certslothcertsloth
← CLF-C02 overview

Cloud Practitioner / STUDY TOOLS

CLF-C02 quick review

Reviewed 10 October 2026 · Cloud Practitioner

Memory hook: Value, responsibility, service fit, then the whole bill.

Cloud concepts 24%; security and compliance 30%; technology and services 34%; billing, pricing and support 12%.

Use this as a final revision pass after the chapters. Each task below maps to the published exam outline; the outline itself is not an exhaustive list of possible questions. Recheck the official guide for your booked exam version, especially beta releases.

Must remember by exam objective

1.1 — Cloud value and elasticity

  • Cloud value comes from agility, elastic capacity, global reach and variable spending. Scalability adds capacity; elasticity also removes it. High availability keeps service usable; durability protects stored data.

1.2 — Architecture principles

  • The six Well-Architected pillars are operational excellence, security, reliability, performance efficiency, cost optimization and sustainability. Design for failure, automate, measure and improve; no pillar overrides mandatory business constraints.

1.3 — Migration and adoption

  • Cloud Adoption Framework perspectives are business, people, governance, platform, security and operations. Migration choices: retain, retire, rehost, relocate, repurchase, replatform and refactor; people/process readiness matters alongside servers.

1.4 — Cloud economics

  • Compare total ownership cost, including facilities, staffing, licenses and idle capacity. Cloud trades upfront capital for variable use; economies of scale and rightsizing can help, but unmanaged usage still wastes money.

2.1 — Shared responsibility

  • AWS protects facilities, hardware and managed infrastructure. Customers protect identities, data and configurations. EC2 customers patch guest operating systems; managed databases and Lambda shift more platform work to AWS without removing application responsibilities.

2.2 — Security, governance and compliance

  • Encryption at rest and TLS in transit solve different risks. Artifact supplies AWS compliance evidence; it does not certify your application. Organizations groups accounts; SCPs restrict permissions; Control Tower establishes governed landing zones.

2.3 — Identity and access

  • Authentication proves identity; authorization permits actions. Roles provide temporary credentials, groups collect user permissions, MFA adds a factor, and explicit deny overrides applicable allows. Use federation/Identity Center for workforce access and protect root credentials.

2.4 — Security tools and resources

  • CloudTrail audits API activity; CloudWatch observes workloads; Config tracks/evaluates configurations. GuardDuty detects threats, Inspector assesses vulnerabilities, Macie discovers sensitive S3 data, and Security Hub consolidates findings. WAF filters web requests; Shield addresses DDoS.

3.1 — Provisioning and operations

  • Console, CLI, SDKs and CloudShell use authorized service APIs. CloudFormation declares infrastructure, Systems Manager operates managed nodes, CodeBuild runs builds and CodePipeline coordinates delivery. Automation still needs scoped roles and error handling.

3.2 — Global infrastructure

  • A Region is a geographic area; an AZ is an isolated regional failure domain; an edge location serves eligible traffic near users. Select Regions for residency, latency, service availability and price. Multiple AZs do not protect from every regional failure.

3.3 — Compute choices

  • EC2 provides OS control, ECS orchestrates containers, EKS supplies managed Kubernetes, Fargate supplies container compute, and Lambda runs bounded event-driven functions. Auto Scaling supplies capacity; load balancers distribute traffic. Beanstalk manages supported application deployments; Lightsail offers simplified bundles.

3.4 — Database choices

  • RDS/Aurora serve relational workloads; DynamoDB serves modeled key/document access; ElastiCache accelerates repeated access; Redshift serves warehouse analytics; Neptune stores graph relationships. Read replicas scale reads; Multi-AZ provides deployment-specific availability behavior.

3.5 — Networking choices

  • VPCs are regional and subnets are AZ scoped. Security groups are stateful allow rules; NACLs are stateless allow/deny rules. Route 53 resolves DNS, CloudFront caches web content, VPN encrypts hybrid tunnels and Direct Connect supplies dedicated connectivity.

3.6 — Storage choices

  • S3 is object storage, EBS persistent block storage, EFS shared NFS, instance store temporary local storage, and FSx a specialized filesystem family. Backups preserve historical recovery; replication alone can copy corruption. Archival choices depend on retrieval delay and billing minimums.

3.7 — AI and analytics

  • Athena queries supported data with SQL; Glue catalogs/transforms; EMR runs big-data frameworks; Kinesis carries streams; Firehose delivers buffered records; Quick Sight visualizes data. Bedrock supports foundation-model applications; SageMaker AI develops and operates ML models.

3.8 — Other service categories

  • SQS queues work, SNS fans out notifications, EventBridge routes events and Step Functions orchestrates workflows. SES sends email; Connect supports contact centers; IoT Core connects devices; WorkSpaces serves desktops; Amplify supports frontend/mobile delivery. Recognize capabilities rather than treating similar names as synonyms.

4.1 — Pricing models

  • On-Demand avoids a long commitment; Savings Plans commit eligible spend; Reserved Instances have offering-specific discount/capacity rules; Spot can be interrupted. Dedicated Hosts expose a physical host allocation. Capacity Reservations reserve matching capacity and are not automatically a discount.

4.2 — Billing and cost controls

  • Pricing Calculator estimates future designs; Cost Explorer analyzes spending; Budgets alerts against plans; Cost Anomaly Detection identifies unusual use; Data Exports provide detailed records. Activate cost-allocation tags and use consolidated billing deliberately. Alerts can lag and are not universal spending caps.

4.3 — Support and technical resources

  • Distinguish self-service documentation/re:Post, account/service events in AWS Health, recommendations in Trusted Advisor, AWS Partners and Professional Services. Current support-plan names and entitlements change; compare Basic, Business Support+, Enterprise and Unified Operations in the current matrix rather than memorizing an old pricing slide.

Choose under exam pressure

Deciding clue Recall the distinction
Need to know who deleted a resource CloudTrail; application error rates instead point to CloudWatch.
Estimate next month before deploying Pricing Calculator; historical spend belongs in Cost Explorer.
Existing Windows SMB shares with AD FSx for Windows; EFS supplies NFS.
Reduce guest OS administration Choose an appropriate managed service; data/access remain customer responsibilities.
Repeatable infrastructure across environments CloudFormation/IaC, with environment-specific parameters and reviewed permissions.

Traps

  • A Region is not an AZ; an AZ is not necessarily one building.
  • A budget, tag or SCP does not automatically grant access or stop all spending.
  • Serverless does not mean limitless or free; stopped compute can retain billed storage.

Verification cues

  • Explain the service choice for one compute, storage, database, networking and integration scenario without looking at the list.
  • Read the current AWS Support comparison before the exam; plan names and entitlements are version-sensitive.

Last-pass active recall

1. Who patches the guest operating system on EC2?

The customer; AWS manages underlying infrastructure.

2. What separates scaling from elasticity?

Scaling changes capacity; elasticity adapts it up and down to demand.

3. A backup exists but recovery was never tested. Is recovery assured?

No. Test restoration, key access, permissions and useful application behavior.

4. Which service discovers personal data in S3?

Macie; GuardDuty focuses on threat detection.

5. Does consolidated billing let one account read another account’s data?

No. Billing relationships are separate from authorization.

Sources and version check

The numbered chapters provide worked distinctions and further technical sources. These are original revision notes and original recall scenarios, not real exam questions.

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Cloud Concepts and Global Infrastructure

Memory hook: Elasticity follows demand; availability survives a failure; agility shortens the time to try an idea.

Must remember

  • Cloud computing supplies technology on demand with usage-based charging. Replace large upfront capacity purchases with variable spending; economies of scale can reduce unit cost. Neither eliminates waste automatically.
  • Scalability handles growth by increasing capacity. Vertical scaling enlarges a machine; horizontal scaling adds machines. Elasticity adds and removes capacity as demand changes. A load balancer distributes requests; it does not create capacity.
  • A Region is a geographic deployment area. An Availability Zone is an isolated failure domain containing one or more data centres. Multiple AZs support regional availability; multiple Regions address regional disasters or geographic requirements. An edge location brings eligible content or traffic processing closer to users.
  • Choose a Region using residency requirements, latency, feature availability and price. A nearby Region without the required service is not automatically suitable. Global services still have data and resource-location rules.
  • IaaS gives more infrastructure control, PaaS removes more platform management, SaaS delivers a finished application. Public cloud, private/on-premises and hybrid describe deployment arrangements, not permission levels on an S3 bucket.
  • Memorise the six Well-Architected pillars through questions: can we operate it well; protect it; recover it; perform efficiently; avoid waste; and reduce environmental impact? These are operational excellence, security, reliability, performance efficiency, cost optimisation and sustainability.
  • Design for failure, automate repeatable work, measure before changing capacity and use managed services when the required control permits. High durability protects stored data; high availability keeps a service usable.

Choose under exam pressure

Requirement Choice and reason
Survive loss of a data centre Deploy useful capacity across AZs.
Worldwide static content CloudFront edge caching.
Rapid experiments without buying servers Cloud agility and variable spending.

Traps

  • An AZ is not a synonym for a single building.
  • Multi-AZ does not itself protect against loss of the entire Region.
  • Pay as you go is a billing model, not a promise that every resource stops charging when unused.

Practise this topic

02 · IAM and Shared Responsibility

Memory hook: AWS secures the underlying cloud; you still control your identities, data and chosen configuration.

Must remember

  • On EC2, AWS manages facilities, hardware and virtualisation; the customer patches the guest OS and manages application security. With RDS, AWS manages more database infrastructure and maintenance; customers still manage data, access and application use. With Lambda, AWS manages the underlying servers; customers own function code, dependency choices and permissions.
  • Authentication establishes identity; authorisation decides permitted actions. An IAM policy states an effect, actions, resources and optional conditions. Explicit deny wins over an applicable allow. Default absence of permission means denial.
  • Users are identities; groups organise permissions for users; roles provide temporary credentials when assumed. Roles have a trust policy controlling who may assume them and permissions controlling what they may do. A group is not a runtime service identity.
  • Prefer workforce federation through IAM Identity Center and temporary roles for workloads. MFA adds another factor. A console password and programmatic access keys are different credentials; a password change does not rotate access keys.
  • Protect the root user, avoid routine root use and do not create root access keys. Some account operations remain root-only or require specific centralised root capabilities; consult the current task list rather than granting root to every administrator.
  • Apply least privilege, review unused access and remove unnecessary credentials. A credentials report summarises IAM-user credential status; access analysis helps discover risky or unused permissions.
  • Secrets Manager stores secrets with rotation integration. Systems Manager Parameter Store stores configuration and SecureString values. Never embed long-lived keys in code, AMIs or public repositories.

Choose under exam pressure

Requirement Choice and reason
Application on EC2 needs S3 access Instance role with scoped permissions.
Employees already use a corporate identity provider Federation and IAM Identity Center.
Database credentials need managed rotation Secrets Manager with supported rotation configuration.

Traps

  • MFA does not expand permissions.
  • An administrator policy is not the same identity as the root user.
  • Managed services reduce operational work but do not decide which customers should access your data.

Practise this topic

03 · Security, Monitoring and Governance

Memory hook: CloudWatch observes, CloudTrail records API activity, Config evaluates configuration.

Must remember

  • CloudWatch handles operational metrics, logs, dashboards and alarms. CloudTrail records account/API activity for audit. AWS Config records resource configurations and evaluates rules; it is not a replacement for application logs.
  • GuardDuty detects suspicious activity from supported telemetry. Inspector finds software vulnerabilities and unintended exposure in supported workloads. Macie discovers sensitive data in S3. Security Hub aggregates and prioritises security findings and posture checks.
  • WAF filters application-layer web requests. Shield addresses DDoS protection; Standard and the paid Advanced offering differ. Firewall Manager centrally applies supported security policies across an organisation.
  • KMS manages encryption keys. Encryption at rest protects stored data; TLS protects data in transit. Key access, application access and network access all need appropriate controls. ACM manages supported TLS certificates; it does not encrypt a database's stored files.
  • AWS Artifact provides AWS compliance reports and agreements. AWS service certification does not certify every workload a customer builds. Evidence, customer controls and data residency still matter.
  • Organizations groups accounts and offers consolidated billing and service control policies. SCPs restrict the maximum permissions available to affected accounts; they grant no permissions. Control Tower helps establish and govern a landing zone with controls.
  • Trusted Advisor recommends improvements in areas such as cost, security and resilience. AWS Health reports events affecting AWS services or specific account resources. Security documentation, the Security Blog and re:Post support investigation; Marketplace offers third-party tools whose licensing and configuration still need review.

Choose under exam pressure

Requirement Choice and reason
Who changed a resource? CloudTrail event history or a configured trail.
Which buckets contain personal data? Macie discovery.
Keep account configurations within policy Config rules and organisation governance controls.

Traps

  • GuardDuty findings do not automatically patch software.
  • Artifact is evidence about AWS, not an application vulnerability scanner.
  • An alarm can notify without preventing spending or damage.

Practise this topic

04 · EC2, Containers and Serverless Compute

Memory hook: Choose who manages the server, then choose how the capacity is paid for.

Must remember

  • EC2 provides virtual machines and OS-level control. General-purpose, compute-optimised, memory-optimised, storage-optimised and accelerated families fit different bottlenecks. More CPU cannot repair a storage bottleneck automatically.
  • An AMI is a launch image; user data bootstraps an instance. Auto Scaling adjusts or maintains fleet capacity, while Elastic Load Balancing sends traffic to healthy targets. Multi-AZ capacity and externalised session data help make instances replaceable.
  • ECS is AWS container orchestration; EKS provides managed Kubernetes. Fargate supplies serverless compute for supported container tasks/pods. A container image is packaged application content, not an orchestration service.
  • Lambda runs functions on events with managed infrastructure and execution limits. It suits bounded processing; persistent state belongs in an appropriate external service. Elastic Beanstalk deploys supported application platforms while provisioning resources that still appear in your account. Lightsail offers simpler bundled infrastructure.
  • On-Demand has no long-term usage commitment. Savings Plans exchange a spend commitment for eligible discounts. Reserved Instances apply reservation/discount rules to qualifying usage; regional and zonal EC2 reservations differ in flexibility and capacity benefit.
  • Spot uses spare capacity that can be interrupted: favour resumable, flexible work. Dedicated Instances isolate tenancy from other customers; Dedicated Hosts expose a physical host allocation for host-level licensing or compliance requirements. Capacity Reservations reserve matching capacity and are not inherently a discount.
  • Match architecture before price. A cheap interrupted instance can be an expensive choice for a non-resumable critical task. Stopping EC2 compute does not remove attached EBS, snapshots or other retained billable resources.

Choose under exam pressure

Requirement Choice and reason
Run an existing Kubernetes workload EKS; select nodes or supported Fargate execution.
Interruptible batch processing Spot with retry/checkpoint design.
Need access to the guest OS EC2 rather than Lambda.

Traps

  • Fargate is compute, ECS/EKS are orchestrators.
  • A commitment discount is not the same as a guarantee of capacity.
  • Serverless means server management is abstracted, not that limits and charges disappear.

Practise this topic

05 · Storage and Databases

Memory hook: Object, block, file and database access patterns are different interfaces.

Must remember

  • S3 stores objects identified by bucket and key. Standard supports frequent access; Intelligent-Tiering adapts eligible data to access patterns; infrequent-access and Glacier classes trade lower storage cost against retrieval, minimum-duration and access-time constraints. Lifecycle rules automate transitions and expiration.
  • EBS is persistent block storage scoped to an AZ. Snapshots support backup and volume restoration. Instance store is local temporary storage whose data can be lost with the instance lifecycle or failure; it is not a durable database backup.
  • EFS provides managed shared NFS file storage. FSx offers managed file systems for particular protocols and workloads, including Windows File Server, Lustre, ONTAP and OpenZFS. Storage Gateway connects on-premises applications to cloud-backed storage using supported interfaces and caching.
  • AWS Backup centralises supported resource backup policies and recovery points. Replication improves access or resilience; backups recover earlier states. Test restore procedures, not only the existence of a backup.
  • RDS manages relational database engines. Aurora is a cloud-designed relational database compatible with supported MySQL/PostgreSQL interfaces. A read replica scales reads; Multi-AZ supports availability. Their exact read/failover behaviour depends on the deployment type.
  • DynamoDB is managed key-value/document storage. ElastiCache provides in-memory caching. Redshift targets analytical warehousing. Neptune targets graph relationships; DocumentDB targets document workloads. Choose by query and consistency needs, not merely the word database.
  • Self-managed databases on EC2 give more control but more patching, backup and availability responsibility. DMS migrates/replicates data; schema-conversion tooling addresses differences between engines. Neither guarantees every application query works unchanged.

Choose under exam pressure

Requirement Choice and reason
Shared Linux file directory EFS.
Relational transactions with managed infrastructure RDS or Aurora.
Archive rarely needed records An appropriate S3 Glacier class after checking retrieval and retention requirements.

Traps

  • S3 is not a normal block device mounted as an EBS volume.
  • Lower storage price may come with retrieval fees and minimum duration.
  • A cache is not automatically the authoritative durable record.

Practise this topic

06 · VPC, DNS and Content Delivery

Memory hook: Routing finds a path; filtering permits it; DNS gives a name an answer.

Must remember

  • A VPC is a regional network; a subnet belongs to one AZ. Routes direct traffic. A public subnet has an appropriate route to an internet gateway; an instance also needs suitable addressing and security configuration for direct internet communication.
  • Security groups are stateful resource-level allow rules. Network ACLs are stateless subnet-level allow/deny rules; return traffic must be allowed explicitly. Neither fixes a missing network route.
  • A NAT gateway enables supported outbound connectivity from private subnets without accepting unsolicited inbound connections. NAT has processing/capacity costs. VPC endpoints provide supported private service access; gateway and interface endpoints have different services, mechanics and costs.
  • Route 53 provides DNS, domain-registration capabilities and routing/health-check features. A DNS answer can be cached according to TTL; it does not proxy every HTTP request. CloudFront is a content delivery network; Global Accelerator improves supported network routing through AWS edge entry points and static anycast addresses.
  • Site-to-Site VPN creates encrypted tunnels over network paths such as the internet. Direct Connect offers dedicated connectivity into AWS and does not inherently mean end-to-end encryption. Redundant connectivity must be designed explicitly.
  • VPC peering connects compatible networks directly; Transit Gateway provides hub connectivity. Network designs must consider address overlap and routing. A subnet called private is not proof that data is encrypted.
  • Compare latency, transfer volume, cross-AZ/Region movement and endpoint/NAT processing when estimating cost. A remote low-cost service can create unnecessary data-transfer charges.

Choose under exam pressure

Requirement Choice and reason
Deliver cacheable web assets worldwide CloudFront.
Encrypted connection over the internet Site-to-Site VPN.
Dedicated hybrid connectivity Direct Connect, with separate encryption and redundancy decisions.

Traps

  • A public IP alone does not supply a working route and permitted traffic.
  • A security group has no explicit deny rule.
  • A dedicated connection is not automatically encrypted.

Practise this topic

07 · Integration, Analytics and AI Services

Memory hook: Queue work, broadcast notifications, route events, retain streams, then analyse the data.

Must remember

  • SQS buffers messages for workers; standard queues require consumers that tolerate possible duplicates. SNS publishes to subscribers for fan-out. EventBridge routes events by rules and integrates event-driven applications. Step Functions coordinates workflow steps and state.
  • Kinesis Data Streams supports streaming records and replay within retention. Amazon Data Firehose delivers streaming data to supported destinations with managed buffering. A queue of jobs and a replayable stream have different consumption models.
  • Athena runs SQL over supported data sources, commonly S3. Glue provides cataloguing and data integration/ETL capabilities. EMR supports big-data frameworks. Redshift is analytical warehousing; Quick Sight is business intelligence/dashboarding. Store, catalogue, transform, query and visualise are distinct stages.
  • SageMaker AI supports building, training and deploying ML models. Bedrock provides managed foundation-model application capabilities. Use Rekognition for supported image/video analysis, Textract for document text and structure, Comprehend for language insights, Translate for translation, Transcribe for speech-to-text, Polly for text-to-speech and Lex for conversational interfaces.
  • Connect supports cloud contact centres; SES sends application email. IoT Core connects and manages messaging for devices. WorkSpaces provides virtual desktops; AppStream 2.0 provides application streaming; WorkSpaces Secure Browser provides managed browser access. Course names can lag product branding.
  • Amplify supports frontend/mobile application development and hosting workflows. CodeBuild runs builds and tests; CodePipeline coordinates delivery stages; X-Ray helps trace distributed requests. These are different parts of application delivery.
  • Prefer an appropriate managed task service over building a custom ML model when the requirement is already supported. AI output still requires evaluation, privacy controls and human review where the consequence demands it.

Choose under exam pressure

Requirement Choice and reason
One event must reach several independent consumers SNS fan-out or EventBridge routing, depending on filtering/integration needs.
Query S3 files using SQL Athena.
Turn a written announcement into speech Polly.

Traps

  • Transcribe and Polly point in opposite directions.
  • SNS fan-out does not replace a durable work queue for every subscriber.
  • Glue metadata does not itself store all of the source data.

Practise this topic

08 · Migration, Deployment and Cloud Adoption

Memory hook: A migration moves a workload; adoption also changes people, process and governance.

Must remember

  • The Cloud Adoption Framework groups concerns into business, people, governance, platform, security and operations perspectives. A technically successful migration can fail its business case if skills, accountability or cost ownership are missing.
  • Recognise the migration strategies: retire what is unnecessary; retain what stays; rehost with minimal change; relocate supported infrastructure; repurchase a replacement product; replatform with selected platform changes; refactor/re-architect for a new design. Pick the smallest justified change that meets the business requirement.
  • Application Migration Service supports server migration through replication. DMS moves database data, including supported ongoing replication. DataSync transfers file/object data between supported locations. Transfer Family exposes managed transfer protocols such as SFTP for supported storage.
  • Discover dependencies before choosing migration waves. Assess licensing, data residency, connectivity, downtime and rollback. The lowest migration effort is not always the lowest long-term operating cost.
  • The console is graphical; CLI and SDKs call service APIs programmatically. CloudShell offers a browser-based command environment using your authorised identity. These interfaces do not bypass IAM.
  • CloudFormation provisions declared infrastructure from templates. Infrastructure as code supports repeatable changes and review. Systems Manager supports administration such as session access, inventory, patching and automation. Elastic Beanstalk automates deployment of supported application platforms.
  • CodePipeline orchestrates delivery; CodeBuild builds/tests; CodeDeploy automates supported deployment targets. AWS Backup centrally organises backup policies. Recovery objectives and tests are part of the operating design, not a final checkbox.
  • Snow-family/offline-transfer references may appear in older course material. Check current customer eligibility rather than assuming an old service can still be ordered. No physical transfer job is required to revise this concept.

Choose under exam pressure

Requirement Choice and reason
Move servers with little redesign Rehost using an appropriate migration mechanism.
Replace a legacy CRM with SaaS Repurchase.
Recreate the same infrastructure in several environments Infrastructure as code.

Traps

  • Copying database rows does not convert every stored procedure.
  • A console operation and a CLI operation need equivalent authorisation.
  • A completed migration is not proof of a tested rollback or recovery procedure.

Practise this topic

09 · Billing, Pricing and Support

Memory hook: Estimate before use, analyse after use, alert during use; none is an automatic spending cap.

Must remember

  • Pricing Calculator estimates a proposed workload. Cost Explorer analyses spending and usage. Budgets alerts against configured thresholds and supports explicitly configured actions. Cost Anomaly Detection highlights unusual spending. Billing data can lag; alerts are not an instant hard limit.
  • Cost and Usage Reports/Data Exports provide detailed billing records. Activate appropriate cost-allocation tags and build ownership conventions. Merely attaching a tag does not automatically make historical spend perfectly attributable.
  • Organizations consolidated billing combines eligible usage and supports sharing of applicable discounts under the organisation's settings. Separate accounts preserve administrative boundaries; a consolidated bill is not shared IAM permission.
  • Compare fixed on-premises spending with variable cloud charges using total cost: power, facilities, maintenance, staff, licences, networking and idle capacity. Rightsizing uses evidence to reduce excess resources; automation can reduce operational effort and forgotten-resource waste. BYOL requires compatible licence terms, not just technical installation.
  • EC2 commitments, Spot and On-Demand serve different workload profiles. Storage prices can include request, retrieval and minimum-duration charges. Data transfer may cost money across AZs/Regions or to the internet. Public IPv4 and retained storage can bill independently of application traffic. Check the service's actual price dimensions.
  • Current CLF guidance names Basic Support, Business Support+, Enterprise Support and Unified Operations. Compare technical access, response objectives and proactive assistance using the current plan matrix; old Developer/Business/Enterprise On-Ramp tables may be outdated. Do not memorise old prices or response times from an unversioned slide.
  • AWS Health reports service/account events; Trusted Advisor recommends improvements. re:Post, documentation, whitepapers and Prescriptive Guidance support self-service learning. The Trust and Safety team handles reports of AWS-resource abuse. Professional Services, solutions architects and AWS Partners provide different kinds of technical assistance; Marketplace offers third-party software procurement and entitlement management.

Choose under exam pressure

Requirement Choice and reason
Estimate a design that does not exist yet Pricing Calculator.
Investigate last month's largest service cost Cost Explorer, then detailed exports if needed.
Get notified about unusual spend Cost Anomaly Detection; add budgets for planned thresholds.

Traps

  • A budget alert is not guaranteed to stop every resource.
  • Savings on compute can be outweighed by storage, licences and transfer.
  • Consolidated billing is not an access grant between accounts.

Practise this topic

Search across every published topic.