<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reference on dantas.io</title><link>https://dantas.io/tags/reference/</link><description>Recent content in Reference on dantas.io</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Tue, 21 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://dantas.io/tags/reference/index.xml" rel="self" type="application/rss+xml"/><item><title>The Complete AWS Services Catalog: A Practitioner's Reference for 2026</title><link>https://dantas.io/p/aws-services-complete-catalog-april-2026/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://dantas.io/p/aws-services-complete-catalog-april-2026/</guid><description>
 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;A practitioner&amp;rsquo;s reference, not a marketing brochure.&lt;/strong&gt; This article catalogs the major AWS services as of April 2026, structured by the certification tier that first introduces them in depth — from the foundational Associate track through Professional and Specialty domains. A downloadable Excel workbook with the full catalog is included at the end.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="why-a-structured-catalog-matters"&gt;Why a Structured Catalog Matters
&lt;/h2&gt;&lt;p&gt;AWS officially offers more than &lt;strong&gt;240 fully featured services&lt;/strong&gt; as of 2026, with individual sub-features and API operations exceeding 500. For anyone designing architectures, studying for certifications, or justifying cloud adoption to leadership, an unordered flat list is operationally useless. Structure matters.&lt;/p&gt;
&lt;p&gt;This reference organizes services into four tiers that align with the AWS certification track — not because the cert is the goal, but because the curriculum progression mirrors how services relate to one another in real architectures.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Tier&lt;/th&gt;
 &lt;th&gt;Scope&lt;/th&gt;
 &lt;th&gt;AWS Exam&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;1 — Foundational&lt;/td&gt;
 &lt;td&gt;Core services every cloud architect must know&lt;/td&gt;
 &lt;td&gt;SAA-C03 (Solutions Architect Associate)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;2 — Advanced Architecture&lt;/td&gt;
 &lt;td&gt;Services for complex, multi-account, hybrid workloads&lt;/td&gt;
 &lt;td&gt;SAP-C02 (Solutions Architect Professional)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;3 — Domain Specialization&lt;/td&gt;
 &lt;td&gt;Deep expertise in Networking, Security, or AI/ML&lt;/td&gt;
 &lt;td&gt;ANS-C01 / SCS-C03 / MLA-C01&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;4 — Extended Portfolio&lt;/td&gt;
 &lt;td&gt;IoT, media, satellite, AR/VR, niche enterprise&lt;/td&gt;
 &lt;td&gt;No primary cert track&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img src="https://dantas.io/p/aws-services-complete-catalog-april-2026/aws-services-complete-catalog-april-2026-info1.png"
	width="2752"
	height="1536"
	loading="lazy"
	
		alt="Generated by NotebookLM"
	
 
	
		class="gallery-image" 
		data-flex-grow="179"
		data-flex-basis="430px"
	
&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="tier-1--core-services-saa-c03"&gt;Tier 1 — Core Services (SAA-C03)
&lt;/h2&gt;&lt;p&gt;These are the services covered by the &lt;strong&gt;AWS Certified Solutions Architect – Associate (SAA-C03)&lt;/strong&gt; exam. Every cloud practitioner operating at a professional level should understand these services, their use cases, and how they compose into production architectures.&lt;/p&gt;
&lt;h3 id="compute"&gt;Compute
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EC2&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Resizable virtual servers. The workhorse of AWS compute — instance types, pricing models (On-Demand, Reserved, Spot), placement groups, and Nitro hypervisor.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Lambda&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Event-driven serverless compute. Pay per invocation. Integrates deeply with API Gateway, S3, EventBridge, and DynamoDB.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon ECS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Container orchestration for Docker workloads. Deploy with EC2 launch type or Fargate.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EKS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Kubernetes. The right choice when you need Kubernetes-native tooling and ecosystem portability.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Elastic Beanstalk&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;PaaS abstraction over EC2, ALB, and Auto Scaling. Deploy code; AWS manages the infrastructure layer.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Fargate&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless compute engine for ECS and EKS. No nodes to manage.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Lightsail&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Simplified VPS for low-complexity workloads. Not the right choice for enterprise architects.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Outposts&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AWS-managed hardware deployed on-premises. Consistent API, tooling, and data residency control.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;EC2 Auto Scaling&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automatically adjust EC2 fleet capacity based on demand signals. Works with Target Tracking, Step, and Scheduled policies.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="storage"&gt;Storage
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon S3&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Object storage at any scale. The foundation of AWS data architectures — versioning, lifecycle policies, event notifications, intelligent-tiering.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EBS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Block storage for EC2. Volume types: gp3, io2 (provisioned IOPS), st1 (throughput), sc1 (cold). Snapshots to S3.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EFS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed NFS for Linux workloads. Multi-AZ, auto-scaling. Not for Windows.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon S3 Glacier&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Low-cost archival storage. Retrieval tiers: Instant, Flexible, Deep Archive.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Storage Gateway&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Hybrid integration: File Gateway (NFS/SMB to S3), Volume Gateway (iSCSI), Tape Gateway.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Backup&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Centralized, policy-driven backup across EC2, RDS, EFS, DynamoDB, and more.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon FSx&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed file systems: FSx for Windows, Lustre, NetApp ONTAP, OpenZFS. Choose based on protocol and workload type.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Snow Family&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Physical data transfer: Snowcone (8TB), Snowball Edge (up to 80TB), Snowmobile (100PB). Also used for edge compute.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="databases"&gt;Databases
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon RDS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed relational DB: MySQL, PostgreSQL, Oracle, SQL Server, MariaDB. Multi-AZ for HA; Read Replicas for read scaling.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Aurora&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AWS-native MySQL/PostgreSQL-compatible DB. 5x faster than MySQL. Shared storage layer across 6 copies in 3 AZs.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon DynamoDB&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless, single-digit millisecond NoSQL DB. Global Tables for multi-region active-active.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon ElastiCache&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;In-memory caching: Redis (rich data structures, persistence) or Memcached (simple cache, horizontal scaling).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Redshift&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Columnar data warehouse. MPP architecture. RA3 nodes with managed storage.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Neptune&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Graph database. Supports Gremlin (property graphs) and SPARQL (RDF/SPARQL).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon DocumentDB&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;MongoDB-compatible document database. Not the same engine as MongoDB — compatibility, not parity.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Keyspaces&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Apache Cassandra-compatible service. Serverless, pay-per-request.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="networking--content-delivery"&gt;Networking &amp;amp; Content Delivery
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon VPC&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;The fundamental network isolation boundary in AWS. Subnets, route tables, NACLs, security groups, gateways.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Route 53&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;DNS with routing policies: Simple, Weighted, Latency, Failover, Geolocation, Geoproximity, Multivalue. Also domain registration.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon CloudFront&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Global CDN with 400+ edge locations. Integrates with S3, ALB, API Gateway, Lambda@Edge, CloudFront Functions.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Elastic Load Balancing&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;ALB (HTTP/HTTPS, L7, host/path routing), NLB (TCP/UDP, L4, static IP), GLB (third-party virtual appliances).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Direct Connect&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Dedicated 1 Gbps or 10 Gbps private connection to AWS. Not encrypted by default — use with MACsec or VPN.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS VPN&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;IPsec VPN over the internet. Site-to-Site VPN or Client VPN (OpenVPN-based).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon API Gateway&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed REST, HTTP, and WebSocket API service. Throttling, caching, authorization, usage plans.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Global Accelerator&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Anycast IP routing through AWS global backbone. Latency and availability improvement for non-HTTP workloads.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="security-identity--compliance"&gt;Security, Identity &amp;amp; Compliance
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IAM&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;The identity layer of AWS. Users, groups, roles, policies (identity-based, resource-based, SCPs). Principle of least privilege is not optional.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS KMS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed encryption keys. CMKs (now KMS keys): AWS-managed, customer-managed. Integrates with S3, RDS, EBS, Lambda.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Secrets Manager&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Store, rotate, and retrieve database credentials, API keys, and tokens. Rotation via Lambda functions.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Certificate Manager (ACM)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Provision and auto-renew TLS/SSL certificates. Public certificates are free. Private CA is paid.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Cognito&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;User Pools (authentication) + Identity Pools (authorization to AWS resources). JWT-based. Federated with OIDC/SAML.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS WAF&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Layer 7 firewall. Managed rule groups, custom rules, rate limiting. Integrates with CloudFront, ALB, API Gateway.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Shield&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;DDoS protection. Standard (free, automatic). Advanced (paid, 24/7 DRT, cost protection).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon GuardDuty&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;ML-based threat detection from VPC Flow Logs, DNS, CloudTrail, EKS audit logs, RDS login events.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CloudTrail&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;API call audit trail. Every API call — who, what, when, from where. Enabled per-region; organization trails for all accounts.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Config&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Configuration compliance and change history. Rules (managed and custom via Lambda) for drift detection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="management--governance"&gt;Management &amp;amp; Governance
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CloudFormation&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Infrastructure as Code with JSON/YAML templates. Stacks, StackSets for multi-account/region deployment.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon CloudWatch&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Unified observability: metrics, logs (Log Insights), alarms, dashboards, Contributor Insights.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Systems Manager&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Operational control: Session Manager (no SSH/bastion), Patch Manager, Parameter Store, Run Command, Automation.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Organizations&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Multi-account governance. SCPs, delegated admin, consolidated billing.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Trusted Advisor&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Best practice checks across cost optimization, security, fault tolerance, performance, service limits.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Health Dashboard&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Personalized service event notifications. Service Health vs. Personal Health.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="application-integration"&gt;Application Integration
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon SQS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed message queue. Standard (at-least-once, best-effort order) and FIFO (exactly-once, strict order).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon SNS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Pub/sub fanout. Topics → SQS, Lambda, HTTP, email, SMS. Message filtering at subscription level.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EventBridge&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless event bus. Schema registry, event replay, cross-account routing, SaaS integrations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Step Functions&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Visual state machine orchestration. Standard (long-running) and Express (high-throughput) workflows.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon MQ&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed ActiveMQ and RabbitMQ. Lift-and-shift for AMQP/STOMP/MQTT workloads.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Kinesis Data Streams&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Real-time data streaming. Shards, retention up to 365 days, consumers via Lambda or KCL.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="analytics"&gt;Analytics
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Athena&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless SQL on S3. Pay per query scanned. Parquet/ORC dramatically reduces cost.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EMR&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Hadoop/Spark. EC2, EKS, or Serverless deployment options.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Glue&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless ETL. Data Catalog (Hive metastore-compatible), crawlers, Spark-based transformations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon OpenSearch Service&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed OpenSearch (fork of Elasticsearch). Full-text search, log analytics, observability.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="ai--machine-learning-associate-level"&gt;AI &amp;amp; Machine Learning (Associate-Level)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon SageMaker&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;End-to-end ML platform. Studio, Pipelines, Feature Store, Ground Truth, Model Monitor.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Rekognition&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Vision AI: object detection, facial analysis, content moderation, text-in-image.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Polly&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Neural text-to-speech. Multiple voices, SSML support, custom lexicons.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Translate&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Neural machine translation. 75+ languages. Custom terminology support.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Comprehend&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;NLP: sentiment, entity recognition, topic modeling, PII detection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Transcribe&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automatic speech recognition. Speaker diarization, medical variant, call analytics.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Lex&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Conversational AI chatbot engine. The same engine that powers Alexa.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="developer-tools"&gt;Developer Tools
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CodeBuild&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Fully managed CI build service. Docker-based build environments, pay per build minute.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CodeDeploy&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automated deployment to EC2, Lambda, and ECS. Blue/green and rolling deployment strategies.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CodePipeline&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;CI/CD pipeline orchestration. Integrates with CodeBuild, CodeDeploy, and third-party tools.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Cloud9&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Cloud-based IDE. Pre-configured with AWS CLI, SDKs.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="tier-2--advanced-architecture-services-sap-c02"&gt;Tier 2 — Advanced Architecture Services (SAP-C02)
&lt;/h2&gt;&lt;p&gt;The &lt;strong&gt;AWS Certified Solutions Architect – Professional (SAP-C02)&lt;/strong&gt; exam goes substantially deeper into multi-account architectures, hybrid connectivity, advanced networking, and cost/governance at scale. These are the services that separate mid-level practitioners from senior architects.&lt;/p&gt;
&lt;h3 id="compute-advanced"&gt;Compute (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Batch&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed batch computing. Job queues, compute environments (EC2/Fargate), array jobs, priority-based scheduling.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EC2 Image Builder&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automated AMI and container image creation, testing, and distribution pipelines.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS App Runner&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run containerized web apps with zero infrastructure management. Source from ECR or GitHub.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Wavelength&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Compute deployed at 5G carrier edge. Single-digit millisecond latency to mobile devices.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="networking-advanced"&gt;Networking (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Transit Gateway&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Hub-and-spoke regional routing. Attach VPCs, VPNs, Direct Connect gateways. Supports multicast and inter-region peering.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Network Firewall&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed stateful VPC firewall with Suricata rule engine. IDS/IPS capability at the VPC perimeter.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS PrivateLink&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Expose services privately via VPC endpoints. No internet exposure, no overlapping CIDR concerns.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon VPC Lattice&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Application-layer networking for microservices. Service directory, auth policies, traffic controls across VPCs and accounts.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Cloud WAN&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed global WAN connecting VPCs, on-premises sites, and Direct Connect via a core network policy document.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="databases-advanced"&gt;Databases (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Aurora Serverless v2&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Auto-scaling Aurora capacity in fine-grained ACU increments. Per-second billing. Ideal for variable workloads.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon RDS Proxy&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Connection pooling layer in front of RDS/Aurora. Reduces connection exhaustion in Lambda-heavy architectures.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon MemoryDB for Redis&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Redis-compatible, durable in-memory database with Multi-AZ persistence. Not just a cache — a primary DB.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Timestream&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Purpose-built time-series database. IoT telemetry, DevOps metrics, financial data.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon QLDB&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Immutable, cryptographically verifiable ledger database. Not a blockchain — a trusted audit trail.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="security-advanced"&gt;Security (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Control Tower&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Landing zone automation for multi-account environments. Guardrails (SCPs + Config rules), Account Factory.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Inspector&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automated vulnerability assessment. Scans EC2 OS packages, Lambda code, and container images in ECR.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Macie&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;ML-based sensitive data discovery in S3. Identifies PII, credentials, PHI at scale.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IAM Identity Center (SSO)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Centralized SSO for AWS accounts and SAML 2.0 applications. Replaces per-account IAM users at scale.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Resource Access Manager (RAM)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Share AWS resources (Transit Gateway, subnets, Route 53 Resolver rules) across accounts within Organizations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Firewall Manager&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Central policy management for WAF, Shield Advanced, Network Firewall, and security groups across accounts.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Detective&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Security investigation using ML-powered graphs correlating CloudTrail, VPC Flow Logs, and GuardDuty findings.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="management--governance-advanced"&gt;Management &amp;amp; Governance (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Service Catalog&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;IT service catalog for publishing approved CloudFormation products. Self-service with governance guardrails.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Compute Optimizer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;ML-powered right-sizing recommendations for EC2, Lambda, EBS, ECS on Fargate, and Auto Scaling Groups.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Cost Explorer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Visualize and analyze AWS spend. Reservation/Savings Plans coverage, anomaly detection, rightsizing recommendations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Well-Architected Tool&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Structured review against the six pillars. Identify high-risk issues (HRIs) and generate improvement plans.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Resilience Hub&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Define RTO/RPO targets and validate application architecture against them with automated assessments.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Fault Injection Simulator (FIS)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Controlled chaos engineering. Pre-built actions for EC2, ECS, EKS, RDS, network. Observability integration.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="migration--transfer"&gt;Migration &amp;amp; Transfer
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Migration Hub&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Centralized tracking across migration tools. Integrates with MGN, DMS, and third-party tools.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Application Migration Service (MGN)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Agent-based lift-and-shift replication. Continuous block-level replication with minimal cutover window.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Database Migration Service (DMS)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Migrate databases with ongoing CDC replication. Homogeneous and heterogeneous migrations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Mainframe Modernization&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automated refactoring or replatforming of COBOL/PL1 workloads. Micro Focus and BluAge runtimes.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="analytics-advanced"&gt;Analytics (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon QuickSight&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Serverless BI and dashboard service. Paginated reports, ML-powered Q&amp;amp;A, anomaly detection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Lake Formation&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Build, secure, and share data lakes in S3. Fine-grained column/row access control over Glue Data Catalog.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Kinesis Data Firehose&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Zero-code streaming ingestion into S3, Redshift, OpenSearch, Splunk. Auto-scaling, buffering, transformation.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon MSK&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Apache Kafka clusters. MSK Connect for Kafka Connect workers. MSK Serverless option.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Service for Apache Flink&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Real-time stream processing. Replaced Kinesis Data Analytics. SQL, Java, Scala, Python APIs.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Workflows for Apache Airflow (MWAA)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Apache Airflow for data pipeline orchestration. Private network deployment.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="application-integration-advanced"&gt;Application Integration (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon AppFlow&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;No-code SaaS integration (Salesforce, Slack, Google Analytics, etc.) to/from S3 or Redshift.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS AppSync&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed GraphQL API service. Real-time subscriptions, offline data sync, conflict resolution.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Workflows for Apache Airflow (MWAA)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Airflow. Python-based DAG-driven orchestration for complex data workflows.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="containers-advanced"&gt;Containers (Advanced)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon ECR&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Container image registry. Private repositories, image scanning, lifecycle policies, cross-account access.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EKS Anywhere&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run EKS-compatible clusters on-premises using your own servers or VMware vSphere.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS App Mesh&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Envoy-based service mesh for microservices traffic management and observability (being superseded by VPC Lattice).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="tier-3--specialty-certification-services"&gt;Tier 3 — Specialty Certification Services
&lt;/h2&gt;&lt;p&gt;These services appear primarily in the &lt;strong&gt;Specialty&lt;/strong&gt; certification tracks. A practitioner without the specific domain context will struggle to use them effectively — but for the right workload, they are the correct and precise tool.&lt;/p&gt;
&lt;h3 id="networking-specialty-ans-c01"&gt;Networking Specialty (ANS-C01)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Direct Connect Gateway&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Aggregate multiple Virtual Interfaces across Regions and VPCs through a single Direct Connect connection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Network Access Analyzer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Identify unintended network access paths to resources using automated path analysis.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Route 53 Resolver&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Hybrid DNS: Inbound Endpoints (on-premises → VPC) and Outbound Endpoints (VPC → on-premises).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS VPC Traffic Mirroring&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Copy raw packet data from ENIs for IDS/IPS, deep packet inspection, or forensic capture.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Reachability Analyzer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Point-to-point connectivity verification. Analyzes routing, security groups, NACLs, VPC peering, VGW, TGW.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;VPC Flow Logs&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Capture IP traffic metadata (5-tuple) for security analysis, troubleshooting, and compliance evidence.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Transit Gateway Network Manager&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Centralized global network topology view. Monitors SD-WAN integrations via CloudWatch metrics.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Verified Access&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Zero-trust access proxy. Evaluate identity and device posture before granting access — no VPN required.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Cloud WAN (Advanced)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Global network policy with segment-based routing and inter-segment traffic inspection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;EC2 Placement Groups&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Cluster (low latency, same AZ), Partition (Hadoop/Cassandra isolation), Spread (hardware fault isolation).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="security-specialty-scs-c03"&gt;Security Specialty (SCS-C03)
&lt;/h3&gt;
 &lt;blockquote&gt;
 &lt;p&gt;The SCS-C02 exam was retired December 1, 2025. The current active version is &lt;strong&gt;SCS-C03&lt;/strong&gt;, available from December 2, 2025. The new version expands coverage of AI/GenAI security guardrails, multi-account governance, and zero-trust patterns.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CloudHSM&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Dedicated hardware security module. You manage the keys — AWS has zero access. FIPS 140-2 Level 3 certified.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Security Lake&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Centralize security data in OCSF (Open Cybersecurity Schema Framework) format. 50+ AWS native sources.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Audit Manager&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Continuous compliance evidence collection. Pre-built frameworks: PCI DSS, CIS, NIST 800-53, SOC 2, HIPAA.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Artifact&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;On-demand access to AWS compliance reports (SOC 1/2/3, ISO 27001, PCI DSS) and legal agreements (BAA, NDA).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Signer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Code signing for Lambda and container images. Ensures code integrity and provenance before deployment.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;IAM Access Analyzer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Identify externally accessible resources (S3 buckets, IAM roles, KMS keys, Lambda, SQS). Policy validation and generation.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Private Certificate Authority&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed private PKI. Issue internal TLS certificates for services that cannot use public ACM certs.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="aiml-specialty-mla-c01--mls-c01"&gt;AI/ML Specialty (MLA-C01 / MLS-C01)
&lt;/h3&gt;
 &lt;blockquote&gt;
 &lt;p&gt;The MLS-C01 (Machine Learning Specialty) had its last testing date on &lt;strong&gt;March 31, 2026&lt;/strong&gt;. The active ML certification is &lt;strong&gt;MLA-C01 (Machine Learning Engineer – Associate)&lt;/strong&gt;. MLS-C01 content remains relevant for practitioners working with deep SageMaker workflows.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Bedrock&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Unified API for foundation models: Anthropic Claude, Meta Llama, Mistral, Amazon Titan, Cohere, AI21. Includes Knowledge Bases, Agents, Guardrails, Model Evaluation, and Prompt Management.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon SageMaker (Advanced)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Pipelines (MLOps CI/CD), Feature Store, Model Monitor (drift/quality), Clarify (bias/explainability), JumpStart (model hub), HyperPod (distributed training clusters).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Q Developer&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AI coding assistant in IDE, CLI, and console. Code generation, security scanning, automated code transformation. Successor to CodeWhisperer.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Q Business&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Enterprise generative AI assistant. Connects to internal data sources (S3, Confluence, Salesforce) with fine-grained access control.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Trainium&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Purpose-built ML training chip. Trainium2 supports 100B+ parameter model training. Priced per chip-hour.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Inferentia&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Purpose-built ML inference chip. Cost-effective, high-throughput inference for production model serving.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Textract&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Document intelligence beyond OCR. Extracts structured forms, tables, signatures, and key-value pairs from PDFs and images.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Personalize&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Real-time ML-based recommendations. No ML expertise required — provide interaction data, receive ranked recommendations.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Forecast&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Time-series forecasting using AutoML. Demand planning, resource allocation, inventory optimization.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Fraud Detector&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed fraud detection combining ML models and business rules. Online fraud, account takeover, payment abuse.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Kendra&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Intelligent enterprise search. ML-powered relevance ranking. Connects to SharePoint, S3, Confluence, Salesforce.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Augmented AI (A2I)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Human review workflows for ML predictions that fall below confidence thresholds. Integrates with Textract and Rekognition.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="tier-4--extended-aws-portfolio"&gt;Tier 4 — Extended AWS Portfolio
&lt;/h2&gt;&lt;p&gt;These services address specific industry domains. Not regularly tested on the main certification tracks, but they represent real production workloads at scale for the right vertical.&lt;/p&gt;
&lt;h3 id="iot"&gt;IoT
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IoT Core&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed MQTT/HTTPS broker. Connect billions of devices, route messages to AWS services via a rules engine.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IoT Greengrass&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run Lambda, ML inference, and stream processing at the edge. Operates without continuous cloud connectivity.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IoT SiteWise&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Collect, structure, and analyze industrial equipment data (OPC-UA, Modbus). Digital twin asset model.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS IoT TwinMaker&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Build digital twins with real-time data integration. Integrates with SiteWise, Grafana, and Unreal Engine.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Kinesis Video Streams&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Ingest, store, and process video streams from connected devices. Integrates with Rekognition Video.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="end-user-computing"&gt;End-User Computing
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon WorkSpaces&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Windows/Linux virtual desktops. Personal or pooled. Billed hourly or monthly.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon AppStream 2.0&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Stream Windows desktop applications to any browser. No client installation required.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon WorkSpaces Web&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed, secure browser for accessing internal web applications. No data persists on the endpoint.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon WorkMail&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed business email and calendaring. Exchange-compatible. Integrated with Directory Service and SES.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="business-applications"&gt;Business Applications
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Connect&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Cloud contact center. Visual IVR flows, real-time analytics, ML-powered agent assist. Priced per minute used.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Pinpoint&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Customer engagement: email, SMS, push notifications, voice. Journey orchestration and campaign analytics.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon SES&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Scalable transactional and bulk email delivery. High deliverability, reputation management, configuration sets.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Supply Chain&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;ML-powered supply chain risk visibility. Inventory, demand sensing, and lead time analytics.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="media--streaming"&gt;Media &amp;amp; Streaming
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon IVS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Interactive live video streaming with sub-second latency. Timed metadata for real-time interactivity (polls, Q&amp;amp;A).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Elemental MediaConvert&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;File-based video transcoding. VOD workflows, HLS/DASH/CMAF output, DRM integration.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Elemental MediaLive&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Live video encoding for broadcast-quality output. Redundant pipelines for 24/7 channels.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Elemental MediaPackage&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Video origination and just-in-time packaging. HLS, DASH, and CDN origin integration.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="satellite--specialized"&gt;Satellite &amp;amp; Specialized
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Ground Station&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Satellite communication as a service. Schedule antenna contacts, downlink data directly into AWS.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Braket&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Quantum computing experimentation platform. Hardware from IonQ, Rigetti, Oxford Quantum Circuit, and D-Wave.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Blockchain&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Create and manage Hyperledger Fabric and Ethereum networks for traceability and provenance use cases.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="hybrid--edge"&gt;Hybrid &amp;amp; Edge
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Local Zones&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AWS infrastructure extension in major metros. Sub-10ms latency to end users for latency-sensitive workloads.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Snow Family (Edge Compute)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Snowball Edge runs EC2 instances and Lambda. Snowcone (2.1 kg) for disconnected, ruggedized environments.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;VMware Cloud on AWS&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run VMware vSphere workloads natively on AWS bare metal. No re-platforming required. Joint support.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon ECS Anywhere&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run ECS tasks on on-premises and edge servers registered as external instances.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon EKS Anywhere&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Deploy EKS-compatible clusters on-premises using your own servers or VMware vSphere.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="developer--devops-extended"&gt;Developer &amp;amp; DevOps (Extended)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS CDK&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Define cloud infrastructure using TypeScript, Python, Java, or Go. Synthesizes to CloudFormation.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Amplify&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Full-stack web and mobile app development. Hosting, authentication, GraphQL, storage — opinionated and fast.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS X-Ray&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Distributed tracing. Service map, latency histograms, root cause identification for microservices.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Grafana&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Grafana workspaces. Integrates natively with CloudWatch, Prometheus, and OpenSearch.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Service for Prometheus (AMP)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Prometheus-compatible metrics storage. Scales to tens of billions of samples.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Distro for OpenTelemetry (ADOT)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AWS-supported OpenTelemetry collector. Vendor-neutral trace and metric collection.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="data--analytics-extended"&gt;Data &amp;amp; Analytics (Extended)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Clean Rooms&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Collaborate on datasets with external partners without exposing underlying raw data. SQL-based analysis rules.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon DataZone&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Data governance portal. Catalog assets, define access policies, enable business-driven data discovery.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Entity Resolution&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Match and link related records across datasets using ML and rule-based matching.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Redshift Serverless&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Run Redshift analytics with no cluster provisioning. Auto-scaling compute, pay per workload run.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="management-extended"&gt;Management (Extended)
&lt;/h3&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Proton&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Automated deployment templates for container and serverless service teams. Platform team-managed scaffolding.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Amazon Managed Grafana&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Managed Grafana workspaces for operations dashboards and SLO visualization.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Distro for OpenTelemetry (ADOT)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Collect distributed traces and metrics in a vendor-neutral format compatible with Jaeger, Zipkin, and Prometheus.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="regional-availability--a-design-constraint-not-a-footnote"&gt;Regional Availability — A Design Constraint, Not a Footnote
&lt;/h2&gt;&lt;p&gt;Not all services are available in all AWS Regions. This is a hard architectural constraint that has broken production launch timelines.&lt;/p&gt;
&lt;p&gt;AWS operates &lt;strong&gt;37+ Regions&lt;/strong&gt; globally as of April 2026. When a new Region launches, it includes a defined set of core services. Additional services are added over subsequent months. Specialized and newer services may remain limited to a handful of Regions for extended periods.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Core services guaranteed in every Region launch&lt;/strong&gt; (partial list): EC2, S3, VPC, IAM, RDS, Lambda, EKS, ECS, CloudFormation, CloudWatch, CloudTrail, Config, KMS, DynamoDB, SQS, SNS, Direct Connect, ELB, EMR, EventBridge, Fargate, Redshift, OpenSearch.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Services typically available within 12 months of a new Region launch&lt;/strong&gt;: Athena, Backup, CloudFront, Cognito, Control Tower, DataSync, Directory Service, EFS, GuardDuty, IAM Identity Center, Lake Formation, SageMaker, Security Hub, Shield Advanced, Storage Gateway, Transit Gateway, WAF.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Services with limited or selective regional availability&lt;/strong&gt;: Bedrock (with all model providers), CloudHSM, Ground Station, Braket, Wavelength, Local Zones, Inferentia/Trainium instances, IVS, Elemental media services, IoT SiteWise, and most Tier 4 services.&lt;/p&gt;
&lt;h3 id="official-aws-regional-availability-resources"&gt;Official AWS Regional Availability Resources
&lt;/h3&gt;&lt;p&gt;Use these authoritative sources for production architecture decisions:&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Resource&lt;/th&gt;
 &lt;th&gt;URL&lt;/th&gt;
 &lt;th&gt;Purpose&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Services by Region&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a class="link" href="https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/" target="_blank" rel="noopener"
 &gt;aws.amazon.com/about-aws/global-infrastructure/regional-product-services/&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Official service availability per Region&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Capabilities by Region&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a class="link" href="https://builder.aws/capabilities-by-region" target="_blank" rel="noopener"
 &gt;builder.aws/capabilities-by-region&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Interactive multi-region comparison, API-level granularity, forward-looking roadmap quarters&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS Global Infrastructure&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a class="link" href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/" target="_blank" rel="noopener"
 &gt;aws.amazon.com/about-aws/global-infrastructure/regions_az/&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Region and AZ map, Local Zones, Wavelength Zones&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;AWS What&amp;rsquo;s New&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a class="link" href="https://aws.amazon.com/new/" target="_blank" rel="noopener"
 &gt;aws.amazon.com/new/&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Authoritative source for service launches and regional expansions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;AWS Capabilities by Region&lt;/strong&gt; (launched November 2025) is the most operationally useful tool for multi-region architecture planning. It provides side-by-side comparison across multiple Regions at the feature and API level — not just service level — and includes directional launch quarters (e.g., &amp;ldquo;2026 Q2&amp;rdquo;) for planned expansions. Use it before committing to a Region strategy.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img src="https://dantas.io/p/aws-services-complete-catalog-april-2026/aws-services-complete-catalog-april-2026-info2.png"
	width="2752"
	height="1536"
	loading="lazy"
	
		alt="Infographic illustrating AWS service tiers as a four-level mountain landscape. At the base (Tier 1 — The Foundational Bedrock) sit core services: EC2, S3, RDS, and VPC represented as stone blocks. Layer two (Tier 2 — Governance at Scale) shows locked gates and control towers for advanced multi-account management. Layer three (Tier 3 — Deep Domain Expertise) displays specialized domes labeled AI (Bedrock), Security (Security Lake), and Networking, surrounded by protective infrastructure. The summit (Tier 4 — Industry-Specific Niche) features satellite dishes, IoT sensors, media broadcast towers, and plant growth icons representing specialized services. "
	
 
	
		class="gallery-image" 
		data-flex-grow="179"
		data-flex-basis="430px"
	
&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="when-to-use-non-core-services-a-decision-framework"&gt;When to Use Non-Core Services: A Decision Framework
&lt;/h2&gt;&lt;p&gt;The services beyond the SAA-C03 core exist because the core services do not solve every problem at the required fidelity. The following principles guide selection:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Use Tier 2 services when your environment has one or more of these characteristics:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Multi-account at scale&lt;/strong&gt; — Control Tower, IAM Identity Center, RAM, and Firewall Manager are not optional at enterprise scale. They are the governance layer that prevents security and compliance debt from compounding.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hybrid connectivity beyond a VPN&lt;/strong&gt; — Transit Gateway replaces VPC peering mesh above 5 VPCs. Cloud WAN applies when routing policy spans multiple Regions with inspection requirements.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cost governance pressure&lt;/strong&gt; — Compute Optimizer, Cost Explorer, and Savings Plans are architectural inputs, not post-deployment afterthoughts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Active migration initiative&lt;/strong&gt; — MGN, DMS, and Migration Hub reduce risk during cutover windows. They do not eliminate architectural thinking; they replace manual replication and tracking.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Use Tier 3 Specialty services when your team owns a specific domain:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Networking&lt;/strong&gt; — Traffic Mirroring, Network Access Analyzer, Reachability Analyzer, and Verified Access address the gap between &amp;ldquo;connectivity exists&amp;rdquo; and &amp;ldquo;connectivity is provably secure and auditable.&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt; — CloudHSM when you cannot allow AWS to have any access to your cryptographic keys. Security Lake when you need SIEM-grade telemetry in OCSF format across accounts and tools. Audit Manager when compliance evidence collection cannot be manual.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI/ML&lt;/strong&gt; — Bedrock when you need frontier model access inside your AWS network perimeter with access control and auditability. SageMaker Feature Store and Pipelines when you need reproducible, governed ML workflows — not notebook experiments.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Use Tier 4 services when your industry vertical demands them:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;IoT for manufacturing, logistics, and utilities. Media services for broadcast and streaming. Ground Station for satellite data acquisition. Braket for quantum algorithm research. These are not general-purpose alternatives to core services — they are purpose-built for specific workloads where the alternative is building the capability from scratch.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="youtube"&gt;Youtube
&lt;/h2&gt;&lt;div class="video-wrapper"&gt;
 &lt;iframe loading="lazy" 
 src="https://www.youtube.com/embed/coZIChCtnlA" 
 allowfullscreen 
 title="YouTube Video"
 &gt;
 &lt;/iframe&gt;
&lt;/div&gt;

&lt;hr&gt;
&lt;h2 id="downloadable-excel-catalog"&gt;Downloadable Excel Catalog
&lt;/h2&gt;&lt;p&gt;The full catalog is available as a structured Excel workbook with six sheets covering all 230+ services organized by tier and category.&lt;/p&gt;

 &lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;&lt;a class="link" href="https://dantas.io/downloads/aws-services-catalog-dantas-io-2026.xlsx" &gt;Download: AWS Services Catalog — dantas.io (April 2026) (.xlsx)&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;Sheets included: README / Summary · Tier-1 Associate (SAA-C03) · Tier-2 Professional (SAP-C02) · Tier-3 Specialty Exams · Tier-4 Additional Services · All Services by Category (flat, sortable).&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="references"&gt;References
&lt;/h2&gt;&lt;p&gt;Amazon Web Services. (2026). &lt;em&gt;AWS services by category&lt;/em&gt;. Amazon Web Services Documentation. &lt;a class="link" href="https://docs.aws.amazon.com/whitepapers/latest/aws-overview/amazon-web-services-cloud-platform.html" target="_blank" rel="noopener"
 &gt;https://docs.aws.amazon.com/whitepapers/latest/aws-overview/amazon-web-services-cloud-platform.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Amazon Web Services. (2026). &lt;em&gt;AWS certification exam guides&lt;/em&gt;. Amazon Web Services Certification. &lt;a class="link" href="https://docs.aws.amazon.com/aws-certification/latest/examguides/aws-certification-exam-guides.html" target="_blank" rel="noopener"
 &gt;https://docs.aws.amazon.com/aws-certification/latest/examguides/aws-certification-exam-guides.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Amazon Web Services. (2026). &lt;em&gt;AWS global infrastructure — Regions and Availability Zones&lt;/em&gt;. Amazon Web Services. &lt;a class="link" href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/" target="_blank" rel="noopener"
 &gt;https://aws.amazon.com/about-aws/global-infrastructure/regions_az/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Amazon Web Services. (2026). &lt;em&gt;Regional product services&lt;/em&gt;. Amazon Web Services. &lt;a class="link" href="https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/" target="_blank" rel="noopener"
 &gt;https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Amazon Web Services. (2025, November). &lt;em&gt;Introducing AWS Capabilities by Region for easier Regional planning and faster global deployments&lt;/em&gt;. AWS News Blog. &lt;a class="link" href="https://aws.amazon.com/blogs/aws/introducing-aws-capabilities-by-region-for-easier-regional-planning-and-faster-global-deployments/" target="_blank" rel="noopener"
 &gt;https://aws.amazon.com/blogs/aws/introducing-aws-capabilities-by-region-for-easier-regional-planning-and-faster-global-deployments/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Amazon Web Services. (2026). &lt;em&gt;What&amp;rsquo;s new with AWS&lt;/em&gt;. Amazon Web Services. &lt;a class="link" href="https://aws.amazon.com/new/" target="_blank" rel="noopener"
 &gt;https://aws.amazon.com/new/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Tutorials Dojo. (2025). &lt;em&gt;What&amp;rsquo;s new in AWS Certified Security Specialty SCS-C03 exam in 2025–2026&lt;/em&gt;. &lt;a class="link" href="https://tutorialsdojo.com/whats-new-in-aws-certified-security-specialty-scs-c03-exam-in-2025-2026/" target="_blank" rel="noopener"
 &gt;https://tutorialsdojo.com/whats-new-in-aws-certified-security-specialty-scs-c03-exam-in-2025-2026/&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>