Cloud / Amazon EFS Interview questions
Last updated
1. What is Amazon EFS?
Amazon Elastic File System (EFS) is a managed, serverless network file system that many compute resources can mount and share at the same time. It speaks NFS, so applications see ordinary directories and files with POSIX permissions.
There is no capacity to provision. The file system grows and shrinks as you add or delete files, and you pay for what is stored. Data is kept redundantly across multiple Availability Zones for Regional file systems.
It works with EC2, ECS, EKS, Fargate and Lambda. Run df -h on a mounted volume and it reports a huge virtual size (8 EiB), which is just how an elastic file system presents itself.
Take quiz
Attach an extra EFS volume once 1 TiB is reached
Raise a support ticket for every 100 GiB of growth
Resize the volume before each batch of writes
Nothing, because storage grows and shrinks automatically
Object access through PUT and GET calls only
Shared POSIX file access over NFS
Raw block devices attached to one instance
2. Which protocol does Amazon EFS use?
EFS uses the Network File System (NFS) protocol, versions 4.1 and 4.0. Clients connect over TCP on port 2049 to a mount target inside your VPC.
NFSv4.1 is the recommended version, and it is what the EFS mount helper uses by default. Older NFSv3 is not supported.
Because it is standard NFS, any Linux client with an NFS 4.x stack can mount it, though the amazon-efs-utils package makes TLS and IAM options much easier.
One practical upside of NFSv4 is that only TCP 2049 has to be open between the client and the mount target. There is no separate portmapper or UDP port to manage, which keeps the firewall rules simple.
Take quiz
EFS supports NFSv3 only
EFS supports NFS 4.0 and 4.1, so the legacy client will not work
EFS supports SMB only
EFS switches to NFSv3 automatically when asked
NFSv2
NFSv4.0 only
NFSv4.1
NFSv3
3. What are the storage classes in Amazon EFS?
EFS offers five storage classes, split by redundancy and access pattern:
- EFS Standard - frequently accessed data, stored across multiple AZs.
- EFS Standard-IA - infrequently accessed data, multi-AZ, lower storage price plus a per-GB access charge.
- EFS Archive - rarely accessed data (a few times a year), cheapest multi-AZ option.
- EFS One Zone - frequently accessed data in a single AZ.
- EFS One Zone-IA - infrequently accessed data in a single AZ.
Lifecycle management moves files between the frequently accessed and colder classes based on last access time.
Take quiz
EFS Standard
EFS Archive
EFS Standard-IA
EFS One Zone
EFS Archive
EFS One Zone-IA
EFS Standard
EFS One Zone
4. What are the throughput modes in Amazon EFS?
EFS has three throughput modes: Elastic, Provisioned and Bursting.
| Mode | How throughput is decided | Billing |
| Elastic | Scales up and down automatically with the workload | Pay per GB read and written |
| Provisioned | You set a fixed MiBps regardless of stored size | Pay for throughput above the included amount |
| Bursting | Baseline grows with storage size, plus burst credits | Included in the storage price |
Elastic is the recommended default for spiky or unpredictable workloads.
You can switch modes on a live file system, but AWS makes you wait 24 hours before the next change, so choose the mode deliberately.
Take quiz
Max I/O throughput
Provisioned throughput
Bursting throughput
Elastic throughput
Bursting throughput
Elastic throughput
Provisioned throughput
5. What are the performance modes in Amazon EFS?
EFS has two performance modes chosen at creation time: General Purpose and Max I/O.
General Purpose is the default. It gives the lowest per-operation latency and suits web serving, CMS, home directories and most applications.
Max I/O was built for highly parallel jobs with thousands of clients, trading slightly higher latency for higher aggregate operations. It is not supported with One Zone file systems or Elastic throughput, so AWS treats it as a legacy choice and recommends General Purpose for nearly everything.
Take quiz
Max I/O
Bursting
Elastic
General Purpose
Elastic throughput
Standard storage class
Lifecycle management
Encryption at rest
6. What is a mount target in Amazon EFS?
A mount target is the network endpoint of an EFS file system inside one subnet of your VPC. It has its own IP address and an attached security group, and clients mount the file system through it.
A Regional file system can have one mount target per Availability Zone. A One Zone file system has just one, in the AZ where it was created.
When an EC2 instance resolves the file system DNS name (fs-id.efs.region.amazonaws.com), it gets the mount target IP in its own AZ, which avoids cross-AZ traffic.
Take quiz
As many as there are instances
One
Three
None, mount targets are optional
The file system name tag
The instance type of the client
The security group attached to it
The S3 bucket policy
7. How do you mount an EFS file system on Linux?
Install the EFS mount helper, create a directory, and mount using the efs file system type.
sudo yum install -y amazon-efs-utils sudo mkdir /mnt/efs sudo mount -t efs -o tls fs-0123456789abcdef0:/ /mnt/efs
To make it survive reboots, add a line to /etc/fstab:
fs-0123456789abcdef0:/ /mnt/efs efs _netdev,tls 0 0
Without the helper you can use the plain NFS client with -t nfs4 and the recommended mount options. Make sure port 2049 is open between the client and the mount target.
Take quiz
tls only
noauto,ro
nodiratime
_netdev
mount -t efs -o tls fs-id:/ /mnt/efs
mount -t ext4 -o tls fs-id /mnt/efs
mount -t efs -o nfsv3 fs-id:/ /mnt/efs
mount -t cifs //fs-id/share /mnt/efs
8. What are the main use cases of Amazon EFS?
EFS fits workloads that need a shared, elastic file system reachable from many servers at once.
- Web serving and CMS - WordPress or Drupal uploads shared across an Auto Scaling group.
- Home directories and developer tools shared by teams.
- Container and serverless persistence for ECS, EKS, Fargate and Lambda.
- Analytics and ML - shared datasets and model artifacts for training jobs.
- Content management and media processing pipelines.
It is a poor fit for Windows workloads, a boot volume, or latency-critical databases, where EBS or FSx are better.
Take quiz
Windows file share using SMB
Uploads directory shared by web servers in an Auto Scaling group
Boot volume for a single EC2 instance
Storing 10 billion tiny objects behind a CDN
EFS only works in one Region
EFS cannot store files larger than 1 GB
Network file access adds latency compared with block storage
EFS is not encrypted
9. What is an EFS access point?
An access point is an application-specific entry into an EFS file system. It forces a root directory and a POSIX user and group on every request that comes through it, no matter what identity the client presents.
You can also set creation permissions so that the root directory is created automatically with the right owner and mode the first time it is used.
Access points are popular for multi-tenant apps, Lambda functions and containers, because each workload sees only its own subtree. You can attach an IAM policy that allows a role to mount only through a specific access point.
Take quiz
A separate KMS key per request
A maximum file size of 1 MB
A dedicated mount target
A root directory and a POSIX user and group
They limit the function to its own directory with a fixed identity
They convert NFS into HTTP
They remove the need for a VPC
They cache files in memory
10. Can Amazon EFS be used with Windows instances?
No. Amazon EFS is not supported on Windows instances. It depends on NFS, and the Windows NFS client is not supported for EFS mounts.
For Windows workloads that need a shared file system, use Amazon FSx for Windows File Server, which speaks SMB and integrates with Active Directory.
EFS is meant for Linux-based clients such as Amazon Linux, Ubuntu and RHEL, and for Linux containers.
In a mixed estate, run EFS for the Linux side and FSx for Windows for the Windows side, rather than trying to force one service to serve both.
Take quiz
Amazon S3 Glacier
Amazon FSx for Windows File Server
Amazon EFS
AWS Snowball
Mainframes
Browsers
Linux-based instances and containers
Windows Server only
11. What is the maximum size of a single file in Amazon EFS?
A single file in EFS can be up to 47.9 TiB (52,673,613,135,872 bytes). This is a fixed quota and cannot be raised.
The file system itself has no practical size limit, since it is elastic and grows to petabytes.
Related quotas worth remembering: up to 1,000 file systems per account per Region (adjustable) and up to 10,000 access points per file system (adjustable).
Even well below the limit, very large files such as raw genomics or video captures are worth splitting into chunks. A single huge file is handled by one client thread and does not benefit from EFS's parallelism.
Take quiz
5 TiB, adjustable by support
There is no limit at all
16 TiB like ext4 defaults
47.9 TiB, and it cannot be increased
Number of file systems per account in a Region
Maximum file name length
Hard links per file
Maximum size of a single file
12. What are Regional and One Zone file systems in Amazon EFS?
A Regional file system stores data redundantly across multiple Availability Zones and can have a mount target in each of them. It survives the loss of an AZ.
A One Zone file system keeps data in a single AZ, so it costs less but is exposed to an AZ-level outage. Clients in other AZs can still mount it, but they pay cross-AZ network costs and get extra latency.
| Regional | One Zone |
| Multi-AZ data, 99.99% availability design | Single-AZ data, lower availability design |
| Mount target in every AZ | One mount target only |
| Best for production data | Best for dev, test or re-creatable data |
Take quiz
Neither of them
Regional
Only Max I/O
One Zone
Max I/O mode
Regional with Provisioned throughput
One Zone
Regional with Archive only
13. What is EFS lifecycle management?
Lifecycle management automatically moves files between storage classes based on how long it has been since they were last accessed. The goal is to lower cost without any application change.
You can set a policy to move files to IA after a chosen period (1, 7, 14, 30, 60, 90, 180, 270 or 365 days), move them to Archive later, and optionally bring them back to Standard on first access.
Files smaller than 128 KiB are never moved to IA, so they stay in Standard. Metadata stays in Standard as well.
Take quiz
The file extension
The size of the EFS volume
The number of clients mounted
The time since the file was last accessed
Files smaller than 128 KiB
Files larger than 1 GiB
Files created on Monday
Files owned by root
14. What is the amazon-efs-utils package?
amazon-efs-utils is an open-source set of tools from AWS that includes the EFS mount helper (mount.efs). It lets you use mount -t efs instead of hand-writing NFS options.
What it adds over plain NFS:
- Encryption in transit with the
tlsoption. - IAM authorization with the
iamoption. - Mounting through an access point with
accesspoint=fsap-.... - A watchdog that restarts the TLS proxy if it dies.
- Sensible default mount options and AZ-aware DNS resolution.
Logs live under /var/log/amazon/efs/, which is the first place to look when a mount fails.
Take quiz
nosuid
iam
rsize=1048576
sec=krb5
/var/log/dmesg.old only
The S3 access log bucket
/var/log/amazon/efs/mount.log
/etc/efs/errors.json
15. How do you encrypt data in Amazon EFS?
EFS supports two separate layers of encryption.
At rest: tick the encryption option when you create the file system. Data and metadata are encrypted with an AWS KMS key, either the AWS managed key aws/elasticfilesystem or your own customer managed key. You cannot turn it on later for an existing file system.
In transit: mount with -o tls through the EFS mount helper, so traffic between client and mount target is encrypted with TLS.
To encrypt an existing unencrypted file system, create a new encrypted one and copy the data across with AWS DataSync or AWS Backup restore.
Take quiz
Attach a KMS key to the mount target
Run the mount helper with -o tls
Flip the encryption toggle in the console
Create an encrypted file system and migrate the data
Mounting with -o tls
Enabling a KMS key at creation only
Turning on lifecycle management
Using One Zone storage
16. How should you configure security groups for Amazon EFS?
Attach a security group to each mount target that allows inbound TCP 2049 from your clients. The cleanest way is to reference the client security group as the source instead of using CIDR ranges.
| Security group | Rule |
| EFS mount target SG | Inbound TCP 2049 from the client SG |
| Client (EC2, ECS, EKS node) SG | Outbound TCP 2049 to the EFS SG |
Network ACLs on the subnets must also allow 2049 in both directions, including ephemeral ports for the return traffic.
Take quiz
UDP 111 from the VPC
TCP 2049 from the client security group
TCP 445 from the client security group
TCP 22 from 0.0.0.0/0
It makes NFS faster
It disables cross-AZ charges
Rules keep working when instances scale in and out
It is required for encryption at rest
17. How do you back up an Amazon EFS file system?
The standard way is AWS Backup. Automatic backups are enabled by default when you create a file system through the console, with a daily schedule and a 35-day retention in the default plan.
Backups are incremental after the first full copy, and they do not consume your file system's throughput or burst credits. You can also build your own plans with custom schedules, cross-Region copies and cross-account copies.
To restore, you can bring back the whole file system or only specific files and directories, into a new or an existing file system.
Take quiz
AWS Config
AWS Glue
Amazon Inspector
AWS Backup
The whole file system or selected files and directories
Only the whole file system
Only metadata
Only files under 1 MB
18. What is Amazon EFS Replication?
EFS Replication creates and maintains a read-only copy of a file system in another AWS Region or in the same Region. Changes are copied continuously in the background, and most changes show up at the destination within minutes, with a recovery point objective of 15 minutes.
It is configured on the source, and the destination stays read-only while replication is active. It works for both Regional and One Zone file systems, and the destination can use a different storage configuration.
Typical uses are disaster recovery and keeping a nearby read copy for another Region.
Take quiz
Offline
Read-only
Fully writable
Locked by a KMS grant
Encrypting files in transit
Speeding up NFS reads on one client
Disaster recovery with a copy in another Region
Converting EFS to S3 objects
19. What is EFS Intelligent-Tiering?
EFS Intelligent-Tiering is a lifecycle setup that moves data in both directions so you do not have to predict access patterns.
- Files not accessed for a period you choose (for example 30 days) move from Standard to IA.
- When a file in IA is read again, it moves back to Standard on first access.
The second rule is the important one. Without it, a file that becomes popular again keeps incurring the IA per-GB access charge. With it, active data returns to Standard and frequently used data ends up billed at the Standard rate.
Take quiz
A nightly cron job on the client
Changing the throughput mode
Remounting the file system
The 'transition to Standard on first access' policy
To avoid repeated IA access charges on files that become active again
To add a mount target
To disable encryption
To increase the 47.9 TiB file size limit
20. What is the Amazon EFS Archive storage class?
EFS Archive is the lowest-cost multi-AZ storage class, made for data that is opened only a few times a year, such as old project files, logs kept for audits, or historical datasets.
You reach it through lifecycle policies: a file can go from Standard to IA and then on to Archive after a set number of days without access. Reads still use the same NFS path, so applications do not need to change.
The trade-off is a higher per-GB access charge than IA, so it only pays off for data that truly stays cold. Check the current throughput-mode prerequisites in the docs before you enable it.
Take quiz
Active web uploads
Files accessed a few times per year
Session files read every minute
Database redo logs
By changing the security group
By using a special mount command
Through a lifecycle policy
By manual copy to S3 Glacier
21. How do you use Amazon EFS with AWS Lambda?
Lambda can mount an EFS file system so functions read and write a shared, persistent directory instead of the 512 MB-by-default /tmp.
- Put the function in a VPC that has a mount target for the file system.
- Create an EFS access point for the function.
- Add the file system configuration to the function, with the access point ARN and a local mount path that starts with
/mnt/. - Give the execution role the
elasticfilesystem:ClientMountpermission, plusClientWriteif it writes.
Use it for large ML models, shared libraries and data that must outlive an invocation.
Take quiz
/var/task/
/tmp/
/opt/efs/
/mnt/
elasticfilesystem:ClientMount
ec2:AttachVolume
lambda:InvokeFunction
s3:GetObject
22. How do you use Amazon EFS with Amazon ECS and Fargate?
You define an EFS volume in the task definition and mount it into one or more containers, so tasks share persistent storage.
"volumes": [{ "name": "shared-data", "efsVolumeConfiguration": { "fileSystemId": "fs-0123456789abcdef0", "transitEncryption": "ENABLED", "authorizationConfig": { "accessPointId": "fsap-0abc...", "iam": "ENABLED" } } }]
Then reference the volume in mountPoints on the container. On Fargate you need platform version 1.4.0 or later. The task role needs the EFS client permissions, and the task's security group must reach the mount target on port 2049.
Take quiz
0.9.5
1.4.0
2.2.1 only
1.0.0
In the load balancer listener
In the container image Dockerfile only
In the task definition under volumes
In the ECS cluster tags
23. How do you use Amazon EFS with Amazon EKS?
Install the Amazon EFS CSI driver (aws-efs-csi-driver) as an add-on. It lets pods use EFS through PersistentVolume and PersistentVolumeClaim objects with the ReadWriteMany access mode, which many pods across nodes can share.
Two provisioning styles exist:
- Static - you create the PV pointing at an existing file system or access point.
- Dynamic - a StorageClass creates an EFS access point per PVC automatically.
Pods on Fargate can only use static provisioning. Worker nodes need network access to the mount target, and IAM permissions for the driver are granted through IAM Roles for Service Accounts.
Take quiz
ExclusiveWrite
ReadOnlyOnce
ReadWriteOnce
ReadWriteMany
An EFS access point
A new S3 bucket
A new VPC
A new EBS volume
24. Which CloudWatch metrics should you monitor for Amazon EFS?
EFS publishes metrics under the AWS/EFS namespace. The ones that matter most:
| Metric | What it tells you |
| BurstCreditBalance | Remaining burst credits in Bursting mode |
| PermittedThroughput | Throughput the file system may currently use |
| MeteredIOBytes | Metered I/O against your throughput allowance |
| PercentIOLimit | How close a General Purpose file system is to its I/O limit |
| ClientConnections | Number of connected clients |
| StorageBytes | Size per storage class |
Alarm on a falling BurstCreditBalance and a high PercentIOLimit before users notice slowness.
Put these on a dashboard and set alarms. A common pattern is one alarm on BurstCreditBalance for Bursting file systems and another on PercentIOLimit for General Purpose file systems.
Take quiz
MetadataIOBytes
BurstCreditBalance
StorageBytes
ClientConnections
Lifecycle rules that never ran
Unused KMS keys
A General Purpose file system nearing its I/O limit
Expired TLS certificates
25. How is Amazon EFS priced?
You pay for what you use, across a few dimensions:
- Storage - per GB-month, at different rates for Standard, IA, Archive and the One Zone classes.
- Data access - a per-GB charge when reading from or writing to IA and Archive data.
- Throughput - Elastic bills per GB read and written, Provisioned bills for throughput above what your storage size already includes, and Bursting has no extra charge.
- Extras - replication data transfer, AWS Backup storage and cross-AZ or cross-Region traffic.
There is no upfront cost or minimum fee for the file system itself.
Take quiz
Max I/O
Provisioned
Elastic
Bursting
A per-GB data access charge
A per-mount-target hourly fee
A fixed monthly licence fee
A KMS key rental fee
26. What is the difference between Amazon EFS and Amazon EBS?
EBS is block storage normally attached to one EC2 instance in one AZ. EFS is a shared file system that thousands of clients can mount at once across AZs.
| EBS | EFS |
| Block device, you format it (ext4, xfs) | NFS file system, ready to use |
| Lives in a single AZ | Regional class spans multiple AZs |
| You provision the size | Grows and shrinks automatically |
| Usually one instance at a time | Many clients in parallel |
| Best for boot volumes and databases | Best for shared content and containers |
Choose EBS for low-latency single-host workloads, and EFS when several servers must see the same files.
Take quiz
Amazon S3
Amazon EBS
AWS Backup
Amazon EFS
An io2 volume with no Multi-Attach
An instance store
Amazon EFS
A gp3 EBS volume
27. What is the difference between Amazon EFS and Amazon S3?
S3 is object storage accessed over HTTP APIs, while EFS is a POSIX file system accessed through NFS mounts.
| S3 | EFS |
| Whole-object PUT and GET | Read and write parts of a file in place |
| No directories or file locking | Real directories, permissions and locks |
| Cheapest per GB, huge scale | Higher price per GB, lower latency |
| Accessed by SDK, CLI or URL | Accessed as a mounted path |
If the application expects to open() and append to a file, use EFS. If it stores large, immutable objects or serves content to the internet, use S3.
Many teams use both: EFS as the working area for active jobs and S3 as the cheap, durable home for finished output, with DataSync moving data between them.
Take quiz
Amazon CloudFront
Amazon SQS
Amazon S3
Amazon EFS
It works on whole objects through an HTTP API
It supports POSIX file locking
It is mounted over NFSv4.1
It edits bytes in the middle of a file in place
28. What is the difference between Amazon EFS and Amazon FSx?
FSx is a family of managed file systems, each built around a specific engine. EFS is a single NFS service tuned for Linux and elastic scaling.
| Service | Protocol / strength |
| EFS | NFS, serverless, automatic scaling, Linux |
| FSx for Windows | SMB, Active Directory, NTFS features |
| FSx for Lustre | High-performance computing, parallel file system |
| FSx for NetApp ONTAP | NFS, SMB and iSCSI, snapshots, data management |
| FSx for OpenZFS | NFS with ZFS features and low latency |
Pick EFS when you want no capacity planning on Linux. Pick FSx when you need SMB, HPC throughput or specific NetApp or ZFS features.
Operations differ too. EFS has nothing to size, while FSx file systems are created with a chosen capacity and, for most types, a throughput setting that you manage.
Take quiz
EFS
FSx for Windows File Server
FSx for OpenZFS
FSx for Lustre
FSx for NetApp ONTAP
FSx for Windows File Server
FSx for Lustre
EFS Archive
29. What is the difference between Elastic and Provisioned throughput in EFS?
With Elastic throughput, EFS scales performance up and down automatically based on what the workload needs, and you pay per GB transferred. There is nothing to size or monitor.
With Provisioned throughput, you pick a fixed MiBps. The file system can always drive that amount regardless of how much data it stores, and you pay for the portion above what your storage size would give you in Bursting mode.
Elastic suits spiky, unpredictable traffic. Provisioned tends to be cheaper when the workload uses a steady, high share of its peak throughput (AWS's guidance is an average-to-peak ratio above roughly 5 percent).
You can switch between modes, but after a change you must wait 24 hours before lowering the provisioned value or changing mode again.
Take quiz
Max I/O
Bursting throughput at 1 GiB of data
Provisioned throughput
Elastic throughput
24 hours
5 minutes
There is no cooldown
7 days
30. What is the difference between General Purpose and Max I/O performance modes?
Both are chosen at file system creation, and only one of them is still recommended.
| General Purpose | Max I/O |
| Lowest latency per operation | Slightly higher latency per operation |
| Default, works with Elastic throughput | Not supported with Elastic throughput |
| Supports One Zone file systems | Not supported on One Zone file systems |
| Tracked by the PercentIOLimit metric | No PercentIOLimit metric |
Max I/O was meant for massively parallel jobs with thousands of clients, but newer Elastic throughput limits make General Purpose the right answer in almost all cases.
If an interviewer asks which to use today, answer General Purpose, and mention that Max I/O exists for historical reasons. The mode is set once at creation and cannot be changed later.
Take quiz
Neither
General Purpose
Both equally
Max I/O
NFS compatibility
Multi-AZ durability
Slightly higher latency per operation
Encryption at rest
31. How does Bursting throughput work in Amazon EFS?
In Bursting mode, throughput scales with the amount of data in Standard storage. The baseline is 50 MiBps per TiB, and the file system can burst to 100 MiBps per TiB while it has credits. Small file systems can still burst to 100 MiBps.
The credit mechanism works like a bucket:
- When usage is below the baseline, credits accumulate.
- When usage goes above the baseline, credits are spent.
- When the bucket is empty, throughput falls back to the baseline.
Read operations are metered at one third the rate of other operations, so the same allowance supports about three times more read traffic. Watch BurstCreditBalance to see the bucket level.
Take quiz
5 MiBps regardless of size
It is set manually
500 MiBps per TiB
50 MiBps per TiB of Standard storage
At one third of the rate
At double the rate
They are not metered
At exactly the same rate
32. Why can't you change the performance mode of an EFS file system after creation?
The performance mode is fixed at creation because it decides how the file system's internal metadata and request paths are laid out, so AWS does not offer an in-place switch.
If you picked the wrong one, the route is to create a new file system with the right mode and copy the data over. AWS DataSync handles that well and keeps permissions and timestamps. Alternatively restore an AWS Backup recovery point into a new file system.
In practice this rarely hurts, because the default, General Purpose, suits almost every workload. By contrast, throughput mode can be changed on a live file system.
Take quiz
Run aws efs update-performance on the live file system
Create a new file system and copy the data across
Change the fstab options
Edit the mode on the mount target
Performance mode
Regional vs One Zone placement
Throughput mode
Encryption at rest flag
33. When should you choose a One Zone file system over a Regional one?
Choose One Zone when the data is cheap to recreate or an AZ outage is acceptable, and the lower price matters.
Good fits:
- Development and test environments.
- Scratch space, build caches and intermediate processing output.
- Secondary copies where the master lives elsewhere.
Stay with Regional for production data, anything that must survive an AZ failure, and workloads whose clients are spread across AZs. A One Zone file system has one mount target, so clients in other AZs pay cross-AZ traffic and see higher latency. For best results, run your clients in the same AZ as the file system.
One Zone also has its own infrequent-access class, One Zone-IA, so lifecycle savings still apply inside a single AZ.
Take quiz
A primary shared web content store for three AZs
Audit evidence for regulators
Customer invoices with a 7-year retention rule
A build cache that can be regenerated
They can mount it but see extra latency and cross-AZ charges
They get a free local replica
They cannot mount it at all
They use NFSv3 automatically
34. How does Amazon EFS control access with IAM and POSIX permissions?
EFS layers two checks, and both must allow the request.
Network and IAM level: the security group decides who can reach the mount target. If you mount with -o iam, the client signs requests with its IAM identity, and EFS evaluates identity policies and the file system policy using actions such as elasticfilesystem:ClientMount, ClientWrite and ClientRootAccess.
File level: once mounted, regular POSIX owner, group and mode bits decide who can read, write or execute each file. Access points can override the client's identity with a fixed UID and GID.
A common hardening step is a file system policy with a aws:SecureTransport condition so only TLS mounts are allowed.
Take quiz
ec2:CreateSnapshot
elasticfilesystem:ClientWrite
s3:PutObject
elasticfilesystem:DeleteFileSystem only
By turning off lifecycle management
By disabling the access point
With an aws:SecureTransport condition
By selecting Max I/O
35. How does encryption in transit work for Amazon EFS?
When you mount with -o tls, the EFS mount helper starts a local proxy process on the client (stunnel in older versions, the EFS proxy in version 2.0 and later). The NFS client connects to that proxy on 127.0.0.1, and the proxy opens a TLS connection to the mount target on port 2049.
So the NFS traffic on your machine stays local and everything that crosses the network is encrypted.
The watchdog in amazon-efs-utils monitors the proxy and restarts it if it stops. Keep in mind that TLS needs the mount helper. A plain mount -t nfs4 does not encrypt the traffic.
Take quiz
The KMS service
A public load balancer
Directly to the S3 endpoint
A local proxy on 127.0.0.1
No, TLS needs the EFS mount helper
Yes, if encryption at rest is on
Yes, always
Yes, if the subnet is private
36. How can you mount Amazon EFS from on-premises servers?
On-premises servers reach EFS through a private connection into your VPC, using AWS Direct Connect or AWS Site-to-Site VPN. EFS does not have a public endpoint.
The steps are straightforward:
- Connect the data center to the VPC.
- Allow TCP 2049 from the on-premises CIDR in the mount target security group.
- Mount using the mount target IP address, because the EFS DNS name will not resolve on-premises by default.
If you want to use DNS names, set up a Route 53 Resolver inbound endpoint and forward queries. The path must be private, and latency is higher than inside the VPC.
Take quiz
CloudFront with an origin access control
Direct Connect or Site-to-Site VPN
An S3 gateway endpoint
A public EFS URL
EFS rejects DNS names
NFS requires IPv6 addresses
The EFS DNS name does not resolve outside the VPC by default
IP addresses skip security groups
37. How do you mount Amazon EFS across VPCs or AWS accounts?
A file system can have mount targets in only one VPC at a time, so other VPCs must route to that VPC.
Use VPC peering or an AWS Transit Gateway between the VPCs. Peering also works across accounts and Regions, though cross-Region adds latency and data transfer charges.
Then mount with the mount target IP address of the peered VPC, since the DNS name only resolves inside its own VPC unless extra DNS configuration is added. Allow TCP 2049 in the security group and route tables.
For cross-account, add a file system policy that grants the other account's role the client actions.
Take quiz
Up to ten
Two
Unlimited
One
A file system policy
A bucket ACL
A KMS alias
A Route 53 alias record
38. How do you migrate data to Amazon EFS?
The usual tool is AWS DataSync. It copies from on-premises NFS or SMB, other AWS storage, or another EFS file system into EFS, running in parallel and preserving ownership, permissions and timestamps. It can also run on a schedule for ongoing sync.
Other routes:
- rsync or parallel cp from an EC2 instance that has both source and EFS mounted. Run several processes at once, because a single thread is slow.
- AWS Transfer Family to let partners upload over SFTP, FTPS or FTP straight into EFS.
- AWS Backup restore to copy into a new file system, for example to switch to an encrypted one.
Plan a final cut-over sync, then stop writers on the source before switching clients.
Take quiz
AWS Glue
AWS DataSync
AWS Step Functions
Amazon Kinesis
EFS rejects more than one client
It lowers the storage price
A single thread cannot use EFS's parallel throughput
It enables TLS
39. How do you troubleshoot an EFS mount that hangs or times out?
A hang almost always means the client cannot reach the mount target on TCP 2049. Work through these checks in order:
- Security groups - the mount target SG allows inbound 2049 from the client SG, and the client can send outbound 2049.
- Network ACLs and routes - subnets allow 2049 in both directions.
- Mount target exists in the client's AZ and is in the available state.
- DNS - the VPC has
enableDnsSupportandenableDnsHostnameson, andfs-id.efs.region.amazonaws.comresolves. - Client software -
amazon-efs-utilsor an NFS 4.x client is installed.
Test connectivity with nc -zv mount-target-ip 2049, then read /var/log/amazon/efs/mount.log for helper errors.
Take quiz
ping the S3 endpoint
nslookup google.com
traceroute to port 443
nc -zv mount-target-ip 2049
enableDnsSupport and enableDnsHostnames
enableClassicLink
enableVpnAcceleration
enableNatGateway
40. How do you troubleshoot slow Amazon EFS performance?
Start by finding which limit you are hitting, then fix that one.
- Throughput mode - in Bursting mode, check
BurstCreditBalance. If it is zero you are stuck at baseline, so move to Elastic or Provisioned. - PercentIOLimit - near 100 percent on a General Purpose file system means the operations limit, so spread load or reconsider the design.
- PermittedThroughput vs MeteredIOBytes - shows whether you are at the ceiling in Provisioned mode.
- Access pattern - many small files, single-threaded copies and
fsyncafter every write all add per-operation latency. - Client side - old
amazon-efs-utils, smallrsizeandwsize, or cross-AZ mounts.
Overall throughput rises with larger I/O sizes and more parallel threads.
Take quiz
Add another mount target
Switch to Elastic or Provisioned throughput
Delete the access point
Change the performance mode to Max I/O
Running multiple parallel threads
Using larger I/O sizes
Calling fsync after every tiny write
Mounting in the same AZ
41. Which NFS mount options are recommended for Amazon EFS?
The mount helper applies good defaults. If you use plain NFS, AWS recommends:
nfsvers=4.1,rsize=1048576,wsize=1048576,hard,timeo=600,retrans=2,noresvport
| Option | Why |
nfsvers=4.1 |
Recommended NFS version |
rsize / wsize = 1048576 |
1 MiB reads and writes for best throughput |
hard |
Retry instead of failing I/O, protecting data integrity |
timeo=600 |
60-second timeout before retry |
noresvport |
Use a new source port after reconnect |
Avoid soft, since a timeout can surface as a write error or silent data loss.
The mount helper sets these for you, so most teams never type them. You need them for plain NFS mounts, for example in custom AMIs or where installing amazon-efs-utils is not possible. noresvport matters most after network interruptions, because it lets the client reconnect from a fresh source port.
Take quiz
soft
ro
noatime
hard
1048576 bytes
4096 bytes
64 bytes
512 bytes
42. What consistency model does Amazon EFS provide?
EFS provides close-to-open consistency, the same model most NFS clients expect. When one client closes a file after writing, another client that opens it afterwards sees the latest data.
That has a practical meaning. Data written and closed is visible to new opens everywhere. But a client that already has the file open can briefly see cached attributes or data.
Writes are acknowledged only after the data is stored durably across AZs for Regional file systems. If applications need stronger coordination, use file locking or write and then close before readers start.
A practical example: a build server writes an artifact and closes it, then a deploy server opens it. That handoff is safe. A reader that has held the same file open for hours may not see updates until it reopens the file or its NFS attribute cache expires.
Take quiz
Only after a remount
After the first client closes the file and the second opens it
The instant the first client calls write
After 24 hours
The mount target is asleep
EFS uses eventual replication to S3
NFS client caching of attributes and data
EFS batches writes nightly
43. How does Amazon EFS handle file locking?
EFS supports NFS advisory file locking, using calls such as flock() and fcntl(). Locks are coordinated between clients, so two instances can safely take turns on the same file.
Two caveats matter for interviews. First, locks are advisory: they only work if every process checks them. Nothing stops a program that ignores locks from writing. Second, there are quotas on how many locks can be held, so a design that opens a lock per tiny file at very large scale needs to be checked against the EFS quotas.
Locks are also released when the client disconnects or the lease expires, so a crashed instance does not keep a file locked forever.
Take quiz
Mandatory kernel locking
Row-level locking
No locking whatsoever
Advisory locking
It is eventually released when the client lease expires
It stays locked until the file is deleted
EFS deletes the file
It moves to Archive
44. How does Amazon EFS achieve high durability and availability?
The design depends on the file system type.
A Regional file system writes each file across multiple Availability Zones. A write is acknowledged only after the data is stored durably, so losing one AZ does not lose data, and clients in other AZs keep working through their own mount targets. AWS designs it for 99.999999999 percent (11 nines) durability and 99.99 percent availability.
A One Zone file system stores data redundantly inside a single AZ. It has the same 11-nines durability design, but availability is designed for 99.9 percent, and an AZ-wide failure can make the data unavailable or, in a catastrophic event, lost.
To add protection, combine EFS with AWS Backup for point-in-time restore and EFS Replication for a copy in another Region.
Take quiz
It uses EBS Multi-Attach
Data is stored across multiple AZs before a write is acknowledged
It copies to S3 every night
It relies on the client cache
Switching to Max I/O
Enabling lifecycle management
Replication to a file system in another Region
Adding a second mount target in the same AZ
45. Explain the execution flow of an EC2 instance mounting an Amazon EFS file system?
Mounting looks like one command, but several steps happen behind it.
sequenceDiagram
participant C as EC2 client
participant D as VPC DNS
participant M as Mount target
participant E as EFS service
C->>D: Resolve fs-id.efs.region.amazonaws.com
D-->>C: IP of mount target in the client's AZ
C->>M: TCP 2049 (via TLS proxy if -o tls)
M->>E: NFSv4.1 session and IAM check if -o iam
E-->>C: Root handle of file system or access point
C->>E: READ / WRITE file operations
- The mount helper resolves the DNS name, which returns the mount target IP in the same AZ.
- With
tls, it starts the local proxy and connects through it. - Security group, IAM policy and file system policy are evaluated.
- The client gets the file system root, or the access point directory, and normal POSIX checks apply to each file.
Take quiz
The IP of an S3 bucket
The instance metadata address
A random mount target from any Region
The mount target IP address in the client's own AZ
When the client accesses each file after the mount succeeds
When the security group is created
Before DNS resolution
Only at instance launch
46. How can you optimize Amazon EFS for workloads with many small files?
EFS adds a small fixed latency to every operation, so many tiny files hurt more than a few large ones. The fix is to reduce operations and run more of them at once.
- Parallelize - use many threads or processes, for example
fpsyncor GNUparallelfor copies. EFS scales with concurrency. - Use larger I/O sizes and avoid
fsyncafter each small write unless durability demands it. - Pick Elastic throughput so bursts are not capped, and use a current
amazon-efs-utilsversion (2.0 or later) for higher per-client throughput. - Bundle files - pack small files into archives or container images and unpack locally when possible.
- Reduce metadata calls - mount with attribute caching defaults and avoid recursive
ls -lorfindon huge directories.
Measure with MetadataIOBytes in CloudWatch to confirm metadata is the bottleneck.
Take quiz
Small files are not encrypted
Each operation pays a small fixed latency cost
EFS cannot store files under 1 MB
Small files always go to Archive
Unmounting between files
Switching to Max I/O on a live system
Running many copy threads in parallel
Running one thread with smaller blocks
47. How do you design multi-tenant isolation with Amazon EFS access points?
Give every tenant its own access point on a shared file system. Each one enforces a separate root directory, such as /tenants/acme, and a separate POSIX UID and GID. The tenant's app sees only that subtree and cannot walk up to other folders.
| Layer | Isolation control |
| Path | Access point root directory per tenant |
| Identity | Fixed UID and GID per access point |
| Authorization | IAM policy with the elasticfilesystem:AccessPointArn condition per role |
| Data protection | KMS key, backups and TLS-only file system policy |
Set creation info so the directory is created with the right owner and mode. A file system supports up to 10,000 access points by default, so very large tenant counts may need sharding across file systems or a quota increase. For strict compliance, use a separate file system or KMS key per tenant.
Take quiz
s3:prefix
ec2:ResourceTag
aws:SourceVpc only
elasticfilesystem:AccessPointArn
The access points per file system quota
The size of the KMS key
The number of security groups
The number of subnets
48. Explain how EFS Replication failover and failback work?
The destination file system is read-only while replication is active, so failover means turning it into a normal writable file system.
flowchart LR
A["Source in Region A"] -->|continuous replication| B["Read-only replica in Region B"]
A -. outage .-> X["Region A unavailable"]
B -->|delete replication configuration| C["Replica becomes writable"]
C --> D["Point clients at Region B"]
D -->|Region A recovers| E["Replicate back to a file system in Region A"]
E --> F["Switch clients back"]
- Failover: delete the replication configuration on the destination. It becomes writable, and you repoint clients and mount targets to it.
- Failback: when the source Region returns, create a replication from the now-active file system back to the original Region, wait for it to catch up, then move clients back.
Because the recovery point objective is about 15 minutes, a small window of recent changes can be missing after a failover. Test the runbook regularly, and keep mount target IPs or DNS ready in the second Region.
Take quiz
Restarting the source instances
Deleting the replication configuration
Changing the throughput mode
Disabling encryption
Lifecycle rules delete new files
Mount targets drop writes
Replication has a recovery point objective of about 15 minutes
The replica is always empty
49. How can you optimize the cost of Amazon EFS?
EFS cost is driven by stored GB per class, data access charges and throughput, so tune each.
| Lever | What to do |
| Storage class | Use lifecycle policies to move cold files to IA and Archive |
| Intelligent-Tiering | Return active files to Standard on first access to avoid repeat access fees |
| File system type | Use One Zone for dev, test and re-creatable data |
| Throughput mode | Elastic for spiky loads, Provisioned for steady high throughput, Bursting for large stores with low demand |
| Housekeeping | Delete stale data, trim backup retention and keep clients in the same AZ as the mount target |
Track the StorageBytes metric per class and review the Cost Explorer EFS usage types monthly. Be careful with IA for small or busy files, as files under 128 KiB are never moved and busy data pays access fees.
Take quiz
Cross-Region replication
Regional Standard with Provisioned throughput
Max I/O mode
One Zone storage classes
StorageBytes
BurstCreditBalance
PermittedThroughput
ClientConnections
50. What happens when you delete an Amazon EFS file system?
Deleting a file system permanently destroys its data. EFS has no recycle bin, so the only way back is a backup taken earlier.
Here is what to expect:
- Mount targets must be removed first. The console does this for you, while the CLI and API need it done explicitly.
- Access points and the file system policy are deleted along with the file system.
- Replication: if it is configured, delete that configuration first. The replica then becomes a regular writable file system.
- AWS Backup recovery points are not removed by the deletion. They stay in the vault until their retention period ends, which is what lets you restore later.
Unmount the file system on all clients before deleting it. Because EFS mounts are hard by default, processes that still have it mounted can hang when the endpoint disappears.
Before deleting, take a final on-demand backup, confirm nothing still mounts the file system, and check that no ECS task definition, Lambda function or Kubernetes PV refers to it.