100 Most Frequently Asked AWS Interview Questions & Answers
Below is a practical AWS interview guide aimed at Senior Java / Spring Boot / Full-Stack / Cloud / Lead Software Engineer roles. The questions progress from fundamentals to architecture, security, DevOps, containers, databases, serverless, and system design.
1. AWS Fundamentals
1. What is AWS?
Answer:
Amazon Web Services (AWS) is a cloud computing platform providing on-demand infrastructure and managed services such as compute, storage, databases, networking, security, analytics, and AI.
2. What are the main benefits of AWS?
Answer:
- Pay-as-you-go pricing
- Elastic scalability
- High availability
- Global infrastructure
- Managed services
- Security and compliance
- Automation
- Rapid provisioning
3. What is an AWS Region?
Answer:
A Region is a geographical area containing multiple isolated Availability Zones (AZs).
Examples include:
eu-west-2— Londoneu-west-1— Irelandus-east-1— N. Virginia
Applications can be deployed across multiple Regions for disaster recovery or global availability.
4. What is an Availability Zone?
Answer:
An Availability Zone is an isolated location within an AWS Region containing one or more data centers.
For high availability, applications should generally distribute workloads across multiple AZs.
5. What is the difference between Region and Availability Zone?
| Region | Availability Zone |
|---|---|
| Geographical area | Isolated infrastructure location |
| Contains multiple AZs | Belongs to one Region |
| Used for geographic resilience | Used for high availability |
6. What is the AWS Shared Responsibility Model?
Answer:
AWS is responsible for security of the cloud, while customers are responsible for security in the cloud.
AWS manages:
- Physical infrastructure
- Data centers
- Hardware
- Networking infrastructure
Customers manage, depending on the service:
- IAM
- Data
- Application security
- OS patching on EC2
- Network configuration
- Encryption configuration
7. What is AWS Well-Architected Framework?
Answer:
It provides architectural best practices based on six pillars:
- Operational Excellence
- Security
- Reliability
- Performance Efficiency
- Cost Optimization
- Sustainability
8. What is AWS account?
Answer:
An AWS account provides an isolated environment for AWS resources, billing, permissions, and security controls.
Organizations often use multiple accounts for:
- Development
- Testing
- Production
- Security
- Shared services
9. What is AWS Organizations?
Answer:
AWS Organizations centrally manages multiple AWS accounts.
It supports:
- Consolidated billing
- Organizational Units
- Service Control Policies
- Central governance
- Account management
10. What is AWS CLI?
Answer:
AWS CLI is a command-line interface for managing AWS resources.
Example:
aws s3 ls
aws ec2 describe-instances
aws iam list-users
2. IAM & Security
11. What is IAM?
Answer:
AWS Identity and Access Management controls who can access AWS resources and what actions they can perform.
Core concepts:
- Users
- Groups
- Roles
- Policies
12. What is an IAM Role?
Answer:
An IAM Role is an identity that provides temporary permissions to AWS resources or applications.
For example, an EC2 instance can assume a role allowing it to read from S3 without storing AWS access keys on the server.
13. IAM User vs IAM Role?
| IAM User | IAM Role |
|---|---|
| Long-term identity | Temporary identity |
| Usually associated with a person/application | Assumed by users/services |
| Can have credentials | Uses temporary credentials |
| Less suitable for AWS workloads | Preferred for AWS workloads |
14. What is an IAM Policy?
Answer:
An IAM policy is a JSON document defining permissions.
Example:
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*"
}
15. What is least privilege?
Answer:
Least privilege means granting only the permissions required to perform a task.
Instead of:
s3:*
grant only:
s3:GetObject
when read access is sufficient.
16. What is MFA?
Answer:
Multi-Factor Authentication adds another authentication factor beyond a password.
For privileged AWS accounts, MFA is strongly recommended.
17. What is AWS KMS?
Answer:
AWS Key Management Service manages encryption keys.
It can be used to encrypt:
- S3 objects
- EBS volumes
- RDS databases
- Secrets
- Application data
18. What is AWS Secrets Manager?
Answer:
Secrets Manager securely stores and manages secrets such as:
- Database passwords
- API keys
- OAuth credentials
- Application secrets
It also supports automatic secret rotation for supported services.
19. Secrets Manager vs Parameter Store?
| Secrets Manager | Parameter Store |
|---|---|
| Designed for secrets | Configuration + parameters |
| Secret rotation | Basic parameter management |
| More specialized | Often simpler/cheaper |
| Supports secret lifecycle management | Supports String/StringList/SecureString |
20. What is AWS WAF?
Answer:
AWS WAF is a web application firewall used to protect applications from attacks such as:
- SQL injection
- Cross-site scripting
- Malicious requests
- IP-based attacks
- Bot traffic
It can be associated with services such as CloudFront and Application Load Balancer.
3. EC2 & Compute
21. What is Amazon EC2?
Answer:
Amazon Elastic Compute Cloud provides resizable virtual servers in AWS.
You control:
- OS
- Applications
- Runtime
- Networking
- Storage
22. What is an AMI?
Answer:
An Amazon Machine Image is a template used to launch EC2 instances.
It can contain:
- Operating system
- Applications
- Configuration
- Required software
23. What is an EC2 Instance Type?
Answer:
An instance type defines the compute resources available to an EC2 instance.
Examples of categories:
- General purpose
- Compute optimized
- Memory optimized
- Storage optimized
- Accelerated computing
24. What is an Auto Scaling Group?
Answer:
An Auto Scaling Group automatically maintains the desired number of EC2 instances.
It can:
- Add instances when demand increases
- Remove instances when demand decreases
- Replace unhealthy instances
25. What is an EC2 Launch Template?
Answer:
A Launch Template defines how EC2 instances should be created.
It can specify:
- AMI
- Instance type
- Security groups
- IAM role
- User data
- Storage
- Networking
26. What is EC2 User Data?
Answer:
User Data is a script executed during instance initialization.
Example:
#!/bin/bash
yum update -y
yum install -y docker
systemctl start docker
27. What is a Security Group?
Answer:
A Security Group is a virtual firewall associated with AWS resources such as EC2.
Important characteristics:
- Stateful
- Allows inbound/outbound rules
- No explicit deny rules
- Changes take effect dynamically
28. Security Group vs NACL?
| Security Group | Network ACL |
|---|---|
| Instance/resource level | Subnet level |
| Stateful | Stateless |
| Allow rules | Allow and deny rules |
| Evaluated after traffic reaches resource | Controls subnet traffic |
29. What is Elastic Load Balancing?
Answer:
Elastic Load Balancing distributes incoming traffic across multiple targets.
Common load balancers:
- Application Load Balancer
- Network Load Balancer
- Gateway Load Balancer
30. ALB vs NLB?
ALB — Application Load Balancer
- Layer 7
- HTTP/HTTPS
- Path routing
- Host routing
- Header-based routing
NLB — Network Load Balancer
- Layer 4
- TCP/UDP/TLS
- Very high performance
- Low latency
4. S3
31. What is Amazon S3?
Answer:
Amazon Simple Storage Service is an object storage service designed for high durability and scalability.
Typical uses:
- Documents
- Images
- Videos
- Backups
- Logs
- Data lakes
- Static websites
32. What is an S3 Bucket?
Answer:
A bucket is a logical container for S3 objects.
Example:
s3://company-documents/
33. What is an S3 Object?
Answer:
An object consists of:
- Data
- Key
- Metadata
For example:
Key: invoices/2026/invoice-001.pdf
34. What is S3 Versioning?
Answer:
Versioning maintains multiple versions of an object.
It protects against:
- Accidental deletion
- Accidental overwriting
- Data corruption
35. What are S3 Storage Classes?
Answer:
Common classes include:
- S3 Standard
- S3 Intelligent-Tiering
- S3 Standard-IA
- S3 One Zone-IA
- S3 Glacier Instant Retrieval
- S3 Glacier Flexible Retrieval
- S3 Glacier Deep Archive
The choice depends on access frequency and retrieval requirements.
36. What is S3 Lifecycle Management?
Answer:
Lifecycle policies automatically transition or delete objects.
Example:
Day 0 → S3 Standard
Day 30 → Standard-IA
Day 90 → Glacier
Day 365 → Delete
37. Is S3 strongly consistent?
Answer:
Yes. Amazon S3 provides strong read-after-write consistency for object PUT and DELETE operations.
38. How do you secure an S3 bucket?
Answer:
- Block public access
- IAM policies
- Bucket policies
- Encryption
- Versioning
- Logging
- CloudTrail
- Least privilege
39. What is S3 Pre-Signed URL?
Answer:
A pre-signed URL provides temporary access to an S3 object without making the bucket public.
Example use:
User → Application → Pre-signed URL → S3
40. S3 vs EBS?
| S3 | EBS |
|---|---|
| Object storage | Block storage |
| Highly scalable | Attached to EC2 |
| Access via API | Appears as disk |
| Good for files/data lakes | Good for OS/application disks |
5. VPC & Networking
41. What is Amazon VPC?
Answer:
A Virtual Private Cloud provides an isolated logical network in AWS.
You control:
- IP ranges
- Subnets
- Routing
- Security
- Internet connectivity
42. What is a subnet?
Answer:
A subnet is a range of IP addresses inside a VPC.
Subnets are associated with an Availability Zone.
43. Public vs Private Subnet?
Public subnet:
Has a route to an Internet Gateway.
Private subnet:
Does not have direct inbound internet access through an Internet Gateway.
Typical architecture:
Internet
|
ALB
|
Private Subnet
|
Application
|
Private Database
44. What is an Internet Gateway?
Answer:
An Internet Gateway enables communication between a VPC and the public internet.
45. What is a NAT Gateway?
Answer:
A NAT Gateway allows resources in private subnets to initiate outbound internet connections without allowing unsolicited inbound internet connections.
Example:
Private EC2
|
NAT Gateway
|
Internet
46. What is a Route Table?
Answer:
A route table determines where network traffic is sent.
Example:
0.0.0.0/0 → Internet Gateway
47. What is VPC Peering?
Answer:
VPC Peering connects two VPCs so resources can communicate privately.
It can connect VPCs in:
- Same Region
- Different Regions
48. What is AWS Transit Gateway?
Answer:
Transit Gateway provides a centralized hub for connecting multiple VPCs and on-premises networks.
Instead of:
VPC A ↔ VPC B
VPC A ↔ VPC C
VPC B ↔ VPC C
you can use:
Transit Gateway
/ | \
VPC A VPC B VPC C
49. What is AWS Direct Connect?
Answer:
AWS Direct Connect provides a dedicated network connection between an on-premises environment and AWS.
It provides more predictable network performance than internet-based VPN connectivity.
50. What is AWS VPN?
Answer:
AWS Site-to-Site VPN establishes encrypted connectivity between an on-premises network and AWS.
6. RDS & Databases
51. What is Amazon RDS?
Answer:
Amazon Relational Database Service is a managed relational database service.
Supported engines include:
- PostgreSQL
- MySQL
- MariaDB
- Oracle
- SQL Server
- Aurora
52. What are the benefits of RDS?
Answer:
- Automated backups
- Patching
- Monitoring
- Multi-AZ
- Read replicas
- Automated maintenance
- Scaling options
53. What is RDS Multi-AZ?
Answer:
Multi-AZ provides a standby database in another Availability Zone for high availability.
The standby is primarily intended for failover rather than read scaling.
54. What is an RDS Read Replica?
Answer:
A Read Replica asynchronously replicates data from a source database and is used primarily to scale read workloads.
55. Multi-AZ vs Read Replica?
| Multi-AZ | Read Replica |
|---|---|
| High availability | Read scaling |
| Synchronous replication in typical configurations | Asynchronous replication |
| Automatic failover | Application can route reads |
| Standby | Readable replica |
56. What is Amazon Aurora?
Answer:
Aurora is AWS’s cloud-optimized relational database compatible with MySQL and PostgreSQL.
It separates compute and distributed storage and provides features designed for high availability and scalability.
57. RDS vs DynamoDB?
RDS:
- Relational
- SQL
- Joins
- Transactions
- Structured schema
DynamoDB:
- NoSQL
- Key-value/document
- Massive scale
- Low predictable latency
58. What is DynamoDB?
Answer:
DynamoDB is a fully managed NoSQL database designed for high-scale, low-latency applications.
59. What is a DynamoDB Partition Key?
Answer:
The partition key determines how DynamoDB distributes data across partitions.
A good partition key should provide sufficient cardinality and distribute traffic evenly.
60. What is DynamoDB GSI?
Answer:
A Global Secondary Index allows queries using attributes other than the table’s primary key.
7. Lambda & Serverless
61. What is AWS Lambda?
Answer:
Lambda is a serverless compute service that executes code in response to events.
You don’t manage servers directly.
62. What are Lambda use cases?
Answer:
- REST APIs
- Event processing
- S3 processing
- Scheduled jobs
- Stream processing
- Automation
- Serverless applications
63. What triggers Lambda?
Answer:
- API Gateway
- S3
- EventBridge
- SQS
- SNS
- DynamoDB Streams
- Kinesis
- Step Functions
64. What is Lambda Cold Start?
Answer:
A cold start occurs when AWS needs to initialize a new execution environment before executing a function.
It can increase initial request latency.
65. How can Lambda cold starts be reduced?
Answer:
- Reduce deployment package size
- Reduce initialization work
- Reuse connections
- Use appropriate runtime settings
- Provisioned Concurrency when appropriate
- Keep dependencies efficient
66. What are Lambda limitations?
Answer:
Lambda has constraints around:
- Maximum execution duration
- Memory
- Package size
- Temporary storage
- Concurrency
The exact limits depend on the current AWS service configuration.
67. What is API Gateway?
Answer:
Amazon API Gateway provides APIs for applications and can integrate with Lambda and other backend services.
It supports features such as:
- Authentication
- Throttling
- Monitoring
- API lifecycle management
68. API Gateway vs ALB?
API Gateway:
- API management
- Authentication
- Throttling
- Serverless integration
ALB:
- Load balancing
- HTTP routing
- EC2/ECS/EKS targets
69. What is AWS Step Functions?
Answer:
Step Functions orchestrates workflows using state machines.
Example:
Validate Order
↓
Charge Payment
↓
Reserve Inventory
↓
Send Confirmation
70. What is EventBridge?
Answer:
Amazon EventBridge is an event bus service used to route events between applications and AWS services.
It is useful for event-driven architectures.
8. Messaging & Event-Driven Architecture
71. What is Amazon SQS?
Answer:
Simple Queue Service is a managed message queue.
It decouples producers and consumers.
Producer → SQS → Consumer
72. Standard SQS vs FIFO SQS?
| Standard | FIFO |
|---|---|
| Very high throughput | Ordered processing |
| At-least-once delivery | Exactly-once processing support |
| Ordering not guaranteed | Ordering guaranteed within message groups |
| Lower constraints | Higher ordering/deduplication guarantees |
73. What is SNS?
Answer:
Amazon Simple Notification Service provides pub/sub messaging.
Example:
→ Email
Application → SNS → → SQS
→ Lambda
74. SNS vs SQS?
SNS: Push/fan-out messaging.
SQS: Queue-based asynchronous processing.
They are frequently used together.
75. What is Kinesis?
Answer:
Amazon Kinesis is used for real-time streaming data.
Use cases include:
- Logs
- Clickstreams
- IoT
- Real-time analytics
- Event streams
76. SQS vs Kinesis?
| SQS | Kinesis |
|---|---|
| Message queue | Data streaming |
| Consumer processing | Continuous streams |
| Message-oriented | Stream-oriented |
| Simple decoupling | Real-time streaming analytics |
77. What is dead-letter queue?
Answer:
A DLQ stores messages that cannot be successfully processed after a configured number of attempts.
It allows engineers to:
- Investigate failures
- Prevent endless retries
- Reprocess messages later
78. What is idempotency?
Answer:
Idempotency means processing the same request multiple times produces the same business result.
For example, a payment request should not charge a customer twice if the same message is retried.
9. Containers & Kubernetes
79. What is Amazon ECS?
Answer:
Amazon Elastic Container Service is a managed container orchestration service.
It can run Docker containers without requiring Kubernetes.
80. What is Amazon EKS?
Answer:
Amazon Elastic Kubernetes Service is AWS’s managed Kubernetes service.
AWS manages much of the Kubernetes control plane while customers manage workloads and configuration.
81. ECS vs EKS?
| ECS | EKS |
|---|---|
| AWS-native orchestration | Kubernetes |
| Simpler for many AWS workloads | Kubernetes ecosystem |
| Easier operational model | More flexibility |
| AWS-specific | More portable |
82. What is AWS Fargate?
Answer:
Fargate is a serverless compute engine for containers.
You deploy containers without managing EC2 servers.
It can be used with:
- ECS
- EKS
83. ECS EC2 vs Fargate?
ECS on EC2:
- You manage instances
- More infrastructure control
- Potentially better cost optimization at steady scale
Fargate:
- No server management
- Easier operations
- Pay based on requested resources
84. How would you deploy a Spring Boot microservice on AWS?
Answer:
A typical architecture could be:
CloudFront
|
ALB
|
ECS / EKS / EC2
|
Spring Boot API
/ \
Redis RDS
|
SQS
|
Lambda
Container images can be stored in ECR, while CI/CD can be handled using AWS-native or third-party pipelines.
10. Monitoring & DevOps
85. What is Amazon CloudWatch?
Answer:
CloudWatch provides:
- Metrics
- Logs
- Alarms
- Dashboards
- Events
- Observability capabilities
86. What is AWS CloudTrail?
Answer:
CloudTrail records API activity and account actions.
It is especially useful for:
- Security auditing
- Compliance
- Investigating changes
- Tracking AWS API calls
87. CloudWatch vs CloudTrail?
| CloudWatch | CloudTrail |
|---|---|
| Monitoring | Auditing |
| Metrics/logs/alarms | API activity |
| Application/infrastructure health | Who did what |
| Operational visibility | Governance/security |
88. What is AWS X-Ray?
Answer:
AWS X-Ray helps trace requests through distributed applications.
It can help identify:
- Slow services
- Errors
- Dependencies
- Latency bottlenecks
This is particularly useful for microservices.
89. What is Infrastructure as Code?
Answer:
Infrastructure as Code defines infrastructure using code instead of manually creating resources.
Popular AWS IaC technologies include:
- CloudFormation
- AWS CDK
- Terraform
90. CloudFormation vs Terraform?
CloudFormation:
- AWS-native
- Deep AWS integration
- Managed by AWS
Terraform:
- Multi-cloud
- Large provider ecosystem
- HashiCorp configuration language
11. Architecture & System Design
91. How would you design a highly available AWS application?
Answer:
I would typically:
- Deploy across multiple AZs.
- Put an ALB in front of application instances.
- Use Auto Scaling or ECS/EKS.
- Keep application instances stateless.
- Use RDS Multi-AZ/Aurora for relational data.
- Use S3 for object storage.
- Use ElastiCache for caching where appropriate.
- Use SQS/EventBridge for asynchronous processing.
- Use CloudWatch for monitoring.
- Use CloudTrail for auditing.
- Use IAM roles and least privilege.
- Define infrastructure as code.
92. How would you design a scalable Spring Boot application on AWS?
Answer:
Route 53
|
CloudFront
|
WAF
|
ALB
|
+----------+----------+
| | |
ECS ECS ECS
| | |
+----------+----------+
|
+----------+----------+
| |
Aurora ElastiCache
|
Read Replica
Async workloads
|
SQS
|
Workers
The application should remain stateless so that additional instances can be added horizontally.
93. How would you design an AWS microservices architecture?
Answer:
A typical design could include:
API Gateway
|
Load Balancer
|
+-----------------+----------------+
| | |
Customer Order Payment
Service Service Service
| | |
+-----------------+----------------+
|
EventBridge / SNS
|
SQS
|
Workers
Each service should own its business logic and preferably its data boundary.
94. How would you handle database scaling?
Answer:
Depending on the workload:
Read-heavy:
- Read replicas
- Caching
- ElastiCache
- Database indexing
Write-heavy:
- Partitioning/sharding where appropriate
- Queue-based processing
- DynamoDB where the access pattern fits
- Database optimization
Large datasets:
- Data lifecycle management
- S3/data lake
- Analytics-specific storage
95. How would you design disaster recovery in AWS?
Answer:
Possible DR strategies include:
- Backup and restore
- Pilot light
- Warm standby
- Multi-site active/active
For critical applications, I would define:
- RTO — Recovery Time Objective
- RPO — Recovery Point Objective
Then choose an architecture based on business requirements and cost.
96. What is RTO?
Answer:
Recovery Time Objective is the maximum acceptable time required to restore service after a failure.
Example:
RTO = 30 minutes
means the system should be restored within 30 minutes.
97. What is RPO?
Answer:
Recovery Point Objective defines the maximum acceptable amount of data loss measured in time.
Example:
RPO = 5 minutes
means losing up to approximately five minutes of data may be acceptable.
98. How would you reduce AWS costs?
Answer:
I would look at:
- Right-sizing EC2
- Auto Scaling
- Savings Plans
- Reserved capacity where appropriate
- Spot Instances for interruptible workloads
- S3 lifecycle policies
- Removing unused resources
- Database right-sizing
- Monitoring idle resources
- Efficient architecture
- Serverless for appropriate workloads
The key is to optimize cost per business outcome, not simply minimize infrastructure cost.
99. How would you secure a production AWS environment?
Answer:
I would implement defense in depth:
IAM
↓
Organizations / SCP
↓
VPC
↓
Security Groups / NACL
↓
WAF
↓
Application Security
↓
Encryption
↓
Secrets Management
↓
CloudTrail / CloudWatch
↓
GuardDuty / Security Monitoring
Key principles include:
- Least privilege
- MFA
- IAM roles instead of long-lived credentials
- Encryption at rest and in transit
- Private subnets for sensitive workloads
- Network segmentation
- Centralized logging
- Continuous monitoring
- Automated security controls
100. Describe a production AWS architecture you have designed.
Answer:
A strong interview answer should follow this structure:
1. Business problem
“The system needed to support a highly available client onboarding platform with significant transaction volume.”
2. Architecture
“We used Spring Boot microservices deployed in AWS, behind load balancing, with asynchronous processing through messaging.”
3. Data
“Transactional data was stored in a relational database, while object/document data was stored in S3.”
4. Scalability
“The services were stateless and horizontally scalable. Auto Scaling allowed capacity to increase based on demand.”
5. Reliability
“We deployed workloads across multiple Availability Zones and designed asynchronous operations to tolerate transient failures.”
6. Security
“IAM roles, least-privilege policies, encryption, private networking and centralized auditing were used.”
7. Observability
“CloudWatch metrics and logs, distributed tracing, and centralized alerting were used to identify production issues.”
8. CI/CD
“The deployment pipeline automatically built, tested, scanned and deployed application artifacts using Infrastructure as Code.”
9. Result
“The architecture improved availability, deployment speed, scalability and operational visibility while reducing manual infrastructure management.”