Study guide · Core notes

AWS Cloud Practitioner Notes: services and the boundary

Reference notes for CLF-C02: what the cloud changes, who is responsible, which service matches a need, and how the bill and the support plan work.

Exam guide: CLF-C0212 modulesReviewed October 2026

How to read these notes: Items tagged Extra are outside the CLF-C02 in-scope list, such as Amazon MSK. Learn the unmarked items first. New to the exam? Start with the overview for the format and domain weights. Vendor-neutral cloud models are in the networking and cloud notes.

Module 1: Benefits and cloud economics

AWS describes the cloud as a way to trade capital expense for variable expense, benefit from economies of scale, stop guessing capacity, increase speed and agility, stop running your own data centers, and go global quickly. Those six ideas are the value proposition behind Domain 1.

Elasticity

Capacity grows and shrinks with demand, often automatically. A larger server that you buy once is scalability you paid for in advance. Elasticity gives the capacity back when the spike ends.

High availability and agility

High availability keeps a workload running through a failure, usually by using more than one Availability Zone. Agility is how fast you can try an idea and stop it if it fails.

Fixed cost and variable cost

A data center is mostly fixed: buildings, hardware, and staff, whether the servers are busy or idle. Cloud spend moves with what you run. Rightsizing means choosing a smaller resource when the current one is larger than the workload needs.

Licenses

Bring Your Own License lets you apply licenses you already own, often on a Dedicated Host. An included license is part of the service price. The exam asks you to tell those two approaches apart, not to price a contract.

Module 2: Well-Architected design and migration

The framework is a design vocabulary. The migration strategies say how an application moves.

The six pillars named in the CLF-C02 exam guide. Sustainability is a pillar, not a billing tool.
PillarQuestion it answers
Operational excellenceCan you run, observe, and improve the workload?
SecurityAre identities, data, and infrastructure protected?
ReliabilityDoes it recover, and can it meet demand?
Performance efficiencyAre you using the right resource type for the job?
Cost optimizationAre you paying only for what you need?
SustainabilityAre you reducing the energy and resources the workload uses?
Common migration strategies. Relocate is marked Extra because the exam guide's example is database replication, not a hypervisor move.
StrategyWhat changesPicture
RehostLittle or nothingMove a virtual machine onto Amazon EC2
ReplatformA few cloud optimizationsMove a database onto Amazon RDS
RefactorThe architectureRebuild around AWS Lambda or containers
RepurchaseThe productReplace a self-hosted app with a SaaS product
RetireThe application goes awayTurn off something nobody uses
RetainNothing moves yetKeep it on premises for now
Extra RelocateThe hypervisor, not the guestA VMware-level move. Useful context, not required by the task example in the guide.

The exam guide points at AWS Cloud Adoption Framework outcomes such as reduced business risk, improved environmental, social, and governance performance, increased revenue, and increased operational efficiency. AWS Database Migration Service is the in-scope example of database replication during a move.

Module 3: Global infrastructure

A Region is a separate geographic area. Each Region has multiple Availability Zones. An Availability Zone is one or more discrete data centers with independent power, cooling, and networking. Zones in a Region are isolated from each other so that a failure in one does not take the others down. You get high availability by running in more than one zone, not by hoping one building stays up.

An edge location is a site used by Amazon CloudFront, and by parts of Amazon Route 53 and AWS Global Accelerator, to serve users from a place closer to them. An edge location is not an Availability Zone. You do not launch an EC2 fleet "in an edge location" as a high-availability design.

Use more than one Region when you need disaster recovery, lower latency for distant users, or data to stay in a specific geography. Use more than one Availability Zone when you need the application to survive a zone failure inside the Region you already chose.

You reach services through the AWS Management Console, the AWS CLI, software development kits, or APIs. Infrastructure as code, such as AWS CloudFormation, repeats a setup instead of clicking it once. Choose a repeatable process when you will build the same environment again.

Module 4: Shared responsibility

AWS is responsible for security of the cloud. You are responsible for security in the cloud. The line moves with the service.

How responsibility shifts. The exam guide names Amazon EC2, Amazon RDS, and AWS Lambda as the examples.
ServiceAWS operatesYou still handle
Amazon EC2Facilities, hardware, the hypervisor, and the host networkGuest operating system patches, the application, security groups, and data
Amazon RDSThe database engine and the host underneath itData, access, and the database settings you are allowed to change
AWS LambdaThe runtime and the servers it runs onYour code, the function's permissions, and the data the function touches

Customers always own their data and their identity configuration. Encryption in transit protects data on the path, typically with TLS. Encryption at rest protects stored copies, typically with keys from AWS Key Management Service. Turning a disk off is not encryption.

Module 5: Access management

The root user is the identity that created the account. Use it only for the few tasks that require it, such as closing the account or changing account-level settings. Enable multi-factor authentication on root, and do not create long-lived access keys for it. Day-to-day work belongs to IAM users, or to workforce users in AWS IAM Identity Center.

Users, groups, and roles

An IAM user is an identity in one account. A group is a set of users that share policies. A role is an identity that a person or a service assumes, and it issues temporary credentials. Prefer a role for an EC2 instance over an access key stored on the disk.

Policies and least privilege

A policy is the document that allows or denies actions. Managed policies are ready-made. Custom policies are ones you write. Least privilege means the policy allows only what that identity needs.

Workforce and application users

IAM Identity Center is the workforce single sign-on path across accounts, including federated identities. Amazon Cognito is for the end users of an application you build. They are not substitutes for each other.

Secrets

AWS Secrets Manager stores and can rotate credentials. AWS Systems Manager can also hold parameters. Neither one replaces a role when the caller is an AWS service.

Module 6: Security, governance, and compliance

Match the symptom to the service. Several of these services also appear under management and governance in the exam guide.

In-scope security and governance services for CLF-C02.
ServiceUse it when you need
AWS ArtifactCompliance reports, such as SOC and PCI documents, that you download
AWS CloudTrailA record of API calls: who did what, and from where
AWS ConfigThe configuration history of resources, and whether they still match a rule
Amazon CloudWatchMetrics, logs, and alarms about how a resource is behaving
Amazon GuardDutyDetection of suspicious activity, such as unusual API use or compromised instances
Amazon InspectorVulnerability findings for workloads such as EC2, containers, and Lambda
AWS Security HubOne place that collects security findings from other services
AWS ShieldProtection against distributed denial of service
AWS WAFFilters on web requests, such as common injection patterns
Amazon MacieDiscovery of sensitive data sitting in Amazon S3
AWS KMSCreation and control of encryption keys
AWS Certificate ManagerTLS certificates for AWS services
AWS Trusted AdvisorChecks against AWS best practices, including cost and security

Third-party security products can be bought from AWS Marketplace. The AWS Knowledge Center, AWS Security Blog, and AWS re:Post are places to read, not services that block traffic. Report abuse of AWS resources to the AWS Trust and Safety team.

Module 7: Compute

Amazon EC2 is a virtual server. Instance families point at the bottleneck: general purpose balances resources, compute optimized favors CPU, memory optimized favors RAM, and storage optimized favors local disk throughput. AWS Auto Scaling adds and removes capacity. A load balancer spreads traffic so one instance is not the only door.

AWS Lambda

Runs your code when an event arrives. You do not provision the server. It is the usual answer for a short task that should scale without an instance to patch.

Containers

Amazon ECS orchestrates containers on AWS. Amazon EKS runs Kubernetes. AWS Fargate runs those containers without you managing the underlying servers. Amazon ECR stores the images.

Simpler platforms

AWS Elastic Beanstalk deploys an application and handles capacity, load balancing, and scaling. Amazon Lightsail is a simpler virtual private server with a predictable price. AWS Batch runs batch jobs.

Hybrid

AWS Outposts places AWS infrastructure in your own data center. It is the in-scope answer when the workload must stay on premises and still use AWS services.

Module 8: Storage

Start with the access pattern: object, block, or file. Then pick a class or a durability tradeoff.

Storage services in scope for CLF-C02. Amazon FSx for Lustre is out of scope; Amazon FSx itself is in scope.
ServiceTypeChoose it when
Amazon S3ObjectYou store blobs and fetch them with an API. Lifecycle policies move objects to cheaper classes.
S3 StandardObject classData is read often.
S3 Intelligent-TieringObject classAccess patterns change or are unknown.
S3 Standard-IA and One Zone-IAObject classAccess is infrequent but must still be fast. One Zone-IA keeps the data in a single Availability Zone.
S3 Glacier classesObject classArchive. Instant Retrieval is milliseconds. Flexible Retrieval is minutes to hours. Deep Archive is the lowest-cost, longest-retrieval option.
Amazon EBSBlockA persistent volume for one EC2 instance.
Instance storeBlockTemporary disk on the host. Data is gone when the instance stops.
Amazon EFSFileA shared file system that many Linux instances mount.
Amazon FSxFileManaged file systems, including Windows file servers.
AWS Storage GatewayHybridOn-premises applications need a cache or a path into cloud storage.
AWS BackupBackupCentral backup policies across AWS services.

Module 9: Databases

Ask whether the data is relational, a key-value or document store, a graph, or a cache. Then ask whether you want to operate the engine.

In-scope database and migration services. A database you install yourself on EC2 is still your engine to patch.
ServiceKindRemember
Amazon RDSRelational, managedMySQL, PostgreSQL, MariaDB, Oracle, and SQL Server engines. AWS patches the engine.
Amazon AuroraRelational, managedMySQL-compatible and PostgreSQL-compatible, built for higher throughput.
Amazon DynamoDBNoSQLKey-value and document data, serverless, single-digit millisecond access.
Amazon ElastiCacheIn memoryA cache in front of a slower database. It is not the system of record.
Amazon DocumentDBDocumentA managed document database.
Amazon NeptuneGraphRelationships, not rows.
Amazon RedshiftWarehouseAnalytics over large structured data. It is listed with analytics services.
AWS DMS and AWS SCTMigrationDMS moves data. The Schema Conversion Tool helps convert a schema to a different engine.

Module 10: Networking

A VPC is your private network. The pieces below are the ones the exam guide names.

Subnets and gateways

A subnet is a slice of the VPC in one Availability Zone. An internet gateway lets public subnets reach the internet. A NAT gateway lets private instances start outbound connections without accepting inbound ones from the internet.

Security groups and network ACLs

A security group is a stateful virtual firewall on a resource. It has allow rules. A network ACL is stateless, sits on the subnet, and can allow or deny. Because it is stateless, return traffic needs its own rule.

Names and delivery

Amazon Route 53 is DNS. Amazon CloudFront is the content delivery network at edge locations. AWS Global Accelerator gives you static anycast addresses that route users onto the AWS network.

Private and dedicated links

AWS Site-to-Site VPN and AWS Client VPN encrypt a path over the internet. AWS Direct Connect is a dedicated connection that does not depend on the public internet. AWS PrivateLink reaches services without exposing them to the internet. AWS Transit Gateway is a hub that connects many VPCs and on-premises networks.

Amazon API Gateway fronts APIs. Extra: AWS Network Firewall and Amazon VPC Lattice are on the exam guide's out-of-scope list.

Module 11: Integration, analytics, and other in-scope services

These are identification questions: name the service that does the job.

Other in-scope categories from the CLF-C02 exam guide.
JobService
Hold a message until a worker takes itAmazon SQS
Notify many subscribers of one eventAmazon SNS
Route events between AWS servicesAmazon EventBridge
Coordinate steps in a workflowAWS Step Functions
Send email from an applicationAmazon SES
Run a cloud contact centerAmazon Connect
Query data in S3 with SQLAmazon Athena
Ingest streaming dataAmazon Kinesis
Prepare and catalog dataAWS Glue
Business intelligence dashboardsAmazon QuickSight
Build and train machine learning modelsAmazon SageMaker AI
Image and video analysisAmazon Rekognition
Text to speech, speech to text, translationAmazon Polly, Amazon Transcribe, Amazon Translate
Chat interfaces, document text, natural languageAmazon Lex, Amazon Textract, Amazon Comprehend
Build, deploy, and trace applicationsAWS CodeBuild, AWS CodePipeline, AWS X-Ray
Desktops and streamed applicationsAmazon WorkSpaces, Amazon AppStream 2.0
Frontend and mobile appsAWS Amplify
Connect devicesAWS IoT Core
Define infrastructure in a templateAWS CloudFormation

Extra: The exam guide lists Amazon MSK, AWS CodeDeploy, AWS CloudShell, and AWS Transfer Family as out of scope. Recognize the names so you do not pick them as the tested answer.

Module 12: Pricing, billing, and support

Domain 4 is 12 percent of scored content. The mistakes are usually a tool used for the wrong moment, or a discount that does not match the workload.

Compute purchasing options named in the CLF-C02 exam guide.
OptionCommitmentFits
On-DemandNoneSpiky or unknown workloads. You pay for what you run.
Reserved InstancesA term, often one or three yearsSteady usage. Convertible Reserved Instances can change instance attributes. Standard ones are less flexible and usually a deeper discount.
Savings PlansA dollar-per-hour commitSteady compute spend when you want more flexibility than a specific instance reservation.
Spot InstancesNone, but AWS can reclaim themFault-tolerant and interruptible work, such as batch jobs.
Dedicated HostsA physical serverLicenses that care about sockets or cores, including some bring-your-own-license cases.
Dedicated InstancesHardware dedicated to your accountIsolation from other accounts, without you managing the host.
Capacity ReservationsCapacity in an Availability ZoneYou need the capacity to be there. A reservation is not, by itself, the discount.

Data transfer

Data transferred into AWS is generally not charged. Data transferred out of AWS, and data sent from one Region to another, is charged. Do not assume that "all traffic inside AWS is free."

Cost tools

The Pricing Calculator estimates a future bill. Cost Explorer shows where money already went and can forecast. Budgets sends an alert at a threshold. The Cost and Usage Report is the detailed line-item file. Cost allocation tags attach spend to a team or a project. AWS Organizations consolidated billing rolls many accounts into one bill and can share some discounts.

Support options in the exam guide

The guide's examples are customer service and communities, Basic Support, AWS Business Support+, AWS Enterprise Support, and AWS Unified Operations. Basic Support is the included baseline. Higher plans add technical response and, at the top end, a more proactive relationship. Response times and prices change, so confirm them on the AWS Support plans page.

Where to read and who can help

Documentation, whitepapers, AWS Prescriptive Guidance, the Knowledge Center, and AWS re:Post are self-serve. AWS Health Dashboard shows events that affect your account. AWS Trusted Advisor flags waste and risk. AWS Professional Services and AWS solutions architects are people who help you design. AWS Partners, including software vendors and system integrators, sell and deliver through the partner network and AWS Marketplace.

Frequently asked questions

Who patches the operating system on Amazon EC2?

The customer. AWS operates the hardware, the network, and the hypervisor. On Amazon RDS, AWS patches the database engine. On AWS Lambda, AWS operates the runtime.

What is the difference between a Region and an Availability Zone?

A Region is a geographic area. An Availability Zone is an isolated location inside that Region. Edge locations cache content closer to users and are not a substitute for a second Availability Zone.

Which tool estimates a bill before you launch, and which one reviews spend you already have?

The AWS Pricing Calculator estimates cost before you deploy. AWS Cost Explorer analyzes historical and forecast spend. AWS Budgets alerts you when cost or usage crosses a threshold you set.

Continue the AWS Cloud Practitioner study path

Drill the facts, then test them under a timer.

AWS Cloud Practitioner hub →
Available

Overview

Exam format, the 700 passing score, domain weights, and a study plan.

Available · You are here

Core Notes

Reference notes for responsibility, identity, infrastructure, services, pricing, and support.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by domain.

Related Tools

Useful companions while you study.

All study topics →