Study guide · Flashcards & memory notes

AWS Cloud Practitioner Flashcards & Memory Notes

40 recall cards for the facts CLF-C02 keeps asking you to separate: pillars, responsibility, core services, and the tools that explain a bill.

Exam guide: CLF-C024 decks · 40 cardsNo sign-up required

How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.

Study mode

Choose a deck, flip each card, and mark what you already know.

All flashcards

Select a question to reveal its answer.

Deck 1 · Cloud concepts and places

Value, pillars, migration words, and where a workload runs.

10 cards
1.1What is elasticity?

Capacity that grows and shrinks with demand, often automatically. Scalability is the ability to handle more load.

1.2Name the six pillars of the AWS Well-Architected Framework.

Operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability.

1.3How does a variable cloud cost differ from a data-center cost?

A data center is mostly a fixed cost whether the servers are busy or idle. Cloud spend varies with what you run.

1.4What does rehost mean?

Move an application as-is, such as a virtual machine onto Amazon EC2. It is also called lift and shift.

1.5What does refactor mean in a cloud migration?

Change the architecture to use cloud services, such as rebuilding a feature around AWS Lambda.

1.6What is an AWS Region?

A geographic area that contains multiple Availability Zones.

1.7What is an Availability Zone?

An isolated location inside a Region, with its own power and networking.

1.8What is an edge location used for?

Caching and delivery closer to users, as with Amazon CloudFront. It is not where you place an EC2 high-availability pair.

1.9Why run a workload in more than one Region?

Disaster recovery, lower latency for distant users, or a requirement to keep data in a specific geography.

1.10What does rightsizing mean?

Choosing a smaller or better-fitting resource when the current one is larger than the workload needs.

Deck 2 · Security and access

The responsibility line, identities, and the service that detects or records.

10 cards
2.1Who patches the guest operating system on Amazon EC2?

The customer. AWS operates the hardware and the hypervisor.

2.2Who patches the database engine on Amazon RDS?

AWS. The customer still owns the data and who can access it.

2.3Who operates the runtime for AWS Lambda?

AWS. The customer owns the code and the function's permissions.

2.4How should you treat the AWS account root user?

Enable MFA, do not use it for daily work, and do not create long-lived access keys for it.

2.5What is least privilege?

Grant only the access an identity needs, and nothing more.

2.6What is the difference between an IAM user and an IAM role?

A user is an identity in one account. A role is assumed and receives temporary credentials.

2.7What is AWS IAM Identity Center for?

Workforce single sign-on across AWS accounts, including federated identities.

2.8What does AWS CloudTrail record?

API calls: who did what. Amazon CloudWatch is metrics, logs, and alarms.

2.9What does Amazon GuardDuty do, and what does AWS Shield do?

GuardDuty detects suspicious activity. Shield protects against distributed denial of service.

2.10Where do you download AWS compliance reports?

AWS Artifact.

Deck 3 · Core services

Storage, databases, network controls, and the messaging pair.

10 cards
3.1Which service is AWS object storage?

Amazon S3. You store objects in a bucket and retrieve them with an API.

3.2Which service is a persistent block volume for one EC2 instance?

Amazon EBS. Instance store is temporary and is lost when the instance stops.

3.3Which database is the NoSQL key-value service?

Amazon DynamoDB. Amazon RDS and Amazon Aurora are relational.

3.4What is Amazon ElastiCache?

An in-memory cache. It is not the system of record.

3.5What is the difference between a security group and a network ACL?

A security group is stateful and allows traffic at the resource. A network ACL is stateless, can deny, and sits on the subnet.

3.6What is Amazon Route 53?

The AWS DNS service. Amazon CloudFront is the content delivery network.

3.7What is the difference between AWS Direct Connect and a site-to-site VPN?

Direct Connect is a dedicated connection. A VPN encrypts traffic over the internet.

3.8What is the difference between Amazon SQS and Amazon SNS?

SQS is a queue that holds a message for a consumer. SNS publishes one message to many subscribers.

3.9Which service runs your code without you managing servers?

AWS Lambda. Amazon EC2 is a virtual server whose guest operating system you patch.

3.10Which service queries data in Amazon S3 with SQL?

Amazon Athena. Amazon Redshift is a data warehouse you load for analytics.

Deck 4 · Pricing, billing, and support

Discounts, the moment each cost tool is for, and who answers.

10 cards
4.1When do you choose Spot Instances?

For fault-tolerant work that can be interrupted. AWS can reclaim the capacity.

4.2What is the difference between On-Demand and a Savings Plan?

On-Demand has no commitment. A Savings Plan commits to a dollar amount of compute usage per hour for a discount.

4.3What is a Capacity Reservation?

It reserves capacity in an Availability Zone. It is not, by itself, the billing discount.

4.4Is data transfer into AWS usually charged?

No. Data transfer out of AWS, and data transfer between Regions, is charged.

4.5Which tool estimates cost before you deploy?

The AWS Pricing Calculator. AWS Cost Explorer reviews spend you already have.

4.6What does AWS Budgets do?

It alerts you when cost or usage crosses a threshold you set.

4.7What is consolidated billing?

AWS Organizations combines many accounts into one bill and can share some discounts.

4.8What is Basic Support?

The included support baseline. Higher plans, such as Business Support+ and Enterprise Support, add technical response.

4.9What does AWS Trusted Advisor check?

Best-practice findings for cost, security, performance, fault tolerance, and service limits. The checks you see can depend on the support plan.

4.10Where do you report abuse of AWS resources?

The AWS Trust and Safety team.

Memory notes

Groupings that make the highest-yield CLF-C02 facts easier to recall.

Six pillars

Operational excellence, security, reliability, performance efficiency, cost optimization, sustainability.

Who patches

  • EC2 you patch the guest OS
  • RDS AWS patches the engine
  • Lambda AWS runs the runtime

Places

  • Region geography
  • Availability Zone isolated site in that Region
  • Edge location cache, not a second zone

Storage in one line

S3 objects, EBS persistent block, instance store temporary, EFS shared files.

Observe versus detect

  • CloudTrail API history
  • CloudWatch metrics and alarms
  • GuardDuty threats · Shield DDoS

Bill tools

Pricing Calculator before you launch. Cost Explorer after. Budgets when you cross a line. Data in is generally free. Data out is not.

Continue the AWS Cloud Practitioner study path

Test what you have learned with a timed practice exam.

AWS Cloud Practitioner hub →
Available

Overview

Exam format, the 700 passing score, domain weights, and a study plan.

Available

Core Notes

Reference notes for responsibility, identity, infrastructure, services, pricing, and support.

Available · You are here

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for pillars, services, and pricing.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by domain.

Related Tools

Useful companions while you study.

All study topics →