<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="9706" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/amazon-awsaa" lastchanged="2026-03-16T13:29:18+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Advanced Architecting on AWS</title><productcode>AWSAA</productcode><vendorcode>AW</vendorcode><vendorname>Amazon Web Services</vendorname><fullproductcode>AW-AWSAA</fullproductcode><version>3</version><objective>&lt;h4&gt;In this course, you will learn to:&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Review the AWS Well-Architected Framework to ensure understanding of best cloud design practices by responding to poll questions while following a graphic presentation&lt;/li&gt;&lt;li&gt;Demonstrate the ability to secure Amazon Simple Storage Service (Amazon S3) virtual private cloud (VPC) endpoint connections in a lab environment&lt;/li&gt;&lt;li&gt;Identify how to implement centralized permissions management and reduce risk using AWS Organizations organizational units (OUs) and service control policies (SCPs) with AWS Single Sign-On&lt;/li&gt;&lt;li&gt;Compare the permissions management capabilities of OUs, SCPs, and AWS SSO with and without AWS Control Tower to determine best practices based on use cases&lt;/li&gt;&lt;li&gt;Discuss AWS hybrid network designs to address traffic increases and streamline remote work while ensuring FIPS 140-2 Level 2, or Level 3 security compliance&lt;/li&gt;&lt;li&gt;Explore the solutions and products available to design a hybrid infrastructure, including access to 5G networks, to optimize service and reduce latency while maintaining high security for critical on premises applications&lt;/li&gt;&lt;li&gt;Explore ways to simplify the connection configurations between applications and high-performance workloads across global networks&lt;/li&gt;&lt;li&gt;Demonstrate the ability to configure a transit gateway in a lab environment&lt;/li&gt;&lt;li&gt;Identify and discuss container solutions and define container management options&lt;/li&gt;&lt;li&gt;Build and test a container in a lab environment&lt;/li&gt;&lt;li&gt;Examine how the AWS developer tools optimize the CI/CD pipeline with updates based on near-real-time data&lt;/li&gt;&lt;li&gt;Identify the anomaly detection and protection services that AWS offers to defend against DDoS attacks&lt;/li&gt;&lt;li&gt;Identify ways to secure data in transit, at rest, and in use with AWS Key Management Service (AWS KMS) and AWS Secrets Manager&lt;/li&gt;&lt;li&gt;Determine the best data management solution based on frequency of access, and data query and analysis needs&lt;/li&gt;&lt;li&gt;Set up a data lake and examine the advantages of this type of storage configuration to crawl and query data in a lab environment&lt;/li&gt;&lt;li&gt;Identify solutions to optimize edge services to eliminate latency, reduce inefficiencies, and mitigate risks&lt;/li&gt;&lt;li&gt;Identify the components used to automate the scaling of global applications using geolocation and traffic control&lt;/li&gt;&lt;li&gt;Deploy and activate an AWS Storage Gateway file gateway and AWS DataSync in a lab environment&lt;/li&gt;&lt;li&gt;Review AWS cost management tools to optimize costs while ensuring speed and performance&lt;/li&gt;&lt;li&gt;Review migration tools, services, and processes that AWS provides to implement effective cloud operation models based on use cases and business needs&lt;/li&gt;&lt;li&gt;Provide evidence of your ability to apply the technical knowledge and experience gained in the course to improve business practices by completing a Capstone Project&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;We recommend that attendees of this course have:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Knowledge and experience with core AWS services from the compute, storage, networking, and AWS Identity and Access Management (IAM) categories&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;
&lt;li&gt;At least one of the following:&lt;ul&gt;
&lt;li&gt;Attended the &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/amazon-awsa&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Architecting on AWS &lt;span class=&quot;fl-prod-pcode&quot;&gt;(AWSA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; classroom training OR&lt;/li&gt;&lt;li&gt;Achieved the AWS Certified Solutions Architect - Associate certification OR&lt;/li&gt;&lt;li&gt;Have at least 1 year of experience operating AWS workloads&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;h4&gt;Who should take this course:
&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Cloud architects&lt;/li&gt;&lt;li&gt;Solutions architects&lt;/li&gt;&lt;li&gt;Anyone who designs solutions for cloud infrastructures&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;h4&gt;Day 1&lt;/h4&gt;&lt;h5&gt;Module 1: Reviewing Architecting Concepts&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Group Exercise: Review Architecting on AWS core best practices&lt;/li&gt;&lt;li&gt;Lab 1: Securing Amazon S3 VPC Endpoint Communications&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2: Single to Multiple Accounts&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;AWS Organizations for multi-account access and permissions&lt;/li&gt;&lt;li&gt;AWS SSO to simplify access and authentication across AWS accounts and third-party services&lt;/li&gt;&lt;li&gt;AWS Control Tower&lt;/li&gt;&lt;li&gt;Permissions, access, and authentication&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: Hybrid Connectivity&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;AWS Client VPN authentication and control&lt;/li&gt;&lt;li&gt;AWS Site-to-Site VPN&lt;/li&gt;&lt;li&gt;AWS Direct Connect for hybrid public and private connections&lt;/li&gt;&lt;li&gt;Increasing bandwidth and reducing cost&lt;/li&gt;&lt;li&gt;Basic, high, and maximum resiliency&lt;/li&gt;&lt;li&gt;Amazon Route 53 Resolver DNS resolution&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: Specialized Infrastructure&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;AWS Storage Gateway solutions&lt;/li&gt;&lt;li&gt;On-demand VMware Cloud on AWS&lt;/li&gt;&lt;li&gt;Extending cloud infrastructure services with AWS Outposts&lt;/li&gt;&lt;li&gt;AWS Local Zones for latency-sensitive workloads&lt;/li&gt;&lt;li&gt;Your 5G network with and without AWS Wavelength&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5: Connecting Networks&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Simplifying private subnet connections&lt;/li&gt;&lt;li&gt;VPC isolation with a shared services VPC&lt;/li&gt;&lt;li&gt;Transit Gateway Network Manager and VPC Reachability Analyzer&lt;/li&gt;&lt;li&gt;AWS Resource Access Manager&lt;/li&gt;&lt;li&gt;AWS PrivateLink and endpoint services&lt;/li&gt;&lt;li&gt;Lab 2: Configuring Transit Gateways&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 2&lt;/h4&gt;&lt;h5&gt;Module 6: Containers&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Container solutions compared to virtual machines&lt;/li&gt;&lt;li&gt;Docker benefits, components, solutions architecture, and versioning&lt;/li&gt;&lt;li&gt;Container hosting on AWS to reduce cost&lt;/li&gt;&lt;li&gt;Managed container services: Amazon Elastic Container Service (Amazon ECS) and Amazon Elastic Kubernetes Service (Amazon EKS)&lt;/li&gt;&lt;li&gt;AWS Fargate&lt;/li&gt;&lt;li&gt;Lab 3: Deploying an Application with Amazon ECS on Fargate&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 7: Continuous Integration/Continuous Delivery (CI/CD)&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;CI/CD solutions and impact&lt;/li&gt;&lt;li&gt;CI/CD automation with AWS CodePipeline&lt;/li&gt;&lt;li&gt;Deployment models&lt;/li&gt;&lt;li&gt;AWS CloudFormation StackSets to improve deployment management&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 8: High Availability and DDoS Protection&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Common DDoS attacks layers&lt;/li&gt;&lt;li&gt;AWS WAF&lt;/li&gt;&lt;li&gt;AWS WAF web access control lists (ACLs), real-time metrics, logs, and security automation&lt;/li&gt;&lt;li&gt;AWS Shield Advanced services and AWS DDoS Response Team (DRT) services&lt;/li&gt;&lt;li&gt;AWS Network Firewall and AWS Firewall Manager to protect accounts at scale&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 9: Securing Data&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What cryptography is, why you would use it, and how to use it&lt;/li&gt;&lt;li&gt;AWS KMS&lt;/li&gt;&lt;li&gt;AWS CloudHSM architecture&lt;/li&gt;&lt;li&gt;FIPS 140-2 Level 2 and Level 3 encryption&lt;/li&gt;&lt;li&gt;Secrets Manager&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 10: Large-Scale Data Stores&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Amazon S3 data storage management including storage class, inventory, metrics, and policies&lt;/li&gt;&lt;li&gt;Data lake vs. data warehouse: Differences, benefits, and examples&lt;/li&gt;&lt;li&gt;AWS Lake Formation solutions, security, and control&lt;/li&gt;&lt;li&gt;Lab 4: Setting Up a Data Lake with Lake Formation&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 3&lt;/h4&gt;&lt;h5&gt;Module 11: Large-Scale Applications&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;What edge services are and why you would use them&lt;/li&gt;&lt;li&gt;Improve performance and mitigate risk with Amazon CloudFront&lt;/li&gt;&lt;li&gt;Lambda@Edge&lt;/li&gt;&lt;li&gt;AWS Global Accelerator: IP addresses, intelligent traffic distribution, and health checks&lt;/li&gt;&lt;li&gt;Lab 5: Migrating an On-Premises NFS Share Using AWS DataSync and Storage Gateway&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 12: Optimizing Cost&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;On-premises and cloud acquisition/deprecation cycles&lt;/li&gt;&lt;li&gt;Cloud cost management tools including reporting, control, and tagging&lt;/li&gt;&lt;li&gt;Examples and analysis of the five pillars of cost optimization&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 13: Migrating Workloads&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Business drivers and the process for migration&lt;/li&gt;&lt;li&gt;Successful customer practices&lt;/li&gt;&lt;li&gt;The 7 Rs to migrate and modernize&lt;/li&gt;&lt;li&gt;Migration tools and services from AWS&lt;/li&gt;&lt;li&gt;Migrating databases and large data stores&lt;/li&gt;&lt;li&gt;AWS Schema Conversion Tool (AWS SCT)&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 14: Capstone Project&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Use the Online Course Supplement (OCS) to review use cases, investigate data, and answer architecting design questions about Transit Gateway, hybrid connectivity, migration, and cost optimization&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>In this course, you will learn to:


- Review the AWS Well-Architected Framework to ensure understanding of best cloud design practices by responding to poll questions while following a graphic presentation
- Demonstrate the ability to secure Amazon Simple Storage Service (Amazon S3) virtual private cloud (VPC) endpoint connections in a lab environment
- Identify how to implement centralized permissions management and reduce risk using AWS Organizations organizational units (OUs) and service control policies (SCPs) with AWS Single Sign-On
- Compare the permissions management capabilities of OUs, SCPs, and AWS SSO with and without AWS Control Tower to determine best practices based on use cases
- Discuss AWS hybrid network designs to address traffic increases and streamline remote work while ensuring FIPS 140-2 Level 2, or Level 3 security compliance
- Explore the solutions and products available to design a hybrid infrastructure, including access to 5G networks, to optimize service and reduce latency while maintaining high security for critical on premises applications
- Explore ways to simplify the connection configurations between applications and high-performance workloads across global networks
- Demonstrate the ability to configure a transit gateway in a lab environment
- Identify and discuss container solutions and define container management options
- Build and test a container in a lab environment
- Examine how the AWS developer tools optimize the CI/CD pipeline with updates based on near-real-time data
- Identify the anomaly detection and protection services that AWS offers to defend against DDoS attacks
- Identify ways to secure data in transit, at rest, and in use with AWS Key Management Service (AWS KMS) and AWS Secrets Manager
- Determine the best data management solution based on frequency of access, and data query and analysis needs
- Set up a data lake and examine the advantages of this type of storage configuration to crawl and query data in a lab environment
- Identify solutions to optimize edge services to eliminate latency, reduce inefficiencies, and mitigate risks
- Identify the components used to automate the scaling of global applications using geolocation and traffic control
- Deploy and activate an AWS Storage Gateway file gateway and AWS DataSync in a lab environment
- Review AWS cost management tools to optimize costs while ensuring speed and performance
- Review migration tools, services, and processes that AWS provides to implement effective cloud operation models based on use cases and business needs
- Provide evidence of your ability to apply the technical knowledge and experience gained in the course to improve business practices by completing a Capstone Project</objective_plain><essentials_plain>We recommend that attendees of this course have:



- Knowledge and experience with core AWS services from the compute, storage, networking, and AWS Identity and Access Management (IAM) categories

- At least one of the following:
- Attended the Architecting on AWS (AWSA) classroom training OR
- Achieved the AWS Certified Solutions Architect - Associate certification OR
- Have at least 1 year of experience operating AWS workloads</essentials_plain><audience_plain>Who should take this course:



- Cloud architects
- Solutions architects
- Anyone who designs solutions for cloud infrastructures</audience_plain><outline_plain>Day 1

Module 1: Reviewing Architecting Concepts


- Group Exercise: Review Architecting on AWS core best practices
- Lab 1: Securing Amazon S3 VPC Endpoint Communications
Module 2: Single to Multiple Accounts


- AWS Organizations for multi-account access and permissions
- AWS SSO to simplify access and authentication across AWS accounts and third-party services
- AWS Control Tower
- Permissions, access, and authentication
Module 3: Hybrid Connectivity


- AWS Client VPN authentication and control
- AWS Site-to-Site VPN
- AWS Direct Connect for hybrid public and private connections
- Increasing bandwidth and reducing cost
- Basic, high, and maximum resiliency
- Amazon Route 53 Resolver DNS resolution
Module 4: Specialized Infrastructure


- AWS Storage Gateway solutions
- On-demand VMware Cloud on AWS
- Extending cloud infrastructure services with AWS Outposts
- AWS Local Zones for latency-sensitive workloads
- Your 5G network with and without AWS Wavelength
Module 5: Connecting Networks


- Simplifying private subnet connections
- VPC isolation with a shared services VPC
- Transit Gateway Network Manager and VPC Reachability Analyzer
- AWS Resource Access Manager
- AWS PrivateLink and endpoint services
- Lab 2: Configuring Transit Gateways
Day 2

Module 6: Containers


- Container solutions compared to virtual machines
- Docker benefits, components, solutions architecture, and versioning
- Container hosting on AWS to reduce cost
- Managed container services: Amazon Elastic Container Service (Amazon ECS) and Amazon Elastic Kubernetes Service (Amazon EKS)
- AWS Fargate
- Lab 3: Deploying an Application with Amazon ECS on Fargate
Module 7: Continuous Integration/Continuous Delivery (CI/CD)


- CI/CD solutions and impact
- CI/CD automation with AWS CodePipeline
- Deployment models
- AWS CloudFormation StackSets to improve deployment management
Module 8: High Availability and DDoS Protection


- Common DDoS attacks layers
- AWS WAF
- AWS WAF web access control lists (ACLs), real-time metrics, logs, and security automation
- AWS Shield Advanced services and AWS DDoS Response Team (DRT) services
- AWS Network Firewall and AWS Firewall Manager to protect accounts at scale
Module 9: Securing Data


- What cryptography is, why you would use it, and how to use it
- AWS KMS
- AWS CloudHSM architecture
- FIPS 140-2 Level 2 and Level 3 encryption
- Secrets Manager
Module 10: Large-Scale Data Stores


- Amazon S3 data storage management including storage class, inventory, metrics, and policies
- Data lake vs. data warehouse: Differences, benefits, and examples
- AWS Lake Formation solutions, security, and control
- Lab 4: Setting Up a Data Lake with Lake Formation
Day 3

Module 11: Large-Scale Applications


- What edge services are and why you would use them
- Improve performance and mitigate risk with Amazon CloudFront
- Lambda@Edge
- AWS Global Accelerator: IP addresses, intelligent traffic distribution, and health checks
- Lab 5: Migrating an On-Premises NFS Share Using AWS DataSync and Storage Gateway
Module 12: Optimizing Cost


- On-premises and cloud acquisition/deprecation cycles
- Cloud cost management tools including reporting, control, and tagging
- Examples and analysis of the five pillars of cost optimization
Module 13: Migrating Workloads


- Business drivers and the process for migration
- Successful customer practices
- The 7 Rs to migrate and modernize
- Migration tools and services from AWS
- Migrating databases and large data stores
- AWS Schema Conversion Tool (AWS SCT)
Module 14: Capstone Project


- Use the Online Course Supplement (OCS) to review use cases, investigate data, and answer architecting design questions about Transit Gateway, hybrid connectivity, migration, and cost optimization</outline_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="KZ" currency="USD">1500.00</price><price country="KE" currency="USD">1480.00</price><price country="KW" currency="USD">1480.00</price><price country="MA" currency="USD">1480.00</price><price country="TN" currency="USD">1480.00</price><price country="LB" currency="USD">1480.00</price><price country="JO" currency="USD">1480.00</price><price country="LR" currency="USD">1480.00</price><price country="DZ" currency="USD">1480.00</price><price country="SA" currency="USD">1850.00</price><price country="OM" currency="USD">1850.00</price><price country="QA" currency="USD">1850.00</price><price country="ZA" currency="USD">1450.00</price><price country="AR" currency="USD">1395.00</price><price country="CL" currency="USD">1395.00</price><price country="PE" currency="USD">1395.00</price><price country="CO" currency="USD">1485.00</price><price country="MX" currency="USD">1485.00</price><price country="BR" currency="USD">1485.00</price><price country="P3" currency="USD">1395.00</price><price country="PA" currency="USD">1395.00</price><price country="CR" currency="USD">1485.00</price><price country="US" currency="USD">2025.00</price><price country="IT" currency="EUR">1650.00</price><price country="SI" currency="EUR">1750.00</price><price country="AE" currency="USD">1800.00</price><price country="RU" currency="RUB">127500.00</price><price country="SG" currency="USD">1895.00</price><price country="IL" currency="ILS">9320.00</price><price country="GR" currency="EUR">1750.00</price><price country="MK" currency="EUR">1750.00</price><price country="BE" currency="EUR">2195.00</price><price country="HU" currency="EUR">1750.00</price><price country="DE" currency="EUR">1995.00</price><price country="FR" currency="EUR">2510.00</price><price country="AT" currency="EUR">1995.00</price><price country="PL" currency="PLN">4900.00</price><price country="GB" currency="GBP">2655.00</price><price country="CH" currency="CHF">3150.00</price><price country="CA" currency="CAD">2795.00</price><price country="SE" currency="EUR">1995.00</price><price country="NL" currency="EUR">2395.00</price></pricelist><miles/></course>