PGCP-BDA · February 2026 · Linux & Cloud Computing

Cloud Computing,
from first principles to AWS & Azure.

A complete revision guide built around your syllabus. Every concept is explained in plain language with real Indian examples — IRCTC, UPI, Hotstar, Zomato — so the ideas stick. Use the left navigation to jump to any topic.

Session 8 · Topic 01

What is Cloud Computing?

The one-line definition: Cloud computing is renting computing resources (servers, storage, databases, networking, software) over the internet, paying only for what you use, instead of buying and maintaining your own hardware.

Real-World Analogy — Electricity

Before electricity grids, every factory had its own generator. They had to maintain it, fuel it, and over-provision it. Today, you just plug into the grid and pay a monthly bill. Cloud computing did the same thing for computing power — you plug into AWS/Azure/GCP and pay only for what you consume.

The Official NIST Definition

The US National Institute of Standards and Technology (NIST) defines cloud computing as a model for enabling on-demand network access to a shared pool of configurable computing resources (networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal management effort.

The Indian Context — Why It Matters Now

  • IRCTC handles 10+ lakh ticket bookings daily. During Tatkal, the load spikes 50× in 10 minutes. Without cloud's elasticity, the servers would crash.
  • UPI processed over 16 billion transactions in a single month in 2024. The NPCI backend uses cloud infrastructure to scale instantly.
  • JioCinema streamed IPL 2024 finals to 6+ crore concurrent viewers — only possible because cloud auto-scales.
  • Zomato & Swiggy see 5× traffic during dinner hours. They use cloud auto-scaling so customers don't get "service unavailable".
Session 8 · Topic 02

Cloud Paradigms

A "paradigm" simply means a way of thinking. Cloud computing changes the way we think about IT in three big ways:

Paradigm 1
CapEx → OpEx

Old way: buy a ₹10 lakh server (Capital Expenditure). New way: rent it for ₹500/day (Operating Expenditure). You shift from a one-time massive purchase to a small monthly bill.

Paradigm 2
Own → Rent

You don't own the servers, the AC, the diesel generator, or the data centre security. The cloud provider owns it. You just use it like a tenant.

Paradigm 3
Fixed → Elastic

Old way: buy capacity for your peak load (sits idle 80% of time). New way: capacity grows and shrinks with your actual usage. Pay only for what you use.

Why This Matters

A typical Indian startup like a small fintech can launch a product on AWS for ₹3,000–₹5,000/month. Ten years ago, the same setup would have needed ₹15–20 lakh upfront for servers, plus ongoing electricity, AMC, and IT staff costs. This shift is what enabled the entire Indian startup boom.

Session 8 · Topic 03

The 5 Essential Characteristics of Cloud

NIST identifies 5 essential characteristics that something must have to be called "cloud". If even one is missing, it's not real cloud computing.

CharacteristicWhat it MeansIndian Example
1. On-Demand Self-Service You can spin up a server yourself, instantly, with no human approval. Just click a button or run a command. You sign up on AWS at 2 AM and launch an EC2 instance in 90 seconds without calling anyone.
2. Broad Network Access Resources are accessible over the internet from any device — laptop, mobile, tablet. You access your Gmail from your office desktop, your phone on the local train, and your laptop at home — same data everywhere.
3. Resource Pooling The provider pools physical resources to serve many customers. You don't know which physical server you're on — it could change. This is called multi-tenancy. Your EC2 instance and a Bangalore startup's instance might be running on the same physical machine in Mumbai data centre, but completely isolated from each other.
4. Rapid Elasticity Resources can scale up or down automatically, in minutes, based on demand. Hotstar adds 1000 servers in 5 minutes when an India-Pakistan match starts, and removes them after the match ends.
5. Measured Service Usage is monitored and billed per second/minute/GB. You pay only for what you use. Your AWS bill at the end of the month shows exactly: "EC2 ran for 743.2 hours = ₹2,847.50". Like a Jio bill — pay-per-GB.

The Benefits — Why Companies Move to Cloud

💰 Cost Savings

No upfront hardware purchase, no data centre, no diesel generator, no IT staff for hardware. A college project costs ₹0 (free tier) instead of ₹50,000+ for a physical server.

⚡ Speed & Agility

Launching a server takes 60 seconds, not 6 weeks. Try an idea today, kill it tomorrow if it doesn't work. This is why startups can iterate 10× faster than traditional companies.

🌍 Global Reach

One click and your app is live in Mumbai, Singapore, Frankfurt, and Virginia. Try doing that with on-premise — you'd need 4 data centres.

🔒 Better Security

AWS spends billions on security. A small Indian company cannot match Amazon's army of security engineers, 24×7 monitoring, and compliance certifications.

📈 Auto-Scaling

Traffic doubles? Cloud automatically adds servers. Traffic drops? It removes them. Your bill matches your business — never pay for idle capacity.

🔁 High Availability

Cloud providers offer 99.99% uptime (less than 1 hour downtime per year). Mumbai data centre goes down? Your app automatically fails over to the Hyderabad region.

Session 8 · Topic 04

The Big 3 Cloud Vendors

Globally, three companies dominate the cloud market. Together they hold about 65% of global cloud spend.

AWS — Amazon Web Services

Launched: 2006 · Market Share: ~31%
Strength: Biggest, most mature, widest service catalogue (200+ services). Industry default for startups.
India Regions: Mumbai, Hyderabad

Azure — Microsoft

Launched: 2010 · Market Share: ~25%
Strength: Best for enterprises already using Microsoft (Windows Server, SQL Server, Office 365, Active Directory).
India Regions: Pune, Chennai, Mumbai

GCP — Google Cloud Platform

Launched: 2008 · Market Share: ~11%
Strength: Strongest in data analytics, machine learning, and Kubernetes (which Google invented).
India Regions: Mumbai, Delhi NCR

For Indian Students — Which Should You Learn?

Start with AWS. It has the most jobs in the Indian market (TCS, Infosys, Wipro, almost every startup uses it). Once you understand AWS, Azure and GCP feel familiar — the concepts are the same, only the names change. EC2 in AWS = Virtual Machines in Azure = Compute Engine in GCP.

Service Name Mapping — A Quick Reference

What it doesAWSAzureGCP
Virtual MachinesEC2Virtual MachinesCompute Engine
Object StorageS3Blob StorageCloud Storage
Serverless FunctionsLambdaAzure FunctionsCloud Functions
Managed SQL DatabaseRDSAzure SQL DatabaseCloud SQL
NoSQL DatabaseDynamoDBCosmos DBFirestore / Bigtable
Container ServiceECS / EKSAKSGKE
Virtual NetworkVPCVirtual Network (VNet)VPC
CDNCloudFrontAzure CDNCloud CDN
DNSRoute 53Azure DNSCloud DNS
Session 8 · Self-Learning

Why On-Premise Infrastructure Struggles

"On-premise" (or "on-prem") means servers physically located in your own office or data centre. Before cloud, this was the only option. Here's why it struggles in the modern world:

The Capacity Planning Trap

Imagine you run a food delivery app like Swiggy. Your traffic looks like this:

  • 3 AM to 11 AM — low traffic (10% of peak)
  • 1 PM & 8 PM — peak traffic (100%)
  • Festive day (Diwali) — 3× peak (300%)

If you buy on-premise servers, you must size them for the worst case — 300%. That means for 95% of the year, 70% of your hardware sits idle, eating electricity and depreciating. You paid ₹2 crore for hardware you barely use.

TIME → CAPACITY On-Prem (fixed) Actual demand ↑ Wasted capacity you paid for
Fig 1 · On-Premise: pay for peak, waste during off-peak

The 6 Hard Problems of On-Premise

ProblemWhat Goes Wrong
1. Slow ProvisioningNeed a new server? Place an order with Dell/HP. Wait 4-8 weeks for delivery. Then install, configure, and test for another week. Cloud takes 60 seconds.
2. Over-ProvisioningYou buy for peak load. Resources sit idle 80% of the time. Massive capital waste.
3. Under-ProvisioningIf you guess wrong and traffic spikes, your site crashes. Remember IRCTC during Tatkal 10 years ago? Constant downtime.
4. Maintenance BurdenYou manage AC, UPS, diesel generator, fire suppression, physical security, OS patches, hardware failures. You need a 5-person IT team minimum.
5. Disaster RecoveryIf your Mumbai office floods (like 2005), all servers go down. Setting up a backup data centre in Bangalore costs another ₹2 crore.
6. Geographic ReachWant users in the US to access fast? You need a data centre in the US. With cloud, just click "deploy to N. Virginia region".
Session 9-10 · Topic 06

SaaS — Software as a Service

Definition: SaaS is software delivered over the internet on a subscription basis. You don't install it, you don't update it, you don't host it. You just log in and use it.

Daily SaaS You Already Use

Gmail, WhatsApp Web, Google Docs, Zoom, Netflix, Hotstar, Canva, Notion, Slack, Spotify, Microsoft 365, Salesforce, Zoho CRM, Tally on Cloud, Freshdesk, RazorpayX — every one of these is SaaS. You don't install Gmail on your laptop; you just open the browser.

Traditional Software vs SaaS

AspectTraditional Packaged SoftwareSaaS
DeliveryCD/DVD, installer (.exe)Browser, app login
PaymentOne-time license (₹15,000 for MS Office 2010)Monthly/yearly subscription (₹500/month for Microsoft 365)
UpdatesYou manually upgrade, sometimes pay againAuto-updated by vendor — always latest version
HardwareNeeds your PC's storage, RAM, CPUNeeds only internet + browser
Multi-deviceBought for 1 PC, can't use on phoneSame account works on laptop, mobile, tablet
BackupYour responsibilityVendor's responsibility
ExampleTally ERP installed on shop's PCTally on Cloud — access from anywhere

✓ Pros of SaaS

  • Zero installation — open browser, done
  • Always latest version — no manual upgrades
  • Pay-as-you-go — cancel anytime
  • Multi-device access — laptop, phone, tablet, anywhere
  • Auto-backup — vendor handles data safety
  • Collaboration — multiple users edit same document live (Google Docs)
  • No IT staff needed — vendor handles everything
  • Predictable cost — fixed monthly bill

✗ Cons of SaaS

  • Needs internet — no Wi-Fi, no work (mostly)
  • Less customization — you get what the vendor built
  • Data privacy — your data sits on vendor's servers
  • Long-term cost — ₹500/month × 5 years = ₹30,000 (vs ₹15K one-time)
  • Vendor lock-in — hard to move 5 years of Salesforce data elsewhere
  • Vendor outages — if AWS goes down, your SaaS goes down
  • Limited integrations — must use what the vendor allows
  • Compliance concerns — RBI, SEBI rules on data localization

Famous SaaS Examples (Indian + Global)

Productivity
Google Workspace

Gmail, Docs, Sheets, Slides, Meet. Used by 80%+ of Indian startups. ₹136/user/month for the Business Starter plan.

CRM
Zoho CRM (Indian!)

Made in Chennai. Manages customer relationships for 2.5+ lakh businesses globally. Starts at ₹720/user/month.

Accounting
Tally on Cloud

The traditional Tally ERP, now delivered as a SaaS. Access your books from anywhere — especially useful for CAs with multiple clients.

Entertainment
JioHotstar

Streaming SaaS. You don't download movies — you stream them. The "software" is the video player + content library.

Communication
Zoom / Google Meet

Video conferencing SaaS. No installation needed (browser works). Pay per host per month.

Design
Canva

Graphic design tool that runs in the browser. Free tier + Pro at ₹500/month. Replaced Photoshop for non-designers.

Session 9-10 · Topic 07

IaaS — Infrastructure as a Service

Definition: IaaS gives you the raw building blocks of computing — virtual machines, storage, networks, firewalls — over the internet. You install the OS, you install the database, you write the application. The provider just gives you the empty hardware.

Real-World Analogy — Rent an Empty Flat

IaaS is like renting an empty 2BHK flat. The landlord (cloud provider) gives you walls, electricity, water, security. You bring your own furniture, AC, paint colour, kitchen setup. You have total freedom, but you do all the work.

What You Get with IaaS

  • Virtual Machines (VMs) — like a remote computer you rent (AWS EC2, Azure VM)
  • Storage — block storage (like a hard drive) and object storage (S3, Blob)
  • Networking — virtual networks, firewalls, load balancers
  • Operating System — you choose: Ubuntu, Amazon Linux, Windows Server, RHEL

Famous IaaS Examples

ProviderServiceWhat it is
AWSEC2, EBS, VPC, S3The original and most popular IaaS
MicrosoftAzure VMs, Azure Disks, VNetStrong in enterprise/Windows shops
GoogleCompute Engine, Persistent DisksStrong in analytics workloads
DigitalOceanDropletsPopular with Indian developers — simpler & cheaper than AWS
Linode / HetznerVMsBudget alternatives, popular with hobby projects
When to Use IaaS

Choose IaaS when you need maximum control: custom OS tuning, specific kernel modules, legacy applications, or specialised software that doesn't run on managed platforms. Example — a TCS team migrating an old Oracle Forms application from a SPARC server to cloud would use IaaS.

Session 9-10 · Topic 08

PaaS — Platform as a Service

Definition: PaaS gives you a ready-made platform to run your applications. You write code; the platform handles OS, runtime, scaling, patching, load balancing. You don't manage servers at all.

Real-World Analogy — Serviced Apartment

PaaS is like a fully furnished serviced apartment. Furniture, AC, geyser, kitchen, WiFi — all included. You just walk in with your bags (your code) and start living. Less freedom than an empty flat, but zero setup hassle.

Famous PaaS Examples

AWS Elastic Beanstalk

Upload your Python/Java/Node.js code. AWS handles servers, scaling, load balancers automatically.

Azure App Service

Deploy .NET, Java, Python, Node.js apps. Microsoft handles everything underneath.

Google App Engine

Original PaaS (2008). Just deploy and forget — auto-scales from 0 to millions of users.

Heroku

git push heroku main and your app is live. Wildly popular with Indian devs for MVPs.

Vercel / Netlify

PaaS for frontend/JAMstack apps. Push code to GitHub → auto-deploys in seconds.

Render / Railway

Modern Heroku alternatives. Popular with Indian indie hackers and side-project builders.

When to Use PaaS

Choose PaaS when you want to focus on writing application code, not on managing servers. A 2-person Indian startup building an MVP should use PaaS — they don't have the time or staff to manage EC2 instances, patches, and auto-scaling groups.

Session 9-10 · Topic 09

Virtualization — The Engine of Cloud

Definition: Virtualization is the technology that allows one physical server to be split into many virtual servers, each running its own OS, completely isolated from the others. This is the magic that makes cloud possible.

Analogy — A Mumbai Chawl Building

One physical chawl building (the server) is divided into 20 separate rooms (VMs). Each family lives independently — their own kitchen (OS), their own belongings (apps), their own electricity meter (resources). They share the building (hardware) but never interfere with each other.

Why Cloud Needs Virtualization

  • Multi-tenancy — Many customers can safely share one big server
  • Efficient hardware use — A 64-core server can run 30 VMs instead of sitting 90% idle
  • Isolation — If one customer's VM crashes, others are unaffected
  • Fast provisioning — Creating a VM takes 60 seconds (creating a physical server takes weeks)
  • Mobility — VMs can be moved between physical machines without users noticing

Types of Virtualization

TypeWhat It VirtualizesExample
1. Server VirtualizationOne physical server → many virtual servers (VMs)VMware ESXi, Microsoft Hyper-V, KVM, Xen — basis of EC2, Azure VMs
2. Storage VirtualizationPools many physical disks into one virtual storage poolSAN/NAS storage, EBS, Ceph
3. Network VirtualizationOne physical network → many virtual networks (VLANs, VPCs)AWS VPC, VMware NSX, software-defined networking
4. Desktop Virtualization (VDI)Your "Windows desktop" runs on a remote server, you just see the screenCitrix Workspace, AWS WorkSpaces — used by Indian BPOs & banks
5. Application VirtualizationAn app runs in an isolated environment, not directly on the OSDocker containers (technically containerization), VMware ThinApp
6. OS-Level VirtualizationOne OS kernel runs many isolated user spaces (containers)Docker, LXC, FreeBSD jails
Session 9-10 · Topic 10

Hypervisor — The Boss of VMs

Definition: A hypervisor (also called a Virtual Machine Monitor or VMM) is the software layer that creates, runs, and manages virtual machines. It sits between hardware and VMs, deciding which VM gets which CPU cycles and RAM.

TYPE 1 — BARE METAL VM 1 VM 2 VM 3 HYPERVISOR (Type 1) PHYSICAL HARDWARE Faster · Used by AWS, Azure, GCP Examples: VMware ESXi, KVM, Xen, Hyper-V Server TYPE 2 — HOSTED VM 1 VM 2 HYPERVISOR (Type 2) HOST OS (Windows/macOS) PHYSICAL HARDWARE Slower · Used on your laptop Examples: VMware Workstation, VirtualBox
Fig 2 · Type 1 vs Type 2 Hypervisors
FeatureType 1 (Bare Metal)Type 2 (Hosted)
Runs onDirectly on hardwareOn top of a host OS
PerformanceVery high (no OS overhead)Lower (OS layer in between)
Use caseProduction data centres, cloudDeveloper laptops, testing
ExamplesVMware ESXi, Microsoft Hyper-V, Xen, KVMVirtualBox, VMware Workstation, Parallels
Used byAWS, Azure, GCP, large enterprisesStudents running Ubuntu inside Windows
Session 9-10 · Topic 11

VM Provisioning & Migration Services

What is VM Provisioning?

Provisioning means setting up and configuring a virtual machine so it's ready to use. The steps are:

  1. Select template — Choose an OS image (Ubuntu 22.04, Windows Server 2022, Amazon Linux)
  2. Configure resources — Pick CPU (vCPUs), RAM (GB), disk size (GB), network
  3. Apply security — Set firewall rules, SSH keys, IAM roles
  4. Boot the VM — Hypervisor allocates resources and starts the OS
  5. Install software — Either manually via SSH/RDP, or automatically via scripts (cloud-init, Ansible)

In AWS, this entire process takes 60-120 seconds and is fully self-service. You can do it via Console (GUI), CLI, SDK, or Infrastructure-as-Code (Terraform, CloudFormation).

VM Migration Services

Migration means moving a running VM from one physical host to another with little or no downtime. This is essential for cloud providers — they constantly rebalance VMs across hardware.

Migration TypeDescriptionDowntime
Cold MigrationShut down VM, copy disk to new host, boot it upSeveral minutes
Warm MigrationSuspend VM (pause memory), copy state, resume10-30 seconds
Live MigrationVM keeps running. Memory is copied iteratively; switchover takes milliseconds.<1 second (imperceptible)
Cross-cloud MigrationMove VM from AWS to Azure (e.g., AWS Application Migration Service, Azure Migrate)Depends on data size
Real-World — Why Migration Matters

When AWS needs to patch a physical server, they live-migrate all your VMs to another machine first. You never even know it happened. This is how they maintain 99.99% uptime without scheduled maintenance windows.

Session 9-10 · Topic 12

Cloud Deployment Models

There are 4 ways to deploy cloud — depending on who owns it and who can access it:

Model 1
☁️ Public Cloud

Shared infrastructure, owned by a third-party provider (AWS, Azure, GCP). Anyone can rent it. Most common.

Example: Your AWS account, Gmail, Netflix infrastructure.

Pros: Cheapest, fastest setup, no maintenance.

Cons: Less control, data on third-party servers.

Model 2
🏢 Private Cloud

Cloud infrastructure used by only one organization. Can be on-premises or hosted by a vendor.

Example: SBI's internal cloud, ISRO's MOSDAC cloud, Reliance Jio's internal cloud.

Pros: Full control, compliance, security.

Cons: Expensive, slow to scale, you still maintain it.

Model 3
🔄 Hybrid Cloud

Combination of public + private. Sensitive data on private, scalable workloads on public.

Example: Indian banks — customer data on private cloud (RBI rules), website on AWS.

Pros: Best of both worlds.

Cons: Complex to manage, networking challenges.

Model 4
🤝 Community Cloud

Shared by several organizations with common concerns (e.g., government, healthcare).

Example: GI Cloud (Meghraj) — India's national cloud for government departments.

Pros: Cost shared, common compliance.

Cons: Limited audience, governance complex.

Private Cloud Deployment — A Closer Look

Building a private cloud means setting up cloud-like services inside your own data centre. You provide self-service VMs, storage, networking — but only for your own organization.

Popular Private Cloud Software:

  • OpenStack — Open-source, used by ISRO, Walmart, Comcast
  • VMware vSphere/vCloud — Enterprise standard, used by most Indian banks
  • Microsoft Azure Stack — Azure-compatible private cloud
  • Red Hat OpenShift — Container-focused private cloud
Session 9-10 · Topic 13

Challenges of Cloud Environment

Cloud isn't all rainbows. Here are the real challenges every cloud engineer faces:

ChallengeWhat Goes WrongHow to Mitigate
Security & PrivacyData breach, misconfigured S3 buckets exposing customer dataIAM least-privilege, encryption at rest & in transit, regular audits
ComplianceRBI requires Indian financial data to stay in India. GDPR for EU customers.Use Indian regions (Mumbai, Hyderabad), data residency controls
Cost Management"Bill shock" — a forgotten VM running for 3 months racks up ₹50,000Budget alerts, tagging, FinOps practices, auto-shutdown scripts
Vendor Lock-in5 years of AWS-specific code is hard to move to AzureUse open standards (Kubernetes, Terraform), abstraction layers
Network LatencyMumbai users on a US-region server feel slowChoose nearest region, use CDN (CloudFront)
Downtime & SLAAWS Mumbai region outage = your app is downMulti-AZ, multi-region architecture
Skills GapHiring cloud architects in India is expensive (₹20-40 LPA)Training programs (like PG-DBDA!), AWS/Azure certifications
ComplexityAWS has 200+ services. Choosing the right one is hard.Start simple (EC2 + S3 + RDS), add services as needed
Internet DependencyIf internet is down, no workBackup internet line, hybrid setup, edge caching
Session 11-12 · Topic 14

Administering & Monitoring Cloud Services

"If you can't measure it, you can't manage it." Cloud monitoring tells you what your infrastructure is doing — CPU usage, response times, errors, costs.

What to Monitor

📊 Performance Metrics
  • CPU utilization (%)
  • Memory usage
  • Disk I/O
  • Network throughput
  • Application response time
  • Database query latency
🔒 Security Events
  • Failed login attempts
  • Unauthorized API calls
  • Configuration changes
  • Public-exposed resources
  • Suspicious IPs
💰 Cost & Usage
  • Daily spend per service
  • Idle resources
  • Untagged resources
  • Budget vs actual
  • Reserved instance utilization
⚙️ Availability
  • Uptime / downtime
  • HTTP error rates (4xx, 5xx)
  • Auto-scaling events
  • Failed health checks
  • Backup success/failure

Monitoring Tools

CloudNative ToolUsed For
AWSCloudWatch, CloudTrail, X-RayMetrics, logs, audit, tracing
AzureAzure Monitor, Log Analytics, Application InsightsEnd-to-end monitoring
GCPCloud Monitoring (Stackdriver), Cloud LoggingMetrics, logs
3rd-partyDatadog, New Relic, Grafana, Prometheus, SplunkCross-cloud, deeper analytics

Cloud Monitoring vs Traditional Monitoring

AspectTraditionalCloud
TargetsFixed list of servers (server-1, server-2…)Dynamic — VMs come and go every minute
Metrics granularity1-5 min intervals1-second to 1-minute, even sub-second
ToolingNagios, Zabbix, SCOMCloudWatch, Datadog, Prometheus
Cost monitoringNot a metric (it's a fixed cost)Critical — usage = bill
Auto-responseManual remediationAuto-scaling, auto-healing, runbooks
Session 11-12 · Topic 15

Deploying an Application Over Cloud

Let's walk through deploying a typical Flask application (something you build in your PG-DBDA labs) to AWS:

Architecture for a Production Flask App

USER Mumbai Route 53 DNS CloudFront CDN ALB Load Balancer EC2 #1 EC2 #2 EC2 #3 RDS DB S3 Bucket Static files, images
Fig 3 · Typical Cloud Deployment for a Flask App

Step-by-Step Deployment Flow

  1. Develop locally — Write Flask app on your laptop
  2. Push to GitHub — Version control your code
  3. Provision infrastructure — Create EC2 instance(s), RDS database, S3 bucket via Console or Terraform
  4. Set up VPC + security groups — Network and firewall rules
  5. SSH into EC2 — Install Python, dependencies (or use Docker)
  6. Clone repo & run app — Use Gunicorn + Nginx as production server
  7. Add load balancer & auto-scaling — Handle multiple users, scale automatically
  8. Add CloudFront CDN — Speed up static asset delivery
  9. Set up monitoring & logging — CloudWatch alarms, log groups
  10. Set up CI/CD — GitHub Actions auto-deploys on every git push
Session 11-12 · Topic 16

IaaS vs PaaS vs SaaS — Side by Side

The famous "pizza analogy" makes this concept stick. Imagine you want pizza:

On-Premise
(Made at home)
Applications
Data
Runtime
Middleware
O/S
Virtualization
Servers
Storage
Networking
IaaS
(Take-and-bake)
Applications
Data
Runtime
Middleware
O/S
Virtualization
Servers
Storage
Networking
PaaS
(Delivery)
Applications
Data
Runtime
Middleware
O/S
Virtualization
Servers
Storage
Networking
SaaS
(Dine-out)
Applications
Data
Runtime
Middleware
O/S
Virtualization
Servers
Storage
Networking
You manage Cloud manages

The Pizza Analogy

🏠 On-Premise = Make pizza at home

You buy flour, yeast, tomatoes, cheese. You knead dough, cook it, serve it. Maximum control but maximum effort. You need an oven (server) and electricity (data centre).

🥡 IaaS = Take-and-bake

You buy a ready pizza base + toppings from a store. You bake it in your oven. The provider gives you raw materials; you assemble & cook.

🛵 PaaS = Pizza delivery

Pizza arrives hot at your door. You don't cook or worry about ingredients. You just eat at your table. The platform delivers a finished product to your environment.

🍽️ SaaS = Eat at a restaurant

You walk in, order, eat, leave. Zero work. Even the table, plates, AC, and staff are managed. You just consume the experience.

FactorIaaSPaaSSaaS
ControlHigh (OS & up)Medium (app & data only)Low (only your data)
Maintenance burdenHighMediumNone
FlexibilityMaxMediumLimited
Cost (small scale)MediumLowLowest
Cost (huge scale)LowestMediumHighest
Time to launchDaysHoursMinutes
Best forSystem admins, DevOpsDevelopersEnd users, business teams
ExamplesEC2, Azure VMApp Engine, Beanstalk, HerokuGmail, Salesforce, Zoom
Session 11-12 · Topic 17

Cloud Pricing Models

How do you actually get billed? The five main models:

ModelHow it WorksBest For
1. On-Demand / Pay-as-you-goPay per hour/second of usage. No commitment. Stop anytime.Unpredictable workloads, dev/test, short-term projects
2. Reserved Instances (RI)Commit for 1 or 3 years upfront. Get 40-72% discount.Steady-state production workloads, e.g., your main web server
3. Spot InstancesBid for AWS's spare capacity. Get up to 90% off. But AWS can take it back in 2 minutes.Batch jobs, big data processing, ML training, fault-tolerant workloads
4. Savings PlansCommit to a $/hour spend for 1-3 years. More flexible than RI.Workloads that may change instance types over time
5. Free TierLimited free usage for 12 months (AWS) — perfect for learningStudents, hobbyists, proof-of-concepts

Sample Pricing (AWS Mumbai region, approximate)

ServiceConfigurationApprox. Cost
EC2 t3.micro2 vCPU, 1 GB RAM, on-demand~₹0.85/hour ≈ ₹620/month
EC2 t3.medium2 vCPU, 4 GB RAM, on-demand~₹3.40/hour ≈ ₹2,480/month
S3 Standardper GB stored~₹2/GB/month
S3 data transfer outper GB downloaded~₹8/GB
RDS MySQL db.t3.micro2 vCPU, 1 GB RAM~₹1.50/hour ≈ ₹1,100/month
Lambdaper million requests~₹16 per million calls
EBS gp3 storageper GB/month~₹7/GB/month
⚠️ Cost Traps to Avoid
  • Forgotten resources — A test EC2 running 24×7 for 3 months = ₹2,000+ wasted
  • Data egress — Downloading 1 TB from S3 to internet = ₹8,000
  • Large NAT Gateway hours — Each NAT Gateway costs ~₹3,500/month + data charges
  • Public IPv4 addresses — AWS now charges ~₹0.30/hour for each idle IP
  • Snapshots — Old EBS snapshots accumulate; clean them out

Tip: Always set up Billing Alerts in AWS so you get an email if monthly spend crosses ₹500.

Session 11-12 · Topic 18

The Shared Responsibility Model

This is one of the most important concepts in cloud — and the most misunderstood. Security in the cloud is shared between you and the provider.

Shared Responsibility Model CUSTOMER — Security IN the cloud Customer Data Platform & Application Management Identity & Access Management (IAM) OS, Network & Firewall Configuration Client-side Encryption & Data Integrity Server-side & Network Encryption Setup AWS — Security OF the cloud Software (Compute, Storage, DB, Networking) Hardware / Global Infrastructure Regions, AZs, Edge Locations Physical Data Centre Security (guards, locks)
Fig 4 · Who is responsible for what?

The Simple Rule

  • AWS/Azure/GCP is responsible for security OF the cloud — physical buildings, hardware, hypervisor, network cables.
  • You are responsible for security IN the cloud — your data, your IAM users, your firewall rules, your OS patches, your application code.
Common Mistakes Indian Developers Make
  • Making an S3 bucket public by accident → customer data leaked (this happened to multiple Indian fintechs!)
  • Committing AWS access keys to GitHub → bots find them in minutes, run up ₹5 lakh in Bitcoin mining bills
  • Leaving SSH port 22 open to 0.0.0.0/0 → brute force attacks from foreign IPs
  • Not enabling MFA on the root account → one phishing email and account is compromised

The shared responsibility shifts depending on the model:

LayerOn-PremIaaSPaaSSaaS
ApplicationsYouYouYouProvider
DataYouYouYouYou*
RuntimeYouYouProviderProvider
OSYouYouProviderProvider
VirtualizationYouProviderProviderProvider
HardwareYouProviderProviderProvider

* Even in SaaS, your account data, sharing settings, and user access are still your responsibility.

Session 13-14 · Topic 19

Introduction to AWS

Amazon Web Services launched in 2006. Today it's the world's largest cloud provider, with 200+ services across 33 regions globally.

Core AWS Concepts

🌍 Regions

Geographic locations (e.g., ap-south-1 = Mumbai, ap-south-2 = Hyderabad). Each region has multiple Availability Zones.

🏢 Availability Zones (AZs)

Independent data centres within a region (e.g., Mumbai has 3 AZs). If one AZ floods, your app in another AZ keeps running.

🌐 Edge Locations

200+ smaller PoPs used by CloudFront CDN to serve content close to users. Includes Bangalore, Chennai, Mumbai, Delhi.

🔑 IAM

Identity & Access Management — who can do what. Users, groups, roles, and policies.

AWS Service Categories

CategoryKey Services
ComputeEC2, Lambda, ECS, EKS, Fargate, Elastic Beanstalk
StorageS3, EBS, EFS, Glacier, Storage Gateway
DatabaseRDS, DynamoDB, Aurora, Redshift, ElastiCache
NetworkingVPC, Route 53, CloudFront, ELB, API Gateway
Security & IdentityIAM, KMS, Secrets Manager, GuardDuty, WAF
AnalyticsAthena, EMR (Hadoop/Spark), Kinesis, Glue, QuickSight
Machine LearningSageMaker, Bedrock, Rekognition, Comprehend, Transcribe
DevOpsCodeCommit, CodeBuild, CodeDeploy, CodePipeline, CloudFormation
MonitoringCloudWatch, CloudTrail, X-Ray, Config
Session 13-14 · Topic 20

EC2 — Elastic Compute Cloud

What it is: EC2 lets you rent virtual servers (called instances) in the cloud. Think of it as your remote Linux/Windows computer in AWS data centre.

EC2 Instance Types

AWS offers hundreds of instance types, categorized by what they're optimized for:

FamilyExampleBest For
General Purposet3, t4g, m5, m6iWeb servers, dev environments — balanced CPU/RAM
Compute Optimizedc5, c6i, c7gBatch processing, scientific computing, game servers
Memory Optimizedr5, r6i, x2In-memory databases (Redis), Spark, SAP HANA
Storage Optimizedi3, i4i, d3Big data, data warehousing, distributed file systems
Accelerated Computingp4, g5, inf2Machine learning training, GPU workloads

Naming Convention Decoded

An instance like t3.micro breaks down as:

  • t = family (T-series, burstable general purpose)
  • 3 = generation (3rd gen)
  • micro = size (nano < micro < small < medium < large < xlarge < 2xlarge…)

So m6i.2xlarge = General-purpose, 6th gen, Intel, 2× extra-large.

EC2 Storage Options

  • EBS (Elastic Block Store) — Like a hard drive attached to your VM. Persists when VM is stopped. Types: gp3 (general), io2 (high-IOPS), st1 (throughput).
  • Instance Store — Physically attached disk. Very fast but data is lost when VM stops. Used for caching/temp data.
  • EFS — Shared file system (NFS) that multiple EC2s can mount.
EC2 Free Tier

AWS gives 750 hours/month of t2.micro or t3.micro free for 12 months — that's 24×7! Perfect for learning. Use this for all your PG-DBDA lab practicals.

Lab Practical · L1

Lab: Create & Access an EC2 Instance

Step-by-Step: Launch Linux EC2

  1. Sign in to AWS Console → search "EC2"
  2. Click "Launch Instance"
  3. Name: my-first-server
  4. AMI: select Amazon Linux 2023 (Free Tier eligible)
  5. Instance type: t2.micro or t3.micro (Free Tier)
  6. Key pair: Create new → name it my-key → download .pem file (keep it safe!)
  7. Network settings: Allow SSH (port 22) from your IP only, HTTP (80) from anywhere
  8. Click "Launch Instance"

Connect via SSH (from Linux/Mac)

# Set correct permissions on key file
chmod 400 my-key.pem

# SSH into the instance
ssh -i my-key.pem ec2-user@<your-public-ip>

# Once inside, update packages
sudo dnf update -y

# Install Apache web server
sudo dnf install httpd -y
sudo systemctl start httpd
sudo systemctl enable httpd

# Create a sample page
echo "<h1>Hello from EC2!</h1>" | sudo tee /var/www/html/index.html

# Now open http://<your-public-ip> in browser

Launch Windows Server VM

Same steps but:

  • Select AMI: Microsoft Windows Server 2022 Base
  • Network: allow RDP (port 3389)
  • After launch: click "Connect" → "RDP client" → download .rdp file
  • Get password: paste your .pem private key to decrypt the Administrator password
  • Open .rdp file → enter password → you're in Windows desktop!
⚠️ Don't Forget to Stop/Terminate!

When done with your lab, STOP the instance (free, but disk still bills) or TERMINATE it (deletes everything, no bills). Forgotten EC2 instances are the #1 reason students get unexpected ₹500-2000 charges.

Session 13-14 · Topic 21

S3 — Simple Storage Service

What it is: S3 is AWS's object storage service. Store anything — files, images, videos, backups, datasets — with virtually unlimited capacity, 99.999999999% (11 nines!) durability.

What S3 is Used For
  • Static website hosting — Your portfolio site
  • Backup & archival — Database snapshots, log files
  • Media storage — Hotstar streams videos from S3
  • Data lake — Raw data for analytics (Spark, Athena read directly from S3)
  • App assets — Profile pictures on a social app, PDF invoices
  • ML training data — Datasets stored before feeding to SageMaker

Key Concepts

  • Bucket — A container for objects. Name must be globally unique (e.g., vineeta-pgdbda-bucket-2026). Has a region.
  • Object — A file + metadata. Max size: 5 TB. Identified by a key (the filename + path).
  • Key — The unique path: uploads/students/2026/photo.jpg
  • URL — Every object gets a URL: https://<bucket>.s3.<region>.amazonaws.com/<key>

S3 Storage Classes

ClassUse CaseCost (₹/GB/month)Retrieval
StandardFrequently accessed data~₹2.0Instant
Standard-IAInfrequent access, kept available~₹1.1Instant
One Zone-IARe-creatable data, single AZ~₹0.9Instant
Glacier InstantArchive, milliseconds retrieval~₹0.4Instant
Glacier FlexibleArchive, minutes-hours retrieval~₹0.3Minutes-hours
Glacier Deep ArchiveLong-term archive (compliance, tax records)~₹0.0812+ hours

Lifecycle Policies: Automatically move objects between classes. E.g., "Move logs to Glacier after 90 days, delete after 2 years."

Lab Practical · L2

Lab: Create an S3 Bucket

Create a Bucket via Console

  1. AWS Console → search "S3" → "Create bucket"
  2. Bucket name: globally unique (e.g., vineeta-cdac-demo-2026)
  3. Region: ap-south-1 (Mumbai)
  4. Block all public access: keep checked (default — secure)
  5. Versioning: enable (allows recovery of deleted/overwritten files)
  6. Default encryption: SSE-S3 (enabled by default now)
  7. Create bucket

Upload & Manage Files via AWS CLI

# Install AWS CLI and configure
aws configure
# Enter Access Key, Secret Key, region: ap-south-1

# Upload a single file
aws s3 cp ./report.pdf s3://vineeta-cdac-demo-2026/reports/

# Upload entire folder
aws s3 cp ./project/ s3://vineeta-cdac-demo-2026/project/ --recursive

# List buckets
aws s3 ls

# List objects in a bucket
aws s3 ls s3://vineeta-cdac-demo-2026/ --recursive

# Download a file
aws s3 cp s3://vineeta-cdac-demo-2026/reports/report.pdf .

# Sync a folder (incremental, like rsync)
aws s3 sync ./local-folder s3://vineeta-cdac-demo-2026/backup/

# Delete an object
aws s3 rm s3://vineeta-cdac-demo-2026/old-file.txt

Host a Static Website on S3

  1. Create index.html with your portfolio content
  2. Create bucket (e.g., vineeta-portfolio.com)
  3. Uncheck "Block all public access" (this one should be public)
  4. Properties → Static Website Hosting → Enable → Index document: index.html
  5. Permissions → Bucket Policy → allow public s3:GetObject
  6. Upload index.html
  7. Visit the website URL — your site is live!
Session 13-14 · Topic 22

AWS Lambda — Serverless Computing

What it is: Lambda lets you run code without provisioning servers. You upload a function, AWS runs it when triggered (HTTP request, S3 upload, schedule, etc.), and you pay only for actual execution time.

"Serverless" doesn't mean no servers

There ARE servers — AWS just manages them invisibly. From your perspective, you only write the function. No SSH, no patching, no scaling — AWS handles everything.

How Lambda Works

  1. You write a function (Python, Node.js, Java, Go, .NET, Ruby)
  2. Upload it to Lambda
  3. Attach a "trigger" — what causes it to run? (HTTP, S3 upload, DynamoDB change, cron schedule, SQS message…)
  4. When triggered, AWS spins up a container, runs your code, returns the result, shuts down
  5. You pay for compute time used (per millisecond)

Lambda Pricing

  • Requests: ~₹16 per 1 million requests
  • Compute: ~₹1.4 per million GB-seconds
  • Free tier: 1 million requests + 400,000 GB-seconds per month, always free

This means small projects can run completely free. A Telegram bot with 10,000 messages/month? ₹0.

Common Lambda Use Cases

  • Image processing — When user uploads to S3, Lambda creates thumbnails
  • API backend — API Gateway + Lambda = fully serverless REST API
  • Scheduled tasks — Daily backup of database to S3 (replaces cron jobs)
  • IoT data processing — Stream sensor data through Lambda
  • Chatbots — WhatsApp / Telegram bots
  • ETL — Triggered when new file lands in S3, process it
Lab Practical · L3

Lab: Create a Lambda Function

Hello World Lambda (Python)

  1. AWS Console → search "Lambda" → "Create function"
  2. Author from scratch · Name: hello-pgdbda · Runtime: Python 3.12 · Architecture: x86_64
  3. Click "Create function"
  4. In the code editor, paste:
import json
from datetime import datetime

def lambda_handler(event, context):
    name = event.get('name', 'PG-DBDA Student')
    now = datetime.now().strftime('%H:%M:%S')
    
    return {
        'statusCode': 200,
        'body': json.dumps({
            'message': f'Hello {name}!',
            'timestamp': now,
            'from': 'AWS Lambda (Mumbai)'
        })
    }
  1. Click "Deploy"
  2. Click "Test" → create test event with {"name": "Vineeta"} → Test
  3. See the JSON response in the output panel!

Add an HTTP Trigger (Function URL)

  1. Configuration tab → Function URL → Create
  2. Auth type: NONE (for testing)
  3. You get a public URL like: https://abc123.lambda-url.ap-south-1.on.aws/
  4. Open it in browser → your Lambda runs over HTTP!
  5. Pass query string: ?name=Vineeta (you'll need to modify the handler to read query strings)
Session 13-14 · Topic 23

VPC — Virtual Private Cloud

What it is: A VPC is your own private, isolated network inside AWS. Think of it as your own data centre — but virtual. You define the IP range, subnets, routing, and firewall rules.

VPC Components

ComponentPurpose
VPCThe main private network. Pick a CIDR block like 10.0.0.0/16 (gives you 65K IPs).
SubnetA slice of the VPC. Public subnet (has internet) or private subnet (no internet). Each in one AZ.
Internet Gateway (IGW)Doorway that connects VPC to the public internet. Attached to VPC.
Route TableRules telling traffic where to go. Each subnet has a route table.
NAT GatewayLets private subnet resources reach internet (for updates) without being reachable from internet.
Security GroupStateful firewall at the instance level. "Allow port 22 from my IP".
Network ACL (NACL)Stateless firewall at the subnet level. Defense layer 1.
Elastic IPStatic public IP you can move between EC2 instances.

Typical VPC Architecture (3-Tier)

VPC 10.0.0.0/16 Internet Gateway PUBLIC SUBNET · 10.0.1.0/24 Web Server EC2 + Public IP NAT Gateway Outbound for private PRIVATE SUBNET · 10.0.2.0/24 App Server EC2 (no public IP) App Server EC2 (no public IP) PRIVATE DB SUBNET · 10.0.3.0/24 RDS MySQL Multi-AZ deployment
Fig 5 · 3-Tier VPC Architecture
Lab Practical · L4

Lab: Create a VPC

Easy Path — VPC Wizard

  1. AWS Console → VPC → "Create VPC"
  2. Select "VPC and more" (creates everything in one click)
  3. Name: pgdbda-vpc
  4. IPv4 CIDR: 10.0.0.0/16
  5. Number of AZs: 2
  6. Public subnets: 2, Private subnets: 2
  7. NAT gateways: 1 (or "None" to save cost during lab)
  8. VPC endpoints: S3 Gateway (free!)
  9. Create VPC

In 2 minutes, AWS creates VPC, subnets, IGW, route tables, NACLs — everything wired up correctly.

⚠️ Delete NAT Gateways After Lab

NAT Gateway is not free — costs ~₹3,500/month + per-GB data. After your lab, delete it. Otherwise your AWS bill will surprise you.

Session 13-14 · Topic 24

Introduction to Microsoft Azure

Azure is Microsoft's cloud platform, launched in 2010. It's the #2 cloud provider globally, dominant in enterprises that already use Windows Server, Active Directory, SQL Server, or Office 365.

Why Azure Wins in Enterprises

  • Hybrid Cloud — Azure Arc, Azure Stack lets you extend on-prem to cloud seamlessly
  • Windows Integration — Native Active Directory, Group Policy, .NET
  • Office 365 Sync — One Microsoft login for everything
  • Enterprise Agreements — Easier procurement for big Indian banks/PSUs

Azure Core Concepts

ConceptWhat it Means
SubscriptionBilling container. All resources go inside a subscription.
Resource GroupLogical folder grouping related resources (e.g., "MyWebApp" group with VM + DB + Storage)
RegionGeographic location (e.g., Central India = Pune, South India = Chennai)
Azure Resource Manager (ARM)The API/engine that manages all Azure resources
Azure AD / Entra IDIdentity service (replaces AWS IAM)

Three Ways to Manage Azure

🖥️ Azure Portal

Web-based GUI at portal.azure.com. Best for beginners and quick checks.

⌨️ Azure CLI

Command-line tool. az vm create --name myvm…. Runs on Windows/Mac/Linux. Best for automation.

💻 Azure PowerShell

PowerShell modules. New-AzVM -Name "myvm". Native for Windows admins.

Session 13-14 · Topic 25

Key Azure Services

Azure Data Services

🗄️ Azure SQL Database

Fully managed Microsoft SQL Server as a service. You don't install or patch anything. Auto-backup, auto-tune, built-in HA.

Use case: Replace on-prem SQL Server in enterprises. Tiers: Basic (₹400/month), Standard, Premium.

🌐 Azure Cosmos DB

Globally distributed multi-model NoSQL database. Supports document, key-value, graph, column-family APIs.

Use case: Apps with users in multiple countries, low-latency reads everywhere. Used by Flipkart, Walmart.

Azure Storage

📦 Blob Storage

Equivalent of AWS S3. Object storage for unstructured data (images, videos, backups). Tiers: Hot, Cool, Archive.

📁 File Storage

SMB/NFS file shares accessible from VMs (Windows + Linux). Drop-in replacement for on-prem file servers.

📨 Queue Storage

Simple message queue for decoupling app components. Producer adds message, consumer processes later.

Azure Functions

Azure's equivalent of AWS Lambda. Serverless code execution triggered by events (HTTP, Blob upload, timer, queue message).

Languages: C#, JavaScript, Python, Java, PowerShell, TypeScript, Go.

Pricing: Consumption plan — first 1 million executions free per month.

# Sample Python Azure Function (HTTP trigger)
import azure.functions as func

def main(req: func.HttpRequest) -> func.HttpResponse:
    name = req.params.get('name', 'World')
    return func.HttpResponse(
        f"Hello, {name}!",
        status_code=200
    )
Lab Practical · L5

Lab: Deploy from GitHub

Deployment to AWS via GitHub Actions

The modern way: push code to GitHub, a workflow auto-deploys to AWS.

# .github/workflows/deploy.yml
name: Deploy to AWS

on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Configure AWS credentials
        uses: aws-actions/configure-aws-credentials@v4
        with:
          aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
          aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
          aws-region: ap-south-1

      - name: Deploy to S3
        run: aws s3 sync ./public s3://my-bucket/ --delete

      - name: Invalidate CloudFront cache
        run: aws cloudfront create-invalidation \
          --distribution-id ${{ secrets.CF_DIST_ID }} \
          --paths "/*"

Deployment to Azure via GitHub Actions

name: Deploy to Azure Web App

on:
  push:
    branches: [main]

jobs:
  build-and-deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: '3.11'

      - name: Install dependencies
        run: pip install -r requirements.txt

      - name: Deploy to Azure Web App
        uses: azure/webapps-deploy@v3
        with:
          app-name: my-flask-app
          publish-profile: ${{ secrets.AZURE_PUBLISH_PROFILE }}

Deployment via Azure DevOps

Azure DevOps Pipelines is an alternative to GitHub Actions, popular in enterprises:

  1. Create Azure DevOps account at dev.azure.com
  2. Create a new Project & import your code from GitHub
  3. Pipelines → Create pipeline → Select repo → Choose template (Python web app, Node.js, etc.)
  4. The YAML pipeline auto-generates
  5. Configure service connection to your Azure subscription
  6. Save & run — pipeline builds, tests, and deploys
Exam Prep · Cheat Sheet

Quick Revision Sheet

One-Line Definitions (memorize these)

TermDefinition
Cloud ComputingOn-demand delivery of IT resources over the internet on pay-as-you-go basis
IaaSInfrastructure (VMs, storage, network) delivered as a service
PaaSReady-made platform to deploy apps without managing servers
SaaSFully functional software delivered over the internet on subscription
Public CloudShared cloud owned by third party, accessible to anyone (AWS, Azure)
Private CloudCloud dedicated to one organization (e.g., SBI's internal cloud)
Hybrid CloudCombination of public + private cloud
VirtualizationTechnology to create multiple virtual servers on one physical machine
HypervisorSoftware that creates and manages VMs
ElasticityAbility to scale resources up/down automatically based on demand
ScalabilityAbility to handle growing workload by adding resources
Multi-tenancyMultiple customers share same physical infrastructure, isolated logically
RegionGeographic area with multiple data centres (AWS: ap-south-1 = Mumbai)
Availability ZoneIsolated data centre within a region
EC2AWS service for renting virtual machines (Elastic Compute Cloud)
S3AWS object storage service (Simple Storage Service)
LambdaAWS serverless compute — run code without managing servers
VPCVirtual Private Cloud — your private network in AWS
IAMIdentity & Access Management — who can do what
SLAService Level Agreement — uptime guarantee (e.g., 99.99%)

The 5 NIST Characteristics (memorize)

  1. On-demand self-service
  2. Broad network access
  3. Resource pooling
  4. Rapid elasticity
  5. Measured service

The 4 Deployment Models

  1. Public
  2. Private
  3. Hybrid
  4. Community

The 3 Service Models

  1. IaaS (Infrastructure)
  2. PaaS (Platform)
  3. SaaS (Software)
Exam Prep · Interview Questions

Common Interview Questions

Conceptual Questions

  1. What is cloud computing? Give 3 real-world examples.
    Cloud computing is on-demand delivery of IT resources over the internet with pay-as-you-go pricing. Examples: Gmail (SaaS), AWS EC2 (IaaS), Heroku (PaaS).
  2. Difference between scalability and elasticity?
    Scalability is the ability to handle growth (manual or planned). Elasticity is automatic, real-time scaling up/down based on current demand.
  3. Why would a bank choose private cloud over public?
    Compliance (RBI data localization), full control over data, predictable performance, regulatory requirements.
  4. Explain the shared responsibility model.
    Cloud provider is responsible for security of the cloud (hardware, hypervisor). Customer is responsible for security in the cloud (data, IAM, configurations).
  5. What's the difference between vertical and horizontal scaling?
    Vertical = bigger server (more CPU/RAM). Horizontal = more servers (more instances behind a load balancer). Horizontal is preferred in cloud.
  6. What is a hypervisor? Difference between Type 1 and Type 2?
    A hypervisor manages VMs. Type 1 runs directly on hardware (ESXi, used in cloud). Type 2 runs on a host OS (VirtualBox, used on laptops).
  7. Why is virtualization important for cloud computing?
    It enables multi-tenancy, efficient hardware use, fast provisioning, isolation between customers — all the foundations of cloud economics.

AWS-Specific Questions

  1. Difference between EC2 and Lambda?
    EC2 = persistent virtual server you manage. Lambda = stateless function that runs only when triggered, fully managed by AWS.
  2. What is an S3 bucket?
    A container for objects (files) in S3. Globally unique name, lives in one region, contains unlimited objects.
  3. Difference between EBS and S3?
    EBS = block storage attached to one EC2 (like a hard drive). S3 = object storage accessible via HTTP from anywhere.
  4. What is a VPC and why use it?
    A private network within AWS. Lets you isolate resources, control IP addressing, set firewall rules, and segment public/private workloads.
  5. Public vs private subnet?
    Public subnet has a route to internet via Internet Gateway. Private subnet doesn't — for databases & backend services.
  6. What is Auto Scaling?
    A service that automatically adds/removes EC2 instances based on demand or schedule.

Scenario Questions

  1. Your e-commerce site crashes during Big Billion Days sale. How would you fix it on AWS?
    Put EC2 behind an Auto Scaling Group + Application Load Balancer. Add CloudFront CDN for static assets. Use RDS Multi-AZ. Set CloudWatch alarms.
  2. How would you reduce a high AWS bill?
    Identify idle resources via Cost Explorer. Buy Reserved Instances for steady workloads. Use Spot for batch jobs. Move infrequent S3 data to Glacier. Delete unused EBS volumes & snapshots. Set budget alerts.
  3. You need to process 1 TB of CSV files nightly. Which AWS services?
    Store data in S3. Use AWS Glue or EMR (Spark) for processing. Trigger via EventBridge schedule. Output to S3/Redshift. For smaller files, Lambda can work too.