AWS Certified Cloud Practitioner (CLF-C02) flashcards
171 free flashcards. Tap a card to flip it.
ECS EC2 Launch Type
Flip cardAn ECS launch type where customers manage and provision the underlying EC2 instances that host containers, offering full control over infrastructure.
- Contrasts with Fargate's serverless model
- Requires capacity planning and instance management
- Allows custom AMIs, agents, and instance type selection
Memory trick: EC2 launch type: you drive the bus (manage the instances).
NAT Gateway
Flip cardA managed AWS service placed in a public subnet that allows instances in private subnets to initiate outbound internet traffic without accepting unsolicited inbound connections.
- Deployed in a public subnet
- Provides outbound-only internet access
- Requires a route table entry from the private subnet
Memory trick: NAT = No Access Traveling in, only out
Consolidated Billing RI Sharing
Flip cardA feature of AWS Organizations where Reserved Instance and Savings Plans discounts purchased by one account are automatically shared with other accounts having matching usage.
- Sharing is enabled by default but can be turned off per account.
- Applies to RIs and Savings Plans, not just usage aggregation for volume pricing.
- Consolidated billing also combines usage to reach volume pricing tiers faster.
Memory trick: One family bill, shared discounts for everyone in the household.
AWS WAF
Flip cardA web application firewall that lets you monitor and control HTTP/HTTPS requests forwarded to protected resources based on customizable rules.
- Protects against SQL injection, XSS, and other common exploits
- Can be attached to CloudFront, ALB, API Gateway, and AppSync
- Uses rules and rule groups (managed or custom)
Memory trick: WAF = Wall Against Forgeries at the web layer.
Cost Allocation Tags
Flip cardKey-value labels applied to AWS resources that enable cost tracking and reporting by category such as project or department.
- Activated in the Billing console before appearing in reports
- Used in Cost Explorer and Cost and Usage Reports
- AWS-generated and user-defined tag types exist
Memory trick: Tag it to track it
Root User Protection
Flip cardThe AWS account root user has unrestricted access and should be secured with MFA and reserved for account/billing tasks, with IAM users/roles used for daily work.
- Enable MFA on root immediately after account creation
- Do not create access keys for root unless absolutely necessary
- Use IAM users, groups, and roles for everyday administrative tasks
Memory trick: Lock the root, hand out IAM keys instead
DynamoDB Global Tables
Flip cardA DynamoDB feature that automatically replicates table data across multiple AWS Regions, providing multi-active, low-latency read/write access globally.
- Fully managed multi-region, multi-active replication
- Uses eventual consistency across regions
- Ideal for globally distributed applications needing local low-latency access
Memory trick: Global Tables: one table, copies everywhere, always in sync eventually.
AWS STS
Flip cardAWS Security Token Service issues temporary security credentials for IAM users and roles that automatically expire after a configured duration.
- Underlies IAM roles including EC2 instance profiles
- Credentials expire (default 1 hour, configurable)
- Reduces risk versus long-term access keys
Memory trick: STS = 'Short Term Security' credentials
Blue/Green Deployment
Flip cardA deployment strategy that runs two identical production environments (blue and green) and shifts all traffic to the new environment at once, enabling zero-downtime releases and quick rollback.
- Two full, identical environments running simultaneously
- All traffic switches at once (not gradual like canary)
- Rollback is instant by redirecting traffic back to the old environment
Memory trick: Blue/Green: flip the switch between two full houses.
AWS Artifact & HIPAA BAA
Flip cardAWS Artifact is the self-service portal for downloading compliance reports and accepting agreements like the AWS Business Associate Addendum needed for HIPAA workloads.
- HIPAA is a shared responsibility; customers must also configure services correctly
- Artifact Agreements section lets eligible accounts accept the BAA online
- Not all AWS services are HIPAA-eligible; check the eligible services list
Memory trick: Artifact is the filing cabinet holding the HIPAA handshake agreement.
Convertible Reserved Instances
Flip cardA Reserved Instance type that allows exchanging attributes like instance family during the term for a smaller discount than Standard RIs.
- 1 or 3-year terms
- Can exchange for different instance types
- Lower discount than Standard RI but more flexible
Memory trick: Convertible = Change it up
Amazon Cognito
Flip cardA managed service providing user sign-up, sign-in, and access control for web and mobile applications, including social and enterprise identity federation.
- User Pools handle sign-up/sign-in
- Identity Pools grant temporary AWS credentials to app users
- Supports Google, Facebook, Amazon, SAML, and OIDC federation
Memory trick: Cognito = 'cognizant' of your app's end users
SSE-S3 vs SSE-KMS
Flip cardTwo S3 server-side encryption options: SSE-S3 uses AWS-managed keys with no extra cost, while SSE-KMS uses customer managed KMS keys offering auditability, key policies, and rotation at additional cost.
- SSE-S3: AES-256, keys fully managed by AWS, no CloudTrail key usage logging
- SSE-KMS: keys are customer managed in KMS, usage logged in CloudTrail, incurs per-request fees
- Choose SSE-KMS when you need granular access control or audit trails on key usage
Memory trick: S3 hides the key itself; KMS hands you the keyring to control.
EC2 Savings Plans
Flip cardA pricing model offering lower prices in exchange for a commitment to a consistent amount of compute usage ($/hour) for a 1- or 3-year term, flexible across instance families and compute services.
- Covers EC2, Fargate, and Lambda usage
- More flexible than Reserved Instances
- Discount based on committed hourly spend, not specific instance type
Memory trick: Savings Plans = commit to spend, not to a specific server.
Refactor / Re-architect
Flip cardA migration strategy that involves redesigning an application to take advantage of cloud-native features, often changing its architecture significantly.
- Most time- and resource-intensive of the 7 Rs
- Often used to improve scalability, agility, or add new features
- Commonly involves moving to microservices, serverless, or managed services
Memory trick: Refactor rebuilds the house from scratch, cloud-style.
EC2 Auto Scaling
Flip cardA service that automatically adjusts the number of EC2 instances in a group based on demand, health checks, or schedules.
- Uses scaling policies (target tracking, step, scheduled)
- Maintains minimum, desired, and maximum instance counts
- Improves availability and cost efficiency
Memory trick: Auto Scaling breathes in and out with traffic.
IAM Role for EC2 (Instance Profile)
Flip cardAn IAM role attached to an EC2 instance that supplies temporary security credentials to applications running on it, avoiding hard-coded keys.
- Credentials rotate automatically
- Assigned via an instance profile
- Best practice over embedding access keys
Memory trick: Roles rent credentials, users own them.
AWS IAM Identity Center
Flip cardA service that provides centralized single sign-on access for workforce users across multiple AWS accounts and business applications.
- Formerly known as AWS Single Sign-On (SSO)
- Integrates with external identity providers like Azure AD or Okta
- Eliminates the need to create individual IAM users in every account
Memory trick: Identity Center is the single front door to every AWS account.
Reliability Pillar
Flip cardA Well-Architected pillar ensuring a workload performs its intended function correctly and consistently, recovering from failures automatically.
- Includes multi-AZ/multi-region design
- Focuses on automated recovery
- Tests disaster recovery plans
Memory trick: Reliability = Recover, Rebound, Repeat.
EC2 Spot Instances
Flip cardSpare EC2 capacity offered at up to 90% discount, subject to interruption with a two-minute warning.
- Best for fault-tolerant, flexible workloads
- Can be reclaimed by AWS with short notice
- Cheapest EC2 pricing model available
Memory trick: Spot = Save big, but Stop anytime
Implicit Deny
Flip cardIn IAM, all requests are denied by default unless explicitly allowed by an attached policy.
- Default state for every IAM principal is deny-all
- An explicit Deny always overrides an explicit Allow
- Users need at least one Allow statement to perform any action
Memory trick: No key, no door — IAM locks everything until you hand out a key.
CloudWatch Logs
Flip cardA CloudWatch feature that centralizes, stores, and enables searching of log files from EC2 instances, Lambda, and other AWS resources.
- Requires the CloudWatch agent on EC2 for OS/application logs
- Supports log groups, streams, and metric filters
- Can trigger alarms based on log patterns
Memory trick: CloudWatch Logs is the central filing cabinet for your app's diary.
AWS Lambda
Flip cardA serverless compute service that runs code in response to triggers/events without requiring server provisioning or management.
- Pay only for compute time used (per millisecond)
- Automatically scales with incoming events
- Commonly triggered by S3, API Gateway, DynamoDB Streams, etc.
Memory trick: Lambda: 'run the code, skip the server.'
AWS Fargate
Flip cardA serverless compute engine for containers that works with ECS and EKS, eliminating the need to manage EC2 instances.
- No server provisioning or patching needed
- Works with both ECS and EKS
- Pay based on vCPU/memory used by containers
Memory trick: Fargate = Forget servers, just run containers
CloudWatch Alarms + SNS
Flip cardCloudWatch Alarms monitor metrics and change state when a threshold is breached, which can trigger an SNS notification (e.g., email) or an automated action.
- CloudWatch collects metrics (CPU, memory via agent, etc.)
- Alarms can trigger Auto Scaling actions or SNS notifications
- SNS delivers alerts via email, SMS, or other subscribers
Memory trick: Watch the metric, alarm when it's hot, shout via SNS.
AWS Business Support SLA
Flip cardThe Business support plan guarantees under 1-hour response time for production-system-down issues, with 24/7 phone/chat/email access to Cloud Support Engineers.
- Business plan: <1 hr for production system down, <4 hrs for production system impaired.
- Enterprise plan: <15 min for business-critical system down.
- Developer plan: no phone support, general guidance response <24 hrs.
Memory trick: Business = 1 hour for down systems; Enterprise = 15 minutes for critical.
Amazon EFS
Flip cardA managed, elastic NFS file system that can be concurrently mounted by many EC2 instances across multiple AZs.
- Uses NFS protocol
- Scales automatically with usage
- Supports multi-AZ concurrent access
Memory trick: EFS = Everyone's File Share
AWS Budgets Actions
Flip cardA feature of AWS Budgets that triggers automated or approval-based actions, such as applying IAM policies or stopping instances, when budget thresholds are exceeded.
- Can apply IAM or SCP policies automatically
- Can stop or terminate EC2/RDS instances
- Actions can require manual approval or run automatically
Memory trick: Budgets alert, Actions act
Shield Standard vs Shield Advanced
Flip cardAWS Shield Standard provides free, automatic protection against common DDoS attacks; Shield Advanced is a paid tier adding DDoS Response Team access, cost protection, and advanced mitigation for larger/sophisticated attacks.
- Shield Standard: free, automatic, all AWS customers
- Shield Advanced: paid subscription with DRT support and cost protection
- Shield Advanced also integrates with WAF for enhanced application-layer mitigation
Memory trick: Standard is the free helmet, Advanced hires bodyguards
IAM Permissions Boundary
Flip cardAn advanced IAM feature that defines the maximum permissions an identity-based policy can grant to a user or role.
- Effective permissions = intersection of boundary and identity policy
- Used for delegated administration
- Different from SCPs which apply at the Organizations account level
Memory trick: Boundary = the fence around a role's permissions
Route 53 Weighted Routing
Flip cardA routing policy that distributes traffic across multiple resources based on assigned weight values, useful for testing and gradual deployments.
- Weights determine traffic percentage
- Common for A/B testing and canary releases
- Weights can be adjusted dynamically
Memory trick: Weighted = Weigh out the traffic split
AWS Config Configuration Timeline
Flip cardAWS Config records resource configuration changes over time, enabling review of a resource's configuration history and compliance status.
- Config records configuration snapshots and change history
- Config Rules evaluate compliance continuously
- Different from CloudTrail, which logs API calls
Memory trick: Config = configuration snapshots; CloudTrail = call log
Consolidated Billing Volume Discounts
Flip cardAWS Organizations consolidated billing aggregates usage across accounts, letting combined usage reach lower-priced volume tiers faster.
- Applies to services like S3 with tiered pricing
- Master/management account receives one combined bill
- Savings arise because usage tiers are combined across accounts
Memory trick: Combine usage, hit cheaper tiers sooner
Network ACLs
Flip cardA stateless, subnet-level firewall in a VPC that evaluates numbered rules in order and supports both allow and explicit deny rules.
- Operate at the subnet level, not instance level
- Stateless — return traffic must be explicitly allowed
- Support explicit DENY rules, unlike Security Groups
Memory trick: NACL = 'Numbered gate that can say NO.'
CAF Business Perspective
Flip cardA CAF perspective helping business managers, finance, and strategy stakeholders align cloud investments with business outcomes.
- Involves finance and program managers
- Focuses on ROI and business case for cloud
- One of six CAF perspectives
Memory trick: Business Perspective = Bottom-line and business value.
S3 Intelligent-Tiering
Flip cardAn S3 storage class that automatically moves objects between access tiers based on changing access patterns to optimize storage cost.
- No retrieval fees for tier changes
- Ideal for unpredictable or unknown access patterns
- Monitors access and moves objects automatically
Memory trick: Intelligent-Tiering is the auto-pilot for unpredictable data.
AWS Shield Advanced
Flip cardA paid DDoS protection service offering enhanced detection, 24/7 DDoS Response Team access, and cost protection against attack-related scaling charges.
- Shield Standard is free and automatically enabled for all AWS customers
- Shield Advanced requires a subscription with a 1-year commitment
- Provides cost protection for scaling charges due to DDoS attacks on protected resources
Memory trick: Standard is the free shield; Advanced brings a DDoS SWAT team.
Regions and Availability Zones
Flip cardAn AWS Region is a geographic area containing multiple isolated Availability Zones (AZs), each made up of one or more data centers with independent infrastructure.
- Regions contain 2 or more AZs (most have 3+)
- AZs are physically separated but connected via low-latency links
- Edge locations are separate, used for CloudFront caching
Memory trick: Region = city; AZs = separate buildings in that city.
KMS Key Policy
Flip cardA resource-based policy attached to a KMS key that controls who can use and manage the key, required for cross-account access.
- Every KMS key must have a key policy
- Cross-account access requires both key policy and IAM policy grants
- Default key policy gives full access only to the account root
Memory trick: Key policy is the gatekeeper of the key itself
Access Key Rotation Best Practice
Flip cardAWS recommends using IAM roles for temporary credentials instead of long-lived access keys, and rotating any necessary access keys regularly.
- Long-lived access keys increase risk if leaked or forgotten
- IAM roles issue temporary credentials via AWS STS automatically
- When keys are required, rotate periodically and remove unused/old keys
Memory trick: Old keys rust — swap for a role's fresh temporary badge.
Amazon Detective
Flip cardA service that automatically collects and analyzes log data to build visual graphs helping security teams investigate the root cause of security findings.
- Ingests data from GuardDuty, VPC Flow Logs, CloudTrail
- Provides interactive visualizations of resource relationships
- Used for root-cause investigation, not initial detection
Memory trick: Detective 'connects the dots' visually after GuardDuty flags something
SQS Standard Queue
Flip cardA fully managed message queue offering nearly unlimited throughput and at-least-once delivery, with best-effort message ordering.
- Default SQS queue type
- At-least-once delivery, possible duplicates
- Higher throughput than FIFO queues
Memory trick: Standard queue: fast and flexible, order not guaranteed.
Public vs Private Subnets
Flip cardPublic subnets route traffic to an internet gateway, allowing direct internet access; private subnets do not have this direct route, isolating resources from the internet.
- Public subnets host internet-facing resources like web servers or load balancers
- Private subnets host backend resources like databases
- NAT gateways allow private subnet outbound internet access without inbound exposure
Memory trick: Public greets the world, private guards the data.
Trusted Advisor Core Checks
Flip cardA limited free set of Trusted Advisor checks (including service limits and select security checks) available to all AWS customers regardless of support plan.
- Core checks include service limits and some security checks
- Full 100+ checks require Business or Enterprise Support
- Business/Enterprise also add programmatic access via API
Memory trick: Everyone gets a taste, paid plans get the feast
AWS Budgets Forecasted Alerts
Flip cardA budget alert type that notifies users when AWS predicts spend will exceed a set threshold by period end, based on usage trends.
- Alert types include Actual and Forecasted cost/usage.
- Notifications can go to SNS topics, email, or chatbot integrations.
- Budgets can also trigger automated actions like applying IAM policies or stopping instances (Budgets Actions).
Memory trick: Forecast alerts are the 'weather report' warning of a storm before it hits.
AWS Free Tier
Flip cardA program offering limited free usage of AWS services for new accounts, including 12-month trials and always-free offers.
- 750 hrs/month t2.micro EC2 for 12 months
- 5GB S3 standard storage for 12 months
- Some services like Lambda have an always-free tier
Memory trick: Free Tier = Try before you pay
AWS Penetration Testing Policy
Flip cardAWS allows customers to conduct penetration tests against their own resources for a list of commonly tested services without prior approval, subject to the Acceptable Use Policy.
- No prior approval needed for permitted services (EC2, ELB, NAT gateways, etc.)
- Prohibited actions include DNS zone walking and DDoS simulation
- Some services still require special permission requests
Memory trick: Test freely on your own house, but follow AWS's house rules
Envelope Encryption (KMS)
Flip cardA technique where a data key encrypts the actual data locally, and the data key itself is then encrypted by a KMS master key, avoiding sending large data to KMS.
- KMS generates a plaintext and encrypted copy of the data key via GenerateDataKey
- The CMK never leaves the KMS service boundary
- Only the small encrypted data key needs to be decrypted by KMS to unlock the data
Memory trick: Put your letter in an envelope, then lock the envelope with the master key.
AWS Network Firewall
Flip cardA managed, stateful network firewall and intrusion prevention service for filtering traffic to and from Amazon VPCs.
- Operates at the VPC level, unlike security groups which are per-instance
- Supports domain filtering, stateful rules, and intrusion prevention signatures
- Integrates with AWS Firewall Manager for centralized policy management
Memory trick: Network Firewall guards the whole VPC gate, not just one door.
GuardDuty Malware Protection
Flip cardA GuardDuty feature that automatically scans EBS volumes attached to EC2 instances or containers flagged with suspicious findings, checking for malware.
- Triggered by suspicious GuardDuty findings tied to an EC2 instance
- Performs agentless scanning of EBS snapshots
- Generates malware findings that feed into the GuardDuty console and Security Hub
Memory trick: Malware Protection is GuardDuty's doctor checking the volume for infection.
Savings Plans
Flip cardA pricing model offering lower rates in exchange for a commitment to a consistent amount of compute usage ($/hour) for 1 or 3 years.
- Two types: Compute Savings Plans (most flexible) and EC2 Instance Savings Plans (family-specific).
- Can save up to 72% compared to On-Demand.
- No upfront payment required, though upfront/partial upfront options exist for greater discounts.
Memory trick: Savings Plans = 'Spend Promise', not 'Instance Promise'.
RI Payment Options Cost Comparison
Flip cardReserved Instances can be purchased No Upfront, Partial Upfront, or All Upfront; the cheapest option depends on the specific upfront fee and hourly rate combination, not a fixed rule.
- No Upfront: pay only an hourly rate, no discount for prepayment
- Partial Upfront: pay a portion upfront for a lower hourly rate
- All Upfront: pay the full commitment upfront, often the largest discount but not always cheapest depending on rates given
Memory trick: Do the math each time — upfront isn't always cheapest
CloudTrail Data Events
Flip cardCloudTrail events that record object-level operations (e.g., S3 GetObject/PutObject, Lambda Invoke) which are not logged by default.
- Must be explicitly enabled per resource
- Higher volume/cost than management events
- Management events are enabled by default and cover control plane actions
Memory trick: Data events = the 'data plane' details, off by default
Cost Explorer
Flip cardAn AWS billing tool that visualizes and analyzes historical and forecasted spending patterns.
- Supports filtering and grouping by service, account, tag, region.
- Provides up to 12 months of historical data and forecasts up to 12 months ahead.
- Free to use for viewing standard reports.
Memory trick: Cost Explorer = 'Cost X-ray' to see inside your bill.
Security Hub Security Standards
Flip cardAWS Security Hub can enable security standards such as the CIS AWS Foundations Benchmark, AWS Foundational Security Best Practices, and PCI DSS to automatically check account configuration against recognized frameworks.
- Standards run automated checks and produce a compliance score
- CIS AWS Foundations Benchmark is a widely recognized standard
- Security Hub aggregates findings from GuardDuty, Inspector, Config, and more
Memory trick: Security Hub grades you against the industry rulebook
Amazon CloudFront
Flip cardAWS's content delivery network (CDN) that caches and delivers content from edge locations close to end users to reduce latency.
- Uses global edge locations
- Integrates with S3, EC2, and custom origins
- Reduces latency and origin load
Memory trick: CloudFront = Content at the Front door (edge)
VPC Flow Logs
Flip cardA feature that captures metadata about IP traffic flowing to and from network interfaces within a VPC.
- Can be enabled at VPC, subnet, or ENI level
- Captures source/destination IP, port, protocol, and action (accept/reject)
- Logs can be sent to CloudWatch Logs or S3 for analysis
Memory trick: Flow Logs are the traffic camera watching every packet's path.
Rehost (Lift and Shift)
Flip cardA migration strategy where an application is moved to the cloud with minimal or no modification to the code or architecture.
- Fastest of the 7 Rs migration strategies
- Ideal for tight deadlines or large-scale migrations
- Part of AWS's 7 Rs migration strategies framework
Memory trick: Lift the box, shift it to the cloud—Rehost.
Service Control Policy (SCP)
Flip cardA policy in AWS Organizations that sets the maximum available permissions for accounts within an OU, acting as a guardrail that overrides local IAM permissions.
- Applied at OU or account level in AWS Organizations
- Does not grant permissions, only restricts maximum allowed actions
- Cannot be overridden by IAM policies within the account
Memory trick: SCPs are the org-wide 'ceiling' no IAM policy can break through.
Technical Account Manager (TAM)
Flip cardA dedicated Enterprise Support resource who provides proactive guidance, architectural reviews, and acts as a single point of contact.
- Included only in Enterprise Support plan
- Provides proactive operational and cost guidance
- Different from case-based support engineers
Memory trick: TAM = Trusted Advisor for humans