Skip to content
Bill Liao
Go back

100 AWS interview Questions and Answers

Edit page

100 Most Frequently Asked AWS Interview Questions & Answers

Below is a practical AWS interview guide aimed at Senior Java / Spring Boot / Full-Stack / Cloud / Lead Software Engineer roles. The questions progress from fundamentals to architecture, security, DevOps, containers, databases, serverless, and system design.


1. AWS Fundamentals

1. What is AWS?

Answer:
Amazon Web Services (AWS) is a cloud computing platform providing on-demand infrastructure and managed services such as compute, storage, databases, networking, security, analytics, and AI.


2. What are the main benefits of AWS?

Answer:


3. What is an AWS Region?

Answer:
A Region is a geographical area containing multiple isolated Availability Zones (AZs).

Examples include:

Applications can be deployed across multiple Regions for disaster recovery or global availability.


4. What is an Availability Zone?

Answer:
An Availability Zone is an isolated location within an AWS Region containing one or more data centers.

For high availability, applications should generally distribute workloads across multiple AZs.


5. What is the difference between Region and Availability Zone?

RegionAvailability Zone
Geographical areaIsolated infrastructure location
Contains multiple AZsBelongs to one Region
Used for geographic resilienceUsed for high availability

6. What is the AWS Shared Responsibility Model?

Answer:
AWS is responsible for security of the cloud, while customers are responsible for security in the cloud.

AWS manages:

Customers manage, depending on the service:


7. What is AWS Well-Architected Framework?

Answer:
It provides architectural best practices based on six pillars:

  1. Operational Excellence
  2. Security
  3. Reliability
  4. Performance Efficiency
  5. Cost Optimization
  6. Sustainability

8. What is AWS account?

Answer:
An AWS account provides an isolated environment for AWS resources, billing, permissions, and security controls.

Organizations often use multiple accounts for:


9. What is AWS Organizations?

Answer:
AWS Organizations centrally manages multiple AWS accounts.

It supports:


10. What is AWS CLI?

Answer:
AWS CLI is a command-line interface for managing AWS resources.

Example:

aws s3 ls
aws ec2 describe-instances
aws iam list-users

2. IAM & Security

11. What is IAM?

Answer:
AWS Identity and Access Management controls who can access AWS resources and what actions they can perform.

Core concepts:


12. What is an IAM Role?

Answer:
An IAM Role is an identity that provides temporary permissions to AWS resources or applications.

For example, an EC2 instance can assume a role allowing it to read from S3 without storing AWS access keys on the server.


13. IAM User vs IAM Role?

IAM UserIAM Role
Long-term identityTemporary identity
Usually associated with a person/applicationAssumed by users/services
Can have credentialsUses temporary credentials
Less suitable for AWS workloadsPreferred for AWS workloads

14. What is an IAM Policy?

Answer:
An IAM policy is a JSON document defining permissions.

Example:

{
  "Effect": "Allow",
  "Action": "s3:GetObject",
  "Resource": "arn:aws:s3:::my-bucket/*"
}

15. What is least privilege?

Answer:
Least privilege means granting only the permissions required to perform a task.

Instead of:

s3:*

grant only:

s3:GetObject

when read access is sufficient.


16. What is MFA?

Answer:
Multi-Factor Authentication adds another authentication factor beyond a password.

For privileged AWS accounts, MFA is strongly recommended.


17. What is AWS KMS?

Answer:
AWS Key Management Service manages encryption keys.

It can be used to encrypt:


18. What is AWS Secrets Manager?

Answer:
Secrets Manager securely stores and manages secrets such as:

It also supports automatic secret rotation for supported services.


19. Secrets Manager vs Parameter Store?

Secrets ManagerParameter Store
Designed for secretsConfiguration + parameters
Secret rotationBasic parameter management
More specializedOften simpler/cheaper
Supports secret lifecycle managementSupports String/StringList/SecureString

20. What is AWS WAF?

Answer:
AWS WAF is a web application firewall used to protect applications from attacks such as:

It can be associated with services such as CloudFront and Application Load Balancer.


3. EC2 & Compute

21. What is Amazon EC2?

Answer:
Amazon Elastic Compute Cloud provides resizable virtual servers in AWS.

You control:


22. What is an AMI?

Answer:
An Amazon Machine Image is a template used to launch EC2 instances.

It can contain:


23. What is an EC2 Instance Type?

Answer:
An instance type defines the compute resources available to an EC2 instance.

Examples of categories:


24. What is an Auto Scaling Group?

Answer:
An Auto Scaling Group automatically maintains the desired number of EC2 instances.

It can:


25. What is an EC2 Launch Template?

Answer:
A Launch Template defines how EC2 instances should be created.

It can specify:


26. What is EC2 User Data?

Answer:
User Data is a script executed during instance initialization.

Example:

#!/bin/bash
yum update -y
yum install -y docker
systemctl start docker

27. What is a Security Group?

Answer:
A Security Group is a virtual firewall associated with AWS resources such as EC2.

Important characteristics:


28. Security Group vs NACL?

Security GroupNetwork ACL
Instance/resource levelSubnet level
StatefulStateless
Allow rulesAllow and deny rules
Evaluated after traffic reaches resourceControls subnet traffic

29. What is Elastic Load Balancing?

Answer:
Elastic Load Balancing distributes incoming traffic across multiple targets.

Common load balancers:


30. ALB vs NLB?

ALB — Application Load Balancer

NLB — Network Load Balancer


4. S3

31. What is Amazon S3?

Answer:
Amazon Simple Storage Service is an object storage service designed for high durability and scalability.

Typical uses:


32. What is an S3 Bucket?

Answer:
A bucket is a logical container for S3 objects.

Example:

s3://company-documents/

33. What is an S3 Object?

Answer:
An object consists of:

For example:

Key: invoices/2026/invoice-001.pdf

34. What is S3 Versioning?

Answer:
Versioning maintains multiple versions of an object.

It protects against:


35. What are S3 Storage Classes?

Answer:

Common classes include:

The choice depends on access frequency and retrieval requirements.


36. What is S3 Lifecycle Management?

Answer:
Lifecycle policies automatically transition or delete objects.

Example:

Day 0      → S3 Standard
Day 30     → Standard-IA
Day 90     → Glacier
Day 365    → Delete

37. Is S3 strongly consistent?

Answer:
Yes. Amazon S3 provides strong read-after-write consistency for object PUT and DELETE operations.


38. How do you secure an S3 bucket?

Answer:


39. What is S3 Pre-Signed URL?

Answer:
A pre-signed URL provides temporary access to an S3 object without making the bucket public.

Example use:

User → Application → Pre-signed URL → S3

40. S3 vs EBS?

S3EBS
Object storageBlock storage
Highly scalableAttached to EC2
Access via APIAppears as disk
Good for files/data lakesGood for OS/application disks

5. VPC & Networking

41. What is Amazon VPC?

Answer:
A Virtual Private Cloud provides an isolated logical network in AWS.

You control:


42. What is a subnet?

Answer:
A subnet is a range of IP addresses inside a VPC.

Subnets are associated with an Availability Zone.


43. Public vs Private Subnet?

Public subnet:
Has a route to an Internet Gateway.

Private subnet:
Does not have direct inbound internet access through an Internet Gateway.

Typical architecture:

Internet
   |
ALB
   |
Private Subnet
   |
Application
   |
Private Database

44. What is an Internet Gateway?

Answer:
An Internet Gateway enables communication between a VPC and the public internet.


45. What is a NAT Gateway?

Answer:
A NAT Gateway allows resources in private subnets to initiate outbound internet connections without allowing unsolicited inbound internet connections.

Example:

Private EC2
    |
NAT Gateway
    |
Internet

46. What is a Route Table?

Answer:
A route table determines where network traffic is sent.

Example:

0.0.0.0/0 → Internet Gateway

47. What is VPC Peering?

Answer:
VPC Peering connects two VPCs so resources can communicate privately.

It can connect VPCs in:


48. What is AWS Transit Gateway?

Answer:
Transit Gateway provides a centralized hub for connecting multiple VPCs and on-premises networks.

Instead of:

VPC A ↔ VPC B
VPC A ↔ VPC C
VPC B ↔ VPC C

you can use:

       Transit Gateway
       /      |      \
     VPC A  VPC B   VPC C

49. What is AWS Direct Connect?

Answer:
AWS Direct Connect provides a dedicated network connection between an on-premises environment and AWS.

It provides more predictable network performance than internet-based VPN connectivity.


50. What is AWS VPN?

Answer:
AWS Site-to-Site VPN establishes encrypted connectivity between an on-premises network and AWS.


6. RDS & Databases

51. What is Amazon RDS?

Answer:
Amazon Relational Database Service is a managed relational database service.

Supported engines include:


52. What are the benefits of RDS?

Answer:


53. What is RDS Multi-AZ?

Answer:
Multi-AZ provides a standby database in another Availability Zone for high availability.

The standby is primarily intended for failover rather than read scaling.


54. What is an RDS Read Replica?

Answer:
A Read Replica asynchronously replicates data from a source database and is used primarily to scale read workloads.


55. Multi-AZ vs Read Replica?

Multi-AZRead Replica
High availabilityRead scaling
Synchronous replication in typical configurationsAsynchronous replication
Automatic failoverApplication can route reads
StandbyReadable replica

56. What is Amazon Aurora?

Answer:
Aurora is AWS’s cloud-optimized relational database compatible with MySQL and PostgreSQL.

It separates compute and distributed storage and provides features designed for high availability and scalability.


57. RDS vs DynamoDB?

RDS:

DynamoDB:


58. What is DynamoDB?

Answer:
DynamoDB is a fully managed NoSQL database designed for high-scale, low-latency applications.


59. What is a DynamoDB Partition Key?

Answer:
The partition key determines how DynamoDB distributes data across partitions.

A good partition key should provide sufficient cardinality and distribute traffic evenly.


60. What is DynamoDB GSI?

Answer:
A Global Secondary Index allows queries using attributes other than the table’s primary key.


7. Lambda & Serverless

61. What is AWS Lambda?

Answer:
Lambda is a serverless compute service that executes code in response to events.

You don’t manage servers directly.


62. What are Lambda use cases?

Answer:


63. What triggers Lambda?

Answer:


64. What is Lambda Cold Start?

Answer:
A cold start occurs when AWS needs to initialize a new execution environment before executing a function.

It can increase initial request latency.


65. How can Lambda cold starts be reduced?

Answer:


66. What are Lambda limitations?

Answer:
Lambda has constraints around:

The exact limits depend on the current AWS service configuration.


67. What is API Gateway?

Answer:
Amazon API Gateway provides APIs for applications and can integrate with Lambda and other backend services.

It supports features such as:


68. API Gateway vs ALB?

API Gateway:

ALB:


69. What is AWS Step Functions?

Answer:
Step Functions orchestrates workflows using state machines.

Example:

Validate Order
      ↓
Charge Payment
      ↓
Reserve Inventory
      ↓
Send Confirmation

70. What is EventBridge?

Answer:
Amazon EventBridge is an event bus service used to route events between applications and AWS services.

It is useful for event-driven architectures.


8. Messaging & Event-Driven Architecture

71. What is Amazon SQS?

Answer:
Simple Queue Service is a managed message queue.

It decouples producers and consumers.

Producer → SQS → Consumer

72. Standard SQS vs FIFO SQS?

StandardFIFO
Very high throughputOrdered processing
At-least-once deliveryExactly-once processing support
Ordering not guaranteedOrdering guaranteed within message groups
Lower constraintsHigher ordering/deduplication guarantees

73. What is SNS?

Answer:
Amazon Simple Notification Service provides pub/sub messaging.

Example:

                    → Email
Application → SNS → → SQS
                    → Lambda

74. SNS vs SQS?

SNS: Push/fan-out messaging.

SQS: Queue-based asynchronous processing.

They are frequently used together.


75. What is Kinesis?

Answer:
Amazon Kinesis is used for real-time streaming data.

Use cases include:


76. SQS vs Kinesis?

SQSKinesis
Message queueData streaming
Consumer processingContinuous streams
Message-orientedStream-oriented
Simple decouplingReal-time streaming analytics

77. What is dead-letter queue?

Answer:
A DLQ stores messages that cannot be successfully processed after a configured number of attempts.

It allows engineers to:


78. What is idempotency?

Answer:
Idempotency means processing the same request multiple times produces the same business result.

For example, a payment request should not charge a customer twice if the same message is retried.


9. Containers & Kubernetes

79. What is Amazon ECS?

Answer:
Amazon Elastic Container Service is a managed container orchestration service.

It can run Docker containers without requiring Kubernetes.


80. What is Amazon EKS?

Answer:
Amazon Elastic Kubernetes Service is AWS’s managed Kubernetes service.

AWS manages much of the Kubernetes control plane while customers manage workloads and configuration.


81. ECS vs EKS?

ECSEKS
AWS-native orchestrationKubernetes
Simpler for many AWS workloadsKubernetes ecosystem
Easier operational modelMore flexibility
AWS-specificMore portable

82. What is AWS Fargate?

Answer:
Fargate is a serverless compute engine for containers.

You deploy containers without managing EC2 servers.

It can be used with:


83. ECS EC2 vs Fargate?

ECS on EC2:

Fargate:


84. How would you deploy a Spring Boot microservice on AWS?

Answer:

A typical architecture could be:

                  CloudFront
                      |
                     ALB
                      |
              ECS / EKS / EC2
                      |
              Spring Boot API
                 /         \
              Redis       RDS
                |
               SQS
                |
             Lambda

Container images can be stored in ECR, while CI/CD can be handled using AWS-native or third-party pipelines.


10. Monitoring & DevOps

85. What is Amazon CloudWatch?

Answer:
CloudWatch provides:


86. What is AWS CloudTrail?

Answer:
CloudTrail records API activity and account actions.

It is especially useful for:


87. CloudWatch vs CloudTrail?

CloudWatchCloudTrail
MonitoringAuditing
Metrics/logs/alarmsAPI activity
Application/infrastructure healthWho did what
Operational visibilityGovernance/security

88. What is AWS X-Ray?

Answer:
AWS X-Ray helps trace requests through distributed applications.

It can help identify:

This is particularly useful for microservices.


89. What is Infrastructure as Code?

Answer:
Infrastructure as Code defines infrastructure using code instead of manually creating resources.

Popular AWS IaC technologies include:


90. CloudFormation vs Terraform?

CloudFormation:

Terraform:


11. Architecture & System Design

91. How would you design a highly available AWS application?

Answer:

I would typically:

  1. Deploy across multiple AZs.
  2. Put an ALB in front of application instances.
  3. Use Auto Scaling or ECS/EKS.
  4. Keep application instances stateless.
  5. Use RDS Multi-AZ/Aurora for relational data.
  6. Use S3 for object storage.
  7. Use ElastiCache for caching where appropriate.
  8. Use SQS/EventBridge for asynchronous processing.
  9. Use CloudWatch for monitoring.
  10. Use CloudTrail for auditing.
  11. Use IAM roles and least privilege.
  12. Define infrastructure as code.

92. How would you design a scalable Spring Boot application on AWS?

Answer:

                  Route 53
                     |
                 CloudFront
                     |
                    WAF
                     |
                    ALB
                     |
          +----------+----------+
          |          |          |
        ECS        ECS        ECS
          |          |          |
          +----------+----------+
                     |
          +----------+----------+
          |                     |
       Aurora                ElastiCache
          |
       Read Replica

       Async workloads
             |
            SQS
             |
          Workers

The application should remain stateless so that additional instances can be added horizontally.


93. How would you design an AWS microservices architecture?

Answer:

A typical design could include:

                    API Gateway
                         |
                  Load Balancer
                         |
       +-----------------+----------------+
       |                 |                |
    Customer          Order           Payment
    Service           Service          Service
       |                 |                |
       +-----------------+----------------+
                         |
                  EventBridge / SNS
                         |
                       SQS
                         |
                      Workers

Each service should own its business logic and preferably its data boundary.


94. How would you handle database scaling?

Answer:

Depending on the workload:

Read-heavy:

Write-heavy:

Large datasets:


95. How would you design disaster recovery in AWS?

Answer:

Possible DR strategies include:

  1. Backup and restore
  2. Pilot light
  3. Warm standby
  4. Multi-site active/active

For critical applications, I would define:

Then choose an architecture based on business requirements and cost.


96. What is RTO?

Answer:
Recovery Time Objective is the maximum acceptable time required to restore service after a failure.

Example:

RTO = 30 minutes

means the system should be restored within 30 minutes.


97. What is RPO?

Answer:
Recovery Point Objective defines the maximum acceptable amount of data loss measured in time.

Example:

RPO = 5 minutes

means losing up to approximately five minutes of data may be acceptable.


98. How would you reduce AWS costs?

Answer:

I would look at:

The key is to optimize cost per business outcome, not simply minimize infrastructure cost.


99. How would you secure a production AWS environment?

Answer:

I would implement defense in depth:

IAM
 ↓
Organizations / SCP
 ↓
VPC
 ↓
Security Groups / NACL
 ↓
WAF
 ↓
Application Security
 ↓
Encryption
 ↓
Secrets Management
 ↓
CloudTrail / CloudWatch
 ↓
GuardDuty / Security Monitoring

Key principles include:


100. Describe a production AWS architecture you have designed.

Answer:

A strong interview answer should follow this structure:

1. Business problem

“The system needed to support a highly available client onboarding platform with significant transaction volume.”

2. Architecture

“We used Spring Boot microservices deployed in AWS, behind load balancing, with asynchronous processing through messaging.”

3. Data

“Transactional data was stored in a relational database, while object/document data was stored in S3.”

4. Scalability

“The services were stateless and horizontally scalable. Auto Scaling allowed capacity to increase based on demand.”

5. Reliability

“We deployed workloads across multiple Availability Zones and designed asynchronous operations to tolerate transient failures.”

6. Security

“IAM roles, least-privilege policies, encryption, private networking and centralized auditing were used.”

7. Observability

“CloudWatch metrics and logs, distributed tracing, and centralized alerting were used to identify production issues.”

8. CI/CD

“The deployment pipeline automatically built, tested, scanned and deployed application artifacts using Infrastructure as Code.”

9. Result

“The architecture improved availability, deployment speed, scalability and operational visibility while reducing manual infrastructure management.”


Edit page
Share this post:

Previous Post
100 Microsoft Azure interview Questions and Answers
Next Post
100 Microservice Questions and Answers