AWS Certified Cloud Practitioner (CLF-C02) flashcards
171 free flashcards. Tap a card to flip it.
Well-Architected Security Pillar
Flip cardOne of the six pillars of the AWS Well-Architected Framework focused on protecting data, systems, and assets through risk assessment and mitigation.
- One of six pillars (also: Operational Excellence, Reliability, Performance Efficiency, Cost Optimization, Sustainability)
- Emphasizes identity management, detective controls, infrastructure protection, data protection, incident response
- Guides architectural best practices, not a specific tool
Memory trick: Security pillar = the 'lock' pillar protecting the whole building
AWS Key Management Service (KMS)
Flip cardA managed service for creating and controlling encryption keys used to encrypt data across AWS services.
- Supports automatic annual key rotation for customer-managed keys
- Integrates with S3, EBS, RDS, and other services for encryption
- Customers can define key policies and control who can use or manage keys
Memory trick: KMS is the master keyring for all your encryption keys.
SQS FIFO Queue
Flip cardAn SQS queue type that guarantees messages are processed exactly once, in the exact order they were sent.
- Exactly-once processing and strict ordering
- Lower throughput than Standard queues (unless using high-throughput mode)
- Queue name must end with .fifo
Memory trick: FIFO: 'First In, First Out, no do-overs.'
Elastic Load Balancing (ELB)
Flip cardA managed service that automatically distributes incoming traffic across multiple targets like EC2 instances to improve availability and fault tolerance.
- Supports Application, Network, and Gateway Load Balancer types
- Performs health checks to route traffic only to healthy targets
- Works across multiple Availability Zones
Memory trick: ELB is the traffic cop directing cars to open lanes.
EBS Provisioned IOPS SSD (io2)
Flip cardAn EBS volume type designed for I/O-intensive workloads requiring sustained high IOPS and low latency.
- Supports up to 256,000 IOPS per volume
- Ideal for critical relational/NoSQL databases
- io2 Block Express offers even higher performance and durability
Memory trick: 'io' stands for I/O intensity — pick io2 for demanding databases.
Management Account Root Security
Flip cardIn AWS Organizations, the management account's root user has organization-wide power, so it must be secured with MFA and used minimally, delegating tasks to IAM roles/users.
- Management account actions can affect all member accounts
- Root user credentials cannot be deleted, only secured and restricted in use
- Best practice: enable MFA, use hardware key if possible, avoid routine use
Memory trick: The master key to the whole kingdom stays locked in a vault, not on a keychain.
Shared Responsibility Model
Flip cardA framework defining that AWS secures the cloud infrastructure while customers secure what they put in the cloud.
- AWS: hardware, facilities, hypervisor, global infrastructure
- Customer: data, IAM, OS patching (for EC2), network configuration
- Responsibility split varies by service (e.g., managed vs unmanaged)
Memory trick: AWS locks the building, you lock your office door.
IAM Groups
Flip cardIAM groups let you attach policies to multiple users at once, simplifying permission management for users with similar access needs.
- Users can belong to multiple groups
- Policies attached to a group apply to all members
- Best practice: attach policies to groups, not individual users
Memory trick: Group first, individual last
Amazon Inspector
Flip cardAn automated vulnerability management service that continuously scans EC2 instances, Lambda functions, and container images for software vulnerabilities and network exposure.
- Automatically scans ECR container images for known CVEs
- Provides risk scores to help prioritize remediation
- Continuously rescans as new vulnerabilities are discovered
Memory trick: Inspector inspects images and instances for hidden vulnerabilities.
Performance Efficiency Pillar
Flip cardA Well-Architected pillar focused on using IT and computing resources efficiently and adapting as needs and technology evolve.
- Includes selecting right resource types
- Encourages experimentation with new services
- Considers tradeoffs like latency vs cost
Memory trick: Performance = Pick the right tool for the job.
EBS Encryption with KMS
Flip cardAmazon EBS uses AWS KMS keys to encrypt volumes, snapshots, and associated data transfer, without requiring customers to manage keys manually.
- Uses AES-256 encryption under the hood
- Can enable account-level default encryption for all new volumes
- Encrypted snapshots and volumes remain encrypted when copied or restored
Memory trick: KMS holds the keys that lock every EBS volume.
WAF Rate-Based Rule
Flip cardAn AWS WAF rate-based rule tracks the number of requests from an IP address over a rolling time window and blocks IPs that exceed a set threshold.
- Effective against application-layer DDoS/brute-force attempts
- Threshold is configurable (requests per 5-minute window)
- Complements Shield, which protects at network/transport layers
Memory trick: Too many knocks, WAF shuts the door
RI/Savings Plans Utilization Budget
Flip cardAn AWS Budgets type that alerts when the percentage of purchased Reserved Instance or Savings Plan capacity actually used falls below a target threshold.
- Distinct from cost, usage, and coverage budgets
- Helps detect underused reservations wasting money
- Coverage budgets instead measure how much on-demand usage is covered by commitments
Memory trick: Cost = $, Usage = units, Utilization = wasted RIs, Coverage = eligible usage covered
Systems Manager Session Manager
Flip cardA Systems Manager capability that provides secure, browser-based or CLI shell access to managed instances without opening inbound ports or managing SSH keys.
- No need to open port 22 or manage bastion hosts
- Requires the SSM Agent and an IAM role attached to the instance
- All session activity can be logged for auditing via CloudTrail/S3
Memory trick: Session Manager opens a hidden tunnel, no keys, no open doors needed.
AWS Artifact
Flip cardA self-service portal for accessing AWS compliance reports and agreements such as SOC, ISO, and PCI documents.
- Free service available in the AWS Management Console
- Provides on-demand access to audit artifacts
- Also used to accept agreements like the BAA for HIPAA
Memory trick: Artifact = Archive of certificates.
CAF People Perspective
Flip cardA perspective in the AWS Cloud Adoption Framework focused on developing an organization-wide change management strategy for successful cloud adoption, including staffing and training.
- One of six CAF perspectives (Business, People, Governance, Platform, Security, Operations)
- Stakeholders typically include HR and staffing leaders
- Addresses culture change and skills gaps
Memory trick: People power the transformation—train the team.
Rolling Deployment
Flip cardA deployment strategy that gradually replaces instances running the old application version with instances running the new version, in batches, until fully updated.
- Reduces risk by limiting exposure to a subset of instances at a time
- No need for duplicate full-scale environment like blue/green
- Rollback can be slower than blue/green since old instances are already replaced
Memory trick: Rolling deployment: swap instances one batch at a time, like changing tires while driving slowly.
EC2 Reserved Instances
Flip cardA pricing model that offers significant discounts on EC2 usage in exchange for a 1- or 3-year commitment to a specific instance configuration.
- Up to 72% cheaper than On-Demand
- Best for steady-state, predictable workloads
- Standard, Convertible, and Scheduled RI types available
Memory trick: 'Reserve now, save later' for workloads that never stop.
Edge Locations
Flip cardGlobally distributed AWS sites used by CloudFront and Route 53 to cache content and reduce latency close to end users.
- Far more numerous than Regions/AZs
- Used for CloudFront caching and Route 53 DNS resolution
- Improve performance by serving content near the end user
Memory trick: Edge locations are the CDN's front doors closest to users.
Operational Excellence Pillar
Flip cardA Well-Architected Framework pillar focused on running and monitoring systems and continually improving processes and procedures.
- One of six Well-Architected pillars
- Emphasizes automation of changes and small, reversible changes
- Includes learning from operational failures
Memory trick: Operate, Observe, Improve—Operational Excellence.
Sustainability Pillar
Flip cardA Well-Architected pillar focused on minimizing the environmental impacts of running cloud workloads.
- Uses Customer Carbon Footprint Tool
- Encourages maximizing utilization to reduce waste
- Sixth and newest Well-Architected pillar
Memory trick: Sustainability = Save the planet, not just money.
IAM Policy Evaluation Logic
Flip cardWhen evaluating multiple IAM policies, AWS defaults to implicit deny, but any explicit deny statement always overrides an explicit allow.
- Default is implicit deny (no access unless explicitly allowed)
- Explicit deny in any policy always wins over any allow
- Applies across identity-based and resource-based policies
Memory trick: Deny is the trump card in IAM poker
CAF Security Perspective
Flip cardAn AWS CAF perspective that helps organizations structure the selection and implementation of security controls across the cloud environment to meet business and regulatory requirements.
- Covers IAM, detective controls, infrastructure protection, data protection, incident response
- Aligns security requirements with business objectives
- One of six CAF perspectives
Memory trick: Security = locking down identity, detection, and response.
AWS Migration Phases: Mobilize
Flip cardThe second phase of the AWS migration process, where organizations refine the business case, address readiness gaps, and build a landing zone before migrating workloads.
- Follows the Assess phase
- Includes landing zone setup (networking, identity, security)
- Precedes the Migrate and Modernize phase
Memory trick: Assess the fit, Mobilize the plan, Migrate the workload.
Well-Architected Pillar Trade-offs
Flip cardA recognition that the six Well-Architected Framework pillars can sometimes conflict, requiring organizations to balance priorities such as reliability versus cost based on business needs.
- Multi-AZ redundancy boosts reliability but raises cost
- Pillars are not always mutually reinforcing
- Business context determines acceptable trade-offs
Memory trick: More 9s of uptime often means more $ spent.
Relocate (7 Rs)
Flip cardA migration strategy that moves infrastructure to the cloud at the hypervisor level (e.g., VMware Cloud on AWS) without changing the underlying architecture or purchasing new hardware.
- Distinct from Rehost because no new EC2 instances are provisioned
- Preserves existing VMware tools and skills
- Fastest option for large-scale VMware environments
Memory trick: Relocate = 'Relocate the whole virtualization layer, unchanged.'
CAF Operations Perspective
Flip cardAn AWS CAF perspective focused on ensuring cloud workloads are effectively deployed, operated, monitored, and recovered to support business requirements.
- Includes SRE practices
- Covers incident and problem management
- Emphasizes observability and resilience
Memory trick: Operations = keeping the lights on and the system healthy.
Retain (7 Rs)
Flip cardA migration strategy where an application is kept in its current environment without migrating, often due to dependencies, compliance, or low priority.
- Also called 'revisit'
- Common for legacy or recently upgraded systems
- No migration effort spent now, but may be reconsidered later
Memory trick: Retain = 'Remain' where it is for now.
Increased Speed and Agility
Flip cardA cloud benefit where new IT resources can be provisioned in minutes, allowing organizations to experiment quickly and lower the cost of failure.
- Enables rapid innovation cycles
- Reduces the cost and risk of experimentation
- Resources can be terminated quickly if not needed
Memory trick: Agility = try fast, fail cheap, learn quick.
Stop Spending Money on Data Centers
Flip cardA cloud benefit where organizations no longer need to manage physical data center tasks like power, cooling, and racking, allowing focus on projects that differentiate the business.
- AWS handles the undifferentiated heavy lifting
- Frees IT staff for higher-value work
- One of the six core cloud benefits
Memory trick: Stop babysitting servers, start building features.
Savings Plans Discount Calculation
Flip cardSavings Plans offer lower hourly rates than On-Demand pricing in exchange for a commitment to consistent usage, and savings are calculated as the difference between On-Demand and discounted totals.
- Savings Plans provide flexible discounts across instance families/regions
- Savings = (On-Demand rate − Savings Plan rate) × hours used
- Require usage commitment (1 or 3 years)
Memory trick: Commit to usage, AWS commits to a discount.
AWS Migration Process: Mobilize Phase
Flip cardThe second phase of the AWS migration process, following Assess, focused on building an operational foundation for migration, including detailed planning, business case development, and identifying organizational readiness.
- Involves deep assessment of the current environment.
- Identifies migration blockers and dependencies.
- Develops a comprehensive business case for cloud adoption.
- Prepares the organization and technical environment for migration.
Memory trick: Assess, Mobilize, Migrate, Modernize: The cloud journey.
AWS Savings Plans
Flip cardA flexible pricing model that offers lower prices compared to On-Demand, in exchange for a commitment to a consistent amount of compute usage (measured in $/hour) for a 1-year or 3-year term.
- Commit to consistent usage for discounts.
- Applicable to EC2, Fargate, and Lambda.
- Reduces costs and provides predictability.
Memory trick: Save predictably with plans, not just explore or budget.
Elasticity
Flip cardThe ability of a system to automatically scale computing resources up or down to match demand, providing the right amount of resources at the right time.
- Automatic scaling.
- Responds to demand fluctuations.
- Optimizes cost and performance.
Memory trick: Elasticity stretches and shrinks with demand, like a rubber band.
Global Reach
Flip cardThe ability to deploy applications and data across multiple AWS Regions and Availability Zones worldwide, enabling low-latency access and compliance with data residency requirements.
- AWS has a vast global infrastructure.
- Allows deployment close to end-users for reduced latency.
- Facilitates meeting data residency and compliance needs.
Memory trick: Global cloud, local speed, secure data.
Stop Guessing Capacity
Flip cardA key benefit of cloud computing where organizations no longer need to predict and over-provision resources for peak demand, but can instead dynamically scale capacity up or down as needed.
- Eliminates wasted resources from over-provisioning.
- Ensures sufficient capacity during peak demand.
- Achieved through services like Auto Scaling.
Memory trick: No more capacity guesses, just perfect fit.
Reduced Operational Overhead
Flip cardCloud computing reduces the amount of effort required to manage physical infrastructure and underlying systems, shifting that responsibility to the cloud provider.
- AWS handles hardware provisioning, patching, and maintenance.
- Frees up customer resources for application development and innovation.
- Directly addresses concerns about managing complex infrastructure.
Memory trick: Cloud's core benefit: less work, more focus.
Rapid Elasticity
Flip cardA cloud characteristic allowing computing capabilities to be provisioned and released rapidly, often automatically, to scale commensurate with demand.
- Automatic scaling.
- Quick resource allocation/deallocation.
- Adapts to fluctuating demand.
Memory trick: On-demand Broad Rapid Measured Resource Pooling.
Amazon ECS with AWS Fargate
Flip cardA combination of services that allows you to run containerized applications without provisioning or managing the underlying infrastructure (servers).
- ECS: Container orchestration service
- Fargate: Serverless compute engine for containers
- No EC2 instance management required
- Ideal for microservices and containerized applications
Memory trick: ECS and Fargate, a serverless pair, containers run, no servers to bear.
Amazon Virtual Private Cloud (VPC)
Flip cardA logically isolated section of the AWS Cloud where you can launch AWS resources in a virtual network that you define, with full control over network configuration.
- Enables private IP communication between instances.
- Uses Security Groups for stateful instance-level firewalls.
- Allows creation of subnets, route tables, and internet gateways.
Memory trick: VPC: Your Private Cloud network.
AWS Direct Connect
Flip cardA cloud service solution that links your internal network to AWS Direct Connect locations, bypassing the public internet.
- Establishes a dedicated network connection.
- Reduces network costs, increases bandwidth throughput, and provides a more consistent network experience.
- Supports all AWS services accessible over the public internet.
Memory trick: Direct Connect is the 'private highway' to AWS.
Amazon DynamoDB Global Tables
Flip cardA fully managed, multi-Region, multi-master database solution that provides fast, local read and write performance for globally distributed applications.
- Automatically replicates data across chosen AWS Regions.
- Provides low-latency access for users in different geographic locations.
- Supports multi-master writes, allowing updates in any replica Region.
Memory trick: Global Tables: Globally replicate, low latency, always available.
Amazon Kinesis Data Streams
Flip cardA real-time data streaming service capable of continuously capturing and storing gigabytes of data per second from hundreds of thousands of sources, ensuring durability and order within shards.
- Scales to millions of messages per second.
- Guarantees order of records within a shard.
- Data is available for processing within milliseconds.
Memory trick: Kinesis: Keep streams moving, ordered, and fast.
Amazon ECS with Fargate
Flip cardA serverless compute engine for Amazon ECS that allows you to run containers without having to provision, configure, or scale clusters of virtual machines.
- No servers to manage.
- Pay only for the resources consumed by your containers.
- Seamlessly integrates with ECS for container orchestration.
Memory trick: ECS Fargate: Effortless Container Service, Fulfills all serverless dreams.
Amazon CloudWatch Logs
Flip cardA service that enables you to centralize logs from all of your systems, applications, and AWS services, allowing for monitoring, storage, and access of log files.
- Centralized log collection and storage
- Real-time log monitoring
- Search and filter log data
- Create alarms based on log patterns
Memory trick: CloudWatch Logs: collect, search, alarm's call, insights from logs, for one and all.
Amazon DynamoDB
Flip cardA fully managed, serverless NoSQL database service that delivers single-digit millisecond performance at any scale, designed for high-performance applications.
- Supports key-value and document data models.
- Offers on-demand or provisioned capacity modes.
- Integrated with other AWS services like Lambda and API Gateway.
Memory trick: Dyna-mo: Dynamic, NoSQL, Millisecond response.
VPC Endpoints
Flip cardA feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Keeps traffic entirely within the AWS network.
- Enhances security by eliminating exposure to the public internet.
- Two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints (for S3 and DynamoDB).
Memory trick: Endpoint: End the public path, point to private.
VPC Endpoint
Flip cardA feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Private connection to AWS services (e.g., S3, DynamoDB)
- Traffic stays within the Amazon network
- Enhances security by avoiding the public internet
- Two types: Interface Endpoints and Gateway Endpoints
Memory trick: VPC Endpoint, a private gate, connects services, seals your fate (securely).
Amazon SQS Standard
Flip cardA fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications.
- Offers high throughput, best-effort ordering, and at-least-once delivery.
- Used for asynchronous communication between application components.
- Eliminates the need to manage message queue infrastructure.
Memory trick: SQS Standard is the 'standard' choice for reliable, decoupled messaging.
Amazon SQS Standard Queue
Flip cardA highly scalable, fully managed message queuing service that offers at-least-once message delivery and does not guarantee the order of messages.
- Fully managed message queue
- Decouples microservices
- At-least-once delivery
- No strict message ordering (high throughput)
Memory trick: SQS Standard: Messages flow free, order's not key, but delivered, you see.
Amazon CloudFront for Video Streaming
Flip cardA global content delivery network (CDN) that accelerates the delivery of video content to millions of concurrent viewers with low latency and high transfer speeds.
- Global content delivery network (CDN)
- Optimized for video streaming
- Low latency and high transfer speeds
- Automatically scales for massive traffic spikes
Memory trick: CloudFront's edge, video's delight, millions stream, day and night.