2025-10-19 18:20:52
๋ฐ˜์‘ํ˜•

๐Ÿ“˜ Q403.

Which statements represent the cost-effectiveness of the AWS Cloud? (Choose two)

AWS ํด๋ผ์šฐ๋“œ์˜ ๋น„์šฉ ํšจ์œจ์„ฑ์„ ๋‚˜ํƒ€๋‚ด๋Š” ์„ค๋ช…์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? (2๊ฐœ ์„ ํƒ)


โœ… ์ •๋‹ต: A. Users can trade fixed expenses for variable expenses.

โœ… ์ •๋‹ต: E. Users benefit from economies of scale.


๐Ÿ’ก ํ•ด์„ค

๐Ÿงฎ A. Users can trade fixed expenses for variable expenses

  • ์˜จํ”„๋ ˆ๋ฏธ์Šค ํ™˜๊ฒฝ์—์„œ๋Š” ์„œ๋ฒ„, ์Šคํ† ๋ฆฌ์ง€, ๋„คํŠธ์›Œํฌ ์žฅ๋น„ ๋“ฑ์„ ๋ฏธ๋ฆฌ ๊ตฌ์ž…ํ•ด์•ผ ํ•˜๋Š” ๊ณ ์ •๋น„์šฉ(CapEx) ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  • ๋ฐ˜๋ฉด AWS๋Š” ํ•„์š”ํ•  ๋•Œ๋งŒ ๋ฆฌ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ๊ทธ๋งŒํผ๋งŒ ๋น„์šฉ์„ ์ง€๋ถˆํ•˜๋Š” ๋ณ€๋™๋น„์šฉ(OpEx) ๊ตฌ์กฐ์ž…๋‹ˆ๋‹ค.

๐Ÿ“Š ์˜ˆ์‹œ:

  • ๊ธฐ์กด: ์„œ๋ฒ„ 10๋Œ€๋ฅผ ์„ ๊ตฌ๋งค(์ˆ˜์ฒœ๋งŒ ์›์˜ ์ดˆ๊ธฐ ๋น„์šฉ)
  • AWS: ์‹ค์ œ ์‚ฌ์šฉ ์‹œ๊ฐ„๋งŒํผ๋งŒ ๊ณผ๊ธˆ (์˜ˆ: 2์‹œ๊ฐ„๋งŒ EC2 ์ธ์Šคํ„ด์Šค ์‹คํ–‰)

๐Ÿ‘‰ ์ฆ‰, “๊ณ ์ •๋น„๋ฅผ ๋ณ€๋™๋น„๋กœ ์ „ํ™˜”ํ•จ์œผ๋กœ์จ ์ดˆ๊ธฐ ํˆฌ์ž ๋ถ€๋‹ด ์—†์ด ํด๋ผ์šฐ๋“œ ๋„์ž…์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.


๐Ÿ’ก E. Users benefit from economies of scale

  • AWS๋Š” ์ „ ์„ธ๊ณ„ ์ˆ˜๋ฐฑ๋งŒ ๊ณ ๊ฐ์˜ ์ธํ”„๋ผ ์‚ฌ์šฉ๋Ÿ‰์„ ๊ธฐ๋ฐ˜์œผ๋กœ ๊ทœ๋ชจ์˜ ๊ฒฝ์ œ(economies of scale) ๋ฅผ ์‹คํ˜„ํ•ฉ๋‹ˆ๋‹ค.
  • ๋Œ€๊ทœ๋ชจ ์ธํ”„๋ผ ์šด์˜์œผ๋กœ ์ธํ•ด AWS๋Š” ๋” ๋‚ฎ์€ ๋‹จ๊ฐ€๋กœ ์ปดํ“จํŒ… ํŒŒ์›Œ, ์Šคํ† ๋ฆฌ์ง€, ๋„คํŠธ์›Œํฌ ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“‰ ํšจ๊ณผ:

  • AWS์˜ ๊ณ ๊ฐ์ด ๋งŽ์•„์งˆ์ˆ˜๋ก ๋‹จ๊ฐ€๊ฐ€ ๋‚ฎ์•„์ง€๊ณ ,
  • ๊ทธ ํ˜œํƒ์ด ๋‹ค์‹œ ์‚ฌ์šฉ์ž์—๊ฒŒ ๊ฐ€๊ฒฉ ์ธํ•˜(Price Reduction) ํ˜•ํƒœ๋กœ ๋Œ์•„์˜ต๋‹ˆ๋‹ค.

๐Ÿท๏ธ ์‹ค์ œ๋กœ AWS๋Š” 2006๋…„ ์ดํ›„ 100ํšŒ ์ด์ƒ ๊ณต์‹์ ์œผ๋กœ ๊ฐ€๊ฒฉ์„ ์ธํ•˜ํ–ˆ์Šต๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต 
B. Users can deploy all over the world in minutes. ์ด๋Š” ๋ฏผ์ฒฉ์„ฑ(Agility) ๊ด€๋ จ ์ด์ ์ด์ง€ ๋น„์šฉ ํšจ์œจ์„ฑ๊ณผ ์ง์ ‘ ๊ด€๋ จ ์—†์Œ โŒ
C. AWS offers increased speed and agility. ์†๋„ ํ–ฅ์ƒ์€ ์šด์˜ ํšจ์œจ์„ฑ ์ธก๋ฉด์ด์ง€ ๋น„์šฉ ์ ˆ๊ฐ๊ณผ๋Š” ๋ณ„๊ฐœ โŒ
D. AWS is responsible for patching the infrastructure. AWS๊ฐ€ ์ธํ”„๋ผ ๋ณด์•ˆ์„ ๋‹ด๋‹นํ•˜๋Š” ๊ฒƒ์€ ๋ณด์•ˆ(Shared Responsibility Model) ๊ฐœ๋… โŒ

๐Ÿ“Š ํ•ต์‹ฌ ์š”์•ฝ

ํ•ต์‹ฌ ๊ฐœ๋…์„ค๋ช…
CapEx → OpEx ์ „ํ™˜ ์ดˆ๊ธฐ ํˆฌ์ž ์—†์ด ํ•„์š”ํ•œ ๋งŒํผ๋งŒ ์‚ฌ์šฉ ํ›„ ์ง€๋ถˆ
๊ทœ๋ชจ์˜ ๊ฒฝ์ œ (Economies of Scale) AWS์˜ ๋Œ€๊ทœ๋ชจ ์ธํ”„๋ผ ์šด์˜์œผ๋กœ ๋‚ฎ์€ ๋‹จ๊ฐ€ ์‹คํ˜„
์‚ฌ์šฉ๋Ÿ‰ ๊ธฐ๋ฐ˜ ๊ณผ๊ธˆ (Pay-as-you-go) ์œ ํœด ๋ฆฌ์†Œ์Šค ์ œ๊ฑฐ ๋ฐ ๋‚ญ๋น„ ์ตœ์†Œํ™”

๐Ÿงฉ ์‹œ๊ฐ ์š”์•ฝ (Mermaid)

```mermaid
flowchart LR
    A["๐Ÿข On-Premises"] -->|"๐Ÿ’ฐ CapEx - ์„œ๋ฒ„ ๊ตฌ๋งค ๋ฐ ์œ ์ง€๋น„"| B["๐Ÿ’ธ ๋†’์€ ๊ณ ์ •๋น„"]
    C["โ˜๏ธ AWS Cloud"] -->|"โš™๏ธ OpEx - ์‚ฌ์šฉํ•œ ๋งŒํผ ์ง€๋ถˆ (Pay-as-you-go)"| D["๐Ÿ’ต ๋ณ€๋™๋น„ + ํšจ์œจ์  ๋น„์šฉ"]
    D -->|"๐Ÿ“‰ ๊ทœ๋ชจ์˜ ๊ฒฝ์ œ๋กœ ์ง€์†์  ๊ฐ€๊ฒฉ ์ธํ•˜"| E["๐Ÿš€ ๋น„์šฉ ํšจ์œจ ํ–ฅ์ƒ"]
```
 

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

โ˜๏ธ AWS์˜ ๋น„์šฉ ํšจ์œจ์„ฑ ํ•ต์‹ฌ์€ “CapEx → OpEx ์ „ํ™˜” + “๊ทœ๋ชจ์˜ ๊ฒฝ์ œ(Economies of Scale)”


๐Ÿ“˜ Q406.

A company needs to consolidate the billing for multiple AWS accounts.

์—ฌ๋Ÿฌ AWS ๊ณ„์ •์˜ ๊ฒฐ์ œ๋ฅผ ํ†ตํ•ฉํ•ด์•ผ ํ•œ๋‹ค๋ฉด ์–ด๋–ค ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: B. AWS Organizations


๐Ÿ’ก ์ •๋‹ต ํ•ด์„ค

๐Ÿ”น AWS Organizations๋ž€?

AWS Organizations๋Š” ์—ฌ๋Ÿฌ AWS ๊ณ„์ •์„ ์ค‘์•™์—์„œ ๊ด€๋ฆฌํ•˜๊ณ ,
์ฒญ๊ตฌ์„œ ํ†ตํ•ฉ(Consolidated Billing) ๋ฐ ์ •์ฑ… ์ œ์–ด(Service Control Policies, SCPs) ๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


โœ… ํ•ต์‹ฌ ๊ธฐ๋Šฅ

๊ธฐ๋Šฅ ์„ค๋ช…
๐Ÿงพ Consolidated Billing (ํ†ตํ•ฉ ์ฒญ๊ตฌ) ์—ฌ๋Ÿฌ AWS ๊ณ„์ •์„ ํ•˜๋‚˜์˜ “Payer Account(๊ฒฐ์ œ ๊ณ„์ •)” ์•„๋ž˜ ๋ฌถ์–ด ๋‹จ์ผ ์ฒญ๊ตฌ์„œ๋กœ ๊ด€๋ฆฌ ๊ฐ€๋Šฅ
๐Ÿ’ฐ ๋น„์šฉ ์ ˆ๊ฐ ํšจ๊ณผ (Savings) ๋ชจ๋“  ๊ณ„์ •์˜ ์‚ฌ์šฉ๋Ÿ‰์ด ํ•ฉ์‚ฐ๋˜์–ด ๋ณผ๋ฅจ ํ• ์ธ๊ณผ Savings Plan/RI ํ• ์ธ์„ ํ•จ๊ป˜ ์ ์šฉ๋ฐ›์Œ
๐Ÿ”’ Policy Control (SCP) ๋ฉค๋ฒ„ ๊ณ„์ •์ด ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋น„์Šค๋‚˜ ๋ฆฌ์†Œ์Šค๋ฅผ ์กฐ์ง ๋‹จ์œ„๋กœ ์ œํ•œ ๊ฐ€๋Šฅ
๐Ÿง‘‍๐Ÿ’ผ ์กฐ์ง ๊ตฌ์กฐ ๊ด€๋ฆฌ OU(Organizational Units)๋ฅผ ์‚ฌ์šฉํ•ด ๋ถ€์„œ, ํŒ€, ํ”„๋กœ์ ํŠธ๋ณ„ ๊ณ„์ • ๊ทธ๋ฃนํ™” ๊ฐ€๋Šฅ
โš™๏ธ ์ž๋™ ๊ณ„์ • ์ƒ์„ฑ ๋ฐ ์ดˆ๋Œ€ ์ƒˆ๋กœ์šด ๊ณ„์ •์„ ์ž๋™์œผ๋กœ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ๊ธฐ์กด ๊ณ„์ •์„ ์กฐ์ง์— ์ดˆ๋Œ€ ๊ฐ€๋Šฅ

๐Ÿงฎ Consolidated Billing ์˜ˆ์‹œ

๊ณ„์ • EC2 ์‚ฌ์šฉ๋ฃŒ ํ•ฉ์‚ฐ ํ• ์ธ์œจ ์ด ๋น„์šฉ
A (๊ฐœ๋ฐœํŒ€) $100    
B (์šด์˜ํŒ€) $200 โœ… 10% ํ• ์ธ ์ ์šฉ (300๋‹ฌ๋Ÿฌ ๋‹จ์œ„) ๐Ÿ’ต $270
์ดํ•ฉ $300 ํ†ตํ•ฉ ์ฒญ๊ตฌ + ํ• ์ธ ์ ์šฉ โœ… ๋” ์ ์€ ์ด ๋น„์šฉ

์ฆ‰, ๊ฐœ๋ณ„ ๊ณ„์ •์ด ์•„๋‹Œ ์กฐ์ง ์ „์ฒด ์‚ฌ์šฉ๋Ÿ‰์„ ๊ธฐ์ค€์œผ๋กœ ํ• ์ธ์œจ์ด ์ ์šฉ๋˜์–ด
๋น„์šฉ ํšจ์œจ์„ฑ์ด ์ฆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. AWS Trusted Advisor ๋ณด์•ˆ, ๋น„์šฉ, ์„ฑ๋Šฅ, ์„œ๋น„์Šค ํ•œ๋„ ๊ด€๋ จ ๊ถŒ์žฅ์‚ฌํ•ญ ์ œ๊ณต โŒ ๊ฒฐ์ œ ํ†ตํ•ฉ ๊ธฐ๋Šฅ ์—†์Œ
C. AWS Budgets ์˜ˆ์‚ฐ ํ•œ๋„ ๋ฐ ์ดˆ๊ณผ ์‹œ ์•Œ๋ฆผ ์„ค์ • ๊ธฐ๋Šฅ ์ œ๊ณต โŒ “์•Œ๋ฆผ” ๊ธฐ๋Šฅ์ด์ง€, ๊ฒฐ์ œ ํ†ตํ•ฉ์€ ๋ถˆ๊ฐ€
D. AWS Service Catalog ์Šน์ธ๋œ ์„œ๋น„์Šค ํ…œํ”Œ๋ฆฟ์„ ์นดํƒˆ๋กœ๊ทธ ํ˜•ํƒœ๋กœ ๋ฐฐํฌ โŒ ๊ฒฐ์ œ ๊ด€๋ฆฌ์™€ ๋ฌด๊ด€

๐Ÿงฉ ์‹œ๊ฐ ์š”์•ฝ (Mermaid)

```mermaid
flowchart TD
    A["๐Ÿ‘ฉ‍๐Ÿ’ผ Management / Payer Account"] -->|"๐Ÿงพ Consolidated Billing"| B["๐Ÿ‘ฅ Linked Accounts"]
    B -->|"๐Ÿ“Š Usage Data + ๐Ÿ’ธ Discounts"| C["๐Ÿ’ฐ Single Combined Invoice"]
    A -->|"๐Ÿ›ก๏ธ Apply SCPs"| D["๐Ÿ”’ Control Policies"]
```
 

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿ’ผ ์—ฌ๋Ÿฌ AWS ๊ณ„์ •์˜ ์ฒญ๊ตฌ๋ฅผ ํ†ตํ•ฉํ•˜๋ ค๋ฉด AWS Organizations์˜ Consolidated Billing ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.


VPC ๋‚ด์—์„œ EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ์ œ์–ด๋ฅผ ์œ„ํ•œ AWS ๋„ค์ดํ‹ฐ๋ธŒ ๋ณด์•ˆ ๋ฆฌ์†Œ์Šค๋ฅผ ๋ฌป๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.

๐Ÿ“˜ Q413.

Which AWS service or feature will meet this requirement?

ํŠน์ • EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„์˜ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ์ œ์–ดํ•˜๊ธฐ ์œ„ํ•œ AWS ๊ธฐ๋ณธ ๋ณด์•ˆ ๊ธฐ๋Šฅ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?


โœ… ์ •๋‹ต: D. Security groups


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Security Group์ด๋ž€?

  • AWS์˜ ๊ฐ€์ƒ ๋ฐฉํ™”๋ฒฝ(Virtual Firewall) ์—ญํ• ์„ ํ•˜๋Š” ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€ ๋ณด์•ˆ ์ œ์–ด(Instance-level security control) ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.
  • VPC ๋‚ด์˜ ๊ฐœ๋ณ„ EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„ ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๊ฑฐ๋‚˜ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

โœ… ์ฃผ์š” ํŠน์ง•

ํ•ญ๋ชฉ ์„ค๋ช…
์ ์šฉ ์ˆ˜์ค€ ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€ (Instance Level)
์ƒํƒœ ์ €์žฅ(Stateful) ์š”์ฒญ์ด ํ—ˆ์šฉ๋˜๋ฉด ์‘๋‹ต ํŠธ๋ž˜ํ”ฝ์€ ์ž๋™ ํ—ˆ์šฉ
๊ทœ์น™ ๋ฐฉํ–ฅ Inbound (์ˆ˜์‹ ) / Outbound (์†ก์‹ ) ํŠธ๋ž˜ํ”ฝ ์ œ์–ด ๊ฐ€๋Šฅ
๊ธฐ๋ณธ ๋™์ž‘ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ ๊ฑฐ๋ถ€(Deny All) ํ›„ ๋ช…์‹œ์ ์œผ๋กœ ํ—ˆ์šฉ(Allow Only)
์ ์šฉ ๋Œ€์ƒ EC2, RDS, Lambda ENI, ALB ๋“ฑ ENI(Elastic Network Interface) ๊ธฐ๋ฐ˜ ๋ฆฌ์†Œ์Šค
์˜ˆ์‹œ ํŠน์ • EC2 ์ธ์Šคํ„ด์Šค๋ผ๋ฆฌ๋งŒ SSH(22๋ฒˆ ํฌํŠธ) ํ†ต์‹  ํ—ˆ์šฉ

๐Ÿงฑ ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

ํšŒ์‚ฌ๊ฐ€ VPC ์•ˆ์— EC2 ์ธ์Šคํ„ด์Šค 10๊ฐœ๋ฅผ ์‹คํ–‰ ์ค‘์ด๊ณ ,
์ด ์ค‘ ์›น ์„œ๋ฒ„(EC2-1) ์™€ DB ์„œ๋ฒ„(EC2-2) ์‚ฌ์ด์—๋งŒ ํ†ต์‹ ์„ ํ—ˆ์šฉํ•˜๊ณ  ์‹ถ์„ ๋•Œ:

  • EC2-2(DB) ์ธ์Šคํ„ด์Šค์˜ Security Group์—์„œ
    • Inbound ๊ทœ์น™: EC2-1์˜ Security Group ID๋กœ๋ถ€ํ„ฐ๋งŒ 3306(MySQL) ํฌํŠธ ํ—ˆ์šฉ
    • ๋‹ค๋ฅธ ํŠธ๋ž˜ํ”ฝ์€ ๋ชจ๋‘ ์ฐจ๋‹จ
 
Inbound Rule: Type: MySQL/Aurora (3306) Source: sg-0a1b2c3d4e5f (์›น์„œ๋ฒ„ SG)

โœ… ์ด๋ ‡๊ฒŒ ํ•˜๋ฉด DB ์ธ์Šคํ„ด์Šค๋Š” ์ง€์ •๋œ ์›น ์„œ๋ฒ„ SG์—์„œ ์˜ค๋Š” ์š”์ฒญ๋งŒ ์ˆ˜๋ฝํ•ฉ๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Network ACLs ์„œ๋ธŒ๋„ท ๋‹จ์œ„(Subnet-level) ํŠธ๋ž˜ํ”ฝ ์ œ์–ด, Stateless ๋ฐฉ์‹ โŒ ์ธ์Šคํ„ด์Šค ๊ฐ„ ์„ธ๋ถ€ ์ œ์–ด ๋ถˆ๊ฐ€๋Šฅ
B. AWS WAF ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต(7๊ณ„์ธต)์—์„œ HTTP/HTTPS ์š”์ฒญ ํ•„ํ„ฐ๋ง โŒ EC2 ๊ฐ„ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ ์ œ์–ด์™€ ๋ฌด๊ด€
C. Amazon GuardDuty ์œ„ํ˜‘ ํƒ์ง€(Threat Detection) ์„œ๋น„์Šค๋กœ, ํŠธ๋ž˜ํ”ฝ ์ œ์–ด ๋ถˆ๊ฐ€๋Šฅ โŒ ๋ชจ๋‹ˆํ„ฐ๋ง ์šฉ๋„์ผ ๋ฟ ์ œ์–ด ๋ถˆ๊ฐ€
D. Security groups โœ… ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€์—์„œ ํŠธ๋ž˜ํ”ฝ ์ œ์–ด (์ •๋‹ต) โœ…

๐Ÿงฉ ์‹œ๊ฐ ์š”์•ฝ (Mermaid)

 
```mermaid
flowchart LR
    A["๐Ÿ’ป EC2-1 - Web Server"] -->|"โœ… Allow Port 3306"| B["๐Ÿ—„๏ธ EC2-2 - DB Server"]
    A -.->|"๐Ÿšซ Other Ports Denied"| B
    subgraph VPC ["๐ŸŒ VPC"]
        A
        B
    end
    Note["๐Ÿ”’ Security Group - Instance-level, Stateful, Allow-based Rules"]
```
 

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿ›ก๏ธ EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ์ œ์–ด๋Š” ๋ณด์•ˆ ๊ทธ๋ฃน(Security Group) ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๋ฉฐ, ์ด๋Š” ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€์˜ ์ƒํƒœ ์ €์žฅํ˜• ๋ฐฉํ™”๋ฒฝ์ž…๋‹ˆ๋‹ค.


๐Ÿ“˜ Q426.

Which AWS service should the company use to meet these requirements?

์ „ ์„ธ๊ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ์›น์‚ฌ์ดํŠธ๋ฅผ ๋น ๋ฅด๊ณ  ํšจ์œจ์ ์œผ๋กœ ์ „๋‹ฌํ•˜๋ ค๋ฉด ์–ด๋–ค ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: B. Amazon CloudFront


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Amazon CloudFront๋ž€?

Amazon CloudFront๋Š” AWS์˜ ๊ธ€๋กœ๋ฒŒ ์ฝ˜ํ…์ธ  ์ „์†ก ๋„คํŠธ์›Œํฌ(CDN, Content Delivery Network) ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.
์ „ ์„ธ๊ณ„ 600๊ฐœ ์ด์ƒ์˜ Edge Location(์—ฃ์ง€ ๋กœ์ผ€์ด์…˜) ์„ ํ†ตํ•ด ์ฝ˜ํ…์ธ ๋ฅผ ์บ์‹ฑํ•˜๊ณ ,
์‚ฌ์šฉ์ž์—๊ฒŒ ๊ฐ€์žฅ ๊ฐ€๊นŒ์šด ์œ„์น˜์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•จ์œผ๋กœ์จ ์ง€์—ฐ์‹œ๊ฐ„(Latency) ์„ ์ตœ์†Œํ™”ํ•ฉ๋‹ˆ๋‹ค.


โœ… CloudFront์˜ ์ฃผ์š” ์—ญํ• 

๊ธฐ๋Šฅ ์„ค๋ช…
๐ŸŒ ๊ธ€๋กœ๋ฒŒ ์—ฃ์ง€ ๋„คํŠธ์›Œํฌ ์ œ๊ณต ์‚ฌ์šฉ์ž์™€ ๊ฐ€์žฅ ๊ฐ€๊นŒ์šด Edge Location์—์„œ ์ฝ˜ํ…์ธ  ์ œ๊ณต
โšก ๋‚ฎ์€ ์ง€์—ฐ์‹œ๊ฐ„ (Low Latency) EC2/S3์˜ ์›๋ณธ ๋ฐ์ดํ„ฐ๋ฅผ ์ „ ์„ธ๊ณ„ ์บ์‹œ ์„œ๋ฒ„์— ๋ถ„์‚ฐ ์ €์žฅ
๐Ÿ”’ ๋ณด์•ˆ ๊ฐ•ํ™” AWS Shield, WAF, SSL/TLS ํ†ตํ•ฉ ์ง€์›
๐Ÿ’ธ ๋น„์šฉ ์ ˆ๊ฐ ์บ์‹ฑ์„ ํ†ตํ•ด ์›๋ณธ ์„œ๋ฒ„(EC2/S3)์— ๋Œ€ํ•œ ์š”์ฒญ ๊ฐ์†Œ → ๋„คํŠธ์›Œํฌ ๋น„์šฉ ์ ˆ๊ฐ
๐Ÿง  ์ž๋™ ํ™•์žฅ์„ฑ ํŠธ๋ž˜ํ”ฝ ๊ธ‰์ฆ ์‹œ ์ž๋™์œผ๋กœ Edge ์„œ๋ฒ„ ๋ฆฌ์†Œ์Šค ํ™•์žฅ

๐Ÿ“ฆ ๊ตฌ์„ฑ ์˜ˆ์‹œ

ํšŒ์‚ฌ๋Š” EC2 ์ธ์Šคํ„ด์Šค์—์„œ ์›น์‚ฌ์ดํŠธ๋ฅผ ํ˜ธ์ŠคํŒ… ์ค‘
CloudFront๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ ์ „ ์„ธ๊ณ„ ์—ฃ์ง€ ๋กœ์ผ€์ด์…˜์— ์บ์‹ฑํ•˜๋ฉด ์ง€์—ฐ์ด ํฌ๊ฒŒ ๊ฐ์†Œํ•ฉ๋‹ˆ๋‹ค.

 
 

๐Ÿ“ ์š”์•ฝ:
์‚ฌ์šฉ์ž๋Š” ๊ฐ€๊นŒ์šด Edge Location์„ ํ†ตํ•ด ์ฝ˜ํ…์ธ ๋ฅผ ๋ฐ›๊ธฐ ๋•Œ๋ฌธ์—
์„œ์šธ, ๋‰ด์š•, ๋Ÿฐ๋˜ ์–ด๋””์„œ ์ ‘์†ํ•˜๋“  ๋น ๋ฅธ ์†๋„๋กœ ์›น์‚ฌ์ดํŠธ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Amazon Route 53 DNS ์„œ๋น„์Šค๋กœ ๋„๋ฉ”์ธ ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•จ โŒ ์ „์†ก ์ง€์—ฐ ์ตœ์†Œํ™” ๋ชฉ์ (CDN)์ด ์•„๋‹˜
C. Elastic Load Balancing (ELB) ๋ฆฌ์ „ ๋‚ด EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋ถ„์‚ฐ โŒ ๊ธ€๋กœ๋ฒŒ ์‚ฌ์šฉ์ž์—๊ฒŒ๋Š” ํ•œ๊ณ„ ์žˆ์Œ
D. AWS Lambda ์„œ๋ฒ„๋ฆฌ์Šค ์ปดํ“จํŒ… ์„œ๋น„์Šค โŒ ์›น ์ฝ˜ํ…์ธ  ์ „์†ก ๋ฐ ์บ์‹ฑ ๊ธฐ๋Šฅ ์—†์Œ

๐Ÿงฉ CloudFront์˜ ์žฅ์  ์ •๋ฆฌ

ํ•ญ๋ชฉ ์„ค๋ช…
๐ŸŒ ์ „ ์„ธ๊ณ„ ์ปค๋ฒ„๋ฆฌ์ง€ ๊ธ€๋กœ๋ฒŒ ์—ฃ์ง€ ๋„คํŠธ์›Œํฌ๋กœ ์‚ฌ์šฉ์ž์™€ ๋ฌผ๋ฆฌ์  ๊ฑฐ๋ฆฌ ์ตœ์†Œํ™”
๐Ÿš€ ์„ฑ๋Šฅ ํ–ฅ์ƒ ๋ฐ์ดํ„ฐ ์ „์†ก ์†๋„ ๊ฐœ์„ , ์ง€์—ฐ์‹œ๊ฐ„ ๊ฐ์†Œ
๐Ÿ’ฐ ๋น„์šฉ ์ ˆ๊ฐ ์›๋ณธ ์„œ๋ฒ„ ๋ถ€ํ•˜ ๋ฐ ๋ฐ์ดํ„ฐ ์ „์†ก ๋น„์šฉ ์ ˆ๊ฐ
๐Ÿ”’ ๋ณด์•ˆ ๊ฐ•ํ™” DDoS ๋ณดํ˜ธ(AWS Shield), HTTPS ํ†ต์‹ , WAF ํ†ตํ•ฉ

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

โšก ์ „ ์„ธ๊ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ๋น ๋ฅด๊ณ  ์•ˆ์ „ํ•˜๊ฒŒ ์›น์‚ฌ์ดํŠธ๋ฅผ ์ „๋‹ฌํ•˜๋ ค๋ฉด Amazon CloudFront (CDN) ๋ฅผ ์‚ฌ์šฉํ•˜์„ธ์š”.


๐Ÿ“˜ Q435.

Which AWS service should the company use to identify who accessed an AWS service and what action was performed?


โœ… ์ •๋‹ต: B. AWS CloudTrail


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น AWS CloudTrail์ด๋ž€?

AWS CloudTrail์€ ๊ณ„์ • ๋‚ด์—์„œ ๋ฐœ์ƒํ•œ ๋ชจ๋“  API ํ˜ธ์ถœ(Activity Logs) ์„ ๊ธฐ๋กํ•˜๋Š” ๊ฐ์‚ฌ(Audit) ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

์ฆ‰,
๋ˆ„๊ฐ€ (Who)”,
์–ธ์ œ (When)”,
์–ด๋””์„œ (Where)”,
๋ฌด์—‡์„ (What)
ํ–ˆ๋Š”์ง€๋ฅผ ๋ชจ๋‘ ์ถ”์ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


โœ… ์ฃผ์š” ๊ธฐ๋Šฅ ์š”์•ฝ

๊ธฐ๋Šฅ ์„ค๋ช…
๐Ÿงพ API ํ˜ธ์ถœ ๊ธฐ๋ก AWS Management Console, CLI, SDK, ๋˜๋Š” ๋‹ค๋ฅธ ์„œ๋น„์Šค์—์„œ ๋ฐœ์ƒํ•œ ๋ชจ๋“  API ํ˜ธ์ถœ์„ ๊ธฐ๋ก
๐Ÿ‘ค ์‚ฌ์šฉ์ž ์‹๋ณ„ ์–ด๋–ค IAM ์‚ฌ์šฉ์ž, ์—ญํ• (Role), ๋˜๋Š” ์„œ๋น„์Šค๊ฐ€ ์š”์ฒญ์„ ์ˆ˜ํ–‰ํ–ˆ๋Š”์ง€ ํ™•์ธ ๊ฐ€๋Šฅ
๐Ÿ•“ ์‹œ๊ฐ„๋ณ„ ์ด๋ฒคํŠธ ์ถ”์  ํŠน์ • ์‹œ๊ฐ„๋Œ€(Time Window) ๋™์•ˆ์˜ ๋ชจ๋“  ํ™œ๋™ ๋กœ๊ทธ๋ฅผ ๊ฒ€์ƒ‰ ๊ฐ€๋Šฅ
๐Ÿ’พ ๋กœ๊ทธ ์ €์žฅ CloudTrail ๋กœ๊ทธ๋Š” S3 ๋ฒ„ํ‚ท์— ์ž๋™ ์ €์žฅ ๊ฐ€๋Šฅ
๐Ÿ” ์ด์ƒ ํ™œ๋™ ๊ฐ์ง€ CloudTrail Insights๋ฅผ ํ†ตํ•ด ๋น„์ •์ƒ์  API ํ˜ธ์ถœ ํŒจํ„ด ํƒ์ง€
๐Ÿ”’ ๋ณด์•ˆ ๊ฐ์‚ฌ ๋ฐ ์ปดํ”Œ๋ผ์ด์–ธ์Šค PCI-DSS, ISO 27001 ๋“ฑ ๊ทœ์ • ์ค€์ˆ˜๋ฅผ ์œ„ํ•œ ๋กœ๊ทธ ์ฆ์  ํ™•๋ณด ๊ฐ€๋Šฅ

๐Ÿง  ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

ํšŒ์‚ฌ๊ฐ€ “์–ด์ œ ๋ˆ„๊ฐ€ S3 ๋ฒ„ํ‚ท์„ ์‚ญ์ œํ–ˆ๋Š”์ง€” ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค๋ฉด?

  1. CloudTrail ์ฝ˜์†”Event history(์ด๋ฒคํŠธ ๊ธฐ๋ก) ๋กœ ์ด๋™
  2. Event Name = DeleteBucket ๊ฒ€์ƒ‰
  3. ๊ฒฐ๊ณผ์—์„œ userIdentity ํ•„๋“œ๋ฅผ ํ™•์ธ
    → ํ•ด๋‹น ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•œ ์‚ฌ์šฉ์ž ๋˜๋Š” IAM Role์„ ํ™•์ธ ๊ฐ€๋Šฅ

๐Ÿ“ฆ ๋กœ๊ทธ ์ €์žฅ ๊ตฌ์กฐ (์˜ˆ์‹œ)

 
{
  "eventVersion": "1.05",
  "userIdentity": {
    "type": "IAMUser",
    "userName": "admin-user"
  },
  "eventTime": "2025-10-18T09:33:12Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "DeleteBucket",
  "sourceIPAddress": "203.0.113.45"
}
 

์œ„ ๋กœ๊ทธ์—์„œ ๋ˆ„๊ฐ€(userName), ์–ธ์ œ(eventTime), ์–ด๋–ค ์„œ๋น„์Šค(eventSource) ์—์„œ
์–ด๋–ค ํ–‰๋™(eventName) ์„ ์ˆ˜ํ–‰ํ–ˆ๋Š”์ง€๋ฅผ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Amazon CloudWatch ์„ฑ๋Šฅ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ๋ฉ”ํŠธ๋ฆญ ์ˆ˜์ง‘ ์„œ๋น„์Šค โŒ API ํ˜ธ์ถœ ๊ธฐ๋ก ๋ถˆ๊ฐ€ (๋ฆฌ์†Œ์Šค ์ƒํƒœ๋งŒ ๋ชจ๋‹ˆํ„ฐ๋ง)
C. AWS Security Hub ๋ณด์•ˆ ์ƒํƒœ ์ข…ํ•ฉ ๊ด€๋ฆฌ ๋Œ€์‹œ๋ณด๋“œ โŒ CloudTrail, GuardDuty ๋“ฑ์—์„œ ๋ฐ›์€ ๋ฐ์ดํ„ฐ๋ฅผ ์ข…ํ•ฉ ๋ถ„์„
D. Amazon Inspector ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ทจ์•ฝ์  ๋ฐ ๋ณด์•ˆ ํ‰๊ฐ€ ์„œ๋น„์Šค โŒ API ํ™œ๋™ ์ถ”์  ๊ธฐ๋Šฅ ์—†์Œ

๐Ÿงฉ ์‹œ๊ฐ ์š”์•ฝ (Mermaid)

 
```mermaid
flowchart TD
    A["๐Ÿ‘ค IAM User / Role"] -->|API Call| B["๐Ÿง  AWS CloudTrail"]
    B --> C["๐Ÿ“ฆ S3 Log Storage"]
    B --> D["๐Ÿ” Event History Console"]
    D --> E["๐Ÿ‘๏ธ Identify who, when, and what action was taken"]
```
 

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿ•ต๏ธ‍โ™‚๏ธ AWS CloudTrail์€ “๋ˆ„๊ฐ€ ์–ธ์ œ ๋ฌด์—‡์„ ํ–ˆ๋Š”์ง€”๋ฅผ ๊ธฐ๋กํ•˜๋Š” ๊ฐ์‚ฌ ๋ฐ ๋ณด์•ˆ ์ถ”์  ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


์—ฌ๋Ÿฌ VPC ๋ฐ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ๋ฅผ ํšจ์œจ์ ์œผ๋กœ ์—ฐ๊ฒฐํ•˜๊ณ , ํ”ผ์–ด๋ง ๊ด€๊ณ„๋ฅผ ๋‹จ์ˆœํ™”ํ•˜๊ธฐ ์œ„ํ•œ AWS ๋„คํŠธ์›Œํฌ ์„œ๋น„์Šค๋ฅผ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q445.

Which AWS service can the company use as a cloud router to simplify peering relationships?

์—ฌ๋Ÿฌ VPC์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ๋ฅผ ์—ฐ๊ฒฐํ•˜๊ณ  ๋ผ์šฐํŒ…์„ ๋‹จ์ˆœํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” AWS ์„œ๋น„์Šค๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?


โœ… ์ •๋‹ต: B. AWS Transit Gateway


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น AWS Transit Gateway๋ž€?

AWS Transit Gateway๋Š” ์—ฌ๋Ÿฌ VPC, ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ, VPN ์—ฐ๊ฒฐ์„
ํ•˜๋‚˜์˜ ์ค‘์•™ ํ—ˆ๋ธŒ(Cloud Router) ๋ฅผ ํ†ตํ•ด ์—ฐ๊ฒฐํ•˜๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

๊ธฐ์กด์˜ VPC Peering(1:1 ์—ฐ๊ฒฐ) ์€ ๋ณต์žกํ•œ Full Mesh ๊ตฌ์กฐ๋ฅผ ๋งŒ๋“ค์–ด ๊ด€๋ฆฌ๊ฐ€ ์–ด๋ ค์› ์ง€๋งŒ,
Transit Gateway๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ชจ๋“  ๋„คํŠธ์›Œํฌ๊ฐ€ ํ•˜๋‚˜์˜ ํ—ˆ๋ธŒ๋ฅผ ํ†ตํ•ด ๊ฐ„๋‹จํžˆ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


โœ… ์ฃผ์š” ํŠน์ง•

๊ธฐ๋Šฅ ์„ค๋ช…
๐ŸŒ ์ค‘์•™ ๋ผ์šฐํŒ… ํ—ˆ๋ธŒ ์—ญํ•  ์—ฌ๋Ÿฌ VPC, Direct Connect, VPN์„ ํ•˜๋‚˜์˜ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์—ฐ๊ฒฐ
๐Ÿ” Full Mesh ๋‹จ์ˆœํ™” VPC ๊ฐ„ ๊ฐœ๋ณ„ ํ”ผ์–ด๋ง(Peering) ์„ค์ • ์—†์ด ์ค‘์•™์—์„œ ๊ด€๋ฆฌ
๐Ÿงญ ๋ผ์šฐํŒ… ์ •์ฑ… ํ†ตํ•ฉ ๊ด€๋ฆฌ ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์„ ์ค‘์•™์—์„œ ์ œ์–ด ๊ฐ€๋Šฅ
๐Ÿ”’ ๋ณด์•ˆ ์ œ์–ด ๋ฐ ๋ถ„๋ฆฌ ๊ฐ€๋Šฅ ๋ถ€์„œ๋ณ„/ํ™˜๊ฒฝ๋ณ„ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ” ๋ถ„๋ฆฌ ์šด์˜ ๊ฐ€๋Šฅ
๐Ÿš€ ํ™•์žฅ์„ฑ(Scalability) ์ˆ˜์ฒœ ๊ฐœ์˜ VPC๋ฅผ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅ (AWS Network Manager ํ†ตํ•ฉ ์ง€์›)

๐Ÿงฉ ๊ตฌ์กฐ ์˜ˆ์‹œ

๊ธฐ์กด์˜ VPC Peering ๋ฐฉ์‹์€ ๋ณต์žกํ•œ N² ๊ตฌ์กฐ๋ฅผ ๊ฐ€์ง€์ง€๋งŒ,
Transit Gateway๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์ค‘์•™ ํ—ˆ๋ธŒ ํ˜•ํƒœ๋กœ ๊ฐ„๊ฒฐํ•˜๊ฒŒ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค.

 

๐Ÿ“ฆ ์‹œ๋‚˜๋ฆฌ์˜ค ์˜ˆ์‹œ

ํšŒ์‚ฌ๊ฐ€ ์—ฌ๋Ÿฌ ๋ถ€์„œ(VPC)๋ฅผ ์šด์˜ํ•˜๋ฉฐ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฐ์ดํ„ฐ์„ผํ„ฐ์™€ ์—ฐ๊ฒฐํ•  ๋•Œ,

  • Before (VPC Peering)
    • VPC ๊ฐ„ ๊ฐœ๋ณ„ Peering (A↔B, B↔C, A↔C...)
    • ๊ด€๋ฆฌ ๋ณต์žก๋„ ↑
  • After (Transit Gateway)
    • ๋ชจ๋“  VPC๊ฐ€ Transit Gateway์— ์—ฐ๊ฒฐ
    • ๋ผ์šฐํŒ… ์ค‘์•™ ๊ด€๋ฆฌ, ํŠธ๋ž˜ํ”ฝ ์ œ์–ด ๋‹จ์ˆœํ™” โœ…

โŒ ์˜ค๋‹ต ํ•ด์„ค 

๊ธฐ๋Šฅ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. AWS Direct Connect ์˜จํ”„๋ ˆ๋ฏธ์Šค ↔ AWS ๊ฐ„ ์ „์šฉ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ โŒ ํ”ผ์–ด๋ง ๋‹จ์ˆœํ™” ๊ธฐ๋Šฅ ์—†์Œ
C. Amazon Connect ๊ณ ๊ฐ์„ผํ„ฐ์šฉ ํด๋ผ์šฐ๋“œ ์ฝœ์„ผํ„ฐ ์„œ๋น„์Šค โŒ ๋„คํŠธ์›Œํฌ์™€ ๋ฌด๊ด€
D. Amazon Route 53 DNS ๊ด€๋ฆฌ ๋ฐ ๋„๋ฉ”์ธ ๋ผ์šฐํŒ… ์„œ๋น„์Šค โŒ ๋„คํŠธ์›Œํฌ ํ”ผ์–ด๋ง์ด๋‚˜ ๋ผ์šฐํŒ… ํ—ˆ๋ธŒ ๊ธฐ๋Šฅ ์—†์Œ

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿ”„ ์—ฌ๋Ÿฌ VPC์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ๋ฅผ ํ•˜๋‚˜์˜ ์ค‘์•™ ํ—ˆ๋ธŒ๋กœ ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด AWS Transit Gateway๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค — “Cloud Router” ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.


์˜จํ”„๋ ˆ๋ฏธ์Šค ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์ €์ง€์—ฐ(๋กœ์šฐ ๋ ˆ์ดํ„ด์‹œ) ์ ‘๊ทผ๊ณผ ๋ฐ์ดํ„ฐ ์ƒ์ฃผ(Data Residency) ์š”๊ตฌ์‚ฌํ•ญ์„ ๋™์‹œ์— ์ถฉ์กฑํ•ด์•ผ ํ•˜๋Š” ์ƒํ™ฉ์„ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q459.

Which AWS service should the company use to design a solution that meets these requirements?

“๋กœ์šฐ ๋ ˆ์ดํ„ด์‹œ(์ €์ง€์—ฐ) + ๋ฐ์ดํ„ฐ ์ƒ์ฃผ(๋ฐ์ดํ„ฐ๊ฐ€ ํšŒ์‚ฌ ๋‚ด์— ๋จธ๋ฌด๋ฅผ ๊ฒƒ)”
๐Ÿ‘‰ ์–ด๋–ค AWS ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: D. AWS Outposts


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น AWS Outposts๋ž€?

AWS Outposts๋Š” AWS ์ธํ”„๋ผ, ์„œ๋น„์Šค, API, ํˆด์„
๊ณ ๊ฐ์˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ฐ์ดํ„ฐ์„ผํ„ฐ ๋˜๋Š” ๋กœ์ปฌ ํ™˜๊ฒฝ์— ๋ฌผ๋ฆฌ์ ์œผ๋กœ ์„ค์น˜ํ•˜์—ฌ
AWS ํด๋ผ์šฐ๋“œ์™€ ๋™์ผํ•œ ๊ฒฝํ—˜์„ ์ œ๊ณตํ•˜๋Š” ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํด๋ผ์šฐ๋“œ ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค.

์ฆ‰,

“์˜จํ”„๋ ˆ๋ฏธ์Šค์—์„œ AWS๋ฅผ ๊ทธ๋Œ€๋กœ ์‚ฌ์šฉํ•˜๋Š” ์„œ๋น„์Šค” ์ž…๋‹ˆ๋‹ค.


โœ… Outposts์˜ ์ฃผ์š” ํŠน์ง•

ํ•ญ๋ชฉ ์„ค๋ช…
โš™๏ธ ์˜จํ”„๋ ˆ๋ฏธ์Šค ์„ค์น˜ํ˜• AWS ์ธํ”„๋ผ AWS์—์„œ ์ œ๊ณตํ•˜๋Š” ํ•˜๋“œ์›จ์–ด ๋ž™์„ ๊ณ ๊ฐ ๋ฐ์ดํ„ฐ์„ผํ„ฐ์— ์ง์ ‘ ์„ค์น˜
๐Ÿ” AWS์™€ ์™„์ „ ํ†ตํ•ฉ EC2, EBS, ECS, EKS, RDS ๋“ฑ AWS ๋ฆฌ์†Œ์Šค๋ฅผ ๋กœ์ปฌ์—์„œ ์‹คํ–‰
โšก ๋กœ์šฐ ๋ ˆ์ดํ„ด์‹œ(Local Processing) AWS ๋ฆฌ์ „์„ ๊ฑฐ์น˜์ง€ ์•Š๊ณ  ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋‚ด๋ถ€์—์„œ ์š”์ฒญ ์ฒ˜๋ฆฌ
๐Ÿงญ ๋ฐ์ดํ„ฐ ์ƒ์ฃผ(Residency) ๋ฐ์ดํ„ฐ๊ฐ€ ๋ฌผ๋ฆฌ์ ์œผ๋กœ ๊ณ ๊ฐ ํ™˜๊ฒฝ์— ์ €์žฅ๋จ (๊ทœ์ œ ๋ฐ ๋ณด์•ˆ ์š”๊ตฌ ์ถฉ์กฑ)
โ˜๏ธ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์•„ํ‚คํ…์ฒ˜ ๊ตฌ์„ฑ ๊ฐ€๋Šฅ Outposts ↔ AWS ๋ฆฌ์ „ ๊ฐ„ ๋„คํŠธ์›Œํ‚น ๋ฐ ๋ฐฑ์—… ์—ฐ๋™ ๊ฐ€๋Šฅ

๐Ÿ“ฆ ์•„ํ‚คํ…์ฒ˜ ์˜ˆ์‹œ

 

๐Ÿ“ ๊ฒฐ๊ณผ:

  • ๋ฐ์ดํ„ฐ๋Š” ํšŒ์‚ฌ ๋‚ด(On-prem)์— ์ƒ์ฃผ
  • AWS API, ๊ด€๋ฆฌ ์ฝ˜์†”, ์„œ๋น„์Šค๋Š” ๊ทธ๋Œ€๋กœ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
  • ๋กœ์ปฌ ์ฒ˜๋ฆฌ๋กœ ์งง์€ ์ง€์—ฐ์‹œ๊ฐ„ ๋ณด์žฅ

๐Ÿง  ์‚ฌ์šฉ ์‚ฌ๋ก€

์‹œ๋‚˜๋ฆฌ์˜ค Outposts ์‚ฌ์šฉ ์ด์œ 
๐Ÿญ ์ œ์กฐ/๊ธˆ์œต/๊ณต๊ณต๊ธฐ๊ด€ ๋ฐ์ดํ„ฐ๊ฐ€ ๋ฌผ๋ฆฌ์ ์œผ๋กœ ํšŒ์‚ฌ ๋‚ด๋ถ€์— ์žˆ์–ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ (๋ณด์•ˆ/๊ทœ์ œ)
โšก ์‹ค์‹œ๊ฐ„ ์‚ฐ์—… ์ œ์–ด ์‹œ์Šคํ…œ ๋ฐ€๋ฆฌ์ดˆ(ms) ๋‹จ์œ„์˜ ์ €์ง€์—ฐ ์ฒ˜๋ฆฌ๊ฐ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ
๐Ÿฅ ํ—ฌ์Šค์ผ€์–ด ๋ฐ์ดํ„ฐ ์ €์žฅ ๋ฐ์ดํ„ฐ ์ƒ์ฃผ๋ฒ•(Data Residency Compliance) ์ค€์ˆ˜ ํ•„์š” ์‹œ
๐ŸŒฉ๏ธ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๋ฐฐํฌ ์ผ๋ถ€ ์›Œํฌ๋กœ๋“œ๋Š” ํด๋ผ์šฐ๋“œ, ์ผ๋ถ€๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค์— ์œ ์ง€

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. AWS Wavelength 5G ์—ฃ์ง€ ์ปดํ“จํŒ…์šฉ ์ธํ”„๋ผ (ํ†ต์‹ ์‚ฌ ๋„คํŠธ์›Œํฌ ๋‚ด ๋ฐฐ์น˜) โŒ ์ด๋™ํ†ต์‹  ์—ฃ์ง€์šฉ, ๋ฐ์ดํ„ฐ ์ƒ์ฃผ ์š”๊ฑด๊ณผ ๋ฌด๊ด€
B. AWS Transit Gateway ์—ฌ๋Ÿฌ VPC ๋ฐ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ๋ฅผ ์—ฐ๊ฒฐ โŒ ๋„คํŠธ์›Œํฌ ๋ผ์šฐํŒ… ์šฉ๋„์ด์ง€ ๋กœ์šฐ ๋ ˆ์ดํ„ด์‹œ ์ฒ˜๋ฆฌ ๋ถˆ๊ฐ€
C. AWS Ground Station ์œ„์„ฑ ๋ฐ์ดํ„ฐ ์†ก์ˆ˜์‹  ์„œ๋น„์Šค โŒ ์˜จํ”„๋ ˆ๋ฏธ์Šค์™€ ๋ฌด๊ด€, ์œ„์„ฑ ํ†ต์‹ ์šฉ ์„œ๋น„์Šค

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿงฉ AWS Outposts = AWS ์ธํ”„๋ผ๋ฅผ ์˜จํ”„๋ ˆ๋ฏธ์Šค์— ์ง์ ‘ ์„ค์น˜ํ•˜์—ฌ
์ €์ง€์—ฐ ์ฒ˜๋ฆฌ์™€ ๋ฐ์ดํ„ฐ ์ƒ์ฃผ ๊ทœ์ œ ์ค€์ˆ˜๋ฅผ ๋™์‹œ์— ๋งŒ์กฑ์‹œํ‚ค๋Š” ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํด๋ผ์šฐ๋“œ ์†”๋ฃจ์…˜.


Amazon CloudFront์— ์œ ์ž…๋˜๋Š” ์•…์„ฑ HTTP/HTTPS ์š”์ฒญ์„ ๊ฐ์‹œํ•˜๊ณ  ์ฐจ๋‹จํ•˜๋Š” ์„œ๋น„์Šค๋ฅผ ๋ฌป๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.

๐Ÿ“˜ Q468.

Which AWS service should the company use to monitor and block malicious HTTP and HTTPS requests that its Amazon CloudFront distributions receive?

CloudFront๋กœ ๋“ค์–ด์˜ค๋Š” ์•…์„ฑ ์š”์ฒญ(HTTP/HTTPS)์„ ํƒ์ง€ํ•˜๊ณ  ์ฐจ๋‹จํ•˜๊ธฐ ์œ„ํ•ด ์–ด๋–ค ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: C. AWS WAF (Web Application Firewall)


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น AWS WAF๋ž€?

AWS WAF(Web Application Firewall) ๋Š”
์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต(Layer 7) ์˜ ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ
HTTP ๋ฐ HTTPS ํŠธ๋ž˜ํ”ฝ์„ ํ•„ํ„ฐ๋ง, ๋ชจ๋‹ˆํ„ฐ๋ง, ์ฐจ๋‹จํ•˜๋Š” ๋ณด์•ˆ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


โœ… ์ฃผ์š” ๊ธฐ๋Šฅ ์š”์•ฝ

๊ธฐ๋Šฅ ์„ค๋ช…
๐Ÿ›ก๏ธ ์š”์ฒญ ํ•„ํ„ฐ๋ง (Request Filtering) IP ์ฃผ์†Œ, HTTP ํ—ค๋”, URI ๊ฒฝ๋กœ, ์ฟผ๋ฆฌ ๋ฌธ์ž์—ด ๋“ฑ์„ ๊ธฐ์ค€์œผ๋กœ ํŠธ๋ž˜ํ”ฝ ์ œ์–ด
๐Ÿšซ ๊ณต๊ฒฉ ์ฐจ๋‹จ (Attack Protection) SQL Injection, XSS, HTTP Flood, Bot ๋“ฑ ์›น ๊ธฐ๋ฐ˜ ๊ณต๊ฒฉ ๋ฐฉ์–ด
๐ŸŒ CloudFront / ALB / API Gateway ํ†ตํ•ฉ CloudFront ๋ฐฐํฌ, ALB, API Gateway, AppSync์™€ ํ†ตํ•ฉ ๊ฐ€๋Šฅ
๐Ÿ“Š ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง CloudWatch Metrics ๋ฐ AWS WAF Console์—์„œ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„
๐Ÿ”„ Managed Rules ์ง€์› AWS ๋ฐ ๋ณด์•ˆ ํŒŒํŠธ๋„ˆ๊ฐ€ ์ œ๊ณตํ•˜๋Š” ์‚ฌ์ „ ์ •์˜๋œ ๋ณด์•ˆ ๋ฃฐ ์„ธํŠธ ์‚ฌ์šฉ ๊ฐ€๋Šฅ

โš™๏ธ ๊ตฌ์„ฑ ์˜ˆ์‹œ


๐Ÿง  ์‹œ๋‚˜๋ฆฌ์˜ค ์˜ˆ์‹œ

ํ•œ ํšŒ์‚ฌ์˜ ์›น์‚ฌ์ดํŠธ๊ฐ€ DDoS๋‚˜ SQL Injection ๊ณต๊ฒฉ์„ ๋ฐ›๋Š”๋‹ค๋ฉด?

  • CloudFront์— AWS WAF๋ฅผ ์—ฐ๊ฒฐํ•˜๋ฉด,
    ๊ณต๊ฒฉ ํŠธ๋ž˜ํ”ฝ์€ ์—ฃ์ง€ ๋กœ์ผ€์ด์…˜(Edge Location) ๋‹จ๊ณ„์—์„œ ์ฆ‰์‹œ ์ฐจ๋‹จ๋จ.
  • AWS Shield์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜๋ฉด DDoS ๋ฐฉ์–ด๋„ ๊ฐ•ํ™” ๊ฐ€๋Šฅ.

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Amazon GuardDuty AWS ๊ณ„์ • ๋ฐ ๋„คํŠธ์›Œํฌ ํ™œ๋™์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์œ„ํ˜‘ ํƒ์ง€ (ML ๊ธฐ๋ฐ˜ ์ด์ƒ์ง•ํ›„ ํƒ์ง€) โŒ ๋„คํŠธ์›Œํฌ ์ „์ฒด ๋ณด์•ˆ ๊ฐ์‹œ์šฉ, HTTP ์š”์ฒญ ๋‹จ์œ„ ์ฐจ๋‹จ ๋ถˆ๊ฐ€
B. Amazon Inspector EC2, ECR์˜ ์ทจ์•ฝ์ (Vulnerability) ์Šค์บ” ์„œ๋น„์Šค โŒ ํŠธ๋ž˜ํ”ฝ ํ•„ํ„ฐ๋ง ๊ธฐ๋Šฅ ์—†์Œ
D. Amazon Detective GuardDuty๋‚˜ CloudTrail ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•˜์—ฌ ์›์ธ ํŒŒ์•… โŒ ์‚ฌํ›„ ๋ถ„์„์šฉ, ์‹ค์‹œ๊ฐ„ ์ฐจ๋‹จ ๋ถˆ๊ฐ€

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿงฉ AWS WAF๋Š” CloudFront, ALB, API Gateway์— ์—ฐ๊ฒฐ๋˜์–ด
์•…์„ฑ HTTP/HTTPS ์š”์ฒญ์„ ํƒ์ง€·์ฐจ๋‹จํ•˜๋Š” ์›น ๋ฐฉํ™”๋ฒฝ(Web Application Firewall) ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


“์™ธ๋ถ€ ID ๊ณต๊ธ‰์ž(IdP)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ํšŒ์‚ฌ๊ฐ€, ๋ณ„๋„์˜ ์ž๊ฒฉ ์ฆ๋ช… ์—†์ด AWS์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ์„œ๋น„์Šค”๋ฅผ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q477.

A company uses a third-party identity provider (IdP).
Which AWS service will meet this requirement?

ํšŒ์‚ฌ์—์„œ ์™ธ๋ถ€ IdP(์˜ˆ: Azure AD, Okta, Google Workspace ๋“ฑ)๋ฅผ ์‚ฌ์šฉ ์ค‘์ด๋ฉฐ,
์ง์›๋“ค์ด ๋ณ„๋„์˜ ๋กœ๊ทธ์ธ ์ž๊ฒฉ ์ฆ๋ช… ์—†์ด AWS ๋ฆฌ์†Œ์Šค์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.


โœ… ์ •๋‹ต: B. Amazon Cognito


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Amazon Cognito๋ž€?

Amazon Cognito๋Š” ์‚ฌ์šฉ์ž ์ธ์ฆ(Authentication), ๊ถŒํ•œ ๋ถ€์—ฌ(Authorization),
๊ทธ๋ฆฌ๊ณ  ์‚ฌ์šฉ์ž ๊ด€๋ฆฌ(User Management)๋ฅผ ์ œ๊ณตํ•˜๋Š” ID ๊ด€๋ฆฌ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

ํŠนํžˆ,

  • ์™ธ๋ถ€ IdP(Identity Provider) ์™€์˜ ํ†ตํ•ฉ ์ธ์ฆ (Federation) ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๋ฏ€๋กœ,
  • ์‚ฌ์šฉ์ž๋Š” ๊ธฐ์กด ํšŒ์‚ฌ ๊ณ„์ • (์˜ˆ: Google, SAML, Azure AD) ์œผ๋กœ ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฆ‰,

“AWS ๋ฆฌ์†Œ์Šค ์ ‘๊ทผ ์‹œ ์ƒˆ๋กœ์šด ๋กœ๊ทธ์ธ ์ •๋ณด ์—†์ด ๊ธฐ์กด ๊ณ„์ •์œผ๋กœ ์ธ์ฆํ•  ์ˆ˜ ์žˆ๋‹ค”
๐Ÿ‘‰ ๋ฐ”๋กœ Cognito Federated Identity ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.


โœ… Cognito์˜ ๋‘ ๊ฐ€์ง€ ์ฃผ์š” ๊ตฌ์„ฑ์š”์†Œ

๊ตฌ์„ฑ ์š”์†Œ ์„ค๋ช…
User Pool ์‚ฌ์šฉ์ž์˜ ๋“ฑ๋ก, ๋กœ๊ทธ์ธ, ์ธ์ฆ์„ ์ฒ˜๋ฆฌํ•˜๋Š” ์‚ฌ์šฉ์ž ๋””๋ ‰ํ„ฐ๋ฆฌ
Identity Pool (Federated Identities) ์™ธ๋ถ€ IdP(Azure AD, SAML, Google ๋“ฑ)๋ฅผ ์—ฐ๊ฒฐํ•˜์—ฌ AWS ์ž๊ฒฉ ์ฆ๋ช… ๋ฐœ๊ธ‰

โš™๏ธ ์ธ์ฆ ํ๋ฆ„ ์˜ˆ์‹œ

์š”์•ฝ:
์™ธ๋ถ€ IdP → Cognito → AWS STS → AWS ๋ฆฌ์†Œ์Šค ์ ‘๊ทผ


๐Ÿง  ์‹œ๋‚˜๋ฆฌ์˜ค ์˜ˆ์‹œ

ํšŒ์‚ฌ๊ฐ€ Google Workspace ๋ฅผ ์‚ฌ์šฉ ์ค‘์ด๋ผ๋ฉด,
Cognito๋ฅผ ํ†ตํ•ด Google ๊ณ„์ •์œผ๋กœ AWS ์„œ๋น„์Šค ๋กœ๊ทธ์ธ ๊ฐ€๋Šฅ.
→ ๋ณ„๋„์˜ IAM ์œ ์ € ์ƒ์„ฑ ๋ถˆํ•„์š”
→ ๊ธฐ์กด ID ๊ด€๋ฆฌ ์ฒด๊ณ„๋ฅผ ๊ทธ๋Œ€๋กœ ์œ ์ง€


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. AWS Directory Service Active Directory(AD) ๊ธฐ๋ฐ˜ ์ธ์ฆ ์„œ๋น„์Šค โŒ ์ž์ฒด AD ํ†ตํ•ฉ์šฉ, ์™ธ๋ถ€ IdP ์—ฐ๋™ ๋ชฉ์ ๊ณผ ๋‹ค๋ฆ„
C. AWS IAM Identity Center (SSO) AWS ๊ณ„์ • ๊ฐ„ SSO ๋ฐ IdP ์—ฐ๋™ ์ง€์› โš ๏ธ ์‚ฌ์‹ค์ƒ ์ด ์„œ๋น„์Šค๋„ ๊ฐ€๋Šฅํ•˜์ง€๋งŒ, ๋ฌธ์ œ์—์„œ๋Š” ์ง์›์šฉ ๋กœ๊ทธ์ธ ๋ฐ ์™ธ๋ถ€ IdP ํ†ตํ•ฉ → Cognito๊ฐ€ ํ•ต์‹ฌ
D. AWS Resource Access Manager (RAM) AWS ๋ฆฌ์†Œ์Šค ๊ณต์œ  ์„œ๋น„์Šค โŒ ์ธ์ฆ ๊ด€๋ จ ์•„๋‹˜

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿ” Amazon Cognito๋Š” ์™ธ๋ถ€ IdP(Azure AD, Google, Okta ๋“ฑ)์™€ ์—ฐ๋™ํ•˜์—ฌ
๋ณ„๋„์˜ AWS ์ž๊ฒฉ ์ฆ๋ช… ์—†์ด ๊ธฐ์กด ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ด์ฃผ๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


“๋ฐ˜๋ณต ๊ฐ€๋Šฅํ•˜๊ณ  ์ผ๊ด€๋œ ์ธํ”„๋ผ ๊ตฌ์„ฑ(Highly Repeatable Infrastructure Configurations)”์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋Š” AWS ์„œ๋น„์Šค๋ฅผ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q487.

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

๋ฐ˜๋ณต์ ์ด๊ณ  ์˜ˆ์ธก ๊ฐ€๋Šฅํ•œ ๋ฐฉ์‹์œผ๋กœ ์ธํ”„๋ผ๋ฅผ ๋ฐฐํฌํ•˜๋ ค๋ฉด ์–ด๋–ค AWS ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: A. AWS CloudFormation


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น AWS CloudFormation์ด๋ž€?

AWS CloudFormation์€ ์ธํ”„๋ผ๋ฅผ ์ฝ”๋“œ๋กœ ๊ด€๋ฆฌ (IaC, Infrastructure as Code) ํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.
์ฆ‰, YAML ๋˜๋Š” JSON ํ…œํ”Œ๋ฆฟ์„ ํ†ตํ•ด AWS ๋ฆฌ์†Œ์Šค๋ฅผ ๋ฐ˜๋ณต์ ์ด๊ณ  ์ผ๊ด€๋˜๊ฒŒ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


โœ… ํ•ต์‹ฌ ๊ฐœ๋…

๊ฐœ๋… ์„ค๋ช…
๐Ÿ“„ ํ…œํ”Œ๋ฆฟ(Template) EC2, VPC, S3, RDS ๋“ฑ ๋ฆฌ์†Œ์Šค ์ •์˜๋ฅผ ์ฝ”๋“œ๋กœ ๊ธฐ์ˆ 
๐Ÿงฑ ์Šคํƒ(Stack) ํ…œํ”Œ๋ฆฟ์„ ์‹คํ–‰ํ•ด ์‹ค์ œ๋กœ ์ƒ์„ฑ๋œ ๋ฆฌ์†Œ์Šค ๋ฌถ์Œ
๐Ÿ” ๋ฐ˜๋ณต ๊ฐ€๋Šฅ์„ฑ(Repeatability) ๋™์ผํ•œ ํ…œํ”Œ๋ฆฟ์œผ๋กœ ์—ฌ๋Ÿฌ ํ™˜๊ฒฝ(Dev/Test/Prod)์„ ์ผ๊ด€๋˜๊ฒŒ ๋ฐฐํฌ ๊ฐ€๋Šฅ
๐Ÿ’ฅ ์ž๋™ ๋กค๋ฐฑ ๋ฐฐํฌ ์‹คํŒจ ์‹œ ์ด์ „ ์ƒํƒœ๋กœ ์ž๋™ ๋ณต๊ตฌ
๐Ÿ” ๋ฒ„์ „ ๊ด€๋ฆฌ ๋ฐ ํ˜‘์—… ๊ฐ€๋Šฅ GitHub ๋“ฑ๊ณผ ์—ฐ๋™ํ•˜์—ฌ IaC ํŒŒ์ดํ”„๋ผ์ธ ๊ตฌ์ถ• ๊ฐ€๋Šฅ

โš™๏ธ ์˜ˆ์‹œ (CloudFormation ํ…œํ”Œ๋ฆฟ - YAML)

 
AWSTemplateFormatVersion: '2010-09-09'
Description: Simple EC2 instance template

Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      InstanceType: t3.micro
      ImageId: ami-0abcdef1234567890
      Tags:
        - Key: Name
          Value: MyCFNInstance

โžก๏ธ ์œ„ ํ…œํ”Œ๋ฆฟ์„ ์‹คํ–‰ํ•˜๋ฉด ๋™์ผํ•œ EC2 ์ธ์Šคํ„ด์Šค๋ฅผ ์—ฌ๋Ÿฌ ๋ฒˆ ๋ฐ˜๋ณต์ ์œผ๋กœ ๋ฐฐํฌ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.


๐Ÿง  ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

๊ฐœ๋ฐœํŒ€, ํ…Œ์ŠคํŠธํŒ€, ์šด์˜ํŒ€์ด ๋™์ผํ•œ ์•„ํ‚คํ…์ฒ˜๋ฅผ ๊ฐ๊ฐ์˜ ํ™˜๊ฒฝ์— ๊ตฌ์ถ•ํ•ด์•ผ ํ•  ๋•Œ
CloudFormation ํ…œํ”Œ๋ฆฟ ํ•˜๋‚˜๋กœ Dev/Test/Prod ํ™˜๊ฒฝ์„ ์‰ฝ๊ฒŒ ๋ณต์ œ ๊ฐ€๋Šฅ


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
B. AWS CodeDeploy ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฐํฌ ์ž๋™ํ™” ์„œ๋น„์Šค โŒ ์ธํ”„๋ผ ๊ตฌ์„ฑ ๊ด€๋ฆฌ๊ฐ€ ์•„๋‹Œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฐํฌ ๋ชฉ์ 
C. AWS CodeBuild ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋นŒ๋“œ ๋ฐ ํ…Œ์ŠคํŠธ ์ž๋™ํ™” ์„œ๋น„์Šค โŒ CI/CD ๋นŒ๋“œ ํŒŒ์ดํ”„๋ผ์ธ ์šฉ๋„
D. AWS Systems Manager EC2 ๋ฐ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํ™˜๊ฒฝ ๊ด€๋ฆฌ ์„œ๋น„์Šค โŒ ์ธํ”„๋ผ ์ƒ์„ฑ/๋ฐฐํฌ๊ฐ€ ์•„๋‹Œ ์šด์˜ ๊ด€๋ฆฌ ๋ชฉ์ 

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿงฉ AWS CloudFormation์€ ์ธํ”„๋ผ๋ฅผ ์ฝ”๋“œ(YAML/JSON)๋กœ ์ •์˜ํ•˜์—ฌ
๋ฐ˜๋ณต์ ์ด๊ณ  ์ž๋™ํ™”๋œ ๋ฐฉ์‹์œผ๋กœ AWS ๋ฆฌ์†Œ์Šค๋ฅผ ์ผ๊ด€๋˜๊ฒŒ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.


์Œ์„ฑ ํ†ตํ™”(Voice Calls) ๋ฐ ์›น ์ฑ„ํŒ…(Web Chat) ๊ธฐ๋Šฅ์„ ํ™œ์šฉํ•œ ๊ณ ๊ฐ ์„œ๋น„์Šค ์ œ๊ณต์— ์ ํ•ฉํ•œ AWS ์„œ๋น„์Šค๋ฅผ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q488.

A company needs to provide customer service by using voice calls and web chat features.
Which AWS service should the company use to meet these requirements?

์Œ์„ฑ ํ†ตํ™” ๋ฐ ์›น ์ฑ„ํŒ… ๊ธฐ๋Šฅ์œผ๋กœ ๊ณ ๊ฐ ์ƒ๋‹ด ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
์–ด๋–ค AWS ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: B. Amazon Connect


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Amazon Connect๋ž€?

Amazon Connect๋Š” ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ปจํƒ ์„ผํ„ฐ(Contact Center) ์„œ๋น„์Šค๋กœ,
์Œ์„ฑ ํ†ตํ™”, ์ฑ„ํŒ…, ์ƒ๋‹ด ์›Œํฌํ”Œ๋กœ์šฐ๋ฅผ ์†์‰ฝ๊ฒŒ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ๋Š” AWS ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

์ฆ‰, ๊ณ ๊ฐ์ด ์ „ํ™”๋‚˜ ์ฑ„ํŒ…์œผ๋กœ ๋ฌธ์˜ํ•  ๋•Œ ์ƒ๋‹ด์›๊ณผ ์—ฐ๊ฒฐํ•ด์ฃผ๋Š”
์ฝœ์„ผํ„ฐ ์†”๋ฃจ์…˜์„ AWS์—์„œ ์™„์ „๊ด€๋ฆฌํ˜•(fully managed) ํ˜•ํƒœ๋กœ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.


โœ… Amazon Connect์˜ ์ฃผ์š” ํŠน์ง•

๊ธฐ๋Šฅ ์„ค๋ช…
โ˜Ž๏ธ ์Œ์„ฑ ํ†ตํ™” (Voice Calls) ๊ณ ๊ฐ์ด ์›น์‚ฌ์ดํŠธ๋‚˜ ์•ฑ์„ ํ†ตํ•ด ์ƒ๋‹ด์›๊ณผ ์ง์ ‘ ํ†ตํ™” ๊ฐ€๋Šฅ
๐Ÿ’ฌ ์›น ์ฑ„ํŒ… (Web Chat) ์‹ค์‹œ๊ฐ„ ์›น ์ฑ„ํŒ… ๊ธฐ๋Šฅ์œผ๋กœ ๊ณ ๊ฐ ๋ฌธ์˜ ๋Œ€์‘ ๊ฐ€๋Šฅ
๐Ÿค– Amazon Lex ์—ฐ๋™ AI ์ฑ—๋ด‡์„ ํ†ตํ•œ ์ž๋™ํ™”๋œ ๊ณ ๊ฐ ์‘๋‹ต ์ง€์›
๐Ÿ“ž ์ปจํƒ ๋ฃจํŒ…(Contact Routing) ๊ณ ๊ฐ์˜ ์š”์ฒญ ์œ ํ˜•, ์šฐ์„ ์ˆœ์œ„, ์ƒ๋‹ด์› ์Šคํ‚ฌ ๊ธฐ๋ฐ˜ ์ž๋™ ์—ฐ๊ฒฐ
๐Ÿ“Š ๋ถ„์„ ๊ธฐ๋Šฅ Amazon Kinesis, QuickSight ๋“ฑ๊ณผ ์—ฐ๋™ํ•˜์—ฌ ์ƒ๋‹ด ๋ฐ์ดํ„ฐ ๋ถ„์„ ๊ฐ€๋Šฅ
๐Ÿง  AI/ML ๊ธฐ๋ฐ˜ ์ธ์‚ฌ์ดํŠธ Amazon Transcribe, Comprehend์™€ ์—ฐ๋™ํ•˜์—ฌ ๊ฐ์ • ๋ถ„์„ ๋ฐ ๋Œ€ํ™” ์š”์•ฝ ๊ฐ€๋Šฅ

โš™๏ธ ์˜ˆ์‹œ ์•„ํ‚คํ…์ฒ˜

 

๐Ÿง  ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

์˜ˆ๋ฅผ ๋“ค์–ด, ์˜จ๋ผ์ธ ์‡ผํ•‘๋ชฐ์—์„œ ๊ณ ๊ฐ์ด
“๋ฐฐ์†ก์ด ์ง€์—ฐ๋˜์—ˆ์–ด์š”” ๋ผ๊ณ  ์ฑ„ํŒ…ํ•˜๊ฑฐ๋‚˜ ์ „ํ™”๋ฅผ ๊ฑธ๋ฉด,
Amazon Connect๊ฐ€ Amazon Lex๋ฅผ ํ†ตํ•ด ์ž๋™ ์‘๋‹ต ํ›„,
ํ•„์š” ์‹œ ์ƒ๋‹ด์›์—๊ฒŒ ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Amazon Aurora ๊ณ ์„ฑ๋Šฅ ๊ด€๊ณ„ํ˜• ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์„œ๋น„์Šค โŒ ๊ณ ๊ฐ ์ƒ๋‹ด ๊ธฐ๋Šฅ๊ณผ ๊ด€๋ จ ์—†์Œ
C. Amazon WorkSpaces ๊ฐ€์ƒ ๋ฐ์Šคํฌํ†ฑ ์„œ๋น„์Šค โŒ ๋‚ด๋ถ€ ์ง์›์šฉ ์›๊ฒฉ ๊ทผ๋ฌด ํ™˜๊ฒฝ ์ œ๊ณต์šฉ
D. AWS Organizations ๋‹ค์ค‘ ๊ณ„์ • ๊ด€๋ฆฌ ์„œ๋น„์Šค โŒ ๊ณ ๊ฐ ์„œ๋น„์Šค ๊ธฐ๋Šฅ๊ณผ ๋ฌด๊ด€

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐ŸŽง Amazon Connect๋Š” AWS์˜ ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ์ปจํƒ ์„ผํ„ฐ(Contact Center) ์„œ๋น„์Šค๋กœ,
์Œ์„ฑ ํ†ตํ™”·์›น ์ฑ„ํŒ…·AI ์ฑ—๋ด‡ ํ†ตํ•ฉ ๊ธฐ๋Šฅ์„ ํ†ตํ•ด
๊ณ ๊ฐ ์ง€์›(Customer Service) ์„ ์‰ฝ๊ณ  ๋น ๋ฅด๊ฒŒ ๊ตฌ์ถ•ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


VPC ๋‚ด์—์„œ ์„œ๋ธŒ๋„ท(subnet) ์ˆ˜์ค€์˜ ๋ฐฉํ™”๋ฒฝ ์—ญํ• ์„ ํ•˜๋Š” ๊ธฐ๋Šฅ์„ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q493.

Which AWS tool or feature acts as a VPC firewall at the subnet level?
์„œ๋ธŒ๋„ท ์ˆ˜์ค€์—์„œ VPC ๋ฐฉํ™”๋ฒฝ ์—ญํ• ์„ ํ•˜๋Š” AWS ๋„๊ตฌ ๋˜๋Š” ๊ธฐ๋Šฅ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?


โœ… ์ •๋‹ต: B. Network ACL


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Network ACL (NACL, Network Access Control List)

Network ACL์€ ์„œ๋ธŒ๋„ท(Subnet) ์ˆ˜์ค€์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ์ œ์–ดํ•˜๋Š” ๋ฐฉํ™”๋ฒฝ ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

  • VPC์˜ ๊ฐ ์„œ๋ธŒ๋„ท(Subnet) ์— ์ ์šฉ๋˜๋ฉฐ,
  • ๋“ค์–ด์˜ค๋Š”(Inbound) ๋ฐ ๋‚˜๊ฐ€๋Š”(Outbound) ํŠธ๋ž˜ํ”ฝ์„
    ํ—ˆ์šฉ(Allow) ๋˜๋Š” ๊ฑฐ๋ถ€(Deny) ๊ทœ์น™์œผ๋กœ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.

โœ… ์ฃผ์š” ํŠน์ง• ๋น„๊ต

ํ•ญ๋ชฉ Network ACL (NACL) Security Group (๋ณด์•ˆ ๊ทธ๋ฃน)
์ ์šฉ ์ˆ˜์ค€ ์„œ๋ธŒ๋„ท(Subnet) ์ˆ˜์ค€ ์ธ์Šคํ„ด์Šค(EC2) ์ˆ˜์ค€
์ƒํƒœ ์ €์žฅ ์—ฌ๋ถ€ โŒ ๋น„์ƒํƒœ ์ €์žฅ (Stateless) → Inbound/Outbound ๊ทœ์น™ ๋ชจ๋‘ ์„ค์ • ํ•„์š” โœ… ์ƒํƒœ ์ €์žฅ (Stateful) → ํ•œ์ชฝ๋งŒ ์„ค์ •ํ•ด๋„ ๋ฐ˜๋Œ€ ๋ฐฉํ–ฅ ์ž๋™ ํ—ˆ์šฉ
๊ทœ์น™ ํ‰๊ฐ€ ๋ฐฉ์‹ ๋ฒˆํ˜ธ ์ˆœ์„œ๋Œ€๋กœ(๋‚ฎ์€ ๋ฒˆํ˜ธ ์šฐ์„ ) ํ‰๊ฐ€ ๋ชจ๋“  ๊ทœ์น™์ด ๋™์‹œ์— ํ‰๊ฐ€๋จ
ํ—ˆ์šฉ/๊ฑฐ๋ถ€ ํ—ˆ์šฉ(Allow) + ๊ฑฐ๋ถ€(Deny) ๋ชจ๋‘ ๊ฐ€๋Šฅ ํ—ˆ์šฉ(Allow)๋งŒ ๊ฐ€๋Šฅ
๊ธฐ๋ณธ ์„ค์ • ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ ๊ฑฐ๋ถ€

โš™๏ธ ๋™์ž‘ ํ๋ฆ„ ์˜ˆ์‹œ

  • ํŠธ๋ž˜ํ”ฝ์ด ์„œ๋ธŒ๋„ท์— ๋“ค์–ด์˜ค๊ฑฐ๋‚˜ ๋‚˜๊ฐˆ ๋•Œ Network ACL์ด ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.
  • ๋”ฐ๋ผ์„œ, ๋ณด์•ˆ ๊ทธ๋ฃน๋ณด๋‹ค ๋จผ์ € ํŠธ๋ž˜ํ”ฝ์„ ํ•„ํ„ฐ๋งํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿง  ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

ํšŒ์‚ฌ๊ฐ€ VPC ๋‚ด Public Subnet๊ณผ Private Subnet ๊ฐ„ ํ†ต์‹ ์„ ์ œํ•œํ•˜๋ ค๊ณ  ํ•  ๋•Œ
Network ACL์„ ์„ค์ •ํ•˜์—ฌ ํŠน์ • ํฌํŠธ(์˜ˆ: 22, 80) ๋งŒ ํ—ˆ์šฉํ•˜๊ณ  ๋‚˜๋จธ์ง€๋Š” ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Security group ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€์˜ ๊ฐ€์ƒ ๋ฐฉํ™”๋ฒฝ โŒ ์„œ๋ธŒ๋„ท ๋‹จ์œ„๊ฐ€ ์•„๋‹ˆ๋ผ ์ธ์Šคํ„ด์Šค ๋‹จ์œ„
C. Traffic Mirroring ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ ๋ณต์ œ ๊ธฐ๋Šฅ โŒ ๋ณด์•ˆ ๋ชจ๋‹ˆํ„ฐ๋ง์šฉ, ๋ฐฉํ™”๋ฒฝ ์•„๋‹˜
D. Internet gateway VPC์™€ ์ธํ„ฐ๋„ท ์—ฐ๊ฒฐ ๊ฒŒ์ดํŠธ์›จ์ด โŒ ๋ฐฉํ™”๋ฒฝ ๊ธฐ๋Šฅ์ด ์—†์Œ

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿงฑ Network ACL์€ ์„œ๋ธŒ๋„ท ๋‹จ์œ„์˜ ๋ฐฉํ™”๋ฒฝ์œผ๋กœ,
์ธ๋ฐ”์šด๋“œ/์•„์›ƒ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉ ๋˜๋Š” ๊ฑฐ๋ถ€ ๊ทœ์น™์œผ๋กœ ์ œ์–ดํ•˜๋Š”
๋น„์ƒํƒœ(stateless) ๋ณด์•ˆ ๋ ˆ์ด์–ด์ž…๋‹ˆ๋‹ค.


๋ชจ๋†€๋ฆฌ์‹(monolithic) ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค(MSA) ๋กœ ๋ถ„๋ฆฌํ•ด AWS๋กœ ์ด์ „ํ•˜๋Š” ์ „๋žต์„ ๋ฌป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“˜ Q500.

A company is planning to migrate a monolithic application to AWS.
The company wants to modernize the application by splitting it into microservices.
Which migration strategy should the company use?

ํšŒ์‚ฌ๋Š” ๋ชจ๋†€๋ฆฌ์‹ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ AWS๋กœ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ํ•  ๊ณ„ํš์ด๋ฉฐ,
์ด๋ฅผ ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค ์•„ํ‚คํ…์ฒ˜๋กœ ํ˜„๋Œ€ํ™”(modernize) ํ•˜๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.
์–ด๋–ค ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ „๋žต์„ ์‚ฌ์šฉํ•ด์•ผ ํ• ๊นŒ์š”?


โœ… ์ •๋‹ต: D. Refactor (๋ฆฌํŒฉํ„ฐ๋ง)


๐Ÿ’ก ํ•ด์„ค

๐Ÿ”น Refactor๋ž€?

Refactor (๋˜๋Š” Re-architect) ๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์•„ํ‚คํ…์ฒ˜๋ฅผ ๊ทผ๋ณธ์ ์œผ๋กœ ์žฌ์„ค๊ณ„ํ•˜์—ฌ
ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ ๊ธฐ๋Šฅ๊ณผ ํ™•์žฅ์„ฑ์„ ๊ทน๋Œ€ํ™”ํ•˜๋Š” ๊ฐ€์žฅ ํ˜„๋Œ€์ ์ธ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ „๋žต์ž…๋‹ˆ๋‹ค.


โœ… Refactor์˜ ํ•ต์‹ฌ ๊ฐœ๋…

ํ•ญ๋ชฉ ์„ค๋ช…
๐ŸŽฏ ๋ชฉ์  ๊ธฐ์กด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ตฌ์กฐ์™€ ์ฝ”๋“œ๋ฅผ ๋ณ€๊ฒฝํ•˜์—ฌ ํด๋ผ์šฐ๋“œ ์ตœ์ ํ™”
๐Ÿงฉ ์˜ˆ์‹œ ๋ชจ๋†€๋ฆฌ์‹ ์•ฑ → ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค ์•„ํ‚คํ…์ฒ˜ (MSA) ๋กœ ์ „ํ™˜
โš™๏ธ ์ ์šฉ ์„œ๋น„์Šค ์˜ˆ์‹œ Amazon ECS / EKS / Lambda / API Gateway / DynamoDB ๋“ฑ
๐Ÿ’ช ์žฅ์  ํ™•์žฅ์„ฑ(Scalability), ํƒ„๋ ฅ์„ฑ(Elasticity), ๋น„์šฉ ํšจ์œจ์„ฑ, ๋ฐฐํฌ ์ž๋™ํ™”
โณ ๋‹จ์  ๋†’์€ ๊ฐœ๋ฐœ ๋ฆฌ์†Œ์Šค์™€ ์‹œ๊ฐ„์ด ํ•„์š” (์ฝ”๋“œ ๋ณ€๊ฒฝ ๋งŽ์Œ)

โš™๏ธ ์˜ˆ์‹œ ์‹œ๋‚˜๋ฆฌ์˜ค

 
  • ๊ธฐ์กด์˜ ํ•œ ๋ฉ์–ด๋ฆฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜(๋ชจ๋†€๋ฆฌ์‹)์„
    ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๋…๋ฆฝ์ ์ธ ์„œ๋น„์Šค(๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค) ๋กœ ๋‚˜๋ˆ„๊ณ 
    AWS์˜ ์ปจํ…Œ์ด๋„ˆ(ECS, EKS) ๋‚˜ ์„œ๋ฒ„๋ฆฌ์Šค(Lambda) ๊ธฐ๋ฐ˜์œผ๋กœ ์žฌ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

โŒ ์˜ค๋‹ต ํ•ด์„ค

๋ณด๊ธฐ ์„ค๋ช… ์˜ค๋‹ต ์ด์œ 
A. Rehost (์žฌํ˜ธ์ŠคํŒ…) “Lift & Shift” ๋ฐฉ์‹ — ์ฝ”๋“œ๋ฅผ ๋ณ€๊ฒฝํ•˜์ง€ ์•Š๊ณ  AWS๋กœ ์˜ฎ๊น€ โŒ ํ˜„๋Œ€ํ™”๋‚˜ MSA ๋ถ„๋ฆฌ ๋ถˆ๊ฐ€๋Šฅ
B. Repurchase (ํ™˜๋งค) SaaS ์†”๋ฃจ์…˜์œผ๋กœ ๊ต์ฒด (์˜ˆ: CRM → Salesforce) โŒ ์ž์ฒด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ฝ”๋“œ ์œ ์ง€ ๋ถˆ๊ฐ€
C. Replatform (ํ”Œ๋žซํผ ๊ต์ฒด) ์ผ๋ถ€ ์ˆ˜์ •๋งŒ ํ•˜์—ฌ ํด๋ผ์šฐ๋“œ๋กœ ์ด์ „ (์˜ˆ: DB๋ฅผ RDS๋กœ ๋ณ€๊ฒฝ) โŒ ์•„ํ‚คํ…์ฒ˜ ๋ณ€๊ฒฝ์ด ์•„๋‹Œ ์ตœ์†Œ ์ˆ˜์ • ์ˆ˜์ค€
โœ… D. Refactor (๋ฆฌํŒฉํ„ฐ๋ง) ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ตฌ์กฐ๋ฅผ ์™„์ „ํžˆ ์žฌ์„ค๊ณ„ํ•˜์—ฌ ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค๋กœ ์ „ํ™˜ โœ… ํ˜„๋Œ€ํ™”(modernization) ๋ชฉ์ ์— ๊ฐ€์žฅ ์ ํ•ฉ

๐Ÿง  7R Migration Strategies ์š”์•ฝํ‘œ

์ „๋žต ์„ค๋ช… ์ฝ”๋“œ ์ˆ˜์ • ์ •๋„
1๏ธโƒฃ Rehost Lift & Shift – ์ฝ”๋“œ ๋ณ€๊ฒฝ ์—†์ด AWS๋กœ ์ด๋™ ๐Ÿ”น ๋‚ฎ์Œ
2๏ธโƒฃ Replatform ์ผ๋ถ€ ๊ตฌ์„ฑ ์ˆ˜์ • ํ›„ ์ด๋™ (DB, ๋ฏธ๋“ค์›จ์–ด ๊ต์ฒด ๋“ฑ) ๐Ÿ”ธ ๋ณดํ†ต
3๏ธโƒฃ Repurchase SaaS๋กœ ์ „ํ™˜ (์˜ˆ: ERP → Workday) ๐Ÿ”ธ ๋ณดํ†ต
4๏ธโƒฃ Refactor / Re-architect ์•„ํ‚คํ…์ฒ˜ ๋ณ€๊ฒฝ (๋ชจ๋†€๋ฆฌ์‹ → MSA) ๐Ÿ”บ ๋†’์Œ
5๏ธโƒฃ Retire ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ข…๋ฃŒ โŒ
6๏ธโƒฃ Retain ์˜จํ”„๋ ˆ๋ฏธ์Šค์— ์œ ์ง€ โŒ
7๏ธโƒฃ Relocate VMware → AWS (VM ์ˆ˜์ค€ ์ด์ „) ๐Ÿ”น ๋‚ฎ์Œ

๐Ÿ“— ํ•œ ์ค„ ์š”์•ฝ

๐Ÿง  Refactor๋Š” ๋ชจ๋†€๋ฆฌ์‹ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋งˆ์ดํฌ๋กœ์„œ๋น„์Šค ์•„ํ‚คํ…์ฒ˜(MSA) ๋กœ ์žฌ์„ค๊ณ„ํ•˜์—ฌ
AWS์˜ ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ ๊ธฐ๋Šฅ์„ ์ตœ๋Œ€ํ•œ ํ™œ์šฉํ•˜๋Š” ํ˜„๋Œ€ํ™” ์ „๋žต์ž…๋‹ˆ๋‹ค.


 

๋ฐ˜์‘ํ˜•