Cloud
Computing
Technical
Skills
CO RE
SK IL L
AREAS
01 – 15
01
Cloud
Platforms
&
Providers
Vendor
ecosystems
,
console
and
API
fluency
,
and
multi
-
cloud
operating
models
.
Amazon
Web
Services
(
AWS
)
Microsoft
Azure
Google
Cloud
Platform
(
GCP
)
Oracle
Cloud
Infrastructure
(
OCI
)
IBM
Cloud
Alibaba
Cloud
DigitalOcean
VMware
Cloud
on
AWS
Multi
-
cloud
architecture
Hybrid
cloud
&
on
-
prem
integration
02
Compute
&
Virtualization
Instance
sizing
,
scaling
behaviour
,
and
the
virtualization
layers
underneath
.
Amazon
EC
2 /
Azure
VMs
/
Compute
Engine
Auto
Scaling
groups
&
VM
scale
sets
Load
balancing
(
ALB
,
NLB
,
App
Gateway
)
Instance
right
-
sizing
Spot
,
preemptible
&
reserved
capacity
Bare
-
metal
instances
GPU
&
accelerator
instances
(
A
100,
H
100)
Placement
groups
&
affinity
rules
Arm
-
based
compute
(
AWS
Graviton
,
Ampere
)
Hypervisors
(
KVM
,
Xen
,
ESXi
,
Hyper
-
V
)
03
Storage
&
Data
Management
Object
,
block
,
and
file
storage
design
,
durability
models
,
and
lifecycle
economics
.
Object
storage
(
S
3,
Blob
Storage
,
GCS
)
Block
storage
(
EBS
,
Managed
Disks
,
Persistent
Disk
)
Managed
file
systems
(
EFS
,
Azure
Files
,
Filestore
)
Storage
classes
&
lifecycle
policies
Snapshots
,
backups
&
point
-
in
-
time
recovery
Cross
-
region
replication
Data
lake
storage
(
S
3 +
Glue
/
Athena
)
Offline
transfer
(
Snowball
,
Azure
Data
Box
)
IOPS
&
throughput
tuning
Data
compression
&
deduplication
1 / 6
04
Networking
&
Content
Delivery
Virtual
network
topology
,
connectivity
,
edge
delivery
,
and
traffic
control
.
VPC
/
VNet
design
&
subnetting
Route
tables
,
NAT
&
internet
gateways
Security
groups
&
network
ACLs
DNS
(
Route
53,
Azure
DNS
,
Cloud
DNS
)
CDN
(
CloudFront
,
Front
Door
,
Cloud
CDN
)
Transit
Gateway
&
VNet
peering
Site
-
to
-
site
VPN
Direct
Connect
/
ExpressRoute
Global
load
balancing
&
failover
routing
Private
Link
&
private
endpoints
Cloud
firewalls
(
Network
Firewall
,
Palo
Alto
VM
-
Series
)
IPv
6
dual
-
stack
05
Containers
&
Orchestration
Container
packaging
,
Kubernetes
operations
,
and
cluster
scaling
strategy
.
Docker
&
container
image
builds
Kubernetes
(
EKS
,
AKS
,
GKE
)
Helm
Ingress
controllers
&
Gateway
API
Container
registries
(
ECR
,
ACR
,
Artifact
Registry
)
Horizontal
&
vertical
pod
autoscaling
Kustomize
Service
mesh
(
Istio
,
Linkerd
,
App
Mesh
)
KEDA
event
-
driven
scaling
StatefulSets
&
persistent
volumes
Cluster
Autoscaler
&
Karpenter
OpenShift
,
Rancher
,
Tanzu
06
Infrastructure
as
Code
Declarative
provisioning
,
module
design
,
and
policy
enforcement
.
Terraform
AWS
CloudFormation
Azure
Bicep
&
ARM
templates
Ansible
OpenTofu
Terragrunt
Pulumi
Packer
Crossplane
Policy
as
code
(
OPA
/
Rego
,
Sentinel
,
Checkov
)
Module
design
&
remote
state
management
Configuration
drift
detection
07
CI
/
CD
&
Release
Engineering
Build
pipelines
,
deployment
strategy
,
and
safe
progressive
delivery
.
GitHub
Actions
GitLab
CI
/
CD
Jenkins
Azure
DevOps
Pipelines
Trunk
-
based
development
Argo
CD
&
Flux
(
GitOps
)
Blue
/
green
&
canary
deployments
Feature
flags
Automated
rollback
&
progressive
delivery
Pipeline
secrets
&
OIDC
federation
Artifact
repositories
(
Artifactory
,
Nexus
)
Build
caching
&
pipeline
optimization
2 / 6
08
Observability
&
Site
Reliability
Metrics
,
logs
,
traces
,
service
level
objectives
,
and
incident
practice
.
Prometheus
&
Grafana
OpenTelemetry
instrumentation
Log
aggregation
(
ELK
/
OpenSearch
,
Loki
,
CloudWatch
Logs
)
APM
platforms
(
Datadog
,
New
Relic
,
Dynatrace
)
Alerting
&
on
-
call
(
PagerDuty
,
Opsgenie
)
Incident
command
&
postmortems
Distributed
tracing
(
Jaeger
,
Tempo
,
X
-
Ray
)
SLIs
,
SLOs
&
error
budgets
Chaos
engineering
(
Litmus
,
Chaos
Monkey
)
Load
&
performance
testing
(
k
6,
JMeter
,
Locust
)
09
Security
,
Identity
&
Compliance
Access
control
,
encryption
,
threat
detection
,
and
regulatory
alignment
.
IAM
roles
,
policies
&
least
privilege
SSO
&
federation
(
SAML
,
OIDC
,
Entra
ID
)
Secrets
management
(
Vault
,
AWS
Secrets
Manager
)
KMS
,
HSM
&
encryption
at
rest
/
in
transit
WAF
&
DDoS
protection
Compliance
frameworks
(
SOC
2,
ISO
27001,
HIPAA
,
PCI
DSS
,
FedRAMP
)
Certificate
&
key
rotation
(
ACM
,
Let
'
s
Encrypt
)
Zero
-
trust
architecture
CSPM
&
vulnerability
scanning
Threat
detection
(
GuardDuty
,
Microsoft
Sentinel
)
Microsegmentation
&
network
policy
Cloud
penetration
testing
&
audit
10
Databases
&
Data
Engineering
Managed
persistence
,
warehousing
,
streaming
,
and
pipeline
construction
.
Managed
relational
databases
(
RDS
:
PostgreSQL
,
MySQL
,
SQL
Server
)
NoSQL
(
DynamoDB
,
Cosmos
DB
,
Firestore
)
Caching
(
ElastiCache
,
Redis
,
Memorystore
)
Warehouses
(
Redshift
,
Snowflake
,
BigQuery
,
Synapse
)
Query
optimization
&
indexing
Amazon
Aurora
,
Azure
SQL
,
Cloud
Spanner
Streaming
(
Kafka
,
Kinesis
,
Event
Hubs
,
Pub
/
Sub
)
ETL
/
ELT
(
dbt
,
Airflow
,
Glue
,
Data
Factory
)
Lakehouse
formats
(
Iceberg
,
Delta
Lake
,
Hudi
)
Graph
databases
(
Neptune
,
Neo
4
j
)
Database
migration
(
AWS
DMS
,
Azure
Migrate
)
Search
(
OpenSearch
,
Elasticsearch
,
Azure
AI
Search
)
3 / 6
11
Serverless
&
Event
-
Driven
Architecture
Function
platforms
,
event
routing
,
and
asynchronous
integration
patterns
.
AWS
Lambda
/
Azure
Functions
/
Cloud
Functions
API
Gateway
&
API
management
SQS
,
SNS
,
Service
Bus
—
queues
&
topics
Step
Functions
&
Durable
Functions
EventBridge
,
Event
Grid
&
event
buses
Change
data
capture
&
DynamoDB
Streams
Cold
-
start
optimization
Function
cost
&
concurrency
modelling
Serverless
Framework
,
AWS
SAM
,
SST
12
Languages
,
Scripting
&
Automation
Programming
and
tooling
used
for
automation
,
SDK
work
,
and
service
development
.
Python
(
boto
3,
Azure
SDK
,
google
-
cloud
libraries
)
Bash
&
PowerShell
JavaScript
/
TypeScript
&
Node
.
js
SQL
YAML
,
JSON
&
HCL
REST
&
GraphQL
API
design
Go
AWS
CDK
gRPC
&
service
contracts
Java
& .
NET
on
cloud
runtimes
Regular
expressions
&
log
parsing
13
AI
/
ML
&
Generative
AI
on
Cloud
Managed
model
services
,
inference
infrastructure
,
and
retrieval
pipelines
.
SageMaker
,
Azure
ML
,
Vertex
AI
Bedrock
,
Azure
OpenAI
,
Vertex
AI
Studio
Model
hosting
&
inference
endpoints
Vector
databases
(
pgvector
,
Pinecone
,
OpenSearch
)
RAG
pipelines
(
LangChain
,
LlamaIndex
)
GPU
cluster
orchestration
MLOps
pipelines
&
model
registries
Feature
stores
(
SageMaker
Feature
Store
,
Feast
)
Prompt
evaluation
&
guardrails
14
Cost
Management
&
Governance
(
FinOps
)
Spend
visibility
,
commitment
planning
,
and
account
-
level
guardrails
.
Cost
Explorer
&
Azure
Cost
Management
Tagging
&
cost
allocation
Savings
Plans
&
reserved
capacity
Rightsizing
&
idle
resource
cleanup
Budget
alerts
&
anomaly
detection
Quotas
,
limits
&
service
boundaries
Showback
&
chargeback
models
Landing
zones
(
Control
Tower
,
Cloud
Adoption
Framework
)
FinOps
framework
&
unit
economics
4 / 6
15
Migration
&
Architecture
Patterns
Moving
workloads
to
cloud
and
designing
them
for
resilience
and
change
.
Migration
frameworks
(
the
6
R
'
s
)
Lift
-
and
-
shift
vs
re
-
platform
vs
refactor
Well
-
Architected
Framework
reviews
Microservices
&
domain
-
driven
design
High
availability
&
multi
-
AZ
design
Event
sourcing
&
CQRS
Disaster
recovery
(
RTO
/
RPO
,
pilot
light
,
warm
standby
)
Immutable
infrastructure
&
blue
/
green
cutover
Landing
zone
&
account
structure
design
Architecture
decision
records
(
ADRs
)
P RIO RIT Y
SK IL L S
BY
RO L E
4
tracks
T R AC K
01
Cloud
Engineer
T R AC K
02
Cloud
Solutions
Architect
T R AC K
03
Site
Reliability
/
DevOps
Engineer
T R AC K
04
Cloud
Security
Engineer
Linux
administration
&
systems
troubleshooting
Terraform
module
authoring
and
state
management
Kubernetes
cluster
operations
and
workload
deployment
CI
/
CD
pipeline
construction
and
maintenance
Monitoring
with
Prometheus
,
Grafana
,
and
log
aggregation
IAM
policy
design
and
VPC
networking
Automation
scripting
in
Python
and
Bash
Requirements
gathering
and
solution
design
Well
-
Architected
Framework
assessments
Landing
zone
and
multi
-
account
structure
design
Hybrid
networking
and
connectivity
architecture
Cost
modelling
and
total
cost
of
ownership
analysis
Migration
strategy
and
phased
cutover
planning
Stakeholder
communication
and
design
documentation
SLI
/
SLO
definition
and
error
budget
management
Observability
stack
design
(
metrics
,
logs
,
traces
)
Incident
response
leadership
and
postmortem
practice
Capacity
planning
and
performance
testing
Automation
at
scale
and
toil
reduction
Chaos
testing
and
resilience
validation
Progressive
delivery
and
rollback
strategy
IAM
policy
design
and
permission
boundary
reviews
CSPM
tooling
and
misconfiguration
remediation
Threat
modelling
for
cloud
-
native
workloads
Encryption
,
key
management
,
and
certificate
lifecycle
Compliance
mapping
(
SOC
2,
ISO
27001,
HIPAA
,
PCI
DSS
)
Cloud
incident
forensics
and
log
analysis
Secure
SDLC
and
supply
chain
controls
5 / 6
CERT IFICAT IO NS
WO RT H
L IST ING
12
credentials
AWS
Certified
Solutions
Architect
–
Associate
AWS
·
AS S OC IAT E
AWS
Certified
Solutions
Architect
–
Professional
AWS
·
P R OFES S IONAL
AWS
Certified
DevOps
Engineer
–
Professional
AWS
·
P R OFES S IONAL
AWS
Certified
Security
–
Specialty
AWS
·
S P EC IALT Y
Microsoft
Certified
:
Azure
Administrator
Associate
AZUR E
·
AZ
- 104
Microsoft
Certified
:
Azure
Solutions
Architect
Expert
AZUR E
·
AZ
- 305
Google
Professional
Cloud
Architect
GOOGL E
C L OUD
·
P R OFES S IONAL
Google
Professional
Cloud
DevOps
Engineer
GOOGL E
C L OUD
·
P R OFES S IONAL
Certified
Kubernetes
Administrator
(
CKA
)
C NC F
·
P L US
C KAD
AND
C KS
HashiCorp
Certified
:
Terraform
Associate
HAS HIC OR P
·
AS S OC IAT E
FinOps
Certified
Practitioner
FINOP S
FOUNDAT ION
CompTIA
Cloud
+
VENDOR
-
NEUT R AL
·
ENT R Y
L EVEL
6 / 6