AWS Certified Cloud Practitioner (CLF-C02) flashcards
171 free flashcards. Tap a card to flip it.
VPC Flow Logs
Flip cardA feature that captures metadata about IP traffic flowing to and from network interfaces within a VPC.
- Can be enabled at VPC, subnet, or ENI level
- Captures source/destination IP, port, protocol, and action (accept/reject)
- Logs can be sent to CloudWatch Logs or S3 for analysis
Memory trick: Flow Logs are the traffic camera watching every packet's path.
Rehost (Lift and Shift)
Flip cardA migration strategy where an application is moved to the cloud with minimal or no modification to the code or architecture.
- Fastest of the 7 Rs migration strategies
- Ideal for tight deadlines or large-scale migrations
- Part of AWS's 7 Rs migration strategies framework
Memory trick: Lift the box, shift it to the cloud—Rehost.
Service Control Policy (SCP)
Flip cardA policy in AWS Organizations that sets the maximum available permissions for accounts within an OU, acting as a guardrail that overrides local IAM permissions.
- Applied at OU or account level in AWS Organizations
- Does not grant permissions, only restricts maximum allowed actions
- Cannot be overridden by IAM policies within the account
Memory trick: SCPs are the org-wide 'ceiling' no IAM policy can break through.
Technical Account Manager (TAM)
Flip cardA dedicated Enterprise Support resource who provides proactive guidance, architectural reviews, and acts as a single point of contact.
- Included only in Enterprise Support plan
- Provides proactive operational and cost guidance
- Different from case-based support engineers
Memory trick: TAM = Trusted Advisor for humans
Encryption in Transit with ACM
Flip cardAWS Certificate Manager provisions TLS/SSL certificates that can be attached to load balancer listeners to encrypt data between clients and AWS resources.
- ACM certificates are free for use with integrated AWS services like ALB and CloudFront
- Encryption in transit protects data as it moves over networks
- Complements at-rest encryption like SSE-KMS for full data protection
Memory trick: ACM = the padlock icon in your browser's address bar
Amazon EKS
Flip cardA managed service that runs the open-source Kubernetes control plane, allowing customers to use standard Kubernetes tools while AWS manages availability and patching of the control plane.
- Runs standard, certified Kubernetes
- Can use EC2 or Fargate as compute for worker nodes
- Different from ECS, which is AWS's proprietary orchestrator
Memory trick: EKS = 'Kubernetes, the AWS-managed way.'
CapEx to OpEx
Flip cardCloud computing lets organizations replace large upfront capital expenditures on hardware with variable operational expenditures based on actual usage.
- CapEx = upfront purchase of physical infrastructure
- OpEx = pay-as-you-go, usage-based spending
- One of the six benefits of cloud computing
Memory trick: Trade the big check for a monthly bill.
S3 Block Public Access
Flip cardAn S3 security feature that overrides bucket policies and ACLs to prevent public access, settable at the account or bucket level.
- Can be enabled account-wide to protect all buckets
- Overrides any future public bucket policy or ACL changes
- Recommended as a default security baseline for S3
Memory trick: A locked bucket lid stays shut no matter who tries to open it.
AWS CloudTrail
Flip cardA service that records API calls and account activity across AWS services, providing an audit trail for security analysis and compliance.
- Captures caller identity, timestamp, source IP, and request parameters
- Events can be stored in S3 for long-term retention and analysis
- Enables detection of unauthorized or unusual account activity
Memory trick: CloudTrail leaves a trail of who did what, when, and from where.
CAF Platform Perspective
Flip cardA CAF perspective led by technology leaders that defines architecture principles, provisioning standards, and hybrid/multi-cloud infrastructure design.
- Involves CTOs and architects
- Establishes service catalogs and provisioning standards
- Supports hybrid and multi-cloud strategies
Memory trick: Platform = Plans the technical foundation.
IAM Password Policy
Flip cardAn account-wide setting that enforces password length, complexity, expiration, and reuse rules for IAM users.
- Configured per AWS account in IAM settings
- Can require minimum length, uppercase/lowercase/numbers/symbols
- Can set expiration period and prevent password reuse
Memory trick: One ruler measures every password in the account.
Spot Instances
Flip cardEC2 pricing model that uses spare AWS capacity at steep discounts, suitable for flexible, interruptible workloads.
- Up to 90% cheaper than On-Demand
- AWS can reclaim capacity with a 2-minute warning
- Best for batch jobs, CI/CD, stateless web servers
Memory trick: Spot = spare & spontaneous savings
Consolidated Billing (Payer Account)
Flip cardA feature of AWS Organizations where the management account receives one combined invoice for usage across all linked member accounts.
- Management account = payer account, billed for all usage
- Member accounts see their own usage but not each other's
- Enables volume discounts and RI/Savings Plan sharing across the organization
Memory trick: One Org, One Bill, One Payer
CAF Governance Perspective
Flip cardA perspective in the AWS Cloud Adoption Framework that focuses on skills and processes to align IT strategy with business strategy, including risk management, compliance, and IT portfolio management.
- One of six CAF perspectives
- Stakeholders typically include CIO, program managers, enterprise architects
- Distinct from the Security perspective, which focuses narrowly on security objectives
Memory trick: Governance sets the rules and tracks the assets.
AWS Certificate Manager (ACM)
Flip cardA service that provisions, manages, and automatically renews public and private SSL/TLS certificates for use with AWS services.
- Public certificates are free when used with supported AWS services
- Automatic renewal avoids expired certificate outages
- Integrates with ALB, CloudFront, API Gateway
Memory trick: ACM = Automatic Certificate Maintenance, free and renewed.
Concierge Support Team
Flip cardA dedicated group under AWS Enterprise Support that assists with billing, account, and administrative questions, distinct from technical support engineers.
- Included only with Enterprise Support (and Enterprise On-Ramp)
- Handles billing/account issues, not technical troubleshooting
- Complements the Technical Account Manager (TAM) role
Memory trick: Enterprise = Everything: TAM + Concierge + 15-min SLA
Reserved Instance Savings
Flip cardReserved Instances offer discounted pricing compared to On-Demand for steady-state workloads by committing to a 1- or 3-year term.
- All-upfront RIs have no hourly charge
- Savings increase with longer commitment terms
- Best for predictable, continuous workloads
Memory trick: Reserve ahead, save instead.
Security Pillar
Flip cardA Well-Architected pillar focused on protecting data, systems, and assets through risk assessment and mitigation.
- Includes IAM, data protection, incident response
- One of six Well-Architected pillars
- Emphasizes defense in depth
Memory trick: 'S' for Security = Shield your data.
Principle of Least Privilege
Flip cardA security best practice of granting users or systems only the permissions necessary to perform their required tasks.
- Reduces attack surface
- Applied via scoped IAM policies
- Core AWS Well-Architected security pillar concept
Memory trick: Give only the keys needed, not the whole keyring.
Savings Plans
Flip cardA pricing model offering lower rates in exchange for a commitment to a consistent amount of compute usage ($/hour) for 1 or 3 years.
- Two types: Compute Savings Plans (most flexible) and EC2 Instance Savings Plans (family-specific).
- Can save up to 72% compared to On-Demand.
- No upfront payment required, though upfront/partial upfront options exist for greater discounts.
Memory trick: Savings Plans = 'Spend Promise', not 'Instance Promise'.
Trusted Advisor Security Checks
Flip cardA category of AWS Trusted Advisor recommendations that identifies security gaps like open ports, public S3 buckets, and missing MFA.
- One of five Trusted Advisor categories
- Checks include MFA on root, security groups, public S3 access
- Full checks require Business/Enterprise support plan
Memory trick: Trusted Advisor's 5 categories: Cost, Performance, Security, Fault Tolerance, Service Limits.
S3 Standard-IA
Flip cardAn S3 storage class for infrequently accessed data that requires rapid access when needed, at a lower storage cost than S3 Standard.
- Millisecond access time
- Lower storage cost, but per-GB retrieval fee applies
- Ideal for backups and disaster recovery data
Memory trick: IA: Infrequent visits, Instant Access.
Multi-Factor Authentication (MFA)
Flip cardA security mechanism requiring users to present two or more verification factors to gain access, such as a password plus a one-time code.
- Should be enabled on the root user and privileged IAM users
- Supports virtual MFA apps, hardware tokens, and security keys
- Adds a critical layer of defense against compromised passwords
Memory trick: Something you know PLUS something you have.
EC2 Per-Second Billing
Flip cardAWS bills EC2 On-Demand, Reserved, and Spot Linux instances by the second with a 60-second minimum charge, rather than rounding to the nearest full hour.
- Applies to Linux/Unix instances; Windows and some marketplace AMIs remain hourly.
- Minimum billable duration is 60 seconds per instance run.
- EBS volumes are billed per GB-month regardless of EC2 billing granularity.
Memory trick: Linux ticks by the second, Windows still counts by the hour.
AWS Config Aggregator
Flip cardA Config feature that collects configuration and compliance data from multiple AWS accounts and Regions into a single aggregator account for centralized visibility.
- Supports both individual account aggregation and AWS Organizations-wide aggregation
- Provides a single pane of glass for multi-account compliance review
- Does not replace Config Rules; it aggregates their results
Memory trick: An aggregator gathers every account's Config report into one binder.
AWS Secrets Manager
Flip cardA service for securely storing, retrieving, and automatically rotating secrets such as database credentials and API keys.
- Built-in automatic rotation for supported databases
- Integrates with RDS, Redshift, DocumentDB
- Encrypts secrets using KMS
Memory trick: Secrets Manager 'manages' and rotates your secrets automatically.
Amazon Macie
Flip cardA fully managed data security service that uses machine learning to discover, classify, and protect sensitive data like PII in Amazon S3.
- Focuses on S3 data discovery
- Uses ML and pattern matching
- Generates findings for exposed/sensitive data
Memory trick: Macie 'sees' sensitive data hiding in S3.
Internet Gateway
Flip cardA VPC component that enables communication between instances in a VPC and the internet for both inbound and outbound traffic.
- Must be attached to a VPC and referenced in route tables
- Enables public subnet instances to have public IP connectivity
- Highly available and horizontally scaled by AWS
Memory trick: Internet Gateway is the VPC's front door to the web.
CloudTrail Log File Integrity Validation
Flip cardA CloudTrail feature that uses SHA-256 hashing and digital signatures to create digest files, enabling detection of whether log files were altered or deleted after delivery.
- Uses SHA-256 hashing and digest files
- Digest files are digitally signed
- Helps prove log files are unaltered for audits/forensics
Memory trick: Digest files are the tamper-evident seal on your logs.
Amazon Aurora
Flip cardA MySQL/PostgreSQL-compatible relational database built for the cloud, offering higher performance, up to 15 read replicas, and storage that auto-scales to 128 TB.
- Up to 15 read replicas (vs 5 for RDS)
- Storage auto-scales up to 128 TB
- Failover typically under 30 seconds
Memory trick: Aurora = Aurora borealis lights up with 15 replicas
RDS Read Replica
Flip cardA read-only copy of an RDS database used to offload read traffic from the primary instance, improving performance for read-heavy workloads.
- Uses asynchronous replication
- Can be promoted to a standalone database if needed
- Supported for MySQL, PostgreSQL, MariaDB, Oracle, and SQL Server
Memory trick: Read Replica = a photocopy for readers so the original stays free to write.
VPC Peering
Flip cardA networking connection between two VPCs that enables routing of traffic using private IP addresses without going through the public internet.
- Non-transitive: peering doesn't extend beyond the two directly connected VPCs
- Can connect VPCs in the same or different accounts/regions
- Requires route table updates on both VPCs
Memory trick: Peering builds a private bridge between two neighborhoods.
SNS Fan-Out Pattern
Flip cardAn architecture where an SNS topic publishes a message to multiple subscribers (SQS, Lambda, email, etc.) simultaneously, enabling decoupled parallel processing.
- One message, multiple subscriber types
- Decouples producers from consumers
- Common subscribers: SQS, Lambda, HTTP, email
Memory trick: SNS fans out the message like a megaphone to many ears
S3 One Zone-IA
Flip cardAn S3 storage class for infrequently accessed data that stores data in a single Availability Zone at a lower cost than Standard-IA.
- Cheapest IA class but less resilient (single AZ)
- Best for reproducible or non-critical data
- Millisecond access like Standard-IA
Memory trick: One Zone = one basket, cheaper but riskier.
Canary Deployment
Flip cardA deployment strategy that releases a new application version to a small subset of users or traffic first, gradually increasing exposure while monitoring for issues.
- Minimizes blast radius of potential issues
- Differs from Blue/Green by gradual traffic shift rather than full cutover
- Often paired with monitoring tools like CloudWatch
Memory trick: Canary in the coal mine: test with a few before risking everyone.
Trusted Advisor Access by Support Plan
Flip cardTrusted Advisor's full set of checks across cost, performance, security, fault tolerance, and service limits requires Business support or higher; Basic/Developer only get core security and limit checks.
- Basic/Developer: ~7 core checks (S3 permissions, security groups, IAM use, MFA, service limits).
- Business/Enterprise: full check catalog plus API access and CloudWatch Events integration.
- Trusted Advisor itself is free to access at some level for every account.
Memory trick: Basic peeks through the keyhole; Business opens the whole vault.
AWS Config
Flip cardA service that continuously monitors and records AWS resource configurations and evaluates them against desired rules for compliance.
- Uses Config Rules to check for compliance conditions
- Provides configuration history and change timeline for resources
- Can trigger automated remediation actions for non-compliant resources
Memory trick: Config keeps configs compliant continuously.
EBS Snapshot
Flip cardAn incremental, point-in-time backup of an Amazon EBS volume stored durably in Amazon S3.
- Only changed blocks are saved after the first snapshot
- Can be used to create new volumes or AMIs
- Stored in S3 but not directly accessible as S3 objects
Memory trick: Snapshot = camera click of your volume's current state.
DynamoDB On-Demand Capacity
Flip cardA DynamoDB billing/scaling mode that automatically adjusts throughput to match traffic without pre-provisioning capacity.
- No capacity planning needed
- Pay per request pricing
- Ideal for unpredictable or spiky workloads
Memory trick: On-Demand = On the fly scaling
AWS Marketplace Billing
Flip cardAWS Marketplace software charges are billed through the customer's AWS account and consolidated into the standard monthly AWS invoice.
- Charges appear in Cost Explorer, CUR, and the AWS Billing console.
- Pricing models vary: hourly, monthly, annual, or usage-based (e.g., per API call).
- Marketplace purchases can also be covered under consolidated billing across an Organization.
Memory trick: Marketplace apps ride on the same AWS bill, not a separate tab.
IAM Access Analyzer
Flip cardA service that analyzes resource policies to identify resources shared with external entities, helping detect unintended public or cross-account access.
- Uses automated reasoning (mathematical logic) on policies
- Analyzes S3, IAM roles, KMS keys, and more
- Generates findings for external access, does not block it automatically
Memory trick: Access Analyzer 'peeks outside' your account boundary.
AWS Security Hub
Flip cardA service that provides a comprehensive view of security alerts and compliance status by aggregating findings from multiple AWS security services and standards.
- Aggregates findings from GuardDuty, Inspector, Macie, and Config
- Runs automated compliance checks (e.g., CIS AWS Foundations Benchmark, PCI DSS)
- Provides a unified security score and prioritized findings dashboard
Memory trick: Security Hub is mission control gathering all the security alarms.
Repurchase (7 Rs)
Flip cardA migration strategy that involves switching to a different product, often a SaaS solution, instead of migrating the existing application.
- Also called 'drop and shop'
- Common for CRM/ERP replacements with SaaS
- Reduces maintenance burden of legacy software
Memory trick: Repurchase = Replace it with something new off the shelf.
Amazon GuardDuty
Flip cardA managed threat detection service that uses machine learning and threat intelligence to analyze logs and identify malicious activity across AWS accounts.
- Analyzes VPC Flow Logs, DNS logs, and CloudTrail events
- No agents or additional infrastructure required
- Generates findings that can integrate with Security Hub
Memory trick: GuardDuty guards by watching the logs, not the servers.
Total Cost of Ownership (TCO)
Flip cardA financial estimate comparing the direct and indirect costs of on-premises infrastructure versus cloud alternatives to determine overall savings or expense.
- Includes hardware depreciation, maintenance, and power for on-prem comparisons
- Cloud TCO typically uses hourly or usage-based pricing
- AWS provides a TCO calculator to help with these comparisons
Memory trick: Add up on-prem, subtract cloud, find the savings.
RDS Multi-AZ
Flip cardAn RDS high-availability feature that maintains a synchronous standby replica in a different AZ and automatically fails over during an outage.
- Synchronous replication to standby AZ
- Automatic failover, typically under a minute or two
- Different from Read Replicas, which are for read scaling, not HA
Memory trick: Multi-AZ = 'always a backup twin standing by.'
Data Residency via Region Selection
Flip cardAWS customers control data location by choosing specific AWS Regions to deploy resources; AWS does not move customer data across Regions without explicit action.
- Each AWS Region is a separate geographic area with multiple Availability Zones
- Data stored in a Region stays there unless the customer replicates or moves it
- Choosing appropriate Regions is key to meeting data residency/sovereignty laws
Memory trick: Pick your postcode — AWS keeps your data where you park it.
EC2 On-Demand Instances
Flip cardPay-as-you-go compute capacity with no upfront payment or long-term commitment, billed per second or hour.
- No contract or commitment required
- Highest per-hour price of standard purchase options
- Best for short-term, unpredictable, or new workloads
Memory trick: On-Demand = pay-as-you-go, no strings attached.
AWS Pricing Calculator
Flip cardA free tool for estimating the cost of AWS services for planned architectures before they are deployed.
- No AWS account or existing usage required
- Supports exporting estimates for proposals
- Different from Cost Explorer, which analyzes actual past spend
Memory trick: Calculator predicts, Explorer reflects
Cost Optimization Pillar
Flip cardA Well-Architected Framework pillar focused on avoiding unnecessary costs, including right-sizing resources and using appropriate pricing models.
- One of six Well-Architected pillars
- Includes practices like right-sizing and using Reserved/Savings Plans
- Complements, not replaces, other pillars like performance and reliability
Memory trick: Trim the fat, keep the muscle—Cost Optimization.
Route 53 Latency-Based Routing
Flip cardA Route 53 routing policy that routes traffic to the AWS Region that provides the lowest network latency for the end user, based on measured latency data.
- Uses latency measurements between users and AWS Regions
- Different from geolocation, which uses physical location
- Useful for improving performance for globally distributed applications
Memory trick: Latency routing: fastest road wins, not nearest map pin.
Basic Support Plan Limitations
Flip cardThe free Basic support plan included with every AWS account covers account/billing support and limited Trusted Advisor checks, but excludes technical support cases entirely.
- Technical support cases require Developer support or higher.
- Basic support includes 24/7 access to customer service, forums, and documentation.
- All AWS accounts automatically have Basic support by default.
Memory trick: Basic is billing-only; pay more to talk tech.
Retire (7 Rs)
Flip cardA migration strategy that involves decommissioning applications no longer needed, reducing licensing and infrastructure costs.
- Applies to unused or redundant applications
- Reduces attack surface and maintenance overhead
- One of the original 6 Rs, later expanded to 7
Memory trick: Retire = Retire the unused, don't relocate it.
IAM Managed Policy
Flip cardA standalone, reusable IAM policy that can be attached to multiple users, groups, or roles and updated centrally.
- AWS managed policies are created and maintained by AWS
- Customer managed policies are created and maintained by the account owner
- Editing a managed policy updates permissions everywhere it's attached
Memory trick: Managed policies are the reusable stamp you attach anywhere.
KMS Automatic Key Rotation
Flip cardAWS KMS can automatically rotate the cryptographic material of a customer managed key approximately every year while preserving the key ID and ARN.
- Rotation keeps the same key ID so apps need no changes
- Applies to customer managed KMS keys (optional, enabled per key)
- AWS managed keys rotate automatically every year by default
Memory trick: Same lock, new key teeth every year
Cross-Account IAM Role
Flip cardA cross-account IAM role has a trust policy specifying which external AWS account can assume it, providing temporary, scoped access without sharing long-term credentials.
- Trust policy defines who can assume the role
- Permissions policy defines what the role can do
- Temporary credentials are issued via AWS STS when the role is assumed
Memory trick: Lend the key temporarily, don't give away the house
AWS Cost Explorer
Flip cardA tool that visualizes and analyzes historical AWS costs and usage with filtering by account, service, and other dimensions.
- Default view shows up to 12 months of history plus forecasts
- Supports filtering by linked account, service, tag, and instance type
- Free to use within the AWS Management Console
Memory trick: Explorer looks back, Calculator looks ahead
AWS Firewall Manager
Flip cardA security management service that centrally configures and enforces AWS WAF rules, Shield Advanced protections, and security groups across multiple accounts in an AWS Organization.
- Requires AWS Organizations
- Centralizes WAF, Shield Advanced, and security group policies
- Automatically applies policies to new accounts/resources
Memory trick: Firewall Manager = one firewall policy ruling many accounts
CloudTrail Insights
Flip cardA CloudTrail feature that uses machine learning to detect unusual API call volume or error rate patterns and generates Insight events for investigation.
- Analyzes management event activity for anomalies like spikes or drops
- Must be explicitly enabled on a trail (incurs additional cost)
- Insight events appear in the CloudTrail console and can trigger alerts via EventBridge
Memory trick: Insights is CloudTrail's alarm bell for weird spikes in API calls.
Economies of Scale
Flip cardAs aggregate usage from many customers increases, AWS can achieve greater cost efficiencies and pass the savings on in the form of lower pricing.
- One of the six advantages of cloud computing
- Driven by massive aggregated demand across all AWS customers
- Results in historical AWS price reductions over time
Memory trick: Bigger buyer, cheaper price for everyone.