Cloud · Infrastructure and application delivery

AWS Cloud

Learn core AWS services including IAM, EC2, VPC, S3, RDS, monitoring, load balancing, Auto Scaling, security, cost awareness, and cloud architecture.

Build a practical understanding of how cloud resources are connected, secured, monitored, scaled, and reviewed for real-world application workloads.

Beginner to Advanced 10 Weeks 10 Modules Online / Classroom AWS Hosted Application

Course overview

AWS Cloud provides services for computing, storage, networking, databases, identity, monitoring, and application delivery. This course introduces how those services can be combined to build practical cloud workloads.

You will begin with cloud concepts, AWS regions, Availability Zones, accounts, and identity management. You will then explore EC2, VPC, S3, RDS, load balancing, Auto Scaling, monitoring, logging, security, and cost awareness.

The course finishes with an AWS-hosted application project that brings together compute, storage, networking, database, access control, monitoring, and documentation.

Cloud architecture is not only about selecting services. It also requires understanding access, failure, performance, cost, operations, security, and the responsibilities shared between the provider and the customer.

Prerequisites

The course is designed for learners starting with cloud concepts. The following knowledge will make the practical activities easier.

  • Basic computer and internet knowledge.
  • Basic understanding of files, folders, and applications.
  • Awareness of IP addresses, ports, and web requests.
  • Basic Linux or terminal familiarity is helpful.
  • Basic Git knowledge is recommended.
  • Prior AWS experience is not required.

Readiness activity

Draw a simple architecture for a web application with a browser, application server, database, and object storage. Mark which components need public access and which should remain private.

Who can explore this course?

Cloud beginners

Understand AWS foundations

Learn how cloud resources are organized, accessed, connected, and monitored.

Developers

Deploy application workloads

Explore compute, storage, databases, networking, and application delivery options.

System administrators

Move infrastructure concepts to cloud

Connect server, identity, networking, and monitoring knowledge with AWS services.

DevOps learners

Prepare for delivery workflows

Explore automation, deployment, logging, scaling, reliability, and cost awareness.

What you will learn

  • Understand cloud-computing and AWS fundamentals.
  • Navigate AWS accounts, regions, services, and billing concepts.
  • Use IAM users, groups, roles, policies, and least-privilege ideas.
  • Launch and manage EC2-based compute resources.
  • Design VPCs with subnets, route tables, and security groups.
  • Store and protect objects using Amazon S3 concepts.
  • Connect applications with managed relational databases using RDS.
  • Distribute traffic with load balancing concepts.
  • Scale workloads and understand health-based availability.
  • Monitor applications with CloudWatch concepts and logs.
  • Review security, reliability, performance, and cost decisions.
  • Deploy and document a portfolio-ready AWS application.

Curriculum outline

The ten-module outline moves from AWS foundations to a complete hosted application. Exercises should be performed in an authorized account with spending controls and resources removed after practice.

01

AWS Cloud fundamentals

Build a foundation in cloud terminology, shared responsibility, service categories, accounts, regions, and Availability Zones.

  • Cloud computing compared with traditional infrastructure.
  • Infrastructure, platform, and software service ideas.
  • AWS accounts, regions, Availability Zones, and edge concepts.
  • Elasticity, scalability, availability, and resilience.
  • Shared responsibility and operational ownership.
  • Service selection based on workload requirements.

Practice: Draw a basic AWS architecture and label its users, compute, storage, database, network, and monitoring components.

02

Environment, account, and cost setup

Prepare a safe learning environment and understand the account-level controls needed before launching resources.

  • Console navigation and service search.
  • Region selection and resource-location awareness.
  • Budgets, billing alerts, and cost visibility.
  • Resource naming and tagging conventions.
  • AWS CLI and local configuration concepts.
  • Cleanup planning for temporary lab resources.

Practice: Create a project naming convention, define environment tags, and prepare a checklist for deleting resources after each lab.

03

IAM, identity, and access control

Learn how AWS identities and permissions control access to cloud resources and services.

  • Users, groups, roles, and policies.
  • Authentication compared with authorization.
  • Managed and inline policy concepts.
  • Least privilege and permission review.
  • Roles for applications and AWS services.
  • MFA and protection of privileged access.
  • Credential handling and access-key risks.

Practice: Create a restricted lab identity, test permitted and denied actions, and document why each permission is needed.

04

EC2 compute and application servers

Explore virtual servers, machine images, storage, access, security groups, and application setup.

  • Instance types and workload considerations.
  • Amazon Machine Images and launch configuration.
  • Key pairs and secure administrative access.
  • Security groups and inbound/outbound rules.
  • Elastic Block Store concepts.
  • User data and instance initialization.
  • Stopping, terminating, and protecting resources.

Practice: Launch a lab instance, install a small web service, test access through a controlled port, and terminate the resource after verification.

05

VPC networking and private architecture

Understand how AWS resources are placed inside a logically isolated virtual network.

  • VPC address ranges and subnet planning.
  • Public and private subnets.
  • Route tables and internet connectivity.
  • Internet gateways and NAT concepts.
  • Security groups and network ACL concepts.
  • Availability Zones and fault isolation.
  • DNS and private-service communication.

Practice: Design a two-tier network with a public application layer and a private database layer. Explain the route and access decisions.

06

S3 storage and data protection

Explore object storage for static assets, backups, uploads, logs, and application content.

  • Buckets, objects, keys, and prefixes.
  • Storage classes and lifecycle concepts.
  • Bucket policies and access control.
  • Public access risks and private-by-default design.
  • Encryption and data-protection concepts.
  • Versioning and recovery considerations.
  • Static website and application-integration patterns.

Practice: Create a private storage bucket, upload sample objects, apply tags, test controlled access, and document the protection settings.

07

RDS databases and application data

Learn how managed relational databases can support applications while separating data services from application compute.

  • Managed database concepts and service responsibilities.
  • Engine, instance, storage, and connectivity choices.
  • Database subnet groups and private placement.
  • Security groups for database access.
  • Backups, snapshots, and maintenance concepts.
  • Connection configuration and secret handling.
  • Availability and recovery considerations.

Practice: Design an application-to-database connection path and explain why the database should not be directly exposed to the public internet.

08

Load balancing, Auto Scaling, and reliability

Explore how applications can distribute traffic, detect unhealthy targets, and adjust compute capacity.

  • Load balancer and target-group concepts.
  • Health checks and healthy-target routing.
  • Availability Zones and distributed application layers.
  • Launch templates and Auto Scaling concepts.
  • Scaling policies and demand changes.
  • Session and state considerations.
  • Failure scenarios and recovery planning.

Practice: Draw an architecture with a load balancer and multiple application targets. Explain how unhealthy targets should be handled.

09

Monitoring, logging, and operations

Develop an operational view of a workload by reviewing metrics, logs, alarms, and activity history.

  • CloudWatch metrics, logs, dashboards, and alarms.
  • Application, system, and access logs.
  • Health checks and operational signals.
  • CloudTrail activity and audit concepts.
  • Incident investigation and evidence collection.
  • Alert thresholds and alert fatigue.
  • Operational runbooks and response procedures.

Practice: Define three useful monitoring signals for a hosted application and create a response checklist for each possible warning.

10

Architecture review and capstone delivery

Bring the services together and review the application across security, reliability, performance, operations, cost, and sustainability.

  • Architecture diagrams and decision records.
  • Security and least-privilege review.
  • Reliability and failure-recovery review.
  • Performance and scaling considerations.
  • Cost estimation and resource cleanup.
  • Deployment and rollback planning.
  • Final documentation and presentation.

Practice: Complete the hosted-application capstone, perform a six-pillar review, and explain the main trade-offs in your architecture.

Practical exercise ideas

Complete these smaller activities before building the complete hosted-application project.

Identity

Least-privilege lab

Create a restricted identity and verify which AWS actions are allowed or denied.

Review focus: policies, roles, MFA, and safe credential handling.

Compute

EC2 web server

Launch a lab instance, configure a web service, verify access, and clean up the resource.

Review focus: AMIs, security groups, access, storage, and lifecycle.

Networking

Two-tier VPC design

Design public application and private database subnets with appropriate routing.

Review focus: isolation, routes, gateways, and controlled communication.

Storage

Protected S3 bucket

Store sample objects privately and document how an application could access them safely.

Review focus: policies, encryption, versioning, and lifecycle.

Database

Application data layer

Plan a private relational database connection for an application running on cloud compute.

Review focus: subnet placement, security groups, backups, and secrets.

Operations

Monitoring checklist

Select useful metrics, logs, alarms, and response actions for a sample workload.

Review focus: signal quality, incident response, and operational ownership.

Suggested ten-week learning plan

This is an illustrative sequence for organizing learning and practice. Confirm the academy's actual timetable, class hours, and lab access before publishing.

Weekly focus and practical milestones
Week Focus Suggested milestone
01 Cloud and AWS fundamentals Draw a basic cloud architecture and review shared responsibility.
02 Account, tools, and cost awareness Prepare tags, budgets, CLI concepts, and cleanup procedures.
03 IAM and access control Create and test a restricted lab identity.
04 EC2 compute Launch, configure, test, and terminate a lab instance.
05 VPC networking Design public and private subnet architecture.
06 S3 and storage Create a protected object-storage workflow.
07 RDS and application data Design a private application-to-database connection.
08 Load balancing and scaling Review healthy targets, scaling, and failure scenarios.
09 Monitoring and operations Define metrics, logs, alarms, and response procedures.
10 Capstone and architecture review Deploy, document, review, and present the architecture.
Bring the services together

Capstone project

AWS-hosted web application

Deploy a small web application using a practical AWS architecture. The project should demonstrate compute, storage, database connectivity, networking, identity, monitoring, documentation, and responsible resource management.

Core project requirements

  • Define the application's purpose and target users.
  • Create an architecture diagram and service inventory.
  • Use IAM roles and least-privilege access where appropriate.
  • Deploy application compute on EC2 or an approved alternative.
  • Use a VPC with documented subnet and routing decisions.
  • Store static assets or uploads with an appropriate storage design.
  • Connect the application to a managed database or approved data layer.
  • Restrict database access to the required application layer.
  • Configure basic monitoring and operational logs.
  • Document deployment, testing, cleanup, and known limitations.

Architecture review requirements

  • Explain how users reach the application.
  • Explain which resources are public and which are private.
  • Describe identity, permissions, and secret-handling decisions.
  • Describe what happens if an application instance fails.
  • Identify the main performance and scaling considerations.
  • Estimate the cost categories and cleanup requirements.
  • Describe logs, alerts, and operational response steps.
  • Record trade-offs and improvements for a future version.

Optional extensions

Add a load balancer, Auto Scaling, a managed DNS workflow, HTTPS planning, infrastructure as code, a CI/CD pipeline, container deployment, or a serverless alternative. Extend the project only after the basic architecture is understood and stable.

Cloud resources can create charges. Use budgets, permissions, tags, and cleanup checklists. Never leave temporary lab resources running without understanding their billing and access implications.

Suggested project structure

Organize diagrams, application code, deployment notes, configuration examples, and operational documentation so another person can understand and reproduce the project.

aws-cloud-project/
├── app/
│   ├── src/
│   └── README.md
├── architecture/
│   ├── architecture-diagram.png
│   └── decisions.md
├── infrastructure/
│   ├── templates/
│   └── configuration.example
├── operations/
│   ├── monitoring.md
│   ├── runbook.md
│   └── cleanup.md
├── security/
│   └── access-review.md
├── README.md
└── .gitignore

Do not commit access keys, passwords, private certificates, database credentials, personal data, or other secrets to a public repository.

AWS architecture review

Use a structured review to understand the trade-offs in your design. AWS Well-Architected organizes architecture guidance around six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. [62][63]

Operations

Can the workload be operated?

Review deployment, monitoring, logging, runbooks, ownership, and change procedures.

Security

Are access and data protected?

Review identity, permissions, network exposure, encryption, secrets, and audit activity.

Reliability

Can the system recover?

Review failure scenarios, backups, health checks, redundancy, and recovery procedures.

Performance

Can it meet its workload needs?

Review resource selection, latency, throughput, scaling behavior, and bottlenecks.

Cost

Is spending understood?

Review resource usage, tagging, budgets, cleanup, and cost-to-value decisions.

Sustainability

Can resource use be improved?

Review efficient resource selection, utilization, lifecycle, and unnecessary capacity.

Security and cost practices

Cloud learning should include access protection and spending awareness from the beginning. A working deployment is not complete if access is excessive, secrets are exposed, or temporary resources are left running without review.

Identity

Use least privilege

Grant only the permissions needed for the current task and review them as the project changes.

Credentials

Protect access information

Never hardcode secrets in application files, public repositories, or screenshots.

Network

Reduce public exposure

Keep databases and internal services private unless public access is explicitly required.

Monitoring

Review activity and health

Use logs, metrics, alarms, and audit information to understand system behavior.

Budget

Track resource spending

Use budgets, tags, and cost review to understand which resources create charges.

Cleanup

Remove unused resources

Terminate lab instances, delete temporary storage, and review related networking resources.

This page is educational content. AWS pricing, service availability, regional features, and billing outcomes can change. Confirm current details in the AWS console and official documentation before deployment.

Tools and technologies

The course focuses on AWS services while introducing supporting tools for development, deployment, monitoring, documentation, and automation.

  • AWS Management Console
  • AWS CLI concepts
  • IAM
  • EC2
  • VPC
  • S3
  • RDS
  • CloudWatch
  • CloudTrail concepts
  • Git
  • GitHub
  • VS Code

Supporting concepts

  • Linux and server administration.
  • Networking, ports, routes, and DNS.
  • Web applications and HTTP traffic.
  • Databases and application configuration.
  • Infrastructure as code and CI/CD concepts.
  • Security, monitoring, cost, and incident response.

Learning outcomes

By completing the proposed lessons and exercises, aim to demonstrate the following abilities:

  • Explain core cloud and AWS architecture concepts.
  • Navigate regions, services, accounts, and billing controls.
  • Apply basic IAM and least-privilege principles.
  • Launch and manage a controlled compute resource.
  • Design a simple VPC with public and private components.
  • Store and protect application objects in S3.
  • Plan a private application-to-database connection.
  • Explain load balancing and scaling concepts.
  • Define useful monitoring signals and response steps.
  • Review an architecture across six quality areas.
  • Document and present an AWS-hosted application.

These are learning objectives, not guarantees of employment, certification, placement, or a specific cloud role. Results depend on practice, lab access, project quality, and continued learning.

Related career interests

This course can support exploration of cloud, infrastructure, operations, and DevOps-related work.

  • AWS Cloud Trainee
  • Cloud Support Associate
  • Junior Cloud Engineer
  • DevOps Trainee
  • Infrastructure Engineer
  • Cloud Operations Associate
  • Associate Software Engineer
  • Implementation Engineer

Portfolio presentation ideas

  • Explain the workload and its intended users.
  • Show the architecture diagram and service choices.
  • Explain public and private network components.
  • Demonstrate IAM and security-group decisions.
  • Show the hosted application and its data flow.
  • Review monitoring signals and failure scenarios.
  • Discuss cost controls and cleanup procedures.
  • Present one trade-off and one planned improvement.

Frequently asked questions

Who is this course for?

It is suitable for beginners to cloud computing, developers, system administrators, DevOps learners, and anyone who wants to understand AWS application infrastructure.

Do I need previous AWS experience?

No. The course begins with cloud and AWS fundamentals. Basic computer knowledge is required, while Linux, networking, and Git familiarity are helpful.

Which AWS services are covered?

The main topics include IAM, EC2, VPC, S3, RDS, load balancing, Auto Scaling, CloudWatch, CloudTrail concepts, and related architecture practices.

What is the capstone project?

The proposed capstone is an AWS-hosted web application covering compute, networking, storage, database access, identity, monitoring, documentation, and cleanup.

Will the course require an AWS account?

Practical labs may require access to an authorized AWS account. Confirm account, billing, lab, and free-tier arrangements with the academy before beginning hands-on work.

Can AWS resources create charges?

Yes. AWS services and resources may incur charges depending on usage, region, account status, and pricing terms. Use budgets, alerts, permission controls, and cleanup procedures.

What is a VPC?

A VPC is a logically isolated section of the AWS Cloud where you can launch resources in a virtual network that you define. [71]

What is load balancing?

Elastic Load Balancing distributes incoming traffic across registered targets and can route traffic toward healthy targets based on health checks. [68]

Does the course cover security?

Yes. It includes IAM, least privilege, MFA concepts, security groups, private networking, secret handling, monitoring, audit concepts, and architecture review.

Does the course cover cost optimization?

It introduces budgets, tagging, resource selection, cleanup, utilization review, and the importance of understanding workload costs. Verify current AWS pricing before deployment.

How long is the course?

The supplied course information proposes a duration of 10 weeks. Confirm the official schedule and practical-lab duration before publishing or enrolling.

How do I enroll?

This page is a frontend course-information demonstration. Enrollment, payment, scheduling, and admission workflows are not implemented here.

Does this course guarantee a job?

No. The course can support practical learning and portfolio development, but it does not guarantee employment, placement, certification, or salary.

Build in the cloud

Design your next AWS workload

Learn how AWS services connect, how cloud resources are protected and monitored, and how to document an application architecture with clear trade-offs.