Free AWS Certified Cloud Practitioner (CLF-C02) Study Resources
Free to use right now: 1,047 practice questions with explanations, 163 study notes and 790 flashcards. Questions follow the four domains of the official exam guide, so a weak area on screen is a weak area on the day. Nothing here is a brain dump, and BrainyBee is not the exam vendor — the CLF-C02 exam itself is booked and paid for separately.
1,047
Practice Questions
163
Study Notes
790
Flashcards
CLF-C02 exam prep
Booked CLF-C02? Start practising now.
Free to use right now: 1,047 practice questions with explanations, 163 study notes and 790 flashcards. Questions follow the four domains of the official exam guide, so a weak area on screen is a weak area on the day. Nothing here is a brain dump, and BrainyBee is not the exam vendor — the CLF-C02 exam itself is booked and paid for separately.
The timed mock is assembled to the blueprint's 65 questions from this bank each time you start one.
Practise, read why an answer was wrong, study that domain, practise again.
The diagnostic draws questions from every domain in the exam guide, so each domain has enough evidence behind it. You answer at your own pace; nothing is charged and no card is asked for.
Each question carries a written explanation, and your results break down by exam domain so you can see which areas are costing you marks rather than guessing at them.
Study notes and flashcards for this certification are on this page and in the workspace, and the free AI tutor will answer follow-up questions about anything you just got wrong. The free tutor has fair-use limits.
Come back and practise again — a fresh set each time, and a full-length timed paper when you want to rehearse the real sitting. Your readiness estimate moves with the evidence; it is an estimate, not a probability of passing.
The diagnostic draws questions from every domain in the exam guide, so each domain has enough evidence behind it. You answer at your own pace; nothing is charged and no card is asked for.
$0 to study
Public study material, practice tests and the free AI tutor cost nothing. The free tutor has fair-use limits.
Optional AI credit top-ups start at $5, and premium usage is charged from your wallet.
No subscription and no card are needed to start free practice. The certification exam fee is separate and goes to the exam vendor.
This curriculum covers the core AWS services designed to enable communication between independent components of cloud-native applications: Amazon EventBridge, Amazon Simple Notification Service (SNS), and Amazon Simple Queue Service (SQS). These services are fundamental to building decoupled, highly scalable, and event-driven architectures.
## Prerequisites
Before starting this module, students should possess the following foundational knowledge:
Cloud Fundamentals: Basic understanding of AWS Regions, Availability Zones, and the Shared Responsibility Model.
Computing Basics: Familiarity with Amazon EC2 (instances) and AWS Lambda (serverless functions).
Data Formats: A basic understanding of JSON (JavaScript Object Notation), as it is the primary format for events and messages.
Architectural Concepts: Awareness of the difference between monolithic and microservices architectures.
Polling, decoupling, visibility timeout, and buffers
Medium
4. Integration Patterns
Orchestration & Design
Choosing the right service for the right use case
High
## Module Objectives per Module
Module 1: Amazon EventBridge
Define EventBridge as a "smart hub" for application events.
Configure Rules to trigger actions based on system state changes (e.g., an EC2 instance stopping).
Differentiate between event-based triggers and metric-based triggers (CloudWatch Alarms).
Module 2: Amazon SNS
Explain the Publish/Subscribe (Pub/Sub) model.
Identify supported protocols: SMS, Email, HTTP/S, and Lambda.
Understand the "fan-out" pattern where one message is sent to multiple subscribers.
Module 3: Amazon SQS
Define Decoupling and its importance in preventing system failure cascades.
Distinguish between Standard Queues (at-least-once delivery) and FIFO Queues (first-in-first-out).
Describe how SQS acts as a buffer to handle spikes in traffic.
## Visual Anchors
Service Selection Logic
Loading Diagram...
Figure 1 — Mermaid diagram
Integration Architecture Example
Compiling TikZ diagram…
⏳
Running TeX engine…
This may take a few seconds
Figure 2 — TikZ diagram
## Success Metrics
To demonstrate mastery of this curriculum, the student must be able to:
Identify which service to use when a requirement specifies "pushing notifications to mobile devices" (SNS).
Explain how SQS prevents a web server from crashing during a sudden burst of 1,000,000 requests.
Design a simple workflow where EventBridge triggers a Lambda function based on an IAM user login event.
Calculate basic free tier limits: Recognize that SNS and SQS both offer ~1 million free requests/publishes.
## Real-World Application
In a career as a Cloud Architect or Developer, these services are the "glue" of the cloud:
Resilience: By using SQS, you ensure that if your database goes down, your messages aren't lost—they stay in the queue until the database returns.
Agility: With EventBridge, you can add new features (like an email alert) to an existing system without modifying the original code; you simply add a new event rule.
Scalability: These services are serverless and scale automatically, meaning you don't have to manage servers for your messaging infrastructure.
## Examples Section
[!TIP]
Use these scenarios to decide which service to implement in your architecture.
Scenario
Primary Service
Why?
Password Reset
Amazon SNS
Immediate delivery to a specific email or phone number is required (Push).
Order Processing
Amazon SQS
Orders arrive at different speeds; the backend needs a buffer to process them at its own pace (Polling/Decoupling).
Daily Report Trigger
Amazon EventBridge
EventBridge supports "Scheduled Events" (cron jobs) to run tasks at specific times.
Image Metadata Extraction
SQS + Lambda
When a user uploads a photo, the photo ID is put in a queue so a worker can process it without making the user wait.
▶Deep Dive: SNS vs. SQS
While both handle messages, remember: SNS is Push (it sends data to you immediately) and SQS is Pull (your application must go and ask for the data). They are often used together in a "Fan-out" pattern where SNS sends a message to multiple SQS queues simultaneously.
This document provides a structured roadmap for mastering AWS Identity and Access Management (IAM) and related security services, aligned with the AWS Certified Cloud Practitioner (CLF-C02) exam objectives.
Prerequisites
Before beginning this curriculum, learners should have a foundational understanding of the following:
Cloud Computing Basics: Familiarity with the on-demand nature of cloud resources.
The Shared Responsibility Model: Understanding that while AWS secures the "cloud," the customer is responsible for security "in the cloud" (specifically identity and data access).
Basic Networking: Understanding that resources exist within a Virtual Private Cloud (VPC) and require controlled entry points.
[!IMPORTANT]
Mastery of Access Management is the single most critical factor in preventing data breaches within an AWS environment.
Module Breakdown
Module
Topic
Primary Focus
Difficulty
1
The Root User
Protection, initial setup, and restricted tasks
★☆☆☆☆
2
IAM Fundamentals
Users, Groups, and the Principle of Least Privilege
★★☆☆☆
3
Policies & Permissions
JSON structures, Managed vs. Custom policies
★★★☆☆
4
Roles & Federation
Cross-account access, service-to-service, and SSO
★★★★☆
5
Secret Management
AWS Secrets Manager and Systems Manager
★★☆☆☆
Learning Objectives per Module
Module 1: The Root User & Initial Security
Identify tasks that only the account root user can perform (e.g., changing account settings, closing the account).
Explain the critical importance of protecting the root user with Multi-Factor Authentication (MFA).
Understand why daily administrative tasks should never be performed by the root user.
Module 2: IAM Entities (Users, Groups, Roles)
Differentiate between an IAM User (individual), an IAM Group (collection of users), and an IAM Role (temporary credentials).
Apply the Principle of Least Privilege: Granting only the minimum permissions required to perform a task.
Loading Diagram...
Figure 1 — Mermaid diagram
Module 3: Permissions & Policies
Understand that policies are JSON documents that define what actions are allowed on which resources.
Identify the difference between AWS Managed Policies (pre-built) and Customer Managed Policies.
Module 4: Enterprise Identity
Define AWS IAM Identity Center (formerly Single Sign-On) and its role in managing multiple accounts.
Understand Federation (e.g., SAML 2.0) to allow users to sign in using corporate credentials (like Active Directory).
Module 5: Credential Storage & Automation
Explain the role of AWS Secrets Manager in rotating and managing database credentials and API keys.
Identify how AWS Systems Manager provides a unified interface for operational tasks and parameter storage.
Real-World Application
Understanding access management is not just for passing the exam; it is vital for professional cloud operations:
Case Study: The S3 Data Breach: A company fails to use the Principle of Least Privilege, giving an EC2 instance full administrative access. If the instance is compromised, the attacker can delete the entire S3 infrastructure. Applying an IAM Role with only s3:GetObject permission would have prevented the disaster.
Compliance & Auditing: Using AWS CloudTrail in conjunction with IAM allows organizations to see exactly who made what API call, which is essential for HIPAA or PCI-DSS compliance.
Credential Rotation: In a production environment, hardcoding passwords in application code is a major risk. Using AWS Secrets Manager allows the system to change passwords automatically every 30 days without human intervention.
Success Metrics
To determine if you have mastered this curriculum, you should be able to:
Diagram the Auth Flow: Explain how an IAM User authenticates (MFA/Password) and then gets authorized (Policy evaluation).
Configuration Task: Successfully create an IAM Group, attach the AmazonS3ReadOnlyAccess policy, and verify a user in that group cannot delete a bucket.
Policy Logic Calculation: Identify the outcome of a policy conflict.
Formula for Policy Evaluation:(Explicit Deny)>(Explicit Allow)>(Default Deny)
Recall Test: List 3 tasks exclusive to the Root User.
Before starting this lab, ensure you have the following ready:
An active AWS Account.
Administrative access to the account (It is highly recommended to use an IAM Admin user, not the AWS root user, to follow best practices).
AWS CLI installed and configured on your local machine (aws configure) with your administrative credentials.
Basic familiarity with using a command-line interface (CLI) or terminal.
Learning Objectives
By completing this 30-minute lab, you will be able to:
Create and manage IAM Groups and Users within an AWS account.
Apply the Principle of Least Privilege by attaching specific, restricted managed policies to an IAM Group.
Generate and configure programmatic access credentials (access keys) for an IAM User.
Verify access controls by attempting authorized and unauthorized actions via the AWS CLI.
Architecture Overview
The following diagram illustrates the relationship between the IAM entities and the AWS resources you will configure in this lab.
Loading Diagram...
Figure 1 — Mermaid diagram
Step-by-Step Instructions
Step 1: Create a Test S3 Bucket
We need a resource for our new IAM user to interact with. We will create an Amazon S3 bucket.
bash
aws s3 mb s3://brainybee-lab-bucket-12345
(Note: S3 bucket names must be globally unique. Replace 12345 with random numbers if the bucket name is taken).
▶Console alternative
Navigate to
S3 > Create bucket
. Enter a unique bucket name like brainybee-lab-bucket-12345, leave all defaults, and click
Create bucket
.
[!TIP]
Always use lowercase letters and hyphens for S3 bucket names to avoid DNS-compliance errors.
Step 2: Create an IAM Group
Following best practices, we assign permissions to groups rather than individual users. We will create a group for users who only need read access to S3.
bash
aws iam create-group --group-name brainybee-s3-readers
▶Console alternative
Navigate to
IAM > User Groups > Create group
. Name the group brainybee-s3-readers and click
Create group
.
[!IMPORTANT]
IAM Group names are case-sensitive in some contexts, so stick to a consistent naming convention.
Step 3: Attach a Least-Privilege Policy to the Group
We will attach an AWS Managed Policy that explicitly grants Read-Only access to S3, embodying the principle of least privilege.
bash
aws iam attach-group-policy --group-name brainybee-s3-readers --policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
▶Console alternative
Navigate to
IAM > User Groups
, click on brainybee-s3-readers, go to the
Permissions
tab, click
Add permissions > Attach policies
. Search for AmazonS3ReadOnlyAccess, check the box, and click
Add permissions
.
[!NOTE]
The ARN (Amazon Resource Name) arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess points to an AWS-managed policy maintained by AWS. You do not need to write the JSON for this policy yourself.
Step 4: Create an IAM User and Access Keys
Now, create a user who will act as our test subject, and generate programmatic credentials so they can use the CLI.
bash
aws iam create-user --user-name brainybee-test-user
aws iam create-access-key --user-name brainybee-test-user
▶Console alternative
Navigate to
IAM > Users > Add users
. Name the user brainybee-test-user. Do not give them console access. Once created, click on the user, go to
Security credentials
, and click
Create access key
for CLI use. Save the resulting keys.
[!WARNING]
The CLI will output an AccessKeyId and a SecretAccessKey. Copy these immediately! The secret key is only displayed once. If you lose it, you must delete the key and generate a new one.
Step 5: Add the User to the Group
Currently, the user has no permissions. By adding them to the group, they will inherit the S3 Read-Only policy.
bash
aws iam add-user-to-group --user-name brainybee-test-user --group-name brainybee-s3-readers
▶Console alternative
Navigate to
IAM > Users
, click brainybee-test-user, go to the
Groups
tab, click
Add user to groups
, select brainybee-s3-readers, and save.
[!TIP]
In a real-world scenario, if a user changes roles within a company, you simply remove them from their old group and add them to a new one, rather than auditing dozens of individual user-level policies.
Step 6: Configure the Test User Profile locally
Set up a secondary AWS CLI profile on your machine to test the new user's access.
bash
aws configure --profile testuser
Paste the AccessKeyId and SecretAccessKey you generated in Step 4. You can leave the default region and output format blank.
Checkpoints
Verify that the configuration works and that the principle of least privilege is actively protecting your environment.
Checkpoint 1: Test Authorized Access (Read)
Attempt to list S3 buckets using the test user's profile. Because they are in the brainybee-s3-readers group, this should succeed.
bash
aws s3 ls--profile testuser
Expected Result: You should see a list of your S3 buckets, including the brainybee-lab-bucket-12345 you created in Step 1.
Checkpoint 2: Test Unauthorized Access (Write)
Attempt to create a new S3 bucket using the test user's profile. This should fail because the policy explicitly grants only read access.
Expected Result: An AccessDenied error. This proves your least privilege boundaries are functioning correctly.
Clean-Up / Teardown
[!WARNING] Remember to run the teardown commands to avoid ongoing clutter and potential security vulnerabilities from stray access keys.
Run the following CLI commands using your default (Admin) profile to remove all created resources.
bash
# 1. Delete the user's access key (Replace <ACCESS_KEY_ID> with the ID from Step 4)aws iam delete-access-key --user-name brainybee-test-user --access-key-id <ACCESS_KEY_ID># 2. Remove the user from the groupaws iam remove-user-from-group --user-name brainybee-test-user --group-name brainybee-s3-readers
# 3. Delete the useraws iam delete-user --user-name brainybee-test-user
# 4. Detach the policy from the groupaws iam detach-group-policy --group-name brainybee-s3-readers --policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
# 5. Delete the groupaws iam delete-group --group-name brainybee-s3-readers
# 6. Delete the S3 bucket (Replace the number with your unique bucket suffix)aws s3 rb s3://brainybee-lab-bucket-12345 --force
Troubleshooting
Common Error
Cause
Fix
An error occurred (AccessDenied) when calling the CreateBucket operation (During Step 1)
Your default CLI profile doesn't have Admin permissions.
Reconfigure aws configure using an IAM Admin user access key.
An error occurred (NoSuchEntity) when calling the AttachGroupPolicy operation
A typo in the policy ARN or the group name.
Verify the ARN is exactly arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess and the group name matches Step 2.
An error occurred (BucketAlreadyExists)
S3 bucket names must be globally unique across all of AWS.
Append random numbers to your bucket name in Step 1.
DeleteConflict during Teardown
Trying to delete a group before removing users, or deleting a user before deleting their access keys.
Follow the Teardown list in the exact numbered order. Dependencies must be removed first.
Cost Estimate
This lab strictly utilizes AWS IAM (which is always free) and standard Amazon S3 bucket creation without uploading heavy objects.
Total Estimated Cost: $0.00 (Covered entirely by the AWS Free Tier and IAM zero-cost structure).
Curriculum Overview750 words
AWS AI/ML and Data Analytics Services: Curriculum Overview
AWS artificial intelligence and machine learning (AI/ML) services and analytics services
AWS AI/ML and Data Analytics Services: Curriculum Overview
This curriculum provides a comprehensive overview of the Artificial Intelligence (AI), Machine Learning (ML), and Data Analytics services within the AWS ecosystem, specifically aligned with the AWS Certified Cloud Practitioner (CLF-C02) exam objectives (Domain 3.7).
Prerequisites
Before diving into AI/ML and Analytics, students should possess the following foundational knowledge:
Cloud Fundamentals: Understanding of the AWS Shared Responsibility Model and Global Infrastructure.
Storage Basics: Familiarity with Amazon S3 (Simple Storage Service), as it often serves as the "Data Lake" for analytics and ML training.
Basic IT Literacy: Understanding the difference between structured data (databases) and unstructured data (text, images).
Cloud Economics: Awareness of the pay-as-you-go model, which is critical for high-resource tasks like ML training.
Module Breakdown
Module
Focus Area
Difficulty
Primary Services
1
Foundations of AI & ML
Beginner
SageMaker
2
Specialized AI Services
Intermediate
Lex, Polly, Rekognition, Comprehend
3
Data Analytics Core
Intermediate
Athena, Glue, Redshift (Overview)
4
Real-Time & Visualization
Intermediate
Kinesis, QuickSight
Learning Objectives per Module
Module 1: Foundations of AI & ML
Define AI vs. ML: Distinguish between general Artificial Intelligence and the subset of Machine Learning.
Amazon SageMaker: Understand its role as a "smart assistant" for the entire ML lifecycle: building, training, and deploying models.
Module 2: Specialized AI Services
Natural Language Processing (NLP): Identify Amazon Comprehend for sentiment analysis and Amazon Translate for language conversion.
Speech & Text: Differentiate between Polly (text-to-speech), Transcribe (speech-to-text), and Textract (extracting text from documents).
Vision & Conversation: Explain the use of Rekognition for image analysis and Lex for building conversational chatbots.
Module 3: Data Analytics Core
Serverless Querying: Use Amazon Athena to query data residing in S3 using standard SQL.
Data Integration: Understand AWS Glue for ETL (Extract, Transform, Load) processes and data cataloging.
Module 4: Real-Time & Visualization
Streaming Data: Identify Amazon Kinesis for processing real-time, streaming data at scale.
Business Intelligence (BI): Recognize Amazon QuickSight as the primary tool for creating dashboards and visualizing data.
Visual Anchors
The Data Analytics Pipeline
Loading Diagram...
Figure 1 — Mermaid diagram
AI/ML Service Categorization
Loading Diagram...
Figure 2 — Mermaid diagram
Success Metrics
To demonstrate mastery of this curriculum, students should be able to:
Match Service to Scenario: If a customer needs to turn a voice recording into text, identify Amazon Transcribe immediately.
Explain SageMaker's Value: Articulate how SageMaker allows developers to build ML models without being "coding experts" in low-level algorithms.
Define SQL-on-S3: Explain how Amazon Athena eliminates the need to load data into a database before querying it.
Identify Real-Time Constraints: Recognize that Amazon Kinesis is the correct choice for sub-second data ingestion, unlike batch processing.
[!IMPORTANT]
For the CLF-C02 exam, you do not need to know how to code these services, but you must know what problem each service solves.
Real-World Application
Understanding these services is critical for modern career paths in Cloud Architecture and Data Engineering:
Customer Support: Using Amazon Lex and Amazon Polly to create automated, human-like phone support systems (IVR).
Financial Auditing: Using Amazon Textract to automatically pull data from thousands of scanned invoices, saving hundreds of manual labor hours.
E-commerce: Using Amazon Personalize (AI) or SageMaker to suggest products to users based on their browsing history.
Executive Reporting: Connecting Amazon QuickSight to an S3 data lake to give CEOs real-time visibility into global sales trends.
▶Deep Dive: Why use SageMaker vs. Specialized Services?
If you have a very specific, common task (like translating text), use a specialized service like
Amazon Translate
. If you are trying to predict something unique to your business (like custom stock market fluctuations), use
Amazon SageMaker
to build a custom model from your own data.
Hands-On Lab918 words
Hands-On Lab: AWS AI/ML and Storage Services Integration
AWS artificial intelligence and machine learning (AI/ML) services and analytics services
Hands-On Lab: AWS AI/ML and Storage Services Integration
Welcome to this guided hands-on lab! Artificial intelligence (AI) and machine learning (ML) are among the most exciting areas in cloud computing today. AWS provides a suite of managed AI services that allow you to add powerful capabilities—like natural language processing (NLP) and computer vision—to your applications without requiring deep ML expertise.
In this 30-minute lab, we will combine Amazon S3 (for storage) with Amazon Comprehend (for text analytics) and Amazon Rekognition (for image analysis) to demonstrate how these services interact.
Prerequisites
Before starting this lab, ensure you have the following ready:
AWS Account: Active AWS account with Administrator or PowerUser access.
CLI Tools: AWS CLI installed and configured (aws configure) with valid access keys.
Prior Knowledge: Basic familiarity with the terminal/command prompt and understanding of cloud storage concepts.
Local Files: You will need a sample image (e.g., a .jpg of a landscape, animal, or city) saved on your local machine.
[!WARNING]
Never hardcode or share your AWS credentials. Always use environment variables or secure AWS CLI profiles.
Learning Objectives
By completing this lab, you will be able to:
Provision an Amazon S3 bucket to store raw unstructured data for machine learning.
Use Amazon Rekognition to identify objects, people, or scenes in an image.
Extract sentiment and key entities from unstructured text using Amazon Comprehend.
Clean up and tear down AWS resources to avoid unexpected charges.
Architecture Overview
The following diagram illustrates the workflow of the services we are building:
Loading Diagram...
Figure 1 — Mermaid diagram
Step-by-Step Instructions
Step 1: Create an S3 Bucket for ML Data
Amazon S3 (Simple Storage Service) is the foundational object storage layer for most data analytics and ML workflows on AWS. We need a place to store our image before analyzing it.
bash
aws s3 mb s3://brainybee-ai-lab-<YOUR_ACCOUNT_ID>
[!TIP]
S3 bucket names must be globally unique. Replace <YOUR_ACCOUNT_ID> with your actual 12-digit AWS account number or a unique random string.
▶Console alternative
Log into the AWS Management Console.
Navigate to S3 and click Create bucket.
Enter brainybee-ai-lab-<YOUR_ACCOUNT_ID> as the Bucket name.
Leave all other settings as default and click Create bucket.
Click Add files, select sample-image.jpg from your computer.
Click Upload at the bottom of the screen.
Step 3: Analyze Image with Amazon Rekognition
Amazon Rekognition makes it easy to add image and video analysis to your applications. We will ask Rekognition to detect labels (objects, scenes, concepts) in the image we just uploaded.
Explanation: This command tells Rekognition to look at sample-image.jpg inside your S3 bucket and return the top 5 labels describing what it sees along with a confidence score.
▶Console alternative
Navigate to Amazon Rekognition in the AWS Console.
In the left sidebar, click Label detection.
Under the demo section, upload your sample-image.jpg.
View the resulting tags and confidence scores on the right-hand panel.
Step 4: Analyze Text Sentiment with Amazon Comprehend
Amazon Comprehend uses natural-language processing (NLP) to find insights and relationships in text. Let's analyze a sample review to determine its sentiment (Positive, Negative, Neutral, or Mixed).
bash
aws comprehend detect-sentiment \--text"AWS machine learning services like SageMaker and Comprehend are incredibly powerful and easy to use!"\ --language-code en \--region us-east-1
Explanation: Unlike Rekognition which read from S3, here we are passing the text string directly into the synchronous Comprehend API. You should receive a JSON response indicating a high POSITIVE sentiment score.
Step 5: Extract Entities with Amazon Comprehend
Comprehend can also pull out key entities like Organizations, Locations, Persons, and Dates.
bash
aws comprehend detect-entities \--text"Jeff Bezos founded Amazon in Bellevue, Washington in 1994."\ --language-code en \--region us-east-1
▶Console alternative (Steps 4 & 5)
Navigate to Amazon Comprehend in the AWS Console.
Click Launch Amazon Comprehend.
Scroll down to the Real-time analysis section.
Paste your text into the Input text box.
Click Analyze and explore the Entities and Sentiment tabs below to see the visual output.
Checkpoints
Verify your progress after the steps above to ensure everything is functioning correctly:
Storage Verification: Run aws s3 ls s3://brainybee-ai-lab-<YOUR_ACCOUNT_ID>/.
Expected Output: You should see sample-image.jpg listed with its timestamp and file size.
Rekognition Verification: Review the JSON output from Step 3.
Expected Output: A list of Labels containing a Name (e.g., "Nature", "Dog") and a Confidence score close to 99.0.
Comprehend Verification: Review the JSON output from Step 4.
Expected Output:"Sentiment": "POSITIVE" should be the top-level key.
Troubleshooting
Error Message / Issue
Likely Cause
Solution
InvalidToken or AccessDenied
Your AWS CLI credentials are not configured or have expired.
Run aws configure and provide valid access keys. Ensure your IAM user has S3 and AI service permissions.
BucketAlreadyExists
Another AWS user globally has taken the S3 bucket name.
Change your bucket name to include more random characters.
InvalidS3ObjectException
Rekognition cannot find the image.
Check that the --image JSON string in Step 3 exactly matches your bucket name and file name.
UnrecognizedClientException
The region specified doesn't support the requested AI service.
Append --region us-east-1 to your commands, as US-East-1 supports all AI services.
Cost Estimate
This lab is designed to be highly cost-effective and falls comfortably within the AWS Free Tier if you are eligible:
Amazon S3: Standard storage for one image is a fraction of a cent.
Amazon Rekognition: Free tier includes 1,000 image analyses per month.
Amazon Comprehend: Free tier includes 50,000 units of text (100 characters = 1 unit) per month.
Total Estimated Cost: $0.00
Clean-Up / Teardown
[!WARNING]
Remember to run the teardown commands to avoid ongoing charges. Even though storage costs are negligible, it is best practice to clean up lab environments.
To destroy the resources created in this lab, execute the following commands in your CLI:
This document provides a comprehensive overview of the AWS Certified Cloud Practitioner (CLF-C02) curriculum. This foundational certification validates an individual's overall understanding of the AWS Cloud platform, independent of specific technical roles.
## Prerequisites
While there are no mandatory certifications required before taking the CLF-C02, AWS recommends the following baseline experience to ensure success:
Experience: Approximately six months of exposure to the AWS Cloud in any capacity (technical, managerial, sales, purchasing, or financial).
General IT Knowledge: A basic understanding of information technology (IT) services and how they are integrated into the AWS Cloud platform.
Technical Familiarity: General knowledge of application servers and basic networking concepts.
[!IMPORTANT]
This exam is designed for individuals who want to demonstrate cloud fluency and a high-level understanding of the AWS ecosystem, making it ideal for both technical and non-technical professionals.
## Module Breakdown
The curriculum is divided into four primary domains. Each domain focuses on a critical aspect of cloud operations and strategy.
Curriculum Structure
Loading Diagram...
Figure 1 — Mermaid diagram
Domain
Focus Area
Key Elements
Domain 1
Cloud Concepts
Value proposition, Cloud economics, and Well-Architected Framework.
Domain 2
Security & Compliance
Shared Responsibility Model, AWS IAM, and security best practices.
Domain 3
Cloud Technology
Compute (EC2/Lambda), Storage (S3), Database (RDS), and Networking.
Domain 4
Billing & Pricing
Pricing models (On-Demand vs. Reserved), AWS Budgets, and Support plans.
## Learning Objectives per Module
Domain 1: Cloud Concepts
Objective: Define the AWS Cloud and its value proposition.
Example: Understanding how "Agility" allows a startup to launch global applications in minutes rather than weeks.
Domain 2: Security and Compliance
Objective: Describe the AWS Shared Responsibility Model.
Example: AWS is responsible for the security of the cloud (physical data centers), while the customer is responsible for security in the cloud (patching their own guest OS).
Domain 3: Cloud Technology and Services
Objective: Identify core AWS services for common use cases.
Example: Using Amazon S3 for durable object storage (like hosting static website images) versus Amazon EC2 for scalable virtual servers.
Domain 4: Billing, Pricing, and Support
Objective: Compare various pricing models and support tools.
Example: Utilizing AWS Cost Explorer to visualize and forecast spending patterns over a 12-month period.
## Success Metrics
To pass the CLF-C02 examination, candidates must meet specific scoring criteria and demonstrate proficiency across all domains.
Scoring Breakdown
Score Range: 100 to 1000 points.
Passing Threshold: A minimum scaled score of 700 is required.
Question Format: Multiple choice (one correct) and Multiple response (two or more correct).
Loading Diagram...
Figure 2 — Mermaid diagram
[!TIP]
The exam includes 15 unscored questions used by AWS for evaluation. These do not affect your final grade, but they are not identified, so treat every question as if it counts.
## Real-World Application
Achieving the AWS Cloud Practitioner certification is not just about passing an exam; it provides the foundational language for modern business technology.
Career Progression: It serves as the prerequisite or "stepping stone" toward Associate-level certifications, such as AWS Certified Solutions Architect or AWS Certified Developer.
Cross-Functional Collaboration: Enables sales, marketing, and legal teams to communicate effectively with engineering departments regarding cloud costs and security requirements.
Strategic Migration: Helps decision-makers understand the Well-Architected Framework, ensuring that cloud migrations are cost-effective, secure, and reliable.
▶Click to expand: Key Core Service Real-World Examples
Amazon EC2: Virtual machines for running custom software.
AWS Lambda: Serverless functions that run code only when triggered by events (e.g., a file upload).
Amazon RDS: Managed relational databases (SQL) that handle their own backups and patching.
Amazon VPC: A private, isolated section of the AWS Cloud where you can launch resources in a virtual network you define.
In the left navigation pane, choose Account settings.
Under Password policy, click Edit.
Select Custom and check the boxes for uppercase, lowercase, numbers, and non-alphanumeric characters.
Set the minimum password length to 14.
Check Allow users to change their own password.
Click Save changes.
📸 Screenshot: The IAM Account Settings page showing custom password policy checkboxes.
[!TIP]
The Principle of Least Privilege states that users should only be granted the permissions necessary to perform their specific job functions. Combining strict password policies with Multi-Factor Authentication (MFA) is a critical best practice.
Step 2: Enable Amazon GuardDuty for Threat Detection
Amazon GuardDuty is a machine-learning-powered threat detection service that continuously monitors malicious activity and unauthorized behavior.
bash
aws guardduty create-detector --enable
Note: This command will output a DetectorId. You do not need to save it for this lab.
▶Console alternative
Navigate to GuardDuty in the AWS Management Console.
Click Get Started.
Click the Enable GuardDuty button.
📸 Screenshot: The GuardDuty welcome screen with the blue "Enable GuardDuty" button.
Step 3: Securely Store Credentials in AWS Secrets Manager
Hardcoding passwords in application code is a major security vulnerability. AWS Secrets Manager allows you to securely store, rotate, and manage API keys and database passwords.
Expected Result: A JSON response containing your secret string with the username and password.
Clean-Up / Teardown
[!WARNING]
Remember to run the teardown commands to avoid ongoing charges. GuardDuty offers a 30-day free trial, but Secrets Manager charges per secret stored.
Execute the following commands to delete the resources created in this lab:
1. Delete the IAM Password Policy (Reverts to AWS defaults):
bash
aws iam delete-account-password-policy
2. Delete the Secret (forces immediate deletion without a recovery window):
Ensure your CLI user has AdministratorAccess or specific policies for IAM, GuardDuty, and Secrets Manager attached.
ResourceExistsException
A secret with the name brainybee-lab-db-secret already exists.
Delete the existing secret or choose a different name for your lab secret.
InvalidInputException (IAM)
Invalid password policy parameters.
Ensure you copy the exact CLI arguments or check the correct boxes in the console.
Stretch Challenge
Now that you have enabled GuardDuty, try enabling AWS Security Hub. Security Hub aggregates findings from GuardDuty, Inspector, and Macie into a single pane of glass.
Your Challenge: Use the AWS CLI to enable AWS Security Hub and manually trigger a sample GuardDuty finding to see it appear in the Security Hub console.
▶Show solution
bash
# Enable Security Hubaws securityhub enable-security-hub --enable-default-standards
# Get your GuardDuty Detector IDDETECTOR_ID=$(aws guardduty list-detectors --query'DetectorIds[0]'--output text)# Generate sample findings in GuardDuty (which will sync to Security Hub)aws guardduty create-sample-findings --detector-id $DETECTOR_ID
Navigate to Security Hub in the console to view the aggregated sample findings.
Cost Estimate
This lab falls largely under the AWS Free Tier, assuming your account is eligible and you clean up promptly:
IAM / CloudTrail Event History: Always free.
Amazon GuardDuty: 30-day free trial for new accounts. Afterward, priced based on log volume analyzed.
AWS Secrets Manager: $0.40 per secret per month. If deleted immediately using --force-delete-without-recovery, the prorated cost will be $0.00.
Concept Review
Security and Compliance in the AWS Cloud are governed by the Shared Responsibility Model. AWS is responsible for the security OF the cloud (infrastructure, physical data centers), while you (the customer) are responsible for security IN the cloud (your data, password policies, firewall rules).
The CIA Triad
AWS security measures are built around the CIA Triad:
Compiling TikZ diagram…
⏳
Running TeX engine…
This may take a few seconds
Figure 2 — TikZ diagram
Confidentiality: Ensuring data is encrypted (e.g., KMS) and access is strictly controlled (e.g., IAM, Secrets Manager).
Integrity: Ensuring data is not altered.
Availability: Ensuring systems and data remain accessible.
AWS Security Service Comparison
Understanding the differences between AWS threat detection and compliance tools is essential for the Cloud Practitioner exam:
Service
Primary Use Case
Key Mechanism
Amazon GuardDuty
Continuous threat detection
Machine learning analysis of CloudTrail, VPC Flow Logs, and DNS logs.
Amazon Inspector
Vulnerability assessment
Scans EC2 instances and container images for software vulnerabilities.
AWS CloudTrail
API Auditing
Records user activity and API calls for governance and compliance.
AWS Secrets Manager
Credential management
Securely stores and automatically rotates database passwords and API keys.
Amazon Macie
Data privacy and protection
Uses machine learning to discover and protect sensitive data (PII) in Amazon S3.
AWS Artifact
Regulatory compliance
On-demand access to AWS security and compliance reports (e.g., SOC, PCI).
These tools combined allow organizations to build highly secure architectures that adhere strictly to industry compliance standards while leveraging the elastic nature of the AWS cloud.
Curriculum Overview685 words
AWS Cloud Security, Governance, and Compliance: Curriculum Overview
AWS Cloud security, governance, and compliance concepts
AWS Cloud Security, Governance, and Compliance: Curriculum Overview
This curriculum provides a structured path to mastering the foundational security, governance, and compliance concepts required for the AWS Certified Cloud Practitioner (CLF-C02) exam. It focuses on the Shared Responsibility Model, AWS security services, and regulatory compliance tools.
Prerequisites
Before starting this curriculum, students should have a baseline understanding of the following:
Cloud Computing Basics: Familiarity with on-demand delivery, pay-as-you-go pricing, and scalability.
Foundational AWS Concepts: Basic knowledge of the AWS Management Console and core services (Compute, Storage, Networking).
General Security Concepts: A high-level understanding of what firewalls, encryption, and user passwords are used for in traditional IT.
Module Breakdown
Module
Focus Area
Difficulty
Est. Time
1. The Shared Responsibility Model
Defining the line between AWS and Customer duties.
Beginner
2 Hours
2. Security Governance & Compliance
AWS Artifact, compliance programs, and auditing.
Intermediate
3 Hours
3. Threat Detection & Monitoring
Amazon GuardDuty, Inspector, and Security Hub.
Intermediate
4 Hours
4. Data Protection & Encryption
KMS, CloudHSM, Encryption at Rest vs. In Transit.
Advanced
3 Hours
Module Objectives
Module 1: The Shared Responsibility Model
Objective: Distinguish between "Security OF the Cloud" and "Security IN the Cloud."
Key Skill: Describe how responsibilities shift when moving from IaaS (EC2) to PaaS (RDS) or SaaS (Lambda).
Module 2: Compliance & Governance
Objective: Identify where to find AWS compliance reports and how to manage multiple accounts.
Key Skill: Use AWS Artifact to download SOC or HIPAA reports for auditing purposes.
Module 3: Security Monitoring
Objective: Understand the purpose of automated security assessment services.
Key Skill: Differentiate between Amazon GuardDuty (threat detection) and Amazon Inspector (vulnerability scanning).
Visual Anchors
The Shared Responsibility Model
Loading Diagram...
Figure 1 — Mermaid diagram
The Security (CIA) Triad
Compiling TikZ diagram…
⏳
Running TeX engine…
This may take a few seconds
Figure 2 — TikZ diagram
Success Metrics
To demonstrate mastery of this curriculum, the learner must be able to:
Map Services to Needs: Correctly identify which service to use for a specific security task (e.g., "Which service finds PII?" → Amazon Macie).
Compliance Literacy: Locate and explain the significance of a SOC 2 report within AWS Artifact.
Scenario Analysis: Given a scenario (e.g., an EC2 instance is compromised), identify whether the fix is the customer's or AWS's responsibility.
Security Hub Integration: Explain how AWS Security Hub aggregates findings from GuardDuty and Inspector into a single dashboard.
[!IMPORTANT]
Domain 2 (Security and Compliance) represents 30% of the scored content on the CLF-C02 exam. Mastering these concepts is critical for passing.
Real-World Application
Compliance Officer: Use AWS Artifact to provide evidence of security controls to external auditors during annual certifications.
Security Operations (SecOps): Set up Amazon GuardDuty to automatically alert the team if an unauthorized user attempts to access an S3 bucket from a malicious IP address.
Cloud Architect: Implement encryption at rest using AWS KMS to ensure that even if physical storage media were stolen, the data would remain unreadable.
▶Click to expand: Service Comparison Table
Service
Primary Function
Real-World Example
AWS Shield
DDoS Protection
Protecting a web app from being overwhelmed by fake traffic.
AWS WAF
Web Traffic Filtering
Blocking SQL injection attacks on a login page.
Amazon Inspector
Vulnerability Scanning
Finding out if your EC2 instance has an outdated, insecure software version.
AWS KMS
Key Management
Managing the digital keys used to encrypt your database.
Hands-On Lab948 words
AWS Security, Governance, and Compliance: Foundational Controls Lab
AWS Cloud security, governance, and compliance concepts
AWS Security, Governance, and Compliance: Foundational Controls Lab
Welcome to this hands-on lab covering Domain 2 of the AWS Certified Cloud Practitioner (CLF-C02) exam. In this lab, you will apply the AWS Shared Responsibility Model by implementing critical security and compliance controls "IN" the cloud. You will enable threat detection, enforce encryption at rest, configure public access blocks, and practice least-privilege IAM policies.
Prerequisites
Before starting this lab, ensure you have the following:
AWS Account: Access to an AWS account with Administrator privileges.
AWS CLI Installed: The AWS Command Line Interface installed and configured on your local machine.
IAM Credentials: Your CLI must be authenticated using aws configure with an Access Key and Secret Access Key.
Prior Knowledge: Basic understanding of Amazon S3, IAM, and the concepts of encryption.
Learning Objectives
By completing this lab, you will be able to:
Enable and interpret findings in Amazon GuardDuty (Continuous Threat Detection).
Secure an Amazon S3 bucket using Server-Side Encryption (Encryption at Rest) and Public Access Blocks.
Implement IAM least-privilege access management for cloud resources.
Understand the practical application of the AWS Shared Responsibility Model.
Architecture Overview
The following diagrams illustrate the infrastructure you will build and how it maps to the AWS Shared Responsibility Model.
Lab Infrastructure
Loading Diagram...
Figure 1 — Mermaid diagram
AWS Shared Responsibility Context
Loading Diagram...
Figure 2 — Mermaid diagram
Step-by-Step Instructions
Step 1: Enable Amazon GuardDuty for Threat Detection
Amazon GuardDuty is an intelligent threat detection service that continuously monitors for malicious activity and unauthorized behavior. As a customer, enabling it fulfills your responsibility to monitor your AWS environment.
bash
# Enable GuardDuty in your current region and capture the detector IDaws guardduty create-detector --enable# Note the detectorId from the output. Replace <DETECTOR_ID> below with your ID.aws guardduty create-sample-findings --detector-id <DETECTOR_ID>
[!TIP]
Generating sample findings populates the GuardDuty console with mock data (like simulated Bitcoin mining or unauthorized API calls) so you can see what actual threats look like without needing a real security incident.
▶Console alternative
Navigate to the GuardDuty console.
Click Get Started and then click Enable GuardDuty.
In the left navigation pane, choose Settings.
Scroll down to Sample findings and click Generate sample findings.
Go back to the Findings page in the left pane to view the generated threats.
📸 Screenshot: A list of findings with severity tags (High, Medium, Low).
Step 2: Create a Secure, Encrypted S3 Bucket
Data security requires "Encryption at Rest." We will create an S3 bucket, enable default AES-256 encryption, and apply a strict "Block Public Access" configuration.
Note: Replace <YOUR_ACCOUNT_ID> with your actual 12-digit AWS account number to ensure the bucket name is globally unique.
Navigate to the S3 console and click Create bucket.
Enter brainybee-secure-data-<YOUR_ACCOUNT_ID> for the Bucket name.
In the Block Public Access settings for this bucket section, ensure Block all public access is CHECKED.
Scroll to Default encryption, ensure Server-side encryption is Enabled, and Encryption key type is Amazon S3 managed keys (SSE-S3).
Click Create bucket.
📸 Screenshot: The S3 bucket creation screen highlighting the "Block all public access" checkbox.
Step 3: Implement Least Privilege with IAM
Identity and Access Management (IAM) is a core piece of the customer's shared responsibility. We will create a policy that grants only read access to the specific S3 bucket you just created.
bash
# 1. Create the policy JSON file locallycat<<EOF> s3-read-only-policy.json{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::brainybee-secure-data-<YOUR_ACCOUNT_ID>",
"arn:aws:s3:::brainybee-secure-data-<YOUR_ACCOUNT_ID>/*"
]
}
]
}
EOF# 2. Create the IAM Policy in AWSaws iam create-policy \ --policy-name BrainyBeeS3ReadOnly \ --policy-document file://s3-read-only-policy.json
▶Console alternative
Navigate to the IAM console.
In the left navigation pane, choose Policies, then click Create policy.
Switch to the JSON tab and paste the JSON from the code block above (ensure you replace <YOUR_ACCOUNT_ID>).
Click Next, name the policy BrainyBeeS3ReadOnly, and click Create policy.
📸 Screenshot: The IAM visual editor showing "Limited: Read" access to a specific S3 resource.
Checkpoints
Verify that your configurations were applied correctly by running the following commands:
Checkpoint 1: Verify GuardDuty is Active
bash
aws guardduty list-detectors
# Expected result: A JSON array containing your active DetectorId.
aws s3api get-public-access-block --bucket brainybee-secure-data-<YOUR_ACCOUNT_ID># Expected result: JSON output showing all four Block/Ignore rules set to "true".
Troubleshooting
Error Message / Issue
Likely Cause
Solution
BucketNameAlreadyExists
Another AWS user already took this S3 bucket name.
Ensure you appended your unique 12-digit AWS Account ID to the bucket name.
AccessDenied when creating the IAM Policy
Your CLI user lacks IAM permissions.
Verify you are using credentials for a user with AdministratorAccess or IAMFullAccess.
An error occurred (BadRequestException) in GuardDuty
GuardDuty might already be enabled in this region.
Run aws guardduty list-detectors to get the existing Detector ID instead of creating a new one.
Clean-Up / Teardown
[!WARNING]
Cost Warning: Amazon GuardDuty offers a 30-day free trial. If left running after the trial, you will incur ongoing charges based on the volume of CloudTrail and VPC Flow Logs analyzed. Run these teardown commands to avoid unexpected costs.
Execute the following commands to delete all resources provisioned in this lab:
bash
# 1. Delete the IAM Policy (Replace <YOUR_ACCOUNT_ID>)aws iam delete-policy --policy-arn arn:aws:iam::<YOUR_ACCOUNT_ID>:policy/BrainyBeeS3ReadOnly
# 2. Delete the S3 Bucket (Bucket must be empty first!)aws s3 rm s3://brainybee-secure-data-<YOUR_ACCOUNT_ID>--recursiveaws s3api delete-bucket --bucket brainybee-secure-data-<YOUR_ACCOUNT_ID># 3. Disable and Delete GuardDuty (Replace <DETECTOR_ID> with your detector ID)aws guardduty delete-detector --detector-id <DETECTOR_ID># 4. Remove local filerm s3-read-only-policy.json
[!NOTE]
If you enabled GuardDuty via the console, you can disable it by navigating to GuardDuty > Settings > Suspend or Disable GuardDuty and clicking Disable GuardDuty.
This document provides a comprehensive roadmap for mastering the AWS Cloud Value Proposition, focusing on the economic, operational, and strategic benefits of migrating to the Amazon Web Services ecosystem. This curriculum aligns with the AWS Certified Cloud Practitioner (CLF-C02) exam objectives.
## Prerequisites
Before beginning this curriculum, candidates should possess the following foundational knowledge:
General IT Knowledge: Basic understanding of information technology services and their use in business.
Infrastructural Basics: Familiarity with the concepts of servers, networking, and storage.
Recommended Experience: AWS suggests at least six months of experience with the AWS Cloud in any role (technical, managerial, sales, or financial).
Business Context: A basic understanding of the difference between capital investments and operational expenses.
## Module Breakdown
Module
Title
Focus Area
Difficulty
1
Benefits of the AWS Cloud
Speed, Agility, and Global Reach
Introductory
2
Design Principles
AWS Well-Architected Framework
Intermediate
3
Migration Strategies
AWS CAF & Cloud Transformation
Intermediate
4
Cloud Economics
CapEx vs. OpEx, Economies of Scale
Foundational
Loading Diagram...
Figure 1 — Mermaid diagram
## Learning Objectives per Module
Module 1: Benefits of the AWS Cloud
Define Agility: Understand how AWS increases speed of deployment and fosters experimentation.
Global Infrastructure: Explain the benefits of global reach for reducing latency and providing high availability.
Elasticity vs. Scalability: Distinguish between the ability to handle growth and the ability to shrink resources based on demand.
Module 2: Design Principles
Well-Architected Framework: Identify and define the six pillars of the framework.
[!IMPORTANT]
The Well-Architected Framework is essential for building secure, high-performing, resilient, and efficient infrastructure.
The CAF Perspectives: Understand the six perspectives: Business, People, Governance, Platform, Security, and Operations.
Value Chain: Describe the transformation of technology, processes, and organizations.
Module 4: Cloud Economics
Cost Models: Compare Capital Expenses (CapEx) with Operating Expenses (OpEx).
Metered Payment: Explain the "pay-as-you-go" model and how it relates to rightsizing and automation.
## Success Metrics
To determine mastery of the AWS Cloud Value Proposition, you should be able to:
Articulate the "Big Idea": Explain why a university would "terminate" millions of CPUs after a weekend rather than buying them (CapEx avoidance).
Pillar Identification: Given a scenario (e.g., "reducing carbon footprint"), identify the relevant Well-Architected Pillar (Sustainability).
Economic Justification: Calculate the theoretical benefit of Economies of Scale (lower prices due to AWS's massive volume).
Migration Readiness: Identify which AWS CAF perspective addresses "reduced business risk" or "increased revenue."
Concept
Metric of Mastery
Rightsizing
Ability to choose the instance type that matches the workload precisely without waste.
Agility
Explaining how CloudFormation templates allow for instant experimentation.
High Availability
Designing for automated "failover" across geographically remote locations.
## Real-World Application
Case Study: High-Speed Experimentation
In traditional IT, testing a new AI model required purchasing physical servers (weeks of procurement). In the AWS environment, a large university can spin up hundreds of thousands of EC2 virtual machines for a single weekend of testing.
The Result: The university pays only for the hours used (metered billing) and avoids the massive overhead of unneeded idle hardware.
Career Impact
Understanding the value proposition allows professionals in Sales, Finance, and Management to:
Build business cases for cloud migration.
Optimize existing cloud spend to increase ROI.
Leverage AWS global reach to enter new markets in minutes rather than months.
[!TIP]
Always remember: In the cloud, infrastructure is temporary and disposable, not a permanent asset to be maintained at all costs.
AWS Certified Cloud Practitioner (CLF-C02) Practice Questions
Try 15 sample questions from a bank of 1,047. Answers and detailed explanations included.
Q1medium
A company holds unexpired licences for software it intends to keep running on AWS. Which licensing approach fits?
A.
An included licence, because it is always the cheaper option.
B.
Neither, because existing licences cannot be used in the cloud.
C.
An included licence, because bringing your own removes the need to track compliance.
D.
Bring Your Own License, re-purposing its existing licence inventory for its cloud resources.
Show answer & explanation
Correct Answer: D
An included licence, because it is always the cheaper option.: Incorrect. Neither model is documented as always cheaper; an included licence adds cost the company has already paid for elsewhere.
Neither, because existing licences cannot be used in the cloud.: Incorrect. Re-purposing existing licence inventory for cloud resources is exactly what the documented model permits.
An included licence, because bringing your own removes the need to track compliance.: Incorrect. Bringing your own leaves you holding the compliance obligation; an included licence is what removes the separate tracking.
Bring Your Own License, re-purposing its existing licence inventory for its cloud resources.: Correct. AWS states that you can save costs by using Bring Your Own License model opportunities — that is, you can re-purpose your existing licence inventory for use with your cloud resources.
Answer: D
Q2easy
Which AWS resource provides a curated collection of articles and videos created by AWS experts to help customers troubleshoot common technical challenges and find answers to frequent questions?
A.
AWS Support Center
B.
AWS Knowledge Center
C.
AWS re:Post
D.
AWS Health Dashboard
Show answer & explanation
Correct Answer: B
The AWS Knowledge Center is the correct resource because it contains a curated set of articles and videos developed by AWS experts to address the most common technical questions and troubleshooting scenarios encountered by customers. While the AWS Support Center is used for managing private support cases, AWS re:Post is a community-driven discussion forum, and the AWS Health Dashboard provides real-time information on the operational status of AWS services, the Knowledge Center is specifically designed for authoritative 'how-to' guidance and frequent FAQ resolution.
Q3medium
A startup in the healthcare sector is preparing to launch a new application on AWS that will store and process Protected Health Information (PHI). To ensure compliance with HIPAA regulations, the company must enter into a legal agreement with AWS. Which AWS service provides a central repository for on-demand access to this required agreement and other security and compliance reports?
A.
AWS Secrets Manager
B.
AWS Trusted Advisor
C.
AWS Artifact
D.
AWS Shield
Show answer & explanation
Correct Answer: C
The correct answer is AWS Artifact. AWS Artifact is the central, self-service repository for on-demand access to AWS's security and compliance reports and select online agreements. For organizations in the healthcare industry, AWS Artifact is used to review and accept the Business Associate Addendum (BAA), a legal requirement for HIPAA compliance. It also provides reports like the PCI DSS Attestation of Compliance (AOC) for the finance industry and FedRAMP documents for the public sector. AWS Trusted Advisor provides guidance on security and cost optimization but not legal agreements. AWS Secrets Manager is for credential rotation and management. AWS Shield is a managed DDoS protection service.
Q4medium
An organization is planning to migrate a complex legacy application suite to the AWS Cloud and is looking for proven methodologies and vetted architectural patterns to accelerate the process. Which of the following best explains the role of AWS Prescriptive Guidance (APG) in this scenario?
A.
It is a premium support tier that assigns a dedicated Technical Account Manager (TAM) to lead the organization's architectural discovery and design sessions.
B.
It serves as a real-time AI-powered assistant that automatically reviews application code and suggests troubleshooting steps for serverless functions.
C.
It is a central repository for mandatory legal and compliance documents required for regulated industries like healthcare and finance.
D.
It provides a library of time-tested strategies, guides, and patterns vetted by AWS experts to provide actionable roadmaps for migration and modernization.
Show answer & explanation
Correct Answer: D
AWS Prescriptive Guidance (APG) is designed to provide customers with a library of deployment-ready strategies, guides, and patterns. These resources are vetted by AWS professional services and partners based on real-world customer engagements.
Step-by-step reasoning:
Identify the Core Value: APG focuses on prescriptive advice, meaning it tells you how to do something (e.g., the '7 Rs' of migration) rather than just what a service does.
Analyze Distractors:
Option B describes tools like Amazon Q or Amazon CodeGuru.
Option C describes AWS Artifact, which handles compliance reports and agreements.
Option A describes AWS Enterprise Support, which provides access to a Technical Account Manager (TAM).
Conclusion: Because the organization needs 'proven methodologies' and 'vetted patterns' to accelerate migration, APG is the correct resource.
Q5medium
An organisation must apply the same protections consistently across twelve AWS accounts. Which service is designed for that?
A.
AWS WAF, by writing the same rules in each account.
B.
Amazon GuardDuty, by detecting inconsistencies.
C.
AWS Marketplace, by procuring a management product.
D.
AWS Firewall Manager, which simplifies administration across multiple accounts and resources.
Show answer & explanation
Correct Answer: D
AWS WAF, by writing the same rules in each account.: Incorrect. That is the manual approach Firewall Manager exists to replace; WAF itself acts within its own scope.
Amazon GuardDuty, by detecting inconsistencies.: Incorrect. GuardDuty detects threats from data sources and logs; it does not administer protections.
AWS Marketplace, by procuring a management product.: Incorrect. A native service is documented for exactly this need, so procuring a third-party one is not the fitting answer.
AWS Firewall Manager, which simplifies administration across multiple accounts and resources.: Correct. AWS states that Firewall Manager simplifies your administration and maintenance tasks across multiple accounts and resources for a variety of protections, including AWS WAF, AWS Shield Advanced, Amazon VPC security groups and network ACLs, and AWS Network Firewall.
Answer: D
Q6easy
When configuring AWS Security Groups to control traffic to an Amazon EC2 instance, what does it mean that Security Groups are 'stateful'?
A.
Return traffic for an allowed inbound request is automatically permitted, regardless of outbound rules.
B.
Both inbound and outbound rules must be explicitly configured to allow a complete communication cycle.
C.
The security group automatically scales its rules based on the volume of incoming network traffic.
D.
Traffic is filtered at the subnet level rather than at the individual network interface level.
Show answer & explanation
Correct Answer: A
AWS Security Groups are stateful, which means they automatically track the state of network connections. If an inbound request is allowed by a rule, the response (return traffic) from the instance is automatically permitted to flow out, even if no outbound rule explicitly allows it. Conversely, if outbound traffic is initiated and allowed, the return traffic is allowed back in. This differs from Network ACLs, which are stateless and require explicit rules for traffic in both directions. Therefore, Option A is the correct description of stateful behavior.
Q7hard
An enterprise is analyzing a strategic shift from its traditional on-premises data center infrastructure to a cloud-based model. The two models present the following cost structures:
Cost Component
Traditional Model
Cloud Model
Annual Fixed Costs
$100,000
$20,000
Variable Cost per Unit
2
6
Selling Price per Unit
10
10
Assuming the business experiences volatile demand cycles that fluctuate between $10,000 and $40,000 units annually, which of the following best analyzes the impact of this transition on the firm's profitability and risk profile?
A.
The Cloud model is the more profitable choice at all volume levels above $5,000 units because the reduction in fixed costs outweighs the unit cost premium at any scale.
B.
The Cloud model increases the break-even point to $20,000 units because the higher variable costs offset the fixed cost savings, making the business more susceptible to losses during demand downturns.
C.
Transitioning to the Cloud model eliminates operating leverage, ensuring that the net profit margin remains constant at 40% across both the $10,000 and $40,000 unit utilization levels.
D.
The Cloud model lowers the break-even point from $12,500 to $5,000 units, providing superior downside protection during low-demand periods, but results in lower total profits at $40,000 units due to a lower contribution margin.
Show answer & explanation
Correct Answer: D
To analyze the impact, we must calculate the Break-Even Point (BEP) and the profits at different demand levels for both models.
Insight: The Cloud model significantly lowers the risk threshold for profitability.
Analyze Profit at Low Demand ($10,000 units):
Traditional:(10,000×8)−100,000=−20,000 (Loss).
Cloud:(10,000×4)−20,000=+20,000 (Profit).
Analyze Profit at High Demand ($40,000 units):
Traditional:(40,000×8)−100,000=220,000.
Cloud:(40,000×4)−20,000=140,000.
Conclusion: The transition de-risks the business by lowering the BEP (downside protection), but it reduces operating leverage. Because the contribution margin per unit is lower in the Cloud model (4 vs 8), the business captures less profit during periods of high growth.
Q8easy
In the context of the AWS Well-Architected Framework and cost management, which of the following best defines the concept of rightsizing?
A.
Automatically increasing or decreasing the number of active instances in a group based on real-time traffic demand.
B.
The process of matching instance types and sizes to your workload performance and capacity requirements at the lowest possible cost.
C.
Distributing incoming application traffic across multiple Availability Zones to ensure high availability and fault tolerance.
D.
The practice of purchasing Reserved Instances for a one-year or three-year term to receive a significant discount compared to On-Demand pricing.
Show answer & explanation
Correct Answer: B
Rightsizing is a fundamental practice within the Cost Optimization pillar of the AWS Well-Architected Framework. It involves continuously evaluating your resource utilization to ensure that instance types and sizes are aligned with actual workload needs.
Identify Utilization: Determine if a resource is over-provisioned (e.g., an instance with CPU utilization ≤10%).
Match to Requirements: Select the smallest and most cost-effective instance type that still fulfills the performance and capacity requirements of the specific task.
Eliminate Waste: This process ensures that you are not paying for idle or underutilized capacity.
Option A describes Auto Scaling, which focuses on the quantity of instances.
Option C describes Load Balancing and High Availability.
Option D describes Commitment-based savings, which is a different cost-saving strategy.
Q9hard
A developer is architecting a collaborative mobile application using AWS Amplify DataStore and AWS AppSync. The application must support multiple users modifying different attributes of the same record while offline (e.g., User A updates status, while User B updates description). Which configuration and schema design should be synthesized to ensure that these field-level updates are merged seamlessly without requiring a 'Full Sync' or causing synchronization failures when devices reconnect?
A.
Enable Conflict Detection on the AppSync API with the 'Automerge' resolution strategy, and ensure the GraphQL schema includes the _version, _lastChangedAt, and _deleted metadata fields.
B.
Enable Conflict Detection on the AppSync API with 'Optimistic Concurrency' resolution, and utilize a DynamoDB Stream to manually increment the version field for every field-level change.
C.
Configure the Amplify client to use 'Manual Sync' mode and implement a background service that polls the AppSync endpoint for changes using the list operation every time connectivity is restored.
D.
Enable Conflict Detection on the AppSync API with 'Lambda' resolution to compare the local and remote state, while keeping the GraphQL schema free of metadata to minimize payload size.
Show answer & explanation
Correct Answer: A
To achieve seamless offline synchronization and collaborative editing in AWS Amplify DataStore, the following must be synthesized:
Conflict Resolution Strategy: The Automerge strategy is specifically designed for collaborative environments. Unlike Optimistic Concurrency, which rejects a write if the version has changed (causing the entire update to fail), Automerge merges non-overlapping field updates from different clients. If User A changes Field X and User B changes Field Y, Automerge preserves both.
Schema Metadata: DataStore relies on the Delta Sync protocol. For this to work, the GraphQL schema must include specific metadata:
_version: An incrementing integer used to track the record state.
_lastChangedAt: A server-side timestamp used for fetching only the changes (deltas) since the last sync.
_deleted: A boolean flag used for soft deletes, ensuring the local store can purge records that were deleted remotely.
Delta Sync Protocol: This avoids the inefficiency of a 'Full Sync' by allowing the client to only request records modified since its last known _lastChangedAt value.
Option B is incorrect because Optimistic Concurrency would cause one of the two users' updates to be rejected entirely upon a version mismatch. Option C is incorrect because manual polling and Full Sync are anti-patterns for DataStore's reactive model. Option D is incorrect because metadata fields are strictly required in the schema for DataStore's sync engine to function.
Therefore, Option A is the correct configuration.
Q10hard
An organization is evaluating its operational overhead regarding security maintenance across different compute and database service models. The architecture includes Amazon EC2 for custom legacy applications, Amazon RDS for primary relational data, and AWS Lambda for event-driven processing. According to the AWS Shared Responsibility Model, which of the following statements accurately analyzes the shift in patch management responsibilities as the organization transitions from unmanaged to serverless services?
A.
AWS manages the host operating system in EC2 and the guest operating system in RDS, but the customer remains responsible for patching the database engine in RDS and the language runtime in Lambda to maintain version control.
B.
In Amazon EC2, the customer is responsible for patching the guest operating system and applications, while in RDS and Lambda, AWS assumes responsibility for patching the underlying operating system and the database engine or managed language runtime.
C.
In an EC2 environment, AWS provides a standard service for automated guest OS patching that transfers responsibility to AWS, whereas in Lambda, the customer must manually apply security patches to the specific runtime environment they select.
D.
In EC2, the customer is responsible for the physical host and hypervisor (Host OS) maintenance, while AWS handles the Guest OS patching to ensure that the virtualized environment remains secure and compliant.
Show answer & explanation
Correct Answer: B
To analyze the shift in patch management, we must look at where the boundary of 'Security of the Cloud' (AWS) ends and 'Security in the Cloud' (Customer) begins:
Amazon EC2 (Infrastructure as a Service - IaaS): AWS is responsible for the physical infrastructure and the virtualization layer (Host OS). The customer has full control over the instance and is therefore responsible for patching the Guest OS (e.g., Windows/Linux) and any installed applications.
Amazon RDS (Managed Service): This is a platform-level service where AWS manages the underlying operating system and the database engine software (e.g., MySQL, PostgreSQL). The customer is responsible for data, access control, and schema management, but AWS handles the patching of both the OS and the engine.
AWS Lambda (Serverless): This model abstracts all infrastructure. AWS is responsible for the OS and the managed language runtime (e.g., Node.js, Python). The customer is only responsible for the security of their own code.
Option A is incorrect because AWS, not the customer, patches the RDS engine and the Lambda runtime.
Option C is incorrect because Guest OS patching in EC2 is a customer responsibility (unless using extra services like Systems Manager Patch Manager, but the responsibility still lies with the customer), and Lambda runtimes are fully managed by AWS.
Option D is incorrect because the Host OS (Hypervisor) is always an AWS responsibility, and the Guest OS in EC2 is always a customer responsibility.
Q11hard
A team creates a full-size test environment for one afternoon, runs its tests, and then removes it. Which advantage does this practice best illustrate?
A.
Agility, because a production-scale test environment can be created on demand and decommissioned afterwards.
B.
High availability, because testing at full scale proves the workload survives failure.
C.
Economies of scale, because the test costs less than owning the hardware.
D.
Global reach, because the environment can be built in any Region.
Show answer & explanation
Correct Answer: A
Agility, because a production-scale test environment can be created on demand and decommissioned afterwards.: Correct. The Well-Architected Framework gives exactly this as a design principle: in the cloud you can create a production-scale test environment on demand, complete your testing, and then decommission the resources.
High availability, because testing at full scale proves the workload survives failure.: Incorrect. Creating a test environment says nothing about tolerating the loss of a data centre, which is what high availability concerns.
Economies of scale, because the test costs less than owning the hardware.: Incorrect. The lower unit price comes from aggregated demand across customers; the practice described is about creating and removing an environment quickly.
Global reach, because the environment can be built in any Region.: Incorrect. Global reach is about serving customers from nearer locations, which is not what a short-lived test environment demonstrates.
Answer: A
Q12medium
A developer is building a high-performance Python application that needs to interact with Amazon S3 and Amazon DynamoDB. To meet AWS security and reliability requirements, the application must implement AWS Signature Version 4 for request signing and handle exponential backoff for retries during transient failures. What is the most efficient and standard practice for implementing this functionality?
A.
Develop a custom module using the Python requests library that manually calculates HMAC-SHA256 signatures for the Authorization header.
B.
Use the AWS SDK for Python (Boto3) to interact with services directly within the application code.
C.
Execute AWS CLI commands through Python's subprocess or os.system() modules and parse the resulting JSON string.
D.
Use the AWS Management Console to manually monitor and trigger resource actions in response to application logs.
Show answer & explanation
Correct Answer: B
The most efficient and robust way to integrate AWS services into custom code is by using the AWS Software Development Kit (SDK).
Abstraction: SDKs provide language-specific libraries (like Boto3 for Python) that abstract the complexity of underlying REST APIs.
Security: They automatically handle the cryptographic signing process (AWS Signature Version 4), which involves complex hashing of request data: Signature = HMAC-SHA256(SigningKey, StringToSign).
Reliability: SDKs include built-in logic for automatic retries and exponential backoff, which are critical for handling transient network errors.
Option C (CLI shell calls) is inefficient due to overhead and parsing complexity. Option A (manual HTTP/HMAC) is error-prone and difficult to maintain. Option D is a manual process and cannot be integrated into automated application logic. The AWS SDK (Boto3) is the standard tool for this use case.
Q13easy
Which of the following describes the primary financial shift an organization experiences when moving from an on-premises data center to a cloud computing model?
A.
The requirement for larger up-front payments for physical server hardware and data center cooling
B.
A shift from variable operating expenses (OpEx) to higher fixed capital expenditures (CapEx)
C.
The total elimination of all operating costs through the use of one-time perpetual software licenses
D.
A shift from fixed capital expenditures (CapEx) to variable operating expenses (OpEx)
Show answer & explanation
Correct Answer: D
Moving from on-premises infrastructure to the cloud involves a transition from Capital Expenditures (CapEx) to Operating Expenditures (OpEx). In an on-premises model, organizations must invest heavily in physical hardware (servers, storage, networking) and data center facilities before they can begin operations. In contrast, cloud computing utilizes a 'pay-as-you-go' model where costs are variable and based on actual resource consumption. This shift allows businesses to avoid large up-front costs, reduce the risk of overprovisioning, and better align their spending with actual demand. Option D is the correct answer.
Q14easy
Which of the following best defines a core infrastructure management responsibility for an organization utilizing an on-premises (private cloud) deployment model?
A.
The organization is responsible for procuring, installing, and maintaining all physical hardware and facility requirements.
B.
The organization is only responsible for application code, while a third-party provider manages the underlying server hardware.
C.
The organization relies on a cloud provider to automatically scale physical capacity based on real-time demand.
D.
The organization shares physical hardware with multiple other unrelated companies to reduce maintenance costs.
Show answer & explanation
Correct Answer: A
In an on-premises (private cloud) deployment model, the organization retains full control and responsibility over its infrastructure.
Physical Responsibility: Unlike public cloud models where a provider (like AWS, Azure, or Google Cloud) handles the hardware, an on-premises model requires the organization to manage the procurement, installation, and maintenance of all physical servers, storage, and networking devices.
Facilities Management: The organization must also provide and pay for the physical space, electricity, cooling, and security for the data center.
Manual Scaling: To increase capacity, the organization must manually purchase and install new physical hardware, which contrasts with the automated scaling found in public cloud environments.
Therefore, Option A is the correct definition of the management requirements for this model.
Q15hard
An enterprise uses AWS Organizations to manage multiple accounts. The hierarchy is structured as follows:
Root: The default FullAWSAccess Service Control Policy (SCP) is attached.
Production OU: A custom SCP is attached that explicitly denies all dynamodb:* actions.
Web-App Account: This member account is located within the Production OU. The default FullAWSAccess SCP is also attached to this account.
IAM User: An IAM user within the Web-App Account has the AdministratorAccess managed policy attached, which allows all actions (∗).
If the IAM user attempts to execute the dynamodb:PutItem action on a table within the Web-App Account, which of the following best describes the outcome and the underlying reason?
A.
The action is allowed because the 'Allow' statement in the Root SCP and the Account-level SCP creates a 'most-permissive' path that bypasses the OU-level restriction.
B.
The action is allowed because the IAM policy provides an explicit 'Allow' statement, which takes precedence over SCPs within a member account's local evaluation context.
C.
The action is denied only if the same user attempts the action from the Management Account, as SCPs are exclusively enforced on management-level entities for global compliance.
D.
The action is denied because the SCP at the OU level acts as a guardrail that defines the maximum available permissions, and an explicit 'Deny' in an SCP overrides any 'Allow' in an IAM policy.
Show answer & explanation
Correct Answer: D
To determine the effective permissions in an AWS Organization, the policy evaluator checks both the Service Control Policies (SCPs) and the IAM Policies.
SCPs as Guardrails: SCPs define the maximum permissions (the 'ceiling') for a member account. They do not grant permissions; they filter them.
The Hierarchical Filter: For an action to be permitted, every level of the hierarchy from the Root to the Account must allow the action. If any level (Root, OU, or Account) contains an explicit Deny, that action is blocked regardless of what any other policy says.
SCP vs. IAM: Even though the IAM user has AdministratorAccess (∗), the SCP at the Production OU level denies dynamodb:*. This 'Deny' statement acts as a hard boundary that the local IAM permissions cannot exceed.
Management Account Exception: It is important to note that SCPs do not affect users or roles in the Management Account; however, for all member accounts (like the Web-App Account), the SCP is absolute.
Therefore, the explicit 'Deny' at the OU level ensures the action is denied. Final Answer: D
[!WARNING]
Storage-optimized instances often use local "Instance Store" volumes. Remember that data on instance stores is ephemeral and will be lost if the instance is stopped.
Question
Accelerated Computing Instances
What differentiates Accelerated Computing instances from standard CPU-based instances?
Answer
Accelerated computing instances use hardware accelerators, or co-processors, to perform functions (such as floating-point number calculations or graphics processing) more efficiently than is possible in software running on CPUs.
Hardware Components Used:
GPUs (Graphics Processing Units)
FPGAs (Field Programmable Gate Arrays)
ASICs (Application-Specific Integrated Circuits)
Primary Use Cases:
Machine Learning (ML): Training and inference (Families: P, Trn, Inf).
Graphics/Video: 3D rendering, video streaming (Families: G).
Data Compression: High-speed hardware-based compression.
Loading Diagram...
Figure 1 — Mermaid diagram
Amazon Route 53 Essentials(5 cards shown)
Question
What is the primary purpose of Amazon Route 53?
Answer
Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service.
Its primary function is Name Resolution: translating human-readable domain names (like example.com) into numeric IP addresses (like 192.0.2.1) that computers use to connect to each other.
[!NOTE]
It effectively directs user requests to infrastructure running in AWS (EC2, ELB, S3) and can also route users to infrastructure outside of AWS.
Question
Explain the dual role of Route 53 as a Domain Registrar and a DNS Service.
Answer
Route 53 provides two distinct but related functions:
Domain Registration: Acts as a registrar where you can purchase and manage domain names (e.g., .com, .net, .org).
DNS Hosting: Provides the infrastructure to host DNS records and manage the "Hosted Zone" for a domain.
Function
Description
Registrar
Buying the name and owning the lease (1-10 years).
DNS Hosting
Defining where traffic goes (A records, MX records, etc.).
[!TIP]
You can register a domain with Route 53 and host it elsewhere, or vice-versa, but using both in Route 53 provides seamless integration.
Question
Compare Public Hosted Zones vs. Private Hosted Zones.
Answer
A hosted zone is a container for records that define how you want to route traffic for a domain.
Public Hosted Zone: Determines how traffic is routed on the Internet. Anyone can resolve these DNS records.
Private Hosted Zone: Determines how traffic is routed within one or more Amazon VPCs. These records are invisible to the public internet.
Loading Diagram...
Figure 1 — Mermaid diagram
[!NOTE]
Private zones are ideal for internal service discovery, such as mapping db.internal to a private database IP.
Question
Describe the common Route 53 Routing Policies.
Answer
Routing policies determine how Route 53 responds to DNS queries when multiple resources are available:
Simple: Routes traffic to a single resource (e.g., one IP address).
Weighted: Distributes traffic across multiple resources based on assigned proportions (e.g., 90% to 'Blue' environment, 10% to 'Green').
Latency: Routes users to the AWS Region that provides the lowest network latency.
Geolocation: Routes traffic based on the physical location of the users (e.g., send all UK users to a specific London endpoint).
Failover: Used for active-passive configurations; routes to a secondary resource if the primary is unhealthy.
[!WARNING]
Simple routing does not support health checks.
Question
How do DNS Health Checks improve application reliability in Route 53?
Answer
Route 53 can monitor the health and performance of your application endpoints.
Mechanism:
Monitoring: Route 53 sends requests to your application (HTTP, HTTPS, or TCP) to see if it's reachable.
Decision: If an endpoint is found to be unhealthy, Route 53 stops routing traffic to it.
Failover: Traffic is automatically redirected to a healthy resource (using policies like Failover, Weighted, or Latency).
Loading Diagram...
Figure 1 — Mermaid diagram
Amazon S3 Storage Classes(5 cards shown)
Question
Concept: S3 Standard vs. S3 Standard-IA
Explain the primary differences in use cases and availability between these two classes.
Answer
Comparison Table
Feature
S3 Standard
S3 Standard-IA
Use Case
Frequently accessed data (active)
Infrequently accessed but needs immediate access
Availability
99.99%
99.9%
AZ Coverage
≥ 3 Availability Zones
≥ 3 Availability Zones
Pricing
Higher storage cost; no retrieval fee
Lower storage cost; per-GB retrieval fee
[!TIP]
Think of Standard-IA for data like long-term backups or older sync data that is rarely touched but must be available in milliseconds when needed.
Question
Concept: S3 Intelligent-Tiering
How does S3 Intelligent-Tiering manage data with unknown or changing access patterns?
Answer
S3 Intelligent-Tiering is the only cloud storage class that delivers automatic cost savings by moving data between access tiers based on usage.
Key Features:
Automation: It monitors access patterns and moves objects that haven't been accessed for 30 consecutive days to the Infrequent Access tier.
Tiers: Includes Frequent Access, Infrequent Access, and Archive Instant Access.
No Retrieval Fees: Unlike Standard-IA, there are no fees for retrieving data when it moves back to frequent access.
Loading Diagram...
Figure 1 — Mermaid diagram
Question
Concept: S3 One Zone-IA
Explain the tradeoff between cost and resilience when choosing S3 One Zone-IA.
Answer
S3 One Zone-IA is designed for data that is infrequently accessed but does not require the multi-AZ resilience of other S3 classes.
Resilience: Data is stored in only one Availability Zone. If that AZ is destroyed, the data is lost.
Cost: Storage price is typically 20% lower than S3 Standard-IA.
Durability: Still designed for 99.999999999% (11 9s) durability within that single zone.
[!WARNING]
Only use this class for reproducible data, such as secondary backup copies or thumbnails generated from original images stored elsewhere.
Question
Concept: S3 Glacier Retrieval Options
Compare the retrieval times for Glacier Instant, Flexible, and Deep Archive.
Answer
S3 Glacier Retrieval Matrix
Storage Class
Retrieval Time
Best For
Glacier Instant Retrieval
Milliseconds
Medical records, news assets
Glacier Flexible Retrieval
1-5 mins (Expedited) 3-5 hrs (Standard)
Backup/disaster recovery
Glacier Deep Archive
12 hrs (Standard) 48 hrs (Bulk)
Compliance, 7-10 year logs
[!NOTE]
Glacier Flexible Retrieval (formerly just S3 Glacier) has a minimum storage duration of 90 days, while Deep Archive requires 180 days.
Question
Concept: S3 Lifecycle Management
Explain the two types of actions defined in an S3 Lifecycle rule.
Answer
S3 Lifecycle policies automate the management of objects so they are stored cost-effectively.
Transition Actions: Define when objects transition to another storage class (e.g., move to S3 Standard-IA after 30 days and then to S3 Glacier after 90 days).
Expiration Actions: Define when objects expire and should be permanently deleted by S3 on your behalf.
Example Workflow:
Loading Diagram...
Figure 1 — Mermaid diagram
[!TIP]
Use lifecycle policies to handle the "ageing" of logs or temporary data without manual intervention.
Analytics Services: Athena, Kinesis, Glue and Quick Sight(5 cards shown)
Question
What does Amazon Athena query, and in what language?
Answer
Data in Amazon Simple Storage Service (Amazon S3), using standard SQL.
Amazon Athena is an interactive query service that makes it easy to analyze data directly in Amazon Simple Storage Service (Amazon S3) using standard SQL.
The load-bearing word is directly: nothing has to be loaded into a database first.
Question
Which AWS service is built to collect and process record streams as they arrive, rather than in batches?
Answer
Amazon Kinesis Data Streams.
You can use Amazon Kinesis Data Streams to collect and process large streams of data records in real time.
If a scenario says real time and streams in the same breath, this is the service being described.
Question
What is AWS Glue, in one line?
Answer
A serverless data integration service.
AWS Glue is a serverless data integration service that makes it easy for analytics users to discover, prepare, move, and integrate data from multiple sources.
Four verbs worth memorising — discover, prepare, move, integrate. Glue is the plumbing between sources, not the place anyone looks at an answer.
Question
The CLF-C02 exam guide prints Amazon QuickSight. What is that service called today?
Answer
Amazon Quick Sight — two words — and it is now a feature inside Amazon Quick.
Amazon Quick evolved from Amazon QuickSight. QuickSight continues as Amazon Quick Sight, a feature within Quick. All existing QuickSight APIs, SDKs, and integrations continue to work without changes.
The published guide still carries the old spelling, so expect to meet either. Nothing built against the old name breaks.
Question
Raw logs sit in Amazon S3 and a manager wants a dashboard. Which two services split that job, and where is the seam?
Answer
Service
Its half of the job
Amazon Athena
analyze data directly in Amazon Simple Storage Service (Amazon S3) using standard SQL
Amazon Quick Sight
Interactive data visualization and business intelligence
The seam is SQL against storage versus the picture a person reads. Athena works out the answer; Quick Sight is where the answer is shown.
AWS Access Management Capabilities(5 cards shown)
Question
AWS Identity and Access Management (IAM)
Answer
IAM is a web service that enables you to manage access to AWS services and resources securely. It handles both Authentication (Who are you?) and Authorization (What can you do?).
Core Components:
Users: Permanent identities for specific people or applications.
Groups: Collections of users that share the same permissions.
Roles: Temporary identities used by AWS services (like EC2) or federated users.
Policies: JSON documents that define permissions and are attached to identities.
[!NOTE]
IAM is a global service; you do not select a region when working with it.
Question
Principle of Least Privilege (PoLP)
Answer
The security best practice of granting users, groups, and roles only the minimum permissions required to perform their specific tasks.
Implementation in AWS:
Start with Deny: By default, all requests are denied (Implicit Deny).
Explicit Allow: Attach policies that only allow necessary actions (e.g., s3:GetObject instead of s3:*).
Regular Audits: Use tools like IAM Access Analyzer to find and remove unused permissions.
[!TIP]
Adhering to PoLP limits the "blast radius" if a set of credentials is ever compromised.
Question
The AWS Account Root User
Answer
The single identity created when the AWS account is first established. It has unrestricted access to all resources and billing information in the account.
Example Case for Roles:
An EC2 Instance needs to upload logs to an S3 Bucket. You assign an IAM Role to the EC2 instance so it can fetch temporary credentials automatically without storing hardcoded keys.
Question
AWS IAM Identity Center
Answer
Formerly known as AWS Single Sign-On (SSO), this service centralizes the management of access to multiple AWS accounts and business applications.
Key Capabilities:
Federation: Connect your existing identity source (e.g., Microsoft Active Directory, Okta, Google Workspace).
Single Sign-On: Users log in once to a web portal to access all their assigned AWS accounts.
Multi-Account Management: Works with AWS Organizations to assign permissions across the entire fleet of accounts from one place.
[!NOTE]
This is the recommended service for managing workforce identities in AWS, rather than creating individual IAM users in every account.
Flowchart, top to bottom. Need to integrate services? connects to Messaging Pattern?. B connects to Amazon SNS (One-to-Many / Push). B connects to Amazon SQS (Asynchronous / Polling). B connects to Amazon EventBridge (State Changes / Scheduling). C connects to Fan-out to multiple subscribers. D connects to Buffer & Decouple components. E connects to Event-driven smart hub.
Loading Diagram...
Flowchart, top to bottom. Root User connects to Initial IAM Admin (Discards Access Keys). B connects to IAM Entities (Creates). C connects to Users - For People. C connects to Groups - For Collections. C connects to Roles - For Applications/Services. D connects to E (Belongs to). E connects to Managed Policies (Assigned). F connects to EC2 Instances/Lambda (Assumed by).
Loading Diagram...
Mermaid diagram. root AWS Access Management. Core Entities. Users. Groups. Roles. Security Best Practices. MFA. Least Privilege. 8 more statements.
Loading Diagram...
Flowchart, top to bottom. Admin (You) connects to S3 Bucket: lab-bucket (1. Creates). Admin (You)"] -->|1. Creates| B["S3 Bucket: lab-bucket connects to IAM Group: s3-readers (2. Creates). Admin (You)"] -->|1. Creates| B["S3 Bucket: lab-bucket connects to IAM User: test-user (3. Creates). C connects to Policy: AmazonS3ReadOnlyAccess (4. Attaches). D connects to C (5. Added to). D connects to E (Inherits permissions). D connects to B (6. Can Read / Cannot Write).
Loading Diagram...
Flowchart, left to right. Data Sources connects to Amazon S3 - Data Lake. B connects to Processing. C connects to AWS Glue - ETL. C connects to Amazon Athena - SQL. D connects to Amazon Redshift - Warehouse. E connects to Amazon QuickSight - BI. F connects to G.
Flowchart, top to bottom. Learner Workstation connects to Amazon S3 Bucket (1. Uploads Image). Learner Workstation"] -->|1. Uploads Image| B["Amazon S3 Bucket connects to Amazon Rekognition (2. API: detect-labels). C connects to B (3. Reads Image). C connects to Learner Workstation"] -->|1. Uploads Image| B["Amazon S3 Bucket (4. Returns JSON Tags). Learner Workstation"] -->|1. Uploads Image| B["Amazon S3 Bucket connects to Amazon Comprehend (5. API: detect-sentiment). D connects to Learner Workstation"] -->|1. Uploads Image| B["Amazon S3 Bucket (6. Returns Sentiment).
Loading Diagram...
Flowchart, left to right. Raw Unstructured Data connects to Data Type?. B connects to Amazon Comprehend (Text / Documents). B connects to Amazon Rekognition (Images / Video). B connects to Amazon Transcribe (Audio / Voice). C connects to Data Analytics <br> e.g., Amazon Athena, QuickSight. D connects to F. E connects to F.
Loading Diagram...
Mermaid diagram. root CLF-C02 Curriculum. Domain 1: Cloud Concepts. Value Proposition. Cloud Economics. Design Principles. Domain 2: Security and Compliance. Shared Responsibility Model. Identity & Access IAM. 9 more statements.
Loading Diagram...
Sequence diagram. C sends E: Completes 65 Questions. E sends R: Calculates Raw Score. R sends R: Applies Scaled Scoring Model. R sends C: Pass/Fail Result (Threshold 700).
Loading Diagram...
Flowchart, top to bottom. AWS Admin User connects to IAM Password Policy (1. Enforces). AWS Admin User"] -->|1. Enforces| B["IAM Password Policy connects to Amazon GuardDuty (2. Enables). AWS Admin User"] -->|1. Enforces| B["IAM Password Policy connects to AWS Secrets Manager (3. Stores). C connects to CloudTrail Event Logs (Monitors). C connects to VPC Flow Logs (Monitors). E connects to B (Audits). E connects to D (Audits).
Loading Diagram...
Flowchart, top to bottom. Customer Data connects to Platform, Applications, IAM. B connects to Operating System, Network & Firewall Configuration. Software: Compute, Storage, Database, Networking connects to Hardware / AWS Global Infrastructure. E connects to Regions, Availability Zones, Edge Locations. C connects to Software: Compute, Storage, Database, Networking] --> E[Hardware / AWS Global Infrastructure.
Loading Diagram...
Flowchart, top to bottom. Admin User (You) connects to Amazon GuardDuty (1. Enables). Admin User (You)"] -->|1. Enables| GD["Amazon GuardDuty connects to Amazon S3 Bucket (2. Creates & Secures). Admin User (You)"] -->|1. Enables| GD["Amazon GuardDuty connects to IAM Policy (3. Configures). GD connects to AWS Environment (monitors). S3 connects to AES-256 Encryption (secured by). S3 connects to Public Internet Access (blocks). IAM connects to S3 (restricts access to).
Loading Diagram...
Flowchart, top to bottom. AWS Responsibility (Security OF the Cloud connects to Hardware & Global Infrastructure (manages). AWS Responsibility (Security OF the Cloud connects to Compute, Storage & Network Infrastructure (secures). Customer Responsibility (Security IN the Cloud connects to Customer Data (S3 Content) (configures). Customer Responsibility (Security IN the Cloud connects to IAM Policies (Access Management) (manages). Customer Responsibility (Security IN the Cloud connects to Encryption & GuardDuty Settings (enforces).
Loading Diagram...
Mermaid diagram. root AWS Value Proposition. Cloud Concepts. Agility. Elasticity. High Availability. Economics. Variable Expense. Economies of Scale. 7 more statements.
Loading Diagram...
Flowchart, top to bottom. Well-Architected Framework connects to Operational Excellence. Well-Architected Framework] --> B(Operational Excellence connects to Security. Well-Architected Framework] --> B(Operational Excellence connects to Reliability. Well-Architected Framework] --> B(Operational Excellence connects to Performance Efficiency. Well-Architected Framework] --> B(Operational Excellence connects to Cost Optimization. Well-Architected Framework] --> B(Operational Excellence connects to Sustainability.
Loading Diagram...
Flowchart, top to bottom. Workload connects to CPU Intensive?. B -- Yes connects to Compute Optimized - C Series. B -- No connects to Evaluate Memory/Storage Needs.
Flowchart, left to right. Internet User connects to Public Hosted Zone (Resolves). EC2 in VPC connects to Private Hosted Zone (Resolves). EC2 in VPC] -->|Resolves| D(Private Hosted Zone connects to B (Also Resolves).
Loading Diagram...
Flowchart, top to bottom. User Query connects to Route 53. R53 connects to Server A: Healthy (Check). R53 connects to Server B: UNHEALTHY (Check). R53 connects to S1 (Routes Traffic).
Loading Diagram...
Flowchart, top to bottom. Upload Object connects to Access Monitoring. B -- "Accessed connects to Frequent Access Tier. B -- "No access (30 days) connects to Infrequent Access Tier. D -- "Accessed connects to C. D -- "No access (90 days) connects to Archive Instant Access. E -- "Accessed connects to C.
Loading Diagram...
Flowchart, left to right. Start([Creation]) -- "30 Days connects to Standard-IA. IA -- "60 Days connects to Glacier. GL -- "365 Days connects to Delete Object.
Loading Diagram...
Flowchart, top to bottom. Root User connects to IAM Admin User (Create). B connects to IAM Users/Groups (Create). Root User] -->|Create| B[IAM Admin User connects to Secure Vault (Lock Away).
Loading Diagram...
Flowchart, left to right. User[Developer/App] -- Signs Request with connects to Access Key Pair. Key -- Authenticates connects to AWS Service API.