experiment quickly


๐Ÿ“˜ Q39. IAM ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ (IAM Security Best Practice)

โ“ ๋ฌธ์ œ ์š”์•ฝ

ํ•œ ํšŒ์‚ฌ๊ฐ€ AWS ๊ณ„์ •์— IAM์„ ์„ค์ •ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.
๋‹ค์Œ ์ค‘ ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€์— ํ•ด๋‹นํ•˜๋Š” ๊ฒƒ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?


โœ… ์ •๋‹ต: C. Turn on multi-factor authentication (MFA) for added security during the login process


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

๐Ÿ”น MFA(Multi-Factor Authentication)

  • IAM ๋ณด์•ˆ์˜ ๊ธฐ๋ณธ์ด์ž ํ•ต์‹ฌ ๋ชจ๋ฒ” ์‚ฌ๋ก€ โœ…
  • ๋น„๋ฐ€๋ฒˆํ˜ธ ์™ธ์—๋„ ์ถ”๊ฐ€ ์ธ์ฆ ์š”์†Œ(์˜ˆ: OTP, ํ•˜๋“œ์›จ์–ด ํ† ํฐ, ์•ฑ ์ธ์ฆ) ๋ฅผ ์š”๊ตฌํ•˜์—ฌ ๋ณด์•ˆ์„ ๊ฐ•ํ™”
  • ๋ฃจํŠธ ๊ณ„์ • ๋ฐ ๊ด€๋ฆฌ์ž ๊ณ„์ •์€ ๋ฐ˜๋“œ์‹œ MFA ํ™œ์„ฑํ™” ๊ถŒ์žฅ

๐Ÿ’ฌ ์ฆ‰, MFA๋Š” “๋น„๋ฐ€๋ฒˆํ˜ธ ์œ ์ถœ ์‹œ์—๋„ ๊ณ„์ • ํƒˆ์ทจ๋ฅผ ๋ง‰๋Š” ์ถ”๊ฐ€ ๋ฐฉ์–ด์„ ” ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์™œ ํ‹€๋ ธ๋Š”๊ฐ€
A. Use the account root user access keys for administrative tasks ๋ฃจํŠธ ์‚ฌ์šฉ์ž๋กœ ๊ด€๋ฆฌ ์ž‘์—… ์ˆ˜ํ–‰ ๋ฃจํŠธ ๊ณ„์ •์€ ์ตœ์†Œํ•œ์˜ ์‚ฌ์šฉ๋งŒ ํ—ˆ์šฉ, ์ ‘๊ทผ ํ‚ค ์ƒ์„ฑ โŒ
B. Grant broad permissions so all employees can access resources ๊ด‘๋ฒ”์œ„ํ•œ ๊ถŒํ•œ ๋ถ€์—ฌ ์›์น™ ์œ„๋ฐ˜ — ์ตœ์†Œ ๊ถŒํ•œ ๋ถ€์—ฌ(Least Privilege Principle) ๊ฐ€ ๋ชจ๋ฒ” ์‚ฌ๋ก€ โŒ
C. Turn on MFA ๋‹ค๋‹จ๊ณ„ ์ธ์ฆ ํ™œ์„ฑํ™” โœ… ์ •๋‹ต — AWS IAM ๋ณด์•ˆ์˜ ํ•ต์‹ฌ ๊ถŒ์žฅ ์‚ฌํ•ญ
D. Avoid rotating credentials ์ž๊ฒฉ ์ฆ๋ช… ์ˆœํ™˜(๊ต์ฒด)์„ ํ”ผํ•˜๋ผ โŒ ์ž˜๋ชป๋œ ๊ด€ํ–‰ — ์ •๊ธฐ์  Credential ํšŒ์ „์ด ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€

๐Ÿ“Š IAM ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ ์š”์•ฝ

ํ•ญ๋ชฉ ์„ค๋ช…
๐Ÿ” MFA ํ™œ์„ฑํ™” ๋ชจ๋“  ๋ฃจํŠธ ๋ฐ ๊ด€๋ฆฌ์ž ์‚ฌ์šฉ์ž์— MFA ์„ค์ •
๐Ÿ‘ฅ ๋ฃจํŠธ ๊ณ„์ • ์ตœ์†Œ ์‚ฌ์šฉ ๋ฃจํŠธ ๊ณ„์ •์€ ๊ณ„์ • ์„ค์ • ์™ธ์—” ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ธฐ
๐ŸŽฏ ์ตœ์†Œ ๊ถŒํ•œ ์›์น™(Least Privilege) ์‚ฌ์šฉ์ž์—๊ฒŒ ๊ผญ ํ•„์š”ํ•œ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌ
๐Ÿ”„ ์ •๊ธฐ์  Credential Rotation ์•ก์„ธ์Šค ํ‚ค์™€ ์•”ํ˜ธ๋ฅผ ์ฃผ๊ธฐ์ ์œผ๋กœ ๊ต์ฒด
๐Ÿงฑ IAM Roles ์‚ฌ์šฉ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ ‘๊ทผ์€ ์‚ฌ์šฉ์ž ํ‚ค ๋Œ€์‹  ์—ญํ• (Role)๋กœ ์ฒ˜๋ฆฌ

๐Ÿงฉ ๊ตฌ์กฐ ์‹œ๊ฐํ™” (Mermaid)

 
```mermaid
flowchart TD
  A[๐Ÿ”‘ IAM User Login] --> B[๐Ÿ” MFA ์ธ์ฆ ๋‹จ๊ณ„ ์ถ”๊ฐ€]
  B --> C[โœ… ๋กœ๊ทธ์ธ ์„ฑ๊ณต]
  A -. ๋น„๋ฐ€๋ฒˆํ˜ธ ์œ ์ถœ์‹œ .-> X[โŒ ๋กœ๊ทธ์ธ ์‹คํŒจ (MFA ์ฐจ๋‹จ)]
```

๐Ÿง  ํ•ต์‹ฌ ์š”์•ฝ

AWS IAM ๋ณด์•ˆ์˜ ์ฒซ ๋‹จ๊ณ„๋Š” MFA ํ™œ์„ฑํ™”,
๊ทธ ๋‹ค์Œ์€ ๋ฃจํŠธ ๊ณ„์ • ์ตœ์†Œ ์‚ฌ์šฉ๊ณผ ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์ ์šฉ์ž…๋‹ˆ๋‹ค.



๐Ÿ“˜ Q40. Elasticity in AWS Cloud

โ“ ๋ฌธ์ œ ์š”์•ฝ

AWS ํด๋ผ์šฐ๋“œ์—์„œ ํƒ„๋ ฅ์„ฑ(Elasticity) ์ด๋ž€ ๋ฌด์—‡์„ ์˜๋ฏธํ•ฉ๋‹ˆ๊นŒ?
(2๊ฐœ ์„ ํƒ)


โœ… ์ •๋‹ต

B. The ability to rightsize resources as demand shifts
E. How easily resources can be procured when they are needed


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

์„ ํƒ์ง€ ์„ค๋ช…
B. The ability to rightsize resources as demand shifts ์ˆ˜์š”(ํŠธ๋ž˜ํ”ฝ, ๋ถ€ํ•˜ ๋“ฑ)์— ๋”ฐ๋ผ ๋ฆฌ์†Œ์Šค์˜ ํฌ๊ธฐ๋‚˜ ๊ฐœ์ˆ˜๋ฅผ ์ž๋™์œผ๋กœ ์กฐ์ •ํ•˜๋Š” ๋Šฅ๋ ฅ. → ์˜คํ† ์Šค์ผ€์ผ๋ง(Auto Scaling) ๊ฐœ๋…๊ณผ ์ง๊ฒฐ
E. How easily resources can be procured when they are needed ํ•„์š”ํ•œ ์‹œ์ ์— ๋น ๋ฅด๊ฒŒ ๋ฆฌ์†Œ์Šค๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ํ•ด์ œํ•  ์ˆ˜ ์žˆ๋Š” ๋Šฅ๋ ฅ. → ์ฆ‰์‹œ ํ™•์žฅ/์ถ•์†Œ ๊ฐ€๋Šฅํ•œ ํด๋ผ์šฐ๋“œ์˜ ์žฅ์ 

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์™œ ํ‹€๋ ธ๋Š”๊ฐ€
A. How quickly an EC2 instance can be restarted ์ธ์Šคํ„ด์Šค ์žฌ์‹œ์ž‘ ์†๋„ ํƒ„๋ ฅ์„ฑ๊ณผ ๋ฌด๊ด€ — ์šด์˜ ์ˆ˜์ค€์˜ ์†๋„ ๊ฐœ๋… โŒ
C. The maximum amount of RAM an EC2 instance can use ๋‹จ์ผ ์ธ์Šคํ„ด์Šค ์‚ฌ์–‘ ์ œํ•œ ํƒ„๋ ฅ์„ฑ๊ณผ ๋ฌด๊ด€ — ๋ฆฌ์†Œ์Šค ํฌ๊ธฐ ์กฐ์ •์ด ์•„๋‹˜ โŒ
D. The pay-as-you-go billing model ์‚ฌ์šฉ๋Ÿ‰ ๊ธฐ๋ฐ˜ ๊ณผ๊ธˆ(์œ ์—ฐํ•œ ๊ณผ๊ธˆ ๋ชจ๋ธ) ์ด๋Š” ๋น„์šฉ ํšจ์œจ์„ฑ(Cost Optimization) ๊ด€๋ จ ๊ฐœ๋… โŒ

๐Ÿ“Š ๊ฐœ๋… ๋น„๊ต

๊ฐœ๋… ์„ค๋ช… ๊ด€๋ จ ์„œ๋น„์Šค ์˜ˆ์‹œ
ํƒ„๋ ฅ์„ฑ (Elasticity) ์ˆ˜์š” ๋ณ€ํ™”์— ๋”ฐ๋ผ ๋ฆฌ์†Œ์Šค๋ฅผ ์ž๋™ ํ™•์žฅ/์ถ•์†Œ EC2 Auto Scaling, DynamoDB Auto Scaling
ํ™•์žฅ์„ฑ (Scalability) ์žฅ๊ธฐ์  ์„ฑ์žฅ์— ๋”ฐ๋ผ ๋ฆฌ์†Œ์Šค ์ถ”๊ฐ€ ๊ฐ€๋Šฅ RDS Read Replica, Load Balancer
๋ฏผ์ฒฉ์„ฑ (Agility) ๋ฆฌ์†Œ์Šค๋ฅผ ๋น ๋ฅด๊ฒŒ ๋ฐฐํฌํ•˜๊ณ  ์‹คํ—˜ ๊ฐ€๋Šฅ CloudFormation, Lambda
๋น„์šฉ ํšจ์œจ์„ฑ (Cost Optimization) ํ•„์š”ํ•œ ๋งŒํผ๋งŒ ์‚ฌ์šฉํ•˜๊ณ  ์ง€๋ถˆ S3, Savings Plans

โš™๏ธ ์‹œ๊ฐํ™” (Mermaid)

```mermaid
flowchart LR
    A[๐Ÿ“ˆ ์ˆ˜์š” ์ฆ๊ฐ€] --> B[โš™๏ธ Auto Scaling: EC2 ์ธ์Šคํ„ด์Šค ์ถ”๊ฐ€]
    B --> C[๐Ÿ’ก ์„ฑ๋Šฅ ์œ ์ง€]
    C --> D[๐Ÿ“‰ ์ˆ˜์š” ๊ฐ์†Œ]
    D --> E[โš™๏ธ Auto Scaling: ์ธ์Šคํ„ด์Šค ์ข…๋ฃŒ]
    E --> F[๐Ÿ’ฐ ๋น„์šฉ ์ ˆ๊ฐ]
```
 
 

 


๐Ÿง  ํ•ต์‹ฌ ์š”์•ฝ

ํƒ„๋ ฅ์„ฑ(Elasticity) =
“์‹œ์‹œ๊ฐ๊ฐ ๋ณ€ํ•˜๋Š” ์ˆ˜์š”์— ๋”ฐ๋ผ IT ๋ฆฌ์†Œ์Šค๋ฅผ ์ž๋™์œผ๋กœ ํ™•์žฅํ•˜๊ฑฐ๋‚˜ ์ถ•์†Œํ•  ์ˆ˜ ์žˆ๋Š” ๋Šฅ๋ ฅ.”

→ ์ฆ‰, ํ•„์š”ํ•œ ๋งŒํผ๋งŒ ์‚ฌ์šฉํ•˜๊ณ , ํ•„์š” ์—†์œผ๋ฉด ์ž๋™์œผ๋กœ ์ค„์ด๋Š” ๊ฒƒ!



๐Ÿ“˜ Q49. Global Content Delivery — CloudFront

โ“ ๋ฌธ์ œ ์š”์•ฝ

ํ•œ ํšŒ์‚ฌ๊ฐ€ ์ด๋ฏธ์ง€์™€ ๋น„๋””์˜ค๋ฅผ ์ „ ์„ธ๊ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ์ตœ์†Œํ•œ์˜ ์ง€์—ฐ(latency) ์œผ๋กœ ์ „๋‹ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
๋น„์šฉ ํšจ์œจ์ ์ธ ๋ฐฉ๋ฒ•์œผ๋กœ ์ด๋ฅผ ๋‹ฌ์„ฑํ•˜๊ธฐ ์œ„ํ•ด ์–ด๋–ค ์ ‘๊ทผ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: A. Deliver the content through Amazon CloudFront


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

๐Ÿ”น Amazon CloudFront

AWS์˜ ์ฝ˜ํ…์ธ  ์ „์†ก ๋„คํŠธ์›Œํฌ(CDN) ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.
์ •์ (์ด๋ฏธ์ง€, ๋™์˜์ƒ, HTML ๋“ฑ)๊ณผ ๋™์  ์ฝ˜ํ…์ธ ๋ฅผ ์ „ ์„ธ๊ณ„ ์—ฃ์ง€ ๋กœ์ผ€์ด์…˜(Edge Location) ์— ์บ์‹ฑํ•˜์—ฌ,
์‚ฌ์šฉ์ž์—๊ฒŒ ๊ฐ€์žฅ ๊ฐ€๊นŒ์šด ์œ„์น˜์—์„œ ๋น ๋ฅด๊ฒŒ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ‘‰ ํ•ต์‹ฌ ํšจ๊ณผ:

  • ๐ŸŒŽ ๊ธ€๋กœ๋ฒŒ ์ „์†ก ์†๋„ ํ–ฅ์ƒ (์ง€์—ฐ ์ตœ์†Œํ™”)
  • ๐Ÿ’ฐ S3๋‚˜ EC2์™€ ์—ฐ๋™ ์‹œ ๋น„์šฉ ์ ˆ๊ฐ
  • ๐Ÿ”’ SSL/TLS, WAF ๋“ฑ ๋ณด์•ˆ ๊ธฐ๋Šฅ ํ†ตํ•ฉ ๊ฐ€๋Šฅ

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์™œ ํ‹€๋ ธ๋Š”๊ฐ€
B. Store the content on Amazon S3 and enable cross-region replication S3 ์ง€์—ญ ๊ฐ„ ๋ณต์ œ(CRR)๋Š” ๋ฐฑ์—… ๋ฐ ๊ฐ€์šฉ์„ฑ ํ–ฅ์ƒ ๋ชฉ์  ์ „์†ก ์ง€์—ฐ(latency) ๊ฐœ์„ ์—๋Š” ํ•œ๊ณ„ ์žˆ์Œ โŒ
C. Implement a VPN across multiple AWS Regions VPN์€ ๋ณด์•ˆ ํ†ต์‹  ์šฉ๋„๋กœ ์‚ฌ์šฉ ๊ธ€๋กœ๋ฒŒ ์ฝ˜ํ…์ธ  ๋ฐฐํฌ์™€ ๋ฌด๊ด€ โŒ
D. Deliver through AWS PrivateLink PrivateLink๋Š” VPC ๊ฐ„ ํ”„๋ผ์ด๋น— ์—ฐ๊ฒฐ ์„œ๋น„์Šค ํผ๋ธ”๋ฆญ ์‚ฌ์šฉ์ž์—๊ฒŒ ์ฝ˜ํ…์ธ  ์ „์†ก ๋ถˆ๊ฐ€๋Šฅ โŒ

๐Ÿงฉ ๊ตฌ์กฐ ์‹œ๊ฐํ™” (Mermaid)

 
```mermaid
flowchart LR
    A[๐Ÿ“ฆ S3 Origin or EC2 Server] --> B[๐ŸŒ Amazon CloudFront Edge Locations]
    B --> C[๐Ÿ‘ฉ‍๐Ÿ’ป Global Users]
    C -->|์š”์ฒญ ์‹œ ๊ฐ€์žฅ ๊ฐ€๊นŒ์šด Edge์—์„œ ์ œ๊ณต| B
    B -->|Cache ๋ฏธ์กด์žฌ ์‹œ Origin์œผ๋กœ ์š”์ฒญ| A
```

๐Ÿง  ํ•ต์‹ฌ ์š”์•ฝ

CloudFront = ์ „ ์„ธ๊ณ„ ์—ฃ์ง€ ๋กœ์ผ€์ด์…˜์„ ํ™œ์šฉํ•œ ์ €์ง€์—ฐ ์ฝ˜ํ…์ธ  ์ „์†ก ์„œ๋น„์Šค

ํ•ญ๋ชฉ ์„ค๋ช…
๐Ÿ”น ์„œ๋น„์Šค ์œ ํ˜• CDN (Content Delivery Network)
๐Ÿ”น ์ฃผ์š” ๊ธฐ๋Šฅ ์บ์‹ฑ, ์ง€์—ฐ ์ตœ์†Œํ™”, ์ „์†ก ๊ฐ€์†
๐Ÿ”น ์—ฐ๋™ ์„œ๋น„์Šค S3, EC2, ALB, API Gateway
๐Ÿ”น ๋ณด์•ˆ ํ†ตํ•ฉ AWS WAF, ACM, Shield
๐Ÿ”น ๋น„์šฉ ํšจ์œจ์„ฑ ํŠธ๋ž˜ํ”ฝ ๊ธฐ๋ฐ˜ ๊ณผ๊ธˆ (S3๋ณด๋‹ค ์ €๋ ดํ•œ ์ „์†ก๋น„)

 


โœ… ์ •๋‹ต

A. Deliver the content through Amazon CloudFront


 

๋ฐ˜์‘ํ˜•