Elasticity
Capacity grows and shrinks with demand, often automatically. A larger server that you buy once is scalability you paid for in advance. Elasticity gives the capacity back when the spike ends.
Study guide · Core notes
Reference notes for CLF-C02: what the cloud changes, who is responsible, which service matches a need, and how the bill and the support plan work.
How to read these notes: Items tagged Extra are outside the CLF-C02 in-scope list, such as Amazon MSK. Learn the unmarked items first. New to the exam? Start with the overview for the format and domain weights. Vendor-neutral cloud models are in the networking and cloud notes.
AWS describes the cloud as a way to trade capital expense for variable expense, benefit from economies of scale, stop guessing capacity, increase speed and agility, stop running your own data centers, and go global quickly. Those six ideas are the value proposition behind Domain 1.
Capacity grows and shrinks with demand, often automatically. A larger server that you buy once is scalability you paid for in advance. Elasticity gives the capacity back when the spike ends.
High availability keeps a workload running through a failure, usually by using more than one Availability Zone. Agility is how fast you can try an idea and stop it if it fails.
A data center is mostly fixed: buildings, hardware, and staff, whether the servers are busy or idle. Cloud spend moves with what you run. Rightsizing means choosing a smaller resource when the current one is larger than the workload needs.
Bring Your Own License lets you apply licenses you already own, often on a Dedicated Host. An included license is part of the service price. The exam asks you to tell those two approaches apart, not to price a contract.
The framework is a design vocabulary. The migration strategies say how an application moves.
| Pillar | Question it answers |
|---|---|
| Operational excellence | Can you run, observe, and improve the workload? |
| Security | Are identities, data, and infrastructure protected? |
| Reliability | Does it recover, and can it meet demand? |
| Performance efficiency | Are you using the right resource type for the job? |
| Cost optimization | Are you paying only for what you need? |
| Sustainability | Are you reducing the energy and resources the workload uses? |
| Strategy | What changes | Picture |
|---|---|---|
| Rehost | Little or nothing | Move a virtual machine onto Amazon EC2 |
| Replatform | A few cloud optimizations | Move a database onto Amazon RDS |
| Refactor | The architecture | Rebuild around AWS Lambda or containers |
| Repurchase | The product | Replace a self-hosted app with a SaaS product |
| Retire | The application goes away | Turn off something nobody uses |
| Retain | Nothing moves yet | Keep it on premises for now |
| Extra Relocate | The hypervisor, not the guest | A VMware-level move. Useful context, not required by the task example in the guide. |
The exam guide points at AWS Cloud Adoption Framework outcomes such as reduced business risk, improved environmental, social, and governance performance, increased revenue, and increased operational efficiency. AWS Database Migration Service is the in-scope example of database replication during a move.
A Region is a separate geographic area. Each Region has multiple Availability Zones. An Availability Zone is one or more discrete data centers with independent power, cooling, and networking. Zones in a Region are isolated from each other so that a failure in one does not take the others down. You get high availability by running in more than one zone, not by hoping one building stays up.
An edge location is a site used by Amazon CloudFront, and by parts of Amazon Route 53 and AWS Global Accelerator, to serve users from a place closer to them. An edge location is not an Availability Zone. You do not launch an EC2 fleet "in an edge location" as a high-availability design.
Use more than one Region when you need disaster recovery, lower latency for distant users, or data to stay in a specific geography. Use more than one Availability Zone when you need the application to survive a zone failure inside the Region you already chose.
You reach services through the AWS Management Console, the AWS CLI, software development kits, or APIs. Infrastructure as code, such as AWS CloudFormation, repeats a setup instead of clicking it once. Choose a repeatable process when you will build the same environment again.
The root user is the identity that created the account. Use it only for the few tasks that require it, such as closing the account or changing account-level settings. Enable multi-factor authentication on root, and do not create long-lived access keys for it. Day-to-day work belongs to IAM users, or to workforce users in AWS IAM Identity Center.
An IAM user is an identity in one account. A group is a set of users that share policies. A role is an identity that a person or a service assumes, and it issues temporary credentials. Prefer a role for an EC2 instance over an access key stored on the disk.
A policy is the document that allows or denies actions. Managed policies are ready-made. Custom policies are ones you write. Least privilege means the policy allows only what that identity needs.
IAM Identity Center is the workforce single sign-on path across accounts, including federated identities. Amazon Cognito is for the end users of an application you build. They are not substitutes for each other.
AWS Secrets Manager stores and can rotate credentials. AWS Systems Manager can also hold parameters. Neither one replaces a role when the caller is an AWS service.
Match the symptom to the service. Several of these services also appear under management and governance in the exam guide.
| Service | Use it when you need |
|---|---|
| AWS Artifact | Compliance reports, such as SOC and PCI documents, that you download |
| AWS CloudTrail | A record of API calls: who did what, and from where |
| AWS Config | The configuration history of resources, and whether they still match a rule |
| Amazon CloudWatch | Metrics, logs, and alarms about how a resource is behaving |
| Amazon GuardDuty | Detection of suspicious activity, such as unusual API use or compromised instances |
| Amazon Inspector | Vulnerability findings for workloads such as EC2, containers, and Lambda |
| AWS Security Hub | One place that collects security findings from other services |
| AWS Shield | Protection against distributed denial of service |
| AWS WAF | Filters on web requests, such as common injection patterns |
| Amazon Macie | Discovery of sensitive data sitting in Amazon S3 |
| AWS KMS | Creation and control of encryption keys |
| AWS Certificate Manager | TLS certificates for AWS services |
| AWS Trusted Advisor | Checks against AWS best practices, including cost and security |
Third-party security products can be bought from AWS Marketplace. The AWS Knowledge Center, AWS Security Blog, and AWS re:Post are places to read, not services that block traffic. Report abuse of AWS resources to the AWS Trust and Safety team.
Amazon EC2 is a virtual server. Instance families point at the bottleneck: general purpose balances resources, compute optimized favors CPU, memory optimized favors RAM, and storage optimized favors local disk throughput. AWS Auto Scaling adds and removes capacity. A load balancer spreads traffic so one instance is not the only door.
Runs your code when an event arrives. You do not provision the server. It is the usual answer for a short task that should scale without an instance to patch.
Amazon ECS orchestrates containers on AWS. Amazon EKS runs Kubernetes. AWS Fargate runs those containers without you managing the underlying servers. Amazon ECR stores the images.
AWS Elastic Beanstalk deploys an application and handles capacity, load balancing, and scaling. Amazon Lightsail is a simpler virtual private server with a predictable price. AWS Batch runs batch jobs.
AWS Outposts places AWS infrastructure in your own data center. It is the in-scope answer when the workload must stay on premises and still use AWS services.
Start with the access pattern: object, block, or file. Then pick a class or a durability tradeoff.
| Service | Type | Choose it when |
|---|---|---|
| Amazon S3 | Object | You store blobs and fetch them with an API. Lifecycle policies move objects to cheaper classes. |
| S3 Standard | Object class | Data is read often. |
| S3 Intelligent-Tiering | Object class | Access patterns change or are unknown. |
| S3 Standard-IA and One Zone-IA | Object class | Access is infrequent but must still be fast. One Zone-IA keeps the data in a single Availability Zone. |
| S3 Glacier classes | Object class | Archive. Instant Retrieval is milliseconds. Flexible Retrieval is minutes to hours. Deep Archive is the lowest-cost, longest-retrieval option. |
| Amazon EBS | Block | A persistent volume for one EC2 instance. |
| Instance store | Block | Temporary disk on the host. Data is gone when the instance stops. |
| Amazon EFS | File | A shared file system that many Linux instances mount. |
| Amazon FSx | File | Managed file systems, including Windows file servers. |
| AWS Storage Gateway | Hybrid | On-premises applications need a cache or a path into cloud storage. |
| AWS Backup | Backup | Central backup policies across AWS services. |
Ask whether the data is relational, a key-value or document store, a graph, or a cache. Then ask whether you want to operate the engine.
| Service | Kind | Remember |
|---|---|---|
| Amazon RDS | Relational, managed | MySQL, PostgreSQL, MariaDB, Oracle, and SQL Server engines. AWS patches the engine. |
| Amazon Aurora | Relational, managed | MySQL-compatible and PostgreSQL-compatible, built for higher throughput. |
| Amazon DynamoDB | NoSQL | Key-value and document data, serverless, single-digit millisecond access. |
| Amazon ElastiCache | In memory | A cache in front of a slower database. It is not the system of record. |
| Amazon DocumentDB | Document | A managed document database. |
| Amazon Neptune | Graph | Relationships, not rows. |
| Amazon Redshift | Warehouse | Analytics over large structured data. It is listed with analytics services. |
| AWS DMS and AWS SCT | Migration | DMS moves data. The Schema Conversion Tool helps convert a schema to a different engine. |
A VPC is your private network. The pieces below are the ones the exam guide names.
A subnet is a slice of the VPC in one Availability Zone. An internet gateway lets public subnets reach the internet. A NAT gateway lets private instances start outbound connections without accepting inbound ones from the internet.
A security group is a stateful virtual firewall on a resource. It has allow rules. A network ACL is stateless, sits on the subnet, and can allow or deny. Because it is stateless, return traffic needs its own rule.
Amazon Route 53 is DNS. Amazon CloudFront is the content delivery network at edge locations. AWS Global Accelerator gives you static anycast addresses that route users onto the AWS network.
AWS Site-to-Site VPN and AWS Client VPN encrypt a path over the internet. AWS Direct Connect is a dedicated connection that does not depend on the public internet. AWS PrivateLink reaches services without exposing them to the internet. AWS Transit Gateway is a hub that connects many VPCs and on-premises networks.
Amazon API Gateway fronts APIs. Extra: AWS Network Firewall and Amazon VPC Lattice are on the exam guide's out-of-scope list.
These are identification questions: name the service that does the job.
| Job | Service |
|---|---|
| Hold a message until a worker takes it | Amazon SQS |
| Notify many subscribers of one event | Amazon SNS |
| Route events between AWS services | Amazon EventBridge |
| Coordinate steps in a workflow | AWS Step Functions |
| Send email from an application | Amazon SES |
| Run a cloud contact center | Amazon Connect |
| Query data in S3 with SQL | Amazon Athena |
| Ingest streaming data | Amazon Kinesis |
| Prepare and catalog data | AWS Glue |
| Business intelligence dashboards | Amazon QuickSight |
| Build and train machine learning models | Amazon SageMaker AI |
| Image and video analysis | Amazon Rekognition |
| Text to speech, speech to text, translation | Amazon Polly, Amazon Transcribe, Amazon Translate |
| Chat interfaces, document text, natural language | Amazon Lex, Amazon Textract, Amazon Comprehend |
| Build, deploy, and trace applications | AWS CodeBuild, AWS CodePipeline, AWS X-Ray |
| Desktops and streamed applications | Amazon WorkSpaces, Amazon AppStream 2.0 |
| Frontend and mobile apps | AWS Amplify |
| Connect devices | AWS IoT Core |
| Define infrastructure in a template | AWS CloudFormation |
Extra: The exam guide lists Amazon MSK, AWS CodeDeploy, AWS CloudShell, and AWS Transfer Family as out of scope. Recognize the names so you do not pick them as the tested answer.
Domain 4 is 12 percent of scored content. The mistakes are usually a tool used for the wrong moment, or a discount that does not match the workload.
| Option | Commitment | Fits |
|---|---|---|
| On-Demand | None | Spiky or unknown workloads. You pay for what you run. |
| Reserved Instances | A term, often one or three years | Steady usage. Convertible Reserved Instances can change instance attributes. Standard ones are less flexible and usually a deeper discount. |
| Savings Plans | A dollar-per-hour commit | Steady compute spend when you want more flexibility than a specific instance reservation. |
| Spot Instances | None, but AWS can reclaim them | Fault-tolerant and interruptible work, such as batch jobs. |
| Dedicated Hosts | A physical server | Licenses that care about sockets or cores, including some bring-your-own-license cases. |
| Dedicated Instances | Hardware dedicated to your account | Isolation from other accounts, without you managing the host. |
| Capacity Reservations | Capacity in an Availability Zone | You need the capacity to be there. A reservation is not, by itself, the discount. |
Data transferred into AWS is generally not charged. Data transferred out of AWS, and data sent from one Region to another, is charged. Do not assume that "all traffic inside AWS is free."
The Pricing Calculator estimates a future bill. Cost Explorer shows where money already went and can forecast. Budgets sends an alert at a threshold. The Cost and Usage Report is the detailed line-item file. Cost allocation tags attach spend to a team or a project. AWS Organizations consolidated billing rolls many accounts into one bill and can share some discounts.
The guide's examples are customer service and communities, Basic Support, AWS Business Support+, AWS Enterprise Support, and AWS Unified Operations. Basic Support is the included baseline. Higher plans add technical response and, at the top end, a more proactive relationship. Response times and prices change, so confirm them on the AWS Support plans page.
Documentation, whitepapers, AWS Prescriptive Guidance, the Knowledge Center, and AWS re:Post are self-serve. AWS Health Dashboard shows events that affect your account. AWS Trusted Advisor flags waste and risk. AWS Professional Services and AWS solutions architects are people who help you design. AWS Partners, including software vendors and system integrators, sell and deliver through the partner network and AWS Marketplace.
The customer. AWS operates the hardware, the network, and the hypervisor. On Amazon RDS, AWS patches the database engine. On AWS Lambda, AWS operates the runtime.
A Region is a geographic area. An Availability Zone is an isolated location inside that Region. Edge locations cache content closer to users and are not a substitute for a second Availability Zone.
The AWS Pricing Calculator estimates cost before you deploy. AWS Cost Explorer analyzes historical and forecast spend. AWS Budgets alerts you when cost or usage crosses a threshold you set.
Drill the facts, then test them under a timer.
Exam format, the 700 passing score, domain weights, and a study plan.
Reference notes for responsibility, identity, infrastructure, services, pricing, and support.
40 recall cards in four decks, plus memory notes for pillars, services, and pricing.
200 original questions with custom exams, explanations, and a score report by domain.
Useful companions while you study.
Generate strong random passwords with custom length, characters, symbols, and security options.
Convert structured data between JSON and YAML with formatting and validation.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Compare two text blocks and highlight added, removed, and changed content.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Amazon Web Services, AWS, and related marks are trademarks of Amazon.com, Inc. or its affiliates. NodnWebTools is not affiliated with, endorsed by, or sponsored by Amazon.