Acing the Fresher AWS Technical Interview
.png&w=3840&q=75)
Recruiters do not expect freshers to know how to architect multi-region, active-active failover systems. What they *do* expect is a rock-solid, concrete understanding of the fundamentals, networking, and security.
Core Compute (EC2) Questions
1. Can you explain the difference between an On-Demand, Spot, and Reserved EC2 instance?
Answer: On-Demand is pay-by-the-second with no commitment, used for unpredictable workloads. Spot instances use spare AWS capacity at up to 90% discount, but AWS can terminate them with a 2-minute warning (good for batch processing). Reserved Instances require a 1-3 year contract in exchange for up to 72% discount, perfect for steady-state databases or primary app servers.
2. How would you connect securely to a private Linux EC2 instance from your laptop?
Answer: I would not open Port 22 to the internet (0.0.0.0/0). Instead, I would use AWS Systems Manager Session Manager (SSM) which allows secure shell access via the browser without requiring inbound ports, or use an EC2 Instance Connect Endpoint via a Bastion Host.
Storage (S3 & EBS) Questions
3. When would you use EBS instead of S3?
Answer: EBS (Elastic Block Store) is block storage attached directly to a single EC2 instance, running an OS or database. It is fast and local. S3 (Simple Storage Service) is object storage over the internet (HTTP via high-level API). I would use EBS for my C: drive or database files, and S3 for storing user-uploaded images or backups.
4. What happens if you accidentally delete a critical file in an S3 bucket? How do you prevent this?
Answer: To prevent accidental deletion, I would enable S3 Versioning alongside MFA Delete. If versioning is enabled and a file is deleted, AWS simply places a "delete marker" on top of it, but the old version is fully retrievable.
Networking (VPC) Fundamentals
5. What is the fundamental difference between a Public and Private Subnet?
Answer: A public subnet has a route table entry pointing to an Internet Gateway (IGW), allowing direct internet access. A private subnet does not have a route to an IGW; it can only access the internet outwards via a NAT Gateway that sits in the public subnet.
6. Security Groups vs NACLs—how do they differ?
Answer: Security Groups operate at the Instance level, act as a virtual firewall, and are stateful (if traffic is allowed in, return traffic is automatically allowed out). NACLs (Network Access Control Lists) operate at the Subnet level, are stateless (inbound and outbound rules must be explicitly defined), and support explicit DENY rules.
Databases (RDS & DynamoDB)
7. What is the difference between Amazon RDS and DynamoDB?
Answer: RDS is a managed relational database service supporting SQL engines like MySQL, PostgreSQL, and Oracle, ideal for complex transactions and structured data. DynamoDB is a fully managed NoSQL serverless key-value database built for single-digit millisecond performance at an infinite scale, perfect for unstructured data or high-traffic web apps.
8. How does Amazon RDS Multi-AZ differ from Read Replicas?
Answer: Multi-AZ is strictly for disaster recovery (High Availability); it synchronously replicates your primary DB to a standby instance in another Availability Zone, and automatically fails over if the primary goes down. Read Replicas are for improving performance (Scalability) by asynchronously replicating data to read-only instances offloading read traffic from the primary DB.
Security & Identity (IAM)
9. What is the Principle of Least Privilege?
Answer: It is a fundamental security practice in AWS IAM where a user, group, or role is granted only the minimum permissions necessary to perform their specific job functions, and nothing more.
10. Why should you use IAM Roles instead of IAM Users for EC2 instances?
Answer: Hardcoding IAM User access keys (Access Key ID and Secret Access Key) inside an EC2 instance is a major security risk. Instead, you attach an IAM Role to the EC2 instance, which securely provides temporary, automatically rotating credentials to the instance to access other AWS services like S3 or DynamoDB.
Scaling and Load Balancing
11. What are the main types of Elastic Load Balancers (ELB) in AWS?
Answer: The three main ELBs are the Application Load Balancer (ALB) acting at Layer 7 (HTTP/HTTPS) routing traffic based on URL paths or hostnames, the Network Load Balancer (NLB) acting at Layer 4 (TCP/UDP) for ultra-low latency and extreme performance, and the Gateway Load Balancer (GWLB) used for deploying third-party network virtual appliances.
12. How does Auto Scaling work in conjunction with an ALB?
Answer: An Auto Scaling Group (ASG) uses target tracking or step scaling policies governed by CloudWatch alarms (e.g., CPU utilization > 70%) to automatically launch or terminate EC2 instances. Once an instance is launched and passes health checks, it is automatically registered with the Application Load Balancer to start receiving traffic.
Serverless and Application Services
13. What is AWS Lambda and what is its primary limitation?
Answer: AWS Lambda is a serverless compute service that runs code in response to events without provisioning or managing servers. Its primary limitations are the 15-minute maximum execution timeout per function and cold starts when a function hasn't been invoked recently.
14. What is the difference between SQS and SNS?
Answer: Amazon SQS (Simple Queue Service) is a message queuing service using a pull-based model, where workers poll the queue to retrieve messages for processing (Point-to-Point). Amazon SNS (Simple Notification Service) is a publish-subscribe service using a push-based model, where a single message is fanned out to multiple subscribers like SQS queues, Lambda functions, or email addresses.
15. How do you serve static website assets globally with low latency?
Answer: I would store the static assets (HTML, CSS, JS, images) in an Amazon S3 bucket, and place Amazon CloudFront (a Content Delivery Network) in front of it. CloudFront will cache the assets at edge locations globally, drastically reducing load times for users regardless of their geographic location.
(Looking for more? Dive into our interactive portal to practice all 50+ scenario-driven questions inside modern cloud environments.)