solutions architect · study hub

How the cloud actually works: one request, every pillar, across AWS, GCP and Azure

Companion to the network visualizer. Five sections: a step-by-step walk of one request from phone to database (start here if any of this is new), the non-networking exam domains as decision-oriented cards with a diagram each, an animated disaster-recovery failover simulator, a door into the three-cloud atlas of service names, and the deep conceptual differences between the three clouds that actually change your architecture. Every diagram has a plain-English caption, no cloud background assumed.

AgentCore lab ↗ Agents lab ↗ ADK lab ↗ Evals lab ↗ Gemini lab ↗ Govern lab ↗ Diagram lab ↗

Follow one tap: what happens between the phone and the answer

Your phonetaps "open" DNSRoute 53 / Cloud DNS CDN edgeCloudFront / Cloud CDN Load balancerALB / Cloud LB Object storageS3 / Cloud Storage App servers3 running CacheRedis / Memorystore DatabaseRDS / Cloud SQL QueueSQS / Pub-Sub Workersends the email

Now break something

Try this: switch pieces off and send a request. Some failures nobody notices, some make the site slower, and one takes it down completely. That difference is the entire reason the diagram has this many boxes.
in real lifeA relay of people passing a note across a building. Remove one and sometimes the note still gets through by another route; remove a different one and everything stops.
start byswitch off the cache and send a request, then switch off the database and send another. Very different outcomes.
words hererequest one tap on a phone, travelling all the way to a server and backcache a copy of a recent answer kept close byload balancer the receptionist deciding which server takes this oneCDN copies of your content kept near users, so it loads from nearbyDNS the phone book that turns a name into an address

Every stop

The trick that makes it click

In plain English: the seven layers are not seven steps a message goes through. They are seven separate conversations happening at once, each layer talking only to its own counterpart on the machine at the other end, and treating everything handed down from above as sealed cargo it must never open.
Layer 3 on your laptop is having a conversation with layer 3 on the server. It neither knows nor cares that the bytes it is carrying happen to be an HTTP request. Layer 3 on a router halfway between them cares even less. It reads the address on the outside and passes it on.
That is the whole idea. Once you have it, the model stops being a list to memorise and becomes a way of narrowing down where a problem lives.

Try it: post a birthday card, one layer at a time

Try this: you want to send a birthday message to a friend abroad. Walk the seven things that happen to it, and at each step look at what the person carrying it can actually see. Then press the sorting office to find out how much of your message the postal worker in the middle is allowed to read.
in real lifeThis is the real life one. Post has worked this way for two centuries, and computer networks copied it, which is why the analogy is not a simplification but the actual design.
start bypress 1 and keep going. Then press the sorting office.
words hereencapsulation wrapping something in an outer layer that hides what is insidepayload the part being carried, which the carrier never opensheader the writing on the outside of the wrapperhop one leg of the journey, between two neighbours

One request, wrapped and unwrapped: what each layer adds

Try it: trace your own lab request through the stack

Try this: one concrete request, curl http://203.0.113.7/, followed all the way down and back. Step down the stack watching each layer add its own wrapper, then step back up the other side watching each one strip its wrapper off, until Apache sees nothing but the HTTP request. The last step explains why your firewall rule is written the way it is.
in real lifePacking a parcel inside a box, inside a sack, onto a lorry, then the same in reverse at the other end. Nobody along the way unpacks more than their own layer.
start bypress send and step all the way down, then keep going. The return journey is where it clicks.
words herecurl a command that fetches a web page from the terminalsegment / packet / frame what the message is called at layers 4, 3 and 2port the number saying which program on the machine should get itMAC address the name of one network card, used for a single hop

The seven layers

Two memory aids. Top-down, 7→1: All People Seem To Need Data Processing. Bottom-up, 1→7: Please Do Not Throw Sausage Pizza Away.

The honest caveat. Real networks run TCP/IP, not OSI. Layers 5, 6 and 7 do not exist as separate things in practice, HTTPS smears encryption, session and application into a single stack. OSI survives anyway, because it gives engineers a shared vocabulary: saying “that’s a layer 3 problem” instantly means routing, rather than the app being broken.

How you actually use this at 3am

In plain English: the payoff of the model is not knowing the seven names. It is being able to cut the search in half with one command, then in half again, because each test that passes eliminates everything below it.
What you observeWhere the problem isBecause
Cannot ping the IP at allLayer 3Nothing is reaching the machine. Routing, the address, or a network-level block, and no point looking at the app
Ping works, but the port is refusedLayer 4The machine is reachable, so routing is fine. Either a firewall is blocking that port or nothing is listening on it
Port is open, but you get a 500Layer 7The whole network path works. The request arrived and the application itself failed, stop looking at infrastructure
Works by IP, fails by nameLayer 7 (DNS)Everything below is proven by the IP working. Only the name lookup is broken
Works from one machine, not anotherLayer 3 or 4The service is fine, so it is about the path or the permission, a source range, a security group, a route
That is layer-by-layer elimination, and it is the model’s real payoff. Each of those tests is cheap, and each one rules out several floors of the building at once. Working up from the bottom is almost always faster than guessing at the top, because the lower layers are the ones with fewer possible causes.

Break something: and see which layer stops it

Try this: every one of these faults looks identical to a user (“the site is down”) and completely different to whoever has to fix it. Pick one, watch how far the request gets, and read what the command actually prints.
in real lifeA tap that will not run. It could be the tap, the pipe, the stopcock, or the water company. To the person in the kitchen all four look exactly the same.
start bypick DNS fails, then pick the certificate expired, and compare what the commands print.
words hereOSI layers seven named levels, from the cable up to the app, used to say where a fault livesDNS the phone book that turns a name into an addresscertificate the proof a site is who it says it is. It expires on a dateNAT lets private machines reach the internet without being reachable themselvesTLS the encryption that makes it https rather than httpWAF a filter in front of the app that blocks known-bad web requests

The comparison that comes up most

Send traffic

What this shows

CIDR calculator: how many addresses does that block actually give you?

Why five are missing: AWS reserves the first four addresses and the last one in every subnet, network, VPC router, DNS, one held for future use, and broadcast. GCP reserves four. That is why a /28 gives you 11 usable addresses, not 16.

Where does each layer actually stop something?

Try this: click down the ladder. Each rung looks like a container, but only some of them are a real wall. Knowing which is which is the difference between a design that holds and one that only looks like it does.
in real lifeA building with a perimeter fence, locked floors, and rooms with no locks at all. Three of those look like security. Only two of them are.
start byclick Subnet and read the line about what it stops. It is the answer most people get wrong.
words hereVPC your own private network in the cloud, with nothing going in or out until you allow itsubnet a slice of that network, a routing decision, not a wallblast radius the most damage something can do if it goes wrong

The estate map: click any part of it

Try this: this is one company’s cloud network, drawn once. Click a box and you get the plain-English version, what it has to sit next to, what it must never share a room with, and what breaks when somebody ignores that.
in real lifeA business park. A gatehouse everyone drives through, a shopfront facing the road, a private road to head office, and the buildings where the actual work happens.
start byclick the GUT / shared utility box. The tier nobody thinks about until it is down.
words hereperimeter the security gate all traffic passes through and is inspected atbastion the single controlled door administrators use to log inproxy something that stands in the middle and decides what may passprivate link a hatch exposing one service, instead of joining two networksDNS the phone book that turns a name into an addressNAT lets private machines reach the internet without being reachable themselvesVPC your own private network in the cloudWAF a filter in front of the app that blocks known-bad web requests

Try it: put eight things in the right subnet

Try this: eight real workloads, seven tiers. Some are obvious. Two of them are the ones people get wrong in production, and the reason is written out either way.
in real lifeDeciding which room in a building each thing goes in. The reception desk faces the street; the safe does not. Almost nothing you build belongs at the front.
start byplace the batch worker that downloads from a partner API in the public tier and read why that is the trap.
words herepublic subnet the only tier with a route out to the open internetprivate subnet no route in from outside; it reaches out through a controlled pathendpoint a private door to a cloud service, so you never go via the internetACL a list of what traffic is allowed in or outIAM the permissions system, who and what may do which thingsKMS the managed service that holds and rotates encryption keysVPC your own private network in the cloudegress traffic going out, your side reaching outservice account a login used by a program rather than a personsignature a recognisable pattern of known-bad traffic

Try it: close one gate and read the symptom

Try this: one request, seven gates, every one of which must say yes. Close any of them and the request fails, but each layer fails in a different way, and telling those ways apart is the single most useful debugging skill on this page.
in real lifeGetting into a building: a road to the door, a key that turns, and your name on the list inside. Missing the road and missing the key feel completely different, one is a locked door, the other is being lost.
start byclose the route table gate, then close the identity policy gate, and compare the two symptoms.
words hereroute whether there is a path there at allsecurity group the rule on the door of one machine saying who may knockIAM who is allowed to do what, once they have arrivedAccessDenied a fast, explicit refusal, as opposed to a hang, which means the networkACL a list of what traffic is allowed in or outCIDR the /24-style notation for how big a block of addresses isVPC your own private network in the cloud

Try it: hand out address ranges, then try to connect them

Try this: pick how big the estate is and watch the plan fall out of it. Then turn on the shortcut everybody takes when they are in a hurry, and see which day it stops being free.
in real lifeHouse numbering across a town. Two streets can both have a number 14 quite happily, right up to the day the council merges them and the post stops being deliverable.
start bytick every region just uses 10.0.0.0/16 and read the four days on which that stops being free.
words hereCIDR a range of addresses written as a block, like 10.0.0.0/16/16 and /24 the bigger the number, the smaller the blockoverlap two networks using the same addresses. They can never be joinedpeering connecting two networks so they can reach each otherDNS the phone book that turns a name into an addressNAT lets private machines reach the internet without being reachable themselvesTLS the encryption that makes it https rather than httpVPC your own private network in the cloudWAF a filter in front of the app that blocks known-bad web requests

Try it: follow six journeys through the estate

Try this: pick a journey and walk it hop by hop. Then remove one control and see the shortcut the traffic takes instead, which is exactly the path an incident report describes afterwards.
in real lifeFollowing a parcel through a sorting office. Every stop is somewhere it can be checked, delayed or turned back, and the fast route is fast because nobody is checking.
start bychoose an app server downloads a patch, then tick the box to remove the control in the middle.
words hereegress traffic going out, your side reaching outNAT hides who is asking, but has no opinion about where they are goingforward proxy checks whether you are allowed to go there, and writes it downhop one step of the journeyACL a list of what traffic is allowed in or outCIDR the /24-style notation for how big a block of addresses isDNS the phone book that turns a name into an addressIAM the permissions system, who and what may do which thingsKMS the managed service that holds and rotates encryption keysVPC your own private network in the clouddistractor a wrong option that is a real answer to something else

Try it: the same traffic, four routes, four bills

Try this: your private servers need to read files from object storage. Nothing about the application changes in any of these four, only the route the bytes take. Move the volume up and watch three of the four bills stop being rounding errors.
in real lifeFour ways to get stock from the warehouse next door. Walk it across the yard, drive it round the ring road, post it, or courier it. The goods are identical and so is the destination. One of them charges you by the parcel and by the hour, and nobody notices until the volume grows.
start byleave it on NAT gateway and drag the volume to 50 TB, then switch to gateway endpoint without moving anything else.
words hereNAT gateway a managed box that lets private machines reach out without being reachablegateway endpoint a private door to object storage, added to your route tableinterface endpoint a private address inside your network for a serviceavailability zone one physically separate data centre in a regionegress traffic going out, your side reaching outobject storage a service that holds files, addressed by name

Try it: how many networks should this estate have?

Try this: five questions about what you are actually building. The recommendation at the end is not the interesting part. The trade-off underneath it is, because every one of these answers costs you something.
in real lifeDeciding how many buildings a company needs. One open-plan floor is cheap and means anyone can wander into payroll. Four buildings means somebody has to be let in, which is the whole point, and also four sets of keys.
start byanswer just production to the first question and read the warning that appears.
words hereVPC your own private network in the cloudenvironment production, testing, sandbox, the same system at different stakeshub one place all the networks attach to, instead of joining every pairblast radius the most damage something can do if it goes wrongNAT lets private machines reach the internet without being reachable themselves

Try it: audit what is sitting in the public subnet

Try this: ten things somebody has put in a public subnet on a real estate. Decide which of them belong there. Most do not, and two of them are not the ones you would guess.
in real lifeWalking round a building checking which rooms have a door onto the street. The reception should. The server cupboard should not, even if the door is currently locked.
start byjudge the database, with public accessibility switched off. It is the one people argue about.
words herepublic subnet a subnet whose route table has a way out to the internetprivate subnet one that does not, so nothing can arrive from outsidepublic IP an address the internet can actually send toNAT lets private machines reach the internet without being reachable themselvesVPC your own private network in the cloud

Try it: size the subnets before anything is built

Try this: the sizing nobody does until it is too late. Set the shape of the estate and watch which tier runs out first. It is rarely the one people worry about.
in real lifeNumbering the parking bays before the building opens. Twelve spaces for visitors and four hundred for staff is not tidy, and it is what the building actually needs.
start bydrag private endpoints up to 40 and watch which bar turns red first.
words heresubnet a slice of the network with its own range of addresses/24, /28 how big a slice is, the bigger the number, the smaller the sliceprivate endpoint a private door to a cloud service, one address per zoneheadroom spare addresses for growth you have not thought of yetVPC your own private network in the cloud

Try it: do you actually need one of these?

Try this: eight components people add because a reference architecture had one. For each, the question that decides it, and what it costs you if you add it anyway.
in real lifeBuying tools for a new workshop. The catalogue photo has thirty of them on the wall. You need four, and the other twenty-six are things to store, maintain and trip over.
start byclick Bastion host. It is the one most estates still have and most no longer need.
words hereNAT gateway lets private machines reach out to the internetbastion one hardened machine administrators log intofirewall appliance a device that inspects traffic in the pathtransit hub one junction every network plugs into onceVPC your own private network in the cloud

Try it: sort a case study into what actually binds you

Try this: twelve lines lifted from a case study. Only some of them are requirements. Sorting them is the skill the exam is really testing, because an answer that is excellent and breaks one stated constraint is still wrong.
in real lifeReading a job advert. Most of it is about the company's exciting culture. Two lines say “must have a driving licence” and “office-based five days a week”, and those are the only ones that decide whether you can take it.
start bysort the line about the operations team having no Kubernetes experience. It reads like background and it is not.
words herecase study a long company scenario the exam publishes in advancebusiness requirement something the company wants to achieve, in business termsconstraint something that rules options out, a law, a deadline, a skill the team lacks

Try it: work a case end to end

Try this: a complete fictional case, with the requirements it states. Choose an architecture, then see which requirements your choices satisfy and which they quietly break, scored against what the case said, not against general good practice.
in real lifeChoosing a car for someone else. The fastest one is not the answer if they told you it has to fit three child seats and cost under fifteen thousand.
start bypick Rewritten as containers on Cloud Run for the monolith and read why the better answer is the wrong one.
words herePub/Sub a durable queue for messages that must not be lostBigtable a store built for enormous write volumes looked up by keyBigQuery a warehouse for asking questions across huge historyorganisation policy a rule set company-wide that no project can overrideGKE Google’s managed Kubernetes. It runs your containers for youVPC your own private network in the cloud

Try it: the option that works and is still wrong

Try this: six questions where more than one answer would function. Only one survives what the scenario actually said. This is the single commonest way marks are lost on this exam.
in real lifeA pub quiz where three of the four answers are true statements and only one answers the question asked.
start byread each scenario twice before looking at the options, and note the word that disqualifies.
words herescales to zero costs nothing when nobody is using itSpot VM a cheap machine the cloud may take back at any momentcommitted use discount a lower rate in exchange for committing to a year or threeGKE Google’s managed Kubernetes. It runs your containers for youIAM the permissions system, who and what may do which thingsVPC your own private network in the cloud

Try it: trigger phrases, one at a time

Try this: the same drill shape as the AWS tab, in Google’s vocabulary. A card only clears after two clean passes, so recognising it once does not count.
in real lifeFlashcards for a language you half know. Recognising a word on the page is not the same as producing it in conversation, which is why one pass does not clear a card.
start byanswer out loud before you press show the answer. Thinking “I knew that” after seeing it is the trap this drill exists to close.
words heretrigger phrase the wording in a question that points at one particular serviceShared VPC one team owns the network, many projects deploy into itVPC Service Controls a boundary data may not cross, whoever is askingIAM the permissions system, who and what may do which things

What NGINX actually is

In plain English: NGINX is a very fast, very calm receptionist that sits in front of your application. Everything arriving from the internet talks to it first. It checks who the visitor asked for, hands them a leaflet from the drawer if it already has one, deals with the locked front door, and only bothers your staff when it genuinely has to. It is the same job the cloud load balancers do, except this one is a program you run and configure yourself, which is exactly why it is still everywhere.

One process does four jobs that used to need four products: web server (hands out files), reverse proxy (forwards requests to your app), load balancer (spreads them across several copies), and edge (TLS, caching, compression, rate limiting). In Kubernetes it is usually running as the ingress controller, so if you use Kubernetes you almost certainly run NGINX already, whether you chose it or not.

Why it stays fast when a thousand people arrive at once

One request, step by step through NGINX

The jobs you actually configure

Run it yourself: turn things on and send traffic

Try this: switch the cache off and send twenty requests, then switch it on and send twenty more. Then break the upstream and watch the difference between a cache that can serve stale and one that cannot.
in real lifeA shop assistant who keeps the ten most-asked-about items on the counter. Most customers are served without anyone going to the stockroom.
start bysend twenty requests with the cache off, then switch it on and send twenty more.
words herecache a copy of a recent answer kept close byhit rate the fraction of requests answered without going to the databaseorigin the real source, at the far end, that you are trying not to bother

What goes wrong in production, and what you see when it does

The one sentence every permission system is trying to write

In plain English: somebody is allowed to do something to a particular thing, and sometimes only under certain conditions. That is the whole idea. All three clouds write that sentence. They just disagree about the grammar, and about what happens when two sentences contradict each other.

Where permissions come from: grant one, see what it reaches

Try this: grant at the organisation and watch every resource light up. Then try to take one back by granting less further down. You cannot. Only a deny or a guardrail claws anything back, which is why a grant made high up is never really temporary.
in real lifeGiving someone a master key at head office. It opens the branch offices too, and every cupboard in them, and nobody at the branch was asked.
start bygrant at the top level and watch how far down the tree it reaches.
words hereinheritance a permission given high up applies to everything beneath itscope how much of the estate a permission coversleast privilege granting the smallest thing that still does the job

Two different gates: what you may do, and what may exist

The distinction people miss: a permission answers “may this person do it?” A guardrail answers “may anyone do it here, ever?” They are separate systems, checked separately, which is why a full administrator can still be refused, and why nobody can grant their way around a guardrail.

Try it: will this request be allowed?

Try this: give the developer admin rights, then turn the region guardrail on and try to create a VM in the wrong region anyway. Admin does not help. That is the point of a guardrail.
in real lifeA company rule that no office may be opened abroad. It does not matter how senior you are. The rule is above you, and that is the whole point of it.
start bygrant full admin, then switch the guardrail on and try the same action again.
words hereguardrail a rule set above an account that nobody inside it can overrideexplicit deny a refusal that beats every permission granted anywhere elseboundary a ceiling on what a role is able to grant itself

How a machine proves who it is

How privilege escalates quietly

Segregation: where to draw the lines

Provisioning roles without creating a second job for yourself

AWS, GCP and Azure: the same job, three models

The checklist, and what a reviewer looks for

What the exam is, and how it is scored

Trigger words: what the question is really asking for

How to use this: SAP-C02 questions are long, and most of the length is scenery. One or two phrases carry the decision. Learn to spot those phrases and the answer usually falls out before you have finished reading the options.
AreaWhen you see thisThe answer is usuallyBecause

Drill: one trigger at a time

Missed cards come back. The deck is not finished until you have seen every one of them twice in a row without a miss, which is a better use of ten minutes than re-reading the table.

The four decisions that carry the most marks

Numbers that decide answers

Traps, and how the exam words things

Database connection pool: what min and max actually decide

In plain English: opening a database connection is slow, a handshake, a login, a bit of setup. So the app opens a few up front and lends them out. Min is how many it keeps warm even when nothing is happening. Max is the most it will ever open. Every request that cannot get one waits in a queue, and if it waits too long it gives up with an error that looks nothing like “the pool was full”.

Idle timeouts: every layer has one, and they disagree

In plain English: a connection nobody is using gets closed, to stop things holding resources forever. The trouble is that the browser, the load balancer, the NAT gateway, your app and the database all do this, each on a different clock, and none of them tells the others. Almost every mysterious hang or intermittent 502 is two of these numbers disagreeing.

MVC: where the logic is allowed to live

In plain English: a restaurant. The waiter takes your order and brings the food, but never cooks. The kitchen knows the recipes and owns the ingredients, but never talks to you. The plate is how it arrives at the table. MVC is the same split, and almost every complaint about it comes from one of the three doing another one's job.

Failover simulator: pick a strategy, then break us-east-1

Users global Route 53 failover routing · health checks PRIMARY · us-east-1 Load balancer App fleet · 6 instances Aurora (writer) RECOVERY · eu-west-1 Load balancer App fleet Database replication

Strategy

Strategy notes

Service translator: it grew into its own lab

What this is for: the three clouds mostly sell the same things under different names, the way the same shop is a chemist, a drugstore and a pharmacy. The translator that lived here has grown into the three-cloud atlas: every service each provider lists, mapped onto the jobs they do, with what each buys you and bills you, what has been renamed or retired since 2024, and the small print where “equivalent” is not the same thing. Type a name from any cloud and it opens there.
The Cloud differences tab next door keeps the handful of structural differences that change an architecture; the atlas keeps the names.

Try it: which cloud behaves like this?

Try this: ten behaviours. Name the cloud each one describes. These are the structural differences that actually change a design, not naming trivia, which is why every one of them has a consequence attached.
in real lifeThree cars from three manufacturers. Most of the differences are where the buttons are. Two of them are whether it is front or rear wheel drive, and that one changes how you drive it.
start byanswer the first one about a global network. It is the difference that changes designs most.
words hereVPC / VNet your own private network, called different things by each cloudregion a geography containing several zoneszone one failure domain within a regionstateful / stateless whether a firewall remembers that it let a request in