All certifications / Cloud Practitioner / Cheat sheet
Cloud Practitioner CLF-C02 cheat sheet
Domain 1: Cloud Concepts (24%)
Exam tips
- Agility is about how fast you can provision and experiment; elasticity is about capacity automatically following demand. Look at whether the scenario complains about slow setup or about fluctuating load before choosing.
- Memorize the six phrases exactly. Distractors that sound plausible, such as 'eliminate security responsibilities' or 'guarantee 100 percent uptime', are not advantages of cloud computing.
- 'No interruption at all' means fault tolerance; 'minimal downtime' or 'survives an AZ failure' means high availability. 'Automatically adds and removes capacity' is elasticity, which is more specific than scalability.
- There are six pillars; sustainability is the one people forget. Separate reliability (recover and meet demand) from performance efficiency (right resources for speed), and cost optimization (money) from sustainability (environmental impact).
- Decouple tiers or absorb spikes between them with Amazon SQS; provision identical environments repeatedly with AWS CloudFormation. Do not confuse SQS (queue, consumers pull) with SNS (push to many subscribers).
- The Well-Architected Tool reviews a workload's design from your answers; Trusted Advisor inspects your real account resources automatically; AWS Config tracks resource configurations against rules.
- Governance manages the program, risk and money; Operations runs services day to day (monitoring, incidents, patching). Training and culture belong to People.
- Moving a database onto Amazon RDS without redesigning the application is replatform; rewriting a monolith into microservices or serverless functions is refactor. Retain keeps an application; retire removes it.
- Servers go with Application Migration Service, databases with DMS (plus SCT when engines differ), and file shares with DataSync. DMS moves data; SCT converts the schema.
- Costs that move to AWS are physical: hardware, data center space, power, cooling and physical security. Staff who build and run your workloads, application licenses and data transfer stay with you.
- Licenses bound to sockets or physical cores point to Dedicated Hosts with BYOL; avoiding license management points to license included. Rightsizing recommendations come from Compute Optimizer and Cost Explorer.
Key terms
- Cloud computing
- On-demand delivery of IT resources over the internet with pay-as-you-go pricing.
- Pay-as-you-go pricing
- A billing model where you pay only for the resources you consume, with no large up-front purchase.
- Economies of scale
- Lower cost per unit that AWS achieves by aggregating the usage of many customers, passed on as lower prices.
- Agility
- The ability to provision resources and experiment quickly, cutting the time from idea to working system.
- Elasticity
- Automatically adding and removing capacity so resources match current demand.
- Global reach
- The ability to deploy workloads in AWS Regions around the world in minutes to serve users with low latency.
- AWS Region
- A separate geographic area containing multiple isolated Availability Zones where you choose to run resources.
- Capital expense (CapEx)
- Money spent up front on long-lived physical assets such as servers and data centers.
- Operational expense (OpEx)
- Ongoing spending on services as they are consumed, such as a monthly cloud bill.
- Variable expense
- A cost that rises and falls with actual usage instead of being fixed in advance.
- Undifferentiated heavy lifting
- Necessary infrastructure work, such as racking and powering servers, that does not set a business apart from competitors.
- Capacity planning
- Forecasting how much computing capacity will be needed; in the cloud, scaling on demand replaces much of the guesswork.
- Auto Scaling group
- A set of EC2 instances that AWS grows or shrinks automatically to match a target such as average CPU utilization.
- Availability Zone (AZ)
- One or more discrete data centers in a Region with independent power, cooling and networking.
- High availability
- Design that keeps a system accessible with minimal downtime when components fail, often with a brief failover.
- Fault tolerance
- Design that keeps a system running with no interruption or data loss when a component fails, using fully redundant components.
- Scalability
- The ability to handle more load by adding resources, vertically (bigger) or horizontally (more).
- Elastic Load Balancing (ELB)
- A service that spreads incoming traffic across healthy targets in multiple AZs.
- Multi-AZ deployment
- An Amazon RDS option that keeps a synchronous standby in another AZ and fails over automatically.
- AWS Well-Architected Framework
- AWS guidance of design principles, best practices and questions for building and reviewing cloud workloads.
- Workload
- A set of components that together deliver business value, such as an application and its data stores.
- Operational excellence pillar
- Running and monitoring systems and continually improving processes and procedures.
- Reliability pillar
- Ensuring a workload performs correctly and consistently and recovers from failures.
- Performance efficiency pillar
- Using the right resources efficiently as demand changes and technology evolves.
- Cost optimization pillar
- Delivering business value at the lowest price point.
- Sustainability pillar
- Minimizing the environmental impact of running cloud workloads.
- Loose coupling
- Designing components to interact through interfaces or buffers so a failure or slowdown in one does not break the others.
- Amazon SQS
- A managed message queue that stores messages until a consumer retrieves and processes them.
- Amazon SNS
- A managed publish and subscribe service that pushes messages to many subscribers at once.
- Design for failure
- Assuming components will fail and building in redundancy and automatic recovery.
- Disposable resources
- Treating servers as replaceable units that are terminated and relaunched instead of repaired by hand.
- Infrastructure as code (IaC)
- Defining infrastructure in version-controlled template or code files that can be deployed repeatedly.
- AWS CloudFormation
- An AWS service that creates and manages resources from JSON or YAML templates as stacks.
- AWS Well-Architected Tool
- A console service that reviews a workload against the Well-Architected Framework through a questionnaire.
- High-risk issue (HRI)
- A finding in a review where missing best practices could significantly harm the workload.
- Improvement plan
- A prioritized list of recommended changes produced from a Well-Architected review.
- Milestone
- A saved snapshot of a workload review used to compare progress over time.
- Lens
- An extension that adds best practices and questions for a specific technology, industry or internal standard.
- AWS Trusted Advisor
- A service that automatically inspects account resources and recommends improvements.
- AWS Cloud Adoption Framework (AWS CAF)
- AWS guidance that organizes the capabilities needed for cloud adoption into six perspectives.
- Business perspective
- Ensures cloud investments accelerate business outcomes and digital strategy.
- People perspective
- Covers culture, organizational structure, leadership and workforce skills for the cloud.
- Governance perspective
- Orchestrates cloud initiatives and manages benefits, risk, portfolio and cloud financial management.
- Platform perspective
- Builds a scalable hybrid cloud platform and modernizes or builds cloud-native workloads.
- Operations perspective
- Delivers cloud services at agreed levels through observability, incident, change and patch management.
- Envision, align, launch, scale
- The four phases of the iterative cloud transformation journey described by the AWS CAF.
- Rehost (lift and shift)
- Moving an application to AWS without changes, typically onto Amazon EC2.
- Replatform (lift, tinker and shift)
- Moving with a few cloud optimizations, such as a managed database, while keeping the core architecture.
- Refactor (re-architect)
- Redesigning an application to use cloud-native features such as serverless or containers.
- Repurchase (drop and shop)
- Replacing an application with a different product, usually a SaaS offering.
- Retire
- Decommissioning an application that is no longer needed.
- Retain (revisit)
- Keeping an application in its current environment for now.
- Relocate
- Moving infrastructure, such as VMware-based workloads, to the cloud without changing applications or operations.
- AWS Application Migration Service (AWS MGN)
- The primary AWS rehosting service that continuously replicates source servers and launches them as EC2 instances at cutover.
- Cutover
- The final switch from the source system to the migrated system in AWS.
- AWS Database Migration Service (AWS DMS)
- A service that migrates data between databases while the source stays operational.
- Change data capture (CDC)
- Continuously replicating ongoing changes from the source database to the target after the initial load.
- AWS Schema Conversion Tool (AWS SCT)
- A tool that converts database schema and code objects from one engine to another for heterogeneous migrations.
- Heterogeneous migration
- A database migration between different engines, such as Oracle to Aurora PostgreSQL.
- AWS DataSync
- An online service that moves and synchronizes files and objects between on-premises storage and AWS storage services.
- Fixed cost
- A cost paid regardless of usage, such as purchased servers or a data center lease.
- Variable cost
- A cost that changes with usage, such as hourly compute charges.
- Total cost of ownership (TCO)
- The full lifetime cost of owning and operating a system, including hidden costs such as power and staff time.
- Direct cost
- A cost clearly attributable to a system, such as a server purchase or a service charge.
- Indirect cost
- A real but less visible cost such as staff time, downtime or delayed delivery.
- AWS Pricing Calculator
- A tool for estimating the cost of a planned set of AWS services.
- AWS Migration Evaluator
- A service that analyzes on-premises utilization to build a data-driven business case for migrating to AWS.
- License included
- A model where the software license cost is built into the price of the AWS resource.
- Bring your own license (BYOL)
- Using licenses you already own on AWS and paying AWS only for infrastructure.
- Amazon EC2 Dedicated Host
- A physical server dedicated to one customer, with socket and core visibility for license compliance.
- AWS License Manager
- A service that tracks software license usage and enforces licensing rules across accounts.
- Rightsizing
- Matching instance types and sizes to actual workload needs to eliminate paid but unused capacity.
- AWS Compute Optimizer
- A service that analyzes utilization and recommends better-sized compute resources.
Domain 2: Security and Compliance (30%)
Exam tips
- Customer data, IAM permissions, security group rules and guest operating system patching are always the customer's job. Physical security, hardware disposal, the global network and the hypervisor are always AWS's.
- The operating system is the key signal: on EC2 you patch it; on RDS and Lambda AWS does. In every service, you configure access and protect your data.
- Artifact holds AWS's compliance reports and agreements; it does not assess your resources. To check whether your own resources meet a configuration standard, use AWS Config; to gather audit evidence, use Audit Manager.
- 'Managed keys integrated with AWS services' is KMS; 'dedicated, single-tenant HSM' or 'exclusive control of the hardware' is CloudHSM; 'SSL/TLS certificates' is ACM. ACM is for data in transit, not at rest.
- Protect root with MFA, delete any root access keys and use it only for root-only tasks. Changing the root email or account name, closing the account and restoring locked-out IAM permissions need root; creating IAM users or launching instances do not.
- An AWS service that needs to call another AWS service should use an IAM role, never stored access keys. Several people needing the same permissions means an IAM group. An explicit Deny always overrides an Allow.
- Workforce access to AWS accounts means IAM Identity Center; end users of your app mean Amazon Cognito. 'Millions of app users' or 'social identity providers' points to Cognito.
- 'Rotate' or 'rotation' points to AWS Secrets Manager. 'Store configuration data or simple secrets at no additional cost' points to Parameter Store. KMS manages keys, not secret values.
- Stateful and allow-only means security group; stateless with allow and deny means network ACL. To block one IP address at the network level you need a network ACL (or WAF for web requests), because security groups cannot deny.
- Vulnerabilities and CVEs mean Inspector; sensitive data or PII in S3 means Macie; malicious activity from logs means GuardDuty; investigating root cause means Detective; a single view of findings and compliance checks means Security Hub.
- 'Who made this change?' or 'audit API calls' is CloudTrail. 'CPU utilization', 'set an alarm' or 'collect application logs' is CloudWatch. 'Best practice recommendations including open security groups and root MFA' is Trusted Advisor.
- Marketplace sells mostly third-party products. Compliance reports come from AWS Artifact, common answers from the Knowledge Center or re:Post, hired experts from APN partners or Professional Services, and abuse reports go to Trust & Safety.
Key terms
- Shared responsibility model
- The division of security duties between AWS (security of the cloud) and the customer (security in the cloud).
- Security of the cloud
- AWS's responsibility for the physical facilities, hardware, network and virtualization layer that run AWS services.
- Security in the cloud
- The customer's responsibility for data, identities, configurations, guest operating systems and applications.
- Hypervisor
- The virtualization layer that isolates instances on shared hardware; AWS secures it.
- Shared control
- A control where AWS and the customer each handle their own layer, such as patch or configuration management.
- Inherited control
- A control fully provided by AWS that the customer inherits, such as physical and environmental security.
- Infrastructure as a service (IaaS)
- A model where the provider supplies virtual compute, storage and networking and the customer manages the operating system and above.
- Managed service
- A service where AWS operates the underlying infrastructure and software, such as the OS and database engine for Amazon RDS.
- Serverless
- A model such as AWS Lambda where AWS manages servers, runtime and scaling and you provide code and configuration.
- Maintenance window
- A weekly time period you choose during which AWS applies patches to managed resources such as RDS instances.
- Execution role
- The IAM role a Lambda function assumes to get permissions to other AWS services.
- S3 Block Public Access
- Account- and bucket-level settings that prevent S3 data from being made public, which the customer controls.
- AWS Artifact
- A self-service portal for AWS's third-party audit reports and agreements such as the BAA.
- Business Associate Addendum (BAA)
- An agreement required under HIPAA before handling protected health information on AWS, accepted through Artifact Agreements.
- AWS Audit Manager
- A service that continuously collects evidence from your AWS usage and maps it to compliance frameworks.
- AWS Config
- A service that records resource configurations over time and evaluates them against rules.
- Config rule
- A check that marks resources compliant or noncompliant with a desired configuration.
- Conformance pack
- A deployable collection of AWS Config rules and remediation actions.
- Services in Scope
- AWS information listing which services are covered by each compliance program.
- Encryption at rest
- Encrypting stored data such as S3 objects, EBS volumes and database storage.
- Encryption in transit
- Encrypting data as it moves across a network, usually with TLS.
- AWS Key Management Service (AWS KMS)
- A managed service for creating and controlling encryption keys, integrated with most AWS services.
- Customer managed key
- A KMS key you create and control, including its key policy, rotation and deletion.
- Hardware security module (HSM)
- A tamper-resistant device that stores keys and performs cryptographic operations.
- AWS CloudHSM
- A service providing dedicated, single-tenant HSMs whose keys the customer exclusively manages.
- AWS Certificate Manager (ACM)
- A service that provisions, deploys and automatically renews TLS certificates for AWS services.
- Root user
- The identity created with a new AWS account that has unrestricted access to every resource and setting.
- Multi-factor authentication (MFA)
- Requiring a second factor, such as a security key or authenticator code, in addition to a password.
- Access keys
- Long-term credentials made of an access key ID and secret access key for programmatic access.
- Root-only task
- An account-level action, such as closing the account or changing the root email, that only the root user can perform.
- Centralized root access
- An AWS Organizations capability that lets administrators remove and manage root credentials for member accounts centrally.
- AWS CloudTrail
- The service that records API activity, including root user sign-ins, in an account.
- IAM user
- An identity with long-term credentials representing one person or application.
- IAM group
- A collection of IAM users that share the permissions attached to the group.
- IAM role
- An identity with permissions that trusted entities assume to receive temporary credentials.
- IAM policy
- A JSON document that allows or denies actions on resources, optionally under conditions.
- Amazon Resource Name (ARN)
- A unique identifier for an AWS resource used in policies.
- Least privilege
- Granting only the minimum permissions required to perform a task.
- IAM Access Analyzer
- A tool that identifies external or unused access and helps generate least-privilege policies.
- AWS IAM Identity Center
- The recommended AWS service for workforce single sign-on to multiple AWS accounts and business applications.
- Single sign-on (SSO)
- Signing in once to access many accounts or applications without separate credentials.
- Permission set
- A collection of policies in IAM Identity Center that becomes an IAM role in each assigned account.
- Identity provider (IdP)
- A system that authenticates users and vouches for them to other services, such as Okta or Microsoft Entra ID.
- Amazon Cognito
- A service that adds sign-up, sign-in and access control to web and mobile applications.
- Cognito user pool
- A user directory for an application that handles sign-up, sign-in and token issuance.
- Cognito identity pool
- A Cognito feature that exchanges tokens for temporary AWS credentials.
- Secret
- A sensitive value such as a password, API key or token that must be protected from disclosure.
- AWS Secrets Manager
- A service that stores, retrieves and automatically rotates secrets such as database credentials.
- Secret rotation
- Changing a credential on a schedule and updating both the store and the target system.
- AWS Systems Manager Parameter Store
- A capability of Systems Manager that stores configuration data and secrets as hierarchical parameters.
- SecureString
- A Parameter Store parameter type whose value is encrypted with AWS KMS.
- Hard-coded credentials
- Secrets written directly into source code or configuration files, a practice to avoid.
- Security group
- A stateful, allow-only virtual firewall attached to network interfaces of resources such as EC2 instances.
- Network ACL
- A stateless subnet-level firewall with numbered allow and deny rules evaluated in order.
- Stateful
- Automatically allowing return traffic for a permitted connection.
- AWS WAF
- A web application firewall that filters HTTP and HTTPS requests to CloudFront, load balancers and APIs.
- Distributed denial of service (DDoS)
- An attack that floods a target with traffic from many sources to make it unavailable.
- AWS Shield
- DDoS protection, with Standard included for all customers and Advanced as a paid tier with response team access.
- AWS Firewall Manager
- A service that centrally applies WAF, Shield Advanced and security group policies across AWS Organizations accounts.
- Amazon GuardDuty
- A threat detection service that analyzes CloudTrail, VPC Flow Logs, DNS logs and more for malicious activity.
- Amazon Inspector
- An automated vulnerability management service that scans EC2, ECR images and Lambda functions for CVEs and exposure.
- Common Vulnerabilities and Exposures (CVE)
- A public catalog of identifiers for known software vulnerabilities.
- Amazon Macie
- A service that discovers sensitive data such as PII in Amazon S3 and reports bucket security issues.
- Amazon Detective
- A service that links and visualizes log data to investigate the root cause of security findings.
- AWS Security Hub
- A service that aggregates security findings and checks accounts against security standards.
- Finding
- A record produced by a security service describing a detected threat, vulnerability or misconfiguration.
- Event history
- The CloudTrail console view of the last 90 days of management events in a Region, available at no charge.
- Trail
- A CloudTrail configuration that delivers log files to an S3 bucket for long-term retention and analysis.
- Amazon CloudWatch
- A monitoring service for metrics, logs, dashboards and alarms.
- CloudWatch alarm
- A watch on a metric that notifies or takes action when a threshold is crossed.
- Metric filter
- A CloudWatch Logs pattern that turns matching log events into a metric you can alarm on.
- AWS Trusted Advisor
- A service that checks your account against best practices for cost, performance, security, fault tolerance, service limits and operational excellence.
- AWS Knowledge Center
- A collection of articles and videos, hosted on re:Post, answering the questions AWS Support receives most often.
- AWS re:Post
- AWS's community question-and-answer site where customers and AWS experts answer technical questions.
- AWS Marketplace
- A curated catalog of third-party software, data and services that run on AWS and can be billed through your AWS account.
- AWS Partner Network (APN)
- The global community of consulting and technology companies that build services and solutions on AWS.
- AWS Security Bulletins
- Official notices of security issues affecting AWS services and any action customers need to take.
- AWS Trust & Safety team
- The AWS team that receives reports of AWS resources being used for abuse such as spam or attacks.
- Security Competency
- An AWS validation showing a partner has proven expertise and customer success in security.
Domain 3: Cloud Technology and Services (34%)
Exam tips
- Repeatable, consistent deployment across accounts or Regions, or 'infrastructure as code', means CloudFormation. The CLI scripts tasks and SDKs are for application code; neither is the IaC answer.
- Hybrid needs both on-premises infrastructure and cloud resources connected together. Multi-Region or multi-account designs that run entirely on AWS are still the cloud model.
- High availability questions want multiple Availability Zones; surviving a whole-Region event wants multiple Regions. 'AWS services in the customer's own data center' is Outposts, and '5G' is Wavelength.
- If a scenario mentions a legal or regulatory requirement about where data lives, that factor wins over price and latency. Rule out non-compliant Regions first, then weigh latency, services and price.
- Match the workload to the family: in-memory databases are memory optimized, batch or HPC is compute optimized, ML training or graphics is accelerated computing. HTTP path-based routing means an Application Load Balancer.
- 'Kubernetes' means EKS; 'containers without managing servers' means Fargate; 'event-driven code, pay only when it runs' means Lambda; 'upload code and AWS handles the rest' means Elastic Beanstalk.
- Multi-AZ is for availability (automatic failover); read replicas are for read performance. Redshift is analytics (OLAP), not transactions; DynamoDB is NoSQL, not relational.
- An internet gateway allows two-way internet access for public subnets; a NAT gateway allows outbound-only access for private subnets. VPN runs encrypted over the internet; Direct Connect is a dedicated private line.
- Shared Linux file storage is EFS; Windows file shares are FSx for Windows File Server; a single instance's disk is EBS. Never keep data that must survive a stop on instance store.
- Transcribe is speech to text; Polly is text to speech. Textract extracts text from documents; Comprehend understands text you already have. Custom models mean SageMaker AI; foundation models mean Bedrock.
- Athena and Redshift both run SQL. Athena queries files in S3 on demand with nothing to load; Redshift is a data warehouse you load data into for heavy, repeated analytics.
- SQS is pull-based and each message is processed by one consumer; SNS is push-based and delivers every message to all subscribers. One event that must reach several systems means SNS, often with SQS queues behind it.
Key terms
- AWS Management Console
- The browser-based graphical interface for managing AWS services.
- AWS CLI
- The command line tool for calling AWS service APIs from a terminal or script.
- AWS CloudShell
- A browser-based, pre-authenticated shell with the AWS CLI installed, launched from the console.
- SDK
- A software development kit: language-specific libraries that let application code call AWS APIs.
- Infrastructure as code (IaC)
- Defining and provisioning infrastructure through machine-readable templates or code rather than manual steps.
- AWS CloudFormation
- The AWS service that creates, updates and deletes resources as a stack from a JSON or YAML template.
- AWS CDK
- The Cloud Development Kit, which defines infrastructure in a programming language and synthesizes CloudFormation templates.
- Cloud deployment
- A model where all parts of an application run in the cloud.
- Hybrid deployment
- A model that connects cloud resources with infrastructure that remains on premises.
- On-premises (private cloud)
- A model where resources run in the organization's own data center using virtualization and management tools.
- One-time provisioning
- Creating resources manually for a single use, typically through the console.
- Repeatable provisioning
- Creating resources from code or templates so the same configuration can be recreated consistently.
- AWS Outposts
- AWS-managed hardware installed in a customer's facility to run AWS services on premises.
- Region
- A separate geographic area containing multiple isolated Availability Zones.
- Availability Zone (AZ)
- One or more discrete data centers with redundant power and networking, isolated from others in the same Region.
- Edge location
- A site used by CloudFront and other edge services to cache content and serve users with low latency.
- AWS Local Zone
- An extension of a Region that places AWS services close to a large city for single-digit-millisecond latency.
- AWS Wavelength Zone
- AWS compute and storage embedded in a telecom provider's 5G network for ultra-low-latency mobile applications.
- High availability
- Designing a system to keep running when a component or location fails, typically by using multiple AZs.
- Data residency
- A requirement that data be stored in a specific geographic location or jurisdiction.
- Data sovereignty
- The principle that data is subject to the laws of the country in which it is stored.
- Latency
- The delay between a request and its response, which grows with distance to the Region.
- Service availability
- Whether a given AWS service, feature or instance type is offered in a particular Region.
- AWS Pricing Calculator
- A free tool for estimating and comparing the cost of an architecture, including across Regions.
- Service control policy (SCP)
- An AWS Organizations policy that sets the maximum permissions in accounts, for example blocking unapproved Regions.
- Amazon EC2
- The AWS service that provides resizable virtual servers called instances.
- Instance family
- A group of instance types optimized for a workload type, such as compute, memory or storage.
- AMI
- An Amazon Machine Image: the template of OS, software and configuration used to launch an instance.
- Elastic Load Balancing (ELB)
- A service that distributes traffic across healthy targets in multiple Availability Zones.
- Application Load Balancer (ALB)
- A layer 7 load balancer for HTTP and HTTPS that can route by path or host name.
- Network Load Balancer (NLB)
- A layer 4 load balancer for TCP and UDP with very high performance and static IP support.
- EC2 Auto Scaling
- A service that adds or removes EC2 instances automatically to match demand and replaces unhealthy ones.
- Launch template
- A saved configuration naming the AMI, instance type and settings that Auto Scaling uses to launch instances.
- Container
- A package of an application and its dependencies that runs consistently across environments and shares the host OS kernel.
- Amazon ECS
- AWS's fully managed container orchestration service.
- Amazon EKS
- A managed service for running Kubernetes on AWS, with AWS operating the control plane.
- AWS Fargate
- A serverless compute engine that runs ECS or EKS containers without you managing servers.
- AWS Lambda
- A serverless service that runs code in response to events and bills per request and compute time.
- AWS Elastic Beanstalk
- A platform as a service that deploys and manages web applications, handling capacity, load balancing and scaling.
- Amazon ECR
- A managed registry for storing and sharing container images.
- Amazon RDS
- A managed service for relational database engines such as MySQL, PostgreSQL, MariaDB, Oracle and SQL Server.
- Amazon Aurora
- AWS's MySQL- and PostgreSQL-compatible relational engine with storage replicated across multiple AZs.
- Multi-AZ deployment
- An RDS configuration with a synchronous standby in another AZ for automatic failover.
- Read replica
- An asynchronously updated copy of a database used to offload read traffic.
- Amazon DynamoDB
- A serverless NoSQL key-value and document database with consistent single-digit-millisecond performance.
- Amazon ElastiCache
- A managed in-memory cache compatible with Valkey, Redis OSS and Memcached.
- Amazon Redshift
- A managed data warehouse for SQL analytics over large volumes of structured data.
- Amazon Neptune
- A managed graph database for highly connected data.
- Amazon VPC
- A logically isolated virtual network in AWS whose IP ranges, subnets and routing you control.
- Subnet
- A range of IP addresses within a VPC, located in a single Availability Zone.
- Internet gateway
- The VPC component that allows two-way communication between resources in public subnets and the internet.
- NAT gateway
- A managed service in a public subnet that lets private-subnet instances make outbound-only internet connections.
- Amazon Route 53
- AWS's DNS service, providing domain registration, health checks and routing policies.
- Amazon CloudFront
- AWS's content delivery network that caches content at edge locations close to viewers.
- AWS Site-to-Site VPN
- Encrypted IPsec tunnels between an on-premises network and a VPC over the internet.
- AWS Direct Connect
- A dedicated private network connection between on premises and AWS that bypasses the public internet.
- Amazon S3
- Object storage that keeps data as objects in buckets, designed for eleven nines of durability.
- S3 storage classes
- Price tiers for S3 objects based on access frequency and retrieval needs, from Standard to Glacier Deep Archive.
- Lifecycle rule
- An S3 policy that transitions objects to cheaper classes or deletes them as they age.
- Amazon EBS
- Persistent block storage volumes that attach to EC2 instances within one Availability Zone.
- Instance store
- Temporary block storage on the host whose data is lost when the instance stops or terminates.
- Amazon EFS
- A managed, elastic NFS file system that many Linux clients can mount at once across AZs.
- Amazon FSx
- Fully managed third-party file systems such as Windows File Server and Lustre.
- AWS Storage Gateway
- A hybrid service giving on-premises applications access to AWS storage as files, volumes or virtual tapes.
- Amazon SageMaker AI
- A platform for building, training and deploying custom machine learning models.
- Amazon Bedrock
- A managed service providing API access to foundation models for building generative AI applications.
- Foundation model
- A large model pretrained on broad data that can be adapted to many tasks such as writing and summarizing.
- Amazon Q
- A generative AI assistant for businesses (Q Business) and developers (Q Developer).
- Amazon Rekognition
- A service that analyzes images and video to detect objects, text, scenes and faces.
- Amazon Textract
- A service that extracts printed and handwritten text, forms and tables from documents.
- Amazon Comprehend
- An NLP service that finds sentiment, entities, key phrases and language in text.
- Amazon Transcribe and Amazon Polly
- Transcribe converts speech to text; Polly converts text to lifelike speech.
- Amazon Athena
- A serverless service for querying data in S3 with standard SQL, billed by data scanned.
- AWS Glue
- A serverless data integration service for ETL, with crawlers and a central Data Catalog.
- ETL
- Extract, transform and load: moving data from sources, reshaping it and loading it into a target store.
- AWS Glue Data Catalog
- A central metadata repository of table definitions used by Athena, EMR and Redshift.
- Amazon Kinesis Data Streams
- A service for capturing and processing streaming data records in real time.
- Amazon Data Firehose
- A service that loads streaming data into destinations like S3 and Redshift without custom code.
- Amazon EMR
- A managed platform for big data frameworks such as Apache Spark and Hadoop.
- Amazon OpenSearch Service
- A managed service for search, log analytics and operational dashboards.
- Amazon SQS
- A fully managed message queue that decouples producers and consumers, with consumers pulling messages.
- Amazon SNS
- A pub/sub service that pushes each message published to a topic to all its subscribers.
- Fan-out
- A pattern where one SNS message is delivered to several SQS queues or other subscribers for parallel processing.
- Amazon EventBridge
- A serverless event bus that routes events to targets based on matching rules.
- Amazon CloudWatch
- The AWS service for metrics, logs, dashboards and alarms.
- AWS Systems Manager
- A set of tools for managing, patching and accessing EC2 and on-premises servers at scale.
- Session Manager
- A Systems Manager capability that provides audited shell access without inbound ports or SSH keys.
- AWS IoT Core
- A managed service that securely connects IoT devices and routes their messages to AWS services.
Domain 4: Billing, Pricing, and Support (12%)
Exam tips
- 'Steady for one to three years' means RIs or Savings Plans; 'can be interrupted' means Spot; 'short-term and cannot be interrupted' means On-Demand; 'existing per-core licenses' means Dedicated Hosts.
- Remember 'in is free, out costs money', and cross-AZ and cross-Region traffic is charged. Cheaper S3 classes are not always cheaper overall: frequent reads from IA or Glacier classes can cost more in retrieval fees than Standard.
- The Free Tier does not cap spending automatically on a standard paid account. Usage beyond the limits is billed at normal rates, so budgets, Free Tier alerts and clean-up are how you stay safe.
- 'Estimate cost of a planned workload' is the Pricing Calculator. 'Analyze past spending' is Cost Explorer. 'Alert when costs exceed a threshold' is AWS Budgets. Cost Explorer does not send threshold alerts; Budgets does.
- Tags don't appear in billing reports until they are activated as cost allocation tags in the billing console. For the most granular billing data, choose Cost and Usage Reports or data exports, not Cost Explorer.
- SCPs never grant permissions; they only set guardrails. A user needs both an IAM policy allowing the action and no SCP blocking it. 'One bill' and 'shared volume discounts' mean consolidated billing.
- Trusted Advisor covers many categories across the account; Compute Optimizer focuses on rightsizing compute and related resources using ML. The full set of Trusted Advisor checks needs Business Support or higher.
- 'Designated Technical Account Manager' means Enterprise Support; 'pool of TAMs' means Enterprise On-Ramp. The minimum plan with 24/7 phone support and all Trusted Advisor checks is Business.
- Reporting abuse coming from AWS resources, such as spam, phishing or attacks, always goes to the AWS Trust & Safety team, not to AWS Support, AWS Shield or GuardDuty.
Key terms
- On-Demand Instances
- EC2 capacity billed per second or hour with no commitment.
- Reserved Instances (RIs)
- A one- or three-year commitment to an instance configuration in exchange for a significant discount.
- Savings Plans
- A commitment to a dollar-per-hour amount of compute usage for one or three years in exchange for discounted rates.
- Compute Savings Plans
- The most flexible Savings Plan, applying across EC2 families, sizes and Regions plus Fargate and Lambda.
- Spot Instances
- Spare EC2 capacity at a steep discount that AWS can reclaim with a two-minute warning.
- Dedicated Hosts
- Physical servers dedicated to one customer with visibility into sockets and cores, useful for BYOL licensing.
- Dedicated Instances
- Instances running on hardware dedicated to one account, without host-level control.
- Inbound data transfer (ingress)
- Data moving into AWS from the internet, generally not charged.
- Outbound data transfer (egress)
- Data moving from AWS to the internet, charged per gigabyte with tiered rates.
- Cross-Region data transfer
- Data moved between AWS Regions, which is charged.
- Retrieval fee
- A per-gigabyte charge for reading data from infrequent access or archive S3 storage classes.
- Minimum storage duration
- A minimum period an object is billed for in certain S3 classes, even if deleted sooner.
- VPC gateway endpoint
- A private route from a VPC to S3 or DynamoDB that avoids the internet and NAT gateway charges.
- AWS Free Tier
- AWS's program of free usage allowances, trials and credits for exploring services within set limits.
- Always Free
- Free Tier offers that do not expire and apply to all customers within monthly limits.
- Free trial
- A short-term free offer that starts when you first use a particular service.
- Free Tier usage alert
- A billing preference that emails you when usage approaches or exceeds Free Tier limits.
- AWS Budgets
- A service that alerts you when actual or forecasted cost or usage crosses thresholds you set.
- Zero-spend budget
- A Budgets template that alerts you as soon as any spending occurs.
- AWS Pricing Calculator
- A free tool for estimating the cost of a planned architecture before deployment.
- AWS Cost Explorer
- A tool for visualizing and analyzing historical cost and usage, with forecasts and recommendations.
- Budget action
- An automatic response, such as applying a restrictive policy or stopping instances, when a budget threshold is crossed.
- Forecasted spend
- A projection of future costs based on historical usage patterns.
- AWS Cost Anomaly Detection
- A service that uses machine learning to find unusual spending and alert you.
- Billing and Cost Management console
- The central console for bills, invoices, payments, billing preferences and cost tools.
- Cost and Usage Report (CUR)
- The most detailed AWS billing data, delivered as files to S3, down to individual resources.
- Data Exports
- The AWS feature for exporting cost and usage data, including CUR 2.0, to Amazon S3.
- Tag
- A key-value label attached to an AWS resource for organization, automation or cost tracking.
- Cost allocation tag
- A tag activated in the billing console so it appears in cost reports and can filter and group costs.
- Showback and chargeback
- Reporting cloud costs to the teams that caused them (showback) or billing those teams internally (chargeback).
- Tag policy
- An AWS Organizations policy that standardizes tag keys and values across accounts.
- AWS Organizations
- A free service for centrally managing and governing multiple AWS accounts.
- Management account
- The account that creates the organization, manages member accounts and pays the consolidated bill.
- Organizational unit (OU)
- A group of accounts within an organization, used to apply policies together.
- Service control policy (SCP)
- A policy that sets the maximum permissions for accounts in an organization; it never grants permissions.
- Consolidated billing
- An Organizations feature that combines all member accounts' charges into one bill paid by the management account.
- Volume pricing tiers
- Price levels that drop per unit as usage grows, reached sooner when an organization's usage is combined.
- AWS Control Tower
- A service that sets up and governs a multi-account landing zone with guardrails on top of Organizations.
- AWS Trusted Advisor
- A service that checks your account against best practices in cost, performance, security, fault tolerance, quotas and operational excellence.
- AWS Compute Optimizer
- A service that uses ML on utilization history to recommend optimal sizes for EC2, EBS, Lambda and other resources.
- Rightsizing
- Matching resource types and sizes to actual workload requirements at the lowest cost.
- Over-provisioned
- A resource larger than its workload needs, wasting money.
- Under-provisioned
- A resource too small for its workload, risking poor performance.
- AWS Cost Optimization Hub
- A console feature that consolidates and ranks cost-saving recommendations from several AWS tools.
- Basic Support
- The free plan with billing and account support, documentation, core Trusted Advisor checks and AWS Health, but no technical cases.
- Developer Support
- A plan with business-hours email access to technical support for testing and early development.
- Business Support
- A plan with 24/7 technical support by phone, email and chat, fast production response and full Trusted Advisor checks.
- Enterprise On-Ramp
- A plan with a pool of Technical Account Managers and faster response for business-critical workloads.
- Enterprise Support
- The top plan with a designated TAM, the fastest critical response, concierge support and proactive programs.
- Technical Account Manager (TAM)
- An AWS technical contact who provides proactive guidance and advocacy for a customer.
- AWS Health Dashboard
- A personalized view of AWS events, maintenance and issues affecting your resources, free for all customers.
- AWS re:Post
- AWS's free community question-and-answer site with answers from customers and AWS experts.
- AWS Knowledge Center
- Articles and videos, hosted on re:Post, answering the most common AWS Support questions.
- AWS Marketplace
- A curated catalog of third-party software, data and services that can be purchased and billed through AWS.
- AWS Partner Network (APN)
- The global program of consulting and technology partners that build on AWS.
- AWS Professional Services
- AWS's own team of consultants that helps customers with large projects and business outcomes.
- AWS Trust & Safety team
- The AWS team that investigates reports of abuse involving AWS resources.
- AWS Prescriptive Guidance
- AWS-published strategies, guides and patterns for migrating and running workloads.
Study Cloud Practitioner for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Cloud Practitioner study planLessons, quizzes, exam simulations and hands-on labs.